Privacy
Engineering-preview policy — written to be read, and to show the posture the product is built around.
What this demo collects
The hosted demo stores the data you type into it (display names, labels, simulated IBANs) in server memory only, resets it whenever the environment recycles, and sets no tracking cookies. There is no analytics, advertising, or fingerprinting on this site.
What the product is designed to collect
- Identity data — collected by a regulated KYC provider at onboarding, as the law requires; we store the verification outcome, not your document images.
- Transaction metadata — merchant, amount, category and decision trail, used to run routing, insights, and your own statement.
- Never full card numbers — these exist only inside an isolated token vault; the platform, and any breach of it, sees tokens.
Principles that carry to production
- Data minimisation by architecture: what we don't store, we can't leak.
- No sale of personal data. Insights exist for you, not for advertisers.
- GDPR rights honoured mechanically: export and erasure are product features, not support tickets.
Questions: privacy@valuto.io.