Draft for legal review · updated 2 July 2026 · not yet in force
This Privacy Policy explains how Meranex Ltd (a company registered in England and Wales, company number 13730629, registered office 4 Hatchlands, Milton Keynes MK8 9DN, United Kingdom) ("Meranex", "we", "us") collects, uses and protects your personal data when you use Vailto ("Service"), our app for managing receipts, warranties, purchase and expense data, and AI assistant conversations for UK self-employed people and Italian autonomi. This policy is written to comply with the UK GDPR, the EU GDPR and the UK Data Protection Act 2018.
The data controller is Meranex Ltd (United Kingdom). For any privacy matter you can contact us at privacy@vailto.com.
When we are a controller, and when we are a processor. For individual and self-employed users, Meranex is the data controller of your personal data. However, where a business customer — for example an accounting studio (Pro Studio plan) — uses Vailto to process the personal data of its own clients, that business is the controller of that data and Meranex acts as a processor on its documented instructions, under a Data Processing Agreement (DPA). In that scenario the business customer, not Meranex, decides the purposes of the processing and is responsible towards its own clients (the data subjects). In all cases, Vailto is a gateway that helps you capture, organise and move your data — it is not your accounting system of record.
| Category | Data | Purpose | Lawful basis (GDPR) |
|---|---|---|---|
| Account | Email, optional name, language and tax-region preferences | Create and run your account, sign you in | Art. 6(1)(b) — performance of contract |
| Your content | Receipt images, warranty and product details, purchase / expense data, amounts and currency (original and any conversion), dates, categories, notes, contacts (recipients), AI assistant chat history | Provide the core Service (store, organise, search, export your records) | Art. 6(1)(b) — performance of contract |
| Purchase line-item detail (receipt lines) | When the feature is on, we extract the individual purchased items from the receipt: item description, brand (if printed), per-item price, quantity, category and sub-category. Used for spend breakdown, price insights and the purchase observatory. | Provide spend-analysis features from your own documents (nothing to enter by hand) | Art. 6(1)(b) — performance of contract |
| Reimbursement & sharing (Pro / Pro Studio and Family plans) | If you use the reimbursement flow or share with a studio/family: reimbursement status (submitted/approved/paid/rejected), outcomes and reasons, who decided and when, and the expense's associations to a client-group (studio) or a family pool. This data is visible to the authorised members of that group (e.g. your approving accountant or family members). | Run the reimbursement approval and the collaborator/family sharing you enable | Art. 6(1)(b) — performance of contract |
| Usage & technical logs | API call timestamps, AI usage/cost tracking, error logs | Operate, secure and debug the Service; prevent abuse | Art. 6(1)(f) — legitimate interest |
| Product analytics | Page views and feature interactions | Understand usage and improve the product | Art. 6(1)(f) — legitimate interest |
| Payments (when active) | Subscription status and tax/billing country — card details are handled by our payment provider, never by us | Manage subscriptions and apply the correct tax | Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax) |
When you scan a receipt or use the conversational assistant, the relevant content is sent to our third-party AI provider, which processes it on our behalf as a sub-processor. It reads your content only to extract or answer (e.g. to read a receipt or respond to a question); we require that your content is not used to train the provider's models. Inputs may be retained briefly for trust & safety review under the provider's policy, then deleted. This provider may process data outside the EU/UK; such transfers are covered by appropriate safeguards (see §9).
Default — your data stays in the EU. By default, your receipts and all account data are stored with our cloud provider in an EU region (Ireland). Under this default setup, your stored data does not leave the EU. Some sub-processors (such as AI processing and payments) may process limited data outside the EU/UK under the safeguards described in §9.
BYOS — Bring Your Own Storage (opt-in). As an alternative to Vailto Cloud, you can keep your receipts in storage you control. This option is available today on our paid plans via Google Drive (a cloud provider) or local storage on your device, and we plan to add more options over time (for example S3-compatible or self-hosted storage such as a NAS). If you choose a cloud provider, the files live in that provider's infrastructure, which may include non-EU regions, governed by that provider's terms; if you choose on-device local storage, your files stay on your device and are not transferred to us or a third party. This option is strictly opt-in and requires your explicit consent before any data is moved. When connecting Google Drive you will see the following notice and must consent to continue:
"Selecting Google Drive — your data will be stored in Google's infrastructure, which may include non-EU regions. Your consent is required to proceed."
Once your data reaches a provider or person you choose, it is outside our control. If you enable BYOS, or otherwise forward or export your data to a storage provider, an accountant or another service you choose, Meranex is not responsible for how that provider, service or person stores, secures or uses your data — that is governed by your relationship with them and their own terms. Meranex remains responsible only for the personal data it processes within its own systems.
We share data only with the trusted providers below, each acting as a processor / sub-processor under a data processing agreement, and only to run the Service. For each we show its function and the region where it operates:
| Provider | Function | Region |
|---|---|---|
| Supabase | Database, file storage and authentication | EU (Ireland) |
| Vercel | Application hosting and web analytics (cookieless page/performance metrics) | EU edge; global CDN |
| Anthropic | AI processing of receipts and chat — reads content only to extract / answer; not used to train models | US — SCCs / adequacy |
| Stripe | Payments and tax calculation — card details handled directly by Stripe, never stored by us | EU + US — SCCs |
| Resend | Outbound transactional email | EU + US |
| Postmark | Inbound transactional email (receipts forwarded into the app) | US — SCCs |
| PostHog | Product analytics (feature usage; no personal data, no session recording) | EU (Frankfurt) |
| Sentry | Error monitoring (client-side; text/media masked, IPs not collected) | EU |
| Cloudflare Turnstile | Bot protection at sign-in and sign-up | Global edge |
| Backblaze B2 | Encrypted disaster-recovery backups | EU |
| Loops | Account-lifecycle emails | US — SCCs |
| Attio | CRM (contact email and name) | EU / US |
| Upstash | Anti-abuse rate-limiting (briefly stores an IP address) | EU |
| Plain | In-app support tickets | UK |
| Slack | Internal operational alerts — region / source / id only, no identifying data and no user content | US |
| Postcodes.io | Address lookup from the postcode you enter | UK |
| DVLA / gov.uk | Vehicle lookup from the number plate you enter | UK (government) |
| Google (Sign in with Google) | Authentication and basic profile (name, email, picture) when you choose this sign-in | US |
This list may change. We may add or replace providers as the Service evolves. When we do, we update this list and post the current version here; for business customers under a Data Processing Agreement we give advance notice of any change and a chance to object. The version of the list published here from time to time always governs.
A BYOS cloud provider (e.g. Google Drive) becomes a processor only if you opt in to it; on-device local storage involves no third-party processor.
Business customers (Pro Studio) — Data Processing Agreement. Where you use Vailto as a business to process the personal data of your own clients, Meranex acts as your processor. A Data Processing Agreement (DPA), incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where relevant, is available and forms part of your terms.
Our backups are for disaster recovery, not a substitute for yours. The backups we keep exist so we can restore the Service after a failure; they are not a personal backup service for you and cannot be used to reverse a deletion you requested. You remain responsible for keeping your own copy of your data via Settings → Export my data (see Terms §4).
Under the GDPR you have the right to:
To exercise any right, email privacy@vailto.com. We respond within 30 days.
Where a sub-processor processes data outside the EU/UK (for example AI processing and payments in the US, or globally distributed services), we rely on lawful transfer mechanisms — the EU/UK adequacy decisions and Standard Contractual Clauses (SCCs) with the UK International Data Transfer Addendum, plus the EU-US Data Privacy Framework where applicable. If you enable BYOS with a cloud provider, transfers to your chosen provider's regions occur on the basis of your explicit consent (see §5); if you choose on-device local storage, no transfer to a third party takes place.
The app uses minimal first-party cookies for session authentication. For web and product analytics we use Vercel Analytics (privacy-friendly, cookieless page and performance metrics — no personal data, no cross-site tracking) and PostHog (EU-hosted, Frankfurt) for feature-usage analytics (no personal data, no session recording). Application errors are monitored via Sentry (EU, client-side; text and media masked). These run on the basis of our legitimate interest in improving and securing the Service; PostHog respects your browser's "Do Not Track" (DNT) setting — enable it to opt out. Inside the app we do not use behavioural profiling and we never sell your data.
We do not currently run any advertising or conversion-tracking pixels (such as Meta, Google Ads or LinkedIn) on our pages, so there is no advertising cookie to consent to. If we introduce advertising measurement in future, it will be subject to your prior cookie consent and we will update this policy. Advertising pixels are in any case never present in the core app (receipt and data management).
Meranex is established in the United Kingdom, so our lead supervisory authority is the UK Information Commissioner's Office (ICO). If you think we have mishandled your data, you can complain to the ICO at ico.org.uk. You may also have the right to lodge a complaint with the supervisory authority in your country of residence.
Vailto is not directed at children under 18. We do not knowingly collect data from minors. If you believe we have, contact us and we will delete it.
We may update this Privacy Policy. For material changes we will notify you by email and via an in-app banner at least 30 days before the new version takes effect.
Questions about privacy, or to exercise your rights: privacy@vailto.com.