Privacy Policy
Last updated: 5 August 2026
1. Who we are
CostCreep is a supplier-cost assurance and recovery service operated by Costcreep Ltd (company number 17369484), registered at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ ("CostCreep", "we"). We check our customers' supplier invoices against their own buying history and agreed rates, raise challenges with suppliers on their behalf, and track recoveries. For questions about this policy or your data, contact privacy@costcreep.co.uk.
We are registered with the Information Commissioner's Office under number ZC209669.
2. The three groups of people this policy covers
Visitors to this website. We collect very little: server logs and, if you contact us, whatever you send us.
Users of the CostCreep application. Our customers' owners, staff and advisers who sign in. For this data we are the controller.
People who work at our customers' suppliers. When a customer connects their accounting data, the invoices and contact records in it include names, business email addresses and phone numbers of people at their suppliers, and CostCreep sends emails to some of those addresses on the customer's behalf. For this data our customer is the controller and we act as their processor, under our Data Processing Agreement. Section 8 below explains what this means if that's you.
3. What we collect and why
Account data (we are controller)
- Name, email address and sign-in credentials (authentication is handled by our identity provider; we never see your password).
- Billing details when you subscribe, handled by our payment provider — we do not store card numbers.
- Product activity needed to operate the service: what was approved, edited, sent and when, kept as an audit trail your business can inspect and export.
Customer business data (we are processor)
- Invoice and purchase data from your accounting platform (read-only), uploaded files, and supplier price lists.
- Supplier contact details — accounts email addresses and phone numbers, whether synced, uploaded or learned from correspondence.
- Correspondence between the cost-review function and suppliers, including replies.
Lawful bases: performance of our contract with you; our legitimate interest in operating, securing and improving the service; and legal obligations (for example, accounting records). We do not sell personal data, and we do not use your business data to train models or benchmark you against other customers without separate, explicit consent.
4. Emails sent to suppliers
Where a customer instructs it, CostCreep sends invoice and pricing queries to the customer's suppliers. Every such email is sent by a declared cost-review function acting for the named customer — never an invented person — states the relationship in the body, and offers a direct way to verify it with the customer. The customer controls whether each email is sent.
5. Who we share data with
Only service providers who process it for us, under contract: hosting and database infrastructure, identity/authentication, transactional email delivery, document-reading (OCR), encrypted off-site backup storage, application error monitoring, and payment processing. The current list, including locations and transfer safeguards, is in the DPA's sub-processor annex. We also share data where the law requires it. Some providers are outside the UK; where they are, transfers rely on the UK Addendum to the EU Standard Contractual Clauses or an adequacy decision.
6. How long we keep it
Account and business data are kept while your subscription is active. On closure, you can export everything we hold, and we delete your company's data — including uploaded files in storage — within 30 days of a deletion request, except what we must keep by law. Server logs rotate within 90 days. We take encrypted off-site backups daily so the service can be restored after a failure; these cannot be edited selectively, so deleted data persists in them until each backup expires, within 35 days. Backups are never read for any purpose other than restoring the service.
Supplier correspondence (emails sent to and received from a customer's suppliers) is kept while that customer's account is active, because it forms part of the customer's evidence and audit trail, and is deleted with the customer's data. Suppression-list entries — the email addresses of people who have asked not to be contacted — are kept for as long as needed to honour that request, and are used for no other purpose.
7. Security
Data is encrypted in transit and at rest, access is limited to what each account is entitled to see, every company's data is isolated from every other's, and accounting connections are read-only by construction. A summary of technical measures is in the DPA.
8. If you work for one of our customers' suppliers
You may have received an email from a CostCreep address on behalf of one of your customers. What we hold about you is limited to business contact details and the correspondence itself, processed on our customer's instructions so that they can query invoices with your company. If you'd rather we didn't email you, reply saying so or write to privacy@costcreep.co.uk — we keep a suppression list and honour it. For rights requests about this data we may refer you to the customer, who is the controller, but we'll always help route it.
9. Your rights
You have the rights UK GDPR gives you: access, correction, deletion, restriction, portability and objection, and the right to withdraw consent where consent was the basis. Write to privacy@costcreep.co.uk; we respond within one month. If you're unhappy with our answer you can complain to the ICO at ico.org.uk.
10. Cookies
The application uses strictly necessary cookies and local storage for signing you in. This marketing site sets no analytics or advertising cookies.
11. Changes
We'll post changes here and, for material changes affecting application users, tell you by email. Continued use after a change takes effect means the updated policy applies.