Kite Privacy Policy
Effective date: 13 June 2026
This Privacy Policy explains how we collect, use, share, and protect your personal data when you use Kite. We have written it to be as clear as we can while remaining legally precise. If anything here is unclear, please contact us using the details in the final section.
1. Who we are
In short: Kite is provided by Kite Tax Limited, and we are responsible for your personal data.
Kite ("Kite" or "the Service") is a web application that helps UK sole traders and landlords keep digital records and meet their obligations under Making Tax Digital for Income Tax Self Assessment (MTD ITSA).
The data controller for the personal data described in this policy is:
- Company: Kite Tax Limited, a company registered in England and Wales.
- Company number: 17253815.
- Registered office: 66 Paul Street, London, England, United Kingdom, EC2A 4NA
- ICO registration number: ZC173804
- Contact email: admin@kite.tax
A data controller is the organisation that decides why and how your personal data is processed. For most of the activities described in this policy, Kite Tax Limited is the controller. HM Revenue and Customs (HMRC) acts as a separate, independent controller for the tax data you submit to it. We explain this in section 8.
2. What this policy covers
In short: this policy covers the Kite application and our website.
This policy applies to your use of the Kite application and our website, including the legal pages published at /legal/privacy and /legal/terms. It describes the personal data we process about account holders and visitors.
This policy does not govern HMRC's own handling of your data, your bank's handling of your data, or any third-party website that may link to or from Kite. Those organisations have their own privacy notices.
A note on what Kite is: Kite is software that helps you keep digital records and submit them to HMRC. Kite is not an accountant or tax adviser and does not provide tax, legal, or financial advice. The figures and submissions in your account are your responsibility, and HMRC's records remain the system of record.
3. The personal data we collect
In short: we collect the data needed to run your account, keep your records, and submit them to HMRC on your instruction.
We collect and process the following categories of personal data.
3.1 Account and identity data
Your full name, email address, email verification status, and password. Your password is stored in hashed form and is managed by our authentication provider; we do not store or see it in readable form. If you sign in using an OAuth provider (Google or GitHub), we also process your profile image and the OAuth tokens issued by that provider.
3.2 Technical and device data
Your IP address, browser user-agent and device information, and session tokens. For HMRC's legally required fraud-prevention headers, we also process your screen size, window size, timezone, and a persistent device identifier stored in a cookie. We describe the cookies we use in section 12.
3.3 Tax identity and business profile
Your National Insurance number (NINO), business trading name, business type (sole trader or property business), accounting basis (cash or accruals), business commencement and cessation dates, your HMRC "MTD ID", and the basis on which you became MTD-mandated.
Your National Insurance number is a national identifier that attracts specific protections under the Data Protection Act 2018. We process it because it is necessary to perform our contract with you and to meet HMRC's MTD requirements, and we handle it under the additional safeguards required by the Data Protection Act 2018, including masking it in our activity logs.
3.4 HMRC connection credentials
If you connect your HMRC account, we store the OAuth access and refresh tokens for that connection. These tokens are encrypted at rest.
3.5 Financial records
Your income and expense transactions (date, description or merchant, amount, income-or-expense type, HMRC category, and your notes), quarterly totals, tax calculations, submissions and the payloads sent to HMRC, brought-forward losses and year-end adjustments, and the advisory messages returned by HMRC's "Self Assessment Assist" service.
Where you connect HMRC, we also retrieve certain figures that HMRC already holds on your record, on a read-only basis: savings interest, dividends, employment (PAYE) income, reliefs, and Construction Industry Scheme (CIS) deductions.
When we use AI to suggest a category for a transaction, only five limited fields are sent to our AI provider, not your full financial record. We explain exactly what is and is not sent in section 5.
3.6 Bank data via Open Banking
If you choose to connect a bank, we retrieve your bank account details (account name, account number, sort code, IBAN, and balance) and your transaction history (dates, amounts, descriptions, and merchant or payee information). We do this through Yapily Ltd, an FCA-authorised Open Banking provider, under your explicit consent.
You grant this consent in your bank's own authentication flow, not in Kite. Open Banking consent is time-limited under Open Banking rules: it expires after a set period and must be periodically reconfirmed (reauthenticated) rather than continuing indefinitely. We store the consent tokens needed to retrieve your data while consent is live. You can withdraw consent at any time, either at your bank or by disconnecting the bank in Kite.
3.7 Receipts and documents
Receipt files you upload (images, PDF, or document files) and their metadata (filename, type, size, and checksum), stored in object storage.
3.8 Audit and activity logs
A record of key account actions: signing in and out; creating, updating, or deleting records; submissions; connecting or disconnecting HMRC or a bank; imports and exports; and settings and admin actions. Each entry is recorded together with the IP address and user-agent. National Insurance numbers are masked in these logs.
3.9 Preferences
Your in-app help and interface preferences, and the categorisation patterns Kite learns from how you categorise your own transactions.
4. Where your data comes from
In short: most of your data comes from you, but some comes from HMRC, your bank, and your sign-in provider.
Most of the personal data we hold is data you give us directly, for example when you create your account, enter your business details, or record your transactions. We also obtain some personal data from sources other than you:
- From HM Revenue and Customs (HMRC), where you have connected your HMRC account: read-only figures that HMRC already holds on your record, namely savings interest, dividends, employment (PAYE) income, reliefs, and Construction Industry Scheme (CIS) deductions.
- From your bank, through Yapily Ltd under your Open Banking consent: your bank account details and transaction history, as described in section 3.6.
- From your sign-in provider, where you sign in using Google or GitHub: your profile image and the OAuth tokens issued by that provider.
Where we obtain data from these sources, we use it for the same purposes and on the same lawful bases set out in this policy.
5. AI and automated categorisation
In short: AI suggests a tax category; you stay in control and can always change it.
Kite uses AI to suggest an HMRC category for a transaction, to save you time. To do this, we send only the transaction description, amount, date, business type, and income-or-expense type to our AI provider, Anthropic, which provides the Claude Haiku model. We do not send your bank credentials, your National Insurance number, or your account numbers to the AI.
This is a suggestion only. You review every suggestion and can change it. No legal or similarly significant decision is made about you solely by automated means, and the categorisation patterns Kite learns are only ever applied as suggestions you can override.
6. How and why we use your data, and our lawful basis
In short: we only use your data for the purposes listed here, and each purpose has a lawful basis under UK GDPR.
Under UK GDPR we must have a lawful basis for each way we use your personal data. The table below sets out our purposes and the basis for each.
| Purpose | Personal data used | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Creating and running your account, and providing the Service | Account and identity data, preferences | Contract |
| Keeping your digital records, calculating quarterly totals, and making the HMRC submissions you initiate | Tax identity and business profile, financial records, HMRC connection credentials | Contract |
| Connecting your bank and importing transactions through Open Banking (time-limited consent, revocable at your bank or in Kite) | Bank data, consent tokens | Consent (given at your bank) |
| Meeting HMRC's mandatory fraud-prevention header requirements | Technical and device data (including device identifier, screen and window size, timezone) | Legal obligation |
| Retaining records where the law requires | Financial records, tax identity data | Legal obligation |
| Security, fraud prevention, and audit logging | Technical and device data, audit and activity logs | Legitimate interests |
| Error monitoring, performance monitoring, and session-replay diagnostics to diagnose and fix faults | Technical and device data, limited personal data in error reports, sampled session replays | Legitimate interests |
| Suggesting an HMRC category for a transaction (AI categorisation) | Transaction description, amount, date, business type, income-or-expense type | Legitimate interests |
| Improving the Service | Privacy-friendly aggregate analytics, preferences | Legitimate interests |
| Sending optional marketing, if you have asked to receive it | Name, email address | Consent |
Where we rely on legitimate interests, we have considered your rights and interests and limited the processing accordingly. You can object to processing based on legitimate interests, and withdraw consent where we rely on consent, as described in section 13.
Providing your National Insurance number and connecting your HMRC account are necessary to use the Service for its core purpose. Without them we cannot keep your MTD records or make submissions to HMRC on your behalf, and you will not be able to use those parts of the Service.
7. Who we share your data with
In short: we use a small set of carefully chosen providers to run the Service, listed below.
We share your personal data with the service providers in the table below, only to the extent needed for them to perform their function. We do not sell your personal data. The "Location" column shows where each provider may process your data; where this can be outside the UK, the safeguards in section 9 apply.
| Provider | Purpose | Location |
|---|---|---|
| Neon | Database hosting and authentication (Neon Auth, built on Better Auth) for accounts and sessions | AWS London (eu-west-2), United Kingdom |
| Yapily Ltd | FCA-authorised Open Banking provider used to retrieve bank account and transaction data under your consent | UK / EEA |
| Cloudflare R2 | Object storage for uploaded receipts and document files | Automatic global distribution; may be outside the UK |
| Resend | Transactional email delivery (deadline reminders, submission confirmations, bank-connection-expiry notices) | May be outside the UK |
| Trigger.dev | Background job processing (bank sync, HMRC sync, AI categorisation, emails, receipt previews); job payloads contain record identifiers and metadata | May be outside the UK |
| Anthropic (Claude) | AI categorisation, using only the limited transaction data described in section 5 | May be outside the UK |
| Sentry | Error monitoring, performance monitoring, and session replay (a sample of sessions, with some personal data included in error reports) | EU |
| Vercel | Application hosting, and Vercel Analytics for aggregate, privacy-friendly website analytics | May be outside the UK |
| Our payment provider | Processing your subscription payments | May be outside the UK |
Most of these providers act as our processors and may only use your data on our instructions. Two exceptions are worth noting. HMRC is a separate, independent controller, which we explain in section 8. Our payment provider also acts as an independent controller for some purposes, such as preventing payment fraud and meeting its own anti-money-laundering and other legal obligations; for those purposes it is responsible for your data under its own privacy notice.
8. HMRC is a separate controller
In short: when you submit to HMRC through Kite, HMRC becomes responsible for that data under its own legal basis.
HMRC is the recipient of the tax information you submit. When you make a submission, Kite acts as the conduit you use to send your data to HMRC: we transmit your National Insurance number, business details, and income and expense figures to HMRC, together with the fraud-prevention headers that all MTD software is legally required to send.
HMRC is a separate and independent data controller for the data it receives, and processes that data under its own legal basis and its own privacy notice. This means that once your data reaches HMRC, HMRC (not Kite) is responsible for it. HMRC's records are the authoritative record of your tax position.
9. International transfers
In short: where data leaves the UK, we make sure it stays protected.
Some of our providers may process your data outside the United Kingdom. This includes, for example, Anthropic, Resend, and Vercel, and may also include Cloudflare R2 (which may store uploaded receipts outside the UK), Trigger.dev, and our payment provider. Wherever a provider listed in section 7 processes your data outside the UK, we ensure the transfer is protected by an appropriate safeguard recognised under UK data protection law. Depending on the provider and destination, this safeguard is one of the following:
- UK adequacy regulations for the relevant country;
- the UK International Data Transfer Agreement; or
- Standard Contractual Clauses together with the UK Addendum.
You can ask us for more detail on the safeguards that apply to a particular transfer using the contact details in section 16.
10. How long we keep your data
In short: we keep your data while your account is active, and only keep it longer where the law requires.
We keep your personal data for as long as your account is active and we need it to provide the Service. The main criteria we use to decide how long to keep data are whether your account remains active, whether we still need the data to provide the Service, and whether the law requires us to retain particular records (for example tax records) for longer.
Separately from Kite, UK self-assessment taxpayers are themselves legally required to keep their own tax records. For sole traders and landlords this is generally until at least the fifth anniversary of the 31 January filing deadline for the relevant tax year. You should keep your own copies accordingly, because deleting your Kite account does not remove your underlying legal record-keeping duty.
When you delete your account, your data is removed as described in section 13. Where we are legally required to retain certain records, we keep only what the law requires and for no longer than necessary. Residual copies in our routine backups are purged on a rolling cycle and are deleted in the ordinary course of that cycle.
11. How we keep your data secure
In short: we take reasonable, practical measures to protect your data, and we do not overstate them.
We use a range of technical and organisational measures to protect your personal data, including:
- HMRC and bank consent tokens are stored encrypted at rest.
- Data is transmitted over encrypted connections (TLS).
- We use UUID identifiers rather than sequential identifiers.
- Access controls restrict who can see financial data.
- National Insurance numbers are masked in our activity logs.
No online service can be completely secure, and we do not claim to hold any particular security certification. We keep our measures under review and aim to apply safeguards appropriate to the sensitivity of the data we hold.
12. Cookies and similar technologies
In short: we use only the cookies needed to run the Service and to diagnose faults, with no advertising or cross-site tracking.
Kite uses a small number of cookies and similar technologies:
- Strictly necessary: one or more session cookies to keep you signed in, and a persistent device-identifier cookie that is required for HMRC's fraud-prevention headers. These are essential for the Service to work and cannot be turned off without affecting your ability to use Kite.
- Preferences: your theme preference is stored locally in your browser (in local storage), so the interface remembers how you like it.
- Analytics: Vercel Analytics gives us aggregate, privacy-friendly website analytics. It does not use advertising cookies and does not track you across other websites.
- Diagnostics: Sentry records a sample of user sessions as session replays, as described in section 7 and below, to help us diagnose faults.
We do not use advertising cookies or cross-site tracking cookies.
Session replay: to diagnose faults, Sentry records a sample (around 10 per cent) of user sessions as replays of on-screen activity. Because Kite is a tax application, a replay may capture information shown on your screen during the sampled session, which can include tax figures and other personal data. Sentry is also configured to include some personal data in error reports. We carry out this diagnostic processing under our legitimate interests in keeping the Service reliable and secure, and you can object to it using the contact details in section 16.
13. Your rights
In short: you have strong rights over your data, and you can exercise them by emailing us.
Under UK GDPR you have the following rights:
- Access: to ask for a copy of the personal data we hold about you.
- Rectification: to ask us to correct inaccurate or incomplete data.
- Erasure: to ask us to delete your data in certain circumstances. This right can be limited where we are legally required to keep certain records, such as tax records, so deletion may not remove data we must retain by law.
- Restriction: to ask us to limit how we use your data in certain circumstances.
- Portability: to ask for your data in a portable, machine-readable format.
- Objection: to object to processing based on our legitimate interests, including the session-replay diagnostics described in section 12.
- Withdraw consent: where we rely on your consent, to withdraw it at any time (for example, by revoking Open Banking consent at your bank or disconnecting the bank in Kite, or by unsubscribing from marketing). Withdrawing consent does not affect processing carried out before you withdrew it.
To exercise any of these rights, email us at admin@kite.tax. We will respond within the time limits set by UK data protection law.
Deleting your account
You can delete your account at any time. Deletion is irreversible. When you delete your account, the deletion cascades to remove your businesses, quarters, transactions, submissions, receipts, bank connections, profile, help progress, audit logs, and categorisation patterns. Where the law requires us to keep certain records, we retain only those records for as long as the law requires. Residual copies in our routine backups are purged on the rolling cycle described in section 10.
Complaining to the ICO
If you are unhappy with how we have handled your personal data, including any concern about an international transfer, you have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. You can complain to the ICO at any time. We would, however, welcome the chance to address your concerns first, so please consider contacting us as well.
14. Children
In short: Kite is not for under-18s.
Kite is intended for adults. The Service is not directed at children, and you must be at least 18 years old and a UK taxpayer to use it. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps.
15. Changes to this policy
In short: if we change this policy, we will update the date and, for significant changes, tell you.
We may update this policy from time to time to reflect changes to the Service, to our providers, or to the law. When we do, we will update the effective date at the top of this page. If a change is significant, we will take reasonable steps to bring it to your attention, for example by email or an in-app notice.
16. How to contact us
In short: email us with any privacy question or request.
If you have any questions about this policy, or you wish to exercise any of your rights, please contact us:
- Company: Kite Tax Limited
- Registered office: 66 Paul Street, London, England, United Kingdom, EC2A 4NA
- Email: admin@kite.tax
If you wish to escalate a concern beyond us, you can contact the Information Commissioner's Office at ico.org.uk.