Burlea Apps
MyAdminAssistantMyWhiskyMyShopAdminMyGamesHubAll apps

Privacy & Security Policy

Last updated: 4 August 2026

This policy explains how Burlea App Development collects, uses, protects and shares your personal data across its apps, and the security measures we apply. It includes a dedicated section on ourHMRC Making Tax Digital (MTD) for VAT integration in the MyShopAdmin app, which connects to HMRC’s APIs on your behalf.

1. Who we are & how to contact us

Burlea App Development (“we”, “us”, “our”) develops and operates a portfolio of mobile and desktop apps, listed atburleaapps.co.uk. For the personal data described in this policy, Burlea App Development is the data controller and is responsible for keeping your data secure. For any privacy question, or to exercise your data rights (section 8), contact us atinfo@burleaapps.co.uk.

2. What data we collect and why

We only collect the data an app needs to do its job. What is collected depends on which app you use:

  • Account details — your email address (and, for apps that offer Google sign-in, your Google account name and profile photo), used to sign you in and sync your data across your devices. Sign-in is handled by Google Firebase Authentication.
  • App content you create — for example, in MyShopAdmin: your inventory, suppliers, invoices, sales, payroll and accounting records; in other apps, the content relevant to that app.
  • Diagnostic information — limited crash and error reports to help us fix problems and keep the apps reliable.
  • HMRC VAT data — see section 4.

We do not sell your personal data, and we do not use it for advertising.

3. Our lawful basis for processing

We process personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, relying on:

  • Performance of a contract — to provide the app’s core features (signing you in, storing and syncing your data, submitting a VAT return you have prepared).
  • Legitimate interests — to keep the apps secure, reliable and free from fraud (diagnostics, and the HMRC-required fraud-prevention data in section 4).
  • Legal obligation — where we must supply data to HMRC to complete a submission you have authorised.
  • Consent — where you separately opt in. You can withdraw consent at any time.

4. HMRC integrations — MyShopAdmin & MyCompanyDueDil

Two of our apps connect to HMRC. MyShopAdmin usesMaking Tax Digital (MTD) for VAT to file your VAT return, and HMRC’s Check a UK VAT Number service to verify a supplier’s VAT registration for due diligence.MyCompanyDueDil also uses HMRC’s Check a UK VAT Number service as part of its company due-diligence checks (alongside Companies House data). Each HMRC service is described below.

4a. Making Tax Digital for VAT — MyShopAdmin (filing your return)

You sign in with HMRC — not with us

We connect to HMRC using OAuth 2.0 with PKCE, the method HMRC requires. When you connect, the app opens HMRC’s own website in your browser, and you enter your Government Gateway sign-in details directly on HMRC’s site. Burlea App Development never sees, collects or stores your HMRC sign-in username or password.

Access tokens are held encrypted, on your device only

After you authorise access on HMRC’s site, HMRC issues the app a temporaryaccess token (and a refresh token). These are storedonly on your own device, inside your operating system’s secure key store (Windows Credential Locker / DPAPI; Android Keystore), so they are encrypted at rest. They are neveruploaded to our servers or the cloud, and you can revoke them at any time by disconnecting HMRC in the app.

What VAT data is used, stored and sent to HMRC

  • Your VAT Registration Number (VRN) and your choice of HMRC’s live or sandbox environment.
  • The nine-box VAT return figures you prepare, your VAT periods/obligations retrieved from HMRC, and HMRC’s receipt reference for a submitted return — stored against your store as a record of what was filed.
  • When you submit, the app sends your nine-box return to HMRC over an encrypted (HTTPS) connection.

The app requests only the read:vat and write:vatpermissions needed to read your VAT obligations and submit your return.

Fraud-prevention data required by HMRC

HMRC requires software that connects to its APIs to sendfraud-prevention header data so HMRC can protect taxpayers against fraud. When you use the VAT feature, the app transmits the following to HMRC with each request, as mandated by HMRC’s fraud-prevention specification:

  • A randomly generated device identifier for the installation (not linked to any other identity);
  • Your operating-system user name, OS name and version;
  • Your screen and application window size and colour depth;
  • Your time zone and connection method;
  • Our software vendor and version identifier.

This data is sent to HMRC only, solely to satisfy HMRC’s fraud-prevention requirement, and is not used by us for any other purpose.

4b. Check a UK VAT Number — MyShopAdmin & MyCompanyDueDil (due diligence)

MyShopAdmin and MyCompanyDueDil can verify whether a business’s VAT registration number is valid using HMRC’s “Check a UK VAT Number” service, and record HMRC’s confirmation as evidence that the check was performed. For this feature:

  • The check runs through our secure backend, not from the app directly. The HMRC credentials used for this service are heldonly on our server and are never placed in the app.
  • The only data sent is the VAT number being checked andyour own business’s VAT number (which HMRC records so the confirmation is attributed to you). No personal HMRC sign-in is involved, and no HMRC access tokens are created or stored for this feature.
  • HMRC returns confirmation of the supplier’s details and aconsultation reference, which the app keeps as a record that you carried out the check.
  • All calls use encrypted (HTTPS) connections.

5. How we protect your data (security)

  • Encryption in transit. All communication with our services and with HMRC uses encrypted HTTPS/TLS connections.
  • Encryption at rest. HMRC access tokens are stored in your device’s OS-backed secure key store (encrypted at rest, on your device only). Data stored in our cloud services is held on Google Firebase and encrypted at rest by the platform.
  • Data separation. Your data is scoped to your account and, in MyShopAdmin, to your store, and is protected by server-side access rules so one account cannot read or change another’s data.
  • Least privilege. We request only the access each feature needs (for HMRC, only the VAT read/submit permissions above).
  • Security testing & review. We test our software for security vulnerabilities before releasing changes that affect the HMRC integration, and periodically review our security controls and our compliance with data-protection law.
  • Fraud prevention. We implement HMRC’s fraud-prevention header specification and test those headers against HMRC before going live.

6. Data sharing & third parties

  • HMRC — the VAT data and fraud-prevention data described in section 4, when you submit a return.
  • Google Firebase (Google Cloud) — authentication, database and file storage. MyShopAdmin’s data is hosted in theUK/Europe (London, europe-west2) region.
  • Payment and platform providers used by a specific app (for example, Shopify and Stripe in MyShopAdmin) to deliver features you use.

We do not sell your data or share it for third-party marketing.

7. Data retention

We keep your data for as long as you use the app and keep an account with us. VAT records are retained so you have a history of what was filed. When you delete your account or ask us to erase your data, we delete it, except where we are required to keep certain records to meet a legal obligation. HMRC access tokens live only on your device and are removed when you disconnect HMRC or uninstall the app.

8. Your rights & control of your data

Under UK GDPR you have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. You can:

  • Access and export your data, so you can move to another provider;
  • Correct inaccurate data;
  • Delete your data and close your account;
  • Disconnect HMRC at any time in MyShopAdmin, which revokes and removes the stored access tokens.

To exercise any of these rights, emailinfo@burleaapps.co.uk. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

9. Marketing

We will not share your personal data for marketing without your consent, and we do not send marketing based on your HMRC or VAT data.

10. Changes to this policy

We may update this policy from time to time. The “last updated” date at the top shows when it last changed. Material changes will be reflected here at this URL.

Burlea App Development

Reliable, mobile-first apps for people and small teams.

info@burleaapps.co.ukPrivacy & Security PolicyTerms & Conditions© 2026 Burlea App Development