Privacy Policy
Last updated 3 September 2026
1. Who we are
Dockspocket Ltd ("DocsPocket", "we", "us") operates docspocket.com, a service for storing copies of identity and personal documents and receiving expiry reminders. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Dockspocket Ltd is the data controller for the personal data described in this notice.
Contact for privacy matters: privacy@docspocket.com.
2. What data we collect
- Account data: email address, optional name, password hash (handled by our authentication provider), sign-in method and timestamps.
- Document data you upload: photos of passports, ID cards, driving licences, residence permits and visas, plus the details you save (holder name, document number, issuing country, expiry date, notes).
- Legacy & Essentials data (optional add-on): records you create about pensions, insurance and similar arrangements, including any beneficiary or contact details you choose to enter.
- Payment data: subscription status, plan tier and renewal date. Card details are collected and processed directly by Stripe — we never see or store them.
- Technical data: IP address (used transiently to show prices in your local currency and for security), browser and device information, and error logs.
3. Special category data
Identity documents can reveal information such as nationality, date of birth, and in some cases biometric-style imagery. We process this content solely on the basis of your explicit consent (Article 9(2)(a) GDPR / UK GDPR), given when you choose to upload a document. You can withdraw that consent at any time by deleting the document or your account; withdrawal does not affect processing carried out before withdrawal.
4. Why we process it and our legal basis
- Providing the vault and expiry reminders — performance of our contract with you (Art. 6(1)(b)), plus explicit consent for document content (Art. 9(2)(a)).
- Account creation, sign-in and service emails — performance of contract.
- Taking payment and preventing fraud — performance of contract and our legitimate interests (Art. 6(1)(f)).
- Keeping the service secure and diagnosing faults — legitimate interests in operating a safe, working service.
- Meeting tax and accounting obligations — legal obligation (Art. 6(1)(c)).
We do not use your data for advertising, profiling or automated decision-making.
5. Who we share it with
We use a small number of processors, each bound by a data processing agreement:
- Supabase — database, authentication and encrypted file storage.
- Cloudflare — hosting, content delivery and network security.
- Stripe — payment processing (independent controller for payment data).
- Resend — delivery of account and reminder emails.
- An AI provider — optional reading of the text on a document photo you upload, so we can pre-fill the expiry date. Images sent for this purpose are not used to train models.
We never sell your data or share it with advertisers. We disclose data to authorities only where legally required.
6. International transfers
Some providers process data outside the EEA or UK. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or by an adequacy decision, plus additional technical measures such as encryption in transit and at rest.
7. How long we keep it
- Documents and vault entries: until you delete them or close your account.
- Account data: for as long as your account is open. After you delete your account we erase your documents and files immediately and remove account records within 30 days.
- Payment and invoice records: retained for up to 7 years to meet tax law.
- Security and error logs: up to 90 days.
8. Security
Document photos are held in private storage that is only readable by your signed-in account. Data is encrypted in transit (TLS) and at rest, access is restricted by row-level security rules that scope every record to its owner, and administrative access is limited to what is needed to run the service. No system is perfectly secure, so please use a strong, unique password.
9. Your rights
Under the EU and UK GDPR you have the right to:
- access a copy of your data (available instantly from your account privacy page);
- have inaccurate data corrected;
- have your data erased (self-service account deletion);
- restrict or object to processing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority.
In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU it is the data protection authority of your country of residence. Email privacy@docspocket.com and we will respond within one month.
10. Children
DocsPocket is not intended for children under 16. You may store a child's document as their parent or guardian, in which case you are responsible for that data.
11. Changes
If we make a material change to this notice we will tell you by email or in the app before it takes effect.
DocsPocket