TOOLIO
Privacy Notice - Version 1.1
Privacy at a glance
- Toolio Ltd is controller for the personal information it uses to operate the marketplace, except where another organisation acts as its own controller.
- Toolio uses account, profile, listing, booking, location, payment-status, messaging, support, safety and dispute information to provide and protect the Platform.
- Stripe handles card/bank credentials, connected-account onboarding, payments, Deposit authorisations, refunds, chargebacks, payouts and relevant verification. Toolio does not store full card numbers, security codes or full bank-account credentials.
- Firebase/Google provide authentication, Firestore/database, storage, hosting/backend and related technical services. Google Sign-In is optional.
- Toolio does not sell personal information and does not publicly display full payment details or identity documents.
- Exact collection details are disclosed only as reasonably necessary for confirmed rentals.
- International transfers are protected using adequacy regulations or contractual safeguards used by the relevant provider, as applicable.
- Toolio provides a clear route for data protection complaints, acknowledges them within 30 days and responds without undue delay.
1. About this Notice
1.1 This Notice explains how Toolio Ltd trading as Toolio (Toolio, we, us or our) collects, uses, shares, stores and protects personal information when you use the Platform.
1.2 Toolio is generally the controller for the processing described here. Stripe, Google and other providers may act as processors for some activities and independent controllers for activities they determine under their own legal, fraud, security or regulatory obligations.
1.3 This Notice is privacy transparency information and should be read with the Marketplace Terms and any just-in-time privacy information shown in the Platform.
1.4 We process personal information under the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations and other applicable law, including amendments made by the Data (Use and Access) Act 2025.
1.5 Privacy requests and data protection complaints may be sent to support@toolioapp.co.uk. Toolio has not appointed a DPO because it does not currently consider the statutory appointment criteria to be met; this will be reviewed if processing changes.
2. Who this Notice applies to
2.1 This Notice applies to account holders, Owners, Renters, private and Business Users, website/app visitors, people communicating through Toolio, support/dispute participants, and people whose information is supplied in connection with a Booking, safety issue, payment, fraud report or legal request.
2.2 Toolio accounts are for people aged 18 or over.
3. Information we collect
3.1 Account/contact: name, email, phone, address/postcode/town, account identifiers, login method, age confirmation and Terms/Privacy acceptance version and timestamp.
3.2 Profile/marketplace: display name, profile image, profile text, approximate location, ratings/reviews, status, rental history and private/trader/business status.
3.3 Business/trader: trading/legal name, legal structure, registration details, business address/contact information, representatives and information required for consumer disclosures, payment onboarding, tax/platform reporting or legal compliance.
3.4 Listings: Tool category/type, brand, model, serial number where supplied, description, photographs, condition, defects, price, Deposit, availability, collection information and listing coordinates.
3.5 Bookings: requests, dates, prices, fees, Deposit, approvals, cancellations, status, collection/return records, condition evidence, review status, conversation references and dispute history.
3.6 Payments/payouts: Stripe customer/connected-account/payment identifiers, limited card descriptors such as brand/last four digits where provided, payment/Deposit/refund/chargeback/payout status, verification status, requirements and failure reasons. Full card security data and full bank credentials are handled by Stripe rather than stored by Toolio.
3.7 Location: the address/postcode supplied by the User and saved coordinates derived from it for search and approximate distance. Core search does not require continuous background GPS.
3.8 Messages/support/disputes: messages, reviews, ratings, reports, complaints, support correspondence, photographs/video, receipts, repair estimates, proof of ownership, serial numbers, police incident details and other relevant evidence.
3.9 Technical/security: IP address, browser/OS/device/app version, authentication events, device/notification tokens, diagnostics, access times, security events and activity logs.
3.10 Preferences/marketing: notification settings, marketing consent/opt-outs and communication interactions where those features are used.
4. How we obtain information
4.1 We obtain information directly from Users; from Google where Google Sign-In is chosen; from Stripe/payment networks; from the other participant in a Booking; automatically from the app/browser; and where lawful from advisers, insurers, regulators, police/courts or public sources relevant to fraud, safety, ownership or business status.
4.2 Where information is necessary for an account, payment, payout, Deposit, Booking, trader disclosure, platform reporting or legal compliance, not providing it may prevent the relevant feature.
5. Purposes and lawful bases
5.1 Account creation/management and core listings/search/Bookings: performance of Toolio's contract with the User; legitimate interests may additionally apply to account integrity and marketplace administration where appropriate.
5.2 Authentication, security, fraud and abuse prevention: legitimate interests in protecting Users, property and the Platform; contract where necessary to provide secure service; legal obligation where applicable.
5.3 Payments, Deposit authorisations, refunds and payouts: contract; legitimate interests in preventing loss and administering transactions; legal obligation where applicable.
5.4 Trader/business verification and disclosures: contract, legitimate interests in marketplace integrity, and legal obligation where applicable.
5.5 Disputes, claims, chargebacks and complaints: contract where necessary; legitimate interests in resolving disputes, protecting property and establishing, exercising or defending legal claims; legal obligation where applicable.
5.6 Support and essential service communications: contract and legitimate interests in effective operation.
5.7 Platform testing, diagnostics, security and improvement: legitimate interests, subject to balancing and to consent where PECR or other law requires consent for storage/access technologies.
5.8 Marketing: consent where required by PECR; otherwise legitimate interests only where electronic-marketing law permits. Users have an absolute right to object to direct marketing.
5.9 Tax, platform reporting, court/regulatory/law-enforcement compliance: legal obligation where one applies; legitimate interests in protecting legal rights where appropriate.
5.10 Corporate investment, reorganisation or sale: legitimate interests in corporate administration and continuity, under confidentiality and data-minimisation safeguards.
6. Legitimate interests and sensitive information
6.1 Where we rely on legitimate interests, we assess necessity and balance our interests against individuals' rights and reasonable expectations. Relevant interests include security, fraud prevention, marketplace integrity, support, property protection, service improvement and legal claims.
6.2 Toolio does not routinely seek special-category or criminal-offence information. Such information may arise in injury, police or dispute evidence. We restrict collection to what is necessary and apply an appropriate Article 9 and/or Data Protection Act 2018 condition where required, including legal-claims or other applicable statutory conditions.
6.3 Users should redact irrelevant medical, identity, criminal or third-party information before uploading evidence where practical.
7. Information visible to other Users
7.1 Public/marketplace display may include display name, profile image/initials, profile text, approximate town/distance, listings, ratings/reviews and trader/private status.
7.2 Before a Booking is confirmed, Toolio intends to show approximate rather than exact residential location.
7.3 After confirmation, collection details and contact/Booking information are disclosed only to the extent reasonably necessary for collection, return, safety or the Booking. Full payment details and identity documents are not shared with other Users.
7.4 Dispute evidence is shared with the other participant only where reasonably necessary for a fair response, and Toolio may redact or withhold irrelevant or sensitive information.
8. Stripe and payment information
8.1 Stripe provides payment processing, card authorisations, Deposit handling, refunds, chargebacks, connected-account onboarding, Owner payouts and relevant fraud/identity/business verification.
8.2 Stripe receives card, bank, identity and verification information through Stripe interfaces. Toolio receives the identifiers, statuses and limited transaction information needed to operate the Platform.
8.3 Stripe may act as Toolio's processor/service provider for some processing and as an independent controller for processing it determines for legal, fraud, security, risk and regulatory purposes. Stripe's privacy information applies to its independent-controller processing.
8.4 Payment/verification status may affect access to payment, payout, Booking or handover features. Toolio does not present Stripe verification as a guarantee of identity, ownership, competence or trustworthiness.
9. Google, Firebase and FlutterFlow
9.1 Google/Firebase are used for authentication, Google Sign-In, Firestore/database, Cloud Storage, hosting/backend/Cloud Functions and related security/technical operations used by the live Platform.
9.2 FlutterFlow is the application development/deployment environment. Toolio limits production-data access to what is necessary for development, deployment or support and will keep its provider role and production access under review.
9.3 Toolio will maintain appropriate processor terms with service providers acting on its instructions and will review subprocessors and access where reasonably necessary.
10. Messages, reviews and evidence
10.1 Platform messages are stored for Booking communication, support, safety, fraud prevention, dispute handling and enforcement. They are not end-to-end encrypted from Toolio.
10.2 Toolio accesses messages only where reasonably necessary for support, a dispute, suspected fraud, prohibited conduct, safety, legal requests or technical/security issues.
10.3 Reviews may be publicly displayed and retained in identifiable or anonymised form where reasonably necessary for marketplace integrity. Toolio may moderate unlawful, fake or misleading reviews.
10.4 Sensitive dispute evidence is access-restricted and may be shared with the other participant, Stripe, advisers, insurers or authorities only where reasonably necessary and lawful.
11. Recipients
11.1 Recipients may include: other Toolio Users as described above; Stripe; Google/Firebase; FlutterFlow where relevant; communications/support providers; professional advisers and insurers; HMRC and other authorities/courts where legally required; and potential purchasers/investors under confidentiality safeguards.
11.2 Toolio does not sell personal information or permit processors to use Toolio-controlled data for unrelated marketing.
12. International transfers
12.1 Some providers and subprocessors operate outside the UK, including in the United States. A restricted transfer is made only where a lawful transfer mechanism applies.
12.2 For Stripe, international transfers may rely on UK adequacy regulations including the UK Extension to the EU-US Data Privacy Framework where applicable, and/or Stripe's contractual transfer mechanisms including the UK Addendum incorporated into its Data Transfers Addendum.
12.3 For Firebase/Google processing, the applicable Firebase/Google data-processing terms include contractual transfer mechanisms and UK supplementary terms/UK Addendum for restricted transfers where required.
12.4 Where Toolio itself initiates a restricted transfer not covered by adequacy, Toolio will use an appropriate safeguard or applicable exception and complete the proportionate data-protection test/transfer risk assessment required by UK law.
12.5 Further information or a copy/description of relevant safeguards may be requested from support@toolioapp.co.uk, subject to confidentiality and security limitations.
13. Cookies, local storage and device technologies
13.1 Toolio uses technologies necessary for authentication, security, sessions, Booking functionality and service delivery.
13.2 Toolio will not intentionally enable non-essential analytics, advertising or tracking technologies that require consent until appropriate information and consent controls are in place.
13.3 Before enabling a new analytics/advertising SDK or similar technology, Toolio will assess whether PECR consent is required and update its cookie/app technology information accordingly.
14. Automated decisions
14.1 Toolio does not currently make solely automated decisions that it intends to have legal or similarly significant effects on Users.
14.2 Stripe, Google and other providers may use automated systems for payment risk, fraud, security, identity or regulatory decisions under their own terms.
14.3 Where Toolio makes a significant decision using automated processing and law requires safeguards, Toolio will provide the applicable information, human intervention or review.
15. Retention
15.1 Toolio keeps personal information only for as long as necessary for the stated purpose, legal obligations, fraud/security, disputes or legal claims. Retention is reviewed and data is deleted or anonymised when no longer needed.
15.2 Account/profile data: while active, then normally deleted or anonymised within 24 months after closure, except limited data linked to transactions, fraud, disputes, tax/platform reporting or legal claims.
15.3 Terms/Privacy acceptance records: normally six years after the relevant contractual relationship ends, or longer for an active claim/legal hold.
15.4 Listings: while live; after removal normally deleted/anonymised within 24 months, except copies forming part of Booking, safety, fraud or dispute records.
15.5 Booking/payment/refund/payout/platform-reporting records: normally six years after the relevant transaction/financial period where justified by accounting, tax, reporting, chargeback or legal-claims purposes.
15.6 Ordinary Booking messages: normally two years after the Booking/last activity. Messages specifically relevant to a dispute, safety issue, fraud or legal claim may be retained with that case for up to six years after closure, or longer while a live claim/legal hold continues.
15.7 Support enquiries: normally two years after closure; longer only where linked to a Booking, dispute, fraud, complaint or legal claim requiring retention.
15.8 Dispute/damage/theft/safety evidence: normally six years after closure where reasonably necessary for legal claims, insurance, fraud or safety; irrelevant sensitive material should be deleted earlier where practicable.
15.9 Security/authentication/technical logs: normally 12-24 months unless required longer for an active incident, fraud investigation or legal obligation.
15.10 Marketing consent/opt-out records: for the period necessary to evidence consent or honour an objection; suppression records may be retained so that an opt-out is respected.
15.11 Backups are overwritten according to provider backup cycles and are access-restricted; deleted information may persist temporarily in disaster-recovery backups until overwritten.
16. Security
16.1 Toolio uses proportionate technical and organisational measures including authentication, access controls, security rules, provider security features and restricted access to sensitive evidence.
16.2 No internet service is completely secure. Users must protect credentials and report suspected compromise promptly.
16.3 Toolio will assess and respond to personal-data breaches and notify the ICO and affected people where required by law.
17. Your rights
17.1 Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making. Where processing relies on consent, consent may be withdrawn.
17.2 The right to object to direct marketing applies at any time. Rights may be limited where law permits or requires continued retention.
17.3 Requests should be sent to support@toolioapp.co.uk. Toolio may need proportionate identity verification before acting on a request.
18. Children and third-party information
18.1 Toolio accounts are for adults aged 18 or over. Toolio does not knowingly offer accounts to children.
18.2 A User may occasionally provide information about another person in a dispute, accident or report. Users must provide only information reasonably necessary and should inform the person where appropriate and lawful.
18.3 Where Toolio obtains personal information indirectly, Toolio will provide Article 14 information where required, subject to applicable exemptions such as where provision would be impossible/disproportionate or would seriously impair a lawful purpose.
19. Marketing and service communications
19.1 Booking, payment, security, account, safety, legal and support communications are service messages.
19.2 Marketing email, SMS, push or similar communications are managed separately. Toolio obtains consent where PECR requires it and uses any lawful soft-opt-in or other permitted basis only where the statutory conditions are met.
19.3 Every marketing channel will provide a practical opt-out or preference method, and an opt-out will not stop essential service communications.
20. Account closure and deletion
20.1 Closing an account stops ordinary use but does not automatically erase records that Toolio still lawfully needs for Bookings, payments, tax/platform reporting, fraud, disputes, safety, legal claims or suppression of marketing.
20.2 Where possible, information no longer needed will be deleted or anonymised. Reviews or transaction records may be retained in anonymised or limited form where necessary to preserve marketplace integrity or another lawful purpose.
21. Data protection complaints
21.1 If you believe Toolio has infringed data protection law in connection with personal information relating to you, you may make a data protection complaint by emailing support@toolioapp.co.uk. Using the subject line “Data Protection Complaint” will help us route it promptly, but you do not have to use legal terminology or a particular form for us to recognise a complaint.
21.2 Toolio will facilitate the making of data protection complaints through an electronic route and any other appropriate means we make available. We will acknowledge receipt within 30 days beginning when the complaint is received.
21.3 Without undue delay, Toolio will take appropriate steps to respond to the complaint. This may include making enquiries into the subject matter to the extent appropriate, asking for information reasonably needed to investigate, and keeping you informed about progress.
21.4 Without undue delay, Toolio will tell you the outcome of the complaint. We will keep appropriate records of the complaint and our handling of it where necessary to demonstrate compliance, resolve the issue or establish, exercise or defend legal claims.
21.5 You also have the right to complain to the UK Information Commissioner's Office (ICO). You do not lose that right by first complaining to Toolio.
22. Changes and contact
22.1 Toolio will review this Notice and update it where processing, providers or law materially changes. Material new uses will be brought to Users' attention before they begin where required.
22.2 Privacy questions, rights requests and data protection complaints: Toolio Ltd, Ganymede, Pitnamoon, Laurencekirk, AB30 1ES; support@toolioapp.co.uk.
22.3 Current information about data protection rights and complaints is available from the UK Information Commissioner's Office (ICO).
END OF PRIVACY NOTICE - Version 1.1 final review candidate
