Privacy notice
Payslip processing privacy notice
A complete, plain-English description of what PayslipIQ does - and does not do - with the data on a UK payslip you upload or type in.
Published 2026-05-09. Last reviewed 2026-08-26. Sits alongside the general privacy policy.
1. What data users may upload
PayslipIQ accepts UK and Ireland payslip images as JPEG, PNG or WebP, up to 5 MB per file. PDF and HEIC are not accepted by the uploader.
A typical payslip contains some or all of: employer name, employee name, employee number, National Insurance number, address, date of birth, pay date, tax code, NI category, gross pay, taxable pay, PAYE, NI, pension contribution, student loan deduction, year-to-date totals and net pay.
You can also enter the same figures manually instead of uploading. Manual entry never sends an image of the payslip - only the typed numbers.
2. What data users should redact
Before uploading, please redact:
- Your full name (initials are fine).
- Your home address.
- Your National Insurance number.
- Your date of birth.
- Your bank account number and sort code.
- Your employee number, if you would prefer not to share it.
Leave the pay figures, tax code, NI category, deduction lines and YTD totals visible - these are what PayslipIQ needs to read. A black marker, a piece of tape, or a quick crop on your phone is enough.
3. What data PayslipIQ needs
To produce a useful explanation, PayslipIQ needs to read:
- Pay date and pay frequency.
- Tax code.
- NI category letter.
- Gross pay for the period.
- Taxable pay for the period.
- Each deduction line (PAYE, NI, pension, student loan, other).
- Net pay for the period.
- Year-to-date totals where available.
4. What data PayslipIQ does not need
PayslipIQ does not need and will not ask for:
- Your bank account number or sort code.
- Your full home address.
- Your date of birth.
- Your National Insurance number.
- Your HMRC sign-in credentials. We never ask you to log in to HMRC and we are not affiliated with HMRC.
- Your employer login credentials.
If your payslip image still contains these fields after redaction, PayslipIQ will process the file but will not extract those fields into the explanation.
5. Whether images are stored
No. PayslipIQ does not retain your payslip image after the analysis is complete.
Operationally: the file is held in volatile memory inside the analysis worker only. As soon as the explanation has been produced and returned to you, the file is purged. We do not write the image to durable storage, do not back it up, and do not include it in any export.
If you choose to receive an email copy of your report, the email contains the explanation text only - never the original image.
6. Whether logs are stored
PayslipIQ does not keep a 90-day hashed-IP security log of every check. Payslip figures, the image, and the generated explanation are not written to application logs. What we actually retain is:
- Vercel request logs (hosting): HTTP path, status and timing for up to 30 days. These are the platform logs, not a PayslipIQ database of payslip figures.
- Upstash rate-limit (EU Redis): a salted hash of the IP address, not the IP itself. The per-IP analyse window expires within 1 hour. The daily Anthropic call counter expires within 26 hours.
- First-party funnel counters (EU Redis): per-day counts of named events plus a small allow-list of properties (region, pay frequency, source, has_pension). No IP, no user-agent, no identifier, no payslip figures. Keys expire after 90 days.
- Web vitals (EU Redis): performance samples that include a salted IP hash and the browser user-agent, retained for up to 30 days.
- CSP violation reports: written to Vercel logs with request metadata (including IP and user-agent) and retained with those request logs for up to 30 days.
There is no separate 90-day store of hashed IPs, user-agents, file sizes or MIME types for abuse prevention beyond the items above.
7. How AI processing works
PayslipIQ uses a third-party large language model provider (Anthropic) on two paths.
The flow is:
- Manual entry: only the numbers you type are sent, together with the rules of the relevant tax year.
- Photo upload: the image you choose (after in-browser downscale and EXIF strip) is sent to Anthropic. Anything still visible in that image, including name, employer or National Insurance number if you have not covered them, is visible to the model. Automatic redaction is not implemented.
- The AI provider returns the plain-English explanation, anomaly flags and suggested questions for payroll.
- PayslipIQ formats and returns the explanation to you. The image is not written to an application database.
Under our enterprise configuration, the AI provider does not use your inputs to train models. The provider may temporarily retain inputs for safety/security under its own terms - currently up to 30 days for our account - and does not share them with other customers.
8. Third-party providers involved
The processors PayslipIQ relies on, and what each one sees:
- Vercel - hosting and function runtime. A photo check is processed in that runtime, so the request body can include the image. PayslipIQ does not write the image to Vercel Blob or an application database. Request logs (path, status, timing) are retained by Vercel for up to 30 days.
- Anthropic (Claude) - large language model. Photo path: sees the image you upload. Manual path: sees the numbers you type. Does not persist the image on PayslipIQ servers. Anthropic may retain inputs for up to 30 days for trust-and-safety.
- Stripe - only invoked when you purchase a Pro Report. Sees: your name, billing email, payment details. Does not see: your payslip data.
- Resend / MailerLite - only invoked when you opt in to an emailed copy or newsletter. Sees: your email address and the explanation text you asked us to email. Does not see: your image.
- Upstash - rate limiting and abuse prevention. Sees: hashed IP and event counters. Does not see: payslip contents.
No third party is given the right to use your data for marketing or model training.
9. Retention periods
Summary of how long PayslipIQ keeps each category of data:
- Payslip image: not retained after analysis (purged within seconds).
- Manually-entered figures: not retained after the explanation is returned, unless you explicitly opt in to email yourself a copy.
- Generated explanation: not retained server-side, unless you explicitly opt in to email or save.
- Vercel request logs: up to 30 days.
- Upstash rate-limit hashes: 1 hour (analyse window); daily Anthropic counter 26 hours.
- First-party funnel counters (no identifiers): 90 days.
- Web vitals samples (salted IP hash and user-agent): up to 30 days.
- Consent-gated Google Analytics 4 and Microsoft Clarity: only after cookie consent. Retention is set in each provider property; the current published figures are on the Trust Centre sub-processor table.
- Pro Report purchase records: retained for 7 years to meet UK accounting and HMRC requirements.
- Email subscriber records: retained until you unsubscribe.
10. Deletion request route
You can request deletion of any data PayslipIQ holds about you at any time. Because the payslip itself is not retained, most deletion requests apply to email subscriptions and Pro Report purchase records. First-party funnel counters are aggregate daily totals and cannot identify you. Web-vitals hashes are not a user-facing identifier we can look up from an email address.
To request deletion, email privacy@payslipiq.co.uk with the subject "Deletion request". Please include the email address you used (for newsletter or Pro Report identification). We aim to action deletion requests within 14 days and confirm completion in writing.
11. DPO contact route
Data Protection enquiries should be addressed to: privacy@payslipiq.co.uk.
PayslipIQ is a trading name of GoldPaid Ltd, a company registered in England and Wales (no. 17382540). Registered office: Unit 217, Bristol Business Centre, 179 Whiteladies Road, Clifton, Bristol BS8 2AG. ICO registration ZC214216.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/ if you are not satisfied with our response.
Need to escalate?
For any privacy query, deletion request or DPO matter, write to privacy@payslipiq.co.uk. You also have the right to complain to the ICO at ico.org.uk/make-a-complaint.