Bricken

Privacy Policy

Last updated 6 October 2026

In short: we collect only what Bricken needs to work. We don’t sell data, we don’t show adverts, and we don’t use tracking or analytics cookies. The records you enter are yours; we look after them for you.

1. Who we are

Bricken is a trading name of Tom Kurpanik, a sole trader, of 126 Colmore Row, Birmingham B3 3AP, United Kingdom. Contact about anything in this policy: hello@bricken.net. ICO registration number: pending.

2. Two kinds of information

3. Crew: people who log their days in Bricken

A builder can add the people who work for them, so they can log their own days and send in receipts. The builder decides this and is the controller for these records; we handle them on the builder’s behalf. For each crew member Bricken keeps their name, email address, the rate and CIS rate the builder sets, the days they log (the times they tapped Arrived and Left), and the receipts they send.

The site check. The builder chooses, for each crew member, whether to use it; it is off unless they switch it on. When it’s on and a crew member taps Arrived or Left, their phone is asked once for its location. Bricken works out how far that is from the job’s postcode and keeps only that distance (for example “On site” or “About a mile away”). Where they actually were is never stored, nothing is checked between the two taps, and nothing is tracked in the background. If they say no to location, the day is still recorded, marked “No site check”. Crew only ever see their own entries, never the builder’s prices or figures.

CIS and right to work. For CIS the builder can record each crew member’s UTR, the CIS rate, whether and when they verified them with HMRC, and their verification number. The builder can also keep a record of how and when they checked someone’s right to work in the UK, who checked, a follow-up date, and an optional photo of the document. Bricken records these checks; it never makes them. Builders can give their crew our crew privacy notice (also in Polish).

Cards, qualifications and inductions. The builder can keep a record of each crew member’s CSCS card and other tickets (type, number, expiry date and an optional photo of the card), and of their site inductions (date, who ran it, and an optional photo of the signed form). Crew can add their own cards; the builder checks them. Only the builder’s owner and approvers, and the crew member themselves, can see them.

Site photos. The builder, their team and crew can add progress photos to a job. Before a photo leaves the phone it is resized and re-drawn, which removes the hidden details phones add, including where it was taken. Photos are seen only by the builder’s team, and a crew member sees only their own. They are kept until the builder deletes them or the job.

4. What we collect about users, and why

InformationWhyLawful basis
Email address, and sign-in codes (kept only as a scrambled code, for up to a day)To sign you in and keep your account secureContract
Company name, VAT settings, team members’ email addressesTo run your account and let your team use itContract
Subscription status, plan and dates; Stripe customer referenceTo bill you and apply your planContract; legal obligation (business records)
IP address, device and browser type, times of sign-in and requestsTo stop abuse (for example limiting sign-in attempts), keep the service secure and fix faultsLegitimate interests
Emails you send usTo answer youLegitimate interests
If you open the demo: your IP address, with the timeTo limit how many demos one visitor can open. The demo is a made-up company; anything you type into it is deleted with itLegitimate interests

We don’t make automated decisions about you that have legal or similarly significant effects.

Prices. To improve the default prices Bricken suggests, we may combine item prices from quotes and receipts across companies (the item, quantity, unit, price, date and region only). Before anything is combined we leave out anything that identifies a person or a business: names, suppliers, clients and addresses. An item’s price is only used combined with the same item from at least 5 companies in a region, so the averages contain no personal information. A company’s owner can turn this off in Settings. See section 6 of our Terms.

5. Cookies and storage on your device

Bricken uses one cookie: a sign-in cookie that keeps you signed in on that device for up to 180 days. It is strictly necessary, so it doesn’t need your consent. The app also saves a few preferences on your device (such as which list you last viewed), which never leave it. There are no analytics, advertising or tracking cookies, and fonts are served from Bricken itself, not from a third party.

Referral links, only with your consent. If you open an accountant’s or partner’s referral link, we ask before remembering it. If you say yes, your browser keeps their code for up to 60 days so the discount applies when you sign up and they are credited. If you say no, nothing is kept and you can still type the code at checkout. We keep your answer on the device so we don’t ask again each time. You can change it at any time in Settings, and turning it off deletes any code that was kept. The website bricken.net stores nothing on your device.

Which advert or post you came from. If you arrive by a link from one of our adverts or posts, it carries a campaign tag (for example “facebook, reel”). When you ask for a sign-in code, we keep that tag, the page you landed on and when, with your email, and copy them to your company when you set it up, so we can tell which adverts work. Nothing is stored on your device for this. If you never set up a company, it’s deleted after 90 days.

Cost guides on bricken.net. The cost guides on bricken.net have a “Try it” calculator. The sizes you type are sent to Bricken to be priced. For each guide we count how many times a day the calculator is used and how many times “Save this as a full quote” is clicked, and nothing else. There’s no cookie and nothing about you or your device is kept. To stop the calculator being misused, your connection’s address is held briefly in memory and never written down. If you then save it as a quote, your browser keeps the item on your device until you’ve signed in and set up your company (for a week at most), then adds it to your first quote and deletes it.

6. Who else handles data

We use these service providers, each under a contract that requires them to protect the data and use it only to provide their service:

ProviderWhat forWhere
CloudflareHosting, the database, receipt photo storage and nightly backupsGlobal network; the database is held in Western Europe
StripeTaking subscription payments. Card details go straight to Stripe; we never see themUK, EU and US
ResendSending sign-in codes and invitation emailsUS
postcodes.ioFinding a job’s location from its postcode, for the crew site check. Only the postcode is sentUK
AnthropicReading the figures from receipt photos when you use automatic receipt reading. The photo is sent to read it; under Anthropic’s commercial terms it is not used to train their modelsUS

Where data goes outside the UK, it is protected by the safeguards UK law requires, such as the UK–US data bridge or the UK International Data Transfer Addendum.

Accountant referrals. If you sign up through an accountant’s link or code, that accountant can see your company name, when you joined, and whether you’re on a free trial, paying or have stopped, so that we can pay them their share. They never see your business records.

We don’t sell personal information, and we share it with others only if the law requires us to, or to protect our rights or someone’s safety.

7. How long we keep it

8. Keeping it safe

All connections are encrypted. Sign-in codes and sign-in tokens are stored only in scrambled (hashed) form. Each company’s records can only be reached by that company’s own team, and every request is checked on our server, not just in the app.

9. Your rights

You can ask us for a copy of the personal information we hold about you, and ask us to correct it, delete it, restrict or object to how we use it, or give it to you in a portable form. Email hello@bricken.net; we will reply within one month. The owner of a company can also download all its records from Settings at any time.

If you are unhappy with how we handle your information, please tell us first. You can also complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, or 0303 123 1113.

10. Changes

If we change this policy in a way that matters, we will email account owners before the change applies. The date at the top shows when it was last updated.