Legal

Privacy Policy

Redstick Trading Limited  ·  Version 1.0  ·  April 2026  ·  Irish DPC jurisdiction

1. Who We Are

This Privacy Policy applies to Redstick Trading Limited, a company registered in the Republic of Ireland (CRO: 803586), operating a senior construction consultancy at redstick.io.

CompanyRedstick Trading Limited
Registered address57 Clontarf Road, Clontarf West, Dublin, D03 A7P0, Ireland
CRO number803586
Emailadmin@redstick.io
Data controllerJohn Friel, Redstick Trading Limited
Supervisory authorityData Protection Commission (DPC), Ireland — dataprotection.ie

2. What Personal Data We Collect

2.1 Account and profile data

When you register for a client account on our portal, we collect your full name, company name, email address, password (stored in hashed form only — never in plain text), client type, and market (UK or Ireland).

2.2 Project and document data

When you upload documents to your project on our portal, we store the documents themselves, project details (name, description, value), file metadata (filename, size, upload timestamp, category), and any revision notes you provide.

Documents you upload may contain personal data relating to third parties — for example, subcontractor names, site addresses, or contact details. By uploading such documents you confirm that you have the right to share them with us for the purpose of receiving our services.

2.3 Usage and technical data

We collect standard technical data including IP address, browser type, pages visited, and timestamps of logins and uploads.

2.4 Payment data

Payments are processed by Stripe or Revolut Business. We do not store card numbers or bank account details on our systems.

3. How We Use Your Data

PurposeLawful basis
Providing the consultancy services you have engaged us forContract performance
Managing your account and project portalContract performance
Delivering completed documents to youContract performance
Sending notifications about your projectContract performance
Processing paymentsContract performance
Complying with legal obligations (tax, GDPR audit logs)Legal obligation
Improving our services and platformLegitimate interests

4. Use of Artificial Intelligence

We use the Anthropic Claude API as part of our internal document processing workflows. When you upload documents to your project portal, those documents may be processed by the Anthropic Claude API to assist our consultants in extracting project information.

This processing takes place on Anthropic's servers. Anthropic's privacy policy is available at anthropic.com.

AI tools are used to support our consultants only. All outputs are reviewed and approved by a qualified professional before delivery. We do not use AI to make automated decisions that produce legal or similarly significant effects on you.

5. Third-Party Data Processors

ProcessorPurpose
Anthropic (USA)AI document processing — project documents may be processed
Supabase (EU West — Ireland)Database, authentication, and file storage
Vercel (USA)Frontend web hosting
Railway (EU West — Amsterdam)Backend API hosting
Stripe (USA/EU)Card payment processing
Resend (USA)Transactional email delivery
Cloudflare (USA/EU)DNS and network security

6. Data Retention

Data typeRetention period
Project documents (uploads and deliverables)90 days from date of delivery, then permanently deleted
Account and profile dataLife of your account
Payment records7 years (tax compliance)
GDPR audit logPermanent

You will receive an email notification 14 days before your project documents are due to be deleted.

7. Your Rights Under GDPR

As a data subject under GDPR and the Data Protection Acts 1988–2018, you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise any of these rights, contact us at admin@redstick.io. We will respond within one month.

You also have the right to lodge a complaint with the Data Protection Commission at dataprotection.ie at any time.

8. Data Security

  • All data is transmitted over TLS/HTTPS
  • Database access is controlled by Row Level Security — each user can only access their own data
  • Passwords are stored in hashed form only
  • API keys and secrets are server-side only — never exposed to client-side code
  • Daily database backups with point-in-time recovery

9. Cookies

Our portal uses essential session cookies to maintain your login state. These are strictly necessary for the operation of the service. We do not use analytics, advertising, or tracking cookies.

10. Changes to This Policy

We may update this policy from time to time. We will notify registered users of material changes by email. The version number and date at the top of this page indicate when it was last updated.

11. Contact

Emailadmin@redstick.io
Address57 Clontarf Road, Clontarf West, Dublin, D03 A7P0, Ireland
DPCdataprotection.ie