Privacy Policy

Effective date
July 2026
Applies to
Vantr, and everyone using it

This Policy sets out what personal data Vantr collects, the legal basis for each use, who we share it with, how long we keep it, where it is stored, and the rights you can exercise over it.

1.Who we are and what this covers

1.1

This Policy explains how Vantr collects, uses, shares and protects personal data when you use the Vantr web application and related services.

1.2

For the purposes of the UK and EU General Data Protection Regulation, Vantr is the controller of the personal data described here. Vantr is currently operated as a sole proprietorship; a registered company has not yet been formed, and this section will be updated when one is.

1.3

Where you use Vantr to publish to a third-party platform, that platform is an independent controller of the data it receives and holds, governed by its own privacy policy. This Policy does not cover what a platform does with your content once published.

1.4

You can reach us about anything in this Policy at support@vantr.app.

2.The personal data we collect

2.1

We collect the following categories of personal data:

CategoryWhat it includesWhere it comes from
Account dataEmail address, display name, password hash or third-party sign-in identifier, workspace name and role.You, when you register
Connected platform dataOAuth access and refresh tokens, platform account ID, username, display name, avatar URL, and granted scopes.The platform, when you authorise it
Content dataVideos, images, captions, hashtags, drafts, scheduled times, and publishing status and errors.You, as you use the Service
Performance dataViews, likes, comments, shares and follower counts retrieved from platforms for posts you published through Vantr.Connected platforms
Business recordsBrand deals, contacts, deal values, income and expense entries you choose to record.You, if you use these features
AI usage dataThe text you submit to an AI feature, the response returned, and a timestamped record of the request.You, when you invoke an AI feature
Billing dataSubscription plan, status, billing period, and payment-processor customer and subscription identifiers. We do not receive or store full card numbers.You and Stripe
Technical dataIP address, browser and device type, and server and error logs generated when you use the Service.Automatically
2.2

We do not collect special categories of personal data (such as health, biometric, or political data) and ask that you do not submit them through the Service.

4.AI features and your content

4.1

AI features are optional. Nothing is transmitted to an AI provider unless you actively invoke a feature such as caption feedback or rewriting.

4.2

When you do, the text you submit is sent to Google (Gemini) to generate a response, and a record of the request is retained in your account history so you can see what was asked and what was returned.

4.3

We do not train AI models on your content, and we use our AI provider under paid API terms that prohibit the provider from using submitted data to train or improve its models. We do not send your videos or images to an AI provider — only text you submit to a text-based feature.

4.4

If you would rather no content ever reach an AI provider, simply do not use the AI features. Every other part of the Service works without them.

5.Who we share it with

5.1

We do not sell your data. We share it only with service providers who process it on our instructions in order to run the Service:

RecipientWhat they processPurposeLocation
SupabaseAccount, content, platform tokens, business recordsDatabase, authentication and file storageUnited States
VercelTechnical data, and content in transitApplication hosting and deliveryUnited States
StripeBilling and payment dataPayment processing and subscription managementUnited States
Google (Gemini API)Text you submit to an AI featureGenerating AI responses when you invoke a featureUnited States
Connected platforms you authoriseContent you choose to publish, and the tokens needed to publish itPublishing your posts at your directionVaries by platform
5.2

Each provider is bound by a data processing agreement, or by contractual terms of equivalent effect, restricting them to processing data on our instructions.

5.3

We may also disclose personal data where we are legally required to, to enforce our Terms, or to protect the rights, safety or property of Vantr or others. Where we are lawfully able to notify you first, we will.

5.4

If Vantr is involved in a merger, acquisition or sale of assets, personal data may transfer as part of that transaction. We will give notice before your data becomes subject to a materially different privacy policy.

6.International transfers

6.1

Vantr and its service providers are located in the United States. If you use the Service from the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to and processed in the United States.

6.2

For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where applicable, incorporated into our agreements with the providers listed in section 5.

6.3

You may request a copy of the relevant transfer mechanism by writing to support@vantr.app.

7.How long we keep it

7.1

We keep personal data only as long as we need it for the purpose it was collected:

DataRetention period
Account and workspace dataFor as long as your account is open, then deleted within 30 days of closure.
Content, drafts and scheduled postsUntil you delete them, or within 30 days of account closure.
Connected platform tokensUntil you disconnect the platform or close your account, then deleted promptly.
Performance and analytics dataFor as long as the associated post exists in your account.
Social listening results30 days, then automatically deleted by a scheduled job.
Comment dataComments are refreshed on a rolling 90-day window; records for deleted comments are retained as tombstones so they are not re-imported.
AI request historyFor as long as your account is open, then deleted with the account.
Billing and tax recordsUp to 7 years after the transaction, as required by tax and accounting law.
Server and security logsTypically 30 days, longer where needed to investigate a specific incident.
7.2

Deleting content in the Service does not remove anything already published on a third-party platform. You must delete that from the platform itself.

7.3

We may retain data longer where necessary to establish, exercise or defend a legal claim, or where the law requires it.

8.Your rights

8.1

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — obtain confirmation of whether we process your data and receive a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where we no longer have grounds to keep it.
  • Restriction — ask us to limit how we use your data while a dispute about it is resolved.
  • Portability — receive the data you provided to us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting processing already carried out.
  • Non-discrimination — under California law, we will not deny you service or charge you a different price for exercising your rights.
8.2

You can exercise most of these rights directly in the Service: your settings include data export and account deletion. For anything else, write to support@vantr.app. We will respond within one month, and will tell you if we need longer because the request is complex.

8.3

We may need to verify your identity before acting on a request. You may use an authorised agent, in which case we will ask for proof of their authority.

8.4

If you are unhappy with how we have handled your data you may complain to your local supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, the authority in your country of residence. We would appreciate the chance to resolve it with you first.

9.How we protect it

9.1

The measures we actually have in place are:

  • Connected platform access and refresh tokens are encrypted with AES-256-GCM before they are written to the database, so a database backup contains only ciphertext.
  • Every table enforces row-level security, so a query can only ever return rows belonging to the requesting user's workspace.
  • Workspace roles restrict what each member can do, including who may publish, approve, or manage billing.
  • All traffic between your browser and the Service is encrypted in transit with TLS.
  • Data is stored with established infrastructure providers (Supabase and Vercel) that maintain their own physical and network security controls.
  • Passwords are never stored in plain text; authentication is handled by our identity provider.
9.2

We want to be straightforward about the limits of that: Vantr has not undergone a third-party security audit and holds no security certification such as SOC 2 or ISO 27001. We do not claim to. No system is perfectly secure, and we cannot guarantee the Service will never be compromised.

9.3

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and will notify you without undue delay where the risk is high.

9.4

To report a suspected vulnerability, email support@vantr.app and give us a reasonable chance to fix it before disclosing publicly.

10.Cookies and similar technologies

10.1

We use a small number of cookies: strictly necessary cookies to keep you signed in and secure your session, and a preference cookie that remembers your light or dark theme.

10.2

We do not use advertising cookies, and we do not embed third-party tracking or advertising networks.

10.3

Our Cookie Policy sets out each cookie, its purpose and its lifetime.

11.Children

11.1

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children.

11.2

If you believe a child has provided us with personal data, write to support@vantr.app and we will delete it.

12.Changes to this Policy

12.1

We may update this Policy as the Service changes. The effective date at the top records when the current version took effect.

12.2

Where a change materially affects how we use your personal data, we will give notice by email or in the Service before it takes effect, and where the law requires it we will ask for your consent.

13.Contact

13.1

For any privacy question, to exercise a right, or to request a copy of a data transfer mechanism, write to support@vantr.app.

13.2

We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy enquiries are handled by the proprietor of Vantr directly.

Privacy Policy · Vantr