The short version
Kerbline is a communication and record-keeping tool for construction sites. Site teams send messages and photographs. Each photograph records the time our servers received it, and whatever time and location the sending device reported — so there is a contemporaneous record of what was done, made at the time rather than reconstructed afterwards.
In plain terms:
- Your employer's account details — the name, email address and billing information of the company that subscribes to Kerbline — are held by us, and we decide how they are used.
- Site content — the photographs, messages, voice notes and location stamps created on a site — belongs to the construction company that runs that site. They decide what is collected and what happens to it. We hold and process it on their instructions.
- We do not delete evidence automatically. A completed site is archived and stays readable. If a subscription lapses, the record becomes read-only but remains accessible. Deletion happens when the customer asks for it.
- We do not sell your information, use it for advertising, or make automated decisions about you.
- Some of our suppliers are outside the UK. Where that happens we use the safeguards UK data protection law requires.
If you want to know what we hold about you, or you are unhappy with something, the contact details are below and we will respond within one month.
Contents
Who is responsible for your information
Data protection law distinguishes between a controller (who decides why and how personal information is used) and a processor (who handles it on the controller's instructions). Kerbline sits in both roles depending on the information concerned.
We are the controller for account data. This means the information our business customers give us in order to have a Kerbline account: the names and contact details of the people who administer the account, billing and payment information, registration and security information, and correspondence with us about queries, complaints or support.
We are a processor for site content. This means the material created inside a site: photographs and the location and time recorded with them, messages, voice notes, albums, the names of the people who sent them, and the records built from that material such as applications, evidence packs and reports.
For site content, the construction company that runs the site is the controller. They decide who joins a site, what is recorded there, how it is used and when it is deleted. We hold and process that content on their instructions under a written contract.
What this means for you in practice. If you are a site worker and you want to know what is held about you, ask to have something corrected, or ask for it to be deleted, the company you work for is the right place to start — they control the record. If you contact us instead, we will tell you which of our customers holds the record and pass your request on to them, and we will help them respond. If your request is about your own Kerbline account rather than site content, we handle it directly.
Contact details
Post
1 Martins Cottages, Church Lane, Bulphan, Upminster, Essex, RM14 3TS, United KingdomWhat information we collect, use, and why
To provide the service
- Names and contact details
- Account information
- Photographs and video recordings
- Messages and voice recordings sent by site users, and the location data attached to photographs
We record the location the sending device reports at the moment a photograph is sent, which is not necessarily where or when it was taken. It is reported by the device and accepted as given. We do not track anyone's location continuously or at any other time.
To operate customer accounts
- Names and contact details
- Payment details, including card or bank information
- Account information, including registration details
- Information used for security purposes
To comply with legal requirements
- Name
- Contact information
- Financial transaction information
- Any other personal information required to comply with a legal obligation
To deal with queries, complaints or claims
- Names and contact details
- Account information
- Correspondence
Lawful bases and data protection rights
Under UK data protection law we must have a "lawful basis" for collecting and using personal information. The list of possible lawful bases is in the UK GDPR, and there is more on the ICO's website.
Which lawful basis applies may affect your rights. In brief, you have:
- The right of access — to ask for copies of your personal information, and for details of where we got it and who we share it with. Some exemptions apply.
- The right to rectification — to ask us to correct information you think is inaccurate, or complete information you think is incomplete.
- The right to erasure — to ask us to delete your personal information.
- The right to restriction of processing — to ask us to limit how we use your personal information.
- The right to object to processing — to object to our processing of your personal information.
- The right to data portability — to ask us to transfer information you gave us to you or to another organisation.
- The right to withdraw consent — where we rely on consent, to withdraw it at any time.
If you make a request we will respond without undue delay and in any event within one month.
Where your request concerns site content, the construction company that runs the site is the controller and the request should go to them. We will help them respond and will pass on any request that reaches us by mistake.
To make a request, use the contact details above.
Our lawful bases
Providing the service
- Contract — we need the information to enter into or carry out a contract with you. All rights may apply except the right to object.
-
Legitimate interests — our business customers are construction companies who use Kerbline to keep an accurate record of work carried out on their sites. Site workers join at their employer's request, so we do not have a direct contract with every person whose information appears in the service. We rely on legitimate interests to provide the service to those users.
The benefit is a clear and reliable record of what was built, by whom and when. That protects workers as much as employers, because disputes about work carried out are common in construction and an accurate record resolves them fairly rather than on memory.
We keep the impact proportionate. We collect only what makes the record useful: the person's name, the photographs and messages they choose to send, and the location their device reports when a photograph is sent. We do not track location continuously. We do not use anyone's information for advertising, profiling or automated decision-making, and we do not sell it. Our customers decide what is kept and for how long, and any individual can contact us to ask what we hold or to raise a concern.
Operating customer accounts
- Contract — we need the information to enter into or carry out a contract with you. All rights may apply except the right to object.
Legal requirements
- Legal obligation — we need the information to comply with the law. All rights may apply except the right to erasure, the right to object and the right to data portability.
Queries, complaints and claims
-
Legitimate interests — when someone raises a query, complaint or claim we need to look into it properly. That means keeping a record of the correspondence and, where relevant, looking at the account or site records the query concerns.
The benefit is that people get a fair answer based on what actually happened rather than on assertion. That applies to individuals as much as to us: someone raising a concern about how their information has been handled, or about work recorded on a site, is better served by us being able to check the record than by us having nothing to check.
The impact is limited. We look only at information relevant to the matter raised, we keep it no longer than we need to resolve it and to meet any legal time limits that follow, and we do not use it for anything else. Anyone can ask what we hold about them or ask us to stop using it, and we will explain our position if we cannot.
For more on our use of legitimate interests, contact us using the details above.
Where we get personal information from
- Directly from you
- From our business customers, who invite their own staff and site workers to join a site and may enter their names when doing so
How long we keep information
We do not delete records on any schedule or timer, and there is no setting that causes them to expire. There is one exception, for free trials that do not become subscriptions, and it is set out below.
Site content. When a site is completed it is archived. An archived site stays readable — the photographs, messages and records remain available to the customer who owns them. If a subscription lapses, the account becomes read-only: nothing new can be added, but the existing record remains accessible.
Site content is deleted when the customer who controls it asks us to delete it. Because the construction company running the site is the controller of that content, the decision to delete is theirs, and they are responsible for setting their own retention periods in line with their obligations.
Free trials are the exception. Where a free trial ends and no subscription begins, we keep the site content created during that trial for 90 days from the end of the trial, and then delete it. This differs from the position for paying customers, whose records we do not delete at all unless they ask us to. We carry that deletion out ourselves rather than by an automatic process, so it remains true that nothing in Kerbline expires records on a timer. The customer can ask us to delete it sooner, and can export it at any time during the 90 days. If a subscription begins before the 90 days are up, the ordinary position above applies to that content permanently and the 90-day period has no further effect.
Account data. We keep account information for as long as the account is open, and for 12 months after it closes, to deal with any questions or disputes that follow. Financial records — invoices, payment records and related correspondence — are kept for six years from the end of the relevant accounting period, as required by UK tax law.
Correspondence. The conversation that follows a query, complaint or support matter — the emails and messages we exchange with you to resolve it — is kept for as long as needed to resolve the matter and to meet any legal time limits that follow, and then deleted.
Enquiries you send us. When you use the contact form on our website — to raise a data protection complaint, report a bug, ask about the product, or anything else — we keep a record of what you sent, so that we can deal with it and, where it matters, show that we did. A general enquiry is kept for 12 months. A data protection complaint is kept for three years, because that record is our own evidence that we received your complaint and handled it properly, which we may need to rely on for longer than an ordinary enquiry.
Fault and bug diagnostics. When something in the app goes wrong — a crash, or a fault you report from inside Kerbline — we record technical information that helps us find and fix it: which part of the app failed, the type of error, the screen you were on, and the version of the app you were running. These reports deliberately do not include the contents of your messages or your photographs. We keep them for 12 months, then delete them.
Who we share information with
This section covers two different things, and the difference matters. Most of it is about companies we have chosen and have a contract with, who handle information for us. The last part is about two organisations we have no contract with at all, which your own browser contacts directly on two particular screens. We have kept them apart rather than running them into one list, because what we can promise about them is not the same.
Data processors
These are companies we have a contract with. They process personal information on our instructions and only for the purposes we set, they are bound by obligations at least as strict as our own, and we remain responsible to you for what they do with it.
- Supabase Inc. — database and file hosting United States company; our data is stored in the United Kingdom Hosts our database and file storage, including all site records, photographs, voice notes and messages. Supabase serves stored files through Cloudflare, Inc. as their own sub-processor.
- Anthropic PBC — artificial intelligence services United States Translates messages between languages when a user has chosen a language other than English.
- Resend, Inc. — email delivery United States Sends transactional email on our behalf, such as invitations, password resets and notifications.
- Stripe — payment processing Republic of Ireland and United States Processes subscription payments and holds the card and billing information used for them. We do not store full card details ourselves.
- Railway Corp. — application hosting United States Hosts the Kerbline backend application. The backend holds the credentials used to read and write the database, so site content passes through this infrastructure whenever the service is used.
- Vercel Inc. — application hosting United States Hosts the Kerbline web application and marketing site. The application runs in your browser and sends requests to our backend; Vercel serves the application code rather than storing site content.
Third parties your browser contacts directly
Two features work by having your own browser make a request straight to another organisation. They are listed separately from the processors above because none of the promises in that paragraph apply to them: they are not our processors, we have no contract with either of them, we give them no instructions, and we send them nothing ourselves — the request goes from your device to theirs without passing through us, so we cannot bind them on your behalf. Each one receives your IP address, as any web request does, along with what is described below. Neither is used for tracking, and neither is contacted from any other screen.
- OpenStreetMap Foundation — map tiles Registered in the United Kingdom; tiles served worldwide by Fastly, Inc. (United States) Supplies the background map, but only when you open the map view of a photo gallery. Nothing is requested until you do, and nothing at all if you never open it. The request tells OpenStreetMap which map squares you are looking at, and that is the point to understand: those coordinates reveal the area you are viewing to within roughly 400 metres, which on a site gallery is the site itself. It also receives the address of the Kerbline page making the request. Around 18 requests are made when the map opens, and more each time you pan or zoom. The Foundation's privacy policy states that data from tile requests is excluded from its guarantee that personal data is held in the UK and the Netherlands.
- Have I Been Pwned — password checking Superlative Enterprises Pty Ltd, Queensland, Australia; hosted in the United States and served through Cloudflare, Inc. Checks whether the password you have chosen appears in a known data breach, so we can warn you before you use it. This happens only when you submit the signup or password-reset form, and only if your password has already passed our own checks — nothing is sent while you are typing. Your password itself is never sent. Your browser hashes it and sends only the first five characters of that hash, which are not enough to work out what the password was. The service returns every leaked hash starting with those five characters and your browser does the comparison itself, and we ask for that response to be padded with decoy entries so its size gives nothing away either.
Others we share personal information with
- Professional or legal advisors
- Organisations we are legally obliged to share personal information with
Sharing information outside the UK
Where necessary we transfer personal information outside the UK. When we do, we comply with the UK GDPR and make sure appropriate safeguards are in place.
| Organisation | Category | Country | Safeguard |
|---|---|---|---|
| Anthropic PBC | Artificial intelligence services | United States | UK Addendum to the EU Standard Contractual Clauses |
| Resend, Inc. | Email delivery | United States | UK Addendum to the EU Standard Contractual Clauses |
| Stripe | Payment processing | United States | UK Addendum to the EU Standard Contractual Clauses |
| Railway Corp. | Application hosting | United States | UK Addendum to the EU Standard Contractual Clauses |
| Vercel Inc. | Application hosting | United States | UK Addendum to the EU Standard Contractual Clauses |
Scroll the table sideways to see every column.
Where necessary, our data processors may also share personal information outside the UK. When they do, they comply with the UK GDPR and make sure appropriate safeguards are in place.
| Organisation | Category | Country | Safeguard |
|---|---|---|---|
| Supabase Inc. | Software hosting | United States | UK Addendum to the EU Standard Contractual Clauses |
Scroll the table sideways to see every column.
The two third parties your browser contacts directly are set out separately, because we cannot put a transfer safeguard in place for a request we do not make. We have no contract with either organisation, and the request goes from your browser to them without passing through us.
| Organisation | Category | Country | Safeguard |
|---|---|---|---|
| OpenStreetMap Foundation | Map tiles | United Kingdom; tiles served from a global network operated by Fastly, Inc. (United States) | None available — your browser makes the request, not us. Only when you open the map view. |
| Superlative Enterprises Pty Ltd (Have I Been Pwned) | Password breach checking | Australia; hosted in the United States | None available — your browser makes the request, not us. Only when you set a password, and your password is not sent. |
Scroll the table sideways to see every column.
How we keep information secure
We take the security of site records seriously, because the value of the service depends on the record being trustworthy.
- Separation between organisations. Every customer's data is separated at the database level. For information your browser requests directly, the database itself enforces the separation. For operations our server performs on your behalf, the server checks your membership of the site before it acts. We test both by attempting access we should not have, rather than by inspection alone.
- Private file storage. Photographs, voice notes and exported evidence packs are held in private storage. They are not publicly addressable and are served only to authenticated users with a right to see them.
- Encryption. Information is encrypted in transit. Files and database contents are encrypted at rest by our hosting providers.
- Authenticated access. All routes that return or modify data require authentication. We test new routes without credentials against realistic data before release.
- Evidence integrity. The account that sent a photograph or message, and the name and role that account held at that moment, are recorded when it is sent and cannot be changed afterwards — not by the sender, not by an administrator, and not by us. The text of a message cannot be changed once sent. A record cannot be deleted afterwards either, by anyone including us, except through a deletion the controlling customer asks us to carry out or the published trial-data cleanup. Location and time information is captured from the original file before any processing.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting personal information we will act on it, notify the ICO where the law requires it within 72 hours, and tell affected individuals and customers where the risk to them is high.
Our access to your information
Running Kerbline means our own systems can reach the information inside it. The part of the service that does work on your behalf — sending a message, building an evidence pack, running a report — connects to your organisation's database with an administrative key that the in-app permissions do not restrict. In plain terms: that key can read any site's messages and photographs, and a person operating Kerbline can therefore reach them. We are saying this directly because the rest of this notice would otherwise leave you to assume we cannot, and that would not be true.
What we do with that reach is deliberately narrow. We look at site content only where it is necessary to operate the service — to investigate a fault, recover data, or keep the service running — where you have asked us for support that needs it, or where the law requires it of us. We do not read your messages or open your photographs as a matter of routine, and never to build a profile of you, to advertise to you, or to train anything.
Browser storage
Kerbline does not set any cookies.
We use browser storage in three ways, none of them for tracking. Your sign-in session is held in local storage so you stay signed in between visits. Photographs you take while offline are held in a queue on your device until they can be sent, so nothing is lost on a site with poor signal. If you work on more than one site, the app remembers which one you were last viewing so it opens where you left off.
Your language preference is stored on your account rather than in your browser, so it follows you to any device.
We do not use analytics, advertising or tracking of any kind. There are no third-party scripts, no advertising pixels and no embedded social media. Our fonts are served from our own servers rather than loaded from Google.
There are two exceptions, and neither happens on an ordinary visit. If you open the map view of a photo gallery, your browser requests map images from OpenStreetMap, which tells them the area of the map you are looking at. If you submit the signup or password-reset form, your browser sends the first five characters of a hash of your chosen password to Have I Been Pwned to check it against known breaches. Both are described in full under who we share information with. Nothing else on any screen loads from a third party.
People under 18
Kerbline is a business tool supplied to construction companies for use on their sites. It is not marketed to or aimed at children.
We recognise that some site workers — apprentices in particular — may be under 18. Where that is the case, the construction company that runs the site decides who joins it and is the controller of the content created there. We ask our customers to make sure anyone they invite understands what the service records and why.
If you are under 18 and using Kerbline, the same rights set out in this notice apply to you. If you want to know what is held about you or you are unhappy about something, you can speak to your employer or contact us using the details above and we will help.
How to complain
If you have concerns about our use of your personal information you can complain to us:
Email: privacy@kerbline.co.uk
Post: 1 Martins Cottages, Church Lane, Bulphan, Upminster, RM14 3TS, United Kingdom
If your complaint is about site content, we will tell you which of our customers controls that record and pass your complaint to them.
If you remain unhappy after raising a complaint with us, you can complain to the Information Commissioner's Office.
ICO address:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
Kerbline