Privacy policy
This policy explains what personal data staging - VCurl (the "service") collects, why, how we use it, who we share it with, and the rights you have over it. It applies whenever you interact with the service.
Most of it is written for people with an account. If you arrived by clicking a short link, scanning a QR code, or filling in a form or poll that one of our customers published, section 2 is the part written for you — it sets out exactly what is and isn't recorded about that visit, and who to contact about it.
The data controller for personal data collected through the service is ANYMO SOLUTIONS LIMITED (company number 17137827), registered at 1b George Street, Hull, United Kingdom, HU12 8JH. For privacy questions or to exercise your rights, contact us at team@anymosolutions.uk.
1. Data we collect
Account data you provide: name, email address, optional phone number, password (stored hashed), profile photo if you upload one, timezone, notification preferences, and your acceptance timestamps for our terms and marketing communications.
Authentication data: hashed multi-factor authentication secrets and recovery codes, OAuth provider links (e.g. Google, GitHub) if you connect them, and personal access tokens you issue.
Usage data: activity within the service (records you create, settings you change), sign-in events, device and IP metadata for session activity, and timestamps for actions needed for audit.
Tenant data: any team workspaces you create or join, the membership relationships between users and teams, and team-level resources (domains, webhooks, API tokens) you configure.
Communications: emails and in-app notifications we send you and any replies or support correspondence you send us.
Technical data: cookies (session, CSRF, preferences), application logs for security and debugging, and error reports.
2. Visitors to links, forms and polls our customers publish
This section is for you if you didn't sign up for anything — you clicked a short link, scanned a QR code, loaded a page containing a tracking pixel, voted in a poll, filled in a feedback form, answered an availability poll or submitted a score to a leaderboard that one of our customers created.
Who's responsible: for these interactions the customer who created the link or form is the data controller — they decide to collect it and what to do with it. We act as their processor, handling it on their instructions under the data processing agreement we have with them. That is an exception to the controller statement at the top of this policy, which covers account holders. If you want your data accessed, corrected or erased, the customer is the right first contact; if you can't reach them or don't know who they are, write to us at team@anymosolutions.uk and we'll pass it on and help where we can.
What gets recorded when you open a link: the date and time, which link you opened, the page that referred you if any, the country and city the request came from, the network it arrived over (its autonomous system number and the operator's name, e.g. a mobile carrier or a hosting company), the kind of device (mobile, tablet or desktop), the operating system family (iOS, Android, Windows, macOS or Linux), and whether the request came from an automated client rather than a person.
What does not get recorded: we do not store your IP address, and we do not store your browser's user-agent string. Both are read as the request is handled, used to work out the coarse facts listed above, and then discarded — they are never written to our records. We also store no identifier of any kind for you, which means we cannot tell that two visits came from the same person, cannot build a profile across links, and cannot recognise you on a later visit. There is no advertising or cross-site tracking, and no cookie is set when a link redirects you.
Automated clients are the exception: when a request comes from a crawler, a search engine or a chat app fetching a link preview, we keep its full user-agent string. Those strings name a company's software rather than a person, so there is no individual behind them.
If you fill something in: whatever you type into a feedback form, poll, availability poll or leaderboard — which may include your name or email address if the customer asked for them — is submitted to that customer. They decide what it's used for, how long it's kept and who sees it, so their own privacy notice governs it, not this one.
Cookies on public pages: if a poll or availability poll is set to accept one
response per browser, we set a single functional cookie
(vcurl_poll_… or vcurl_availability_…) so the page knows you've already
responded. It holds the value "1" and nothing else — no identifier — and lasts a year. It exists
only to do the thing you asked for, so it isn't used for tracking and doesn't need a consent
banner. See our cookie policy for the full list.
Where we do use your IP briefly: public form, poll and availability submissions are rate-limited by IP address to blunt spam and automated abuse. That check happens in memory over a one-minute window and the address is not written to any record. We rely on our legitimate interest in keeping the service available and free of abuse.
Request bins are different, by design: a request bin is a developer tool that captures incoming HTTP requests so our customer can inspect exactly what their own software sent. Reproducing a request faithfully means keeping it intact, so for these — and only these — we do store the source IP address and user-agent alongside the headers and body. Captures are automatically deleted after 30 days.
How long the rest is kept: interaction records are retained for as long as the customer keeps the link, because they contain nothing that identifies an individual. If the customer deletes the link or their account, the records go with it.
3. How we use it
- To operate the service: sign you in, run the features you've configured, deliver the notifications you've opted into, and process payment if you have a paid plan.
- To keep the service secure: detect and respond to abuse, fraud, and unauthorised access; verify it's you when you sign in; track suspicious activity.
- To support you: answer your questions, troubleshoot issues, and respond to your requests.
- To improve the service: diagnose performance issues, understand which features get used, and inform what to build next.
- To meet legal obligations: comply with applicable law, respond to lawful requests from public authorities, and enforce our terms.
We don't use your data to train external advertising or sell it to data brokers. Marketing emails go out only if you've opted in (you can toggle this any time from your profile).
4. Legal bases (UK/EU users)
Where UK GDPR or EU GDPR applies, we rely on these legal bases:
- Performance of a contract: to provide the service you've signed up for.
- Legitimate interests: to keep the service secure, prevent fraud and abuse, and operate efficiently. We balance these interests against your rights and don't process where they're outweighed.
- Consent: for optional things like marketing email. You can withdraw consent at any time without affecting prior processing.
- Legal obligation: to comply with tax, accounting, and other applicable law.
5. Sharing
We don't sell your personal data. We share it only with:
- Our primary infrastructure provider. Enhost (enhost.uk) handles hosting and data housing for the service. Enhost is operated by the same company that operates staging - VCurl, so it's not a separate organisation in commercial terms, but it publishes its own privacy policy listing the specific third-party tools it uses to run its infrastructure. Personal data sits on Enhost-managed servers.
- Other infrastructure providers we need for specific functions (email delivery, SMS delivery, error reporting). They process data on our instructions, under written agreements, and only for purposes we've defined.
- Payment providers when you pay for the service, who process card details directly so we don't store them.
- Your team: when you join a team workspace, other team members can see your name, profile photo, role, and the actions you take inside that workspace.
- Legal recipients when we're required to disclose by law, by court order, or to protect rights, safety, or property.
- Acquirers if the business is sold, merged, or reorganised. We'll notify you in advance and your data will continue to be governed by an equivalent privacy policy.
6. Cookies and similar technologies
We use a small number of cookies to keep you signed in (session cookie), prevent cross-site request forgery (CSRF token), and remember your preferences. We don't use third-party advertising or cross-site tracking cookies. Your browser lets you reject or delete cookies; doing so may disable parts of the service.
7. Data retention
We keep your data while your account is active and as needed to provide the service. When you delete your account, we hold it in a recovery window (currently 90 days) so you can restore it if you change your mind, then permanently delete it. Backups containing your data are overwritten on a rolling cycle, normally within 35 days of deletion. We may retain limited data longer where required by law (e.g. invoices for tax purposes) or for legitimate dispute resolution.
8. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you;
- correct data that's inaccurate (edit it any time from your profile);
- delete your account and the personal data attached to it at any time from your profile. Deleted accounts sit in a 90-day recovery window. Within that window you can restore the account by signing back in and reverting the deletion; after the window expires we permanently delete the data. You don't need to write to us, you can delete it yourself;
- export your personal data at any time from your profile. We package up everything we hold for you (account, teams, domains, webhooks, API tokens, activity) into a downloadable ZIP. This satisfies both the right of access and the right of data portability;
- object to processing based on our legitimate interests;
- withdraw consent for processing where you previously gave it (e.g. marketing, which you can toggle off in your profile);
- lodge a complaint with your local data protection authority.
For account deletion and data export, no written request is needed. Both are self-service in your profile and take effect immediately. For other rights, write to team@anymosolutions.uk; we respond within one calendar month under UK/EU GDPR (with a possible extension for complex requests, and we'll tell you if so).
9. International transfers
We may transfer and process personal data in countries other than the one you live in, including countries that aren't recognised as having "adequate" data protection. Where we do, we use appropriate safeguards (such as Standard Contractual Clauses) so your data is afforded an equivalent level of protection.
10. Children
The service isn't directed to people under 16, and we don't knowingly collect data from them. If you believe a minor has provided us with personal data, contact us and we'll delete it.
11. Security
We protect your data with industry-standard administrative, technical, and physical safeguards (encrypted transport, encrypted-at-rest secrets, hashed passwords, multi-factor authentication, access controls, audit logs, and routine review). No system is perfectly secure; if we become aware of a security incident affecting your personal data, we'll notify you and any regulator as required by law. For the operational detail behind these safeguards (encryption specifics, backup cadence, access provisioning, vulnerability management), see our trust & security FAQ.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we'll notify you in-app and by email. The "last updated" date at the top tells you when the policy was last revised.
13. Contact
Questions about this policy or your data? Email us at team@anymosolutions.uk, or write to ANYMO SOLUTIONS LIMITED, 1b George Street, Hull, United Kingdom, HU12 8JH.
If you're in the UK and we don't resolve your complaint to your satisfaction, you can lodge it with the Information Commissioner's Office (ico.org.uk). If you're in the EU, contact your local supervisory authority.
See our terms of service for the rules of using the platform.