This Privacy Policy explains what personal data is processed through MARF Site Manager ("MARF", "the Platform", "we", "us"), how it's handled, and what rights individuals have over it. MARF is operated by [MARF Site Manager Ltd — company registration number to be confirmed], a company registered in England and Wales, and processes personal data in accordance with the UK GDPR and the Data Protection Act 2018.
If you are an employee, subcontractor or operative whose data is entered into MARF by your employer or engager, please also check with them directly — as the data controller, they are responsible for telling you what's collected and why, and for handling your rights requests in the first instance (see "Your Rights" below).
Subscription billing is handled by Stripe, Inc. Card details are entered directly into Stripe's hosted Checkout and Billing Portal — MARF never receives or stores full card numbers. We hold the Customer's billing contact name/email and Stripe's customer/subscription reference IDs only.
The Android app registers a device token (via Firebase Cloud Messaging) so the Platform can deliver reminders — expiring certifications, timesheet approvals, and similar. Device tokens are used solely for this purpose and are deleted when a device is removed or a user is deactivated.
The web dashboard stores a short-lived access token and a longer-lived refresh token in your browser to keep you signed in. No third-party advertising or analytics cookies are used in the MARF application itself.
This public marketing site (usemarf.com) uses Google Analytics 4
to understand how visitors find and use the site. Analytics cookies are not set until you
choose "Accept" on the cookie banner — we run Google Consent Mode with
analytics_storage denied by default, so no _ga cookie or analytics
identifier is stored if you decline or ignore the banner. IP addresses are truncated before storage,
Google Signals / advertising personalisation is disabled, and data is retained for 14 months. Your
accept/decline choice is remembered in your browser's local storage; clear it to be asked again.
This applies only to the marketing website, never to the logged-in MARF application.
Where MARF processes personal data as the Customer's processor, the Customer determines the legal basis (typically performance of the employment contract, legal obligation — e.g. HMRC payroll records or RIDDOR reporting — or legitimate interests in running a safe site). Where MARF itself is the controller — for example, billing contact details, or visitor data on this marketing website — our basis is performance of our contract with the Customer and our legitimate interest in operating and improving the Platform.
| Sub-processor | Purpose |
|---|---|
| Stripe, Inc. | Subscription billing and payment processing |
| Resend | Transactional email delivery (invites, notifications, verification links) |
| Firebase Cloud Messaging (Google) | Mobile push notification delivery |
| Google Analytics (Google LLC) | Marketing-website usage analytics — consent-gated, marketing site only |
| Our infrastructure hosting provider | Application and database hosting |
A full, current sub-processor list and a Data Processing Agreement are available on request — contact us using the details below.
Each Customer's Financial Admin can configure retention windows for their own company under Settings → GDPR. Defaults are aligned to UK legal minimums:
| Category | Default retention |
|---|---|
| Timesheets (HMRC payroll records) | 7 years |
| Signed documents | 7 years |
| Certifications & training records | 3 years |
| Incident reports (RIDDOR) | 3 years |
| Audit log (ICO guidance) | 5 years |
| Site check-ins | 1 year |
| Leave requests, induction submissions | 2 years |
If your data was entered by an employer or engager using MARF, please raise requests with them first — they are the controller and can action most requests directly from their own Settings → GDPR area (Subject Access Request export, erasure request). Where a request needs to reach us directly, you have the right to:
MARF is a workforce management tool for employees and subcontractors of construction businesses and is not directed at children. We do not knowingly process data relating to anyone under working age.
We will update the "Last updated" date above whenever this policy changes materially. Continued use of the Platform after an update constitutes acceptance of the revised policy.
For privacy questions, Data Processing Agreement requests, or to exercise your rights under UK GDPR: support@usemarf.com
We aim to respond to data-related requests within 30 days, as required by UK GDPR.