← Home|
T
Tonic Pro
PrivacyTermsSecurity
Legal

Privacy Policy

How Tonic Pro collects, uses, and protects your personal data — in plain English.

Last updated: 11 July 2026

Tonic Pro is operated as a personal finance tool for UK users. We are committed to handling your data lawfully under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Tonic Pro is a trading name of GetTonic (“we”, “us”, “our”). We are the data controller for all personal data processed through this service.

Contact: hello@gettonic.co.uk
Website: pro.gettonic.co.uk


2. What Data We Collect

We collect only what is necessary to provide the service:

  • Account data: your email address and name, collected when you sign up via Clerk (our authentication provider).
  • Financial transaction data: records you choose to import from your bank CSV files. This data is processed in your browser and only the parsed transaction records are stored in our database — the raw CSV file is never uploaded to our servers.
  • Subscription data: your subscription status and billing history, managed by Stripe. We never store your card number or payment details.
  • Usage data: basic log data such as pages visited, timestamps, and browser/device type, used for security monitoring and service improvement.

3. Legal Basis for Processing

Processing activityLegal basis
Providing the subscription serviceContractual necessity (Article 6(1)(b))
Processing payments via StripeContractual necessity (Article 6(1)(b))
Sending billing receipts and service emailsContractual necessity (Article 6(1)(b))
Security monitoring and fraud preventionLegitimate interests (Article 6(1)(f))
Retaining subscription recordsLegal obligation — UK tax law (Article 6(1)(c))

4. How We Use Your Data

  • To create and manage your account
  • To store and display your imported transaction data
  • To process your subscription and send billing receipts
  • To send service notifications (e.g. trial ending, payment failed)
  • To investigate and prevent security incidents

We do not sell your data, share it with advertisers, or use it for any purpose beyond operating and improving Tonic Pro.


5. Third-Party Data Processors

We use the following sub-processors. Each is bound by a data processing agreement and complies with applicable data protection law.

ProviderPurposeLocationSafeguard
ClerkUser authenticationUSAStandard Contractual Clauses (SCCs)
StripePayment processingUSA / EUSCCs + PCI DSS Level 1 certified
SupabaseDatabase hostingEU (London, eu-west-2)Data remains in UK/EU region
VercelWeb hosting & CDNGlobal edge networkSCCs + SOC 2 Type II

6. Data Retention

  • Account and transaction data: retained for the duration of your active subscription. If you cancel, your data is retained for 90 days before permanent deletion, giving you time to export it.
  • Subscription and billing records: retained for 7 years to comply with UK tax and accounting obligations.
  • Security logs: retained for 90 days, then deleted.

You can request immediate deletion of your account and all associated data by contacting us at hello@gettonic.co.uk.


7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure:request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
  • Restriction: ask us to limit how we use your data while a dispute is resolved.
  • Portability: receive your transaction data in a machine-readable format (CSV export).
  • Objection: object to processing carried out on the basis of legitimate interests.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email us at hello@gettonic.co.uk. We will respond within 30 days.


8. Cookies

We use only essential session cookies required to keep you signed in. We do not use advertising cookies, tracking pixels, or analytics cookies that follow you across other websites.


9. Security

Your data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest in our database. We use row-level security so that only your account can access your records. For full details, see our Security Policy.


10. Changes to This Policy

We will notify you of any material changes to this policy by email at least 14 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.


11. Contact and Complaints

For any privacy-related queries, contact us at hello@gettonic.co.uk.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data protection authority:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
© 2026 GetTonic. All rights reserved.
Privacy PolicyTerms of UseSecurity