Vouch

Privacy policy

Draft, not yet reviewed by counsel

Last updated 14 September 2026

In short. We collect the minimum needed to run a growth platform for mobile apps. We never use the advertising identifier, we hash device fingerprints with a salt that rotates daily, we do not profile people across different apps, and we do not sell data. For end users of apps built on Vouch, the app developer is in charge of the data and we act on their instructions. The registered address is the one highlighted value still to be added.

1.Who we are and what this policy covers

This policy is issued by Vouch Limited, a company being incorporated in Nigeria; registration number to be added on incorporation (“Vouch”, “we”, “us”). It explains how we handle personal data in three places:

  • The website at vouch.marketing, including the homepage demo.
  • The hosted service: the dashboard, APIs and hosted resolver that app developers (“customers”) sign up for.
  • The SDK, which customers embed in their own mobile apps and which sends data to Vouch on their behalf.

It does not cover the self-hosted open-source software. When you run Vouch on your own infrastructure, you control the data and no personal data reaches us unless you enable an optional connection to the hosted control plane (Section 6).

2.Controller or processor: which one we are

Whether we decide how data is used, or act on a customer’s instructions, depends on whose data it is.

Data aboutOur roleMeaning
Website visitors and early-access sign-upsControllerWe decide the purposes and this policy applies directly.
Customer account holders and their team membersControllerWe decide the purposes for account, billing, security and support data.
End users of customers’ apps (data collected by the SDK, links and funnels)ProcessorThe customer is the controller. We process only on their instructions under our Data Processing Agreement. Requests about this data should go to the app developer first; Section 10 explains how.

3.Data we collect as a controller

Accounts and workspaces

Name, email address, password hash or the identity provided by GitHub, Google or Apple sign-in, workspace name, role, and the apps you register (bundle identifiers, package names, store URLs, signing certificate fingerprints and Apple Team ID). Fingerprints and Team IDs identify apps, not people, but we list them for completeness.

Billing

Plan, invoices, billing contact and VAT or tax identifiers. Card details are collected and stored by our payment provider, never by us.

Usage and security

Dashboard and API activity, API key metadata (keys themselves are hashed at rest), IP address and user agent of requests to the dashboard and API, and an audit log of configuration changes with the actor and timestamp.

Support and correspondence

Anything you send us by email or through the community channel.

Website analytics

Aggregate page views and referrers from a privacy-preserving analytics provider that does not set tracking cookies or build cross-site profiles.

4.Data the SDK and links process for customers

When an app developer integrates Vouch, the following can be processed about that app’s end users. What is actually collected depends on which modules the developer enables.

  • A Vouch device identifier: a random ID generated by the SDK and stored on the device. It is not the advertising identifier and it does not persist across a reinstall beyond what the operating system allows.
  • Link clicks: the link opened, time, platform, country, referrer, a coarse user-agent class and a hashed device fingerprint (IP address, OS version, device model class, language, screen size and time zone combined and hashed with a salt that rotates at least daily). We store the hash, not the raw values, and never expose it through the API.
  • Installs and opens: first launch and subsequent launches, app version, the link that led there if one matched, and whether the match was deterministic or probabilistic.
  • Referral and conversion events: programme, inviter and invitee identifiers assigned by the developer, qualifying events, rewards, and purchase or refund events with amount and currency.
  • Device integrity signals (Security module): categorised indicators such as emulator, rooted or jailbroken device, debugger attached, repackaged app. Categories only, never a raw device dump.
  • Web funnel and checkout data (Web-to-App module): email address, funnel answers and purchase details, so that the purchase can be handed to the app. Card data is handled entirely by the payment provider.

What the SDK never does unless the developer explicitly enables the feature and the platform permission is granted: read the clipboard, read the advertising identifier (IDFA or GAID), or read contacts. Vouch does not use IDFA or GAID at all and does not build profiles of a person across different customers’ apps.

5.Why we use data and our legal bases

PurposeDataLegal basis (NDPA 2023, UK and EU GDPR)
Provide and secure the hosted serviceAccount, workspace, usage and security dataContract
Bill for the serviceBilling dataContract and legal obligation
Prevent abuse of our platform and our customers’ appsSecurity and usage data, device integrity categoriesLegitimate interests (keeping the platform and its customers safe)
Improve the productAggregated, de-identified usageLegitimate interests
Answer support requestsCorrespondenceContract and legitimate interests
Process end-user data for customersSDK, link and funnel dataPerformed on the customer’s instructions; the customer holds the legal basis towards their users

We do not sell personal data and we do not use it for advertising.

6.Who we share data with

We share data only with providers that help us run the service, each under a contract that limits what they may do with it:

  • Cloud hosting and content delivery for the dashboard, APIs and resolver
  • Transactional email delivery
  • Payment processing and, for the Creators module, payout providers who also collect the tax and identity documents that the law requires (we store their status, never the documents)
  • Error monitoring and privacy-preserving analytics
  • Apple and Google, when verifying device attestations. Raw platform attestation tokens are never passed to customers.

A current list of sub-processors with their locations will be published at https://vouch.marketing/legal/subprocessors before the hosted service accepts customers, and customers are notified before a new one is added.

Self-hosted deployments can optionally connect to the hosted control plane for association-file monitoring and risk intelligence. That connection sends configuration and aggregate signals, not end-user data.

We may also disclose data when the law requires it, to protect someone’s safety, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.

7.How long we keep data

DataRetention
Account and workspace dataFor the life of the account, then deleted within 90 days of closure
Billing recordsAs long as tax law requires, typically 6 to 7 years
Raw events (clicks, installs, opens, conversions)90 days by default on the hosted plan, configurable per workspace; aggregated statistics are kept indefinitely and cannot identify a person
Demo links created on the homepageIn memory for up to 24 hours, then discarded
Audit logs2 years
Support correspondence3 years after the last message

8.International transfers

We are based in Nigeria and our providers may process data outside the country where you live. Where data leaves Nigeria we rely on the adequacy and safeguard mechanisms of the Nigeria Data Protection Act 2023. Where data leaves the UK or the European Economic Area we rely on adequacy decisions or the standard contractual clauses approved by the relevant authority, and we assess the destination before transferring. An EU data-residency option for the hosted service is planned; customers who need it should ask before signing up.

9.Security

Data is encrypted in transit and at rest. Platform keys and secrets live in a managed key management service. Customer API keys are hashed at rest. Access to production is limited to staff who need it and is logged. We aim to achieve SOC 2 Type I within twelve months of launch and Type II within twenty-four. Our vulnerability disclosure policy will be published at https://vouch.marketing/security.

No system is perfectly secure. If we learn of a breach that affects you we will tell you and, where required, the supervisory authority without undue delay.

10.Your rights

Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. In Nigeria that is the Nigeria Data Protection Commission (NDPC) under the Nigeria Data Protection Act 2023. In the UK it is the Information Commissioner’s Office. In the EU it is the authority in your member state.

California residents: you have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA.

To exercise a right, email privacy@vouch.dev. We will respond within 30 days and may need to verify your identity first.

If you are a user of an app that uses Vouch

The app developer is the controller of your data and the right place to start. To help them, we provide every customer with a deletion API and an export API keyed on their user identifier, so a request to the developer can be fulfilled across Vouch too. If you cannot reach the developer, contact us and we will help you find them.

11.Cookies and similar technologies

The marketing site uses no tracking cookies. It stores your theme preference in your browser and nothing else. The dashboard uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. Our analytics provider does not use cookies.

The link resolver does not set cookies on end users. The iOS clipboard-token method for deferred deep linking is off by default and, when a developer turns it on, only writes to the clipboard after the person taps a button on a page that says what will happen.

12.Children

The website and the hosted service are for businesses and developers and are not directed at children under 16. We do not knowingly collect their data as a controller. Developers whose apps are directed at children are responsible for configuring Vouch in line with the law that applies to them.

13.Changes to this policy

We will post changes here and update the date at the top. For material changes affecting customers we give at least 30 days’ notice by email. Continued use after that date means you accept the updated policy.

14.Contact

Privacy questions: privacy@vouch.dev

Postal address: [Registered address to be confirmed]

A data protection officer, and an EU or UK representative, will be named here if and when the law requires one.