Privacy Policy
Effective 27 February 2026. This document is written to be read — plain English first, formal fallbacks below.
goodnus Ltd ("goodnus", "we", "us") runs the MyHub operations platform you're using at myhub.goodnus.com. This page explains what personal data we collect when you use MyHub, why we hold it, who else sees it, and what you can do about it.
If anything below is unclear or you'd like a copy of, correction to, or deletion of your data, email us at myhub-support@goodnus.comand we'll respond within 30 days.
1. Who's the data controller?
goodnus Ltd, a company registered in England & Wales, is the data controller for personal data processed by MyHub. We're contactable at the address on our Companies House record and at myhub-support@goodnus.com.
You have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you're unhappy with how we handle your data — but please raise it with us first and we'll try to resolve it directly.
2. What data we collect and why
We only collect data we need to run MyHub. That falls into three buckets:
2.1 Identity & access data
- Work email address — used to sign you in, send transactional emails, and identify you inside the app.
- Google account details (name, email, profile picture) — only if you sign in with Google. We receive these from Google's OAuth service the moment you consent on Google's screen.
- Password hash — stored using industry-standard bcrypt. We never store or see your actual password.
- Multi-factor authentication (MFA) secrets and, optionally, a phone number if you enable SMS-based codes.
- Session & audit logs — timestamped record of sign-ins, page views, key actions (creating a pallet, off-boarding a colleague, changing a customer's contract). We use this for security investigations and to comply with UK employment record-keeping duties.
2.2 Operational data
- Data you enter into MyHub: warehouse stock, pallet movements, customer orders, delivery notes, supplier information, HR records for goodnus staff (leave, absence, contract type, line manager), training records, chat messages, quotations, invoices.
- Photos uploaded to MyHub — van compliance photos, product images, damage evidence, receipt captures.
- Device metadata attached to logins and actions: IP address, browser user-agent, approximate location (city-level, derived from IP).
2.3 Personal data about others
Some of you use MyHub to record data about customers, suppliers, drivers, or job applicants. When goodnus staff put someone else's personal data into MyHub, goodnus Ltd is the controller of that data, and the same protections in this policy apply.
3. Our lawful bases for processing
Under UK GDPR we need a lawful basis for every use of your data. Ours are:
- Contract — most staff data is processed because we need to fulfil your employment contract and the day-to-day contract of running goodnus operations.
- Legitimate interest — audit logs, security telemetry, and behavioural signals we use to detect misuse and to improve the product. We've balanced these against your privacy and think they're proportionate; you can object at any time (see §7).
- Legal obligation — HR records we're required to keep (working time, holiday balances, right-to-work), safety records, and financial records.
- Consent — you gave explicit consent to Google when you signed in with your Google account. You can revoke it at any time via your Google account or by asking us to delete the linked MyHub account.
4. Who we share your data with
We do not sell your data. We do not use it to build advertising profiles. We share it only with the following processors, each of whom is bound by a data processing agreement:
- Emergent (US, with UK/EU delivery via Cloudflare) — hosting and infrastructure. Every byte of MyHub runs on Emergent-managed servers.
- Google LLC — Google Workspace + Google OAuth for sign-in and, where applicable, Google Cloud AI (Gemini) for stock-audit photo processing.
- Cloudflare, Inc. — CDN, DDoS protection, bot mitigation (Cloudflare Turnstile on the sign-in page). No cookies are set for tracking.
- Resend — transactional email delivery (welcome mails, MFA codes, off-boarding notifications).
- Trello (Atlassian) — when goodnus staff push a UAT ticket to a Trello board, the ticket text goes to Atlassian's servers.
- UK authorities — HMRC, Companies House, the ICO, or law enforcement, but only where legally compelled to disclose.
None of the above use your data for their own marketing. Some (Google, Cloudflare, Emergent) may transfer data to the United States; we rely on Standard Contractual Clauses (SCCs) and, where applicable, the UK Extension to the EU-US Data Privacy Framework as the transfer safeguard.
5. How long we keep it
- Active user accounts — for as long as you work at (or transact with) goodnus. If you leave, we retain the account in a deactivated state for six months for handover before permanent deletion.
- HR records — six years after employment ends, in line with UK statutory limits and HMRC guidance.
- Financial records (invoices, POs, credit notes) — six years after the end of the tax year they were raised in.
- Audit & security logs — 12 months, then aggregated statistics only.
- Uploaded files (photos, PDFs) — while the linked record exists. Deleting the record deletes the files.
- Backups — cycled every 30 days; deletions in the live system are removed from backups within 30 days.
6. Cookies and similar tech
MyHub uses only strictly necessary cookies — no marketing, no analytics tracking of individuals. Specifically:
access_token— your signed-in session, delivered as a strictHttpOnly · Secure · SameSite=Laxcookie so JavaScript running on the page cannot read it. Deleted when you sign out.gn_impersonation,gn_view_as_role,gn_sidebar_collapsed— remember your admin preview mode and sidebar state.- Cloudflare's
cf_clearancebot-mitigation cookie on the sign-in page.
You can wipe all of these by clearing your browser storage for myhub.goodnus.com.
7. Your rights
Under UK GDPR you can, at any time:
- Access — request a copy of the personal data we hold about you.
- Rectify — ask us to correct anything that's wrong.
- Erase — ask us to delete your data (subject to the retention rules in §5 and legal holds).
- Restrict — ask us to pause processing while a dispute is resolved.
- Object — object to processing based on legitimate interests.
- Portability — receive your data in a machine-readable format so you can move it elsewhere.
- Withdraw consent — where we relied on consent (e.g. Google sign-in), you can revoke it anytime.
Email myhub-support@goodnus.com to exercise any of these. We'll acknowledge within 5 working days and respond fully within 30.
8. Security
MyHub is delivered over HTTPS only. Passwords are stored as bcrypt hashes. MFA is mandatory for privileged roles (admin, HR manager, super admin) and encouraged for everyone else. Access is role-based and every privileged action is written to an immutable audit log. Google logins are restricted to @goodnus.comWorkspace accounts unless we've explicitly whitelisted another domain.
9. Changes to this policy
If we change how MyHub processes personal data in a way that materially affects you, we'll update this page and email registered users. The "Effective" date at the top shows when the current version came into force. Previous versions are available on request.
10. Contact
Data protection queries: myhub-support@goodnus.com.
Postal: goodnus Ltd (address on our Companies House record).