ailto
EN · IT

Privacy Policy

Draft for legal review · updated 2 July 2026 · not yet in force

This Privacy Policy explains how Meranex Ltd (a company registered in England and Wales, company number 13730629, registered office 4 Hatchlands, Milton Keynes MK8 9DN, United Kingdom) ("Meranex", "we", "us") collects, uses and protects your personal data when you use Vailto ("Service"), our app for managing receipts, warranties, purchase and expense data, and AI assistant conversations for UK self-employed people and Italian autonomi. This policy is written to comply with the UK GDPR, the EU GDPR and the UK Data Protection Act 2018.

1. Who is the data controller

The data controller is Meranex Ltd (United Kingdom). For any privacy matter you can contact us at privacy@vailto.com.

When we are a controller, and when we are a processor. For individual and self-employed users, Meranex is the data controller of your personal data. However, where a business customer — for example an accounting studio (Pro Studio plan) — uses Vailto to process the personal data of its own clients, that business is the controller of that data and Meranex acts as a processor on its documented instructions, under a Data Processing Agreement (DPA). In that scenario the business customer, not Meranex, decides the purposes of the processing and is responsible towards its own clients (the data subjects). In all cases, Vailto is a gateway that helps you capture, organise and move your data — it is not your accounting system of record.

2. What data we collect

CategoryDataPurposeLawful basis (GDPR)
Account Email, optional name, language and tax-region preferences Create and run your account, sign you in Art. 6(1)(b) — performance of contract
Your content Receipt images, warranty and product details, purchase / expense data, amounts and currency (original and any conversion), dates, categories, notes, contacts (recipients), AI assistant chat history Provide the core Service (store, organise, search, export your records) Art. 6(1)(b) — performance of contract
Purchase line-item detail (receipt lines) When the feature is on, we extract the individual purchased items from the receipt: item description, brand (if printed), per-item price, quantity, category and sub-category. Used for spend breakdown, price insights and the purchase observatory. Provide spend-analysis features from your own documents (nothing to enter by hand) Art. 6(1)(b) — performance of contract
Reimbursement & sharing (Pro / Pro Studio and Family plans) If you use the reimbursement flow or share with a studio/family: reimbursement status (submitted/approved/paid/rejected), outcomes and reasons, who decided and when, and the expense's associations to a client-group (studio) or a family pool. This data is visible to the authorised members of that group (e.g. your approving accountant or family members). Run the reimbursement approval and the collaborator/family sharing you enable Art. 6(1)(b) — performance of contract
Usage & technical logs API call timestamps, AI usage/cost tracking, error logs Operate, secure and debug the Service; prevent abuse Art. 6(1)(f) — legitimate interest
Product analytics Page views and feature interactions Understand usage and improve the product Art. 6(1)(f) — legitimate interest
Payments (when active) Subscription status and tax/billing country — card details are handled by our payment provider, never by us Manage subscriptions and apply the correct tax Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax)

3. What we do NOT do

  • We do not sell your data, ever.
  • We do not build advertising or behavioural profiles about you.
  • We do not see your password (authentication is handled by our authentication provider; passwords, where set, are hashed).
  • We do not store your card number (handled directly by our payment provider).
  • We do not use your content to train AI models — see §4.

4. AI processing

When you scan a receipt or use the conversational assistant, the relevant content is sent to our third-party AI provider, which processes it on our behalf as a sub-processor. It reads your content only to extract or answer (e.g. to read a receipt or respond to a question); we require that your content is not used to train the provider's models. Inputs may be retained briefly for trust & safety review under the provider's policy, then deleted. This provider may process data outside the EU/UK; such transfers are covered by appropriate safeguards (see §9).

5. Where your data is stored (data residency)

Default — your data stays in the EU. By default, your receipts and all account data are stored with our cloud provider in an EU region (Ireland). Under this default setup, your stored data does not leave the EU. Some sub-processors (such as AI processing and payments) may process limited data outside the EU/UK under the safeguards described in §9.

BYOS — Bring Your Own Storage (opt-in). As an alternative to Vailto Cloud, you can keep your receipts in storage you control. This option is available today on our paid plans via Google Drive (a cloud provider) or local storage on your device, and we plan to add more options over time (for example S3-compatible or self-hosted storage such as a NAS). If you choose a cloud provider, the files live in that provider's infrastructure, which may include non-EU regions, governed by that provider's terms; if you choose on-device local storage, your files stay on your device and are not transferred to us or a third party. This option is strictly opt-in and requires your explicit consent before any data is moved. When connecting Google Drive you will see the following notice and must consent to continue:

"Selecting Google Drive — your data will be stored in Google's infrastructure, which may include non-EU regions. Your consent is required to proceed."

Once your data reaches a provider or person you choose, it is outside our control. If you enable BYOS, or otherwise forward or export your data to a storage provider, an accountant or another service you choose, Meranex is not responsible for how that provider, service or person stores, secures or uses your data — that is governed by your relationship with them and their own terms. Meranex remains responsible only for the personal data it processes within its own systems.

6. The providers we rely on (sub-processors)

We share data only with the trusted providers below, each acting as a processor / sub-processor under a data processing agreement, and only to run the Service. For each we show its function and the region where it operates:

ProviderFunctionRegion
SupabaseDatabase, file storage and authenticationEU (Ireland)
VercelApplication hosting and web analytics (cookieless page/performance metrics)EU edge; global CDN
AnthropicAI processing of receipts and chat — reads content only to extract / answer; not used to train modelsUS — SCCs / adequacy
StripePayments and tax calculation — card details handled directly by Stripe, never stored by usEU + US — SCCs
ResendOutbound transactional emailEU + US
PostmarkInbound transactional email (receipts forwarded into the app)US — SCCs
PostHogProduct analytics (feature usage; no personal data, no session recording)EU (Frankfurt)
SentryError monitoring (client-side; text/media masked, IPs not collected)EU
Cloudflare TurnstileBot protection at sign-in and sign-upGlobal edge
Backblaze B2Encrypted disaster-recovery backupsEU
LoopsAccount-lifecycle emailsUS — SCCs
AttioCRM (contact email and name)EU / US
UpstashAnti-abuse rate-limiting (briefly stores an IP address)EU
PlainIn-app support ticketsUK
SlackInternal operational alerts — region / source / id only, no identifying data and no user contentUS
Postcodes.ioAddress lookup from the postcode you enterUK
DVLA / gov.ukVehicle lookup from the number plate you enterUK (government)
Google (Sign in with Google)Authentication and basic profile (name, email, picture) when you choose this sign-inUS

This list may change. We may add or replace providers as the Service evolves. When we do, we update this list and post the current version here; for business customers under a Data Processing Agreement we give advance notice of any change and a chance to object. The version of the list published here from time to time always governs.

A BYOS cloud provider (e.g. Google Drive) becomes a processor only if you opt in to it; on-device local storage involves no third-party processor.

Business customers (Pro Studio) — Data Processing Agreement. Where you use Vailto as a business to process the personal data of your own clients, Meranex acts as your processor. A Data Processing Agreement (DPA), incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where relevant, is available and forms part of your terms.

7. How long we keep your data

  • Account and your content: kept until you delete your account or request erasure (deletion is immediate and permanent);
  • Chat and usage logs: up to 30 days;
  • Product analytics: retained according to our EU-hosted analytics provider's configuration;
  • Backups: safety copies managed by our hosting provider and periodic encrypted backups held in the EU for disaster recovery; backups are overwritten/deleted on a rotating cycle.

Our backups are for disaster recovery, not a substitute for yours. The backups we keep exist so we can restore the Service after a failure; they are not a personal backup service for you and cannot be used to reverse a deletion you requested. You remain responsible for keeping your own copy of your data via Settings → Export my data (see Terms §4).

8. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the data we hold about you;
  • Export everything — download all your data in one click as a ZIP archive via Settings → Export my data;
  • Rectification — correct inaccurate data, mostly directly in the app;
  • Erasure — delete your account and data via Settings → Delete account;
  • Restriction — ask us to limit how we process your data;
  • Portability — receive your data in a structured, machine-readable format (the export ZIP);
  • Objection — object to processing based on legitimate interest;
  • Withdraw consent — where processing relies on your consent (e.g. BYOS with a cloud provider).

To exercise any right, email privacy@vailto.com. We respond within 30 days.

9. International transfers

Where a sub-processor processes data outside the EU/UK (for example AI processing and payments in the US, or globally distributed services), we rely on lawful transfer mechanisms — the EU/UK adequacy decisions and Standard Contractual Clauses (SCCs) with the UK International Data Transfer Addendum, plus the EU-US Data Privacy Framework where applicable. If you enable BYOS with a cloud provider, transfers to your chosen provider's regions occur on the basis of your explicit consent (see §5); if you choose on-device local storage, no transfer to a third party takes place.

10. Cookies, analytics and tracking

The app uses minimal first-party cookies for session authentication. For web and product analytics we use Vercel Analytics (privacy-friendly, cookieless page and performance metrics — no personal data, no cross-site tracking) and PostHog (EU-hosted, Frankfurt) for feature-usage analytics (no personal data, no session recording). Application errors are monitored via Sentry (EU, client-side; text and media masked). These run on the basis of our legitimate interest in improving and securing the Service; PostHog respects your browser's "Do Not Track" (DNT) setting — enable it to opt out. Inside the app we do not use behavioural profiling and we never sell your data.

We do not currently run any advertising or conversion-tracking pixels (such as Meta, Google Ads or LinkedIn) on our pages, so there is no advertising cookie to consent to. If we introduce advertising measurement in future, it will be subject to your prior cookie consent and we will update this policy. Advertising pixels are in any case never present in the core app (receipt and data management).

11. Complaints

Meranex is established in the United Kingdom, so our lead supervisory authority is the UK Information Commissioner's Office (ICO). If you think we have mishandled your data, you can complain to the ICO at ico.org.uk. You may also have the right to lodge a complaint with the supervisory authority in your country of residence.

12. Children

Vailto is not directed at children under 18. We do not knowingly collect data from minors. If you believe we have, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy. For material changes we will notify you by email and via an in-app banner at least 30 days before the new version takes effect.

14. Contact

Questions about privacy, or to exercise your rights: privacy@vailto.com.

Vailto · A product by Meranex Ltd · Terms of Service · Back to app