← Back to homePanelPay is a GAA expense management platform operated by PanelPay. We are committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR) and the Data Protection Acts 1988–2018 (Ireland).
1. Who We Are
PanelPay (“we”, “us”, “our”) is the data controller for personal data collected through this platform. If you have any questions about how we handle your data, please contact us at hello@panelpay.ie.
2. Data We Collect
We collect the following categories of personal data:
- Account information: your full name and email address, used to identify your account and send transactional emails (claim approvals, rejections, daily digests).
- Home address: your residential address and its GPS coordinates (latitude/longitude). This is used solely to calculate mileage distances for expense claims.
- Bank details: IBAN, BIC/SWIFT code, and bank name. These are used by your panel treasurer to generate SEPA payment files for approved claim reimbursements.
- Expense and mileage data: journey dates, start and destination addresses, route polylines, distances, costs, receipt images, and claim descriptions.
- Usage data: standard server logs including IP address and browser type, retained for security and debugging purposes.
3. How We Use Your Data
Your data is used to:
- Provide the expense management service — submitting, reviewing, and approving claims.
- Calculate mileage reimbursements based on your home address and journey routes.
- Send transactional email notifications about your claims.
- Enable your panel treasurer to generate SEPA payment files for approved claims.
- Maintain an audit log of claim decisions for financial accountability.
We do not use your data for marketing, profiling, or any automated decision-making that produces legal or similarly significant effects without human review.
4. Who Can See Your Data
- You can see all data stored on your profile and all claims you have submitted.
- Your panel treasurer(s) and admins can see your full name, home address, IBAN, bank details, all submitted claims, journey routes, and receipt images. This access is necessary to process reimbursements and verify expenses.
- PanelPay has administrative access to the database infrastructure for maintenance and support purposes only. We do not access individual claim data for commercial purposes.
- Third parties: we do not sell, rent, or share your personal data with any third party for marketing or commercial purposes.
5. How Your Data Is Stored
All data is stored using Supabase, a managed database platform built on PostgreSQL. Data is encrypted at rest and in transit. Supabase infrastructure is hosted within the European Union (Ireland/EU West region), ensuring your data does not leave the EEA.
Receipt images are stored in Supabase Storage, a secure object storage service. Access to receipt images is controlled by signed URLs and row-level security policies.
6. Data Retention
We retain your personal data for as long as your account is active or as required for financial record-keeping purposes (generally 7 years under Irish tax law for expense records). Upon account deletion, personal profile data (name, address, IBAN) is deleted. Anonymised expense records may be retained for audit purposes.
7. Your GDPR Rights
Under GDPR, you have the right to:
- Access — request a copy of all personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
- Restriction — request that we limit processing of your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, email hello@panelpay.ie. We will respond within 30 days. You also have the right to lodge a complaint with the Data Protection Commission of Ireland (dataprotection.ie) if you believe your data has been handled unlawfully.
8. Cookies
PanelPay uses session cookies solely for authentication purposes (managed by Supabase Auth). We do not use advertising cookies, tracking pixels, or third-party analytics.
9. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-app notice. Continued use of PanelPay after such notice constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions or to exercise your rights:
hello@panelpay.ie