This Privacy Policy explains how Shake On It Limited, trading as TradeFile.ie ("we", "us", "our"), collects, uses, stores, and protects your personal data. We act as a Data Controller for your account management and billing data, and as a Data Processor when handling documents strictly on your instructions to deliver our document organisation service. We are committed to processing personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Protection Acts 1988–2018 (Ireland), and all applicable Irish and European Union data protection law.
| Data Controller / Processor | Shake On It Limited (trading as TradeFile.ie) |
| CRO Number | 814707 |
| Registered Address | Office 2, 12A Lower Main Street, Lucan, Co Dublin, Ireland |
| Contact Email | info@shakeonit.ie |
| 087 204 3049 |
As a core part of our service, you transfer business documents to us including receipts, invoices, supplier statements, and related paperwork. We process these documents strictly as a Data Processor acting on your instructions to fulfil our contract with you.
These documents may contain supplier names and VAT numbers, transaction amounts and dates, bank account references (where visible on documents), business addresses, and names of third parties appearing on submitted documents.
We do not analyse, interpret, audit, or act on the financial content of these documents beyond naming and filing them. Any category labels applied are for organisational purposes only and do not constitute financial or tax advice.
Payment is processed by Stripe, Inc. We do not collect or store your card details. Stripe processes payment data under its own privacy policy (available at stripe.com/ie/privacy) and acts as an independent data controller for payment processing. We receive transaction confirmation and basic billing information from Stripe.
We process your personal data on the following legal bases under Article 6 GDPR:
| Data Category | Legal Basis | Purpose |
|---|---|---|
| Identity and contact data | Contract (Art. 6(1)(b)) | To set up and manage your account and deliver the service |
| Business documents submitted | Contract (Art. 6(1)(b)) | To perform the document organisation service you have contracted for |
| Payment and billing data | Contract / Legal obligation (Art. 6(1)(b) & (c)) | To process payments and comply with financial record-keeping law |
| Communications | Legitimate interests (Art. 6(1)(f)) | To respond to queries and maintain service records |
| Website usage / cookies | Consent / Legitimate interests (Art. 6(1)(a) & (f)) | See Cookie Policy |
| Legal compliance | Legal obligation (Art. 6(1)(c)) | To comply with Irish tax, company law, and Revenue requirements |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests at any time — see Section 9.
We use your personal data solely for the purposes described in Section 3. Specifically:
We will never use your data for marketing purposes without your explicit consent. We will never sell, rent, or trade your personal data to any third party.
We share your personal data only in the following limited circumstances:
| Third Party | Purpose | Notes |
|---|---|---|
| Google Ireland Limited | Google Drive / Sheets document storage | EU hosted. Google acts as data processor under our DPA. |
| Stripe, Inc. | Payment processing | Independent controller. See stripe.com/ie/privacy |
| WhatsApp (Meta Platforms Ireland Ltd) | Document receipt via WhatsApp Business | Meta processes WhatsApp data under its own privacy policy. |
| Irish Revenue Commissioners | Statutory obligation | Disclosed only where legally required. |
| An Garda Síochána / other authorities | Legal requirement | Disclosed only where required by law or court order. |
We do not transfer personal data outside the European Economic Area (EEA) except where the European Commission has issued an adequacy decision for the destination country, or where appropriate safeguards are in place (such as Standard Contractual Clauses). Where US-based processors are used (e.g. Stripe), we rely on Standard Contractual Clauses or equivalent mechanisms approved under GDPR Chapter V.
We retain personal data only for as long as necessary for the purposes for which it was collected, subject to any legal retention obligations.
| Data Type | Retention Period | Reason |
|---|---|---|
| Client account data | Subscription + 7 years | Revenue and company law record-keeping requirements |
| Business documents filed | 7 years from submission | Revenue's standard investigation period |
| Payment records | 7 years | VAT and corporation tax obligations |
| Communications | 3 years from last contact | Dispute resolution and legal purposes |
| Website technical / log data | 12 months | Security and fraud prevention |
| Cookie consent records | 3 years from consent date | GDPR accountability requirements |
On cancellation of your subscription, your Google Drive folder access will be revoked. We will retain copies of your filed documents for the applicable retention period. You should download and retain your own copies before cancelling.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and will notify you without undue delay where the breach is likely to result in a high risk to your rights, in accordance with Articles 33 and 34 GDPR.
We use cookies and similar technologies on our website. For full details of the cookies we use, our legal basis for using them, and how to manage your preferences, please see our Cookie Policy.
Under GDPR and the Data Protection Acts 1988–2018, you have the following rights. These rights apply in most circumstances but may be subject to limitations where permitted by law.
To exercise any of these rights, contact us at info@shakeonit.ie with the subject line "Data Subject Request". We will respond within one calendar month. We may request proof of identity before processing your request.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. All document organisation is carried out by human operators. No automated decisions are made in relation to your data.
Our services are directed at adults (18 years and over) operating businesses. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that personal data of a minor has been collected, we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by email at least 30 days before they take effect. The current version will always be available at tradefile.ie/privacy.
| Data Controller / Processor | Shake On It Limited (trading as TradeFile.ie) |
| CRO | 814707 |
| Address | Office 2, 12A Lower Main Street, Lucan, Co Dublin, Ireland |
| Privacy queries | info@shakeonit.ie |
| Supervisory Authority | Data Protection Commission (DPC) |
| DPC Address | 6 Pembroke Row, Dublin 2, D02 X963 |
| DPC Website | www.dataprotection.ie |
| DPC Phone | 01 765 0100 / 1800 437 737 |
087 204 3049 — we'll get back to you quickly
WhatsApp Us Now