1. Introduction
Vanly ("we", "our", "us") is committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
2. Data Controller
Contact Details:
- Company: VANLY TRADE MANAGEMENT LTD
- Company Number: 17024675
- App Name: Vanly
- Email: support@getvanly.co.uk
- Address: 52a Valley Road, Northallerton, North Yorkshire, DL6 1HY
3. What Data We Collect
Personal Data You Provide:
- Account Information: Email address (via Firebase Authentication)
- Business Information: Business name, phone number, email, address
- Customer Data: Your customers' names, email addresses, phone numbers, addresses
- Financial Records: Invoices, estimates, expenses, job details
- Photos: Receipt images, company logo
- Location Data: GPS coordinates for mileage tracking (only when you use the mileage feature)
Automatically Collected Data:
- Device information (device type, operating system)
- App usage data (crash reports via Firebase Crashlytics)
- Authentication data (via Firebase Auth)
4. Legal Basis for Processing
We process your data under the following legal bases:
- Contract: To provide the service you've signed up for
- Legitimate Interest: To improve our app and prevent fraud
- Consent: For location data (you can revoke this anytime)
- Legal Obligation: To comply with UK tax and accounting requirements
5. How We Use Your Data
- Provide business management services (invoicing, estimates, job tracking)
- Store your business and customer records
- Enable financial record-keeping for tax compliance
- Track mileage for HMRC allowance claims
- Improve app performance and fix crashes
- Communicate with you about the service
6. Data Storage & Security
Where Your Data is Stored:
- Firebase/Google Cloud: Your data is stored on Firebase servers, which may be located in the EU or UK. Google Cloud complies with UK GDPR via Standard Contractual Clauses (SCCs).
- Firebase Storage: Images (receipts, logos) are encrypted at rest
Security Measures:
- Data encrypted in transit (HTTPS/TLS)
- Firebase Authentication for secure access
- Firestore security rules prevent unauthorized access
- Only you can access your business data (user ID based isolation)
7. Data Retention
- Account Data: Retained while your account is active
- Customer Records: You control these — delete anytime via the app
- Financial Records: We recommend keeping for 6 years (HMRC requirement)
- Deleted Data: Permanently removed within 30 days of deletion
8. Your Rights Under UK GDPR
You have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Restrict Processing: Limit how we use your data
- Object: Object to processing based on legitimate interests
- Withdraw Consent: For location tracking, you can disable this in your device settings
To exercise these rights, contact us at support@getvanly.co.uk
9. Your Customers' Data
When you store customer information in Vanly:
- You are the Data Controller for your customers' personal data
- You must have a lawful basis to store their information (e.g., contract, consent)
- You must inform your customers that you're using this app to manage their data
- You are responsible for responding to your customers' GDPR requests
10. Third-Party Services
We use:
- Firebase/Google Cloud (hosting, database, authentication, storage)
- Google Play Services (Android)
- Apple Services (iOS)
- Stripe (payment processing)
These providers comply with UK GDPR. See their privacy policies:
- Firebase: firebase.google.com/support/privacy
- Google: policies.google.com/privacy
11. Children's Privacy
This app is not intended for children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy. We'll notify you via the app or email for significant changes.
13. Contact & Complaints
Contact Us:
Email: support@getvanly.co.uk
File a Complaint:
If you're unhappy with how we handle your data, you can complain to:
- Information Commissioner's Office (ICO)
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
14. Location Data (Mileage Tracking)
- We only collect location when you manually log a mileage trip
- Location permission is optional — you can deny it and still use the app
- You can disable location access anytime in your device settings
- GPS coordinates are stored only for your mileage records (for HMRC compliance)
By using Vanly, you agree to this Privacy Policy.
Last updated: March 2026