Privacy Policy
Tofflo — Making Tax Digital compliance app
Last updated: 31 August 2026 · Effective date: 31 August 2026
1. Introduction
This privacy policy explains how Varyn Ltd (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use the Tofflo mobile application (“the App”), our website varyn.uk, and associated services.
Tofflo helps UK landlords comply with HM Revenue & Customs’ (HMRC) Making Tax Digital for Income Tax Self Assessment (MTD ITSA) requirements. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller:
Varyn Ltd (company number 17033319, registered in England and Wales)
Holmfield, Moor Road, Colchester, Essex, CO4 5NR
Email: [email protected]
2. Data we collect
2.1 Account information
- Email address
- Password (stored as a cryptographic hash by Firebase Authentication; we never store or have access to your plaintext password)
2.2 Tax and financial data
- National Insurance Number (NINO)
- Property income and expense transactions
- Quarterly update data (cumulative totals)
- Expense categories and descriptions
- HMRC business and obligation details retrieved via HMRC APIs
2.3 Receipt images
- Photographs of receipts uploaded by you, stored in Firebase Storage
2.4 HMRC authentication data
- HMRC OAuth 2.0 access tokens and refresh tokens (encrypted at rest using AES-256-GCM; stored server-side only and never exposed to the client application)
2.5 Device and technical data (HMRC fraud prevention headers)
We are required by law to collect and transmit certain device information to HMRC as part of every API request. This data includes:
- Device operating system and version
- Device screen dimensions and window size
- Device identifiers (a locally-generated UUID)
- Timezone information
- Application version information
- Network connection type and public IP address
- Public network port
- Multi-factor authentication details (type, timestamp, reference)
- User-agent string
This data is collected solely to satisfy HMRC’s fraud prevention requirements and is transmitted to HMRC with each API call. We do not use this data for any other purpose.
2.6 Payment and subscription data
If you take out a Tofflo Pro subscription, how your payment data is handled depends on where you subscribe:
- Android and web (Stripe). Payments are processed by Stripe, our payment processor. Your card or other payment details are entered directly with Stripe and are never seen or stored by us. We receive and store your subscription plan, status, renewal date, and the customer and subscription identifiers Stripe issues.
- iOS (Apple In-App Purchase). Payments are processed entirely by Apple, which acts as the merchant of record for these purchases. We never receive your payment details from Apple. We receive and store the transaction identifiers and subscription status Apple provides so we can activate Pro features on your account.
- We do not use Google Play’s billing system. Android subscriptions are purchased through Stripe Checkout in your browser.
2.7 Website visitors
We do not use cookies or third-party analytics on varyn.uk. Cloudflare, which hosts the website, may collect standard web server logs (IP address, browser type, pages visited) as part of providing its service. If you subscribe via Stripe Checkout or the Stripe customer portal, those pages are operated by Stripe and are covered by Stripe’s own privacy policy and cookie practices.
2.8 Data we do not collect
- We do not use third-party analytics SDKs
- We do not use advertising SDKs or tracking technologies
- We do not collect location data beyond what is required by HMRC fraud prevention headers (timezone and IP-derived location)
- We do not use cookies in the mobile application
- We do not receive or store your full payment card details — these are handled by Stripe or Apple
3. How we use your data
| Purpose | Data used | Legal basis (UK GDPR) |
|---|---|---|
| Create and manage your account | Email, password | Contract performance (Art. 6(1)(b)) |
| Send quarterly updates to HMRC | Income, expenses, NINO, HMRC tokens | Contract performance (Art. 6(1)(b)) |
| Retrieve your tax obligations and business details from HMRC | HMRC tokens, NINO | Contract performance (Art. 6(1)(b)) |
| Store receipt images as supporting evidence | Receipt photos | Contract performance (Art. 6(1)(b)) |
| Provide and manage your Tofflo Pro subscription | Subscription plan, status, and Stripe/Apple identifiers | Contract performance (Art. 6(1)(b)) |
| Transmit fraud prevention headers to HMRC | Device and technical data | Legal obligation (Art. 6(1)(c)) — required by UK law |
| Keep accounting and billing records | Subscription and payment records | Legal obligation (Art. 6(1)(c)) |
| Secure your HMRC credentials | HMRC OAuth tokens (encrypted) | Legitimate interest (Art. 6(1)(f)) — security of your data |
| Respond to support requests | Email, account data | Legitimate interest (Art. 6(1)(f)) |
4. Data sharing
4.1 HMRC
We share your tax data (income, expenses, cumulative quarterly totals) and device information (fraud prevention headers) with HMRC via their MTD APIs. This sharing is necessary to fulfil the service we provide and to comply with legal requirements.
4.2 Firebase / Google Cloud Platform
We use Google Firebase as our infrastructure provider. Your data is processed and stored on Firebase services (Authentication, Firestore, Cloud Functions, Cloud Storage) in theeurope-west2 (London) region. Google acts as a data processor on our behalf under a data processing agreement. SeeGoogle’s data processing terms.
4.3 Stripe
If you subscribe on Android or the web, Stripe processes your payment on our behalf. Stripe receives the data needed to take payment and manage your subscription (including your email address and payment details you enter with Stripe). Stripe also processes some data as an independent controller, for example for its own fraud prevention. SeeStripe’s privacy policy.
4.4 Apple
If you subscribe on iOS via Apple In-App Purchase, Apple processes your payment as the merchant of record under your agreement with Apple. Apple shares transaction and subscription status information with us so we can activate your subscription. SeeApple’s privacy policy.
4.5 Cloudflare
Our website varyn.uk is hosted on Cloudflare, which processes standard web server logs as part of serving the site. SeeCloudflare’s privacy policy.
4.6 No other third-party sharing
We do not sell, rent, or share your personal data with any other third parties, advertisers, or data brokers.
5. Data storage and security
5.1 Infrastructure
All data is stored on Google Cloud Platform infrastructure in theeurope-west2 (London) region within the United Kingdom. Your data does not leave the UK unless required by the operation of underlying cloud infrastructure (in which case Google’s data processing terms and appropriate safeguards apply).
5.2 Security measures
- Encryption at rest: HMRC OAuth tokens are encrypted using AES-256-GCM before storage. Firestore and Cloud Storage provide additional encryption at rest by default.
- Encryption in transit: All communications between the App, our backend, and HMRC use TLS/HTTPS.
- Access controls: HMRC token storage is locked to server-side access only via Firestore security rules. Client applications cannot read or write token data directly.
- Token handling: HMRC refresh tokens are single-use. Firestore transactions prevent race conditions during token refresh operations.
- Authentication: Firebase Authentication secures user access to the App and backend services.
- No plaintext secrets: Sensitive credentials are managed via Google Cloud Secret Manager.
5.3 Data retention
| Data type | Retention period |
|---|---|
| Account information | Until you delete your account |
| Tax and financial data | 6 years from the end of the relevant tax year (to meet HMRC record-keeping requirements) |
| Receipt images | 6 years from the end of the relevant tax year |
| Subscription and billing records | 6 years from the end of the relevant financial year (to meet accounting and tax record-keeping requirements) |
| HMRC OAuth tokens | Until you disconnect your HMRC account or delete your Tofflo account |
| Device/fraud prevention data | Not retained by us; transmitted directly to HMRC per request |
After the applicable retention period, data will be securely deleted.
6. Your rights
Under UK GDPR, you have the following rights:
- Right of access — Request a copy of the personal data we hold about you.
- Right to rectification — Request correction of inaccurate personal data.
- Right to erasure — Request deletion of your personal data, subject to our legal obligations to retain certain records (e.g., tax data for 6 years).
- Right to restrict processing — Request that we limit how we use your data.
- Right to data portability — Request your data in a structured, commonly used, machine-readable format.
- Right to object — Object to processing based on legitimate interests.
- Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at[email protected]. We will respond within one month of receiving your request.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
7. International data transfers
Your data is stored in the UK (europe-west2, London). We do not intentionally transfer your personal data outside the United Kingdom. Where Google Cloud’s infrastructure may process data in other jurisdictions as part of service operation, appropriate safeguards are in place under Google’s data processing terms, including Standard Contractual Clauses and adequacy decisions where applicable. Stripe, Apple, and Cloudflare may process payment or web log data outside the UK; each provides appropriate safeguards for international transfers (such as the UK International Data Transfer Agreement or Addendum, Standard Contractual Clauses, or applicable adequacy decisions).
8. Children’s data
Tofflo is a tax compliance service designed for UK landlords aged 18 and over. We do not knowingly collect data from anyone under 18. If we become aware that we have collected data from a person under 18, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at[email protected].
9. Automated decision-making
We do not use automated decision-making or profiling in relation to your personal data.
10. Changes to this policy
We may update this privacy policy from time to time. We will notify you of significant changes via the App or by email. The “Last updated” date at the top of this policy indicates when it was most recently revised. Continued use of the App after changes constitutes acceptance of the updated policy.
11. HMRC fraud prevention — your rights and transparency
UK law requires us to send fraud prevention data to HMRC with every API request we make on your behalf. This is a legal obligation and we cannot provide the service without transmitting this data. The fraud prevention headers are defined by HMRC and include technical information about your device and connection. For full details of what HMRC collects and how they use it, seeHMRC’s fraud prevention guidance.
12. Contact us
If you have any questions about this privacy policy or our data practices, please contact us:
Varyn Ltd
Holmfield, Moor Road, Colchester, Essex, CO4 5NR
Email: [email protected]
13. Legal basis summary
| Legal basis | Applicable processing |
|---|---|
| Contract performance (Art. 6(1)(b)) | Account management, HMRC submissions, data retrieval, receipt storage, subscription management |
| Legal obligation (Art. 6(1)(c)) | HMRC fraud prevention headers, tax record retention, accounting and billing records |
| Legitimate interest (Art. 6(1)(f)) | Security of HMRC credentials, customer support |