1. Introduction
Vanly ("we", "our", "us") is committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
2. Data Controller
Contact Details:
- Company: VANLY TRADE MANAGEMENT LTD
- Company Number: 17024675
- App Name: Vanly
- Email: support@getvanly.co.uk
- Address: 52a Valley Road, Northallerton, North Yorkshire, DL6 1HY
3. What Data We Collect
Personal Data You Provide:
- Account Information: Name, email address, and sign-in credentials (email/password, Google Sign-In, or Sign in with Apple via Firebase Authentication)
- Business Information: Business name, phone number, email, address, VAT/CIS details you enter
- Customer Data: Your customers' names, email addresses, phone numbers, addresses
- Financial Records: Invoices, estimates, expenses, job details, payment status, and subscription status
- Team / employee records (Gold): If you invite staff, you may store their name, email, job title, emergency contacts, National Insurance number, tax code, and bank details for payroll. You are the controller of that HR data; we store it only to provide the service
- Photos: Receipt images, company logo, barcodes, and job site photos (including before/after photographs used for quality records and customer reports). Photos are stored in your private Firebase Storage and only shared with people you choose
- Voice notes & speech-to-text: When you use voice input, audio is captured on your device and converted to text. Transcription may use Apple Speech Recognition or Google Speech Services, which may process short audio samples under their own privacy policies. We do not store raw audio — only text you choose to save
- E-signatures: Customer or staff signatures you capture on estimates, invoices, or related documents
- Team messages: Messages you send inside Vanly to your own staff
- Location data: GPS coordinates for optional live time-tracking / clock-in when a team member enables location tracking during a shift (including background location on the device while that session is active), and postcode-based weather when you use weather features. Mileage trips are logged manually (addresses and miles you enter); the Mileage feature does not collect GPS
Automatically Collected Data:
- Device information (device type, operating system)
- App usage and crash data (Firebase Analytics and Firebase Crashlytics)
- Authentication data (via Firebase Auth)
- Push notification tokens (FCM / APNs) so we can send job, team, and account alerts you enable
Processed on your device only:
- Face ID / biometrics: Optional unlock of the app. Biometric data stays on the device and is not sent to Vanly
We do not use advertising identifiers, show third-party ads, or sell your data.
4. Legal Basis for Processing
We process your data under the following legal bases:
- Contract: To provide the service you've signed up for
- Legitimate Interest: To improve our app and prevent fraud
- Consent: For location data (you can revoke this anytime)
- Legal Obligation: To comply with UK tax and accounting requirements
5. How We Use Your Data
- Provide business management services (invoicing, estimates, job tracking)
- Store your business and customer records
- Enable financial record-keeping for tax compliance
- Send transactional emails (estimates, invoices, reminders) on your behalf when you choose to send them
- Record manually entered mileage for HMRC simplified allowance claims
- Support optional GPS-assisted timesheets / clock-in for your team
- Process subscriptions (Apple In-App Purchase, Google Play Billing, or Stripe on the website)
- Send push and email alerts you enable (jobs, team, billing)
- Improve app performance and fix crashes
- Communicate with you about the service
5A. Emails Sent on Your Behalf (Estimates, Invoices & Related Messages)
When you use Vanly to email a customer (for example an estimate or invoice), Vanly acts as a data processor for that send. You remain the data controller for your customers’ personal data.
How sending works:
- Emails are delivered through Vanly’s email infrastructure (currently SendGrid) so messages can be sent reliably.
- The visible From name is your business name. The technical sending address is a Vanly address (for example
noreply@getvanly.co.uk). - Reply-To is set to your business email where provided, so customer replies go to you — not to a shared Vanly inbox for reading.
- Message content is generated from data you already store in Vanly (estimate/invoice details and the customer contact you entered).
What Vanly and our email provider process for these sends:
- Recipient address, subject, and message content needed to deliver the email
- Delivery status and optional engagement events (such as sent, delivered, opened, or link clicked) so you can see whether a quote or invoice was received or viewed
- Related metadata needed for security, abuse prevention, and service reliability
What we do not do:
- We do not access your customers’ personal email accounts or mailboxes
- We do not use your customers’ emails to market Vanly products to them
- We do not sell customer email lists or message contents
- Vanly staff do not routinely read the content of your customer emails; access is limited to what is necessary to operate, secure, and support the service (for example investigating a delivery failure you report)
Our email provider (SendGrid / Twilio) processes these messages as a sub-processor under its own privacy terms. See Section 10.
6. Data Storage & Security
Where Your Data is Stored:
- Firebase/Google Cloud: Your data is stored on Firebase servers, which may be located in the EU or UK. Google Cloud complies with UK GDPR via Standard Contractual Clauses (SCCs).
- Firebase Storage: Images (receipts, logos) are encrypted at rest
Security Measures:
- Data encrypted in transit (HTTPS/TLS)
- Firebase Authentication for secure access
- Firestore security rules prevent unauthorized access
- Only you can access your business data (user ID based isolation)
7. Data Retention & Account Deletion
- Account Data: Retained while your account is active
- Customer Records: You control these — delete anytime via the app
- Financial Records: We recommend keeping for 6 years (HMRC requirement)
- Deleted Data: Permanently removed within 30 days of account deletion
You can delete your account in the app (account / settings) or via getvanly.co.uk/delete-account. Deleting your Vanly account does not automatically cancel an App Store or Google Play subscription — manage those in your Apple ID or Google Play account.
8. Your Rights Under UK GDPR
You have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Restrict Processing: Limit how we use your data
- Object: Object to processing based on legitimate interests
- Withdraw Consent: For location tracking, you can disable this in your device settings
To exercise these rights, contact us at support@getvanly.co.uk or use in-app account deletion / getvanly.co.uk/delete-account.
9. Your Customers' Data
When you store customer information in Vanly:
- You are the Data Controller for your customers' personal data
- Vanly is a Data Processor when we store that data for you or send emails/messages you initiate
- You must have a lawful basis to store their information (e.g., contract, consent)
- You must inform your customers that you're using this app to manage their data, including that quotes/invoices may be emailed via Vanly’s sending service
- You are responsible for responding to your customers' GDPR requests
10. Third-Party Services
We use:
- Firebase / Google Cloud (hosting, database, authentication, storage, Analytics, Crashlytics, Cloud Messaging)
- SendGrid (Twilio) (transactional email delivery and delivery/open/click events for messages you send)
- Apple (Sign in with Apple, App Store In-App Purchase, push notifications on iOS)
- Google Play (sign-in on Android where offered, Play Billing, Play Services)
- Stripe (card payments for website subscriptions and customer invoice payments you collect)
These providers process data as needed to provide their services and have their own privacy policies:
- Firebase: firebase.google.com/support/privacy
- Google: policies.google.com/privacy
- Apple: apple.com/legal/privacy
- SendGrid / Twilio: twilio.com/legal/privacy
- Stripe: stripe.com/privacy
The website may use essential cookies for sign-in and security. See our Cookie Policy.
11. Children's Privacy
This app is not intended for children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy. We'll notify you via the app or email for significant changes.
13. Contact & Complaints
Contact Us:
Email: support@getvanly.co.uk
File a Complaint:
If you're unhappy with how we handle your data, you can complain to:
- Information Commissioner's Office (ICO)
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
14. Location Data
Vanly may use location primarily for time tracking (optional):
- Mileage: Business mileage for HMRC simplified allowance is logged manually (from/to addresses and miles you enter). The Mileage feature does not collect GPS.
- Time tracking / clock-in: If a worker enables live location tracking for a shift, the app may collect GPS while they are clocked in, including in the background, so the business can verify on-site presence. This uses “Always” / background location permission on the device when granted.
- Weather: Forecasts use a postcode you save or a job site postcode — not continuous GPS tracking.
- Location permission is optional — you can deny it and still use core features of the app
- You can disable location access anytime in your device settings
- Workers can stop a live tracking session at any time by clocking out or turning the feature off
- Location data is stored in your business account and is not sold to third parties
By using Vanly, you agree to this Privacy Policy.
Last updated: 15 August 2026