Privacy policy
Last updated 25 July 2026
Laravel (“we”, “us”) provides Making Tax Digital (MTD) software for UK sole traders, landlords, and CIS subcontractors. This policy explains what personal data we collect, why we use it, how we share it, and your rights under UK GDPR and the Data Protection Act 2018.
This policy covers the EasySubmit software service, including connection to HM Revenue & Customs (HMRC) Making Tax Digital APIs.
Who we are
EasySubmit is operated by EasySubmit, a United Kingdom organisation. We are the controller of personal data processed through EasySubmit.
We are registered with the UK Information Commissioner’s Office (ICO) as a data controller. Our ICO registration covers EasySubmit as part of the same registered organisation. ICO registration confirms we are listed on the public register; we still follow UK GDPR duties set out in this policy.
For privacy questions or data protection requests, contact hello@example.com.
Where you enter business or tax information about yourself for Self Assessment filing, we process that data to provide the service under this policy and our Terms of use.
Information we collect
Depending on how you use EasySubmit, we may collect:
- Account details — name, email address, login credentials, and related profile information.
- Business profile — business name, type, UTR, National Insurance number (NINO), VAT registration details where provided, and service preferences (self-employment, property, CIS).
- Cashbook and filing data — transactions, obligations, submissions, year-end state, reports, and related audit events.
- Technical and usage data — device/browser type, IP address, timestamps, and similar logs needed to operate, secure, and improve the service.
- Support communications — messages you send us about your account.
HMRC Making Tax Digital
If you choose to connect EasySubmit to HMRC for Making Tax Digital for Income Tax (or related HMRC services we enable), we will process additional information needed for that connection:
- Authorisation tokens — OAuth access and refresh tokens issued by HMRC after you grant permission. You can revoke access via HMRC or by disconnecting in EasySubmit where available.
- Tax identifiers and business details — such as NINO, UTR, business IDs, and income-source details returned by HMRC APIs, only as needed to provide MTD features.
- Income, expenses, and submission data — summaries and related figures you choose to submit, retrieve, or store in EasySubmit for quarterly updates, year-end adjustments, other income, and Final Declaration workflows.
- Fraud prevention header data — device, browser, network, and software metadata that HMRC requires by law to be sent with MTD API requests (for example connection method, device ID, public IP, timezone, screen/window size, and product name). We collect and transmit this data to HMRC solely to meet that legal requirement when you use connected HMRC features.
- Payment journey data — when you choose Pay HMRC, we send your UTR and a suggested amount to HMRC’s Initiate Payment API and store the journey ID and status returned by HMRC.
Connecting to HMRC is optional. We only access HMRC data after you authorise EasySubmit. We do not use HMRC-connected tax data for marketing. You remain responsible for the accuracy of information submitted to HMRC and for meeting your tax obligations.
How we use information
We use personal data to:
- provide, maintain, and secure the EasySubmit service;
- support your account and respond to requests;
- send service and security emails (and billing emails if paid plans become available);
- improve the product and understand usage (including limited analytics);
- comply with legal obligations, including fraud-prevention requirements when using HMRC APIs; and
- enable optional HMRC MTD features you choose to use.
Lawful bases
We typically process personal data:
- to perform our contract with you (providing the software);
- for legitimate interests in operating, securing, and improving the service;
- to meet legal obligations (including HMRC fraud-prevention header requirements where applicable); and
- where consent is required (for example optional marketing), we will ask for it and you can withdraw it.
Sharing
We do not sell your tax data. We may share data with:
- Service providers — trusted processors such as UK hosting and email delivery providers, under appropriate agreements and only to operate EasySubmit.
- HMRC — when you authorise a connection and use MTD features, we send and receive data via HMRC APIs as required to provide that functionality, including mandatory fraud-prevention headers.
- Legal and safety — where required by law, regulation, court order, or to protect rights, safety, or the integrity of the service.
HMRC’s own use of information you submit through MTD is governed by HMRC, not by this policy.
Where we process data
EasySubmit is intended for UK customers. Our application and primary database are hosted in the United Kingdom (UK-hosted infrastructure). We do not intentionally store customer tax records outside the UK.
Some supporting processors (for example transactional email) may handle limited account contact data. Where any processing occurs outside the UK, we use appropriate UK GDPR safeguards.
Retention and security
We retain account and filing data while your account uses EasySubmit and for a reasonable period afterwards if needed for legal, accounting, dispute, or security reasons (including evidencing submissions). HMRC authorisation tokens are retained while the connection remains active and deleted or invalidated when you disconnect or the grant expires.
We apply appropriate technical and organisational measures to protect data, including encrypting HMRC access tokens and sensitive tax identifiers (such as NINO, UTR, and VRN) at rest in the application database, TLS for data in transit, authentication, role-based access, and tenant isolation. No method of transmission or storage is completely secure; please keep login details confidential and use strong passwords.
Your records and export
You own your business content in EasySubmit. Where features allow (for example printable reports and submission history), you can retain copies of records you need. For HMRC MTD, digital record-keeping and export expectations also apply under HMRC’s rules — we design EasySubmit so you can access and retain your records as required.
Your rights
Under UK GDPR you may have rights to request access, correction, deletion, restriction, or portability of personal data we hold about you, and to object to certain processing. You may also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Cookies and similar technologies
We use cookies and similar technologies that are necessary to keep you signed in, protect security, and operate the service (including a device identifier used for HMRC fraud-prevention headers when you connect or submit). Where we use non-essential analytics or marketing cookies, we will provide appropriate controls.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of EasySubmit after an update means you accept the revised policy, except where applicable law requires otherwise.
Contact
Privacy requests: hello@example.com. Controller: EasySubmit.