Privacy Policy
How Dispatch handles your business's, your team's and your customers' information.
Who we are
Dispatch is a product of Civil Digital, a Bedford-based UK digital consultancy. Dispatch provides software that helps trades businesses (electricians, plumbers, HVAC and other field-service teams) collect structured customer fault reports, manage jobs, schedule visits, quote for work and invoice for it. This policy explains what personal data we collect, why, and how we look after it.
The two roles we play
Which of us is answerable for a piece of data depends on whose data it is:
- For information about businesses using Dispatch (account holders and their staff), Civil Digital is the data controller.
- For information about a business's own customers (the people submitting fault reports, receiving quotes and paying invoices), the business is the data controller and Civil Digital is a data processor acting on its instructions.
If you are a member of the public whose details were entered by a trades business, contact that business. They hold the controls, including a built-in one-action permanent erasure function.
Information we collect
- Account details: names, email addresses and roles of business owners, office admins and field technicians.
- Customer data: names, contact details and addresses of your customers, entered by your business or submitted by the customer via a secure portal link.
- Fault reports and media: questionnaire answers, photos, videos and documents submitted against a job. These frequently include images of the inside of a customer's home.
- Job and business activity: jobs, statuses, templates and internal notes created within Dispatch. Internal notes are never shown to a customer or printed on any customer-facing document.
- Appointments: the date, time, site town and postcode of a booked visit and which team member it is assigned to.
- Properties and site details: one customer may have several properties — a landlord, a letting agent, a business with more than one site — and each is stored with its address. A business may also choose to record, against a property, access information (a key safe or gate code, where to park, which side the meter is on) and a site contact: the name and, optionally, phone number or email of whoever is actually at the property. That contact may be someone other than the customer, such as a tenant or caretaker. Both are visible only to that business’s own staff. Neither is ever shown to a customer, included in any email we send, or printed on a portal, message, quote or invoice page, and both are erased when that customer’s data is erased.
- Quotes and acceptances: the priced offer sent to a customer and, if they accept or decline it, the name they typed, when they did it and which link they used. This is a record of who agreed, not an electronic signature, and Dispatch does not describe it as one.
- Invoicing and payment data: invoices and credit notes you raise, the customer details frozen onto them at the moment of issue, any photographs of completed work you choose to attach, and, where a customer pays by card, payment status and transaction references from our payment processor. Card details themselves are entered directly with the processor and never reach Dispatch's own systems.
- Financial records: where a business switches on Dispatch's Making Tax Digital bookkeeping, the income and expenses it records there, including any receipt photographs it uploads.
- Email delivery records: a log of the customer-facing emails sent on a business's behalf (what was sent, to which address, and whether it was delivered).
- An audit trail of actions: for example "a report was submitted", "an invoice was issued", "a customer's data was erased". It references internal record numbers only and contains no names, addresses or contact details.
- Technical data: basic usage and device information needed to run and secure the service. Dispatch uses no product analytics: nothing tracks what you click, which screens you visit or how long you spend in the app. The one exception is advertising measurement on our own sign-up pages, described under Cookies and advertising below, and it never applies to your customers.
How we use your information
- To provide and operate the Dispatch service for your business.
- To manage customer fault reports, jobs, appointments, quotes, invoices and team access.
- To keep the service secure and to prevent misuse, including keeping each business's data isolated from every other business's.
- To contact you about your account or, where you've opted in, about product updates.
We do not sell personal information, and we never use fault reports, customer records, photographs or job data for advertising of any kind. See Cookies and advertising below for the one narrow thing we do measure, which involves none of it.
Cookies and advertising
Dispatch sets no cookies for advertising, analytics or profiling anywhere in the product you or your customers actually use. There are no cookies on the customer fault-report portal, none on a job message thread, none on an invoice or quote page, and none anywhere in the dashboard. Those pages set only what is strictly necessary to sign you in and keep you signed in, which needs no consent and cannot be switched off without breaking the service.
This website carries no advertising tag at all. Nothing on dispatch.civildigital.co.uk (not this page, not the home page, not any of the guides) loads an advertising or analytics tag, sets a marketing cookie, or reports your visit to anyone.
The single exception is inside the Dispatch app itself, at app.dispatch.civildigital.co.uk: its home page, the sign-up form and the business set-up page. We advertise Dispatch on Google, and on those three pages only we load Google's advertising tag so we can tell whether an advert led to somebody creating a business account.
- We ask first. The tag loads with advertising storage denied by default. Nothing is stored and no identifier is written unless you press Accept on the banner. Declining is offered with exactly the same prominence as accepting, and the site behaves identically either way.
- Your choice is remembered on your device, and we do not ask again. To change it, clear this site's data in your browser and the banner will reappear.
- What it measures is a count, not a person. We record that a sign-up followed an advert. We do not send Google your name, your email address, your business details or anything you have entered into Dispatch, and we have deliberately not enabled the Google feature ("enhanced conversions") that would upload a hashed email address.
- We do not use it to re-target you. Visiting our sign-up pages does not add you to an advertising audience, and it will not cause Dispatch adverts to follow you around the web. The tag is configured to refuse personalised-advertising signals outright, so the data cannot be used to build a remarketing list even though it is measuring a conversion.
- If you decline, Google is told the conversion happened without any cookie or identifier attached to it. We are given a modelled, aggregate estimate and nothing that could identify you.
- Your customers never see it. A householder who receives a fault-report link, a message or an invoice from a business using Dispatch is never advertised to, never measured, and never asked about cookies, because those pages carry no tag to ask about.
Google acts as an independent controller for the advertising data it receives. Its handling is covered by Google's privacy policy.
Email we send to your customers on your behalf
Dispatch sends email to a business's customers as that business: a quote when it is issued, an invoice or credit note when one is raised, a confirmation when a visit is booked, moved or cancelled, and (only where the business has switched the feature on) automatic reminders about an unpaid invoice. These arrive under the business's own name, with replies going directly to the business; Dispatch appears only as the sender of record.
Payment reminders are off unless a business turns them on. Where they are on, an unpaid invoice may generate up to three emails (3, 10 and 21 days after the payment date) and then no more, after which chasing is manual. A business can stop reminders on any individual invoice at any time, and reminders are only ever sent for an invoice the business actually emailed in the first place.
Reminders about a repeating visit are off unless a business turns them on. Where they are on, Dispatch may email you to say a regular visit — an annual service or a safety check, for example — is coming up, and to ask whether a suggested date suits. At most three emails are sent about any one visit and then they stop for good; nobody is chased indefinitely. Every one of them carries a link to stop them, and once you use that link we will not send you another, ever — that choice is yours and the business cannot undo it. Stopping them does not affect anything to do with work you have already arranged: a booking confirmation, an invoice or a reply to a message still reaches you, because those are about work you asked for rather than an offer of new work.
Where your data is processed
Fault reports, customer records, photographs, invoices and all other files are stored in Google Cloud (Firestore and Cloud Storage) in London, United Kingdom (europe-west2), and all of our own processing runs in that same UK region.
Four narrow exceptions involve infrastructure outside the UK, and we state them rather than claim that all data stays in the UK:
- Sign-in accounts for business staff (email address, display name, encrypted password) are handled by Google's Firebase Authentication, which runs on Google's global infrastructure and cannot be region-pinned.
- Payments are processed by Stripe.
- Email is delivered through Resend, sending from dispatch@civildigital.co.uk.
- Notifications on the Dispatch Android app are delivered through Google's Firebase Cloud Messaging, which is global. A notification carries only what kind of message it is, never a customer's name, address or the words of a message; the app fetches the rest from the UK when you open it.
Sharing your information
We do not sell your personal data. We only share it with trusted service providers who help us run Dispatch (for example, hosting, storage and email delivery), or where we are required to by law. Your business's data is kept within your business and is not shared with other Dispatch customers.
Where a customer pays a Dispatch-issued invoice by card, the payment is processed by Stripe on the invoicing business's own connected Stripe account, and Stripe handles the card details and payment data directly under its own privacy policy. See our Terms for how card payments and fees work.
Calendar syncing shares a job number and a postcode, and nothing else. If an engineer connects their work calendar, Dispatch sends the job number and the site postcode for their visits to their calendar provider: Google, Apple or Microsoft. Customer names, phone numbers and full addresses are never sent, and neither are notes or photographs; an engineer sees those only by opening the job in Dispatch itself. Calendar syncing is off unless an engineer turns it on, and the business can switch it off for everyone.
Data retention
We keep personal data only for as long as it is needed to provide the service or as required by law. A business can permanently erase an individual customer's data at any time using the built-in erasure function, which removes that customer's records, jobs, fault reports, media, appointments, quotes, portal links and the properties recorded against them in one action. That last one includes any access information — a key safe or gate code — and any site contact details, because a code that outlived the record it belonged to would be a working key to somebody's home left in a database for no reason.
Job records are kept for the life of the job. Completion reports, and compliance documents such as Gas Safety Records (CP12) and electrical safety certificates (EICR), are kept for as long as the job exists in Dispatch and are deleted when the job is deleted. That is a limit rather than a promise to keep them: this material does not outlive the job it belongs to.
Other job media is kept for no longer than 30 days after a job ends. Photographs shared through the app that are not part of a completion report, a compliance document or an invoice (photographs a customer shares, images sent in in-app messages, and photographs attached to a portal fault report) are kept only for as long as they are needed. Our retention limit for this material is 30 days from the point the job is completed or cancelled.
A business can delete sooner, and controls the timing throughout. Deleting a job removes everything attached to it, and the one-action erasure function above removes a customer's data across every job at once.
Invoices and credit notes are the exception, and they are kept for seven years from the invoice date. UK tax law requires businesses to keep financial records for six years from the end of their accounting year, which seven years from the invoice always covers, so an invoice survives a request for erasure: a legal obligation neither we nor the business can waive. An invoice keeps a copy of the customer's name, billing address and email address as they stood when it was issued and, where the business chose to attach them, photographs of the completed work, which may include images of the inside of a property. Everything else about that customer is still erased.
CIS deduction statements are kept on the same terms, where a business uses CIS. A business working as a subcontractor under the Construction Industry Scheme records the deduction statements its contractors send it: what was paid over a tax month and what tax was withheld from it. That record is the business's own evidence to HMRC that the tax was taken, so it survives a request for erasure in the same way an invoice does. It keeps the contractor's name and PAYE reference, because HMRC requires a valid statement to carry both. The "customer" on a CIS statement is a main contractor, a construction business the electrician works for, rather than a householder. If that contractor's data is erased, the business also stops being reminded to chase them for any statement still outstanding.
Erasure switches reminders off permanently. If a customer's data is erased, automatic reminders for their retained invoices are silenced at the same moment and cannot be switched back on by anyone. The invoice is kept because the law requires it; it stops being a reason to contact the person.
Quotes are erasable, and are erased. There is no legal obligation to keep an offer that was declined or never taken up, so quotes and their links are deleted along with everything else. Where an accepted quote already produced a deposit invoice, that invoice stays, under the six-year rule above.
Financial records kept for Making Tax Digital (the income and expenses a business records in Dispatch's bookkeeping, including receipt photographs) are retained for at least five years after the 31 January filing deadline for the tax year they belong to, because that is how long HMRC requires a taxpayer to keep them. Like invoices, they survive a request for erasure. That costs very little privacy, deliberately: a financial record holds dates, amounts, categories, a description the business typed and the number of any related invoice. It never holds a customer's name, address or contact details, so erasing a customer removes their personal data without touching the books.
Account information for businesses is kept for as long as the account exists and is removed on closure, subject to legal retention obligations such as billing records kept for tax purposes. Because the duty to keep financial records outlasts a subscription, a business can export all of its financial records as a spreadsheet at any time, including on the way out; we recommend doing so before closing an account.
The audit trail of actions is retained for accountability. It references internal record numbers only.
If a business asks you to report a fault before you are a customer. A business can send you a link to describe a problem — by text or by email — before you have any record with them at all. Until you fill that form in, all we hold is your name and the phone number or email address they used, so we can show you the right form and they can chase you if you go quiet. If you never fill it in, we delete that within 30 days, along with any photographs you started to attach. If you do fill it in, you become a customer of that business and everything above about customer data applies from that moment.
We check the postcode you type against a free UK postcode service, to catch typos and fill in your town. That check is made by our servers rather than by your phone, so the postcode service never sees your device or your IP address, and no third-party code runs on the page.
Your rights
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection. If you are a business using Dispatch, contact us using the details below. If you are a member of the public whose details were entered by a trades business, contact that business; we provide them the tools to honour your request, including permanent erasure. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
This applies to you even if you never contacted the business yourself. If you are a tenant, an occupier or a caretaker whose name or number a business has recorded as the contact for a property, those are your personal details and these rights are yours. The business holds the controls and can remove the entry, or the whole property record, at any time.
Deleting your Dispatch account
If you have a Dispatch account (that is, you work for a business that uses Dispatch) you can ask us to delete it at any time, and you do not need to give a reason.
In the app or on the web: Settings, then Your account, then Delete your account. If you no longer have the app, or cannot sign in: email info@civildigital.co.uk from the address your account uses. Full details are at app.dispatch.civildigital.co.uk/delete-account.
If you ask in Settings, your account is deleted automatically seven days later. We email you a receipt with the date, and you can cancel at any point before then. If you ask by email, we first check the request came from the account holder, and then complete it within 30 days. We email you again when it is done.
We delete your sign-in details, your membership of every Dispatch organisation, your personal settings and preferences, your time-logging records, and your entry on any of our mailing lists.
We cannot delete everything, and it is better to say so plainly. Invoices, credit notes and their payments are kept for seven years from the invoice date, as set out under Data retention above. They keep the customer and supplier details printed on them, because an invoice with those removed is no longer evidence of anything. CIS deduction statements and the business's bookkeeping records (with their receipt photographs) are kept on the same terms, because they are the business's own proof to HMRC. When each record reaches seven years it is deleted automatically, and once nothing is left, so is every remaining trace of the business. We also keep a record that you asked for deletion and that it was carried out, because without it we could not show the request was honoured.
If you are the only Owner of an organisation, deleting your account closes that business account too: its customers, sites, jobs, reports, photographs, quotes and schedule are deleted, its Dispatch subscription is cancelled, and everyone else in the organisation loses access (we email them to say so). Before it closes, you can download every invoice and credit note from the delete screen. After it closes, you can ask us for a copy of the records we keep by emailing info@civildigital.co.uk from the account's address.
Why you are leaving. When you delete your account, or cancel a paid plan, we ask, optionally, why. If you answer, we keep your answer with a few facts about how the business used Dispatch (how long it had been with us, its plan, how far it got with setting up, and how many jobs and invoices it had), without your name, your email address or the business's name, so we can learn what to improve. Please do not put personal details in the comment box; if you did, ask us and we will delete it.
If you are a customer of a business that uses Dispatch, this section is not about you: you have no Dispatch account. Your details belong to that business; ask them, and see Your rights above.
The Dispatch Android app
Dispatch is also available as an Android app from Google Play. It is the same product: the same screens, held on the same servers in the UK, with no separate copy of your data on the phone beyond what the app needs to show you what is on screen.
- We do not track you in the app. It carries no advertising identifier, no analytics, no crash reporting and no advertising tag of any kind.
- We do not read your location. Addresses are looked up from what somebody typed. The app never reads the phone's own location and holds no location permission.
- Photographs are taken through your phone's own camera and handled exactly as photographs added on the web: they belong to the job, and to the business.
- The app does not back itself up to Google Drive. Android's automatic backup is switched off, so a signed-in session and anything stored on the device cannot be copied out of the UK into a personal Drive account.
- Notifications. If you allow them, we hold an identifier for your phone so we can deliver them. It is deleted when you sign out, when you remove the phone in Settings, or when you delete your account. You choose which kinds of notification reach your phone in Settings, then Notifications.
- Updates. The app can update its screens from our own servers in the UK between Play Store releases. Every update is signed by us and the app refuses anything that is not. Nothing about you is sent to make this work.
Security
Every business's data is separated by design, in the structure of the database itself rather than by a filter that could be forgotten; one business cannot reach another's records. Fault-report links are unguessable, expire automatically, lock after repeated failed attempts and become read-only receipts once used. Quote and invoice links are revisitable, so a customer can come back to pay or respond, and are resolved on our servers rather than granting any direct access to the database. Uploads and downloads of photographs use short-lived, single-file links. All traffic is encrypted in transit and data is encrypted at rest by Google Cloud. Within a business, access to customer data is restricted by role.
Access by Civil Digital
We need a limited view of how each business's account is performing so that we can monitor platform performance, improve features and provide support. This section sets out plainly what that means.
What our staff can see. Our operators have a console showing, for each business using Dispatch: the business name and contact details, subscription tier and status, the number of seats and templates in use, counts of jobs, invoices and quotes raised, setup progress, which optional features are switched on, and when the account was last used. This is information about the business — for which we are the data controller — together with counts.
What our staff cannot see through it. The console shows no information about your customers. It cannot display customer names, addresses, phone numbers, fault reports, photographs, messages or invoice contents. For that information the business is the data controller and we act only as a processor on its instructions, so we do not browse it. Where a support question genuinely requires looking at a specific record, we ask the business to show us or to tell us what to look at — we do not help ourselves to it.
Every look is logged. Each time an operator opens the console we record who did so and when, in a log that cannot be edited or deleted, including by that operator. If you want to know whether we have looked at your account, ask us and we can tell you.
Support conversations. When we help a business, we keep a short record of it: notes of our calls and emails with the business, where things stand, and any help request sent from inside Dispatch, with the name and email address of the person who sent it so that we can reply. It is about the business, not its customers, and we ask people not to include their customers' details. It is deleted when the business closes its Dispatch account, and a person's name and contact details are removed from it when they delete their own account. A help request is also emailed to our support inbox so that we can answer it; that email, and our replies, are kept as ordinary correspondence and deleted when we no longer need them, which is separate from the record above.
Who counts as an operator. Only named Civil Digital staff, granted access individually by a deliberate administrative action and protected by multi-factor authentication. Access can be withdrawn, and withdrawal takes effect immediately.
Changes to this policy
We may update this policy as Dispatch develops. When we do, we'll change the "last updated" date below and, where appropriate, let you know directly.
Contact us
Questions about this policy or your data? Get in touch:
- Email: info@civildigital.co.uk
- WhatsApp: +44 7568 296136
Last updated: 10 October 2026