Privacy Policy
How we handle your data · Version 2026-07-28 · Last updated: 28 July 2026
DeskMatch is a trading name of SW19 Labs Ltd (“we”, “us”), the data controller for the personal data described below. We’re based in London, UK, and process data in line with the UK GDPR and the Data Protection Act 2018.
1. Who this applies to
This policy covers everyone who uses DeskMatch — people looking for a desk (“Desk Heroes”), companies offering space (“Hosts”), admins, and anyone who fills in a public form or signs up for the waitlist.
2. Data we collect
We only collect what we need to introduce the right people to the right desks.
2.1 You give us directly
- —name, email, phone number, and company
- —desk requirements (team size, area, budget, lease length, usage frequency)
- —space listings (location, photos, capacity, pricing, amenities)
- —messages you send through the platform or to our team
2.2 We collect automatically
- —session cookies so you stay signed in
- —basic request logs (IP address, user agent, timestamps) for security and rate-limiting
- —page-level analytics on which features get used
2.3 Payment data
Card details are entered directly into Stripe — we never see or store full card numbers. We keep a Stripe customer ID and a receipt of each transaction.
2.4 Payments, payouts & Stripe Connect
- —Stripe and Stripe Connect process payment and identity information on our behalf when you pay for a booking or receive payouts as a Host
- —Host payout onboarding is handled by Stripe and may require business details, identity verification and bank account details — these are collected by Stripe, not stored by DeskMatch
- —we store Stripe identifiers (customer, payment, transfer and account IDs) but never raw card details
- —we retain transaction, refund, payout and dispute records for accounting and tax purposes
3. Why we use it
- —to match Desk Heroes with Hosts and send intros
- —to operate the platform, your account, bookings and payments
- —to send transactional email (confirmations, intros, reminders)
- —to protect the platform from spam and abuse
- —to comply with legal obligations and respond to lawful requests
Our lawful bases are: performance of a contract (running your account and bookings), legitimate interests (operating, securing, and improving the service), consent (where required, e.g. marketing email), and legal obligation (tax, accounting, fraud prevention).
4. Cookies & sessions
We use a small number of first-party cookies and similar storage:
- —a first-party authentication session cookie (dm_session) so you stay signed in
- —a CSRF token cookie to protect form submissions
- —an admin JWT cookie (admin_token) for admin sessions only
We don’t use third-party advertising cookies or cross-site trackers.
You can review or change your cookie choice at any time — .
5. Third-party processors
We share data with a small set of vetted processors who help us run the service:
- —Stripe — payments, billing, and tax (name, email, billing address, payment method)
- —Resend — transactional email delivery (recipient email, message content)
- —Neon / PostgreSQL hosting — primary database storage
- —Replit / our hosting provider — application hosting and logs
Each processor is bound by a data processing agreement and may transfer data outside the UK only under appropriate safeguards (UK IDTA, EU SCCs, or an adequacy decision).
Where required, financial data (transaction, payout, refund and dispute records) may also be shared with our accountants, payment processors, regulators, or professional advisers.
6. Sharing with other users
When you accept an intro, we share your name, email, and phone number with the other party so you can take it forward off-platform. We never share your contact details before you accept. When you pay for a booking, we share the booking information the Host needs to accommodate you (your name, contact details, desk count and dates).
7. How long we keep it
- —active accounts and listings: while your account is open
- —withdrawn or closed requirements / spaces: up to 24 months for analytics and dispute resolution
- —transactional email logs: up to 12 months
- —payment and tax records: 6 years (UK statutory requirement)
- —waitlist sign-ups: until we launch in your area, or you ask us to delete them
8. Your rights
Under UK GDPR you can ask us to:
- —access the personal data we hold about you
- —correct anything that’s wrong
- —delete your data (where we don’t need to keep it for legal reasons)
- —restrict or object to processing
- —port your data to another service
- —withdraw consent at any time, where we rely on it
Email hello@deskmatch.co and we’ll respond within 30 days. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) if you’re not happy with how we’ve handled your data.
9. Security
All traffic is encrypted in transit (HTTPS). Passwords are hashed with bcrypt and admin sessions are signed JWTs. Access to production data is limited to a small number of named team members. We’ll notify affected users and the ICO within 72 hours of becoming aware of any breach that’s likely to affect your rights.
10. Children
DeskMatch is for adults running or working in small teams. We don’t knowingly collect data from anyone under 18.
11. Changes to this policy
We’ll update this page when our practices change and bump the “Last updated” date at the top. For material changes we’ll also email account holders.
12. Contact
Questions, requests, or anything that doesn’t feel right: hello@deskmatch.co
Company details
DeskMatch is a trading name of SW19 LABS LTD, registered in England and Wales (company number 17273490).
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX.
Trading address: Wimbletech, Wimbledon Reference Library, Wimbledon, SW19 7NB.
See also our Terms of Use, Accessibility Statement, and Contact.