staging - VCurl

Privacy policy

Effective on the date you accept our terms of service.

This policy explains what personal data staging - VCurl (the "service") collects, why, how we use it, who we share it with, and the rights you have over it. It applies whenever you interact with the service.

Most of it is written for people with an account. If you arrived by clicking a short link, scanning a QR code, or filling in a form or poll that one of our customers published, section 2 is the part written for you — it sets out exactly what is and isn't recorded about that visit, and who to contact about it.

The data controller for personal data collected through the service is ANYMO SOLUTIONS LIMITED (company number 17137827), registered at 1b George Street, Hull, United Kingdom, HU12 8JH. For privacy questions or to exercise your rights, contact us at team@anymosolutions.uk.

1. Data we collect

Account data you provide: name, email address, optional phone number, password (stored hashed), profile photo if you upload one, timezone, notification preferences, and your acceptance timestamps for our terms and marketing communications.

Authentication data: hashed multi-factor authentication secrets and recovery codes, OAuth provider links (e.g. Google, GitHub) if you connect them, and personal access tokens you issue.

Usage data: activity within the service (records you create, settings you change), sign-in events, device and IP metadata for session activity, and timestamps for actions needed for audit.

Tenant data: any team workspaces you create or join, the membership relationships between users and teams, and team-level resources (domains, webhooks, API tokens) you configure.

Communications: emails and in-app notifications we send you and any replies or support correspondence you send us.

Technical data: cookies (session, CSRF, preferences), application logs for security and debugging, and error reports.

2. Visitors to links, forms and polls our customers publish

This section is for you if you didn't sign up for anything — you clicked a short link, scanned a QR code, loaded a page containing a tracking pixel, voted in a poll, filled in a feedback form, answered an availability poll or submitted a score to a leaderboard that one of our customers created.

Who's responsible: for these interactions the customer who created the link or form is the data controller — they decide to collect it and what to do with it. We act as their processor, handling it on their instructions under the data processing agreement we have with them. That is an exception to the controller statement at the top of this policy, which covers account holders. If you want your data accessed, corrected or erased, the customer is the right first contact; if you can't reach them or don't know who they are, write to us at team@anymosolutions.uk and we'll pass it on and help where we can.

What gets recorded when you open a link: the date and time, which link you opened, the page that referred you if any, the country and city the request came from, the network it arrived over (its autonomous system number and the operator's name, e.g. a mobile carrier or a hosting company), the kind of device (mobile, tablet or desktop), the operating system family (iOS, Android, Windows, macOS or Linux), and whether the request came from an automated client rather than a person.

What does not get recorded: we do not store your IP address, and we do not store your browser's user-agent string. Both are read as the request is handled, used to work out the coarse facts listed above, and then discarded — they are never written to our records. We also store no identifier of any kind for you, which means we cannot tell that two visits came from the same person, cannot build a profile across links, and cannot recognise you on a later visit. There is no advertising or cross-site tracking, and no cookie is set when a link redirects you.

Automated clients are the exception: when a request comes from a crawler, a search engine or a chat app fetching a link preview, we keep its full user-agent string. Those strings name a company's software rather than a person, so there is no individual behind them.

If you fill something in: whatever you type into a feedback form, poll, availability poll or leaderboard — which may include your name or email address if the customer asked for them — is submitted to that customer. They decide what it's used for, how long it's kept and who sees it, so their own privacy notice governs it, not this one.

Cookies on public pages: if a poll or availability poll is set to accept one response per browser, we set a single functional cookie (vcurl_poll_… or vcurl_availability_…) so the page knows you've already responded. It holds the value "1" and nothing else — no identifier — and lasts a year. It exists only to do the thing you asked for, so it isn't used for tracking and doesn't need a consent banner. See our cookie policy for the full list.

Where we do use your IP briefly: public form, poll and availability submissions are rate-limited by IP address to blunt spam and automated abuse. That check happens in memory over a one-minute window and the address is not written to any record. We rely on our legitimate interest in keeping the service available and free of abuse.

Request bins are different, by design: a request bin is a developer tool that captures incoming HTTP requests so our customer can inspect exactly what their own software sent. Reproducing a request faithfully means keeping it intact, so for these — and only these — we do store the source IP address and user-agent alongside the headers and body. Captures are automatically deleted after 30 days.

How long the rest is kept: interaction records are retained for as long as the customer keeps the link, because they contain nothing that identifies an individual. If the customer deletes the link or their account, the records go with it.

3. How we use it

We don't use your data to train external advertising or sell it to data brokers. Marketing emails go out only if you've opted in (you can toggle this any time from your profile).

4. Legal bases (UK/EU users)

Where UK GDPR or EU GDPR applies, we rely on these legal bases:

5. Sharing

We don't sell your personal data. We share it only with:

6. Cookies and similar technologies

We use a small number of cookies to keep you signed in (session cookie), prevent cross-site request forgery (CSRF token), and remember your preferences. We don't use third-party advertising or cross-site tracking cookies. Your browser lets you reject or delete cookies; doing so may disable parts of the service.

7. Data retention

We keep your data while your account is active and as needed to provide the service. When you delete your account, we hold it in a recovery window (currently 90 days) so you can restore it if you change your mind, then permanently delete it. Backups containing your data are overwritten on a rolling cycle, normally within 35 days of deletion. We may retain limited data longer where required by law (e.g. invoices for tax purposes) or for legitimate dispute resolution.

8. Your rights

Depending on where you live, you have the right to:

For account deletion and data export, no written request is needed. Both are self-service in your profile and take effect immediately. For other rights, write to team@anymosolutions.uk; we respond within one calendar month under UK/EU GDPR (with a possible extension for complex requests, and we'll tell you if so).

9. International transfers

We may transfer and process personal data in countries other than the one you live in, including countries that aren't recognised as having "adequate" data protection. Where we do, we use appropriate safeguards (such as Standard Contractual Clauses) so your data is afforded an equivalent level of protection.

10. Children

The service isn't directed to people under 16, and we don't knowingly collect data from them. If you believe a minor has provided us with personal data, contact us and we'll delete it.

11. Security

We protect your data with industry-standard administrative, technical, and physical safeguards (encrypted transport, encrypted-at-rest secrets, hashed passwords, multi-factor authentication, access controls, audit logs, and routine review). No system is perfectly secure; if we become aware of a security incident affecting your personal data, we'll notify you and any regulator as required by law. For the operational detail behind these safeguards (encryption specifics, backup cadence, access provisioning, vulnerability management), see our trust & security FAQ.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we'll notify you in-app and by email. The "last updated" date at the top tells you when the policy was last revised.

13. Contact

Questions about this policy or your data? Email us at team@anymosolutions.uk, or write to ANYMO SOLUTIONS LIMITED, 1b George Street, Hull, United Kingdom, HU12 8JH.

If you're in the UK and we don't resolve your complaint to your satisfaction, you can lodge it with the Information Commissioner's Office (ico.org.uk). If you're in the EU, contact your local supervisory authority.

See our terms of service for the rules of using the platform.