Last updated: September 2026
Paylist ("MyPaylist Ltd", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect personal data in connection with our website and subscription-based software services (the "Services"). This policy is intended to comply with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and the Data (Use and Access) Act 2025, as applicable.
MYPAYLIST LTD is a company registered in England and Wales (Company No. 16935308).
For personal data that we process for our own purposes, including to operate, secure, improve and administer the Services, Paylist is the data controller for the purposes of applicable data protection laws.
Depending on how the Services are used, a business or other organisation using Paylist may remain the data controller for personal data that it provides to Paylist for processing on its behalf. In those circumstances, Paylist may act as a data processor. The respective responsibilities of Paylist and the relevant customer will depend on the nature and purpose of the particular processing.
Where Paylist acts as a processor, the processing will be governed by appropriate contractual terms, including our Data Processing Agreement where applicable, and the customer's documented instructions.
If you are a Paylist customer using the Services to process personal data belonging to your customers, suppliers, employees or other individuals, you remain responsible for ensuring that you have an appropriate lawful basis and authority to provide that information to us and to use the Services for that purpose.
We have not appointed a statutory Data Protection Officer. Questions about this Privacy Policy, our data practices or your rights should be directed to hello@mypaylist.com.
Legal business name, trading name, business type, company registration number, registered and trading address, declared turnover and turnover band, business logo and any public profile information you choose to display, such as public email and phone number.
We also store data returned from Companies House in response to company-number verification checks, including officer details, registered office address, SIC codes and company status.
Some information relating to a company may not constitute personal data where it relates solely to a legal entity. However, information relating to individuals, including sole traders, company officers and business contacts, may constitute personal data and will be handled in accordance with applicable data protection law.
Bank account details including account name, sort code, account number, IBAN and BIC/SWIFT. Each verified bank account is assigned a unique "Paylist number".
We also store transaction and accounting data you submit or that is synchronised through supported integrations, and billing and subscription information, including Stripe customer ID, subscription status and billing period dates.
Bank account information may constitute personal data where it relates to an identifiable individual, including in the case of sole traders or other individuals conducting business activities.
We treat bank account information as confidential financial information and apply appropriate technical and organisational measures to protect it.
Names, email addresses, phone numbers, job titles and postal addresses of authorised users, company officers, authorised signatories and business contacts. Identification information where required for verification purposes.
When you invite contacts to join Paylist, we collect and store the invitee's email address, business name and any custom message you choose to include, in order to deliver the invitation and track its status.
Our lawful basis for processing invitee data is our legitimate interest in facilitating the invitation you have asked us to send. We may also process the invitee's information where necessary to comply with a legal obligation.
Invitees may contact us at any time to ask questions about their data or to exercise applicable data protection rights.
You may provide Paylist with personal information relating to other individuals, such as customers, suppliers, employees, company officers, authorised signatories, business contacts or payment contacts.
Where you provide personal data about another individual, you are responsible for ensuring that you are entitled to provide that information to us and, where required, that the individual has been provided with appropriate privacy information.
We may also receive personal data indirectly from sources including Paylist customers, accounting software platforms, Companies House, bank-account verification providers and other Paylist users.
Where we obtain personal data from another source, we will provide the information required by applicable data protection law unless an applicable legal exception applies.
OAuth access and refresh tokens for connected third-party accounting platforms, including Xero, QuickBooks, Sage and FreeAgent, stored encrypted, and contact records synchronised between Paylist and those platforms at your direction.
We use integration data only to provide, maintain and secure the integration and to perform the synchronisation or other functionality you have requested, subject to any other processing described in this Privacy Policy.
IP address, browser type, device information, usage data relating to how you interact with our Services, authentication session information and other technical information required to operate, secure and maintain the Services.
Aggregated, cookieless measurement data about how the Services are used: pages viewed, referring website, browser, operating system, device type, screen size, language and country.
We also record a small number of product events — for example that a directory search was run, an invitation was sent, or an accounting integration was connected — as counts and categories only.
Analytics events are designed not to include your name, email address, business name, search terms, Paylist numbers or bank details. See "Cookies and analytics" below.
Records of verification checks performed, including company number, officer confirmation, bank-account checks (Confirmation of Payee and modulus checks) and administrator review, together with the requests made, responses received and outcomes.
These records may include information obtained from Companies House, bank-account verification providers and other verification sources.
Verification and audit records are retained where necessary to demonstrate the integrity of our verification processes, prevent fraud and abuse, investigate disputes and comply with applicable legal or regulatory obligations.
Information collected via cookies and similar technologies. See "Cookies and analytics" below.
We use your data to:
We do not use bank account details to initiate payments or move money from or to a bank account unless a separate Paylist service expressly provides for this functionality and you have authorised the relevant transaction.
We rely on the following legal bases under UK GDPR, depending on the particular processing activity:
Contractual necessity — to create and administer your account, provide the Services you have subscribed to, store and manage information necessary to provide the Services, perform requested integrations and provide functionality such as verification and bank-account management.
Legal obligation — where processing is necessary for us to comply with a legal or regulatory obligation applicable to us, including applicable accounting, tax, fraud-prevention, record-keeping or other legal requirements.
Legitimate interests — where processing is necessary for our legitimate interests, or those of a third party, and those interests are not overridden by your interests or fundamental rights and freedoms. This may include operating and securing the Services, preventing fraud and abuse, maintaining audit records, improving our Services, facilitating invitations requested by users, defending legal claims and maintaining the integrity of our verification and directory services.
Consent — where you actively choose to permit a particular use of your personal data and consent is the appropriate lawful basis.
In particular, where you change your bank-account visibility setting from the default Private setting to Public, you are actively choosing to make your full bank account number and sort code available to authenticated Paylist users, without a further approval step, for the specific purpose of enabling them to obtain payment details for your business.
Where the bank-account information constitutes personal data, we rely on your consent under Article 6(1)(a) UK GDPR for this disclosure. The action of changing the setting from Private to Public is a clear affirmative action indicating your agreement to the specified processing and disclosure.
You may withdraw this consent at any time by changing your bank-account visibility setting back to Private. Withdrawal of consent does not affect the lawfulness of any processing or disclosure that took place before your consent was withdrawn.
Under the default Private setting, you consent to Paylist processing your bank-account information for the purpose of managing access requests, and displaying masked bank details to authenticated Paylist users so that your business can be identified. Full bank details will only be disclosed to another authenticated Paylist user where you actively approve that particular request.
We will maintain records of consent where required, including the relevant account or user, the date and time consent was given, the setting selected and the version of the information presented to you at the time of consent.
Where we rely on legitimate interests, we consider the nature of the processing, its impact on individuals and whether their interests, rights and freedoms are adequately protected. You may object to processing based on legitimate interests where the law gives you that right.
You may withdraw consent at any time where we rely on consent.
We use automated checks to verify business and banking information, including company number verification against Companies House, bank-account verification (Confirmation of Payee and modulus checks) and automated eligibility or plan-assignment logic based on declared turnover.
These automated checks do not, on their own, produce legal or similarly significant effects without appropriate human involvement. Final approval or rejection of a business account is reviewed by a member of the Paylist administration team.
Where an automated check produces an outcome that affects your account, you may contact us to request information about the outcome and, where applicable, request human intervention or challenge the decision.
Where applicable law provides additional rights in relation to solely automated decision-making, we will provide those rights and safeguards.
A core feature of Paylist is the ability for verified businesses to be discoverable by other authenticated users.
Once your business is verified, your public profile may include your business name, trading name, city, postcode, logo, public contact details and other information that you choose to make available through the Services. This information may be visible to authenticated Paylist users in the Paylist directory.
A single visibility setting applies to all bank accounts held by your business. The default setting is Private. You may actively change the setting to one of the following:
Private (default) — your business remains listed in the Paylist directory and authenticated Paylist users can see masked bank details, including the account name, bank name, sort code last two digits and account number last four digits. Your full sort code and account number are not disclosed unless you actively approve an access request from a specific user. By using the Services with this setting, you consent to Paylist processing your bank-account information for the purpose of managing those access requests. Each disclosure of full bank details requires your approval through the Services.
Public — masked bank details remain visible to authenticated Paylist users as above, and your full bank account number and sort code may be disclosed to any authenticated Paylist user who uses the relevant Paylist functionality to save your business as a payee or otherwise obtain the full payment details, without a further approval step. By changing your setting from Private to Public, you actively consent, where the information constitutes personal data, to Paylist making those full details available for the specific purpose of enabling other users to obtain payment details for your business.
Your Paylist number is a public identifier associated with your verified bank account and may be visible to authenticated Paylist users.
The purpose of this functionality is to allow businesses using Paylist to identify verified businesses and obtain payment information in accordance with the visibility setting selected by the bank-account owner.
You may change your visibility setting at any time from your account settings. Where you have consented to Public visibility, changing the setting back to Private withdraws your consent to the further disclosure of full bank details without your approval. Masked details remain visible under either setting.
Changes will apply to future discovery and disclosure. A change in visibility cannot retrieve or delete information that another user has already viewed, downloaded, recorded or otherwise obtained before the change, and does not withdraw access from a user whose access request you have already approved. You may withdraw a previously approved access request at any time from your account settings. You should therefore only select Public or approve an access request where you are comfortable with the corresponding disclosure of your bank-account information.
Paylist does not control how another Paylist user may use information after it has been legitimately disclosed to that user. Users must comply with applicable law and their own data-protection obligations when handling information obtained through Paylist.
We may restrict, suspend or remove access to bank-account information where we reasonably believe that an account, access request or disclosure presents a security, fraud or data-protection risk.
Due to the nature of our Services, we process confidential financial information, including bank-account details.
Bank account details are not treated as special-category personal data merely because they are financial information. However, we recognise that such information is confidential and may create significant risks if improperly accessed or disclosed.
We implement appropriate technical and organisational measures to protect this information, including encryption of sort codes, account numbers and IBANs at rest using industry-standard encryption, encryption of integration OAuth tokens at rest, encryption of data in transit using TLS, role-based access controls, least-privilege access, authentication and session management, and logging of administrative actions and verification events for auditing.
Where technically appropriate, access to sensitive information is restricted to authorised users and personnel with a legitimate business need. We maintain controls designed to prevent unauthorised access, disclosure, alteration or loss.
We also take measures designed to detect and investigate suspicious activity, unauthorised access and inappropriate use of the Services.
Although we implement appropriate technical and organisational measures, no method of transmission or storage can be guaranteed to be completely secure. You should take reasonable steps to protect your account credentials and notify us promptly if you suspect that your account has been compromised.
We share your information with the following categories of recipients where necessary to provide the Services, comply with legal obligations, protect our rights or otherwise operate our business:
We currently use the following principal service providers and sub-processors to deliver the Services: Supabase — hosting, database, authentication and file storage; Stripe — payment processing and subscription management; Resend — transactional email delivery; Umami — cookieless website and product analytics; and Xero, Intuit QuickBooks, Sage and FreeAgent — where you choose to connect them, for accounting integration and contact synchronisation.
We also make API calls to Companies House for verification purposes and to eSortcode for bank-account verification, including confirmation that the account holder name you provide matches the bank's records where the relevant verification service is available. For bank-account verification through eSortcode, we send the sort code, account number and account holder name required for the relevant check.
Where we act as a processor on behalf of a Paylist customer, our processing of that customer's personal data will be governed by the applicable data-processing terms and the customer's documented instructions. Where we act as a controller, we determine the purposes and means of the relevant processing. Where required by applicable law, we enter into appropriate contractual arrangements with processors and sub-processors and require appropriate security and data-protection measures.
We may disclose information to legal and regulatory authorities where required to comply with legal obligations, respond to lawful requests, prevent or investigate fraud or other unlawful activity, or enforce our rights. We may also disclose relevant information in connection with a merger, acquisition, reorganisation, financing or sale of assets, subject to applicable legal and data-protection requirements.
Some of our service providers may process personal data outside the United Kingdom. Stripe and Resend may process data in the European Economic Area and the United States. Our analytics provider, Umami, processes data in the European Economic Area only.
Where personal data is transferred outside the United Kingdom, we ensure that an appropriate transfer mechanism or safeguard is in place where required by applicable law. This may include UK-approved International Data Transfer Agreements, International Data Transfer Addenda, applicable Standard Contractual Clauses with the UK Addendum, or transfers to countries recognised as providing an adequate level of protection.
You may request further information about the safeguards applicable to a particular international transfer by contacting us at hello@mypaylist.com.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, fulfil legal, accounting and regulatory requirements, resolve disputes, prevent fraud, enforce our agreements and maintain appropriate records of verification and administrative activity. Retention periods depend on the type of information and the purpose for which it is processed.
Indicative retention periods include:
Where data is no longer required, we will delete it, anonymise it or otherwise securely dispose of it in accordance with our retention and deletion procedures.
We use a limited number of cookies and similar technologies to keep you signed in and maintain your session, remember your preferences and ensure the proper functioning and security of our website and Services. These technologies are strictly necessary where they are required for the operation of the Services and do not require consent where an applicable legal exemption applies.
We use Umami, a privacy-focused analytics service, to understand how the Services are used and how visitors find us. Our current implementation does not use advertising cookies or cross-site advertising tracking.
Umami does not set cookies in our current configuration. It is configured to measure website and product usage without retaining your IP address as part of the analytics record. It may use a temporary identifier derived from technical information such as your IP address and browser configuration to distinguish visits. The analytics data collected is described under "Analytics data" above.
We rely on our legitimate interests in measuring and improving the Services where this processing does not require consent under applicable law. We honour your browser's "Do Not Track" setting where supported by our current implementation. If enabled, no analytics data will be collected through the relevant mechanism.
You may object to analytics processing by contacting us at hello@mypaylist.com, or by blocking the analytics script using your browser or an appropriate extension. The Services are designed to continue to operate without analytics.
We do not use advertising or cross-site tracking technologies. If our use of cookies or similar technologies changes, we will update this Privacy Policy and obtain consent where required by applicable law before using non-essential technologies that require consent. You can also manage cookies through your browser settings, although disabling essential cookies may prevent you from using some parts of the Services.
Depending on the circumstances and applicable law, you may have the following rights in relation to your personal data:
Some rights are subject to conditions and exceptions under data protection law. To exercise your rights, please contact us at hello@mypaylist.com. We may need to verify your identity before responding to a request. We will respond to valid requests within the timeframes required by applicable law.
If you have concerns about how we have collected, used or otherwise handled your personal data, you can contact us at hello@mypaylist.com.
You may also submit a data-protection complaint to us using the contact details above. We will acknowledge and investigate complaints and communicate the outcome in accordance with applicable data protection law.
You also have the right to complain to the Information Commissioner's Office ("ICO"), the UK's independent supervisory authority for data protection. The ICO's website is https://ico.org.uk/. The ICO may be contacted where you believe that your personal data has been handled unlawfully or that your data-protection rights have not been respected.
Our website and Services may link to or integrate with third-party websites and services, including Stripe, Xero, QuickBooks, Sage and FreeAgent.
Where you choose to use a third-party service, that service may process your personal data under its own privacy policy and terms. We are not responsible for the independent privacy practices of third parties, and we encourage you to review their privacy policies before using them.
Where a third party processes personal data on our behalf as a processor, we will take appropriate steps to ensure that the processing is governed by appropriate contractual and data-protection requirements.
The Services are intended for use by legally registered businesses and their authorised representatives. They are not directed at children under the age of 18, and we do not knowingly collect personal data directly from individuals under the age of 18 in connection with the Services.
If you believe that a child has provided personal data to us, please contact us at hello@mypaylist.com.
We take appropriate technical and organisational security measures to protect your data, taking into account the nature of the information we process and the risks associated with its processing.
These measures include encryption of sensitive data in transit and at rest, role-based access controls, the principle of least privilege, secure authentication and session management, monitoring and logging of access to sensitive resources, logging of administrative actions and verification activity, regular security reviews and testing, and controls designed to detect and respond to unauthorised access and other security incidents.
Access to bank-account information is restricted according to the permissions and visibility settings applicable to the relevant account.
We maintain procedures for identifying, investigating and responding to personal-data breaches and other security incidents. Where a personal-data breach is subject to notification requirements under applicable law, we will make the required notifications within the applicable legal timeframes.
You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any suspected unauthorised access or compromise of your account.
We may update this Privacy Policy from time to time to reflect changes to our Services, technology, legal requirements or data-processing practices.
Where changes are material, we will take reasonable steps to notify affected users, including by email or through the Services where appropriate. The "Last updated" date at the top of this Privacy Policy will reflect the latest version.
Where required by applicable law, we will seek consent before introducing new processing that requires consent.
If you have any questions about this Privacy Policy, our data practices, or wish to exercise any of your data-protection rights or make a data-protection complaint, please contact MYPAYLIST LTD by email at hello@mypaylist.com.
We will handle requests and complaints in accordance with applicable data protection law.