This policy explains what Vanly does with personal data. It covers two different groups of people: tradespeople who sign up to use Vanly, and the members of the public who call or message a tradesperson's business and whose data passes through Vanly as a result. If you rang a tradesperson and got a text back, section 3 is the part written for you.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and ICO guidance.
1. Who we are
Vanly is a product of Goto-Tender Ltd, a company registered in England & Wales (company number 16627586), with registered office at 27 Bates Lane, Helsby, Frodsham, England, WA6 9LN.
For anything about this policy or your data, contact hello@vanlyai.com.
2. The two relationships
Your own account data. For the data of the tradesperson who signs up (your name, contact details, business details, billing), we are the data controller. We decide how it is used, and this policy is your privacy notice.
Your customers' data. For the data of the people who contact your business, you are the data controller and Goto-Tender Ltd is your data processor. We process that data on your instructions, to provide the service you signed up for. You are responsible for having a lawful basis for handling your own customers' data and for giving them the privacy information they are due. Section 3 sets out plainly what we do with it on your behalf, so you can point people at it.
3. People who call or message a tradesperson's business
This section is for the general public. If you contacted a tradesperson who uses Vanly, here is what happens to your information. The tradesperson is responsible for your data; we handle it for them.
If you call and they cannot pick up. Tradespeople can divert unanswered calls to a phone number we provide for them through Twilio. When that happens:
- Your voice is recorded. If you leave a message, the audio recording is stored, along with your phone number, the time of the call and how long the message was.
- Your message is written down. The audio is sent to OpenAI (in the United States) and converted to text automatically, so the tradesperson can read it rather than listen back.
- An AI reads the text. The transcript is sent to Anthropic and used to summarise your enquiry and suggest a reply for the tradesperson. A person decides what is actually sent to you.
- You may get a text back.If you ring and do not get through, we may send you one SMS on the tradesperson's behalf, with a link to message them on WhatsApp. It is sent through Twilio. If you reply to it, we send one acknowledgement and pass your message to the tradesperson.
If you message them on WhatsApp.Your messages go to the tradesperson's own WhatsApp number and pass through Meta's WhatsApp Business Cloud API. We store the content of your messages, your name and number as WhatsApp provides them, and anything you send such as photos or voice notes. Voice notes are transcribed the same way as voicemails. Your messages are sent to Anthropic so the assistant can reply or draft a reply.
Replies may be automatic. Tradespeople can choose whether the assistant replies to you on its own or waits for them to approve each message. Either way it is answering routine enquiry questions on their behalf, such as what the job is, your postcode and rough timing. It does not make decisions with legal or similarly significant effects for you, and it does not profile you. It never quotes you a price on its own: a person approves that.
Exercising your rights. You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted. Contact the tradesperson you dealt with, because legally the data is theirs. If that is difficult, email hello@vanlyai.com and we will help you reach them and action it on their instruction. See section 9 for the full list of rights and section 15 for the ICO.
4. What we collect about you (tradespeople)
- Identity and contact: first and last name, email address, phone number.
- Business: business name, postcode, trade, company details looked up from the public Companies House register, VAT and invoice settings, logo.
- Payment: card details and billing address, handled by Stripe. We never see or store full card numbers. We keep a Stripe customer reference.
- Marketing attribution: UTM parameters in the URL when you sign up.
- Email content (if you connect Gmail or Outlook): we read incoming mail to find and parse leads from platforms such as Bark, Checkatrade, MyBuilder and Rated People, and to draft replies to direct enquiries. We store the parsed lead and the original message payload for that lead.
- Calendar (if you connect a calendar): we read events to find your free slots and write events for confirmed bookings. Supported: Google Calendar, Outlook Calendar and Apple iCloud.
- Voice notes you send us: transcribed to text by OpenAI so you can dictate quotes, invoices and customer notes.
- Phone rail: if you switch on missed-call capture, we rent a phone number for you from Twilio. Twilio holds your business identity and address as part of the UK regulatory requirements for owning a number.
- Your work: the customers, jobs, quotes, invoices, payments, bookings and receipts you create in Vanly.
- Technical: IP address and browser user agent at signup, for security and fraud prevention, plus server logs.
5. How we use it, and our lawful basis
- To provide the service, including catching enquiries, replying, quoting, invoicing, booking and chasing payment. Lawful basis: performance of a contract (Art. 6(1)(b)).
- To run the phone rail, including recording and transcribing voicemail and sending the missed-call text back. Lawful basis: performance of a contract with you. For the caller, your legitimate interest in responding to an enquiry they started.
- To send you transactional email, such as receipts and account notices. Lawful basis: performance of a contract.
- To take payment. Lawful basis: performance of a contract.
- To improve the product from your feedback. Lawful basis: legitimate interest (Art. 6(1)(f)).
- For security and fraud prevention. Lawful basis: legitimate interest.
- For advertising measurement through the Meta Pixel. See section 10, which explains this honestly, including where we currently fall short.
- To meet legal obligations, such as tax and accounting records. Lawful basis: legal obligation (Art. 6(1)(c)).
6. Who we share data with
These are our processors. They handle data on our instructions, under contract.
- Supabase Inc. Database and file storage. This holds effectively all product data: your account, your customers, messages, quotes, invoices, receipts, and voicemail audio and transcripts. EU region. supabase.com/privacy
- Twilio Inc. Phone numbers, inbound calls, voicemail recording, and SMS including the missed-call text back. Twilio holds a copy of call recordings on its own systems. twilio.com/legal/privacy
- OpenAISpeech to text (Whisper) for voicemails and voice notes. Audio is sent for transcription only. Under OpenAI's API terms this data is not used to train their models. openai.com/policies/privacy-policy
- Anthropic PBCThe language model behind the assistant. Message content, email content, transcripts and receipt images are sent for inference only. Under Anthropic's API terms this data is not used to train their models. anthropic.com/legal/privacy
- Meta Platforms Ireland Ltd Three separate things: the WhatsApp Business Cloud API that carries messages, Facebook Lead Ads if you use them as a lead source, and the Meta Pixel on our website (section 10). facebook.com/policy
- Google LLC Gmail and Google Calendar access when you connect a Google account, plus Google Cloud Pub/Sub which tells us new mail has arrived. See section 16. policies.google.com/privacy
- Microsoft Corporation Outlook mail and calendar via Microsoft Graph when you connect a Microsoft account. privacy.microsoft.com
- Apple Inc. iCloud Calendar via CalDAV if you connect an Apple calendar. apple.com/uk/legal/privacy
- Stripe Payments Europe LtdCard capture and billing. Card data stays in Stripe's PCI-DSS infrastructure. stripe.com/privacy
- Resend Inc. Transactional and lifecycle email delivery. resend.com/legal/privacy-policy
- Vercel Inc. Website and API hosting, plus cookieless page view analytics (section 10). vercel.com/legal/privacy-policy
- Upstash (QStash) Runs our scheduled jobs on time. It receives no personal data: it only calls our own URLs on a timer. upstash.com privacy
- ImprovMX Forwards email sent to hello@vanlyai.com. improvmx.com/privacy
- Namecheap Inc. Domain registration and DNS. namecheap.com privacy
- Companies House We look up your company name against the public register at signup. Only your search text is sent.
We do not sell personal data and we do not share it with data brokers.
7. International transfers
Several processors are US based, including Twilio, OpenAI, Anthropic, Stripe, Vercel, ImprovMX and Namecheap. Where data goes outside the UK or EU, it is protected by the EU-US Data Privacy Framework where the processor is certified, by the UK Addendum to the EU Standard Contractual Clauses, or by other lawful safeguards. Email us for a copy of the relevant safeguard.
This includes voicemail audio: a recording of a caller's voice is sent to the United States for transcription.
8. How long we keep data
We are being straight with you here, including where we are not yet where we want to be.
- Your account and your work (customers, messages, quotes, invoices, bookings): kept while your account is open.
- Voicemail recordings and transcripts: kept while your account is open. We are building an automatic sweep that deletes audio after a set period, and until it is live, audio is not deleted on a schedule. You can ask us to delete any recording at any time and we will do it. Note that our telephony provider, Twilio, also holds a copy under its own retention.
- Customer messages: kept while your account is open.
- Technical and webhook logs: these can contain message and call content and are currently kept without a fixed expiry. Reducing this is on our list.
- Quotes, invoices and receipts: kept for 6 years from the end of the relevant tax year, because HMRC requires it.
- Payment records: kept while you are a customer. Stripe keeps transaction history longer to meet its own legal obligations.
- Email delivery logs (Resend): around 30 days.
- Calendar events: read for availability and not stored. Events we write stay in your calendar as normal.
Deletion on request. There is no self-serve delete button yet. Email hello@vanlyai.com and we will delete your account and its data, including stored files, within 30 days, except where we must keep records by law.
9. Your rights under UK GDPR
- Access: get a copy of the data held about you.
- Rectification: have inaccurate data corrected.
- Erasure: have your data deleted.
- Portability: receive your data in a usable format.
- Restriction: pause processing while something is resolved.
- Objection: object to processing based on legitimate interest.
- Withdraw consent where we rely on consent.
- Not to be subject to automated decisions with legal or similarly significant effects. We do not make them.
Email hello@vanlyai.com. We respond within 30 days. If you contacted a tradesperson rather than signed up yourself, see section 3.
10. Cookies, analytics and advertising
Vercel Analytics. Counts page views. No cookies, no data stored on your device, no personally identifying information. It falls outside PECR consent requirements.
Meta Pixel. We run a Meta (Facebook) advertising pixel on our public marketing pages, so we can measure which adverts bring tradespeople to us. When it runs it sets Meta cookies and sends your IP address, browser user agent and the page you are on to Meta, and it records when someone signs up so we can attribute that to an advert.
It only runs if you allow it.The first time you visit one of our marketing pages we ask, and nothing is set unless you say yes. Say no and we remember it, and will not ask again. The pixel never runs on the signed-in dashboard, on the signup flow, or on the links we send to your customers: it is limited to our public marketing pages. You can change your mind by clearing this site's stored data in your browser, and you can control ad personalisation in your Meta account settings.
Stripe. Sets functional cookies inside its payment frame for fraud prevention. These are strictly necessary for a payment you asked for and are exempt from consent.
We do not use Google Analytics, and we do not sell data to advertising networks.
11. Marketing
Signing up means you get transactional email about your account: receipts, notices and service messages. We do not run a separate marketing list. Every email tells you how to reach us, and you can opt out of non-essential email by replying or emailing hello@vanlyai.com.
12. Security
- HTTPS/TLS for all traffic.
- Card data never reaches our servers. Stripe handles it directly.
- Database access is restricted, with row level security so one tradesperson's data is not readable by another.
- Connected mailbox and calendar tokens are encrypted before they are stored.
- Files such as voicemail audio and quote PDFs are in private storage and reached through time limited links.
- Secrets are rotated when access changes.
No system is completely secure. If a breach is likely to be a risk to your rights, we will tell the ICO within 72 hours and tell you without undue delay where the law requires it.
13. Children
Vanly is for tradespeople aged 18 or over. We do not knowingly collect data from under 18s. Tell us if you think we have and we will delete it.
14. Changes to this policy
We update this policy when the product changes. The date at the top is the current version. We will email you at least 14 days before material changes take effect.
15. Complaints to the ICO
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
Please contact us first if you can, so we get the chance to put it right: hello@vanlyai.com.
16. Google API Services User Data Policy
Vanly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, we request these scopes:
gmail.readonly, to read incoming mail so we can find and parse leads and draft replies to enquiries.gmail.send, to send quotes, invoices and replies from your own address when you ask us to.calendar, to read your availability and write bookings you have confirmed.openid and email, to identify the account you connected.
Specifically, Vanly:
- Uses Google user data only to provide the features you signed up for and approved at the OAuth consent screen.
- Transfers Google user data to third parties only as needed to run those features. In practice that means the content of an email may be sent to Anthropic so the assistant can parse the lead or draft a reply, and an attached voice note may be sent to OpenAI to be transcribed. Both are bound by terms that prevent training on it.
- Does not use Google user data for advertising, including remarketing or personalised advertising. The Meta Pixel described in section 10 operates on our public website only and never receives Google user data.
- Does not let humans read Google user data unless: you have given explicit consent for a specific purpose, it is needed for security such as investigating abuse, it is required by law, or the data is aggregated and anonymised.
For Microsoft data via Microsoft Graph (Mail.Read, Mail.Send, Calendars.ReadWrite) the same principles apply.