
Version 6.0, 05 August 2026
This Privacy Policy explains how Coconut and GoSimpleTax collect, use, share, retain and protect personal information, and the rights available to individuals.
It applies to visitors to our websites, users of our online services and mobile applications, prospective and existing customers, people who contact us, and individuals whose information is provided through a customer’s use of our services. It applies wherever our services are offered; local law may provide additional rights.
For the purposes of the UK General Data Protection Regulation (UKGDPR), the Data Protection Act 2018, as amended, including by the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations 2003 (PECR), and other applicable privacy laws, the relevant company will normally be the data controller.
The data controllers covered by this policy are:
@GoSimpleTax Limited, trading as “@GoSimpleTax”, “Landlord Calculator” and “SalaryCalculator Pro”
Company number: 08793323
ICO registration number: ZA770578
@Coconut PlatformLimited, trading as “Coconut” and “Get Coconut”
Company number: 09904418
ICO registration number: ZB804847
Each company acts as a separatedata controller for its productsand services. “We”, “us” and “our”
mean the company responsible for the productor service you use.
5 Cromwell Court,
Oldham,
OL1 1ET,
Privacy and compliance enquiries: compliance@getcoconut.co.uk.
The information we process depends on the product or service you use and may include:
· Identity and contact information: name, title, date of birth, residential or business address, email address and telephone number.
· Business and account information: business or employment details, account-registration data, usernames, encrypted password information and authentication records.
· Financial, accounting and tax information: transactions, connected-account data, tax returns, income and accounting records, Unique Taxpayer Reference numbers and other tax identifiers.
· Payment and subscription information: purchase history, invoices, payment records, mandates, refunds, failed payments, chargebacks and subscription details.
· Identity-verification and support information: verification outcomes, correspondence, support records, complaints, disputes, investigations, feedback and reviews.
· Technical and usage information: IP address, device, browser and operating-systemdetails, pages visited, dates and times, cookie and online identifiers, and how you use our services.
· Security and preference information: fraud-prevention data, security-event records, marketing preferences and consent or suppression records.
Please do not provide special-category personal information unless it is necessary for the service or enquiry. Where we process it, we will identify an appropriate lawful basis and additional processing condition.
We may obtain personal information directly from you or someoneacting with your authority; through your use of our websites and applications; from financial institutions, TrueLayer and other connected-account providers; from Zempler Bank and other commercial partners; from payment, identity-verification, fraud-prevention and security providers; from public registers, HM Revenue & Customs, regulators and law-enforcement bodies where permitted; and from suppliers that support our business.
Where a customer provides information about another person,the customer is responsible for ensuring they are authorised to do so and that the person receives any required privacy information.
We use personal information to:
· create and administer accounts and provide tax, accounting, financial-account and other requested functionality;
· process payments, subscriptions, refunds and related transactions;
· verify identity, authenticate access and send service or security communications;
· provide support, handle complaints and disputes, and invite or publish customer feedback;
· monitor, secure, maintain, improve and develop our services, systemsand business operations;
· detect and prevent fraud, crime, misuse and unauthorised access; and
· meet legal and regulatory obligations, respond to authorities, recoverdebts and establish, exercise or defend legal claims.
Telephone calls, emails, SMS messages, webchats, video calls and other communications may be recorded or retained where appropriate for support, training, quality monitoring, fraud prevention, complaints and record-keeping.
We processpersonal information only where a valid lawful basis applies:
· Contract: where processing is necessary to enter into or performa contract, including account administration, service delivery, payments, support and authentication.
· Legal obligation: where processing is required by legal, tax, accounting, regulatory, fraud-prevention, financial-crime or reporting requirements.
· Legitimate interests: where necessary to operate and improve our business, support customers, maintain records, protect systems and accounts, prevent fraud, recover debts, obtain feedback, resolve disputes and protect legalrights, provided those interests are not overridden by your rights.
· Consent: for optional activities such as certain marketing communications, non-essential cookies or other processing where you have made a clear andinformed choice.
Where information is required to provide a service, failing to provide it may mean that we cannot create or maintain your account or provide that service. You may withdraw consent at any time without affecting processing already carried out. Some rights may be restricted where the law permits, including to protect investigations, crime prevention or anotherperson’s rights.
SMS authentication messages are service and security messages, not marketing. Their UK GDPR lawful basis will normally be contract and/or legitimate interests rather than consent.
We process technical and usage information to operate, secure and improve our websites and applications. We use cookies and similar technologies for essential functionality, analytics and user experience. Our Cookie Policy explains the cookies we use and the choices available to you.
We may share personal information where necessary with authorised suppliers and recipients, including Amazon Web Services; TrueLayer and financial institutions; Twilio and telecommunications carriers; Stripe,Stripe Identity, GoCardless and PayPal; Trustpilot; providers of customer support, communications, analytics, website technology, identity verification, fraud prevention and information security; banks, insurers and professional advisers; potential purchasers or investors; HM Revenue & Customs, the Financial Conduct Authority, other regulators, law-enforcement bodies, courts and tribunals; and anyone you authorise or where disclosure is required orpermitted by law.
Suppliers acting as processors may use information only for authorised purposes and must apply appropriate confidentiality and security safeguards. Organisations processing information for their own purposes act as separate controllers and are responsible for their own privacy obligations.
Mobile telephone numbers, SMS opt-in information and SMS consent records are not shared with third parties or affiliates for marketing or promotional purposes.
Coconut uses TrueLayer to let customers connect supported financialaccounts on a read-only basis and display account and transaction information. TrueLayer and the relevant financial institution may process identity, account,consent and technical information to establish and maintain the connection. We receive only the information you authorise, and TrueLayer’s own terms and privacy information also apply.
OpenCalc can be used without a registered GoSimpleTax account.Information entered is processed to perform the requested calculation and, unless the user registers or saves it, is intended to be removed when the browser session ends. Do not enter another person’s information unless authorised.
We do not centrally store complete credit or debit card details. Coconut payments may be processed by GoCardless for Direct Debits and Stripe for card payments; GoSimpleTax payments may be processed by Zoho, Stripe andwhere selected, PayPal.
These providers may process payment, transaction, contact, deviceand account information to complete payments, managesubscriptions, prevent fraud,handle disputes and meet legal or regulatory obligations. Recurring payments may use a secure token, mandate or customer reference so that we do not store complete card or bank-account details.
Where identity verification is required, we may use Stripe Identity or another authorised provider. The provider may collect information directly; we may retain a limited record of the process and outcome rather than a complete copy of the identity information submitted.
This section applies principally to Coconut customers using SMS authentication, including customers in the USA and other third countries. Coconut may send one-time passcodes and other transactional security messages to verify login or account-security activity and protect accounts from unauthorised access.
We may process your mobile number, Coconut account identifier, the date and time of the request,one-time-passcode and related message content, sender and recipient numbers, message and delivery identifiers and status, IP address and device information, the related login or security event, and STOP or HELP request records.
Coconut uses Twilio, its authorised processors and telecommunications carriers to transmit and administer these messages. They may process mobile numbers, message content and associated usage and delivery information where necessary to transmit, route, secure and support the service.
For international customers including those in the USA, providing your mobile number and enabling SMS authentication or requesting a security code authorises Coconut to send these messages. They are sent in response to your login, authentication or account-security activity. Message frequency varies. Message and data rates may apply.
You may reply STOP to stop SMS messages or HELP for assistance. Stopping messages will disable or prevent SMS authentication, so you may need another authentication method or support to regain access.
Authorisation applies only to Coconut messages and is not transferred to another business, affiliate or sender. We do not use authentication messages for advertising, sell or rent mobile numbers or SMS consent information, or share them for third-party or affiliate marketing. Information may be disclosed only to providers needed to operate the service or where required by law.
We process SMS information to provide the requested authentication service and for legitimate interests in account security, fraud prevention, network and information security, investigation of suspicious activity and legal claims.
One-time-passcode message contentis retained for no longer than 30 days, unless reasonably required for a security incident, investigation, dispute or legal obligation. SMS delivery, authentication and security records may be retained for up to 400 days. STOP and other suppression records are retained for as long as needed to respect the request and, where appropriate, for a further two years as evidence of compliance.
We may send customers a Trustpilot review link or provide limited information, such as name, email address and a transaction or service reference, so Trustpilot can issue and verify an invitation. Trustpilot processes information under its own terms and privacy notice.
Where permitted, we may display reviews on our websites or social-media channels without materially changing their meaning. You may ask us to stop review invitations or remove a review from our own materials; removal from Trustpilot is subject to its procedures. Coconut SMS authentication information is not provided to Trustpilot for marketing or promotional purposes.
We and our suppliers operate internationally, so personal information may be processed or accessed outside the United Kingdom. Where a restricted transfer occurs, we use a recognised safeguard, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, approved Binding Corporate Rules, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised mechanism. We may also conduct a transfer-risk assessment and apply supplementary safeguards.
Twilio and its processors may process communications and SMS information in the United States and other countries. You may contactus for information about the safeguards used for a particular transfer or a copy of relevant contractual protections, subject to necessary redactions.
We retain personal information only for as long as reasonably necessary for the purpose collected, taking account of legal, tax, accounting and regulatory requirements, applicable limitation periods, fraud and security risks, complaints, investigations, disputes and legal claims. Financial and tax records are generally retained for seven years.
| Data category | Examples | Lawful basis | Retention period |
|---|---|---|---|
| Customer tax data | Tax returns, income data and financial records | Legal obligation; legitimate interests | 7 years |
| Customer account information | Name, email, contact details, preferences and account records | Contract; legitimate interests | 7 years |
| Payment and transaction records | Invoices, card payments and Direct Debits | Legal obligation; legitimate interests | 7 years |
| Customer-service communications | Complaints, queries and support logs | Legitimate interests; legal obligation | 7 years |
| Marketing preferences and consents | Opt-in and unsubscribe records | Consent; PECR/legal obligation | Until withdrawn, plus 2 years |
| One-time-passcode content | OTP and related SMS message content | Contract; legitimate interests | Up to 30 days |
| SMS authentication and security records | Mobile number, delivery and status data, timestamps, identifiers and security events | Contract; legitimate interests | Up to 400 days |
| SMS suppression records | STOP and related opt-out records | Legal obligation; legitimate interests | While needed, plus up to 2 years |
Information may be kept longer where legal action, an investigation or another retention hold applies. Information retained for analytics or research beyond the normal period will be anonymised. When no longer required, information is securely deleted, anonymised or otherwise disposed of, including by permanent deletion, secure overwriting or shredding where appropriate.
We use appropriate technical and organisational measures to protect personal information against loss, alteration, unauthorised disclosure or access and other unlawful processing. Measures may include access controls and authentication, encryption, logging and monitoring, security testing, supplier due diligence, contractual safeguards, incident-response and business-continuity arrangements, staff training, data minimisation and retention controls.
No electronic system or transmission method is completely secure. You are responsible for keeping login and authentication information confidential and should notify us promptly if you suspect unauthorised account access.
Depending on your location, the information and the lawful basis used, you may have rights to:
· Access: receive copies of your personal information and supporting information about its use.
· Rectification: correct inaccurate or incomplete personal information.
· Erasure: ask us to delete personal information where the law permits.
· Restriction: ask us to limit how we use personal information.
· Objection: object to processing based on legitimate interests or for direct marketing.
· Portability: receive or transfer certain information you provided to us ina structured, commonly used and machine-readable format.
· Withdraw consent: withdraw consentat any time where consentis the lawful basis.
To exercise a right, email compliance@getcoconut.co.uk and provide enough information for us to identify you, locate the records and understand the request. We may request proportionate evidence of identity. Under UK law, we normally respond within one month, although this may be extended for complex or numerous requests. Rights are subject to legal conditions and exemptions.
How to Complain
Please first contact compliance@getcoconut.co.uk with any concern about how we process personal information. We will investigate and respond under our complaints and privacy procedures.
If you are in the United Kingdom and remain dissatisfied, you may complain to:
Information Commissioner’s Office(ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone 0303 123 1113
If you are outside the United Kingdom,you may also have the right to complain to the relevant privacy, or supervisory authority within your resident jurisdiction.
We may update this policy to reflect changes in our services, technology, suppliers, legal obligations or processing activities. Where changes are material, we will take reasonable steps to notify affected users through our website, application, customer account or email before they take effect.

We use cookies to provide you with the best possible experience and analyze usage to improve our site.
See our Cookies Policy