Privacy policy
Last updated 9 October 2026.
This policy explains what personal data LandlordFile collects when you use this website (landlordfile.co.uk) or the LandlordFile app (app.landlordfile.co.uk), why we collect it, who we share it with, how long we keep it, and the rights you have.
1. Who we are
LandlordFile is a trading name of Metal Dog Services Ltd, a company registered in England and Wales (company number 17199387), with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Metal Dog Services Ltd is the data controller for the personal data described in this policy.
We are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We have applied to register with the Information Commissioner's Office (application reference C2046917).
For any privacy question or request, email privacy@landlordfile.co.uk or support@landlordfile.co.uk.
2. What LandlordFile does
LandlordFile is software that helps UK landlords file quarterly Making Tax Digital (MTD) for Income Tax updates to HM Revenue & Customs (HMRC). You sign in with Google or with your email address, connect LandlordFile to your HMRC account, upload a spreadsheet of your rental income and expenses, review the totals, and tell us to submit them to HMRC.
3. What data we collect
- Your sign-in details — when you sign in with Google we receive your name, email address, profile picture link and Google account ID, and store them with your account. We never see your Google password. When you sign in with your email address, we store that address and email you a one-time sign-in link; there is no password.
- Your National Insurance number — which you enter so we can find your MTD income sources at HMRC.
- HMRC connection tokens — when you connect LandlordFile to HMRC, HMRC gives us access and refresh tokens that let us act for you. We encrypt them before storing them (see section 7). We never see your HMRC sign-in password.
- Your properties — the nickname, address and acquisition date you give each property.
- Your spreadsheet — see section 4 for exactly what happens to the file you upload and what we keep from it.
- Submission records — for every filing attempt, a record of what was sent to HMRC and what HMRC said back (section 4).
- Fraud prevention data— HMRC requires all MTD software to send information about the device and connection used for each request. This includes your IP address and port, a random device identifier stored in your browser, your browser's user agent and plugins, screen and window size, time zone, Do Not Track setting, and your LandlordFile account ID. We collect this in your browser and on our servers, store it for up to 30 days, and send it to HMRC with each request we make for you.
- Payment data — if you pay for a subscription, Stripe takes your card details directly; we never receive or store them. We give Stripe your name and email address to set up your customer record, and we store your Stripe customer ID, your plan, and your subscription status and dates.
- Free filing records — a record of any free filing credit on your account (for example, from an invite link) and which submission used it.
- Technical logs — request and error logs, including IP addresses, needed to run the service securely and investigate problems. Rate-limiting counters store only a one-way hash, not your IP address or email address.
- Messages you send us — if you email us, we keep the email and our reply.
- Feedback — if you fill in the feedback form on our preview page, your answers go to a Google Form.
This website itself has no sign-up form and no analytics. If you gave us your email address before launch to hear when LandlordFile opened, see section 8 for how long we keep it.
4. Your spreadsheet and submission records
When you upload a spreadsheet, our server reads it in memory to work out your totals. We do not store the file. The rows we read from it (dates, property, category, amount, description and notes) are sent back to your browser, with a tamper-proof signature, so you can review them, and sent to our server again when you submit. They are not saved in our database.
When you submit, we keep a record of the attempt containing:
- the file name and a fingerprint (SHA-256 hash) of the file;
- a summary of how we read the file (date format, number of rows, period covered);
- any changes you made on the review screen (a row's category changed or a row excluded, the date format, or the quarter);
- the quarter, tax year and HMRC business ID;
- the exact figures sent to HMRC (your totals by HMRC category);
- HMRC's response, its confirmation, and the totals HMRC reports holding afterwards.
We keep this record whether the submission succeeded or failed. It is the evidence of exactly what was filed for you.
5. Why we use your data and our lawful basis
- To provide the service (contract) — your account details, National Insurance number, HMRC tokens, properties, spreadsheet contents, submission records, free filing records and payment data are used to give you the service you signed up for: reading your figures, filing them with HMRC, keeping your filing history, and billing.
- To meet HMRC's requirements (legal obligation) — sending fraud prevention data to HMRC with each request.
- To keep a record of what was filed (legitimate interests) — keeping submission records after an account closes, so we can answer questions from you or HMRC about a filing and deal with any legal claims.
- To keep the service secure (legitimate interests) — technical logs and rate limiting, to protect the service and our users from abuse and to fix problems.
- To answer you and improve the product (legitimate interests) — replying to your emails and reading feedback.
We do not sell your data, share it for advertising, or use it to make automated decisions that have legal or similarly significant effects on you.
6. Who we share it with
HMRC. When you tell us to file, we send your figures, your identifiers and the fraud prevention data above to HMRC through its MTD APIs. HMRC is a separate controller of that data.
We use the following service providers (processors) to run LandlordFile. They act on our instructions and may not use your data for their own purposes.
- Vercel— hosts this website and the app. The app runs in Vercel's London region. Vercel is a US company.
- Neon — our Postgres database, which holds your account and submission records, in the London (AWS eu-west-2) region. Neon is a US company.
- DigitalOcean — our edge server in London, which all traffic to the app passes through, and which keeps short-lived access logs. DigitalOcean is a US company.
- Google— “Sign in with Google”, the feedback form on our preview page, and our email. Google is a US company.
- Stripe — payments. Stripe handles your card details in its own PCI-DSS compliant systems and operates in the UK, EU and US.
- Postmark — sends the sign-in link email when you sign in with your email address. Postmark is a US company.
We may also disclose data where the law requires it, or to protect our rights or other people's safety.
7. How we secure your data
All connections to LandlordFile use TLS 1.2 or later. Our database is encrypted at rest by our hosting provider. HMRC tokens are also encrypted by the app itself (AES-256-GCM) before they reach the database, with keys held separately from the database.
8. How long we keep it
- Your account— your sign-in details, National Insurance number, properties and HMRC tokens are kept while your account is open. You can delete your account at any time in the app's Settings (section 10).
- HMRC tokens — deleted when you disconnect HMRC in Settings or delete your account, and we ask HMRC to revoke them. HMRC ends the connection itself after 18 months.
- Fraud prevention data — up to 30 days per browser session, and deleted straight away if you delete your account. HMRC keeps what we send it under its own policies.
- Submission records — kept for seven years after your account closes, so there is a record of what was filed for you.
- Payment records — our copy of your Stripe customer ID and subscription is kept after your account closes, for our financial records. Stripe keeps its own payment records as the law requires.
- Technical logs — kept for a short period, normally no more than 30 days, then deleted.
- Emails you send us — kept while we need them to help you, then deleted.
- Feedback form answers — kept while we use them to improve the product.
- Pre-launch email sign-ups — email addresses left on this site before launch are used only to tell you LandlordFile is open, and deleted on request.
9. International transfers
Your account and submission records are stored in the UK (London). Some of our providers are based in the United States, so personal data may be accessed from or processed in the US — for example when you sign in with Google, when Stripe handles a payment, or when a provider gives technical support. Where data leaves the UK, we rely on the UK–US data bridge for providers certified under it, or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
10. Deleting your account
You can delete your account yourself in the app's Settings. When you do, we ask HMRC to revoke our access, immediately delete your HMRC tokens, fraud prevention data, properties, sessions and any Google sign-in link, and erase your name, email address, profile picture and National Insurance number from your account. Your submission records are kept for the period in section 8, no longer linked to your name or email address. To remove LandlordFile from your HMRC account as well, use the “manage authorised applications” page in your HMRC online account.
11. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate data;
- ask us to erase your data (you can delete your account yourself, as above), except where we need to keep submission records;
- receive your data in a portable format — you can download your submission history from the app, or ask us for a copy;
- object to, or ask us to restrict, how we use your data;
- complain to the Information Commissioner's Office (below).
To use any of these rights, email privacy@landlordfile.co.uk. We will reply within one month.
12. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.
13. Cookies and browser storage
This website sets no cookies of its own and uses no analytics or advertising cookies. The feedback form on our preview page is embedded from Google, which may set its own cookies when it loads.
The app uses only strictly necessary cookies and browser storage: to keep you signed in, to protect sign-in against forgery, to carry an invite link through sign-up, and to hold the fraud prevention session and device identifier HMRC requires. We will not add analytics or advertising cookies without asking for your consent.
14. Reporting a security issue
If you believe you have found a security vulnerability in LandlordFile, email security@landlordfile.co.uk. We aim to acknowledge reports within two working days. Please do not disclose the issue publicly until we have had a chance to investigate and fix it.
15. Changes to this policy
If we make material changes to this policy we will update the date at the top of this page and, for registered users, email you at least 14 days before the changes take effect.
16. Contact
Metal Dog Services Ltd (trading as LandlordFile), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Email privacy@landlordfile.co.uk for privacy requests, or support@landlordfile.co.uk for anything else.