Privacy policy
This policy explains what personal data VCurl (the "service") collects, why, how we use it, who we share it with, and the rights you have over it. It applies whenever you interact with the service.
The data controller for personal data collected through the service is ANYMO SOLUTIONS LIMITED (company number 17137827), registered at 1b George Street, Hull, United Kingdom, HU12 8JH. For privacy questions or to exercise your rights, contact us at team@anymosolutions.uk.
1. Data we collect
Account data you provide: name, email address, optional phone number, password (stored hashed), profile photo if you upload one, timezone, notification preferences, and your acceptance timestamps for our terms and marketing communications.
Authentication data: hashed multi-factor authentication secrets and recovery codes, OAuth provider links (e.g. Google, GitHub) if you connect them, and personal access tokens you issue.
Usage data: activity within the service (records you create, settings you change), sign-in events, device and IP metadata for session activity, and timestamps for actions needed for audit.
Tenant data: any team workspaces you create or join, the membership relationships between users and teams, and team-level resources (domains, webhooks, API tokens) you configure.
Communications: emails and in-app notifications we send you and any replies or support correspondence you send us.
Technical data: cookies (session, CSRF, preferences), application logs for security and debugging, and error reports.
2. How we use it
- To operate the service: sign you in, run the features you've configured, deliver the notifications you've opted into, and process payment if you have a paid plan.
- To keep the service secure: detect and respond to abuse, fraud, and unauthorised access; verify it's you when you sign in; track suspicious activity.
- To support you: answer your questions, troubleshoot issues, and respond to your requests.
- To improve the service: diagnose performance issues, understand which features get used, and inform what to build next.
- To meet legal obligations: comply with applicable law, respond to lawful requests from public authorities, and enforce our terms.
We don't use your data to train external advertising or sell it to data brokers. Marketing emails go out only if you've opted in (you can toggle this any time from your profile).
3. Legal bases (UK/EU users)
Where UK GDPR or EU GDPR applies, we rely on these legal bases:
- Performance of a contract: to provide the service you've signed up for.
- Legitimate interests: to keep the service secure, prevent fraud and abuse, and operate efficiently. We balance these interests against your rights and don't process where they're outweighed.
- Consent: for optional things like marketing email. You can withdraw consent at any time without affecting prior processing.
- Legal obligation: to comply with tax, accounting, and other applicable law.
4. Sharing
We don't sell your personal data. We share it only with:
- Our primary infrastructure provider. Enhost (enhost.uk) handles hosting and data housing for the service. Enhost is operated by the same company that operates VCurl, so it's not a separate organisation in commercial terms, but it publishes its own privacy policy listing the specific third-party tools it uses to run its infrastructure. Personal data sits on Enhost-managed servers.
- Other infrastructure providers we need for specific functions (email delivery, SMS delivery, error reporting). They process data on our instructions, under written agreements, and only for purposes we've defined.
- Payment providers when you pay for the service, who process card details directly so we don't store them.
- Your team: when you join a team workspace, other team members can see your name, profile photo, role, and the actions you take inside that workspace.
- Legal recipients when we're required to disclose by law, by court order, or to protect rights, safety, or property.
- Acquirers if the business is sold, merged, or reorganised. We'll notify you in advance and your data will continue to be governed by an equivalent privacy policy.
5. Cookies and similar technologies
We use a small number of cookies to keep you signed in (session cookie), prevent cross-site request forgery (CSRF token), and remember your preferences. We don't use third-party advertising or cross-site tracking cookies. Your browser lets you reject or delete cookies; doing so may disable parts of the service.
6. Data retention
We keep your data while your account is active and as needed to provide the service. When you delete your account, we hold it in a recovery window (currently 90 days) so you can restore it if you change your mind, then permanently delete it. Backups containing your data are overwritten on a rolling cycle, normally within 35 days of deletion. We may retain limited data longer where required by law (e.g. invoices for tax purposes) or for legitimate dispute resolution.
7. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you;
- correct data that's inaccurate (edit it any time from your profile);
- delete your account and the personal data attached to it at any time from your profile. Deleted accounts sit in a 90-day recovery window. Within that window you can restore the account by signing back in and reverting the deletion; after the window expires we permanently delete the data. You don't need to write to us, you can delete it yourself;
- export your personal data at any time from your profile. We package up everything we hold for you (account, teams, domains, webhooks, API tokens, activity) into a downloadable ZIP. This satisfies both the right of access and the right of data portability;
- object to processing based on our legitimate interests;
- withdraw consent for processing where you previously gave it (e.g. marketing, which you can toggle off in your profile);
- lodge a complaint with your local data protection authority.
For account deletion and data export, no written request is needed. Both are self-service in your profile and take effect immediately. For other rights, write to team@anymosolutions.uk; we respond within one calendar month under UK/EU GDPR (with a possible extension for complex requests, and we'll tell you if so).
8. International transfers
We may transfer and process personal data in countries other than the one you live in, including countries that aren't recognised as having "adequate" data protection. Where we do, we use appropriate safeguards (such as Standard Contractual Clauses) so your data is afforded an equivalent level of protection.
9. Children
The service isn't directed to people under 16, and we don't knowingly collect data from them. If you believe a minor has provided us with personal data, contact us and we'll delete it.
10. Security
We protect your data with industry-standard administrative, technical, and physical safeguards (encrypted transport, encrypted-at-rest secrets, hashed passwords, multi-factor authentication, access controls, audit logs, and routine review). No system is perfectly secure; if we become aware of a security incident affecting your personal data, we'll notify you and any regulator as required by law. For the operational detail behind these safeguards (encryption specifics, backup cadence, access provisioning, vulnerability management), see our trust & security FAQ.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we'll notify you in-app and by email. The "last updated" date at the top tells you when the policy was last revised.
12. Contact
Questions about this policy or your data? Email us at team@anymosolutions.uk, or write to ANYMO SOLUTIONS LIMITED, 1b George Street, Hull, United Kingdom, HU12 8JH.
If you're in the UK and we don't resolve your complaint to your satisfaction, you can lodge it with the Information Commissioner's Office (ico.org.uk). If you're in the EU, contact your local supervisory authority.
See our terms of service for the rules of using the platform.