Gracombex Ltd, trading as The Money Platform, is the controller of the personal data described in this Privacy Policy. Gracombex Ltd is company number 09413521 and its registered office is WeWork Swan House, 33 Queen Street, London, EC4R 1BR. It is registered with the Information Commissioner's Office under reference ZA099774.
This Privacy Policy explains how we collect, use, disclose and retain personal data when you use our website, apply for or use a borrower or lender account, participate in our peer-to-peer lending services, use a loan funded by The Money Platform's own capital, or contact us. It also applies to individuals acting for a corporate lender or another organisation that deals with us.
The information we collect depends on your relationship with us and the services you use. It may include the following categories.
Identity and contact data: name, date of birth, gender, current and previous addresses, email address, telephone number, account identifiers, and identity verification information.
Application and affordability data: requested loan amount and term, income, employment, housing costs, dependants, expenditure, existing financial commitments, and information used to assess affordability and creditworthiness.
Financial and transaction data: bank and debit card details, payment and repayment history, account balances, credit history, credit scores, bank transaction information, and details of transactions carried out through our services.
Account, profile and communication data: account authentication information, preferences, survey responses, correspondence, call or chat records, complaints, support requests and records of servicing, collections, forbearance, or insolvency activity.
Technical and usage data: IP address, device, browser, log-in and security information, website interactions and cookie or similar technology data. Our Cookie Policy provides further information.
Marketing and preference data: communication choices, permissions, objections, and opt-out records.
Support and vulnerability data: information you choose to give us about circumstances that affect how we should communicate with or support you. This may include health or disability information and is addressed further in section 9.
We obtain personal data from the following sources.
You or your representative: through application and account forms, identity checks, Open Banking authorisation, communications, payments, and use of our services.
Our website and systems: through account activity, security logs, service use and cookies or similar technologies.
Credit reference and fraud prevention sources: including Equifax, TransUnion, identity and bank verification services, fraud prevention services, and relevant public records.
Open Banking: from your bank or building society through Perfect Data Solutions Limited, trading as LendingMetrics, when you authorise that access.
Other parties involved in the service: including credit brokers or introducers, lenders, banks and payment service providers, collection agents, insolvency practitioners, public authorities, and other parties involved in administering or protecting an account or transaction.
We use personal data only for identified purposes and under one or more lawful bases in Article 6 of the UK GDPR. Consent is used only where it is the appropriate basis and does not replace another lawful basis that applies to the activity.
| Purpose | Lawful basis and legitimate interests |
|---|---|
| Set up and manage accounts; verify identity, age, and eligibility. | Steps requested before a contract and performance of a contract; legal obligations; legitimate interests in secure service operation and fraud prevention. |
| Assess affordability and creditworthiness and decide whether, how much and on what terms to lend. | Steps requested before a contract; legal obligations applying to responsible lending; legitimate interests in consistent lending and credit-risk management. |
| Provide peer-to-peer and direct lending services; process payments, allocations, and transactions; administer agreements and accounts. | Performance of a contract; legal obligations; legitimate interests in administering and protecting the services. |
| Obtain and report credit information; verify income and bank details; prevent fraud, money laundering, and other misuse. | Legal obligations; legitimate interests in responsible lending, identity verification, fraud prevention and protecting customers and the business. |
| Manage repayments, arrears, collections, forbearance, insolvency, complaints, disputes, and legal claims. | Performance of a contract; legal obligations; legitimate interests in account servicing, appropriate customer support, debt recovery and establishing or defending legal rights. |
| Send service communications and respond to enquiries, rights requests, and data protection complaints. | Performance of a contract; legal obligations; legitimate interests in customer service and resolving concerns. |
| Maintain security, investigate incidents, analyse performance, and improve our systems, products, and customer outcomes. | Legal obligations; legitimate interests in security, service improvement, risk management, and regulatory accountability. |
| Send marketing and use non-essential cookies or similar technologies. | Consent where required; legitimate interests only where data protection law and the Privacy and Electronic Communications Regulations permit it. You can opt out at any time. |
| Meet regulatory, tax, accounting, audit, reporting and corporate obligations, including a sale, restructure or transfer of the business or assets. | Legal obligations; legitimate interests in governance, professional advice, corporate administration, and business continuity. |
Some information is required to enter or administer a contract, verify identity, carry out affordability and creditworthiness checks, meet anti-money laundering or regulatory requirements, or protect an account. If you do not provide required information, we may be unable to register you, assess an application, offer or administer a product, or continue a service. Marketing choices are optional.
Borrower applications are assessed through automated decision-making, including profiling. Our decisioning process applies lending rules and risk models to application information, verified income, expenditure and financial commitments, credit reference data, Open Banking information where used, identity and fraud results, the amount and term requested, and relevant account history. These inputs are compared with our affordability, creditworthiness, and lending criteria.
The result may automatically approve or decline an application or determine the amount or terms that can be offered. This has a significant effect because it determines whether credit is available and, where applicable, on what terms. We do not use vulnerability information or other special category data as an input to an automated lending decision.
You may ask us to arrange human intervention, give us your point of view, or contest a significant automated decision. Contact support@themoneyplatform.com and identify the application or decision you want us to reconsider. A person will consider the relevant information and the points you raise.
We disclose personal data only where this is necessary for an identified purpose, lawful basis, or legal requirement. Recipients may include the following.
Service providers: providers of hosting, system support, identity and bank verification, analytics, communications, customer support, payment processing, document management, and other services carried out for us. A provider acting as our processor is subject to written data protection terms.
Credit and fraud organisations: credit reference agencies, fraud prevention agencies, and Perfect Data Solutions Limited, as explained in sections 7 and 8.
Banks, payment providers, and account administrators: where required to receive, safeguard, allocate or pay funds and administer accounts or transactions.
Lenders and credit brokers: information needed to operate the peer-to-peer service or an agreed referral. Borrower identity is not disclosed directly to individual lenders; lender-facing information is anonymised or non-identifying. Where a declined application may be referred to a broker, the relevant journey explains the referral.
Collections and insolvency parties: collection agents, insolvency practitioners and professional advisers involved in servicing, recovery, forbearance, insolvency, or disputes.
Authorities and professional bodies: the Financial Conduct Authority, Information Commissioner's Office, Financial Ombudsman Service, law enforcement, courts, tax authorities, auditors and legal or professional advisers where permitted or required.
Corporate transaction parties: prospective buyers, sellers, and advisers where the business or its assets may be reorganised or transferred, subject to appropriate confidentiality and data protection controls.
We do not sell personal data or Open Banking transaction information for marketing purposes.
We use Equifax and TransUnion to obtain information for identity, bank or income verification, affordability, creditworthiness, and fraud prevention. We may also provide them with information about an application, account, and payment performance. A search or account report may appear on your credit file and information about late, missed, or defaulted payments may affect future access to credit.
Credit reference agencies are independent controllers of the information they hold. The common Credit Reference Agency Information Notice explains how Equifax, Experian and TransUnion obtain, use, and share credit reference information. We currently obtain our lending data from Equifax and TransUnion; the common notice also names Experian because it applies across the three principal UK credit reference agencies.
Where Open Banking is used for an application, we use Perfect Data Solutions Limited, trading as LendingMetrics, and its OpenBankVision service. We share the personal, contact and application details needed to create the Open Banking journey. You are then directed to a secure portal and authenticate directly with your bank or building society. Neither The Money Platform nor Perfect Data Solutions Limited asks you to disclose your online banking password to us.
When you authorise access, your bank or building society provides transaction information through Perfect Data Solutions Limited. The result may contain up to 90 days of categorised account information, including income, outgoings, balances, and transaction patterns. Perfect Data Solutions Limited returns a search result to us. We use it to verify income and expenditure, assess affordability and creditworthiness, identify possible fraud, and make the lending decision described in section 5.
Your Open Banking authorisation is separate from the UK GDPR lawful basis on which we process the search result we receive. You may choose not to authorise access. If the journey establishes an ongoing access permission, you can withdraw or manage that permission through the relevant bank or Open Banking provider. Withdrawal does not make earlier processing unlawful and does not require us to delete information that we must or may retain for another lawful purpose.
Perfect Data Solutions Limited is registered with the Financial Conduct Authority for providing credit references under reference 730062 and for account information services under reference 802559. It processes and retains information under its own terms and privacy notice as well as the Open Banking information shown during the journey.
We may receive limited special category data when a customer tells us about a health condition, disability, or other circumstance so that we can provide appropriate support, make a reasonable adjustment, respond to a complaint, or meet regulatory obligations towards customers in vulnerable circumstances. We identify an Article 6 lawful basis and an Article 9 condition before using this information. Depending on the circumstances, this may include explicit consent or substantial public interest under the Data Protection Act 2018, including safeguarding the economic wellbeing of an individual at risk. We use only the information needed for the support purpose and do not use it in automated lending decisions.
We may process information about suspected or actual criminal conduct where necessary for identity checks, fraud prevention, anti-money laundering, investigations, legal claims, or regulatory reporting. This is processed only where Article 10 of the UK GDPR and an applicable Data Protection Act 2018 condition permit it.
Our borrowing products are available only to people over 20. Our services are not directed at children, and we do not knowingly invite a child to open a borrower or lender account. If children's personal data is received in another context, it remains protected by data protection law.
Some service providers or cloud platforms may store personal data outside the United Kingdom or permit access from another country. Where we initiate a restricted transfer, we use a mechanism permitted by the UK GDPR, such as United Kingdom adequacy regulations, the International Data Transfer Agreement, the United Kingdom Addendum to the European Commission's standard contractual clauses, or an applicable statutory exception. We carry out the required transfer assessment where appropriate. You may contact us for information about the safeguard used for a relevant transfer.
We apply technical and organisational measures appropriate to the risks presented by the data and processing. These include access controls based on business need, authentication, secure transfer, and encryption controls where appropriate, monitoring and testing proportionate to risk, supplier controls, staff guidance, and incident response arrangements. No internet or storage system can be guaranteed completely secure.
We retain personal data only while it is needed for the purpose for which it was collected or another documented lawful purpose. The period depends on the type of record and the relevant trigger, such as an application decision, the end of a loan or account relationship, final payment, case closure, last contact, or withdrawal of a preference. We consider contractual and regulatory record-keeping requirements, anti-money laundering and fraud prevention, tax and accounting obligations, complaint and legal claim periods, security needs, and the effect on individual rights.
Communications may be recorded and retained where needed for quality, compliance, security, complaint, or dispute purposes. A legal, regulatory, or investigative hold may extend a normal period. When identifiable information is no longer needed, it is securely deleted or irreversibly anonymised. Backup copies expire through controlled rotation and are not restored for ordinary use after deletion. Credit reference agencies, Open Banking providers and other independent controllers apply their own retention periods.
Depending on the circumstances and the lawful basis used, you may have the right to be informed, obtain access to your personal data, correct inaccurate or incomplete data, request erasure, restrict processing, receive certain data in a portable format, object to processing, withdraw consent, and use the automated decision safeguards explained in section 5. These rights are not absolute and exemptions or continuing lawful reasons may apply. We will explain our decision unless the law restricts what we can disclose.
Your right to object: You have an absolute right to object to direct marketing. You may also object to processing based on legitimate interests because of your situation. Contact us using the details in section 14. We will stop direct marketing and will consider any other objection in accordance with data protection law.
You may withdraw consent at any time where consent is the lawful basis. Withdrawal does not affect processing that was lawful before withdrawal. You can change marketing choices through the available account or communication controls or contact us.
You may complain about how we have handled your personal data by emailing support@themoneyplatform.com and stating that the matter is a data protection complaint. We acknowledge a data protection complaint within 30 days of receipt. Without undue delay, we make appropriate enquiries, keep you informed where appropriate and communicate the outcome.
You may also complain to the Information Commissioner's Office. You do not have to complete our process before exercising your right to complain to the Information Commissioner's Office, although giving us the opportunity to investigate may allow the matter to be resolved more quickly.
We review this Privacy Policy when changes in law, regulation, products, suppliers, data use, or business practices make an update necessary. The current version is published on our website. Where a change is material, we use an appropriate method to bring it to the attention of affected people.
For questions, rights requests or data protection complaints, contact:
The Money Platform
WeWork Swan House
33 Queen Street
London
EC4R 1BR
The Money Platform has not appointed a statutory Data Protection Officer. The person allocated responsibility for data protection coordinates requests and complaints through the contact route above.
The Money Platform is a trading name for Gracombex Ltd (company no. 9413521) and our registered offices are at:
Wework Swan House, 33 Queen Street, London, EC4R 1BR.
Gracombex Ltd is authorised and regulated by the Financial
Conduct Authority (Ref. 716455).
Data Protection Registration Number ZA099774.
©️ 2026 The Money Platform, All Rights Reserved