Privacy Policy
Meter Max is an accounting app for self-employed drivers in the UK: private hire and minicab, taxi, courier and delivery, and van drivers. It keeps your books, works out your tax, and prepares and sends your VAT returns and Making Tax Digital updates to HMRC. This policy explains what information the app handles, where it goes, and your rights. In short: your records stay on your phone, and your figures go to HMRC only when you choose to send them.
1. Who We Are
Meter Max is developed and operated by Archevot Technologies Ltd, a private company limited by shares, registered in England and Wales under company number 17239931, with its registered office at 20 Wenlock Road, London, England, N1 7GU. References to "we", "us" or "Archevot" mean Archevot Technologies Ltd.
For the limited personal information we process ourselves (described in sections 4, 5 and 5A), we are the data controller under UK GDPR and the Data Protection Act 2018. For privacy questions or to exercise your rights, contact support@archevot.com.
2. What Stays on Your Phone
Everything you enter is stored in the app's private storage on your device. We do not have a copy and cannot see it. This includes:
- your details: name, trading name, address, phone, email, bank details you choose to show on invoices, National Insurance number, Unique Taxpayer Reference, VAT number and student loan plan;
- your records: takings, invoices and customer names, expenses, receipt photos, mileage, vehicles, pension providers and payments, and income from other sources;
- the returns and updates you prepare, and a log of every call the app makes to HMRC;
- your HMRC access tokens (see section 4);
- your security settings: whether the app lock is on and, if you set up an authenticator app, the authenticator key, which is encrypted with a key held in your phone's secure hardware (Android Keystore);
- your Google Play subscription's purchase token (see section 5A).
There is no Meter Max account, and the app contains no advertising, analytics or tracking.
3. Backups and Sharing
- Backups you make. "Back up now" creates a file and opens your phone's share sheet. It goes wherever you choose, such as Google Drive or email. The file is not encrypted, so keep it somewhere secure. HMRC access tokens, the authenticator key and your subscription's purchase token are never included.
- Android backup. If backup is switched on in your phone's settings, Android may include the app's data in your Google account backup, under Google's terms. You control this in your phone's settings.
- Documents you share. Invoices, returns, accounts and CSV files are shared only when you tap share, to the app or person you choose.
4. Connecting to HMRC
Connecting is optional. When you tap Connect to HMRC, HMRC's own sign-in page opens in your browser. You sign in with your Government Gateway details on HMRC's site; Meter Max never sees your password.
HMRC then issues access tokens that let the app act for you. To exchange HMRC's one-time sign-in code for those tokens, the app uses a small service we run on Cloudflare at hmrc.metermax.app, because that exchange needs a secret that must not be stored inside an app. That service:
- holds your tokens for no more than two minutes, until the app collects them, then deletes them;
- passes token renewals to HMRC without keeping them;
- does not log tokens, and never receives your records or returns.
Your tokens are then kept only on your phone. You can remove them at any time with Disconnect in Settings, and HMRC's authority lasts no longer than 18 months before you must sign in again.
5. What Is Sent to HMRC
The app sends information to HMRC only when you ask it to, for example when you send a quarterly update, submit a VAT return, read your business details or obligations, or make your Final Declaration. What is sent is the figures and identifiers needed for that request, such as your National Insurance number, VAT number and HMRC business id.
HMRC requires software to send fraud prevention information with every call. The app sends: a random device identifier created by the app, your phone's local network (IP) addresses and the time they were read, your time zone, your screen size and window size, your phone's operating system, manufacturer and model, and the app's name and version. If you have set up an authenticator app, it also sends the fact that a code was checked, when, and a scrambled (hashed) reference to your authenticator set-up; never the code or the key. With an active subscription, it sends a scrambled (hashed) form of your Google Play purchase token as the app's licence identifier. It does not send your location, contacts or phone number.
HMRC is responsible for the information it receives, under its own privacy notice on GOV.UK.
5A. App Lock, Authenticator and Subscription
- App lock. If you turn it on, the app asks Android to check it is you using your phone's fingerprint, face or screen lock. Android only tells the app whether the check passed. Meter Max never receives or stores your fingerprint, face data or PIN.
- Authenticator app. If you set one up, the app creates a secret key, shows it to you as a QR code and a text key for your authenticator app, and keeps it encrypted on your phone. Codes are checked on your phone; the key is never sent to us or to HMRC.
- Subscription. Payment is handled by Google Play under Google's terms and privacy policy; we never see your card details. Google Play gives the app a purchase token. To confirm the subscription is active, the app sends that token to our service at hmrc.metermax.app, which asks Google Play and returns the result: whether the subscription is active, its plan, and when it renews or ends. The service does not keep or log the token. Google shares with us, as the developer, the purchase records it provides to all Google Play developers, such as order numbers and subscription status.
6. Android Permissions
- Internet — to connect to HMRC, the sign-in service and Google Play, and to open links you tap.
- Google Play billing — to show subscription plans and take payment through Google Play.
- Biometrics — only if you turn on the app lock, to ask Android to check your fingerprint, face or screen lock.
- Camera — only when you take a photo of a receipt. Photos are stored in the app on your phone.
The app does not access your location, contacts, microphone, messages or call logs.
7. Links to Other Services
Some buttons open other websites in your browser: your pension provider's payment page (a link you add yourself), MoneyHelper, and the FCA Register. The app never makes payments. Those sites have their own privacy policies.
8. Legal Basis
We process the limited information in sections 4, 5 and 5A to provide the HMRC connection and the subscription you ask for (performance of a contract with you). Fraud prevention information is sent because HMRC requires it of Making Tax Digital software.
9. Security and International Transfers
Connections to HMRC and to the sign-in service use HTTPS. The sign-in secret is held encrypted by Cloudflare and never appears in the app. Cloudflare operates a global network, so a sign-in exchange may be processed outside the UK under Cloudflare's data processing terms and the safeguards required by UK law.
On your phone, your HMRC access tokens and your authenticator key are encrypted with a key held in the phone's secure hardware (Android Keystore), and your records are protected by Android's own storage encryption.
Your phone's own security matters too: use a screen lock, turn on the app lock and an authenticator app in Settings, and keep backup files somewhere secure.
Reporting a security problem. If you find a security weakness in Meter Max or the services it uses, email support@archevot.com with "Security" in the subject, and please do not share it publicly until we have fixed it. If personal data may have been affected by a breach, we tell the Information Commissioner's Office and HMRC within 72 hours, as the law and HMRC require.
10. How Long Information Is Kept
- Records on your phone: until you void or remove them, clear the app's data, or uninstall it. HMRC expects self-employed records to be kept for at least 5 years after the 31 January filing deadline, and VAT records for 6 years, so keep backups.
- Sign-in tokens on the service: no more than two minutes.
- Purchase tokens sent for a subscription check: not kept after the check.
- Emails to support: as long as needed to deal with your enquiry.
11. Your Rights
Under UK GDPR you have rights to access, correct and delete your personal information, to restrict or object to processing, and to data portability. Because your records are held only on your phone, you control them directly: you can edit them, export them with a backup, or delete them all with Settings → Backup → Delete all my data (or by uninstalling the app). For anything we hold, email support@archevot.com.
12. Children
Meter Max is for self-employed adults running a driving business. It is not intended for anyone under 18.
13. Complaints
If you are not satisfied with our response, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk.
14. Changes to This Policy
We will update this policy if the app changes how it handles information, and revise the date at the top. Material changes will also be shown in the app.
15. Contact Us
Email: support@archevot.com
Post: Archevot Technologies Ltd, 20 Wenlock Road, London, England, N1 7GU