TempDash — Worker Privacy Policy
Version 1.3 — Effective Date: 3 October 2026
1. Who we are
TempDash Ltd (Company No. 17264372) is the Data Controller for the personal data we collect from Workers and Practices using the TempDash App. TempDash is a trading name of TempDash Ltd, a company registered in England and Wales.
Registered office: 124 City Rd, London EC1V 2NX Data Protection contact: support@tempdash.app ICO registration number: ZC159507
If you have a concern about how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO) at https://ico.org.uk/ or 0303 123 1113.
2. Scope
This Policy explains how we collect, use, share and protect personal data when you (a) browse our website, (b) register or use the TempDash App as a Worker, or (c) interact with our support team. It is written to comply with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations ("PECR").
3. The data we collect
3.1 Identity, contact & profile
Name, date of birth, photograph, postal address, email, mobile number, professional role, GDC number, and your National Insurance number (your UK Taxpayer Identification Number, collected so we can meet our annual HMRC digital-platform reporting obligation — see clauses 5 and 7).
3.2 Right-to-work and identity verification (VouchSafe)
Government-issued ID (passport / BRP / driving licence), a "live" facial selfie, and the biometric template generated from comparing your selfie to your ID document.
3.2a Verified facial portrait
We keep our own copy of the facial image captured during the identity check described in clause 3.2 (your "verified facial portrait"). This is held separately from any profile photograph you choose to upload yourself, and it is the image shown on your TempDash ID, including to a Practice that has booked you (clause 7).
The portrait is held in a private, access-controlled store. It is never published, never shown on your public profile, and never made available at a public web address; it is released only as a short-lived link generated at the moment an authorised person views your TempDash ID. We do not use it for facial recognition, facial matching, or any other automated comparison (clauses 3.9 and 5).
3.3 Compliance & professional data
GDC registration status, DBS certificate, Hepatitis B immunity proof, indemnity certificate, right-to-work share code, professional CV.
3.4 Location data
Your home address, which you give us and which we use to show you shifts within reach and to work out travel times. Your device's location, only at the moments set out in clause 6: when you clock in and clock out, when you tap On my way, when your arrival at the workplace is detected, when you claim hours for a missed shift, and when you add a location sticker to a story. We do not track your location continuously, and we do not use your device's location to choose which shifts you see.
3.5 Shift, performance & reliability data
Shift offer activity, accept/decline outcomes, clock in and clock out times, whether each clock in was confirmed by location, missed shifts, hours you claim for a missed shift and how many claims you have made, timesheet hours, ratings/reviews, cancellations, strikes, no shows and any pause on your account. Attendance is recorded only through your clock in and your approved timesheet; workplaces do not report it.
3.6 Financial data
We do not store your full bank or card details. Your bank, card and identity-check information is held securely by our regulated payment provider, Stripe Payments Europe, Limited ("Stripe"), under their own responsibility. We keep only your payout status, fee summaries, any balance or payout-speed preferences, and the name of the bank your payout account is with and the last four digits of that account, so we can show you where your money goes.
3.7 Device, technical & usage data
IP address, device type and OS, app version, log files, push-notification tokens, crash diagnostics, in-app session activity.
3.7b When you tend to open the App, and what we send you
So that we can tell you about work at a time that is useful to you rather than at whatever moment a timer happened to go off, we keep a record of the days of the week and the hours of the day you tend to open the App, and a record of every notification we decided to send you or decided not to send you, including which one it was, whether it reached you, and whether you opened it.
We also work out, from shifts you have already taken, which days and times of day you tend to work, how far in advance you tend to book, and roughly the rate at which you take work.
This is explained in full in clause 11.3, including what it is used for and, just as importantly, what it is never used for.
3.7a Devices you are signed in on
So that you can see and control where your account is being used, and so we can stop someone else using it, we keep a record of each device you sign in from: a device name (for example "Pixel 8"), the platform, when it was last used, the IP address it was last used from, and an approximate location (city and country) worked out from that IP address. You can see this list in the App under Settings → Security, sign any device out, and we can block a device and stop payments if your account is at risk.
We do not use this to track your movements. The location is city-level only, it is derived from the network address rather than your device's GPS, and it is shown to you rather than used to make decisions about you.
3.8 Communications
Messages exchanged with TempDash support; the content of, and (where recording is enabled, with notice) the audio recordings, transcripts and notes of, telephone calls we place to you or that you make to us; and emails to/from us.
If our support team needs a document to resolve something you have asked about (for example a photo of your ID, proof of address or a certificate), they ask for it by name in the support chat and you upload it there. We use it only for that request. Our team then either keeps it with your account records or deletes it; see clause 9.
3.9 Special-category data
Biometric data (clause 3.2) and limited health data (Hepatitis B immunity) are special-category personal data under Article 9 UK GDPR. We process these only as set out in clause 5.
The verified facial portrait we retain under clause 3.2a is not special-category data, for the reasons set out in clause 5.
We do not process patient clinical data; that data is held by the Practice as controller.
3.10 Connected-service data (optional)
If you choose to connect an external calendar (such as Google Calendar) so your booked shifts appear there automatically, we store the authorisation (an access/refresh token) that lets us add those events on your behalf, and the identifiers of the calendar events we create. You can disconnect at any time (clause 6A). We do not access this connected service for any purpose other than placing your TempDash shifts in your calendar.
4. How we collect it
Directly from you on registration; from VouchSafe's verification flow; from Stripe in respect of payouts and KYC checks; from Practices in respect of ratings and their answers on your hours (approving or querying them); automatically from your device when you use the App.
5. Lawful basis for processing (Article 6 / Article 9)
Our purposes and the lawful bases we rely on are:
- Creating and operating your Worker account — identity, profile, device data — Performance of contract (Art. 6(1)(b)).
- Verifying right to work (VouchSafe) — identity documents and biometric template — Legal obligation (Art. 6(1)(c) — Immigration, Asylum and Nationality Act 2006); special-category basis: substantial public interest (preventing illegal working) under Art. 9(2)(g) and Sch 1 Pt 2 DPA 2018.
- Verifying GDC registration & DBS — compliance data — Legal obligation / Legitimate interests (Art. 6(1)(c)/(f)) on patient-safety grounds; substantial public interest (regulatory requirements relating to professional standards).
- Retaining and showing your verified facial portrait — the facial image captured at the identity check (clause 3.2a) — Performance of contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in identity assurance at the workplace and in the prevention of identity fraud, so that a Practice can satisfy itself that the person attending a shift is the person who was verified and booked. This processing does not engage Article 9. We retain and display a photograph; we do not process it through technical means for the purpose of uniquely identifying a natural person, which is what would make it biometric data within Article 4(14). We operate no facial recognition, facial matching or other automated comparison against that image, and none is performed on our behalf. You may object to processing based on legitimate interests (clause 10); we may then be unable to make you available for bookings that depend on identity assurance at the workplace.
- Operating the Smart Matching service — profile, home address, the shifts you have shown interest in — Legitimate interests (Art. 6(1)(f)) in operating a marketplace.
- Showing you shifts within reach and working out travel times — your home address and travel preferences — Performance of contract (Art. 6(1)(b)).
- Confirming attendance and paying for hours worked — the location points recorded at clock in and clock out, your distance from the workplace, whether the clock in was confirmed by location, and the hours you claim for a missed shift — Performance of contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in paying for hours that were worked, quickly where location confirms them, and in resolving questions about hours and payments fairly. Location is optional: with it off you can still clock in, and the workplace confirms your hours before they are paid (clause 6.2). You can object to processing based on legitimate interests (clause 10).
- Telling the workplace you are on your way or have arrived — the time you set off, your estimated arrival time, the time you arrived and your home address for the travel estimate — Legitimate interests (Art. 6(1)(f)) in letting the workplace know when to expect you. The On my way and arrival location points are not shown to the workplace; we keep them only as evidence if a question about your hours comes up (clause 6.1). You can turn Share my arrival time off at any time (clause 6.3).
- Processing payments via Stripe — earnings, Stripe IDs — Performance of contract.
- Adding your booked shifts to a calendar you connect — shift details (title, practice, address, time) and the connected-service authorisation — Performance of contract / your consent given when you connect the calendar (Art. 6(1)(b)/(a)).
- HMRC digital-platform reporting — name, date of birth, registered address, National Insurance number (as your UK Taxpayer Identification Number) and total platform earnings — Legal obligation (Art. 6(1)(c) — Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023, SI 2023/817, in force 1 January 2024). We are a "reporting platform operator" and must report this to HM Revenue & Customs once each calendar year.
- AML / fraud / sanctions monitoring — identity, financial, device — Legal obligation (Money Laundering Regulations 2017) and legitimate interests; substantial public interest for special data (fraud prevention).
- Keeping your account and your money secure — the devices you sign in from, their approximate (city-level) location, and records of changes to your payout bank account — Legitimate interests (Art. 6(1)(f)) in protecting your account and your earnings from unauthorised access. This is why we tell you whenever a bank account is added, why a newly added account cannot receive money straight away, and why you can see and sign out your devices. You can object to processing based on legitimate interests (clause 10), though we may need to keep security records to protect you and other Workers.
- Reliability scoring, ratings, dispute resolution — performance (including missed shifts and claims for them), communications — Legitimate interests in fairness and platform safety.
- Service notifications (push / email transactional) — contact, device — Performance of contract / legitimate interests.
- Deciding which notifications about available work you receive, and when — the times you tend to open the App, the days and times you have worked, how far ahead you book, the rate at which you take work, and the record of notifications we have sent you — Legitimate interests (Art. 6(1)(f)) in telling you about work you are likely to want, at a time you are likely to see it, and in not sending you more messages than are useful. Because this is profiling connected to direct marketing, you have an unconditional right to object and we will stop (clause 10). Turning it off costs you nothing: see clause 11.3.
- Signing up on our website — the name and email you give us at tempdash.app/signup — Legitimate interests (Art. 6(1)(f)) in helping you finish the sign up you started. We email you a code to confirm the address, a welcome, and a small number of reminders to finish signing up. Every reminder has a link to stop them, and they stop once you have an account.
- Marketing emails (news and offers about TempDash) — contact — Legitimate interests (Art. 6(1)(f)), relying on the "soft opt-in" in regulation 22 of PECR, which lets us email you about our own similar services when you have signed up with us. You can say no when you sign up, at any time in the App (Wallet, then Settings), and with the unsubscribe link in every marketing email (or your email app's own unsubscribe button). Saying no stops our marketing and our sign up reminders to that address. Emails about your account, your shifts and your pay still arrive.
- Personalised partner offers — the name of the bank your payout account is with — Legitimate interests (Art. 6(1)(f)) in showing you financial offers that suit you and in funding the platform; see clause 5.2. Because this is profiling connected to direct marketing, you have an unconditional right to object and we will stop: switch off Personalised offers in the Wallet at any time.
- Defending legal claims — all relevant data — Legal obligation / legitimate interests; for special-category data, establishment of legal claims (Art. 9(2)(f)).
Legitimate interests assessments (LIAs) for the items above are documented internally and available on request.
5.1 Explicit consent for biometric processing
Where biometric data is processed by VouchSafe, that processing relies in addition on your explicit consent, given when you initiate the verification flow. You may withdraw consent at any time by emailing support@tempdash.app; withdrawal does not affect the lawfulness of prior processing and may prevent you from continuing to use the App, since right-to-work verification is a regulatory pre-condition.
5.2 Personalised partner offers, and your right to object
The Wallet shows offers from financial partners, such as a bonus for switching bank account or a way to check your credit report. Unless you switch it off, we use the name of the bank your payout account is with to choose which offers you see, so that, for example, you are not shown an offer to switch to the bank you already use. Our lawful basis is legitimate interests (Art. 6(1)(f)): showing you offers that are relevant rather than random, and earning referral fees that help fund TempDash. We have weighed those interests against yours and recorded that assessment.
- The Wallet tells you this where the offers appear, and Personalised offers there and in Wallet preferences switches it off in one tap. Your right to object to direct marketing is absolute: once you switch it off we stop, with no reason needed, and TempDash works exactly the same.
- We record when you switched it on or off and which version of this wording applied.
- We never pass your bank details, account number or balance to a partner. If you tap an offer, you leave TempDash for the partner's own website, which has its own privacy policy. The link may tell the partner you came from TempDash, and we may be paid if you take up the offer.
- With personalisation off you may still see general offers that are the same for everyone and are not based on your data.
- We do not send you offers by email, text or push notification under this clause. If we ever do, we will ask you first.
- An offer is information about a third party's product, not advice or a recommendation. Always read the partner's terms.
6. Location data — specific notice
6.1. When we read your device's location. Only at the moments below, only if you have already allowed TempDash to use location in your device settings, and once each time. We do not track your location in between.
- Clocking in and clocking out. We record your location once when you clock in and once when you clock out, to confirm you are at the workplace. We store the position, how accurate your device said it was, your distance from the workplace, whether the clock in was inside the workplace zone, how you clocked in (with location, without location, or by claiming hours) and whether you chose "Clock in anyway" when the App showed you outside the zone.
- On my way and arriving. If Share my arrival time is on, we record one location point when you tap On my way, or when your phone detects that you have left home (clause 6.3), and one when your arrival at the workplace is detected, together with the time you set off, your estimated arrival time and the time you arrived. When you open a booked shift close to its start, the App may check your location once on your phone to see whether you have arrived; nothing is sent unless you have.
- Claiming hours for a missed shift. We record one location point when you submit a claim (clause 6.4), if your device provides one. A claim never needs it.
- Story location stickers. If you add a location sticker to a story, we read your location once to suggest a place name. The position is sent to a postcode lookup service (postcodes.io) and to your device's own place name service to find that name. Only the place name you choose appears on the story.
6.2. Location is optional, and how it affects pay. You can always clock in, whether location is off, cannot be read, or shows you outside the workplace zone. Only a clock in confirmed by location within about 250 metres of the workplace is paid when you clock out without anyone needing to approve it. In every other case (location off or unavailable, outside the zone, "Clock in anyway", a location your device reports as simulated, or a start time earlier than when you tapped clock in) your hours are sent to the workplace to confirm before they are paid, and if the workplace has not answered within 24 hours our team reviews them.
6.3. Background location and arrival sharing. Share my arrival time is on unless you turn it off in the App. If you also allow TempDash to use location "all the time", your device watches two areas for us: about 300 metres around your home address, from about 30 minutes before you need to leave until the shift starts, and about 250 metres around the workplace, from 3 hours before the shift until it ends, for shifts in the next 24 hours. These areas are set from your home address and the workplace's address, not from your live position, and your device tells the App only when you leave one or enter the other. The App then tells the workplace that you are on your way, with an estimated arrival time, or that you have arrived, and records one location point as set out in clause 6.1. To estimate your travel time we may send your home and workplace positions, the travel mode and the time of travel to Google's routing service; we do not send your device's location for this. You can stop all of this by turning off Share my arrival time, or by changing TempDash's location permission in your device settings.
6.4. Missed shifts and claims. If you have not clocked in by the end of a booked shift, the shift is cancelled as missed and recorded on your reliability record (Worker Terms clause 4.9). If you did work it, tap Something wrong? on the shift to chat with our support team, who can send you a link to claim your hours within 72 hours of the booked end. The workplace approves or queries the hours, and a query, or no answer within 24 hours, goes to our team. We keep a count of the hours claims you have made, from your shift records, to help our team resolve questions about hours. If you make a second claim within 90 days we send you an email reminding you to clock in and out, and a firmer one for a third or later claim. The count and these emails are never shared with a workplace.
6.5. Who sees your location. Within TempDash, the location points are seen only by the staff who handle questions about hours and payments, and only for that purpose. Your location points, their accuracy and your distance from the workplace are never sent to the workplace or to any other worker. The workplace does see whether your clock in was confirmed by location, why your hours are waiting for it (for example "location not confirmed" or "hours claimed"), and, if Share my arrival time is on, the time you set off, your estimated arrival time, the time you arrived and whether you are running late.
6.6. How long we keep it. See clause 9. When you close your account, we clear the location points and your distance from the workplace on your paid and cancelled shifts.
6.7. Turning location off. You can withdraw location permission at any time in your device settings. You can still find, book and clock in to shifts. Your hours will then be confirmed by the workplace before they are paid, and your arrival will not be shared automatically.
6A. Google Calendar connection (optional) & Google API Services Limited Use
This clause applies only if you choose to connect your Google Calendar to TempDash so that your booked shifts appear there automatically.
What we ask for. When you connect, Google asks you to grant the `https://www.googleapis.com/auth/calendar.events` permission. We request this single, minimum scope deliberately — it is the least access that allows us to add, update and remove our own events.
What we do with it. We use the access only to create, update and delete the TempDash shift events we place in your calendar (for example when you accept a shift, when a shift's time changes, or when a shift is cancelled).
What we do NOT do. We do not read, list, scan, copy or store your existing calendar entries, your other calendars, or your free/busy information. We do not use Google user data for advertising, and we do not sell it or use it for any purpose unrelated to providing this calendar feature.
Disconnecting. You can disconnect at any time from within the App (Calendar Sync settings) or by removing TempDash's access at https://myaccount.google.com/permissions On disconnection we stop placing events and discard the stored Google authorisation. Events already added to your calendar remain until you delete them.
Limited Use. TempDash's use and transfer to any other app of information received from Google APIs will adhere to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
7. Who we share your data with
We share personal data only with the following categories of recipient, under written contracts containing UK GDPR-compliant safeguards:
- VouchSafe — identity, biometric and right-to-work verification (UK hosted).
- Stripe Payments Europe, Ltd — payments, KYC, payouts (joint or separate controller for payment services; processor for some functions).
- Google — maps and travel-time services (route data only; with safeguards for any transfer outside the UK); automated reading of text from uploaded immunisation documents; and, where you connect Google Calendar (clause 6A), the calendar events we create on your behalf.
- Anthropic — automated reading of expiry, provider and policy details from uploaded indemnity certificates.
- Secure cloud hosting & infrastructure providers — to store and process your information safely.
- Communications providers — to send our text messages, app notifications and emails, and to place, carry and (where enabled) record our support and worker–practice phone calls.
- Analytics & error-monitoring providers — to diagnose and fix problems.
- IP geolocation provider — where we cannot do this on our own systems, the IP address of a sign-in may be sent to a geolocation provider (currently ipwho.is) purely to convert it into an approximate city, so that you can recognise your own devices in the App's security screen. Nothing else about you is sent, and where we resolve the location using a database held on our own servers no data leaves us at all.
- Practices — your professional profile, role, GDC number, ratings, contact data sufficient to coordinate the shift, timesheet records, whether your clock in was confirmed by location, and, if Share my arrival time is on, when you set off, your estimated arrival time and when you arrived (clause 6.5), and your verified facial portrait (clause 3.2a). The portrait is shown only to a Practice that has a confirmed booking for you, only so that it can confirm your identity in connection with that booking, and only through your TempDash ID; it is not supplied to a Practice as a file and is not retained by us on a Practice's behalf.
- HM Revenue & Customs (HMRC) — your name, date of birth, registered address, National Insurance number and total platform earnings, reported once each calendar year as required of digital platform operators under the Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023.
- Financial offer partners — only if you tap one of their offers in the Wallet (clause 5.2): you are taken to their website, and the link may tell them you came from TempDash. We do not send them your bank details, balance or any other data.
- Professional advisors — legal, accounting, audit.
- Regulators and law enforcement — where lawfully compelled or where strictly necessary to prevent fraud, safeguarding harm, or illegal working.
We do not sell personal data.
8. International transfers
Where any recipient processes data outside the UK, we rely on (a) UK adequacy regulations, (b) the UK International Data Transfer Agreement, or (c) the EU Standard Contractual Clauses with the UK Addendum, supplemented by a transfer risk assessment. Copies of the safeguards are available on request.
9. How long we keep it
- Your profile and your social content — deleted when your account closes. This covers your profile, photo, bio, videos, posts, stories, saved workplaces, follows, connections, achievements and your travel and notification preferences. None of it is kept for six years; only the contract, pay and tax records in the next three entries are.
- Contract, shift, timesheet and rating records — 6 years from settlement of the shift (limitation period for contractual claims, Limitation Act 1980 s.5). Ratings keep their score; anything written in words is deleted when the person who wrote it closes their account.
- Payment and tax records — 6 years (corporation tax records, Finance Act 1998 Sch 18 para 21; VAT records, Value Added Tax Act 1994 Sch 11 para 6; and the record keeping duty on digital platform operators under the Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023).
- Anti money laundering records — 5 years from the end of our business relationship, after which the Money Laundering Regulations 2017 reg. 40(5) require us to delete them, unless another law or live legal proceedings require otherwise.
- Your identity details held for the duties above — your name, date of birth, address and National Insurance number are moved out of your account into a separate, encrypted, access controlled record used only for the tax and reporting duties named above, and deleted when the relevant duty ends.
- Right to work and immigration evidence — 2 years after the end of engagement (per Home Office guidance). This includes the check record, our encrypted copy of the Home Office share code result, the audit copy we generate at the time of the check, and the full record we receive from our verification partner including any conditions on your permission to work. All of it is deleted together at the end of that period.
- Biometric verification template — deleted by VouchSafe once the verification decision is recorded; verification decision retained as above. This entry concerns only the template generated by our verification partner. The facial portrait we retain ourselves is covered by the next entry.
- Verified facial portrait (clause 3.2a) — we keep one portrait only, being the most recent, and only while your account is open. It is deleted when a later identity check replaces it, and on closure of your account or on an erasure request under clause 10.
- Location points recorded for a shift (clause 6.1) — our retention period is 180 days after the shift is paid or, where there was a query or dispute about it, 180 days after that is decided. They are never cleared while a query or dispute is open. We keep your distance from the workplace and whether the clock in was confirmed by location as part of the shift record. Points on a shift that is never paid and has no query or dispute (for example one that was cancelled) have no fixed period yet; they are cleared when you close your account, and you can ask us to delete them sooner under clause 10. Location points are not part of the pay record and we do not keep them for six years.
- Connected calendar authorisation — until you disconnect or your account closes, whichever is first.
- Support communications — 3 years from last contact.
- Documents you send through a support chat. Anything our team does not keep is deleted 48 hours after the support request is resolved, or 30 days after you sent it if the request is still open by then. A document our team keeps is held with your account records: a compliance document, such as a DBS certificate, is filed with your other documents and kept on the same terms as one you upload yourself, and anything else is kept for our team only and is not shown in the App.
- Website sign ups, marketing preferences and opt outs — while you are active with us. Activity means something you did that we record: signing up on our website or confirming your email there, signing in, or using the App. We do not track whether you open or click our emails. After 3 years with no activity we delete a website sign up that never became an account, and we stop marketing to an account. If you unsubscribe, ask us to stop, or close your account, we delete the marketing record and keep only a one way scrambled version of your email address, which cannot be read back into an address and exists solely so that we do not email you again. We keep that scrambled version indefinitely, and we keep one for an opt out that reaches the 3 year point too.
- Cookie / device logs — 12 months.
- When you tend to open the App, and the record of notifications sent to you (clause 3.7b) — 24 months, after which it is deleted. It is also deleted when your account closes, and on an erasure request under clause 10.
- Signed in device records (including the approximate location of a sign in) — while the device is signed in, and up to 12 months after it is signed out or blocked, so that a security incident can still be investigated.
- Our record of how we handled your request — when you ask us to delete your data we keep a record of what we did, which is required of us so that we can show the request was handled properly. It records the categories acted on, the counts and the outcomes. It never contains the information that was deleted. Kept for 6 years.
- Record of a restriction on re-registering — see clause 9A.
After the retention period, data is deleted or irreversibly anonymised.
9A. Closing your account, and asking us to delete your data
These are three different things and you can ask for any of them.
Pause. Your account goes quiet. No offers, no notifications, your profile stops showing and you are not findable. Nothing is deleted and no clock starts. Sign in whenever you want to come back.
Close. You will not be able to sign in again. We delete everything that has no remaining purpose, which is the first entry in clause 9, and we start the retention clock on everything that does. This is the event that every "after closure" period in clause 9 is measured from.
Close and delete my data. Closure, plus we delete everything we are not required by law to keep, and remove your name and identity from what is left. This is your right to erasure under Art 17 UK GDPR.
You can do any of these in the App under Account, or by emailing support@tempdash.app. We will confirm it is you before we act. We will never ask you for a photograph of an identity document in order to delete your data.
What we cannot delete, and why
The right to erasure is not absolute. UK GDPR Art 17(3) allows us to keep information where we need it to comply with a legal obligation, or to establish, exercise or defend a legal claim. Where we rely on that we will tell you which information, on what basis, and until when. The categories are the ones listed in clause 9 with a period longer than closure: contract, shift and timesheet records; payment and tax records; anti money laundering records; the identity details those duties need; and right to work evidence.
What happens to things that are not only about you
- Messages you sent stay in the other person's chat. We remove your name, your photograph and any pictures or videos you sent, and the messages show as coming from a deleted account. We cannot remove them altogether, because that chat is the other person's record of a conversation they took part in, and it is often the only record of how a shift was arranged or what was agreed. Message threads are themselves deleted on the periods in clause 9.
- Ratings keep their score, and lose their words. A rating you gave a workplace stays, because other workers rely on it. A rating a workplace gave you stays as a score only. Anything written in words is deleted in both directions.
- Comments you left on other people's posts become "Comment removed" rather than disappearing, so that replies underneath them still make sense. The text is deleted.
- Your username is retired permanently and cannot be taken by anybody else, so that older mentions of you can never come to point at a different person.
If you owe money, are mid shift, or a question about pay is open
We cannot close an account while a shift is booked or unsettled, while a timesheet is still being agreed, while there is money in your wallet, or while an amount is outstanding. Closing an account does not cancel an obligation in either direction, and we will not close one while we are holding your earnings. If any of this applies we will pause your account straight away so that nothing new accrues, tell you exactly what is in the way, and complete the request once it clears.
Where a restriction on re-registering applies
Where an account was closed after being banned, or with an amount outstanding, or with a question about pay unresolved, we keep a minimal record so that the restriction cannot simply be undone by closing and signing up again. It contains a one way scrambled version of your National Insurance number, which cannot be turned back into that number, a device identifier, and a short code for the reason. It contains no name, no address and no correspondence. We keep it for 6 years from the date of the restriction and then delete it. We rely on Art 17(3)(e), and where the reason was suspected criminal conduct on the exemption at Sch 2 Part 1 para 2 of the Data Protection Act 2018. If you think this is wrong, tell us and we will look at it again.
Our payment provider
Stripe holds identity, bank and payment information as a controller for the payment services it provides and for its own legal obligations, and retains it on its own schedule. We cannot delete it and we will not tell you that we can. If you want that information erased you have to ask Stripe directly, and we will give you the details you need to do so.
Our verification partner
A small part of the identity evidence, being the document and facial images captured during your check, is held by VouchSafe rather than by us. We can ask them to delete it but we do not hold it ourselves. Tell us and we will make that request and confirm the outcome to you.
Telling other people
Where we have shared your information with someone else, we will tell them that you have asked for it to be deleted, unless that proves impossible or would take disproportionate effort. You can ask us who those recipients were. Where your information was published, for example on a public profile page, we take reasonable steps including technical ones to have copies and links removed.
Backups
Deleted information can remain in our secure backups for a period after it is deleted from the live service. While it is there we do not use it for any purpose, we do not query it, and nobody outside TempDash has access to it. It is removed on the normal backup cycle. If we ever have to restore from a backup, we re-apply every deletion before the restored system is used again.
If you are not happy
Tell us and we will look at it again. You can also complain to the Information Commissioner's Office at https://ico.org.uk/ or seek a remedy through the courts.
10. Your rights
Subject to UK GDPR exemptions, you have the right to:
- access your data and obtain a copy;
- rectify inaccurate data;
- erase data ("right to be forgotten") where legal grounds exist;
- restrict or object to processing in certain circumstances, including objection to processing based on legitimate interests;
- portability for data you provided where processing is on contract or consent;
- withdraw consent at any time without affecting prior lawful processing;
- not be subject to a solely automated decision producing legal or similarly significant effects (see clause 11);
- complain to the ICO (https://ico.org.uk/).
Notifications about available work. You can turn these off yourself at any time, in the App under Settings → Notifications, and you do not have to give a reason. That is an objection under Article 21(2) and we act on it immediately. You can also email support@tempdash.app and ask us to stop deciding which notifications you receive on the basis of your activity, in which case we will stop and you will simply receive fewer, untargeted messages instead.
To exercise any right, email support@tempdash.app. We will respond within one calendar month and may extend by two further months for complex requests, with notice.
11. Automated decision-making & profiling
11.1. The Smart Matching service uses your profile (such as your role, skills and languages), your home address and the shifts you have shown interest in to decide which shifts you are shown and in what order. Your ratings and reliability record do not affect that order. The only effect of your reliability record is that, while a pause under the Worker Terms applies, you cannot pick up new shifts. We consider this profiling assisted by automation, not a "solely automated decision producing legal or similarly significant effects" within Article 22, because:
- decisions to receive a single offer do not legally bind you;
- you remain free to decline; and
- pauses under the reliability rules are applied automatically, by the fixed rules set out in the Worker Terms (clause 11.1A), and you can ask a person to review any pause (clause 11.2); people at TempDash decide account reviews, suspensions, debt recovery and dispute outcomes.
11.2. You may request information about how the algorithm has affected you and ask for human review of any pause, account suspension or dispute decision by emailing support@tempdash.app.
11.3. Choosing which notifications to send you, and when. We build a picture of when you tend to open the App and what kind of work you tend to take, and we use it to decide which notification about available work to send you, and at what hour. In plain words, we work out:
- roughly when you tend to open the App, by day of the week and hour of the day;
- which days and times of day you tend to work, from shifts you have already worked;
- how far in advance you tend to book a shift;
- roughly the rate at which you take work, from the rates you have accepted;
- which workplaces you go back to.
This is profiling within the meaning of Article 4(4), and because it is connected to telling you about work we could offer you, we treat it as profiling connected to direct marketing. We are telling you plainly rather than describing it as personalisation.
What it is used for. It decides which notification you receive about available work, and at what time of day. It also limits how many you receive, so that a busy day on the platform does not become a busy day on your phone.
What it is never used for. It does not decide whether you can take a shift. It does not decide what you are paid. It does not decide whether you are booked, and no workplace ever sees any part of it. Nothing in it is shown to a workplace, and none of it affects your standing, your reliability record or your access to work. A shift you can take remains a shift you can take, at the same rate, whether or not we ever mention it to you.
Turning it off. You can turn notifications off, by category, in the App under Settings → Notifications, and you do not need a reason. Doing so changes nothing except how many messages you get: the same work is available to you, on the same terms, and you can still find all of it in the App yourself. A small number of messages will still reach you whatever your settings say, because missing them would cost you money or a booking: for example a reminder about a shift you have already booked, a message telling you a workplace is asking where you are, a query about your hours, or an alert that your payout account has changed. The App says so on the setting itself.
Human review. If you want to know why you received a particular notification, or want a person to look at it, email support@tempdash.app. We keep a structured record of the reason behind each one and can tell you what it was.
12. Security
We protect your information with strong, industry-standard security — including encryption, strict access controls, and regular independent testing. Our payment and identity-verification partners maintain their own audited security programmes. Despite our controls, no transmission over the Internet is ever 100% secure, so please keep your login details confidential.
13. Children
The App is not directed at, and does not knowingly process data relating to, anyone under 18.
14. Cookies & similar technologies
Our website uses essential cookies, and — with your consent — analytics cookies; details are in our Cookie Notice at /legal/cookies In the app, we use similar essential storage to keep you signed in and to send notifications, which you can manage in your device settings.
15. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by in-app notice or to your registered email at least fourteen (14) days before taking effect.
16. How to contact us
Email: support@tempdash.app Post: Data Protection, TempDash Ltd, 124 City Rd, London EC1V 2NX ICO: https://ico.org.uk · 0303 123 1113
Version 1.3 · Effective 3 October 2026