Privacy Policy
Last updated: 16 June 2026
Effective date: 16 June 2026
1. Who We Are
Rates Goblin Ltd ("Rates Goblin", "we", "us", or "our") provides a cloud-based platform that enables businesses to submit, manage, analyse, and benchmark construction cost information (the "Service"). The Service is provided to organisations (our "customers") for use by their authorised personnel; it is not a consumer product.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use the Service, visit ratesgoblin.ai, or otherwise interact with us.
- Registered company: Rates Goblin Ltd, 17068813, registered in England & Wales.
- Registered address: 49-51 Bancroft, Hitchin, England, SG5 1LL
- Contact for privacy matters: privacy@ratesgoblin.ai
For the purposes of the UK GDPR and EU GDPR, our role depends on the data in question:
- We are a data controller for personal data we collect about website visitors, prospects, and the authorised users who hold accounts with us (e.g. names and contact details).
- We are a data processor for the construction cost information and any associated personal data that a customer submits to the Service. That data is held under the customer's control and is only accessible through the customer's organisational account (see Section 11).
- We are a data controller for any anonymised and aggregated cost datasets we derive from submitted data and retain for our own purposes (see Section 12). Once data is genuinely anonymised it is no longer personal data and falls outside data protection law; until that point it remains personal data and is processed under our agreement with the customer.
Note that most construction cost information (e.g. material prices, labour rates, project budgets) is commercial data, not personal data, and is therefore primarily governed by your contract with us and our confidentiality obligations rather than by this Privacy Policy. This policy addresses cost data only to the extent it contains or can be linked to information about an identifiable individual (for example, a named estimator or a sole trader).
2. Scope
This policy applies to personal data we process about:
- Visitors to our website and marketing pages;
- Prospective customers and leads;
- Account holders and authorised users of the Service;
- Individuals who contact our support, sales, or other teams.
It does not govern the construction cost information our customers submit through the Service, except where that information contains personal data. Cost data is held by us as a processor on the customer's behalf, is access-controlled through the customer's organisational account, and is governed by our [Data Processing Agreement (DPA)] and customer agreement. Anonymised and aggregated cost datasets that we retain for our own purposes are addressed in Section 12.
3. Personal Data We Collect
3.1 Information You Provide to Us
- Account and profile data: name, email address, job title, employer, username, password (stored hashed), and profile preferences.
- Billing data: billing name, billing address, VAT/tax identifiers, and payment-method details (processed by our payment processor — we do not store full card numbers).
- Communications: the contents of messages you send us, support tickets, and survey or feedback responses.
- Content data: the construction cost information and supporting files, project data, and other materials that you or your organisation upload to or create within the Service. This may incidentally include personal data such as the names or contact details of estimators, project contacts, suppliers, or sole traders.
3.2 Information We Collect Automatically
- Usage data: features used, pages viewed, actions taken, timestamps, and session duration.
- Device and connection data: IP address, browser type and version, operating system, device identifiers, and referring URLs.
- Cookies and similar technologies: see Section 6.
3.3 Information We Receive from Third Parties
- Authentication providers (e.g. single sign-on / OAuth) where you choose to log in via a third party.
- Payment processors confirming transaction status.
- Analytics, enrichment, and marketing partners, where permitted by law.
We do not knowingly collect special category data (e.g. health, biometric, or racial/ethnic data) unless you choose to submit it as Content data; you are responsible for ensuring you have a lawful basis to do so.
4. How and Why We Use Personal Data
We use personal data for the purposes below. Where the UK/EU GDPR applies, we rely on the legal bases noted in brackets.
| Purpose | Legal basis |
|---|---|
| Creating and administering your account | Performance of a contract |
| Providing, maintaining, and securing the Service | Performance of a contract / Legitimate interests |
| Processing payments and managing billing | Performance of a contract / Legal obligation |
| Providing customer support | Performance of a contract / Legitimate interests |
| Sending service and transactional communications | Performance of a contract / Legitimate interests |
| Sending marketing communications | Consent / Legitimate interests |
| Improving and developing our products | Legitimate interests |
| Detecting and preventing fraud and abuse | Legitimate interests / Legal obligation |
| Complying with legal and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure your rights are not overridden; you may request details of that assessment.
5. Marketing
We may send you marketing about our products where we have your consent or another lawful basis. You can opt out at any time by using the unsubscribe link in any marketing email or by contacting privacy@ratesgoblin.ai. Opting out of marketing does not affect service or transactional messages necessary to operate your account.
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Service, remember your preferences, analyse usage, and (where you consent) support marketing. You can manage non-essential cookies through our cookie banner and your browser settings. For details of each cookie, its purpose, and its duration, see our Cookie Policy.
7. How We Share Personal Data
We do not sell your personal data. We share it only as described below:
- Service providers / sub-processors: hosting, infrastructure, analytics, payment processing, email delivery, and support tooling, acting on our instructions under contract. A current list of sub-processors is available within our Terms of Service.
- Professional advisers: lawyers, accountants, and auditors where necessary.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality.
- Legal and safety: where required by law, regulation, legal process, or to protect the rights, property, or safety of Rates Goblin Ltd, our users, or others.
8. International Data Transfers
We are based in the United Kingdom and may transfer personal data to, and store it in, countries outside the UK/EEA. Where we do so, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement (IDTA) or the European Commission's Standard Contractual Clauses (SCCs), and we assess the destination country's protections. You may request a copy of the relevant safeguard by contacting privacy@ratesgoblin.ai.
9. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy, including to satisfy legal, accounting, or reporting requirements. Retention periods vary by data type:
- Account data: for the life of your account and 30 days thereafter. Account holders have the ability to delete the account data with immediate effect.
- Billing records: for 6 years to meet tax and accounting obligations.
- Support communications: for 90 days.
- Usage and analytics data: for 24 months for compliance purposes.
- Customer cost data (non-anonymised): for the duration of the customer's subscription and the period set out in our DPA, after which it is deleted or returned in accordance with that agreement.
- Anonymised and aggregated cost data: retained indefinitely, as it no longer constitutes personal data (see Section 12).
When personal data is no longer required, we securely delete or anonymise it.
10. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, network security, logging and monitoring, employee training, and regular testing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify the relevant supervisory authority and affected individuals where required by law.
11. Our Role as a Processor for Customers
The construction cost information submitted to the Service is Content data belonging to the customer (the organisation whose account it is submitted under). In respect of that data:
- The customer is the controller and we act as a processor, processing it only on the customer's documented instructions and as set out in our Terms of Service.
- Non-anonymised cost data is accessible only through the submitting customer's organisational account and to the users that customer has authorised. We do not make one customer's identifiable cost data available to any other customer.
- Requests to access, correct, or delete personal data contained within a customer's Content data should be directed to the relevant customer; we will assist customers in responding as required by our Terms of Service.
Our right to create and retain anonymised and aggregated datasets from this data is described in Section 12.
12. Anonymised and Aggregated Cost Data
When using the Service, user consent to Rates Goblin creating anonymised and aggregated datasets derived from the cost data submitted by customers, and we retain and use these datasets for purposes including benchmarking, analytics, market insights, product improvement, and the development of new features and products.
- We removing all customer, project, and individual identifiers and aggregating data to a level at which no individual or organisation can be identified before data enters these datasets.
- Once data has been genuinely anonymised in this way, it is no longer personal data and is not subject to the UK/EU GDPR. We may retain and use it indefinitely.
- We do not disclose any individual customer's identifiable cost data to other customers or third parties as part of these features.
Your organisation's agreement to this processing, and our right to retain and use anonymised and aggregated data, are set out in our customer agreement and Terms of Service. Aggregated outputs are designed so that no individual customer's contribution can be re-identified.
13. Your Rights
Depending on your location, you may have some or all of the following rights in respect of your personal data:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion in certain circumstances.
- Restriction — limit how we use your data in certain circumstances.
- Portability — receive certain data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests or to direct marketing.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Automated decision-making — not be subject to solely automated decisions with legal or similarly significant effects, where applicable.
To exercise any right, contact privacy@ratesgoblin.ai. We will respond within the timeframes required by law (one month under the UK/EU GDPR, extendable in complex cases). We may need to verify your identity first.
California residents: subject to the CCPA/CPRA, you have rights to know, delete, correct, and opt out of "sales" or "sharing" of personal information, and not to be discriminated against for exercising those rights. We do not sell personal information.
14. Complaints
If you have concerns about how we handle your personal data, please contact us first at privacy@ratesgoblin.ai. You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO), https://ico.org.uk. In the EEA, you may contact your local data protection authority.
15. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@ratesgoblin.ai and we will take appropriate steps to delete it.
16. Third-Party Links and Services
The Service may contain links to, or integrations with, third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy notices.
17. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
18. Contact Us
Questions about this policy or our privacy practices?
- Email: privacy@ratesgoblin.ai
- Post: Rates Goblin Ltd, 49-51 Bancroft, Hitchin, Hertfordshire, SG5 1LL, United Kingdom