Privacy Policy
Last updated: 24 April 2026
1. Who we are
CashGap is a trading name of Voxa Automation Ltd, a company registered in England and Wales (Company No. 16984959). Voxa Automation Ltd is the data controller for the personal data described in this notice. You can contact us at privacy@cashgap.co.uk.
2. Our role
CashGap operates as an unregulated commercial finance introducer. We are not a lender, we do not hold client money, and we do not make credit decisions. When you request an advance, we pass the information needed to quote and underwrite to the lender you have selected. That lender becomes an independent data controller for its own credit-decisioning and customer-onboarding activities.
3. Information we collect
- Account details you provide: name, email address, phone number, business name and type, turnover band, company number (where applicable), and password hash.
- Read-only invoice, customer and payment data pulled via OAuth from Xero, Sage Business Cloud Accounting, QuickBooks Online or FreeAgent. We never have write access to your accounting ledger.
- Operational data generated when you use CashGap: advance requests, eligibility outcomes, activity logs, IP address, and device metadata used for security and abuse prevention.
- Communications you send us by email or in-app.
4. Why we use your data and legal basis
- Contract (Art. 6(1)(b) UK GDPR): to run your account, assess invoice eligibility, and pass your application to a lender you have selected.
- Legitimate interests (Art. 6(1)(f)): to secure the service, detect fraud, and improve the product.
- Legal obligation (Art. 6(1)(c)): to retain financial records and respond to regulatory requests.
- Consent (Art. 6(1)(a)): for optional marketing emails, which you can withdraw any time via Settings → Notifications.
5. Who we share it with
- Lender panel partners, only when you submit an advance request and only the data required to quote and onboard you.
- Infrastructure processors: Supabase (database, auth, file storage — EU/UK region), Vercel (hosting), Resend (transactional email). Each is bound by a data processing agreement.
- Accounting providers (Xero, Sage, QuickBooks, FreeAgent) only to maintain the OAuth connection you authorised.
- Professional advisors, regulators, and law enforcement where legally required or to defend our rights.
6. Broker commission
When a lender funds an advance you requested through CashGap, that lender pays us a commission. The existence, source, and (where practical) amount of that commission is disclosed to you before you submit an advance request, in line with the Supreme Court's guidance in Johnson v FirstRand Bank Ltd (2025). Commission does not increase the fee you pay.
7. International transfers
We store personal data in the UK/EU. Where a processor (for example Vercel edge or a lender partner) transfers data outside the UK, we rely on UK IDTA / EU Standard Contractual Clauses and additional safeguards as appropriate.
8. Automated decision-making
The eligibility score shown in CashGap is an automated, rule-based indicator. It is not a credit decision and has no legal effect: whether to offer you finance, and on what terms, is decided by the selected lender. You can always ask us to review an eligibility outcome by emailing privacy@cashgap.co.uk.
9. How long we keep it
We keep account data for as long as your account is active, plus 7 years after closure to comply with HMRC, AML, and financial record-keeping requirements. Backups are purged on a rolling 30-day cycle.
10. Your rights
Under UK GDPR you have the right to access, correct, erase, or port your personal data, to restrict or object to processing, and to withdraw consent to marketing. Email privacy@cashgap.co.uk to exercise these rights. If you are not satisfied with our response you can complain to the Information Commissioner's Office (ico.org.uk).
11. Security
OAuth tokens and other sensitive values are encrypted at rest using AES-256-GCM. Traffic is HTTPS-only with HSTS. Access to production systems is limited to named operators with MFA.
12. Updates
We will update this notice as the service evolves. We'll email you about material changes before they take effect.