Privacy Policy
PRIVACY POLICY
Last update: 16 September 2026
(c) Fort Technologies Ltd
This Privacy Policy explains how Fort Technologies Ltd ("Fort", "we", "us", "our") collects, uses, stores, and shares personal data when you use the Fort mobile application, our services, and (where applicable) our website at fort-app.com.
By using Fort, you agree to the collection and use of information in accordance with this Privacy Policy.
Trade businesses on Fort appear in the product interface as Tradesperson or Tradespeople. This Privacy Policy uses Trade Business for the same account type.
1. WHO THIS POLICY APPLIES TO
This policy applies to:
- homeowners and other clients using Fort to find and hire trade businesses;
- trade businesses, sole traders, subcontractors, and company officers or executives registering on Fort;
- visitors to our website where website-specific processing is described;
- anyone who contacts us or interacts with Fort support; and
- individuals whose personal data appears in UK planning application records that we obtain from public sources, where we use that information for internal business development and service planning, even if they do not have a Fort account.
2. DATA CONTROLLER
Fort Technologies Ltd is the data controller for personal data described in this policy.
Contact: fort@fort-app.com
Registered address: 56 Oakway, Woking, England, GU21 8TR
3. CATEGORIES OF PERSONAL DATA WE COLLECT
We may collect and process the following categories of personal data:
3.1 Identity and contact data
Name, email address, telephone number, postal address, postcode, date of birth (where required for trade onboarding), profile photograph, company name, and company registration details.
3.2 Account and authentication data
Username, hashed password, Firebase user identifier, SMS one-time passcodes (OTP), device type, and push notification tokens.
3.3 Trade business and verification data
Trade category, bio, portfolio images, company URL, Companies House number, VAT registration status, VAT number (where provided), preferred VAT pricing mode (inclusive or exclusive), incorporation and trading dates, ownership percentages, executive and owner details, references, CSCS and CIS certificates, insurance documents, qualifications, and other documents you submit for Fort verification.
3.4 Vetting and compliance data
Results of our trade business vetting programme (see section 6), including proof of address, CCJ and financial history information, company history, open-source research findings, insurance validation outcomes, customer experience references, duplicate-business checks, director checks, and encrypted evidence documents uploaded by Fort administrators.
3.5 Payment and financial data
Payment amounts, milestone or stage payment metadata, Stripe payment and payout identifiers, bank account details submitted via Stripe Connect, government-issued identity documents collected during Stripe Connect payment setup, platform fee information, Trade Business upfront Service Fee discount payments (amount, tier, payment identifiers, and status), and, where VAT applies, milestone net, VAT, and gross amounts used for charging and document generation. Fort does not store full card or bank credentials; payment processing is handled by Stripe.
3.6 Project and marketplace data
Project descriptions, job locations, project address line 1 (collected when you create a project but not shown publicly on listings), verified postcodes, town or locality labels shown on public listings, images, quotes, contracts, milestone status, variation orders, milestone completion evidence, reviews and ratings (where available), dispute-related text and images, and other material documents or information pertaining to a project (including, without limitation, the categories listed in our Terms and Conditions, clause 5.22(a)). Where you use Fort, we expect material project records to be maintained on the Platform to the extent the app provides functionality for doing so.
3.7 Communications data
In-app messages, chat attachments, email correspondence, SMS messages (including OTP), and push notification content.
3.8 Technical and usage data
IP address used transiently for security or approximate location lookup, device information, session data, audit logs, admin activity logs, and aggregated internal analytics derived from our databases. Where we use IP-based website analytics, we discard the raw IP address after deriving coarse location data and do not use it to identify returning visitors across days.
3.9 Location data
Postcode, geocoded coordinates, service region assignment, and project or job location for marketplace matching. When you create a project, we collect your project address line 1 and verified postcode for operational and safety purposes. We share the full project address with the company on your project where it appears on invoices, receipts, and variation orders. Public listings display only the town or locality derived from your postcode, not your address line 1. Real-time device location when the Fort app is open (and, where you grant permission, in the background) to improve local search and service matching.
3.10 Marketing preferences
If you opt in to receive marketing communications, we will record your preference. Marketing SMS and promotional campaigns are planned until preference storage and campaign tooling are fully enabled.
3.11 Website analytics data
On fort-app.com, we use first-party, cookieless analytics to measure page views, referral sources, campaign parameters, device/browser type, and approximate location (country, region, and city/town) derived from IP address at the time of the request using offline or edge geolocation. We do not store the raw IP address for these analytics after the location lookup is completed, we do not send visitor IP addresses to third-party geolocation APIs for website analytics, and we do not use cookies or local storage identifiers for website analytics. The native Fort mobile app does not use browser cookies.
3.12 Planning application data
We collect and store information about UK planning applications from public sources, including the UK Planning Data service (planning.data.gov.uk) and, where enabled, local planning authority public registers. This may include application reference, site address, development description, application type and status, decision or submission dates, map coordinates, and a link to the public register entry. We do not intentionally collect applicant names, email addresses, or telephone numbers through our planning ingestion service. We may use this information to identify properties where renovation or construction work may be required and to support Fort's internal marketplace planning and service development. We do not use planning application data to send marketing emails, SMS messages, or make marketing telephone calls.
4. HOW WE COLLECT PERSONAL DATA
We collect personal data when you:
- register for an account or complete onboarding;
- submit verification documents or complete vetting steps;
- create projects, request quotes, enter contracts, or make milestone payments;
- send messages through Fort;
- raise or participate in a dispute;
- contact support;
- use our website (where applicable);
- interact with Fort administrators during verification or safety review; and
- where Fort automatically syncs UK planning application records into our Fort-Planning service for review by Fort administrators through our internal admin tools.
We also collect data from third-party sources where permitted, including Companies House, TrustOnline (the official Register of Judgments, Orders and Fines, operated by Registry Trust), postcodes.io (for postcode and region lookup), open-source and public register research during vetting, Stripe (for identity verification and payments), and public UK planning registers, including the Planning Data API at planning.data.gov.uk and local authority planning portals.
5. PURPOSES AND LEGAL BASES FOR PROCESSING
We process personal data for the following purposes:
| Purpose | Data involved | Legal basis |
|---|---|---|
| Account registration and login | Identity, contact, auth, device token | Contract; legitimate interests (security) |
| Phone verification (SMS OTP) | Phone number, OTP | Contract; legitimate interests (fraud prevention) |
| Service region and matching | Postcode, region, project location | Contract; legitimate interests |
| Trade business onboarding | Company, owner, executive, sole trader data | Contract; legal obligation (where AML/KYC applies); legitimate interests |
| Fort verification documents | References, CSCS, CIS, insurance, qualifications | Contract; legitimate interests (platform safety) |
| 13-point admin vetting programme | Vetting data (section 6) | Legitimate interests (fraud prevention, platform safety); legal obligation where applicable |
| Stripe Connect verification | Government ID during payment setup (via Stripe) | Contract; legal obligation (where applicable) |
| Stripe Connect and milestone payments | Payment, bank, payout data | Contract; legal obligation |
| VAT invoicing and milestone pricing | VAT registration status, VAT number, VAT pricing mode, net/VAT/gross milestone amounts | Contract; legal obligation (where tax invoice particulars apply); legitimate interests (accurate payment documents) |
| Service Fee discount promotion | Upfront payment amount, tier, Stripe payment metadata | Contract; legitimate interests |
| Marketplace and projects | Project, quote, contract, variation, milestone, review data | Contract |
| Platform records (clause 5.22) | Accepted quotes, contracts, variations, milestone evidence, project communications and uploads | Contract; legitimate interests (dispute resolution, platform safety) |
| Planning application ingestion and review | Application reference, address, description, status, dates, coordinates, source URL | Legitimate interests (operational business intelligence, service development) |
| Business development (planning data) | Site address and planning details relating to identifiable properties | Legitimate interests |
| Messaging | Message content, attachments, metadata | Contract; legitimate interests (safety, disputes) |
| Notifications (push, email, SMS) | Contact details, notification content | Contract; consent (marketing); legitimate interests (service messages) |
| Dispute resolution | Dispute text, images, project data, Platform records | Contract; legitimate interests |
| Admin safety and fraud review | User data, decrypted chat (where necessary), vetting records | Legitimate interests; legal obligation |
| Internal analytics | Aggregated SQL metrics (internal only) | Legitimate interests |
| Website analytics | Page URL, referrer, campaign parameters, device/browser type, approximate location, aggregated event data | Legitimate interests |
| Hosting and infrastructure | Technical logs, stored files | Contract; legitimate interests |
6. TRADE BUSINESS ONBOARDING AND VETTING
6.1 Onboarding pipeline
Trade businesses complete a multi-stage onboarding process:
- company or sole trader account registration;
- profile setup (bio, trade category, images);
- for limited companies: owners and executives (including date of birth, address, ownership percentage, and email verification);
- for sole traders: personal KYC information;
- submission of Fort verification documents (references, CSCS, CIS, and related materials), stored encrypted on our servers;
- our 13-point Fort admin verification programme (below);
- Stripe Connect payment setup (government-issued ID collected by Stripe during payout onboarding); and
- Stripe Connect onboarding (bank account details and optional identity documents, processed by Stripe).
Typical vetting turnaround is approximately four to five working days after required documents are submitted, subject to complexity.
6.2 Our trade business vetting process
Fort personnel (not automated third-party credit bureaus alone) perform the following checks as part of our admin verification programme. Results, findings, and supporting evidence documents are stored encrypted and used to decide whether a trade business may use the platform.
- Proof of Address
- Qualifications
- Open Source Check (public internet and open-source research on the business or relevant individuals)
- Personal CCJ Checks (via TrustOnline, the official Register of Judgments, Orders and Fines operated by Registry Trust)
- Business CCJ Check (via TrustOnline)
- Company History Check (including Companies House and corporate records)
- Financial History
- Financial Checks
- Duplicate Checks
- Enhanced Business Check
- Director Check
- Customer Experience (references and track record)
- Insurance Validation
After these admin checks are complete, contractors set up their payment account via Stripe Connect. Stripe collects government-issued identification and other payout requirements on Stripe-hosted infrastructure as part of Connect onboarding.
We may use public registers, submitted documents, references, insurance records, financial distress information (such as CCJs), and open-source research. Personal and Business CCJ checks are searches of TrustOnline (Registry Trust). We may request the information reasonably required to run those searches, including full legal name, previous names or aliases, current and previous addresses, company name, trading style, and registered office or trading address. Date of birth already collected for owner or sole-trader onboarding may be used to match register results where a date of birth appears on the Register. We do not describe this as automated "credit bureau" screening; TrustOnline is the official statutory judgments register, not a credit-reference agency, and a search does not leave a credit-file footprint. Vetting is Fort-administered.
7. PLANNING APPLICATION DATA
7.1 What we collect
Our Fort-Planning service ingests publicly available planning application records for selected local planning authorities (currently including Elmbridge, Woking, Guildford, Mole Valley, and Kingston upon Thames, and others we may add). Data is obtained primarily from the UK government's Planning Data API and, where necessary and enabled, from council public planning portals.
7.2 How we use it
Fort administrators use this data internally to monitor ingestion, assess coverage, develop marketplace features, and plan Fort's services.
We do not use planning application data for electronic marketing. In particular, we do not send marketing emails, SMS messages, or make marketing telephone calls based on planning application data.
7.3 Legal basis
We rely on legitimate interests (Article 6(1)(f) UK GDPR) to ingest and analyse public planning data for internal business intelligence and service development, balanced against the rights of individuals identified from that data.
7.4 Who can access it
Authorised Fort administrators only, via our admin panel. Planning data is stored in our Fort-Planning service database and is not shown to homeowners or trade businesses in the Fort mobile app today.
7.5 Public sources and licences
Planning data obtained from planning.data.gov.uk is subject to the Open Government Licence where applicable. Council portal data is taken from publicly accessible registers. We respect rate limits and terms of use of those sources.
7.6 Retention
We retain planning application records for up to 24 months after our last update to the record, then delete or anonymise them, unless a live customer relationship exists or a longer period is required by law.
7.7 Your rights
If you believe your property or project appears in our planning data, you may contact us at fort@fort-app.com to request access, correction, erasure, or to object to processing based on legitimate interests. You may also complain to the ICO.
8. PAYMENTS
8.1 Milestone stage payments
Fort facilitates milestone-based stage payments between homeowners and trade businesses using Stripe, including Pay-by-Bank and Stripe Connect. Payment data (amounts, stage metadata, payment intent and payout identifiers) is processed by Stripe. Fort may charge a platform fee via Stripe application fees.
Funds are credited to the trade business's Stripe connected account when the homeowner pays for a stage, and paid out to their bank when the milestone is approved on the Platform. Fort does not provide escrow services. Payment receipts and invoices may be generated as PDF documents. Where a trade business has told us it is VAT-registered, invoices and receipts may include its VAT number and a breakdown of net, VAT, and gross amounts for the relevant milestone payment.
8.2 What we do not store
Fort does not store your full payment card or bank account credentials. Stripe processes payment and identity data under its own privacy policy and terms.
8.3 Service Fee discount upfront payments
Trade Businesses may pay an upfront amount to activate a reduced Service Fee tier under our Terms and Conditions (clause 8.14). These payments are processed by Stripe (Pay-by-Bank) directly to Fort and are separate from Milestone Works Fee payments.
9. MESSAGING
9.1 In-app chat
Messages sent through Fort are stored on Fort servers. Message content is encrypted at rest. Chat attachments are stored in encrypted file storage. Thread metadata (participants, timestamps) is retained to operate the service.
9.2 Admin review
Fort administrators may access message content (including decrypted messages where necessary) for platform safety, fraud prevention, vetting, and dispute resolution.
10. NOTIFICATIONS
We send notifications through:
- push notifications via Firebase Cloud Messaging (FCM);
- transactional email via Brevo (SMTP relay);
- SMS via PureSMS (including OTP codes); and
- in-app notification records.
Marketing SMS and promotional email where you have opted in, once preference storage and campaigns are fully enabled.
11. LOCATION DATA
11.1 Current processing
We use your postcode, geocoded coordinates, and assigned service region (via postcodes.io and internal region logic) to match you with relevant trade businesses and projects. When you create a project, we store your project address line 1 for our records, operational use, and safety. We share the full project address with the company on your project on invoices, receipts, and variation orders. We show only the town or locality on public marketplace listings. Project and job location data is also used for marketplace listings and quotes.
11.2 Planned processing
We may collect real-time device location when the Fort app is open, and where you grant permission, while the app runs in the background, to improve local search and service delivery. We will update this policy and request appropriate permissions before enabling this feature.
12. DEVICE AND LOCAL STORAGE
12.1 Mobile app
The Fort app uses local storage (including secure storage and SharedPreferences) for session data, notification preferences, and signup draft data. This data remains on your device unless synchronised with our servers as part of normal app operation.
12.2 Biometric unlock
Where supported, you may use on-device biometric authentication (such as fingerprint or face recognition) to authorise certain payment actions. Biometric data is processed only on your device and is not transmitted to Fort.
13. HOSTING AND INFRASTRUCTURE
13.1 Current
Application servers, databases, and related infrastructure for Fort (including the Fort API, website, planning tooling, and website analytics storage) are hosted on Railway in the European Union. Personal data in our MySQL databases (including application data and, where used, a separate operations database) is stored on Railway-managed MySQL in the EU. Uploaded files are stored in our application file storage; sensitive verification and vetting documents are encrypted where noted in our systems. We use Redis for chat pub/sub and related real-time messaging infrastructure. Cloudflare provides DNS, content delivery, bot and form protection (including Turnstile where enabled), and inbound email routing for Fort domains.
13.2 Planned or alternative infrastructure
We may migrate or expand hosting to other cloud providers such as Amazon Web Services (AWS). We will update this policy when material changes occur.
14. OUR DISCLOSURES - SUBPROCESSORS AND THIRD PARTIES
We share personal data with the following categories of recipients where necessary to provide our services:
14.1 Subprocessors and service providers - live today
- Railway - cloud hosting for application servers, MySQL databases, Redis, and related Fort infrastructure (workloads deployed in the European Union) - Cloudflare - DNS, CDN, bot and form protection (Turnstile where enabled), and inbound email routing - Stripe - payments, Stripe Connect, Pay-by-Bank - Google (Firebase) - authentication and push notifications (FCM) - Brevo - transactional email delivery - PureSMS - SMS OTP and service messages - Companies House - company lookup and verification - Registry Trust (TrustOnline) - official Register of Judgments, Orders and Fines (CCJ and related register searches during trade vetting) - postcodes.io - postcode geocoding and region lookup
14.2 Planned subprocessors
- Amazon Web Services (AWS) - alternative or additional cloud hosting
14.3 Other disclosures
- Trade businesses receive relevant homeowner contact and project information when you engage them through Fort. - Where a VAT invoice or receipt is generated, the trade business's VAT number and related VAT amounts may be shown to the homeowner (and retained on the project document record) as part of that payment document. - Surveyors or other third parties may be involved in dispute resolution where applicable. - Fort administrators and authorised staff access user data, verification documents, and (where necessary) messages for vetting, safety, and support. - Planning application data is obtained from public UK government and council sources; those bodies are data sources, not Fort subprocessors. Fort-Planning runs on Fort-controlled infrastructure. - We may disclose data where required by law, regulation, court order, or to protect rights, safety, and security.
We require processors to protect personal data under appropriate contractual terms.
15. WEBSITE COOKIES AND ANALYTICS
This section applies to fort-app.com and related web properties, not the native Fort mobile app.
15.1 Cookies
When you use fort-app.com, we may use essential cookies or similar browser storage only where needed for core site behaviour, security, fraud prevention, or form protection (including Cloudflare Turnstile where enabled). Our website analytics implementation does not rely on cookies or local storage identifiers. Further detail is set out in our Cookie Policy.
15.2 First-party website analytics
We use a first-party, cookieless analytics service on fort-app.com to understand how visitors use the site and to improve content, navigation, and launch performance. The analytics records page views and selected events (for example sign-up or contact-form submissions), together with referral source, campaign parameters, browser/device information, and approximate country, region, and city/town. We derive approximate location from the incoming IP address using offline or edge geolocation (for example CDN geo headers and an offline IP database on Fort infrastructure) and then discard the raw IP address after lookup. We do not send visitor IP addresses to third-party geolocation APIs for website analytics. We do not use this analytics service for cross-site advertising profiles or behavioural advertising. We do not sell website analytics data, and we do not share, license, or distribute website analytics data to advertising networks, data brokers, or other marketing or analytics partners.
15.3 Advertising technologies
If we later enable optional advertising pixels or similar marketing technologies on fort-app.com, we will update this policy and request consent where required.
16. INTERNATIONAL DATA TRANSFERS
Some of our subprocessors may process personal data outside the United Kingdom. In particular:
- Railway application and database workloads for Fort are deployed in the European Union. Railway is a United States company, so limited platform/control-plane processing may still involve the United States. - Cloudflare may process technical and security-related data in the United Kingdom, the EEA, the United States, and other locations as required to provide its network services. - Stripe and Google/Firebase may process personal data in the United States and other countries. - Brevo primarily processes email-related data in the European Economic Area, but may use further subprocessors that involve international transfers. - PureSMS primarily processes SMS-related data in the United Kingdom and/or the EEA, as described in its terms.
Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including UK adequacy regulations where applicable, the UK/EU–US Data Privacy Framework where a recipient is certified, and Standard Contractual Clauses or equivalent mechanisms approved under UK GDPR.
17. DATA RETENTION
We retain personal data for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type:
- Account data: for the life of your account and a reasonable period thereafter - Platform records (quotes, contracts, variations, milestone evidence, project communications): for the duration of active projects and a reasonable period thereafter for disputes, safety, and legal compliance - Planning application data: 24 months after last record update, unless anonymised sooner, a live customer relationship exists, or a longer period is required by law - Website analytics events and sessions: typically up to 24 months, after which they are deleted or retained only in aggregated or anonymised form - Vetting and verification documents: for the duration of your relationship with Fort and as required for compliance and dispute resolution - Payment records: as required by tax, accounting, and financial regulations - Messages: for the duration of active projects and a reasonable period thereafter for disputes and safety
We may anonymise or aggregate data for analytics and retain it longer in non-identifiable form.
18. YOUR RIGHTS
Under UK data protection law, you have rights including:
- access to your personal data;
- rectification of inaccurate data;
- erasure in certain circumstances;
- restriction of processing;
- data portability where applicable;
- objection to processing based on legitimate interests; and
- withdrawal of consent where processing is based on consent.
If you have a Fort account, you can request erasure from within the Fort app: open Settings, then Privacy & Support, then Delete account. We review deletion requests (including for open projects, disputes, or unsettled payments) and aim to complete approved deletions within 30 days. You will receive confirmation by email when your request is completed or if it cannot be approved. You can cancel a pending request from the same Settings screen.
You may also contact fort@fort-app.com to exercise your rights. If we hold your data from public planning records but you are not a Fort user, you have the same rights above. You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
19. SECURITY
We implement technical and organisational measures to protect personal data, including encryption of sensitive verification and vetting documents, encrypted chat content at rest, access controls for administrators, and secure authentication. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
20. CHILDREN
Fort is not intended for users under 18. We do not knowingly collect personal data from children.
21. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The "Last update" date at the top indicates when it was last revised. Material changes will be communicated through the app or other appropriate channels.
22. CONTACT US
Fort Technologies Ltd 56 Oakway, Woking, England, GU21 8TR Email: fort@fort-app.com
For questions about this Privacy Policy or our processing of your personal data, please contact us at the email above.