Privacy policy
Draft, not yet reviewed by counselLast updated 14 September 2026
1.Who we are and what this policy covers
This policy is issued by Vouch Limited, a company being incorporated in Nigeria; registration number to be added on incorporation (“Vouch”, “we”, “us”). It explains how we handle personal data in three places:
- The website at vouch.marketing, including the homepage demo.
- The hosted service: the dashboard, APIs and hosted resolver that app developers (“customers”) sign up for.
- The SDK, which customers embed in their own mobile apps and which sends data to Vouch on their behalf.
It does not cover the self-hosted open-source software. When you run Vouch on your own infrastructure, you control the data and no personal data reaches us unless you enable an optional connection to the hosted control plane (Section 6).
2.Controller or processor: which one we are
Whether we decide how data is used, or act on a customer’s instructions, depends on whose data it is.
| Data about | Our role | Meaning |
|---|---|---|
| Website visitors and early-access sign-ups | Controller | We decide the purposes and this policy applies directly. |
| Customer account holders and their team members | Controller | We decide the purposes for account, billing, security and support data. |
| End users of customers’ apps (data collected by the SDK, links and funnels) | Processor | The customer is the controller. We process only on their instructions under our Data Processing Agreement. Requests about this data should go to the app developer first; Section 10 explains how. |
3.Data we collect as a controller
Accounts and workspaces
Name, email address, password hash or the identity provided by GitHub, Google or Apple sign-in, workspace name, role, and the apps you register (bundle identifiers, package names, store URLs, signing certificate fingerprints and Apple Team ID). Fingerprints and Team IDs identify apps, not people, but we list them for completeness.
Billing
Plan, invoices, billing contact and VAT or tax identifiers. Card details are collected and stored by our payment provider, never by us.
Usage and security
Dashboard and API activity, API key metadata (keys themselves are hashed at rest), IP address and user agent of requests to the dashboard and API, and an audit log of configuration changes with the actor and timestamp.
Support and correspondence
Anything you send us by email or through the community channel.
Website analytics
Aggregate page views and referrers from a privacy-preserving analytics provider that does not set tracking cookies or build cross-site profiles.
4.Data the SDK and links process for customers
When an app developer integrates Vouch, the following can be processed about that app’s end users. What is actually collected depends on which modules the developer enables.
- A Vouch device identifier: a random ID generated by the SDK and stored on the device. It is not the advertising identifier and it does not persist across a reinstall beyond what the operating system allows.
- Link clicks: the link opened, time, platform, country, referrer, a coarse user-agent class and a hashed device fingerprint (IP address, OS version, device model class, language, screen size and time zone combined and hashed with a salt that rotates at least daily). We store the hash, not the raw values, and never expose it through the API.
- Installs and opens: first launch and subsequent launches, app version, the link that led there if one matched, and whether the match was deterministic or probabilistic.
- Referral and conversion events: programme, inviter and invitee identifiers assigned by the developer, qualifying events, rewards, and purchase or refund events with amount and currency.
- Device integrity signals (Security module): categorised indicators such as emulator, rooted or jailbroken device, debugger attached, repackaged app. Categories only, never a raw device dump.
- Web funnel and checkout data (Web-to-App module): email address, funnel answers and purchase details, so that the purchase can be handed to the app. Card data is handled entirely by the payment provider.
What the SDK never does unless the developer explicitly enables the feature and the platform permission is granted: read the clipboard, read the advertising identifier (IDFA or GAID), or read contacts. Vouch does not use IDFA or GAID at all and does not build profiles of a person across different customers’ apps.
5.Why we use data and our legal bases
| Purpose | Data | Legal basis (NDPA 2023, UK and EU GDPR) |
|---|---|---|
| Provide and secure the hosted service | Account, workspace, usage and security data | Contract |
| Bill for the service | Billing data | Contract and legal obligation |
| Prevent abuse of our platform and our customers’ apps | Security and usage data, device integrity categories | Legitimate interests (keeping the platform and its customers safe) |
| Improve the product | Aggregated, de-identified usage | Legitimate interests |
| Answer support requests | Correspondence | Contract and legitimate interests |
| Process end-user data for customers | SDK, link and funnel data | Performed on the customer’s instructions; the customer holds the legal basis towards their users |
We do not sell personal data and we do not use it for advertising.
7.How long we keep data
| Data | Retention |
|---|---|
| Account and workspace data | For the life of the account, then deleted within 90 days of closure |
| Billing records | As long as tax law requires, typically 6 to 7 years |
| Raw events (clicks, installs, opens, conversions) | 90 days by default on the hosted plan, configurable per workspace; aggregated statistics are kept indefinitely and cannot identify a person |
| Demo links created on the homepage | In memory for up to 24 hours, then discarded |
| Audit logs | 2 years |
| Support correspondence | 3 years after the last message |
8.International transfers
We are based in Nigeria and our providers may process data outside the country where you live. Where data leaves Nigeria we rely on the adequacy and safeguard mechanisms of the Nigeria Data Protection Act 2023. Where data leaves the UK or the European Economic Area we rely on adequacy decisions or the standard contractual clauses approved by the relevant authority, and we assess the destination before transferring. An EU data-residency option for the hosted service is planned; customers who need it should ask before signing up.
9.Security
Data is encrypted in transit and at rest. Platform keys and secrets live in a managed key management service. Customer API keys are hashed at rest. Access to production is limited to staff who need it and is logged. We aim to achieve SOC 2 Type I within twelve months of launch and Type II within twenty-four. Our vulnerability disclosure policy will be published at https://vouch.marketing/security.
No system is perfectly secure. If we learn of a breach that affects you we will tell you and, where required, the supervisory authority without undue delay.
10.Your rights
Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. In Nigeria that is the Nigeria Data Protection Commission (NDPC) under the Nigeria Data Protection Act 2023. In the UK it is the Information Commissioner’s Office. In the EU it is the authority in your member state.
California residents: you have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA.
To exercise a right, email privacy@vouch.dev. We will respond within 30 days and may need to verify your identity first.
If you are a user of an app that uses Vouch
The app developer is the controller of your data and the right place to start. To help them, we provide every customer with a deletion API and an export API keyed on their user identifier, so a request to the developer can be fulfilled across Vouch too. If you cannot reach the developer, contact us and we will help you find them.
12.Children
The website and the hosted service are for businesses and developers and are not directed at children under 16. We do not knowingly collect their data as a controller. Developers whose apps are directed at children are responsible for configuring Vouch in line with the law that applies to them.
13.Changes to this policy
We will post changes here and update the date at the top. For material changes affecting customers we give at least 30 days’ notice by email. Continued use after that date means you accept the updated policy.
14.Contact
Privacy questions: privacy@vouch.dev
Postal address: [Registered address to be confirmed]
A data protection officer, and an EU or UK representative, will be named here if and when the law requires one.