Privacy Policy

Last updated: 1 September 2026

1. Who we are

Guv is a job management app for trade businesses. It is operated by Glebefish Limited, a company registered in England and Wales (company number 14038854), whose registered office is at 1 Johns Road, Woolston, Southampton, SO19 9BW ("we", "us").

For privacy questions, or to exercise any of the rights in section 8, contact us at hello@guvguvguv.com.

2. Two different kinds of people, and who is responsible for their data

This distinction matters, because Guv holds personal data about people who never use the app.

Guv users β€” the business owners, admins and workers who sign in and use the app. For their account data, we are the data controller.

Customers of those businesses β€” the homeowners and clients whose name, address, phone number, email and signature a trade business records against a job. These people do not have Guv accounts and typically never interact with us. For their data, the trade business using Guv is the data controller and we act as a data processor on that business's instructions.

In practice: if you are a customer of a business that uses Guv and you want your data corrected or deleted, please contact that business directly β€” they control it. We will assist them, but we cannot act on their data without their instruction.

3. What we collect

From people who use the app

DataWhy
Email addressSign-in credential and account identifier
PasswordAuthentication. Handled entirely by Google Firebase Authentication; we never see or store it
NameShown to colleagues so jobs and messages are attributable
Phone number (optional)So colleagues can reach you about a job
Your role, and which company you belong toControls what you are allowed to see and do
Notification tokenTo deliver push notifications about your jobs. Tied to your device

About the trade business's customers, entered by its staff

DataWhy
Customer name, phone, emailIdentifying and contacting the customer about the job
Job address, and its map coordinatesLocating the job and providing directions
Signature, and the name of the person signingProof the customer accepted the completed work
Job details, notes and photographsThe record of the work itself

Photographs are taken by workers to document work. They may incidentally show the inside or outside of a customer's property.

Collected automatically

DataWhy
Crash reports β€” error details, device model, operating system versionDiagnosing crashes. Provided by Google Firebase Crashlytics
Usage data β€” which screens are opened, and actions such as creating a job or completing a sign-offUnderstanding which parts of the app are used, and where people get stuck. Provided by Google Analytics for Firebase
An app instance identifierUsed by the above to group events from the same installation. Reset if you reinstall the app
Your user ID, attached to the aboveSo we can diagnose a fault affecting a specific user who reports one

Crash and usage reporting is on by default.

4. What we deliberately do not collect

5. Legal basis for using this data (UK GDPR)

Where we act as a processor (see section 2), the trade business is responsible for establishing its own legal basis for holding its customers' data.

6. Who your data is shared with

Guv is built on Google Firebase, and Google acts as our sub-processor for authentication, database storage, file storage, push notifications, crash reporting and analytics. Google's handling of that data is governed by its own terms.

Data is stored in Google's London (europe-west2) region. Some Google services β€” including crash reporting and analytics β€” may process data outside the UK. Where that happens, it is covered by Google's data transfer safeguards.

Google Analytics data sharing is turned off. Analytics offers a setting that lets Google use the data to improve its own products; enabling it would make Google an independent user of that data rather than a service acting on our instructions. We have disabled it, along with the options that contribute to industry benchmarks and that give Google's sales staff access. The one option we have left on lets Google's technical support staff look at the data when diagnosing a fault.

We also use Resend as a sub-processor to send email on our behalf. When a trade business invites someone to join it on Guv, we pass that person's email address, and the name of the person inviting them, to Resend so the invitation can be delivered. It is used only to send email and for no other purpose. The message itself is sent from Ireland; Resend's own infrastructure is in the United States, covered by standard contractual clauses and the UK Addendum. No job or customer data is sent to Resend.

Two further services support the app without receiving job or customer data:

Anthropic — in use since 3 September 2026. Anthropic Ireland, Limited is on our sub-processor list as of 1 September 2026 for one feature: importing an existing customer list from a spreadsheet, where the column headings and a sample of up to twenty rows are sent so the layout can be worked out. It was listed here, and you were told by email, before it was switched on — which is the point of listing it. Anthropic’s agreement with us states that they may not train models on our data and treats it as confidential. We also read their own supplier list on 1 September 2026 to check nobody reads it by hand — there is no data labelling or human review arrangement on it, which is what would put a person in front of your file. Nothing else in Guv sends data to an AI or machine learning service. What we send is deleted within 30 days — that is Anthropic’s standard period for business customers. We asked them on 1 September 2026 for the arrangement where it is not stored at all, and on 4 September 2026 they declined — they reserve custom retention arrangements for organisations large enough to meet their enterprise criteria, which we are not. So thirty days is the position rather than something pending, and we will ask again if that ever changes. Their agreement with us forbids training on it either way. The one exception, which we cannot switch off: if their automated safety systems flag something, they may keep it for up to two years.

A complete and current list, including what each service handles and where, is published at guvguvguv.com/subprocessors.

We do not share your data with anyone else, except where we are legally required to.

7. How long we keep it

8. Your rights

Under UK data protection law you have the right to: access a copy of your data; have inaccurate data corrected; have your data deleted; restrict or object to how we use it; and receive your data in a portable format.

To exercise any of these, contact hello@guvguvguv.com. We will respond within one month.

If you are a customer of a business that uses Guv, please contact that business β€” see section 2.

You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

Access is controlled by server-enforced security rules, so a business's data can only be read by members of that business. Passwords are handled by Google Firebase Authentication and are never visible to us. Data is encrypted in transit and at rest by Google. Changes to user roles and permissions are recorded in an audit log.

No system is completely secure, and we cannot guarantee absolute security.

10. Children

Guv is a tool for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.

11. Changes to this policy

If we make significant changes we will update the date at the top and, where the change materially affects you, notify you in the app.