Vasker
Privacy policy
How Tweed Tyne Technologies Ltd processes personal data when you use Vasker. Written for treasurers as well as trustees.
Last updated: 31 August 2026
1. Who is responsible
Tweed Tyne Technologies Ltd (company number SC874131, Scotland) operates Vasker. We are registered with the Information Commissioner’s Office under number ZC184042. Contact: privacy@vasker.co.uk.
For account and service data (your officer login, support emails, billing identity, security logs), we are the controller.
For Organisation Data you enter about members, donors and Gift Aid (names, addresses, declarations, donation records, receipts), your organisation is the controller. We act as your processor under our Data processing addendum. You must have a lawful basis to hold that data in your club’s books.
2. What we collect
Account and organisation
Name, email, password (stored hashed), organisation name and type, roles, plan tier, and details needed for Gift Aid claims (such as HMRC Charities reference and authorised official information you choose to store).
Organisation Data you enter
Cash-book transactions, member and subscription records, Gift Aid declarations, donation and GASDS records, uploaded receipts or evidence, and related notes.
Technical and security data
IP address, browser and device signals, timestamps, and bot-protection tokens when
you use login, signup, admin login or public forms protected by Cloudflare Turnstile.
When Google Analytics 4 is configured, page URLs and similar usage signals are also
sent to Google so we can see which pages are used. When the Meta Pixel is configured,
similar technical data (and advertising cookies such as _fbp) may be
sent to Meta so we can measure visits and our own advertising. We also keep audit
logs of sensitive actions inside your organisation.
What we do not store
Government Gateway passwords. Those are typed only at the moment of a claim submission and discarded afterwards.
3. Why we process it
- Contract: to provide Vasker, authenticate users, host your books and send service emails.
- Legitimate interests: to secure the service, prevent abuse, improve reliability, keep audit trails, understand how the website is used (including via Google Analytics 4), and measure our own advertising (including via the Meta Pixel).
- Legal obligation: where tax, accounting or data-protection law requires us to retain or disclose information.
- Processor instructions: for Organisation Data, only as needed to deliver the features you use, under the DPA.
4. Where data lives and who helps us
Production application data is hosted in the European Economic Area on infrastructure operated by Railway (Railway Corp, a US-incorporated provider). Your deployed workloads and primary databases are placed in Railway’s EU region. Railway’s US corporate control plane may still be involved in operating the platform.
We use these processors (among limited support tools):
- Railway — application hosting, managed PostgreSQL, Redis, and S3-compatible media storage for uploads such as receipts.
- Cloudflare, Inc. — Turnstile bot protection on public forms (login, signup, calculator and admin login). Where configured, Cloudflare Email Routing and Workers also receive inbound support mail for Vasker addresses and forward it to our support systems. Cloudflare may process limited technical data such as IP address, and message content for routed mail, to complete those functions.
-
IDrive e2 (IDrive Inc.) — encrypted offsite backup copies of
database dumps, Redis dumps and media mirrors for disaster recovery. Backup
object storage is configured in the London region (
eu-west-3). - Transactional email — we send service mail (invites, password resets, notices) through the SMTP provider configured for Vasker. That provider processes recipient addresses and message content only to deliver those emails.
- Google LLC — Google Analytics 4 (GA4) on the website so we can understand which pages are used. Google processes technical data such as IP address, browser and device signals, and page URLs. We do not send Organisation Data (member, donor or Gift Aid records) to Google Analytics.
-
Meta Platforms Ireland Ltd. — Meta Pixel on the website so we can
measure visits and the effectiveness of our own advertising. Meta processes
technical data such as IP address, browser and device signals, page URLs, and
advertising cookies (for example
_fbp). We do not send Organisation Data (member, donor or Gift Aid records) to Meta.
Transfers outside the UK/EEA (for example where a US provider’s support or control plane is involved) rely on appropriate safeguards such as the provider’s UK/EU Standard Contractual Clauses, Data Privacy Framework participation where applicable, and our contracts with those providers. More operational detail is on Security and compliance.
5. Cookies and similar technology
We use essential cookies and local storage for sign-in sessions, security (including
Turnstile), and basic product preferences. Where Google Analytics 4 is
configured, we also set first-party analytics cookies (such as _ga and
_ga_*) so we can see aggregate site usage. Where the Meta Pixel is
configured, Meta may set cookies and similar technology (such as _fbp)
to measure visits and advertising effectiveness. We do not sell advertising
inventory on Vasker. The Gift Aid gap calculator may store
progressive answers in the browser so you do not lose progress mid-estimate.
6. How long we keep data
Account and Organisation Data stay while your organisation uses Vasker. After a paid plan ends, a grace period allows export; inactive accounts may then be archived and later deleted. Offsite backups are retained for a limited rolling window and then expire. You may ask us to delete sooner by emailing privacy@vasker.co.uk.
Your organisation remains responsible for HMRC and regulator retention rules (for example Gift Aid records often need six years). Export and archive what you need before deletion.
7. Sharing
We do not sell personal data. We share it with processors listed above, with HMRC when you choose to submit a claim, and when required by law or to protect the service. Within your organisation, access follows the roles you assign.
8. Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict, object, and data portability, and to complain to the ICO.
For member or donor records stored in your club’s books, contact your organisation first — they are the controller. For our own account or service processing, contact privacy@vasker.co.uk.
9. Children
Vasker is aimed at adult officers of organisations. If you record youth members, your organisation must ensure it has an appropriate lawful basis and safeguards.
10. Changes
We may update this policy as the product or processors change. The “Last updated” date at the top will change when we do. Significant changes will be highlighted on this page or by email where appropriate.
11. Related policies
Terms of service · Data processing addendum · Security and compliance · Who we are