Data Retention and Deletion

Last updated: 7 February 2026

This policy explains what data COSHHmate (coshhmate.co.uk) stores, how long we keep it, and how you can request deletion. COSHHmate is operated by Crocker Digital Ltd (Company No. 17008789).

What data we store

When you use COSHHmate, we store:

  • Account information: Your name, email address, and password (hashed)
  • Organisation information: Your organisation name and settings
  • Substances: Chemical substance records you create
  • Assessments: COSHH assessment records, including hazards, risks, and control measures
  • Review schedules: Dates and reminders for assessment reviews
  • Email addresses: Used for authentication and transactional emails
  • Billing information: Managed by Stripe; we store your subscription status and plan details but not your full card number

Retention while your account is active

We retain all of the above data for as long as your account is active. We do not automatically delete data from active accounts.

What happens when you delete your account

When you request account deletion:

  1. Immediate: Your account is deactivated and you can no longer log in
  2. 30-day retention period: We retain your data for 30 days after the deletion request. This allows you to contact us and recover your account if the deletion was accidental
  3. Permanent deletion: After 30 days, all your data is permanently deleted from our active systems

How to request deletion

You can delete your account in two ways:

  • In-app: Use the account deletion feature in your account settings
  • Email: Send a deletion request to hello@coshhmate.co.uk from the email address associated with your account

We will confirm your deletion request by email.

Export your data first

Before deleting your account, we recommend exporting your data. COSHHmate provides an in-app JSON export feature that lets you download your substances, assessments, and other records. Once your data is permanently deleted, we cannot recover it.

Backups

Supabase maintains automated database backups as part of its infrastructure. These backups are retained according to Supabase's own retention policy and are used solely for disaster recovery. Backup data is subject to the same security protections as live data and is permanently purged in accordance with Supabase's backup lifecycle.

Stripe billing data

Billing and payment records held by Stripe are subject to Stripe's own data retention policies. We can request deletion of your Stripe customer record on your behalf. Note that Stripe may retain certain records as required by financial regulations.

Contact

If you have questions about data retention or want to request deletion, contact us at hello@coshhmate.co.uk.

Questions? Email hello@coshhmate.co.uk