Privacy Policy

Last updated: September 2026

Paylist ("MyPaylist Ltd", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect personal data in connection with our website and subscription-based software services (the "Services"). This policy is intended to comply with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and the Data (Use and Access) Act 2025, as applicable.

Who we are

MYPAYLIST LTD is a company registered in England and Wales (Company No. 16935308).

For personal data that we process for our own purposes, including to operate, secure, improve and administer the Services, Paylist is the data controller for the purposes of applicable data protection laws.

Depending on how the Services are used, a business or other organisation using Paylist may remain the data controller for personal data that it provides to Paylist for processing on its behalf. In those circumstances, Paylist may act as a data processor. The respective responsibilities of Paylist and the relevant customer will depend on the nature and purpose of the particular processing.

Where Paylist acts as a processor, the processing will be governed by appropriate contractual terms, including our Data Processing Agreement where applicable, and the customer's documented instructions.

If you are a Paylist customer using the Services to process personal data belonging to your customers, suppliers, employees or other individuals, you remain responsible for ensuring that you have an appropriate lawful basis and authority to provide that information to us and to use the Services for that purpose.

We have not appointed a statutory Data Protection Officer. Questions about this Privacy Policy, our data practices or your rights should be directed to hello@mypaylist.com.

Information we collect

Business information

Legal business name, trading name, business type, company registration number, registered and trading address, declared turnover and turnover band, business logo and any public profile information you choose to display, such as public email and phone number.

We also store data returned from Companies House in response to company-number verification checks, including officer details, registered office address, SIC codes and company status.

Some information relating to a company may not constitute personal data where it relates solely to a legal entity. However, information relating to individuals, including sole traders, company officers and business contacts, may constitute personal data and will be handled in accordance with applicable data protection law.

Financial and banking information

Bank account details including account name, sort code, account number, IBAN and BIC/SWIFT. Each verified bank account is assigned a unique "Paylist number".

We also store transaction and accounting data you submit or that is synchronised through supported integrations, and billing and subscription information, including Stripe customer ID, subscription status and billing period dates.

Bank account information may constitute personal data where it relates to an identifiable individual, including in the case of sole traders or other individuals conducting business activities.

We treat bank account information as confidential financial information and apply appropriate technical and organisational measures to protect it.

Personal data

Names, email addresses, phone numbers, job titles and postal addresses of authorised users, company officers, authorised signatories and business contacts. Identification information where required for verification purposes.

Invitee data

When you invite contacts to join Paylist, we collect and store the invitee's email address, business name and any custom message you choose to include, in order to deliver the invitation and track its status.

Our lawful basis for processing invitee data is our legitimate interest in facilitating the invitation you have asked us to send. We may also process the invitee's information where necessary to comply with a legal obligation.

Invitees may contact us at any time to ask questions about their data or to exercise applicable data protection rights.

Information provided about other individuals

You may provide Paylist with personal information relating to other individuals, such as customers, suppliers, employees, company officers, authorised signatories, business contacts or payment contacts.

Where you provide personal data about another individual, you are responsible for ensuring that you are entitled to provide that information to us and, where required, that the individual has been provided with appropriate privacy information.

We may also receive personal data indirectly from sources including Paylist customers, accounting software platforms, Companies House, bank-account verification providers and other Paylist users.

Where we obtain personal data from another source, we will provide the information required by applicable data protection law unless an applicable legal exception applies.

Integration data

OAuth access and refresh tokens for connected third-party accounting platforms, including Xero, QuickBooks, Sage and FreeAgent, stored encrypted, and contact records synchronised between Paylist and those platforms at your direction.

We use integration data only to provide, maintain and secure the integration and to perform the synchronisation or other functionality you have requested, subject to any other processing described in this Privacy Policy.

Technical data

IP address, browser type, device information, usage data relating to how you interact with our Services, authentication session information and other technical information required to operate, secure and maintain the Services.

Analytics data

Aggregated, cookieless measurement data about how the Services are used: pages viewed, referring website, browser, operating system, device type, screen size, language and country.

We also record a small number of product events — for example that a directory search was run, an invitation was sent, or an accounting integration was connected — as counts and categories only.

Analytics events are designed not to include your name, email address, business name, search terms, Paylist numbers or bank details. See "Cookies and analytics" below.

Verification and audit data

Records of verification checks performed, including company number, officer confirmation, bank-account checks (Confirmation of Payee and modulus checks) and administrator review, together with the requests made, responses received and outcomes.

These records may include information obtained from Companies House, bank-account verification providers and other verification sources.

Verification and audit records are retained where necessary to demonstrate the integrity of our verification processes, prevent fraud and abuse, investigate disputes and comply with applicable legal or regulatory obligations.

Cookies and tracking data

Information collected via cookies and similar technologies. See "Cookies and analytics" below.

How we use your information

We use your data to:

  • provide and operate the Services and manage your account;
  • verify your business via Companies House and perform bank-account verification, including Confirmation of Payee and modulus checks;
  • perform administrator review and approval of business accounts;
  • maintain a directory of verified businesses for authenticated Paylist users;
  • allow businesses to choose whether their full bank-account details are disclosed only on approval of an access request or are available to authenticated users, in accordance with the visibility setting they select;
  • facilitate the controlled disclosure of bank-account information between authenticated Paylist users where the relevant business has authorised that disclosure through its selected visibility settings or an approved access request;
  • assign and display Paylist numbers associated with verified bank accounts;
  • send invitations you have asked us to send and track their status;
  • synchronise contact data between Paylist and any third-party accounting software you connect;
  • process payments, manage subscriptions and issue invoices via our payment provider;
  • send transactional emails relating to your account, verification, billing, invitations, bank-access requests and integrations;
  • communicate with you about the Services and, where permitted and where you have opted in or another lawful basis applies, send marketing communications;
  • measure, on an aggregated and cookieless basis, how the Services are used so that we can improve them;
  • improve, monitor, secure and maintain our platform;
  • detect, investigate and prevent fraud, money laundering, abuse, unauthorised access and other security threats;
  • establish, exercise or defend legal claims;
  • comply with legal and regulatory obligations; and
  • otherwise use information where permitted or required by applicable law.

We do not use bank account details to initiate payments or move money from or to a bank account unless a separate Paylist service expressly provides for this functionality and you have authorised the relevant transaction.

Legal bases for processing

We rely on the following legal bases under UK GDPR, depending on the particular processing activity:

Contractual necessity — to create and administer your account, provide the Services you have subscribed to, store and manage information necessary to provide the Services, perform requested integrations and provide functionality such as verification and bank-account management.

Legal obligation — where processing is necessary for us to comply with a legal or regulatory obligation applicable to us, including applicable accounting, tax, fraud-prevention, record-keeping or other legal requirements.

Legitimate interests — where processing is necessary for our legitimate interests, or those of a third party, and those interests are not overridden by your interests or fundamental rights and freedoms. This may include operating and securing the Services, preventing fraud and abuse, maintaining audit records, improving our Services, facilitating invitations requested by users, defending legal claims and maintaining the integrity of our verification and directory services.

Consent — where you actively choose to permit a particular use of your personal data and consent is the appropriate lawful basis.

In particular, where you change your bank-account visibility setting from the default Private setting to Public, you are actively choosing to make your full bank account number and sort code available to authenticated Paylist users, without a further approval step, for the specific purpose of enabling them to obtain payment details for your business.

Where the bank-account information constitutes personal data, we rely on your consent under Article 6(1)(a) UK GDPR for this disclosure. The action of changing the setting from Private to Public is a clear affirmative action indicating your agreement to the specified processing and disclosure.

You may withdraw this consent at any time by changing your bank-account visibility setting back to Private. Withdrawal of consent does not affect the lawfulness of any processing or disclosure that took place before your consent was withdrawn.

Under the default Private setting, you consent to Paylist processing your bank-account information for the purpose of managing access requests, and displaying masked bank details to authenticated Paylist users so that your business can be identified. Full bank details will only be disclosed to another authenticated Paylist user where you actively approve that particular request.

We will maintain records of consent where required, including the relevant account or user, the date and time consent was given, the setting selected and the version of the information presented to you at the time of consent.

Where we rely on legitimate interests, we consider the nature of the processing, its impact on individuals and whether their interests, rights and freedoms are adequately protected. You may object to processing based on legitimate interests where the law gives you that right.

You may withdraw consent at any time where we rely on consent.

Automated decision-making

We use automated checks to verify business and banking information, including company number verification against Companies House, bank-account verification (Confirmation of Payee and modulus checks) and automated eligibility or plan-assignment logic based on declared turnover.

These automated checks do not, on their own, produce legal or similarly significant effects without appropriate human involvement. Final approval or rejection of a business account is reviewed by a member of the Paylist administration team.

Where an automated check produces an outcome that affects your account, you may contact us to request information about the outcome and, where applicable, request human intervention or challenge the decision.

Where applicable law provides additional rights in relation to solely automated decision-making, we will provide those rights and safeguards.

Directory and bank-detail visibility

A core feature of Paylist is the ability for verified businesses to be discoverable by other authenticated users.

Once your business is verified, your public profile may include your business name, trading name, city, postcode, logo, public contact details and other information that you choose to make available through the Services. This information may be visible to authenticated Paylist users in the Paylist directory.

A single visibility setting applies to all bank accounts held by your business. The default setting is Private. You may actively change the setting to one of the following:

Private (default) — your business remains listed in the Paylist directory and authenticated Paylist users can see masked bank details, including the account name, bank name, sort code last two digits and account number last four digits. Your full sort code and account number are not disclosed unless you actively approve an access request from a specific user. By using the Services with this setting, you consent to Paylist processing your bank-account information for the purpose of managing those access requests. Each disclosure of full bank details requires your approval through the Services.

Public — masked bank details remain visible to authenticated Paylist users as above, and your full bank account number and sort code may be disclosed to any authenticated Paylist user who uses the relevant Paylist functionality to save your business as a payee or otherwise obtain the full payment details, without a further approval step. By changing your setting from Private to Public, you actively consent, where the information constitutes personal data, to Paylist making those full details available for the specific purpose of enabling other users to obtain payment details for your business.

Your Paylist number is a public identifier associated with your verified bank account and may be visible to authenticated Paylist users.

The purpose of this functionality is to allow businesses using Paylist to identify verified businesses and obtain payment information in accordance with the visibility setting selected by the bank-account owner.

You may change your visibility setting at any time from your account settings. Where you have consented to Public visibility, changing the setting back to Private withdraws your consent to the further disclosure of full bank details without your approval. Masked details remain visible under either setting.

Changes will apply to future discovery and disclosure. A change in visibility cannot retrieve or delete information that another user has already viewed, downloaded, recorded or otherwise obtained before the change, and does not withdraw access from a user whose access request you have already approved. You may withdraw a previously approved access request at any time from your account settings. You should therefore only select Public or approve an access request where you are comfortable with the corresponding disclosure of your bank-account information.

Paylist does not control how another Paylist user may use information after it has been legitimately disclosed to that user. Users must comply with applicable law and their own data-protection obligations when handling information obtained through Paylist.

We may restrict, suspend or remove access to bank-account information where we reasonably believe that an account, access request or disclosure presents a security, fraud or data-protection risk.

Banking and confidential financial data

Due to the nature of our Services, we process confidential financial information, including bank-account details.

Bank account details are not treated as special-category personal data merely because they are financial information. However, we recognise that such information is confidential and may create significant risks if improperly accessed or disclosed.

We implement appropriate technical and organisational measures to protect this information, including encryption of sort codes, account numbers and IBANs at rest using industry-standard encryption, encryption of integration OAuth tokens at rest, encryption of data in transit using TLS, role-based access controls, least-privilege access, authentication and session management, and logging of administrative actions and verification events for auditing.

Where technically appropriate, access to sensitive information is restricted to authorised users and personnel with a legitimate business need. We maintain controls designed to prevent unauthorised access, disclosure, alteration or loss.

We also take measures designed to detect and investigate suspicious activity, unauthorised access and inappropriate use of the Services.

Although we implement appropriate technical and organisational measures, no method of transmission or storage can be guaranteed to be completely secure. You should take reasonable steps to protect your account credentials and notify us promptly if you suspect that your account has been compromised.

Data sharing and sub-processors

We share your information with the following categories of recipients where necessary to provide the Services, comply with legal obligations, protect our rights or otherwise operate our business:

  • hosting, database, authentication and infrastructure providers;
  • payment and subscription providers;
  • email and communications providers;
  • analytics providers;
  • accounting and software integration providers that you choose to connect;
  • verification providers;
  • professional advisers, insurers and auditors where necessary;
  • legal and regulatory authorities where required or permitted by law; and
  • other Paylist users where information has been made available or disclosed in accordance with the functionality and visibility settings described in this Privacy Policy.

We currently use the following principal service providers and sub-processors to deliver the Services: Supabase — hosting, database, authentication and file storage; Stripe — payment processing and subscription management; Resend — transactional email delivery; Umami — cookieless website and product analytics; and Xero, Intuit QuickBooks, Sage and FreeAgent — where you choose to connect them, for accounting integration and contact synchronisation.

We also make API calls to Companies House for verification purposes and to eSortcode for bank-account verification, including confirmation that the account holder name you provide matches the bank's records where the relevant verification service is available. For bank-account verification through eSortcode, we send the sort code, account number and account holder name required for the relevant check.

Where we act as a processor on behalf of a Paylist customer, our processing of that customer's personal data will be governed by the applicable data-processing terms and the customer's documented instructions. Where we act as a controller, we determine the purposes and means of the relevant processing. Where required by applicable law, we enter into appropriate contractual arrangements with processors and sub-processors and require appropriate security and data-protection measures.

We may disclose information to legal and regulatory authorities where required to comply with legal obligations, respond to lawful requests, prevent or investigate fraud or other unlawful activity, or enforce our rights. We may also disclose relevant information in connection with a merger, acquisition, reorganisation, financing or sale of assets, subject to applicable legal and data-protection requirements.

International data transfers

Some of our service providers may process personal data outside the United Kingdom. Stripe and Resend may process data in the European Economic Area and the United States. Our analytics provider, Umami, processes data in the European Economic Area only.

Where personal data is transferred outside the United Kingdom, we ensure that an appropriate transfer mechanism or safeguard is in place where required by applicable law. This may include UK-approved International Data Transfer Agreements, International Data Transfer Addenda, applicable Standard Contractual Clauses with the UK Addendum, or transfers to countries recognised as providing an adequate level of protection.

You may request further information about the safeguards applicable to a particular international transfer by contacting us at hello@mypaylist.com.

Data retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, fulfil legal, accounting and regulatory requirements, resolve disputes, prevent fraud, enforce our agreements and maintain appropriate records of verification and administrative activity. Retention periods depend on the type of information and the purpose for which it is processed.

Indicative retention periods include:

  • Account and business data — retained for the duration of your subscription and thereafter for as long as reasonably necessary for legitimate business, legal, accounting, fraud-prevention or dispute-resolution purposes.
  • Bank-account information — retained while the relevant account is active or otherwise required to provide the Services, and thereafter only for as long as reasonably necessary for applicable legal, accounting, fraud-prevention, dispute-resolution or audit purposes.
  • Verification and audit records — retained for as long as reasonably necessary to demonstrate verification activity, prevent fraud and abuse, investigate disputes and comply with applicable legal or regulatory requirements.
  • OAuth access and refresh tokens — retained while the relevant integration remains connected or while the token is required for the requested functionality, and deleted or invalidated when no longer required, subject to any necessary security or audit requirements.
  • Invitations — retained until accepted, cancelled or expired and thereafter for a reasonable period where necessary to prevent duplicate invitations, investigate abuse or maintain appropriate records.
  • Rejected account data — generally retained for up to 12 months from rejection unless a longer period is reasonably necessary for fraud prevention, dispute resolution, legal obligations or other lawful purposes.
  • Billing and subscription records — retained for the period required by applicable tax and accounting law and for as long as reasonably necessary to resolve billing disputes or enforce contractual rights.
  • Analytics data — retained in accordance with our analytics configuration and, where retained, in aggregated or pseudonymised form designed not to identify individual Paylist accounts.

Where data is no longer required, we will delete it, anonymise it or otherwise securely dispose of it in accordance with our retention and deletion procedures.

Cookies and analytics

We use a limited number of cookies and similar technologies to keep you signed in and maintain your session, remember your preferences and ensure the proper functioning and security of our website and Services. These technologies are strictly necessary where they are required for the operation of the Services and do not require consent where an applicable legal exemption applies.

We use Umami, a privacy-focused analytics service, to understand how the Services are used and how visitors find us. Our current implementation does not use advertising cookies or cross-site advertising tracking.

Umami does not set cookies in our current configuration. It is configured to measure website and product usage without retaining your IP address as part of the analytics record. It may use a temporary identifier derived from technical information such as your IP address and browser configuration to distinguish visits. The analytics data collected is described under "Analytics data" above.

We rely on our legitimate interests in measuring and improving the Services where this processing does not require consent under applicable law. We honour your browser's "Do Not Track" setting where supported by our current implementation. If enabled, no analytics data will be collected through the relevant mechanism.

You may object to analytics processing by contacting us at hello@mypaylist.com, or by blocking the analytics script using your browser or an appropriate extension. The Services are designed to continue to operate without analytics.

We do not use advertising or cross-site tracking technologies. If our use of cookies or similar technologies changes, we will update this Privacy Policy and obtain consent where required by applicable law before using non-essential technologies that require consent. You can also manage cookies through your browser settings, although disabling essential cookies may prevent you from using some parts of the Services.

Your data protection rights

Depending on the circumstances and applicable law, you may have the following rights in relation to your personal data:

  • the right to be informed about how your personal data is used;
  • the right of access, including to request a copy of your personal data;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure, subject to applicable exceptions and retention obligations;
  • the right to restrict processing in certain circumstances;
  • the right to data portability where the legal requirements for that right are met;
  • the right to object to certain processing, including processing based on legitimate interests and direct marketing;
  • the right to withdraw consent where we rely on consent; and
  • rights relating to certain automated decision-making and profiling where applicable.

Some rights are subject to conditions and exceptions under data protection law. To exercise your rights, please contact us at hello@mypaylist.com. We may need to verify your identity before responding to a request. We will respond to valid requests within the timeframes required by applicable law.

Data protection complaints

If you have concerns about how we have collected, used or otherwise handled your personal data, you can contact us at hello@mypaylist.com.

You may also submit a data-protection complaint to us using the contact details above. We will acknowledge and investigate complaints and communicate the outcome in accordance with applicable data protection law.

You also have the right to complain to the Information Commissioner's Office ("ICO"), the UK's independent supervisory authority for data protection. The ICO's website is https://ico.org.uk/. The ICO may be contacted where you believe that your personal data has been handled unlawfully or that your data-protection rights have not been respected.

Third-party links and services

Our website and Services may link to or integrate with third-party websites and services, including Stripe, Xero, QuickBooks, Sage and FreeAgent.

Where you choose to use a third-party service, that service may process your personal data under its own privacy policy and terms. We are not responsible for the independent privacy practices of third parties, and we encourage you to review their privacy policies before using them.

Where a third party processes personal data on our behalf as a processor, we will take appropriate steps to ensure that the processing is governed by appropriate contractual and data-protection requirements.

Children

The Services are intended for use by legally registered businesses and their authorised representatives. They are not directed at children under the age of 18, and we do not knowingly collect personal data directly from individuals under the age of 18 in connection with the Services.

If you believe that a child has provided personal data to us, please contact us at hello@mypaylist.com.

Data security

We take appropriate technical and organisational security measures to protect your data, taking into account the nature of the information we process and the risks associated with its processing.

These measures include encryption of sensitive data in transit and at rest, role-based access controls, the principle of least privilege, secure authentication and session management, monitoring and logging of access to sensitive resources, logging of administrative actions and verification activity, regular security reviews and testing, and controls designed to detect and respond to unauthorised access and other security incidents.

Access to bank-account information is restricted according to the permissions and visibility settings applicable to the relevant account.

We maintain procedures for identifying, investigating and responding to personal-data breaches and other security incidents. Where a personal-data breach is subject to notification requirements under applicable law, we will make the required notifications within the applicable legal timeframes.

You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any suspected unauthorised access or compromise of your account.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our Services, technology, legal requirements or data-processing practices.

Where changes are material, we will take reasonable steps to notify affected users, including by email or through the Services where appropriate. The "Last updated" date at the top of this Privacy Policy will reflect the latest version.

Where required by applicable law, we will seek consent before introducing new processing that requires consent.

Contact us

If you have any questions about this Privacy Policy, our data practices, or wish to exercise any of your data-protection rights or make a data-protection complaint, please contact MYPAYLIST LTD by email at hello@mypaylist.com.

We will handle requests and complaints in accordance with applicable data protection law.