Privacy Notice
Last updated: 28 May 2026
1. Who we are
MySalaryPal is operated by Gary Curran, a sole trader based in Ireland. We act as the data controller for personal data processed through the Service. For payroll-admin accounts, the employer is the controller of employee payslip content; we act as processor on their behalf.
2. What we collect & why
| Category | Purpose | Legal basis |
|---|---|---|
| Account data (name, email, password hash) | Create and secure your account | Contract |
| Payslip files & extracted figures (gross, net, PAYE, PRSI, USC, pension, employer) | Provide the dashboard and AI explanations | Contract |
| Company / employer membership records | Route payslips to the right employee | Contract / legitimate interests |
| Support messages | Help you when you contact us | Legitimate interests |
| Usage logs, device & IP data | Security, fraud prevention, debugging | Legitimate interests |
| Cookies (essential only) | Keep you signed in | Strictly necessary |
Payment data (card details, billing address) is collected directly by our payment provider Paddle and is not stored on our systems.
3. Who we share data with
- Hosting & infrastructure: Supabase (EU region) for database, authentication and file storage.
- AI processing: Google (Gemini) and OpenAI to generate payslip explanations. Payslip text may be sent to these providers; outputs are not used to train their models.
- Payments: Paddle, our Merchant of Record, for sales, subscription management, tax compliance and invoicing.
- Professional advisers (accountants, legal) where strictly needed.
- Authorities where required by law.
4. International transfers
Some processors (e.g. OpenAI, Google) are based outside the EEA. Transfers are protected by Standard Contractual Clauses or adequacy decisions where applicable.
5. Data retention
We keep your account and payslip data for as long as your account is active. If you delete your account, we delete or anonymise your data within 30 days, unless we are required to keep it longer for legal or accounting reasons.
6. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, port, or object to processing of your personal data, and to withdraw consent at any time. You can also lodge a complaint with the Irish Data Protection Commission. To exercise any right, email hello@mysalarypal.com — we'll respond within one month.
7. Security
We use encryption in transit (TLS), encryption at rest, row-level access controls, and least-privilege service accounts. Only you can see your own payslips; payroll admins never see individual payslip contents.
8. Cookies
We only use strictly-necessary cookies (session and authentication). We do not use advertising or third-party analytics cookies.
9. Contact
Gary Curran · hello@mysalarypal.com