HP HomePassport

Legal

Privacy Policy

Last updated 4 August 2026

1. Who we are

HomePassport is a digital property logbook service operated by a sole trader based in the United Kingdom (the "data controller" for the purposes of UK data protection law). You can contact us about anything in this policy at [email protected].

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What we collect and store

  • Account details — your name, email address and password (stored hashed), and your chosen plan.
  • Property information you provide — addresses and postcodes of properties you add, plus any notes, appliance details, dates and other information you record against them.
  • Documents you upload — certificates, receipts, photographs and other files you choose to store in your document vault.
  • Public-register data — records we fetch on your behalf from official public sources: HM Land Registry price paid data, the MHCLG Energy Performance Certificate register, and planning.data.gov.uk. This data is published under the Open Government Licence v3 and may relate to your property's history before your ownership.
  • Payment information — handled by our payment processor (see section 5). We never see or store your full card details.
  • Technical basics — server logs (IP address, request time) kept for security and troubleshooting.

3. Lawful basis for processing

  • Contract — most processing (your account, your properties, your documents, reminders, sale packs) is necessary to provide the service you signed up for.
  • Legitimate interests — keeping the service secure, preventing abuse, and improving how it works.
  • Legal obligation — retaining basic billing records as required by UK tax law.
  • Consent — optional features that use consent (such as document-photo extraction, section 5) are clearly presented as optional and can be declined.

4. Cookies

We use essential cookies only: a session cookie to keep you signed in and a CSRF token cookie to protect forms. We do not use advertising, analytics or tracking cookies, so we don't show a cookie banner — there is nothing to opt out of.

5. Processors we use

We share data with a small number of service providers ("processors") who act on our instructions:

  • Stripe — payment processing for paid plans. Stripe receives the details needed to take payment and is a certified PCI-DSS provider.
  • Anthropic — if you choose to use the optional document-photo extraction feature, the image you submit is sent to Anthropic's API to read the details from it. This only happens when you actively use the feature.
  • Email provider — to send transactional email such as sign-in links, reminders and receipts.

Where a processor is outside the UK, transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses.

6. Who we share your data with

We do not sell your data, and we do not share it with anyone except:

  • the processors listed above;
  • people you choose to share with — when you create a share link (for example, for your estate agent or solicitor) or transfer a passport to a buyer at sale, the recipient sees the information included in that link or transfer. You control what is shared and can revoke share links at any time;
  • authorities where the law requires it.

7. How long we keep your data

  • Your account and its contents are kept while your account is active.
  • If you close your account, we delete your personal data and uploaded documents within 30 days, except where a passport has been transferred to a new owner (the transferred property record remains with its new owner, with your personal details removed).
  • Billing records are kept for 6 years as required by UK tax law.
  • Server logs are kept for a short rolling period for security purposes.

8. Your rights

Under UK GDPR you have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — ask us to delete your data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction and objection — limit or object to certain processing.

To exercise any of these rights, email [email protected]. We will respond within one month.

9. Complaints

If you are unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk or by phone on 0303 123 1113.

10. Changes to this policy

If we make material changes to this policy we will update the date at the top and, where the change affects how we use your data, notify you by email.