Terms of service
1. About these terms
These terms are an agreement between site software Ltd (company number 17471847, registered office 8 Mostyn Road, Bushey, Hertfordshire, WD23 3PN) (“we”, “us”) and the business that signs up to use costin (“you”). They cover the costin software and any support we give with it (together, the “Service”).
costin is for businesses. By signing up you confirm you are acting for a business, and that the person accepting these terms has authority to bind it. Our privacy policy explains how we handle personal data about the people who use costin. Schedule 1 below covers the data you keep in costin.
2. The Service
costin helps building firms run enquiries, quotes, jobs, orders, supplier invoices, labour and sales invoices in one place. Each firm has its own separate copy of the app and its own database. We may improve and change the Service over time. We will not remove a major feature you rely on without giving you reasonable notice.
During early access, some features may be marked as new or in testing. They may change or be withdrawn, and are provided without the commitments in section 9.
3. Accounts and users
- costin is charged per user. Each person needs their own login. Logins must not be shared, and costin shows you where each login is being used so you can check.
- You choose what each user can see (for example, site staff who can’t see prices or wages), and you are responsible for what your users do in costin.
- Keep passwords private. Tell us straight away at hello@costin.app if you think a login has been misused.
4. Fees and payment
- Fees are £20 per user per month, plus VAT, billed monthly in advance by card or Direct Debit.
- If a payment is more than 14 days late we may suspend access after giving you notice. Your data is kept safe while access is suspended.
- We may change our prices with at least 30 days’ notice. The new price applies from your next billing date after the notice ends.
- We may charge interest on late payments under the Late Payment of Commercial Debts (Interest) Act 1998.
5. Your data
- Everything you put into costin (“Your Data”) belongs to you.
- You give us permission to store and process Your Data only to provide the Service to you, to keep it secure and backed up, and to give you support.
- We do not sell Your Data, use it for advertising, or use it to train artificial intelligence models.
- You can export Your Data at any time using the exports built into costin, and ask us for a full copy (see section 13).
- You are responsible for having a lawful basis to store the personal data you put in costin, and for its accuracy. Schedule 1 sets out how we handle it on your behalf.
6. Connecting your accounting software
If you connect costin to Xero or QuickBooks, you authorise us to send the records you choose (such as sales invoices, supplier bills, subcontractor payments and the matching contacts) to your accounting software, and to read back what is needed to keep them in step (such as whether an invoice has been paid). Your use of that software is governed by its own provider’s terms. You can disconnect at any time from costin’s settings or from the accounting software.
7. What costin is not
costin helps you keep records and work figures out, including VAT, the domestic reverse charge and CIS deductions. It is not tax, accounting or legal advice. You are responsible for checking figures before relying on them, and for what you file with HMRC. Where costin reads information from documents automatically, such as supplier invoices, it asks you to check what it has read. You remain responsible for what is saved.
8. Acceptable use
You must not:
- use the Service for anything unlawful, or to store content you have no right to hold;
- try to get into another firm’s data, test or break our security, or overload the Service;
- copy, resell, or reverse-engineer the Service, or use it to build a competing product.
9. Availability, support and backups
- We aim to keep costin available at all times, apart from planned maintenance, which we will try to do outside working hours.
- Support is by email at hello@costin.app, Monday to Friday, 8am–5pm UK time. We aim to reply within one working day.
- Each firm’s data is backed up every night, and further daily copies of the storage are kept for 30 days. An encrypted copy of each nightly backup is also kept off-site, in the EU. We check backups when they are made. Even so, we recommend you export your records regularly.
10. Our intellectual property
The costin software, name and logo belong to site software Ltd. While you are a customer, you have a non-exclusive, non-transferable right for your users to use the Service for your business. Suggestions you send us may be used to improve costin, with no obligation to you.
11. Confidentiality
Each of us will keep the other’s confidential information private and use it only for this agreement, unless it is already public or the law requires it to be disclosed.
12. Liability
- Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud, or for anything else the law does not allow to be limited.
- Neither of us is liable for indirect or consequential loss, or for loss of profit, revenue, business or goodwill.
- We are not liable for decisions made from figures in costin, for records entered or saved by your users, or for anything done in your accounting software.
- Otherwise, our total liability in any 12 months is limited to the fees you paid us in the 12 months before the claim arose.
13. Ending the agreement
- The agreement runs month to month. You can cancel with 30 days’ notice by email, and we will stop billing at the end of that period.
- We can end it with 30 days’ notice, or immediately if you seriously break these terms (including non-payment after suspension) and don’t put it right within 14 days of being asked.
- After it ends, you have 30 days to export Your Data or ask us for a full copy (the database and your documents). After that we delete Your Data from the live system. Copies in backups are deleted as those backups roll off, within a further 60 days.
14. Changes to these terms
We may update these terms. We will give you at least 30 days’ notice by email of any change that affects you materially. If you don’t agree, you may cancel before the change takes effect.
15. General
- These terms, including Schedule 1, are the whole agreement between us about the Service.
- Neither of us is responsible for delays caused by events outside our reasonable control.
- You may not transfer this agreement without our written agreement. We may transfer it to a company that takes over the Service, and will tell you if we do.
- These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Schedule 1 — Data processing
This schedule forms part of the terms and meets the requirements of Article 28 of the UK GDPR. For the personal data you keep in costin, you are the controller and we are the processor.
1. What we will do
- Process the personal data only on your documented instructions, which are these terms and how you use costin, unless the law requires otherwise (in which case we will tell you, unless the law forbids it).
- Make sure anyone we allow to process it is bound by confidentiality.
- Keep appropriate technical and organisational security measures in place (paragraph 5).
- Only use the sub-processors listed in paragraph 4. We will give you at least 30 days’ notice of any new one, and you may object. If we can’t resolve the objection, you may end the agreement without penalty. Each sub-processor is bound by data protection terms at least as protective as these.
- Help you, as far as we reasonably can, to respond to requests from people exercising their rights, and with security, breach notifications and data protection impact assessments.
- Tell you without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting your data, with the information you need to meet your own duties.
- At the end of the agreement, return or delete the personal data as set out in section 13 of the terms, unless the law requires us to keep it.
- Make available the information you reasonably need to show these obligations are met, and allow reasonable audits on reasonable notice, at your cost, no more than once a year unless a breach has occurred.
- Not transfer the personal data outside the UK unless a lawful safeguard is in place (paragraph 4).
2. What you will do
- Make sure you have a lawful basis to store and use the personal data you put in costin, and give people the privacy information the law requires.
- Not store special category data (such as health information) in costin unless you have a lawful basis for it and it is necessary. For example, keep emergency contact details brief.
3. The processing
| Subject matter and duration | Providing costin to you, for as long as the agreement lasts and until data is deleted under section 13. |
|---|---|
| Nature and purpose | Storing, organising, displaying, backing up and exporting records you create, so your firm can manage enquiries, quotes, jobs, orders, labour, invoices and payments. Reading supplier documents and receipts you upload. Sending records to your accounting software when you connect it, and reading back whether invoices have been paid. Showing progress updates you choose to share with your own customers, through a private link. Sending the emails you write from costin to your customers and suppliers, with their attachments. |
| People the data is about | Your customers and their contacts; your employees; your subcontractors; your suppliers’ contacts; your own users. |
| Types of personal data | Names, addresses (including site addresses), phone numbers and email addresses; quotes, invoices, payments and job details; employee National Insurance numbers, start dates, emergency contacts, pay records and certificates (for example CSCS cards); subcontractor UTR numbers, CIS verification details, rates and payment statements; vehicle driver details; documents and photos you upload. |
4. Sub-processors and transfers
| Sub-processor | Purpose | Data location / safeguard |
|---|---|---|
| Fly.io, Inc. | Hosting, database, document storage and backups | London, UK. Covered by Fly.io’s Data Processing Agreement. Fly.io is certified under the UK Extension to the EU–US Data Privacy Framework. |
| Cloudflare, Inc. | Domain name service: points costin.app addresses at our servers. Storing the off-site copy of each nightly backup. | Your Data goes straight to Fly.io and does not pass through Cloudflare. The off-site backups are stored in the EU, encrypted on our servers before they are sent so Cloudflare cannot read them, and deleted after 60 days. Certified under the UK Extension to the EU–US Data Privacy Framework. |
| Resend (Plus Five Five, Inc.) | Delivering emails you send from costin, such as invoices, quotes, orders and progress updates, with their attachments | Sent from Ireland (EU). Covered by Resend’s Data Processing Agreement. |
| Xero Limited / Intuit Inc. | Only if you connect them: receiving the records you send to your own accounting software | Acting on your instruction under your own agreement with them |
5. Security measures
- Encryption in transit (HTTPS) for all connections.
- A separate app and database for each firm.
- Role-based access for users. Passwords stored only as salted hashes. Sign-in throttling against guessing. Users can see and sign out devices.
- Uploaded documents available only to signed-in users of the same firm, except the progress notes and photos a firm chooses to put in a customer update, which are reachable only through that update’s private, unguessable link.
- Nightly backups checked for integrity, 30 days of storage snapshots, an encrypted off-site copy in the EU, and an offline copy kept on encrypted equipment.
- Access to production systems limited to named people at site software Ltd, using individual accounts.
- Automatic reading of documents done on our own servers, not by outside services.
