Privacy
Privacy
Last updated 4 August 2026.
The short version
We hold your account details, the business details you put on your letterhead, and the searches and leads you save. We do not sell any of it, we do not track you around the internet, and there is no analytics or advertising code on this site at all. Planning data comes from public registers and is not about you.
Who we are
Tradecue is the data controller for the personal data described here. 21days is a Tradecue product for people watching planning near their home. Write to support@tradecue.co.uk about anything on this page, including a request to see or delete what we hold.
What we hold, and why
- Your account. Email address, a hashed password, optionally your name, and if you turn on two-step verification, its secret and recovery codes. Needed to give you an account at all. Lawful basis: performance of a contract.
- Sessions. A hash of your session token, the time, your browser’s user agent and your IP address. Needed to keep you signed in and to let you recognise and revoke a session that is not yours. Lawful basis: legitimate interests in securing accounts.
- Your business details. Company name, contact name, address, phone, reply address, website, a short trade summary and your logo. These exist to fill the letterhead on letters you write, and appear on the letters you print.
- What you save. Alerts and the places they watch, the applications you track and the tags you put on them, your pipeline and its contact notes, and the letters you write — stored as written, so a letter you posted is not rewritten later by a change to a template.
- Alert destinations. Any extra email address or mobile number you add for alerts, and whether it has been confirmed. Nothing is sent to either until you confirm it from a link or code sent to it.
- Feedback you send. Your message, the page you were on, your browser user agent, and a reply address if you give one. To stop the form being abused we also keep a salted hash of the sender’s IP address — never the address itself.
Cookies
Two, and here is what each one does.
- gw_session keeps you signed in. It holds a random token, not your details, and deleting it signs you out.
- gw_searches counts how many searches you have run, up to three, so we can wait until your third before asking you to sign up. It is a single small number — no identifier, and no record of what you searched for. It stops counting at three, so it cannot turn into a picture of how much you use the site, and it expires after 30 days.
There is no analytics, no advertising and no third-party tracking on this site. Nothing here follows you elsewhere.
Who else sees it
- Resend sends our email, so an address we email is processed by them.
- Twilio sends text alerts, if you set one up, and sees the number.
- Stripe takes payment if you subscribe, and holds your card, billing address and invoices. We never receive the card number — it is entered on Stripe’s own page, not ours. What we keep is an identifier for you in their system and whether the subscription is running.
- Cloudflare runs the check on the sign-up and sign-in forms that tells a person from a script, where that is switched on. It sees the request, not the password.
- postcodes.io resolves place and postcode searches. What you type in a search box goes to them; who you are does not.
- OpenStreetMap serves map tiles, so your browser requests tiles for the area you are looking at directly from them.
That is the full list. We do not sell personal data and we do not share it for anyone else’s marketing.
Planning data is not personal data about you
Applications, addresses and decisions come from public planning registers, the Planning London Datahub and planning.data.gov.uk. Councils publish them, and they redact homeowners’ phone numbers and email addresses before doing so. We hold no homeowner contact details, which is why letters are addressed to the property.
If you are an applicant and want to discuss what a council has published about you, the council is the place to start — they are the source and the authoritative record. Tell us as well and we will correct our copy.
How long we keep it
Account data for as long as you have an account, and until you ask us to delete it. Sessions expire after 30 days. Password-reset and confirmation links expire in an hour and a week respectively. Feedback and its IP hash are kept while we are dealing with it and for a reasonable period afterwards.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to how we use it. Email support@tradecue.co.uk and we will answer within a month. If you are not satisfied you can complain to the Information Commissioner’s Office.
Where it is held
On servers in the EU. Our email and text providers may process data outside the UK under their own transfer safeguards.