Skip to content

Rebrse Ltd

Privacy notice

What we collect, why we are allowed to hold it, how long we keep it, and what you can make us do with it.

last updated 7 September 2026

01

Who we are

Rebrse Ltd is the data controller for the personal data described in this notice. You can reach us about anything on this page at hi@rebrse.com.

Where Rebrse operates under an appointed representative arrangement, the principal firm may also be a controller for parts of the regulated activity. Those parts are identified below.

02

What we collect

  • Contact data. The email address you give us, and anything you write to us.
  • Identity data. Name, date of birth and identity document details, collected through our onboarding provider to meet anti money laundering obligations.
  • Account and transaction data. Where you connect a bank account under Open Banking, the account details and transaction records that connection returns.
  • Usage data. Records of refund requests, decisions and payments made through the service.
  • Technical data. IP address, device and browser information, and error reports, collected to keep the service running and secure.

We do not collect your banking credentials. An Open Banking connection is authorised inside your own bank and returns a token that you can revoke at any time.

03

Why we are allowed to hold it

  • Contract. To provide the service you have asked for, including assessing and paying a refund advance.
  • Legal obligation. To meet anti money laundering, fraud prevention, tax and regulatory reporting duties.
  • Legitimate interests. To prevent fraud, to secure and improve the service, and to defend legal claims. We balance those interests against your rights and record that assessment.
  • Consent. For the newsletter, and for any optional cookie that is not strictly necessary. You can withdraw consent at any time without affecting anything done before you withdrew it.

04

Who we share it with

We share personal data only with parties who need it to deliver the service, and only the parts they need. Those categories are our Open Banking and identity provider, our hosting and infrastructure providers, our email provider, our professional advisers, and regulators or law enforcement where we are required to disclose.

We do not sell personal data, and we do not share it for anyone else’s advertising.

05

Where it goes

Personal data is processed in the United Kingdom and the European Economic Area wherever possible. Where a provider processes data elsewhere, the transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement, together with a transfer risk assessment.

06

How long we keep it

Refund and payment records are kept for five years after the end of the relationship, which is what anti money laundering law requires. Newsletter subscriptions are kept until you unsubscribe, at which point the address is deleted rather than suppressed. Technical logs are kept for a shorter period and then discarded.

07

Your rights

Under UK GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing based on legitimate interests, and ask for your data in a portable form. Where a decision is made about you by automated means, you can ask for it to be reviewed by a person.

Write to hi@rebrse.com and we will respond within one month. If you are not satisfied, you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you gave us the chance to put it right first.

08

Changes

If this notice changes in a way that affects you, we will say so here and, where the change is significant, tell you directly. The date at the top of this page is the date of the current version.