SmartRepBack to SmartRep

SmartRep Privacy Policy

Effective date: 9 September 2026

1. Who provides SmartRep

SmartRep is a software service provided by Robert Treacy, an individual sole trader established in Ireland. Robert Treacy is the supplier and data controller for the business information described in this policy; “SmartRep” is the product name.

Privacy and other enquiries: [email protected] or the monitored website contact form.

Complaints may also be made to the Irish Data Protection Commission at dataprotection.ie.

2. What this policy covers

This policy covers information for which Robert Treacy is controller: SmartRep user accounts, signup security, subscriptions and billing administration, legal-acceptance evidence, sales and support correspondence, bug reports and service-security records.

It does not make SmartRep the controller of an elected representative's constituency casework. The representative or office decides why that data is used and is its controller. Robert Treacy processes it through SmartRep only as a processor under the Data Processing Agreement. Constituents should normally direct questions about their case records to the relevant office.

Eircode-based casework mapping: who handles what

The elected representative or office is the controller of casework. It decides why Eircodes are collected, the lawful basis for using them, who may see the map and how long the information is kept.

SmartRep acts as the office's processor. To create a map point, SmartRep normalises the Eircode, sends the normalised Eircode to the external geocoding providers enabled for the service, and stores the returned latitude and longitude with that office's data. If the first enabled provider cannot find an acceptable point, SmartRep may ask the next enabled provider.

Providers can classify a returned point at different levels of precision. SmartRep stores that classification where supplied for operational diagnostics.

An enabled geocoding provider receives only the normalised Eircode and ordinary request metadata needed to answer and secure the request, such as the SmartRep server's IP address, request time and API-account information. SmartRep never includes a constituent's name, phone number, email address, case notes, case category or case details in a geocoding request. The possible providers are ArcGIS by Esri, HERE and Google. Only providers that are configured and enabled receive requests.

The lookup happens between the SmartRep server and the provider. Opening or zooming the map does not send Eircodes to a geocoding provider, and map dots do not make the stored Eircode or coordinates public.

3. Information we use as controller

Office users and signup

We use names, work email addresses, office and representative type, password hashes, MFA state, recovery-code hashes, session and reset-token records, authentication events, source IP address, browser user agent and signup-abuse checks.

We use this information to create and secure accounts, verify email addresses, authenticate users, prevent abuse, recover access and maintain an evidence record. The bases are performance of the SmartRep contract and our legitimate interests in operating a secure service and demonstrating what was agreed.

Billing

We use office identity, administrator contact details, selected plan, subscription status, invoice references and Stripe customer, Checkout and subscription identifiers. This is necessary to perform the contract, take payment and keep required business records.

Stripe hosts Checkout and the billing portal. SmartRep does not receive full payment card or bank-account details. Stripe may process information as a service provider and for its own payment-security, fraud-prevention and legal purposes under its own privacy information.

Messages, sales and support

We use the sender's contact details and message content submitted by email or the website contact form to answer enquiries, provide support and maintain business correspondence. Please do not send constituent casework through these public channels.

Bug reports

An in-product bug report can include the text the user enters, page address, selected element and its visible text, recent browser-console errors, addresses of recent failed requests and an optional screenshot. A screenshot or diagnostic can contain casework visible on screen. Bug reports are stored with SmartRep on our hosting and are not sent to an external analytics or bug-tracking service.

Website, security and abuse information

SmartRep uses Cloudflare as the HTTPS reverse proxy, content-delivery and security layer in front of the website and application. Cloudflare terminates the user's HTTPS connection and forwards requests to SmartRep over an encrypted connection. It therefore processes request and response content in transit, which can include account and casework information when a user works in the application, together with traffic metadata such as IP address, date and time, requested path, response status and browser user agent. SmartRep and Cloudflare use this processing to deliver and secure the service, diagnose faults and prevent abuse. Cloudflare does not host SmartRep's operational database or uploaded-file store.

Public signup and the website contact form also use Cloudflare Turnstile. Cloudflare receives technical browser and network signals needed to distinguish a person from automated activity. Turnstile does not receive the form contents or casework stored later in SmartRep.

The authenticated map requests visible map tiles directly from the OpenStreetMap Foundation. The Foundation can receive the user's IP address, browser information, referring page, time and requested map area. SmartRep does not put constituent names, contact details, Eircodes or case notes into those requests.

Our separate Cookie and device-storage notice explains the exact browser storage used by login, offline capture and the PWA. SmartRep uses no advertising cookies, tracking pixels or product-analytics SDK.

4. Recipients and locations

We use the following providers for the business-side processing described here:

ProviderPurposeRelevant information
Hetzner Online GmbHHosting in Helsinki, Finland (hel1-dc2), European Union, for the application, database and uploaded filesInformation stored in SmartRep
StripeHosted Checkout, subscriptions, invoices and billing portalOffice, billing and payment information; no casework
Proton AGTransactional and human business emailRecipient address, office/user name, verification or reset link and billing-alert information; no casework unless a sender puts it in an email
CloudflareHTTPS reverse proxy, content delivery, traffic security and Turnstile public-form abuse preventionRequest and response content in transit, which can include account and casework information; IP address, request metadata and browser or network security signals
OpenStreetMap FoundationDirect delivery of map tilesUser IP, browser request and map area; no case record content
ArcGIS by EsriEircode geocoding, only when configured and enabledNormalised Eircode and ordinary server request metadata; no names, contact details or case notes
HEREEircode geocoding, only when configured and enabledNormalised Eircode and ordinary server request metadata; no names, contact details or case notes
GoogleEircode geocoding, only when configured and enabledNormalised Eircode and ordinary server request metadata; no names, contact details or case notes

Customer casework stored in SmartRep's operational database and uploaded-file store is hosted in the European Union. Cloudflare operates a global network and may process web traffic and traffic metadata outside the EEA. Proton is based in Switzerland, for which the European Commission has adopted an adequacy decision. Where a provider processes personal data outside the EEA, we rely on its applicable contractual and organisational transfer safeguards.

We may disclose information where required by law or where reasonably necessary to establish, exercise or defend legal rights.

5. Retention

Retention is applied according to the type of record and why it is needed:

InformationCurrent retention approach
Operational Customer Data after cancellationRead-only/export-only, then manually deleted within 90 days unless the office resubscribes or requests earlier deletion
User and office account recordsSubscription and closure period; limited identity and security records may then be retained with contract evidence
Billing and tax recordsUp to six years where required for business, tax or contract records
Legal-acceptance and contract evidenceUp to six years after the contract ends
Signup-abuse countersSeven days
Support and sales correspondenceNormally up to 24 months after the last contact, unless needed for an active matter or legal record
Bug reports and diagnosticsUntil manually removed or the related office's operational data is erased
Server and security logsKept only for a proportionate operational and security period under the hosting configuration

Deletion from the live service does not selectively edit an existing backup. Any backup that exists ages out through its normal operational cycle. A deletion request continues to apply if a backup is restored.

6. Security

Current safeguards include application-level organisation scoping, individual user accounts, administrator and staff roles, restricted-case access, per-user MFA, password hashing, session revocation, TLS in transit, rate limits and application audit records.

No internet service can promise absolute security. Users should protect their devices, use individual accounts and promptly report suspected compromise.

7. Your rights

Depending on the circumstances, a person may ask us for access to their personal data, correction, erasure, restriction, portability, or object to processing based on legitimate interests. They may also complain to the Data Protection Commission.

These rights are not absolute and may be limited where information must be retained by law or for legal claims. To exercise a right relating to a SmartRep account, billing, support or another record covered by this policy, email [email protected]. We may need to verify identity.

For constituent casework, contact the elected representative or office that controls the record. If a casework request reaches us, we will normally refer it to that office.

8. Automated decisions and reuse

SmartRep does not make decisions producing legal or similarly significant effects about individuals. Reports, matching and maps are decision-support tools reviewed by office users.

SmartRep does not use Customer Data for advertising, behavioural profiling, product analytics, cross-customer benchmarking, model training or a provider-owned dataset.

9. Changes

We will publish material changes as a new version and update the effective date. Where a change materially affects existing users, we will provide reasonable notice through the service or by email.