Privacy Policy

PRIVACY POLICY

Last update: 6 July 2026 (service fee discount promotion)

(c) Fort Technologies Ltd

This Privacy Policy explains how Fort Technologies Ltd ("Fort", "we", "us", "our") collects, uses, stores, and shares personal data when you use the Fort mobile application, our services, and (where applicable) our website at fort-app.com.

By using Fort, you agree to the collection and use of information in accordance with this Privacy Policy.

HOW TO READ THIS POLICY

Some processing described below is in use today. Other processing is planned or applies to our website when those features are enabled. Where relevant, we indicate the status as:

[Current] — processing that is live in the Fort app or our systems today. [Planned] — processing we intend to introduce or expand. [Website] — processing that applies to fort-app.com (not the native mobile app).

1. WHO THIS POLICY APPLIES TO

[Current] This policy applies to:

(a) homeowners and other clients using Fort to find and hire trade businesses; (b) trade businesses, sole traders, subcontractors, and company officers or executives registering on Fort; (c) visitors to our website where website-specific processing is described; (d) anyone who contacts us or interacts with Fort support; and (e) [Planned] individuals whose personal data appears in UK planning application records that we obtain from public sources, where we use that information for business development or to contact them about Fort's services, even if they do not have a Fort account.

2. DATA CONTROLLER

Fort Technologies Ltd is the data controller for personal data described in this policy.

Contact: fort@fort-app.com

Registered address: 56 Oakway, Woking, England, GU21 8TR

3. CATEGORIES OF PERSONAL DATA WE COLLECT

We may collect and process the following categories of personal data:

3.1 Identity and contact data [Current] Name, email address, telephone number, postal address, postcode, date of birth (where required for trade onboarding), profile photograph, company name, and company registration details.

3.2 Account and authentication data [Current] Username, hashed password, Firebase user identifier, SMS one-time passcodes (OTP), device type, and push notification tokens.

3.3 Trade business and verification data [Current] Trade category, bio, portfolio images, company URL, Companies House number, incorporation and trading dates, ownership percentages, executive and owner details, references, CSCS and CIS certificates, insurance documents, qualifications, and other documents you submit for Fort verification.

3.4 Vetting and compliance data [Current] Results of our trade business vetting programme (see section 6), including criminal history checks, proof of address, CCJ and financial history information, company history, open-source research findings, insurance validation outcomes, customer experience references, duplicate-business checks, director checks, and encrypted evidence documents uploaded by Fort administrators.

3.5 Payment and financial data [Current] Payment amounts, milestone or stage payment metadata, Stripe payment and payout identifiers, bank account details submitted via Stripe Connect, government-issued identity documents and selfies processed via Stripe Identity, platform fee information, and Trade Business upfront Service Fee discount payments (amount, tier, payment identifiers, and status). Fort does not store full card or bank credentials; payment processing is handled by Stripe.

3.6 Project and marketplace data [Current] Project descriptions, job locations, project address line 1 (collected when you create a project but not shown publicly on listings), verified postcodes, town or locality labels shown on public listings, images, quotes, contracts, milestone status, variation orders, milestone completion evidence, reviews and ratings (where available), dispute-related text and images, and other material documents or information pertaining to a project (including, without limitation, the categories listed in our Terms and Conditions, clause 5.22(a)). Where you use Fort, we expect material project records to be maintained on the Platform to the extent the app provides functionality for doing so.

3.7 Communications data [Current] In-app messages, chat attachments, email correspondence, SMS messages (including OTP), and push notification content.

3.8 Technical and usage data [Current] IP address, device information, session data, audit logs, admin activity logs, and aggregated internal analytics derived from our databases.

3.9 Location data [Current] and [Planned] [Current] Postcode, geocoded coordinates, service region assignment, and project or job location for marketplace matching. When you create a project, we collect your project address line 1 and verified postcode for operational and safety purposes; public listings display only the town or locality derived from your postcode, not your address line 1. [Planned] Real-time device location when the Fort app is open (and, where you grant permission, in the background) to improve local search and service matching.

3.10 Marketing preferences [Current] If you opt in to receive marketing communications, we will record your preference. Marketing SMS and promotional campaigns are [Planned] until preference storage and campaign tooling are fully enabled.

3.11 Website and cookie data [Website] / [Planned] Browser cookies, analytics identifiers, and advertising pixels on fort-app.com when those features are enabled. The native Fort mobile app does not use browser cookies.

3.12 Planning application data [Current] and [Planned] [Current] We collect and store information about UK planning applications from public sources, including the UK Planning Data service (planning.data.gov.uk) and, where enabled, local planning authority public registers. This may include application reference, site address, development description, application type and status, decision or submission dates, map coordinates, and a link to the public register entry. We do not intentionally collect applicant names, email addresses, or telephone numbers through our planning ingestion service. [Planned] We may use this information to identify properties where renovation or construction work may be required and to contact property owners or occupiers about Fort's marketplace services.

4. HOW WE COLLECT PERSONAL DATA

We collect personal data when you:

(a) register for an account or complete onboarding; (b) submit verification documents or complete vetting steps; (c) create projects, request quotes, enter contracts, or make milestone payments; (d) send messages through Fort; (e) raise or participate in a dispute; (f) contact support; (g) use our website (where applicable); (h) interact with Fort administrators during verification or safety review; and (i) [Current] where Fort automatically syncs UK planning application records into our Fort-Planning service for review by Fort administrators through our internal admin tools.

We also collect data from third-party sources where permitted, including Companies House, postcodes.io (for postcode and region lookup), open-source and public register research during vetting, Stripe (for identity verification and payments), and public UK planning registers, including the Planning Data API at planning.data.gov.uk and local authority planning portals (where scraper ingestion is enabled for operational fallback).

5. PURPOSES AND LEGAL BASES FOR PROCESSING

We process personal data for the following purposes:

| Purpose | Data involved | Legal basis | | Account registration and login | Identity, contact, auth, device token | Contract; legitimate interests (security) | | Phone verification (SMS OTP) | Phone number, OTP | Contract; legitimate interests (fraud prevention) | | Service region and matching | Postcode, region, project location | Contract; legitimate interests | | Trade business onboarding | Company, owner, executive, sole trader data | Contract; legal obligation (where AML/KYC applies); legitimate interests | | Fort verification documents | References, CSCS, CIS, insurance, qualifications | Contract; legitimate interests (platform safety) | | 14-point admin vetting programme | Vetting data (section 6) | Legitimate interests (fraud prevention, platform safety); legal obligation where applicable | | Stripe Identity verification | Government ID, selfie (via Stripe) | Contract; legal obligation (where applicable) | | Stripe Connect and milestone payments | Payment, bank, payout data | Contract; legal obligation | | Service Fee discount promotion | Upfront payment amount, tier, Stripe payment metadata | Contract; legitimate interests | | Marketplace and projects | Project, quote, contract, variation, milestone, review data | Contract | | Platform records (clause 5.22) | Accepted quotes, contracts, variations, milestone evidence, project communications and uploads | Contract; legitimate interests (dispute resolution, platform safety) | | Planning application ingestion and review [Current] | Application reference, address, description, status, dates, coordinates, source URL | Legitimate interests (operational business intelligence, service development) | | Business development and outreach [Planned] | Site address and planning details relating to identifiable properties | Legitimate interests; counsel to confirm — may require consent or soft opt-in depending on channel (PECR) | | Messaging | Message content, attachments, metadata | Contract; legitimate interests (safety, disputes) | | Notifications (push, email, SMS) | Contact details, notification content | Contract; consent (marketing); legitimate interests (service messages) | | Dispute resolution | Dispute text, images, project data, Platform records | Contract; legitimate interests | | Admin safety and fraud review | User data, decrypted chat (where necessary), vetting records | Legitimate interests; legal obligation | | Internal analytics [Current] | Aggregated SQL metrics (internal only) | Legitimate interests | | Website analytics and advertising [Website] / [Planned] | Cookie and analytics data | Consent (where required) | | Hosting and infrastructure | Technical logs, stored files | Contract; legitimate interests |

6. TRADE BUSINESS ONBOARDING AND VETTING

6.1 Onboarding pipeline [Current]

Trade businesses complete a multi-stage onboarding process:

(a) company or sole trader account registration; (b) profile setup (bio, trade category, images); (c) for limited companies: owners and executives (including date of birth, address, ownership percentage, and email verification); (d) for sole traders: personal KYC information; (e) submission of Fort verification documents (references, CSCS, CIS, and related materials), stored encrypted on our servers; (f) our 14-point Fort admin verification programme (below); (g) Stripe Identity verification (government-issued ID and selfie, processed by Stripe); and (h) Stripe Connect onboarding (bank account details and optional identity documents, processed by Stripe).

Typical vetting turnaround is approximately four to five working days after required documents are submitted, subject to complexity.

6.2 Our trade business vetting process [Current]

Fort personnel (not automated third-party credit bureaus alone) perform the following checks as part of our admin verification programme. Results, findings, and supporting evidence documents are stored encrypted and used to decide whether a trade business may use the platform.

1. Criminal History Check 2. Proof of Address 3. Qualifications 4. Open Source Check (public internet and open-source research on the business or relevant individuals) 5. Personal CCJ Checks 6. Business CCJ Check 7. Company History Check (including Companies House and corporate records) 8. Financial History 9. Financial Checks 10. Duplicate Checks 11. Enhanced Business Check 12. Director Check 13. Customer Experience (references and track record) 14. Insurance Validation

After these admin checks are complete, Stripe Identity verification (steps 15–16 in our internal process) is required: government-issued identification and a selfie, processed by Stripe on Stripe-hosted infrastructure.

We may use public registers, submitted documents, references, insurance records, financial distress information (such as CCJs), and open-source research. We do not describe this as automated "credit bureau" screening unless a specific external bureau is engaged; vetting is Fort-administered.

7. PLANNING APPLICATION DATA

7.1 What we collect [Current]

Our Fort-Planning service ingests publicly available planning application records for selected local planning authorities (currently including Elmbridge, Woking, Guildford, Mole Valley, and Kingston upon Thames, and others we may add). Data is obtained primarily from the UK government's Planning Data API and, where necessary and enabled, from council public planning portals.

7.2 How we use it

[Current] Fort administrators use this data internally to monitor ingestion, assess coverage, and develop marketplace features.

[Planned] We may use planning application data to identify potential customers for home renovation and construction services and to contact property owners or occupiers about Fort by post, email, telephone, or other channels, where permitted by law.

7.3 Legal basis

We rely on legitimate interests (Article 6(1)(f) UK GDPR) to ingest and analyse public planning data for business development, balanced against the rights of individuals identified from that data. Where we contact you for marketing, we will comply with the Privacy and Electronic Communications Regulations (PECR) and any applicable direct-marketing rules. Our lawful approach for each outreach channel must be confirmed by legal counsel before launch.

7.4 Who can access it

[Current] Authorised Fort administrators only, via our admin panel. Planning data is stored in our Fort-Planning service database and is not shown to homeowners or trade businesses in the Fort mobile app today.

7.5 Public sources and licences

Planning data obtained from planning.data.gov.uk is subject to the Open Government Licence where applicable. Council portal data is taken from publicly accessible registers. We respect rate limits and terms of use of those sources.

7.6 Retention

We retain planning application records for up to 24 months after our last update to the record or last outreach attempt relating to that property, then delete or anonymise them, unless a live customer relationship exists or a longer period is required by law.

7.7 Your rights

If you believe your property or project appears in our planning data, you may contact us at fort@fort-app.com to request access, correction, erasure, or to object to processing based on legitimate interests. You may also complain to the ICO. If we contact you for marketing, we will tell you how to opt out of further messages.

8. PAYMENTS

8.1 Milestone stage payments [Current]

Fort facilitates milestone-based stage payments between homeowners and trade businesses using Stripe, including Pay-by-Bank and Stripe Connect. Payment data (amounts, stage metadata, payment intent and payout identifiers) is processed by Stripe. Fort may charge a platform fee via Stripe application fees.

Funds are credited to the trade business's Stripe connected account when the homeowner pays for a stage, and paid out to their bank when the milestone is approved on the Platform. Fort does not provide escrow services. Payment receipts and invoices may be generated as PDF documents.

8.2 What we do not store [Current]

Fort does not store your full payment card or bank account credentials. Stripe processes payment and identity data under its own privacy policy and terms.

8.3 Service Fee discount upfront payments [Current]

Trade Businesses may pay an upfront amount to activate a reduced Service Fee tier under our Terms and Conditions (clause 8.14). These payments are processed by Stripe (Pay-by-Bank) directly to Fort and are separate from Milestone Works Fee payments.

9. MESSAGING

9.1 In-app chat [Current]

Messages sent through Fort are stored on Fort servers. Message content is encrypted at rest. Chat attachments are stored in encrypted file storage. Thread metadata (participants, timestamps) is retained to operate the service.

9.2 Admin review [Current]

Fort administrators may access message content (including decrypted messages where necessary) for platform safety, fraud prevention, vetting, and dispute resolution.

10. NOTIFICATIONS

[Current] We send notifications through:

(a) push notifications via Firebase Cloud Messaging (FCM); (b) transactional email via Microsoft 365 SMTP; (c) SMS via Voodoo SMS (including OTP codes); and (d) in-app notification records.

[Planned] Marketing SMS and promotional email where you have opted in, once preference storage and campaigns are fully enabled.

11. LOCATION DATA

11.1 Current processing [Current]

We use your postcode, geocoded coordinates, and assigned service region (via postcodes.io and internal region logic) to match you with relevant trade businesses and projects. When you create a project, we store your project address line 1 privately for our records, operational use, and safety; we show only the town or locality on public marketplace listings. Project and job location data is used for marketplace listings and quotes.

11.2 Planned processing [Planned]

We may collect real-time device location when the Fort app is open, and where you grant permission, while the app runs in the background, to improve local search and service delivery. We will update this policy and request appropriate permissions before enabling this feature.

12. DEVICE AND LOCAL STORAGE

12.1 Mobile app [Current]

The Fort app uses local storage (including secure storage and SharedPreferences) for session data, notification preferences, and signup draft data. This data remains on your device unless synchronised with our servers as part of normal app operation.

12.2 Biometric unlock [Current]

Where supported, you may use on-device biometric authentication (such as fingerprint or face recognition) to authorise certain payment actions. Biometric data is processed only on your device and is not transmitted to Fort.

13. HOSTING AND INFRASTRUCTURE

13.1 Current [Current]

Application data, uploaded documents, and encrypted chat are hosted on our servers. Uploaded files are stored in our uploads directory; sensitive verification and vetting documents are encrypted where noted in our systems. We use TiDB/MySQL for data storage and Redis for chat pub/sub.

13.2 Planned [Planned]

We may migrate or expand hosting to cloud providers such as Amazon Web Services (AWS). We will update this policy when material changes occur.

14. OUR DISCLOSURES — SUBPROCESSORS AND THIRD PARTIES

We share personal data with the following categories of recipients where necessary to provide our services:

14.1 Subprocessors and service providers — live today [Current]

- Stripe — payments, Stripe Connect, Stripe Identity, Pay-by-Bank - Google (Firebase) — authentication and push notifications (FCM) - Voodoo SMS — SMS OTP and service messages - Companies House — company lookup and verification - postcodes.io — postcode geocoding and region lookup - Microsoft 365 SMTP — transactional email - Redis — chat pub/sub messaging infrastructure - TiDB/MySQL — database hosting

14.2 Planned subprocessors [Planned]

- Amazon Web Services (AWS) — cloud hosting - Google Analytics — website analytics and advertising features (when enabled on fort-app.com) - Meta / Facebook — advertising and Meta Pixel (when enabled on fort-app.com)

14.3 Other disclosures [Current]

- Trade businesses receive relevant homeowner contact and project information when you engage them through Fort. - Surveyors or other third parties may be involved in dispute resolution where applicable. - Fort administrators and authorised staff access user data, verification documents, and (where necessary) messages for vetting, safety, and support. - Planning application data is obtained from public UK government and council sources; those bodies are data sources, not Fort subprocessors. Fort-Planning runs on Fort-controlled infrastructure. - We may disclose data where required by law, regulation, court order, or to protect rights, safety, and security.

We require processors to protect personal data under appropriate contractual terms.

15. WEBSITE COOKIES AND ANALYTICS [Website] / [Planned]

This section applies to fort-app.com and related web properties, not the native Fort mobile app.

15.1 Cookies [Website]

When you use fort-app.com, we use essential local storage for site operation and cookie consent. A Cookie Policy is available in the Legal section of the Fort app and on our website. Optional analytics and advertising cookies are not enabled today; if we enable them, we will request your consent first.

15.2 Google Analytics [Website] / [Planned]

When enabled on our website, we may use Google Analytics, including Advertising Features, Remarketing, and Demographics and Interests reporting, to understand how visitors use our site and to improve marketing. Google may process data in the United States and other countries. You can opt out via Google Ads Settings and the Google Analytics Opt-out Browser Add-on.

15.3 Meta Pixel / Facebook [Website] / [Planned]

When enabled, we may use the Meta Pixel and related Facebook marketing tools on our website to measure advertising effectiveness. Meta may process data under its own policies.

16. INTERNATIONAL DATA TRANSFERS

Some of our subprocessors (including Stripe, Google/Firebase, Voodoo SMS, and [Planned] AWS, Google Analytics, and Meta) may process personal data outside the United Kingdom.

Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including UK adequacy regulations where applicable and Standard Contractual Clauses or equivalent mechanisms approved under UK GDPR.

17. DATA RETENTION

We retain personal data for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type:

- Account data: for the life of your account and a reasonable period thereafter - Platform records (quotes, contracts, variations, milestone evidence, project communications): for the duration of active projects and a reasonable period thereafter for disputes, safety, and legal compliance - Planning application data: 24 months after last record update or last outreach attempt, unless anonymised sooner, a live customer relationship exists, or a longer period is required by law - Vetting and verification documents: for the duration of your relationship with Fort and as required for compliance and dispute resolution - Payment records: as required by tax, accounting, and financial regulations - Messages: for the duration of active projects and a reasonable period thereafter for disputes and safety

We may anonymise or aggregate data for analytics and retain it longer in non-identifiable form.

18. YOUR RIGHTS

Under UK data protection law, you have rights including:

(a) access to your personal data; (b) rectification of inaccurate data; (c) erasure in certain circumstances; (d) restriction of processing; (e) data portability where applicable; (f) objection to processing based on legitimate interests; and (g) withdrawal of consent where processing is based on consent.

To exercise your rights, contact fort@fort-app.com. If we hold your data from public planning records but you are not a Fort user, you have the same rights above. You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

19. SECURITY

We implement technical and organisational measures to protect personal data, including encryption of sensitive verification and vetting documents, encrypted chat content at rest, access controls for administrators, and secure authentication. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

20. CHILDREN

Fort is not intended for users under 18. We do not knowingly collect personal data from children.

21. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. The "Last update" date at the top indicates when it was last revised. Material changes will be communicated through the app or other appropriate channels.

22. CONTACT US

Fort Technologies Ltd 56 Oakway, Woking, England, GU21 8TR Email: fort@fort-app.com

For questions about this Privacy Policy or our processing of your personal data, please contact us at the email above.