Privacy Notice

How SaidToPaid collects, uses, shares and protects personal data when you use our service and website.

SaidToPaid · Last updated 9 September 2026

Who we are

SaidToPaid ("we", "us") provides voice-led job admin software for trade and service businesses. SaidToPaid is the data controller for personal data described in this notice, which means we decide why and how it is processed.

You can contact us about privacy at support@saidtopaid.ai.

Personal data we collect

We collect the following categories of personal data:

  • Account data: name, email address, sign-in credentials and the business you belong to.
  • Business profile data: trading name, addresses, company and VAT registration details, contact details and logo.
  • Customer records you enter: your customers' names, contact details, addresses, vehicles and job history.
  • Voice recordings, transcripts and the estimates, invoices and messages generated from them.
  • Support data: messages you send us and the context needed to answer them.
  • Usage and technical data: pages used, feature events, device and browser information, IP address and security logs.
  • Billing data held by our payment provider: your billing name, address, country and the payment record for each order. We never see or store full card numbers.

Why we use it and our legal basis

  • To create your account, provide the service and store your records — performance of our contract with you.
  • To transcribe recordings and draft paperwork using an AI processor acting on our instructions — performance of our contract with you.
  • To take payment, manage subscriptions, invoice and meet tax obligations — performance of our contract and compliance with legal obligations.
  • To keep the service secure and prevent fraud or abuse — our legitimate interests in protecting the service and its users.
  • To improve reliability and product quality using aggregated or de-identified usage data — our legitimate interests in improving our product.
  • To send service and product emails you can opt out of — our legitimate interests, or consent where the law requires it.

Your customers' data

Where you enter details about your own customers, you are the controller of that data and we act as your processor: we only process it to provide the service to you and on your instructions. You are responsible for having a lawful basis to enter it and for telling your customers how you use it.

AI processing

Voice recordings and the text drawn from them are sent to an AI provider acting as our processor, solely to produce transcripts and draft documents. Your content is not used to train third-party public models. Drafts are suggestions and must be checked before you send them.

Who we share data with

We share personal data only with:

  • Service providers acting on our instructions: cloud hosting, database and private file storage, AI transcription, email delivery and product analytics.
  • Paddle.com Market Limited, our reseller and Merchant of Record, for the sale of subscriptions, payments, invoicing, subscription management, fraud screening and tax compliance. Paddle acts as an independent controller for that billing data under its own privacy notice.
  • Professional advisers such as our accountants and lawyers, where needed.
  • Public authorities, regulators or courts where we are legally required to do so.

International transfers

Some of our providers process data outside the UK and European Economic Area. Where that happens we rely on an adequacy decision or on Standard Contractual Clauses with additional safeguards, so your data keeps an equivalent level of protection.

How long we keep it

  • Account and business records: for as long as your account is open, then up to 90 days after closure before deletion or anonymisation.
  • Voice recordings: until you delete them, or until account closure.
  • Estimates, invoices and payment records: 7 years, to meet UK tax and accounting requirements.
  • Security and access logs: up to 12 months.
  • Support messages: up to 24 months.

Your rights

Subject to the conditions in data protection law, you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where we relied on it. You can exercise most of these in the app, or by emailing support@saidtopaid.ai. We respond within one month. If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority.

Security

We use appropriate technical and organisational measures: encryption in transit and at rest, private file storage with per-business access rules, database access controls that isolate each business's data, least-privilege administrative access and audit logging of sensitive actions. No system is completely secure, so please use a strong, unique password.

Cookies

We use essential cookies and browser storage to keep you signed in and to keep the service secure, and limited analytics to understand how features are used. We do not use advertising cookies. See our Cookie Policy for detail and how to manage your preferences.

Changes

We will update this notice when our practices change, and will tell you about significant changes by email or in the app.

Questions about this page? Email support@saidtopaid.ai.