Who we are
Taskshire is a project management service run by Taskshire, [registered address]. We are registered with the UK Information Commissioner’s Office (registration [ICO registration number]). Questions and requests about your data go to privacy@taskshire.co.uk.
Two roles matter here:
- For your account, this website, billing and support, we decide how data is used, so we are the controller.
- For the work your workspace puts into Taskshire (projects, tasks, comments, documents, files, people you invite), the workspace’s organisation decides, and we process it on their behalf under our Data Processing Agreement.
What we collect
Your account
- Name, email address and a password, which is stored only as a one-way hash.
- Preferences: timezone, date format, week start, theme, notification settings, your character and town choices.
- If you turn on two-step sign-in: a secret and recovery codes, stored encrypted.
- If you sign in with Google or Microsoft: the account id, name, email and avatar link they give us. We never receive your Google or Microsoft password, mail or files.
- API tokens you create (stored hashed), personal calendar feed links, and which chat apps you have linked.
- The date and version of the terms you agreed to when you signed up.
Work in your workspace
Projects, tasks, comments, checklists, documents, time entries, calendar entries, request-form submissions, files you upload or import from Google Drive, and the messages that flow through chat apps your workspace connects. Other members of the same project can see this, along with your name, avatar and activity in it.
Billing
If a workspace owner buys Town Planner, Stripe handles the payment. We keep Stripe’s customer and subscription references, the card type and its last four digits, and the invoice history. Full card numbers are entered on Stripe’s pages and never reach our servers.
Usage, logs and support
- If you accept analytics cookies on our public pages: Google Analytics page-view data (pages visited, referrer, device type and approximate location, with IP addresses anonymised). See the Cookie Policy.
- An activity log of who changed what and when (used for the project audit log and for security), kept for 365 days.
- Server and security logs with IP address, browser and the pages requested, used for rate limiting, debugging and spotting abuse.
- Counts of API requests and of AI assistant use (tokens and estimated cost), never the content.
- Email delivery events from Resend (sent, bounced), so we can tell when an address stops working.
- Anything you send us in a support request.
We don’t buy data about you, and we don’t use advertising trackers. See the Cookie Policy for the handful of cookies we set.
Why we use it, and the lawful basis
| What we do | UK GDPR basis |
|---|---|
| Run the service: your account, projects, notifications, integrations you connect, the help centre and support | Contract (our Terms with you or your workspace) |
| Keep the service secure: sign-in protection, rate limits, audit and server logs, fraud and abuse prevention | Legitimate interests (ours and other users’), balanced against yours |
| Take payment for Town Planner, issue invoices and keep tax records | Contract, and legal obligation (UK tax and accounting law) |
| Send service email: verification, password resets, notices you have chosen, billing receipts, support replies | Contract. Notification email is under your control at any time. |
| AI assistant features your workspace switches on | Contract and legitimate interests; the workspace owner decides whether the feature is on |
| Measure how people find and use our public pages (Google Analytics) | Consent, given on the cookie banner and withdrawable at any time from Cookie settings |
| Show the public weekly guild league | Legitimate interests: it shows guild names and points, not personal task content |
| Tell you about product changes | Legitimate interests for service messages; consent for anything promotional. We don’t currently send marketing email, and if we start you can opt out in one click. |
| Comply with the law or protect rights and safety | Legal obligation, or legitimate interests |
AI features
Some features (caption help, the assistant, My Day and similar insights) use Claude, a model made by Anthropic. They are off until a workspace owner turns them on. When you use one, the text it needs (for example the task, its comments and your request) is sent to Anthropic’s API in the United States to produce a suggestion, which you review before anything is applied. We record who used the feature, the project, the model, token counts and an estimated cost. We keep the suggestion itself with the task so you can review, apply or dismiss it, and it is deleted with the task or project; we do not keep a copy of the prompt we sent. Under Anthropic’s commercial API terms, data sent this way is not used to train their models.
Who we share it with
We never sell personal data. We share it only with services that help us run Taskshire, each bound by a contract and listed with its purpose on the sub-processor list:
- [hosting provider]: hosting, database, file storage and backups (United Kingdom).
- Stripe: payments and invoices.
- Resend: sending email.
- Anthropic: AI features, only when a workspace turns them on.
- Google, Microsoft, Slack and Discord: only if you sign in with them or your workspace connects them for notices, commands or publishing.
- Google Analytics: page-view statistics for our public pages, only if you accept analytics cookies.
Services your workspace chooses to connect (for example X, LinkedIn, Facebook, Instagram, Threads, TikTok, YouTube, Zapier or Make through webhooks) receive what your workspace sends them under their own terms; they act for your workspace, not for us. We may also disclose data where the law requires it, to enforce our Terms, or as part of a sale or merger of the business, in which case this policy continues to apply.
International transfers
The service and its database are hosted in United Kingdom. Some of the providers above process data in the United States. Where that happens we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or on the UK–US Data Bridge where the provider is certified, so your data keeps the protection UK law gives it.
How long we keep it
- Your account: until you delete it (Profile → Delete account) or ask us to.
- Projects: a deleted project sits in the bin for 30 days, during which an owner can restore it, and is then permanently purged.
- Activity log: 365 days, then deleted automatically.
- Support requests: while your account exists, so we can see the history if you write again.
- Invoices and payment records: for as long as UK tax law requires (currently six years).
- Server and security logs: rotated routinely and kept only as long as needed for security and debugging.
- Backups: expire on a rolling schedule set at our hosting provider, so deleted data leaves backups within that window. See the Security page.
Your rights and how to use them
Under UK GDPR you can ask to access your data, correct it, delete it, restrict or object to how we use it, take it with you (portability), and withdraw consent where consent is the basis. Most of this you can do yourself:
- Export: a workspace owner can download everything in the workspace from Workspace settings → Export, and project tasks as CSV from a project’s board.
- Correct: change your name, email, password and preferences on your Profile.
- Delete: Profile → Delete account removes your account. Work you created inside a workspace stays with that workspace (it belongs to them), with your name removed from the account record.
- Email: change or stop notification email at Account → Notifications, or use the unsubscribe link in any notice.
For anything else, email privacy@taskshire.co.uk from the address on your account. We reply within one month. If you are unhappy with how we handled it, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
If your data is in a workspace run by someone else (your employer, say), it is usually quickest to ask them, and we will help them respond.
Security and breaches
How we protect data is set out on the Security page. If a breach puts your rights at risk we will tell the ICO within 72 hours of becoming aware, as the law requires, and tell affected people and workspaces without undue delay. To report a security problem, email security@taskshire.co.uk.
Children
Taskshire is for working teams and is not intended for anyone under 16. We don’t knowingly collect data from children; if you think we have, tell us and we will delete it.
Changes to this policy
We update this page when our practices change and show the date at the top. If a change matters to you, we will say so in the app or by email before it takes effect.
Contact
- Provider
- Taskshire
- Address
- [registered address]
- Privacy and data requests
- privacy@taskshire.co.uk
- Security reports
- security@taskshire.co.uk
- ICO registration
- [ICO registration number]
Signed in? You can also read the help centre or open a request from Help & support in the app.