Privacy Policy
Last updated: 3 September 2026
1. Who We Are
Arcadeus ("we", "us", "our") is a financial management platform for UK sole traders and small businesses. We are the data controller for personal data processed through our service at app.arcadeus.ai.
For privacy-related enquiries, contact us at info@arcadeus.ai.
2. What Data We Collect
We collect and process the following categories of personal data:
- Account data: email address and password (stored securely via Supabase Auth).
- Business data: business type, estimated turnover, VAT registration details, and tax configuration settings you provide.
- Financial data: income, expense, and invoice records you enter or import.
- National Insurance number (NINO): collected and stored securely when you connect Arcadeus to HMRC for Making Tax Digital for Income Tax (MTD ITSA). Your NINO is used solely to identify you with HMRC's APIs and is never shared with third parties other than HMRC.
- HMRC connection data: OAuth access and refresh tokens issued by HMRC when you authorise Arcadeus to submit VAT returns or income tax submissions on your behalf via Making Tax Digital (MTD).
- VAT submission records: the details of VAT returns submitted to HMRC through our platform, including period dates, VAT figures, and HMRC receipt numbers.
- Income Tax submission records: quarterly income and expense summaries, End of Period Statements (EOPS), and Final Declaration data submitted to HMRC under MTD for Income Tax Self Assessment (MTD ITSA), including HMRC-issued transaction references and calculation IDs.
- Device and session data: browser type, screen size, browser plugins, IP address, and timezone. This data is collected to comply with HMRC's mandatory fraud prevention header requirements under the MTD programme.
3. Why We Process Your Data
We process your data on the following legal bases under UK GDPR:
- Contract performance: to provide the Arcadeus service you have signed up for, including storing your financial records and submitting VAT returns to HMRC.
- Legal obligation: HMRC's Making Tax Digital programme requires us to collect and transmit fraud prevention headers with every API call. This is a statutory requirement we cannot opt out of.
- Legitimate interests: to maintain the security and integrity of our service, detect fraud, and improve the platform.
4. HMRC Making Tax Digital (MTD) — VAT and Income Tax
When you connect Arcadeus to HMRC via MTD, you authorise us to submit tax returns and statements on your behalf using HMRC's API. Depending on your subscription and tax position, this may include:
- VAT returns submitted under MTD for VAT.
- Quarterly income and expense updates submitted under MTD for Income Tax Self Assessment (MTD ITSA). These are cumulative summaries of your self-employment or UK property income and expenses for each tax quarter.
- End of Period Statements (EOPS) confirming the accuracy of your annual income and expense figures for each business source, submitted after the tax year ends.
- Final Declarations crystallising your income tax liability for the tax year, submitted after EOPS and reviewed against an HMRC-generated tax calculation.
All of the above involve:
- Storing your HMRC OAuth access and refresh tokens securely in our database.
- Storing your National Insurance number (NINO) to identify you with HMRC's APIs.
- Transmitting financial data to HMRC's systems on your instruction.
- Collecting device and network metadata (IP address, browser details, screen size, etc.) and including it in every HMRC API request as fraud prevention headers. This is a mandatory requirement set by HMRC, not optional.
You remain responsible for the accuracy of the financial data submitted to HMRC. Arcadeus transmits what you have entered; we do not independently verify the figures.
HMRC tax calculations retrieved via Arcadeus are provided for information only. They are based solely on data HMRC have received and may change. They should be used as an estimate only.
You can disconnect Arcadeus from HMRC at any time via Tax Settings. This revokes our ability to submit on your behalf but does not delete previously submitted returns or statements, which are held by HMRC.
5. Who We Share Data With
We do not sell your personal data. We share data only with the following third parties where necessary:
- HMRC: VAT return data, income tax submission data (quarterly updates, EOPS, final declarations), your NINO, and fraud prevention headers, as required by the MTD programme.
- Supabase: our database and authentication provider. Data is stored in the EU. Supabase processes data under a Data Processing Agreement.
- Vercel: our hosting provider. Application code and serverless functions run on Vercel's infrastructure.
6. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law (for example, financial records that must be kept for HMRC compliance purposes).
HMRC OAuth tokens are deleted immediately when you disconnect Arcadeus from HMRC via Tax Settings.
7. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data ("right to be forgotten").
- Restrict or object to processing of your personal data.
- Receive your personal data in a portable format.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at info@arcadeus.ai. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
Arcadeus uses essential cookies only. We set a short-lived, httpOnly cookie during the HMRC OAuth authorisation flow to prevent cross-site request forgery (CSRF). No tracking or advertising cookies are used.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the application. The date at the top of this page indicates when it was last updated.