Last updated: 11 May 2026
Apron Payments Limited ("Apron", "we", "us", or "our") is committed to protecting your personal data. This Privacy Notice explains how we collect, use, disclose, process, safeguard and otherwise handle your personal data in compliance with the UK General Data Protection Regulation, the Data Protection Act 2018, and other applicable data protection laws (together, the "Data Protection Laws").
This Privacy Notice applies to individuals who: (i) are employees, directors, or authorised representatives of our business customers and prospective customers (including where you operate as a sole trader) ("Business Contacts"); (ii) are suppliers, vendors, payees, or employees paid through our payment services ("Payment Recipients"); (iii) are customers of our clients who are invoiced for payment through our services ("Invoiced Parties"); (iv) are issued an Apron expense card by a business customer ("Expense Cardholders"); and (v) browse and interact with our website ("Website Users").
This Privacy Notice describes:
As a controller, Apron is responsible for deciding how we hold and use your personal data. If you have any concerns about our use of your personal data or questions about this Privacy Notice, you can contact our Data Protection Officer ("DPO") at dpo@getapron.com.
APRON AS A PROCESSORFor certain services, Apron acts as a data processor on behalf of its business customers, who are the data controllers. This means that where Apron processes your personal data in connection with the following services, it does so on the instructions of the business customer and not for its own purposes:
If you are an employee, contractor, director, supplier, or customer of one of Apron's business customers, your personal data may be processed by Apron in its capacity as a processor in connection with one or more of the above services. In these circumstances, the business customer is responsible for the lawful basis on which your personal data is collected and shared with Apron, and for ensuring that you have been provided with appropriate information about how your personal data is used.
For information about how your personal data is processed and to exercise your data protection rights in connection with these services, you should refer to the privacy notice of the relevant business customer. Apron is not in a position to respond directly to data subject rights requests in relation to processing carried out in its capacity as a processor, and any such requests should be directed to the relevant business customer in the first instance.
Category | Examples | Source |
|---|---|---|
Identifiers | Name, job title, role | Directly from you or your employer |
Contact Information | Work email, phone number, postal address, company name | Directly from you or your employer |
Identity Verification Data | Government-issued identification documents, biometric data | Directly from you, where required for onboarding and KYC purposes |
Communications Data | Communications you send to us, including related logs and metadata | Directly from you when you contact us by email, phone or through our platform |
Account Data | Login credentials, account preferences, usage and activity on the Apron platform | Directly from you or generated through your use of our services |
Where you operate as a sole trader, in addition to the above, we will also collect:
Category | Examples | Source |
|---|---|---|
Financial Information | Payment card details, bank account details, transaction and spending data | Directly from you or your employer, or generated through your use of our services |
Category | Examples | Source |
|---|---|---|
Identifiers | Name | From invoices or payment instructions provided to Apron by our business customer |
Contact Information | Business email address, business postal address | From invoices or payment instructions provided to Apron by our business customer |
Financial Information | Bank account details | From invoices or payment instructions provided to Apron by our business customer, where the payment recipient is a sole trader |
Transaction Data | Payment records, transaction history | Generated through the processing of payments, where the payment recipient is a sole trader |
Sanctions Screening Data | Sanctions screening results | Generated by Apron in the course of processing payments as required by any financial services regulations that we deem relevant |
Transaction Monitoring Data | AML monitoring records, transaction monitoring flags | Generated by Apron in the course of fulfilling its regulatory obligations as a regulated payment services provider |
Category | Examples | Source |
|---|---|---|
Identifiers | Name | From invoices or payment instructions provided to Apron by our business customer |
Contact Information | Business email address, business postal address | From invoices or payment instructions provided to Apron by our business customer |
Financial Information | Bank account details | From invoices or payment instructions provided to Apron by our business customer, where the invoiced party is a sole trader or individual |
Transaction Data | Payment records, transaction history | Generated through the processing of payments, where the payment recipient is a sole trader or individual |
Transaction Monitoring Data | AML monitoring records, transaction monitoring flags | Generated by Apron in the course of fulfilling its regulatory obligations as a regulated payment services provider |
Where an Apron expense card is issued to a named individual rather than a department or team, Apron may process the following personal data in connection with that individual's use of the card.
Category | Examples | Source |
|---|---|---|
Identifiers | Name | From our business customer upon card issuance |
Financial Information | Payment card details | Generated by Apron upon card issuance |
Transaction and Spending Data | Merchant details, transaction amounts, spending categories, real-time alerts triggered | Generated through use of the Apron expense card |
Category | Examples | Source |
|---|---|---|
Identifiers | Name, company name | Directly from you when you use our contact form or sign up for communications |
Contact Information | Email address, phone number | Directly from you when you use our contact form or sign up for communications |
Communications Data | Communications you send to us, including related logs and metadata | Directly from you when you contact us through our website |
Technical Data | IP address, browser type and version, operating system, device ID, mobile network information | Collected automatically when you visit our website |
Usage Data | Content viewed or searched, interaction data (scrolling, clicks and hovers), response times, visit duration and navigation paths | Collected automatically when you visit our website |
Session Metadata | Account creation timestamp, session frequency and time of use | Collected automatically when you visit our website |
We automatically collect Technical Data, Usage Data, and Session Metadata through the use of tracking technologies including cookies. We use cookies to understand site usage, maintain functionality, and improve website performance. You can manage your cookie preferences through the cookie management tool on our website. Please see our Cookie Policy for further details.
We will only use your personal data for the purposes described below, or for purposes which are reasonably compatible with those described. We will not use your personal data for other purposes without your permission, unless we have a legal right or obligation to do so.
For ease of reference, we use the following terms throughout this section:
We will use your personal data for Service Delivery, including to:
We will use your personal data for Regulatory Compliance and Fraud and Financial Crime Prevention, including to:
We will use your personal data for Legitimate Business Operations and Security and IT Management, including to:
We will use your personal data for Marketing and Business Development, including to:
We will use your personal data for AI Development and Service Improvement, including to:
We will use your personal data for Service Delivery, Regulatory Compliance, and Fraud and Financial Crime Prevention, including to:
We will use your personal data for Fraud and Financial Crime Prevention, including to:
We will use your personal data for AI analysis and AI Development and Service Improvement, including to:
We will use your personal data for Service Delivery, Regulatory Compliance, and Fraud and Financial Crime Prevention, including to:
We will use your personal data for AI analysis and AI Development and Service Improvement, including to:
We will use your personal data for Service Delivery, including to:
We will use your personal data for Regulatory Compliance and Fraud and Financial Crime Prevention, including to:
We will use your personal data for Security and IT Management and AI Development and Service Improvement, including to:
We will use your personal data for Service Delivery and Security and IT Management, including to:
We will use your personal data for Legitimate Business Operations, including to:
We will use your personal data for Marketing and Business Development, including to:
We will use your personal data for Fraud and Financial Crime Prevention and Security and IT Management, including to:
We will use your personal data for AI Development and Service Improvement, including to:
We will only process your personal data for the purposes set out in Section 3 above and to the extent we have a lawful basis under Data Protection Laws. We rely on the following lawful bases:
Where we process special categories of personal data (such as biometric data for identity verification purposes), we do so only under strict conditions permitted by Data Protection Laws, primarily where you have provided your explicit consent or where processing is necessary for reasons of substantial public interest, including compliance with our anti-money laundering and financial crime prevention obligations.
The main legitimate interests on which Apron relies are as follows, being processing necessary for us to:
When we share your personal data with third parties who act as our service providers, we only disclose personal data that is necessary for them to provide their services. We require all such third parties to respect the security of your personal data and to treat it in accordance with applicable law. We do not permit our service providers to use your personal data for their own purposes and only allow them to process it for specified purposes and in accordance with our instructions.
When we share your personal data with third parties who act as independent controllers of that information, they may disclose or transfer it to other organisations in accordance with their own data protection policies. This does not affect your data subject rights as detailed in Section 9 below. Where you ask us to rectify, erase, or restrict the processing of your personal data, we will take reasonable steps to pass this request on to any such third parties with whom we have shared your personal data.
For all categories of data subject, we may share your personal data with:
For Business Contacts and Website Users, we may also share limited personal data (such as your business email address and company name) with advertising and social media platforms, including LinkedIn, Google, and Meta, for the purpose of targeting and personalising marketing communications and creating matched audiences to show relevant advertisements. You can object to this use of your personal data at any time by contacting dpo@getapron.com.
Our website may contain links to third-party websites and embedded features. These third-party sites are governed by their own privacy policies and we are not responsible for their data processing practices. Where appropriate, we have linked to relevant third-party privacy policies in our Terms and Conditions.
If you connect a Google account (e.g. Gmail), we do not use Google Workspace data (including Gmail message content, metadata, or attachments) or data derived from it to train, fine-tune, or improve any generalised AI/ML models. We use it only to provide and maintain the user-facing functionality you request (e.g. importing invoices/receipts into Apron).
We may also share your personal data with others where you have given us your consent to do so.
Your personal data is primarily stored and processed in the United Kingdom. Some of our service providers and third-party partners are based outside the UK, and in the course of providing the Services we may transfer your personal data to countries whose laws do not provide the same level of data protection as UK law.
Where we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place to protect your personal data, including one or more of the following:
Where required, we carry out transfer risk assessments prior to transferring personal data outside the UK to ensure that an equivalent level of protection is maintained.
You may request further information about the safeguards we have in place for international transfers, including copies of any relevant transfer agreements, by contacting our Data Protection Officer at dpo@getapron.com.
We have put in place appropriate technical and organisational measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a legitimate business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
We maintain the following administrative, technical, and physical safeguards to protect your personal data:
As a regulated payment services provider, our security measures are designed to meet the requirements of applicable financial services regulations, including those relating to the security of payment transactions and the protection of payment card data.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable supervisory authority of a breach where we are legally required to do so.
Despite our best efforts, no online system is completely secure. If you suspect that the security of your personal data has been compromised, please contact us immediately at dpo@getapron.com.
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected and processed, as outlined in this Privacy Notice, including to satisfy our legal and regulatory obligations, resolve disputes, and enforce our terms and conditions.
FCA-REGULATED ACTIVITIESAs a regulated payment services provider, Apron is subject to specific record-keeping requirements under applicable financial services regulations. For personal data processed in connection with our regulated activities — including transaction records, AML monitoring records, sanctions screening results, and KYC documentation — we retain personal data for a minimum of five years from the date of the relevant transaction or the end of our relationship with you, whichever is later, or such longer period as may be required by applicable financial services regulations.
ALL OTHER PERSONAL DATAFor personal data processed in connection with our other activities, we retain your personal data for as long as is necessary for the relevant purpose, and in any event for no longer than five years following the end of our relationship with you or your last interaction with us, unless a longer retention period is required or permitted by law.
The exceptions to the above retention periods are where:
After the applicable retention period has expired, your personal data will be securely deleted or anonymised. Where data is anonymised, it may be retained and used for analytical, research, or service improvement purposes, including AI development, as it will no longer constitute personal data.
Under Data Protection Laws, you have the following rights in relation to your personal data:
To exercise any of the above rights, please contact our Data Protection Officer at dpo@getapron.com. We will respond to your request within one month of receipt, though this period may be extended by a further two months where your request is complex or where we receive a high volume of requests, in which case we will notify you accordingly.
We may need to verify your identity before responding to your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to respond.
RIGHT TO LODGE A COMPLAINTIf you have concerns about how we handle your personal data and are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters:
We may update this Privacy Notice from time to time.