← Back to home

Privacy policy

Last updated: 22 August 2026. This policy covers the vuco website and the vuco app. We collect as little as possible: no cookies, no tracking, no ad analytics. The German version is authoritative.

1. Controller

The controller for data processing described here is:
Miahkyi Yevhen Yuriiovych, FOP (sole proprietor under Ukrainian law)
68 Shchorsa St., apt. 67
Kremenchuk, Poltava Oblast
39600 Ukraine
Email: support@vuco.app

2. Visiting the site (hosting & server logs)

This static site is hosted by Netlify, Inc. (USA, delivered via a global CDN). On access, the provider processes technically necessary access data (e.g. IP address, date/time, requested page, user agent) to deliver and secure the site. The legal basis is our legitimate interest in a secure, functioning service (Art. 6(1)(f) GDPR). Details: Netlify privacy policy; processing is governed by Netlify's data processing agreement including EU standard contractual clauses.

3. No cookies, no analytics

The website uses no cookies and no analytics or tracking services. A chosen language preference is stored only locally in your browser (localStorage) and is never transmitted to us.

4. The vuco app

Account and sign-in. You sign in with your email address and a one-time code sent by email. No password is stored.

What the app processes. To do its job — turning your jobs into compliant invoices and getting them paid — the app processes: your business profile (name, address, tax number or VAT ID, and your IBAN, which appears on invoices and inside the EPC payment QR code); your customers, jobs, quotes and time entries; photos and voice notes you capture on a job; your precise location only at the moment a customer confirms extra work (it becomes part of that confirmation record); a device/push token for notifications; and crash diagnostics.

Purposes and legal bases. Providing the app's functions under the contract with you (Art. 6(1)(b) GDPR); crash diagnostics out of our legitimate interest in a stable, secure app (Art. 6(1)(f)); retaining issued invoices to meet statutory bookkeeping obligations (Art. 6(1)(c)).

Processors. We use the following providers under data processing agreements, with EU data residency by design: Neon (database, Frankfurt, Germany), Hetzner Online (file and document storage including the tamper-proof invoice archive, Falkenstein, Germany), Railway (API hosting, EU-West region, Amsterdam), Brevo (transactional email, EU), Sentry (crash reporting, EU region, with data scrubbing enabled), Google Firebase Cloud Messaging (push notification delivery), RevenueCat (subscription state; USA, under EU standard contractual clauses) and Google Play (payment processing for subscriptions — Google is your contract partner for the payment itself).

Retention and deletion. Account data is kept until you delete your account. Invoices you have issued, including their supporting records, are subject to a statutory retention period (German § 147 AO, up to 10 years) and remain in the archive for that time. How to delete your account or specific data: Delete your account and data.

5. Contact by email

If you email us, we process your email address and message solely to handle your request (Art. 6(1)(b) or (f) GDPR). Email to support@vuco.app is received via a forwarding service and Google (Gmail).

6. Sharing with third parties

Your data is shared only with the service providers named above, to the extent described, and for no other purpose. We do not sell data and we do not share it for advertising.

7. Retention (website emails)

We keep emails you send us for as long as needed to handle your request and delete them at the latest 12 months after the request is closed, unless a statutory retention period applies.

8. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR). You may also lodge a complaint with a supervisory authority (Art. 77 GDPR) — for example the data protection authority of your place of residence. For Germany, the federal commissioner (BfDI, bfdi.bund.de) lists the competent state authorities.

9. Data security

The website and all app traffic are served exclusively over encrypted HTTPS (TLS).

10. Changes to this policy

We update this policy when our data processing changes. The version published here applies.