Privacy Policy

Last updated: 2 August 2026 · Version 2026-08

Identity of the data controller

Vopway Ltd. is registered in England & Wales under company number 17276149. Registered address: 124 City Road, London, United Kingdom, EC1V 2NX. Privacy contact: privacy@vopway.com

Vopway Ltd. is the data controller for account creation and authentication, phone verification, billing, platform security and abuse prevention, support requests, and product and diagnostic telemetry.

Where you use Vopway as a member of an organisation, Vopway Ltd. acts as a processor on that organisation's instructions for the content of your channels, your live location and route history including administrator replay and export, geofenced zones, safety alerts, and talk statistics. Your organisation is the controller for that data and decides how it is used. Direct access, erasure and objection requests about that data to your organisation; we will assist them under Article 28(3)(e).

Categories of personal data collected

The list below is ordered to match the data types declared on our App Store and Google Play privacy labels, so the two can be read side by side.

  • Identity and contact data — first name, last name, pseudo, email address, mobile phone number, profile picture, and your role within your organisation.
  • Location data — precise GPS position and, where you grant reduced-accuracy permission, approximate position. Each sample is stored as a historical location point. See the "Location" section below for how this works in practice.
  • User content — the text of messages you send; push-to-talk voice recordings and the text transcripts produced from them; photos and videos you choose from your library or capture with the camera; other file attachments and documents, including their file names; zone and waypoint names you create; and AI-generated summaries of channel activity.
  • Support requests — the subject, category and free-text description you submit through in-app support, together with your app version, build number and platform, which are attached automatically.
  • Identifiers — your Vopway user ID, device identifiers, and push notification tokens.
  • Purchase data — your subscription status, invoices, and the transaction identifiers we receive from the payment provider: a Stripe customer ID for purchases made on the web, or an Apple or Google transaction ID for purchases made inside the mobile apps. We never receive or store your card number or any payment-instrument details.
  • Usage and activity data — activity events including sign-in and sign-out, channel joins and leaves, talk events, message sends, message reads (read receipts) and connection-loss events; per-channel talk statistics such as total and longest talk duration, session count and time last talked; map-load counts; and AI credit consumption.
  • Diagnostics — crash reports, voice and video call quality telemetry, and application log uploads. See the "Diagnostics and crash reporting" section below.
  • Technical data — IP address, user agent, session identifiers and authentication sessions.
  • Contact matching and invitations — if you use contact matching, the phone numbers and email addresses in your device address book are sent to us for real-time matching only and are not retained. If you invite someone, the email address you supply is stored as an invitation record. See "Contacts and invitations" below.

Encryption, and what Vopway can access

Message bodies and attachment payloads in encrypted channels are encrypted on your device before they are sent, and Vopway cannot read them. All traffic is additionally encrypted in transit using TLS 1.2 or higher, and data at rest is encrypted using AES-256.

Some information is deliberately held in readable form on our servers so that features you use can work. You should assume Vopway staff and the providers named below can access it:

  • The text transcript of a push-to-talk voice message. Some transcripts are produced on the sending device and uploaded as text; others are produced on our servers by sending the audio to a third-party speech-to-text provider. Either way, the transcript is stored in readable form next to the message, including for messages sent in encrypted channels.
  • Attachment file names, which are stored and transmitted unencrypted even where the attachment itself is encrypted.
  • AI Insight output — channel summaries and TL;DR previews — which is generated from message text and voice transcripts and stored in readable form.
  • Push notification metadata. When we send a notification, the sender's display name, the channel name and, for file messages, the attachment file name are included in the notification payload in readable form, and therefore pass through Apple's and Google's notification services. Message text and voice content remain encrypted in the payload.

Live voice and video are relayed by a LiveKit media server that Vopway operates on its own infrastructure. No LiveKit-operated cloud service receives your calls. Where a direct or server-relayed path cannot be established, a TURN relay operated by Twilio may carry the encrypted media stream.

Location

When you enable location sharing, the Vopway app records your position and sends it to your organisation so your team can see where you are on the map. In the current release, location is collected only while the app is open and in use; collection stops when you leave the app. Position is sampled at high accuracy with a minimum-distance filter, and each sample is stored as a point in your location history.

Where you grant your device's reduced-accuracy ("approximate") location permission instead, we receive and store the approximate position through the same pipeline.

Within your organisation, other members of a channel you are sharing with can see your live position. Users with an administrator role can additionally replay your historical route for a chosen period and export it to a GPX or KML file. Your position is also used to evaluate geofenced zones you or your organisation define.

You can stop location sharing at any time by turning it off in the app, or by withdrawing the location permission in your device settings.

Contacts and invitations

If you grant contacts permission, the app sends the phone numbers and email addresses in your device address book to Vopway solely so we can tell you which of your contacts already use Vopway. The list is compared in memory and the result is returned to you immediately. We do not store, cache or log your address book, and we never contact anyone in it.

If you choose to invite someone, the email address you select is stored as an invitation record, together with your identity as the sender and your organisation, so that the invitation can be sent and redeemed. We obtained that address from you. The person invited can ask us to delete it at any time by emailing privacy@vopway.com.

If you choose to invite a contact through WhatsApp or SMS, your device opens that app with your contact's number filled in. The number is then handled by WhatsApp (Meta) or by your mobile carrier under their own privacy policies. Vopway does not send it to them.

Diagnostics and crash reporting

The Vopway apps send us technical data about failures and performance. This is not anonymous: each stream is linked to your account. We rely on our legitimate interest in keeping the service reliable and secure.

  • Crash reports. When the app crashes, a crash report is sent to Google Firebase Crashlytics. It contains the stack trace, device model, operating system version and app version, and is tagged with your Vopway user ID, your role and your organisation ID. Crash reporting is always on and there is currently no in-app way to switch it off.
  • Application logs. The app uploads application log entries to Vopway. Each entry carries a device identifier, a user identifier, your organisation ID and your session ID. Because automatic redaction of coordinates and transcript text is not yet complete, an uploaded log may contain your precise GPS position and short excerpts of voice transcripts. This stream is on by default. You can object to it by emailing privacy@vopway.com, and you can ask us to erase uploaded logs at any time.
  • Call quality telemetry. While you are in a voice or video call, the app records connection quality measurements (bitrate, packet loss, jitter, reconnection events) and uploads them to Vopway linked to your user ID and the channel.

Diagnostic uploads are stored in our object storage under a path that contains your user ID; they are not anonymised. See "Data retention periods" for how long each stream is kept.

Automated features

AI Insight. On plans where it is enabled, Vopway generates written summaries of channel activity from message text and voice transcripts using the AI providers named below. Summaries are stored on our servers in readable form. Ask your organisation administrator whether the feature is enabled for your channels.

These features do not produce decisions with legal or similarly significant effects about you that are made solely by automated means.

Legal basis for processing

PurposeData usedLawful basis
Creating and authenticating your accountIdentity and contact data, identifiers, technical dataPerformance of a contract
Verifying your phone number by SMSPhone numberPerformance of a contract; legitimate interest in preventing fraudulent sign-ups
Delivering messages, voice, video and file attachmentsUser content, identifiersPerformance of a contract
Sharing your location with your team, and making route history available to your organisation's administratorsLocation dataPerformance of a contract with your organisation; where you are a member of a customer organisation, your employer determines this processing and is the controller for it
Automatic transcription of voice messages by third-party providersVoice recordingsPerformance of a contract
AI summaries and virtual agent repliesMessage text, transcripts, sender namesPerformance of a contract
Subscription billing and invoicingPurchase data, identity dataPerformance of a contract; legal obligation for tax and accounting records
Crash reporting, diagnostics and call quality telemetryDiagnostics, identifiers, technical dataLegitimate interest in keeping the service reliable, diagnosing failures and improving quality
Security audit logging, abuse prevention and fraud detectionTechnical data, identifiers, activity dataLegitimate interest in protecting accounts and investigating misuse of the service
Sending and tracking an invitation to someone who is not yet a Vopway userThe invitee's email addressLegitimate interest in enabling our users to invite colleagues to a shared workspace
Answering support requestsSupport ticket content, app version and platformPerformance of a contract
Storing preferences and non-essential data on your device or in your browserBrowser and device storageConsent
Collecting precise location from your deviceLocation dataConsent, given through your device's location permission
Uploading your device address book for contact matchingContact phone numbers and email addressesConsent, given through your device's contacts permission

Where we rely on legitimate interests, we have carried out a balancing test weighing those interests against your rights and freedoms. You can request a summary of that assessment by emailing privacy@vopway.com. The core Vopway service runs on contract performance and legitimate interests; declining any of the consent-based items above does not prevent you from using it.

Data retention periods

  • Account profile data is retained until you delete your account or make a valid erasure request.
  • Location history is retained for as long as your account is active. It is deleted when you delete your account, when you clear your location history in the app, and when a tracking session is torn down. An automatic 90-day limit is being introduced and this policy will be updated when it takes effect.
  • Your plan sets a message retention window — 3 months on Free, 6 months on Pro, 12 months on Business, and unlimited on Enterprise. Automatic deletion of messages and their attachments past that window is being rolled out; until that rollout is complete, messages are retained until you or your account holder delete them.
  • Voice recordings and their transcripts are retained on the same basis as the message they belong to.
  • Attached files may be removed earlier than the periods above where an account exceeds its plan's storage allowance and that limit is enabled for your organisation. The oldest files are removed first, and the message text and any voice transcript are kept.
  • Diagnostic uploads, crash reports and call-quality telemetry are retained until you delete your account.
  • Support tickets are retained for 24 months after the ticket is closed.
  • Invitation records, including the email address of a person you invited, are retained until the invitation is accepted or you or your organisation delete it.
  • Security and audit records, including IP address, user agent and session identifier, are retained indefinitely for security, abuse prevention and auditability. They are deliberately retained after account deletion for that purpose.
  • Authentication sessions are deleted when you sign out or when a session is revoked. Automatic cleanup of long-inactive sessions after 90 days is planned but not yet in place.
  • Billing records may be retained longer where legal, tax, or accounting obligations apply.

What remains when you delete your account. Messages, voice recordings and their transcripts that you sent remain in the channels you posted them to, so the conversation history of the other members stays intact. They are detached from your identity and retained for that channel's plan retention period. Channels you created are not deleted; ownership of them is released to your organisation. Support tickets you raised and diagnostic uploads from your devices are retained on the basis set out above.

Who we share your data with

We share personal data with the providers we use to run Vopway. Each processes it only on our instructions under a written data processing agreement. We name individual providers below wherever they receive the content of your communications or other sensitive data; for routine infrastructure we describe the category. A complete, current list of our sub-processors is available on request from privacy@vopway.com.

Providers that receive the content of your communications

  • Speech-to-text transcription — Groq, Inc. and OpenAI, L.L.C. (United States). When a push-to-talk voice message is transcribed on our servers, the audio file itself is sent to one of these providers, together with a language hint. This applies to voice messages in encrypted channels as well.
  • AI summaries and virtual agents — Anthropic PBC and OpenAI, L.L.C. (United States). Where AI Insight or a virtual agent is enabled for your organisation, message text, voice transcripts, sender display names, the channel name and timestamps are sent to these providers to generate the summary or reply.
  • Push notification delivery — Apple Inc. and Google LLC (United States). Notification payloads pass through Apple's and Google's notification services. Message and voice content stays encrypted in the payload; the sender's display name, the channel name and, for file messages, the attachment file name are readable, as explained under "Encryption, and what Vopway can access".

Live voice and video calls are relayed by a LiveKit media server that Vopway operates on its own infrastructure in the United Kingdom. Where a direct path cannot be established, a TURN relay operated by Twilio Inc. (United States) may carry the encrypted media stream.

Providers that receive other identifying data

  • Phone verification — Twilio Inc. (United States). Your mobile phone number, the one-time verification code and its delivery status.
  • Log storage and search — Grafana Labs. Application logs from our backend and diagnostic logs uploaded by the mobile apps. These entries carry user identifiers, organisation IDs, session identifiers, IP addresses and, in some email delivery logs, recipient email addresses.
  • Crash reporting — Google LLC, through Firebase Crashlytics (United States). Crash reports tagged with your user ID, your role and your organisation ID.

Infrastructure and business operations

  • Hosting and storage. Our application servers, database, cache and media server run on infrastructure in the United Kingdom. Our object storage, which holds media, attachments, voice recordings, diagnostic uploads and encrypted backups, is located in Germany. Our web and admin interfaces are hosted by a provider in the United States.
  • Content delivery, DNS and denial-of-service protection. Our network provider terminates TLS at its edge, so it processes request content in transit. It receives IP addresses and user agents.
  • Email delivery. Our email provider receives recipient email addresses and the content of account, verification and invitation emails.
  • Payments. Subscription purchases made on the web are processed by our payment provider, which receives your email address, billing details and invoice records. Purchases made inside the mobile apps are processed by Apple or Google, and we receive only a transaction identifier and your subscription status. We never receive or store your card number.
  • Maps. Our map providers receive your IP address and the map area you are viewing in order to serve map tiles. One of our map SDKs also transmits its own usage telemetry, including approximate location and device and session identifiers, to its provider.
  • Error monitoring. Our error monitoring provider receives exception messages, stack traces and internal record identifiers such as user, organisation and channel IDs. End-user personal data capture is disabled.

Some providers are used only where the corresponding feature is enabled for your organisation. We update this notice before adding a new category of recipient.

Data subject rights

You have the right to request access to your personal data, its rectification or erasure, restriction of processing, and portability of the data you provided to us, under Articles 15 to 20 of the GDPR. To exercise any of them, email privacy@vopway.com from your registered address, or use the account deletion flow in the app. We verify your identity before acting, respond within one month, and do not charge for requests.

Your right to object. You have the right to object at any time, on grounds relating to your particular situation, to processing we carry out on the basis of our legitimate interests. That includes our security audit logging, abuse prevention, crash reporting, diagnostics and call quality telemetry. To object, email privacy@vopway.com describing what you object to. We will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests.

Withdrawing consent. Where we rely on your consent, you may withdraw it at any time and withdrawing is as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before you withdrew. Location permission and contacts permission are withdrawn in your device settings; browser storage preferences are changed through the consent banner on the web app.

If your Vopway account was created by an employer or other organisation, requests about the content of your channels, your live location and your route history should be directed to that organisation, which is the controller for that data. We will assist them in responding to you.

Right to lodge a complaint

If you believe your data has been processed unlawfully, you may lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO). If you are resident in the EU, you may instead contact your local supervisory authority, for example the CNIL in France.

International data transfers

Vopway's application servers, database and LiveKit media server are located in the United Kingdom. Our object storage, which holds media, attachments, voice recordings, diagnostic uploads and encrypted backups, is located in Germany; that transfer is covered by the UK adequacy regulations for the EEA. Our map tile provider for free-plan accounts is located in Switzerland, which is covered by UK and EU adequacy decisions.

Several of the providers described above are based in the United States or operate global infrastructure, so your personal data is transferred outside the United Kingdom and the EEA. For those transfers we rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, and on Standard Contractual Clauses together with the UK International Data Transfer Addendum where it is not.

You can obtain details of the mechanism relied on for any individual provider, and a copy of the safeguards themselves, by emailing privacy@vopway.com.

Storage on your device

Web app. Vopway uses browser storage for authentication persistence, language and theme preferences, and invitation handoff. Authentication storage is strictly necessary for the service; you can accept or decline non-essential persistent storage through the consent banner.

Mobile apps. The Vopway apps store data on your device: your login session and encryption keys in the iOS Keychain or Android Keystore, your encrypted message-key backup, voice messages queued for upload, your app preferences, and local diagnostic log files. This storage is necessary to run the service and is protected by your device's own encryption. Uninstalling the app removes it. The mobile apps do not use a consent banner; the privacy controls available to you are your device's own permission settings.

Children

Vopway is a workplace communication tool and is not directed at children. You must be at least 16 years old to create a Vopway account. We do not knowingly collect personal data from anyone under that age. If we learn that we hold data about a child, we delete the account and its data promptly. If you believe a child has created an account, contact privacy@vopway.com.

Changes to this policy

We notify material changes to this policy in the app and by email at least 30 days before they take effect. Non-material changes are published with an updated effective date at the top of this page. Previous versions are available on request. Continuing to use Vopway after a change takes effect means you acknowledge the updated policy; where we rely on your consent for a specific processing activity, we will ask for that consent again separately.

Contact for GDPR requests

For privacy, erasure, export, or objection requests, contact privacy@vopway.com.