Privacy policy
What vFound collects, why, who can see it, and what you can ask us to do about it. In effect from 8 October 2026.
What changed on 8 October 2026: sections 4, 5 and 6 no longer mention a stopped server that held archives from before our September 2026 move. That server has been deleted.
What changed on 7 October 2026: our service email is now sent through Resend, which section 4 names with what it receives. vFound now records whether each email it sends was delivered, without keeping the address, so a venue’s team can see when a notice did not reach someone; section 6 says this record is kept 90 days. Section 5 adds our email delivery provider to those that may process data in the United States.
What changed on 6 October 2026: vFound now records when each team member last signed in and when they were last active in the workspace (the time only, not the page, address or device). Section 3 describes it and says how long it is kept. Section 6 now says that a browser’s error reports are counted against the sender’s address for 24 hours under a one-way hash, without storing the address. Section 7 now describes signing in with a one-time link by email.
What changed on 5 October 2026: Ask vFound no longer takes spoken requests, so section 3 no longer describes voice input. Section 4 now names IndexNow, which receives the addresses of our public pages. Section 6 now says that a checkroom ticket left at closing is kept 12 months from that closing, and how long background tasks that could not finish and disconnected AI assistant connections are kept. It also describes the error reports vFound keeps to find and fix faults.
What changed on 4 October 2026: this page now says more completely what we already do. It describes email to inventory (the photos staff email to a venue’s private address, kept as drafts with the sender, subject and note, and deleted after 30 days), what vFound AI is and is not sent, the weekly insights and their Monday email, photo splitting and duplicate checks, how long what the AI wrote is kept, how long application logs are kept and that the server’s system journal is separate, every cookie and browser storage key we use, Cloudflare Turnstile as the only captcha provider, how long hotel stays and connector sync history are kept, and what stays after an account is closed. Drafts and AI results are now deleted automatically on the periods stated. A venue’s owner can take their venue out of a customer group at any time, and a platform administrator’s reads and refused changes of a customer’s records are now recorded in the audit log. When the team describes a lost checkroom ticket to vFound AI, ticket notes are no longer sent and email addresses are removed from the description.
What changed on 3 October 2026: this page now describes the minimal hotel stay context a venue can link to a found item or parcel, what it deliberately excludes, who can see it and when it is deleted. It also describes customer groups, regional access, aggregate command-centre counts, group policy settings and the 24-month retention of their audit history. An owner or manager can connect a Cloudbeds property API key limited to read-only reservation access, an OfficeRnD Flex application or a Microsoft Entra ID application. From Cloudbeds, vFound keeps only the reservation and optional guest references, guest name, arrival and departure, time zone, current room, reservation state and source timestamps needed for private stay context. From OfficeRnD and Entra, it keeps only the source ID, name, email and active status needed for the shared people list. It does not read Cloudbeds rates, payments, loyalty data, identity documents, preferences or unrelated notes; it does not read OfficeRnD memberships, bookings, invoices, payments, custom properties, addresses or phone numbers; and it does not use Entra to create vFound staff accounts, roles or access decisions. Customer-configured operating policies add permanent versions, local exceptions, acknowledgements and aggregate service-level alerts; these advanced controls remain off until a group manager configures them. When a person is deactivated, their private My vFound access and host browser alerts end and they cannot be selected for new work. Open parcels, equipment checkouts, reservations and visitor records remain available to the authorised venue team until they are resolved.
Analytics update on 2 October 2026: optional Google Analytics on public marketing pages now asks for consent, with equal accept and reject choices and withdrawal controls. Private product workflows are excluded.
What changed on 2 October 2026: a visitor type can optionally require a private visitor photo, use it on a printed badge and require staff to record a visual check of a physical photo ID. This page now states who can see the photo, what the check records, what is deliberately not stored or automated, and that both follow the visit retention period.
What changed on 1 October 2026: this page describes optional paid return shipping, its private addresses and labels, its payment records and its providers. It is offered only to enabled venues on reviewed routes. Enabling it requires the venue's separate agreement; no shipping details are sent to Easyship just because you have an account.
What changed on 28 September 2026: a signed My vFound link now works for 60 days, and earlier links stop working when a person’s email changes, when they are deactivated or removed, or when an owner or manager resets their link. A visitor pass shows arrival details once the visit is approved and Wi-Fi details only while you are signed in, and printed badges carry only a short desk code. A visitor type without its own retention period follows the venue’s, and anyone still signed in is signed out automatically after the day ends once they have been in for 12 hours. Checkroom tags on your things show only the ticket number. The private link to a lost-item report now works for 30 days, and the venue page can email a fresh one. Team members other than owners and managers see a masked email address for people on a venue’s people list. A host’s browser alerts about their visitors end when they leave the people list, including when a directory sync deactivates them. Hosts are no longer messaged through a connected Slack workspace, and any stored Slack connection records were deleted; Slack, Microsoft Teams and Google Chat channel alerts are unchanged. A Checkroom ticket can no longer be saved to a phone wallet app.
What changed on 26 September 2026: vFound Equipment now supports reservations, multi-item checkouts, borrower self-service and paired-kiosk checkout, plus asset, maintenance and stock-take records. vFound Checkroom now supports stations, events, an exit queue, printed tags, paired-kiosk self check-in and optional fee recording. This page now names those records and their retention.
What changed on 25 September 2026: this page now covers the vFound suite: vFound Parcels, the mailroom tool (what it keeps about the people a venue receives parcels for, that vFound AI can read a parcel's label, and that finished parcel records are deleted after 12 months), and vFound Checkroom, for coat check and luggage storage (what a ticket holds and how long it is kept), and vFound Equipment, for handing out equipment (what its records hold about a borrower, and that finished records are deleted after 13 months). Later the same day it added vFound Visitors, for visitor sign-in (what a visit record holds, who is told when you arrive, and how visit records were retained). Later still it added private calendar links for a venue’s team, Google Chat alerts, directory connections, each person’s signed My vFound page, and how long unused calendar links are kept. It now also covers visitor types and their questions, self-registration, approvals, multi-day passes, kiosks, roll calls, calendar invitations, host replies, couriers and a venue's visitor retention choice.
What is changing on 25 October 2026: anyone who turns them on can get vFound notifications in their browser. A venue that has agreed to the push services sooner (see the notice) offers them before that date. They are delivered by their browser’s own push service (Google, Apple, Mozilla or Microsoft), encrypted end to end so the push service cannot read them. A person chooses alerts separately in each browser, either while signed in, from a private pass or ticket, or from a signed link in their service email. Emails continue as before. The notice in our Data Processing Agreement has the details.
Also from 7 October 2026: a venue's lost and found page no longer offers a separate email alert. A lost report now does that job: it shows possible matches straight away and emails you each time a likely match is logged over the next 90 days. Alerts set before this date keep working as before until they are used, removed or 60 days old, as section 6 says. One form, "Check my claim or report", now sends a fresh private link to each of your claims and open reports at that venue when you give the email you used. A guest whose claim ends because the item was not collected is now told by email.
What changed on 24 September 2026: this page now names where our servers are (Singapore), our support mailbox (Google Workspace) and our own mail server; lists everything we hold for lost reports, alerts, pickups and returns; states how long each kind of record is kept; and describes our security, closed accounts and the tools venues use to correct, export and delete claim records. It no longer describes extra sign-in checks, the last of which we removed on 23 September 2026.
vFound is operated by Naltyx Data and Marketing Consulting (“Naltyx”, “we”), Ontario, Canada. We sell software to venues. We do not sell personal information, we run no advertising trackers, and we do not use your data or your guests’ data to train AI models.
1. Who is responsible for what
This distinction matters, so it comes first.
- We are the controller for venue account data, staff sign-in data, billing data and data from our public website, and for our own optional return-shipping transaction and fulfilment records. We decide how that is used. The venue continues to control the ownership claim and its decision to release an item.
- The venue is the controller for the found items it publishes, for claims made to it and, if it uses vFound Parcels, vFound Checkroom, vFound Equipment or vFound Visitors, for its parcel, checkroom, equipment and visit records. We are only its processor, acting on its instructions under our Data Processing Agreement.
So if you submitted a claim, the venue handling your item decides what happens to your information. Contact them first; we will help them respond.
2. What we collect
If you make a claim as a guest: your name, email address, optional phone number, where and when you think you lost the item, your description of it, your answers to the venue’s verification questions, any photos you upload as proof, and your messages with the venue. If your item is returned we also keep a shipping address if it is sent to you, or your name and, where the venue asks for one, your signature when you collect it, plus any pickup time you book and any feedback you give. We also record the internet (IP) address you submitted from and an approximate city and region derived from it, so the venue can weigh a claim before handing over someone’s belongings, and so we can detect abuse. We do not collect precise GPS location.
If you choose paid return shipping: we keep the recipient and dispatch names, addresses, email addresses and carrier phone numbers; packed weight and dimensions, description, used value, customs code and country of manufacture; your selected carrier, postage and service fee; payment, refund and dispute references and status; label and customs PDFs; tracking, dispatch and delivery state; and any change or cancellation request. Address, parcel and payment snapshots are encrypted in our database. PDFs stay in private storage and require authorised venue access; the guest page uses a signed link that expires after 30 days. Venue staff, our platform administrators, providers involved in delivery and protected backups can contain these details. They are never shown publicly.
If you report a lost item: your name, email address, optional phone number, what you lost, when and where, and any item-location link you add (such as an Apple Find My link). If you set an alert before 7 October 2026: your email address and what to watch for. New alerts are no longer offered; a lost report includes them.
If a venue receives parcels for you (vFound Parcels): your name, email address, room or apartment and any ID the venue adds to its list; and for each parcel, a photo of its label (showing whatever the label shows, such as your address), the carrier, tracking number and sender, handling instructions, where it is kept, any reminder snooze or hold date, whether you said you were at the desk, any delegate name and email you provide, the emails sent to you about it, and the name, optional pickup photo and, where the venue asks for one, the signature of whoever collected it. For an outgoing parcel or a delivery round, it also records the destination, courier or recipient and handover signature. Parcel records are never shown publicly: the venue’s team and our platform administrators can see them, and the AI provider below reads a label photo when the venue logs a parcel with vFound AI switched on. If the venue also uses vFound Visitors, the same list is who visitors can come to see, and you are emailed when a visitor signs in to see you.
If a hotel links a stay to an item or parcel: the hotel may store its stable stay reference, an optional guest reference, your name, arrival and departure times, source time zone, stay state, current room and the room recorded when the item or parcel was logged. This private context is visible to the venue team and our platform administrators, never on a guest page. A room search helps staff navigate only; vFound never treats a room number as proof or a suggestion of ownership. The feature does not accept rates, payment details, loyalty data, identity documents, preferences or unrelated reservation notes. The hotel can enter this context manually, import it by CSV or API, or connect its own Cloudbeds property key limited toread:reservation. Connection credentials and the sync cursor are encrypted, and the hotel can revoke access in Cloudbeds or vFound.
If you leave things at a venue's checkroom (vFound Checkroom): what you handed in and a photo of it, its number and, for a multi-piece ticket, each piece's letter, type, storage location and hand-back state; and, if you give them, your name, email address and room; the language of your ticket; its station, event and storage location; a request to have your things ready; any fee and whether the venue records it as cash or an external POS or card payment; when each piece was collected, and who collected it, with a signature when the ticket was lost. Your ticket is a private page whose long random address is the only key to it. Tags on your things show only the ticket and piece number, type, station and, on a bag tag, where it is stored; they never show your name, email address or room. The ticket’s QR code is printed only on the stub you keep. Checkroom records are never shown publicly: the venue’s team and our platform administrators can see them. If your things are still there at closing, the venue may move them to its lost and found, with your details in its private notes so it can contact you. If you lose your ticket and the team uses vFound AI to find your things from a description, the AI provider below compares that description (with email addresses, links and phone numbers removed) with the photos and the type of that night's checked-in items. Ticket notes and the name, email address and room on any ticket are never sent, and the team still checks who you are before handing anything back.
If you borrow something from a venue's desk (vFound Equipment): your name and, if you give them, your email address and an ID or reference such as a student number, room or department; what you borrowed, when, and when it is due back; the emails sent to you about it (a receipt, reminders, reservation notices and a return receipt, with one receipt for things from the same checkout brought back together), in the language chosen for you; your signature where the venue asks for one; any reservation you make, whether it needed approval, its dates and status; an extension request or problem report you send; and when each item came back, in what condition, with any note or photo the team takes. An equipment item can also hold a serial number, replacement value, purchase and warranty dates, venue-defined custom fields, maintenance history and stock-take dates. These records are never shown publicly: the venue’s team and our platform administrators can see them. The AI provider below only ever sees a photo of the equipment a venue adds, never who borrowed it. When authorised venues in one customer group move an item, vFound also records its owning, source, destination, service and custody venues, locations and codes, transfer status and times, operational notes and which team members performed each step. Borrower and staff history from the source venue is not shown to the destination through the transfer.
If you visit a venue that uses vFound Visitors: your name, who you came to see and when you arrived and left (including whether you were signed out automatically); if you or the venue give them, your email address, company and the reason for your visit, your answers to questions the venue sets, a time you are expected, the dates your pass is valid and whether it repeats; the language of your emails and the invitation sent to you; whether the venue approved or denied the visit; any short reply your host sends to the desk; and, where the venue has visitor terms, a copy of them, that you agreed, and your signature where the venue asks for one. During a roll call the venue also records whether it marked you safe or missing, when, and which team member did it. Your pass is a private page whose long random address is the only key to it. Once the venue has approved the visit it may show arrival information the venue chooses to share, and the venue’s Wi-Fi details while you are signed in. Printed badges carry only a short desk code, never the pass address. A venue can optionally require a private visitor photo, which its authorised team and our platform administrators can see and which can appear on the printed badge. A venue can also require a staff member to record that they visually checked a physical photo ID; we keep who checked it and when, but no image or number from the ID. vFound does not verify document authenticity, compare faces or run a watch list, and visitor photos are not sent to vFound AI. If the venue’s team pastes or forwards a meeting invite with vFound AI switched on, the AI provider below reads it to suggest the expected visits (names, email addresses, companies, host and time), with links, passcodes, phone numbers and place lines removed first; the team checks each visit before it is created. An invite forwarded by email is kept for up to 30 days. Visit records are never shown publicly: the venue’s team and our platform administrators can see them. The visit, its optional photo and its staff check record follow the same 7 to 365 day retention chosen by the venue or visitor type. When you sign in, the person you came to see is emailed your name and, if given, your company and reason. A Slack, Microsoft Teams or Google Chat channel the venue connects is told only the name of the person you came to see.
If a venue creates visits from calendar invitations: we receive the organizer and attendee names and email addresses, the meeting identifier, sequence and times. We discard the meeting description. The pending invitation details are encrypted in our database. If the sending mail server cannot be verified, no visitor is emailed until the organizer confirms a signed link, and a change to an invitation already confirmed is kept apart, unused, until then.
If you run a venue: your name, work email, business name, venue code, password (stored only as a hash), team members you add, your chosen workspace language, the address guest replies should go to, and your activity in the workspace (including an audit record of security-relevant actions such as sign-ins, staff changes and claim decisions).
When a team member signs in or uses the workspace, we record the time (not the page, address or device) so we can see how venues use vFound, support them and improve the service; only vFound's platform administrators see it. The last sign-in time and the last activity time are kept for as long as the person's account exists, and go when the account is deleted. They belong to the person, so for someone who works at several venues they reflect their activity across all of them.
If your organisation groups several venues: we keep the group name, the venues and optional region assigned to each one, group members and their group or regional roles, group policy templates, and an audit history of group, access, venue and policy changes. The command centre returns aggregate operational counts and account health for venues within that person's group and region. A person receives record details only after opening a venue they are authorised to use.
If a group configures operating policies: we keep the policy name, permanent numbered versions, their rules and service-level targets, venue assignments, local exception reasons and optional expiry dates, acknowledgements, aggregate breach counts and alert-notification times. Reports and escalation emails contain counts, policy and venue names, not claimant, visitor, parcel or other operational record details. Assignment and escalation notices go to active group owners and managers who are authorised for the affected venue; a regional manager receives them only for their region. Replies go to the group manager who performed the assignment or the group owner. These records do not make operational decisions or change payment access.
Items your team logs: photographs, descriptions, storage location, internal notes and return records. Photographs and descriptions your team publishes are public on your venue page; internal notes and claimant details never are.
If your venue uses email to inventory: each venue has a private address that its own team can email or forward photos to. Only mail that a team member’s own mail system really sent is accepted; mail from anyone else is dropped and not kept. For each accepted photo we keep a draft with the photo (saved again without the location or other details the phone added), the sender’s email address, the subject and the first 500 characters of the message, until someone logs or discards it. The photo file is deleted as soon as the draft is logged or discarded, and with vFound AI on, the AI provider below reads the photo to suggest a description. Every draft, with its sender, subject and note, is deleted 30 days after it arrived, whether or not it was logged.
If a venue connects its people directory: we receive the name, email, room or department, reference, language, active status and external identifier the venue sends. A CSV link is encrypted in our database; we also keep its host, sync mode, last run time and row counts. Automatic provisioning creates people-list entries only, never staff accounts. A person’s signed My vFound link shows only parcel, visitor-host and equipment records linked to that person. Anyone with the link can open it, so it should be kept private. Each link works for 60 days, and each new service email carries a fresh one. Earlier links stop working when the person’s email changes, when they are deactivated or removed, or when an owner or manager resets their link. A venue’s owners and managers see each person’s full email address; other team members see it masked. Deactivation also stops new records from being assigned to that person. It does not erase open operational records; owners and managers can review their counts until the venue resolves them.
Card validation and payments: Stripe validates the card for a trial and handles vFound subscription billing. We store the customer, Checkout and subscription or payment references, amounts and status, not your full card number. A venue may record that it collected a Checkroom fee as cash or through its own external POS or card terminal, but vFound receives no guest payment or card details.
Technical: application logs of errors and events, which can include an IP address and the page requested, kept to keep the service running and secure. Our web server keeps no access log. A paired kiosk (for visitor sign-in, parcel arrivals, equipment self check-out or checkroom self check-in) keeps a random, encrypted token in an essential cookie and we keep its venue, device name, permitted actions and last-seen time. The kiosk never stores a people list in the browser.
If you turn on browser alerts: the browser’s push address, public encryption key and authentication token, its stated expiry (if any), recent delivery result, and the account, pass, ticket or service-email record that authorised it. The address and keys are encrypted in our database. We do not receive a device identifier, contact list or the other sites you visit.
Optional public website analytics
If you accept analytics on our public marketing website, Google Analytics receives the public page path, language, broad traffic and device information, an analytics cookie identifier and clicks on trial and demo links. Google receives your network address when your browser contacts it. We strip URL query strings and fragments, send only the origin of the referring website, and send no form answers, names, emails, account IDs or private record links. Analytics is excluded from signed-in pages, venue websites, registration, claims, guest passes, kiosks and administration. A trial-link click measures interest, not a completed signup or a paid subscription.
3. Why we use it, and our legal basis
- To provide the service: publishing items, routing claims, sending service email, taking payment. Basis: performance of a contract.
- To keep it secure: bot protection, rate limiting, fraud and abuse detection, audit logs, backups. Basis: legitimate interests in protecting our service, our venues and their guests.
- To help a venue assess a claim: including the submitting IP address and approximate city. Basis: the venue’s legitimate interest in not handing property to the wrong person.
- To meet legal duties: accounting and responding to lawful requests. Basis: legal obligation.
- To answer your enquiries. Basis: legitimate interests, or consent where you gave it.
- To send optional browser alerts you request. Basis: your consent, which you withdraw by turning them off on that device. Email continues independently.
We do not carry out facial recognition or biometric identification, and we never identify a person from an image. When a venue uses vFound AI, it compares descriptions and photos of items, never of people, to suggest possible matches and to help staff check a claim. These are suggestions only: we make no decisions about you by automated means that produce legal or similarly significant effects, and a person at the venue decides every claim. Nothing vFound AI suggests is applied to a record or sent to a guest until a person at the venue confirms it. The suggestions themselves are kept so the team can see them again: item descriptions and search words, match verdicts for lost reports, claim checks, weekly insights and the wording of the daily summary. See section 6 for how long.
To improve our public website and understand demand:optional analytics uses your consent. Rejecting it does not affect the service. You can withdraw through Analytics preferences on a public page.
4. Who we share it with
Your claim is visible to authorised staff at the venue handling your item, and to our platform administrators who operate and support vFound. If the venue connects other services, such as Slack, Microsoft Teams, Google Chat or its own systems through our API and webhooks, the details that service receives go there on the venue’s instruction. A member of the venue’s team can also add a private calendar link to the calendar app they choose; that app then reads upcoming visits, equipment due times, luggage collection times and booked pickups, including the names shown with them. A directory, published CSV or hotel property system a venue connects is chosen and controlled by that venue; it is not our service provider. Property-system and coworking-member connections store their credentials and settings encrypted and read only the minimal stay or member context described below. The same is true of an AI assistant a venue owner or manager connects to vFound by signing in (for example through its connector for our MCP server): it receives the records its tools return, only within the permissions the venue chose and for the products the venue has open, and its provider handles them under the venue’s own agreement with it. We keep a record of each connection (the assistant’s name, the address it returns to, who connected it and when it was allowed, renewed and disconnected) and store only fingerprints of its codes and tokens. Beyond that we share data only with the providers below, for the purposes shown:
- OVHcloud: hosting of the application, database and uploaded files, in Singapore. Photos a venue’s team emails to vFound arrive at our own mail server on this hosting.
- Resend: sends our service email, such as claim, parcel, visitor and account emails, from 7 October 2026. It receives each email’s recipient address, subject and content, and tells us whether the email was delivered, bounced or marked as spam. It processes data in the United States.
- Stripe: trial card validation, vFound subscription payments, optional one-time return-shipping payments and refunds, payment contact details and receipts. We store payment references and status, not full card numbers.
- Cloudflare: Turnstile bot protection on every public form that asks for it: sign-in, registration, password reset, contact, claims, claim and report lookup, lost reports, photo search, the lost-item chat, checkroom self check-in, visitor self sign-in and visitor registration.
- ipapi.co: converting a submitting IP address into an approximate city and region. Private and internal addresses are never sent.
- OpenRouter (OpenRouter, Inc.): an AI gateway used when a venue keeps AI assistance switched on: to read a found item's photo and suggest its details and search words; to read a parcel's label photo and suggest who it is for, the carrier and the tracking number; to suggest a name for equipment a venue adds, from its photo; to compare what a guest describes, and any photo they choose to add, with found items to rank possible matches; to help the venue's team check a claim against their record of the item, including its private description and internal notes, and any proof photos the claimant uploaded; to translate messages between guests and the team and draft the team's replies; and to turn a guest's lost item chat into a report; to turn what a team member types in Ask vFound into a suggested action (phone numbers are removed first, and the records it finds are never sent); to tell whether a photo taken with the workspace camera shows a found item or a parcel label and read it (QR codes and barcodes are read on the device and not sent); to read a meeting invite the venue pastes or forwards and suggest the expected visits; to compare a description of a checkroom item with that night's item photos and item types, never ticket notes or a guest's name, email address or room; to cut a photo that shows several items into one photo per item; to compare a newly logged item's photo and description with up to three earlier items to flag a possible duplicate; to word the daily summary on the workspace home page and the checkroom's end of night summary, from counts only, never names; and to write a weekly read of the venue's numbers, from the venue's name and aggregate counts, rates, item categories and the places guests said they lost things, never a guest's name or contact details. That weekly read is shown on the dashboard and emailed every Monday to the venue's owners and managers unless the venue switches the email off. A guest's search photo is used for that one search and not kept by vFound. Photos of items already flagged as showing personal details (an ID, a card, a lit screen) are not sent again, and an answer to a verification question that asks for a passcode, password, PIN, phone number, address, date of birth or full name is not sent: the AI is only told that an answer was given. Proof photos a claimant uploads are the exception: when AI is on for the venue they are sent as supplied, because nothing can tell what they show first, so please do not upload identity documents or cards. The lost item chat never asks for a guest's name or contact details, and the form that collects them is not sent to the AI. AI suggestions never decide a claim: the venue's team makes every decision. OpenRouter passes the request to the AI model's provider: Google, with an OpenAI model as a backup run by OpenAI or Microsoft Azure. Every request asks for zero data retention, so it only reaches a provider that keeps no copy and does not use it to train models, and OpenRouter itself keeps no copy of the content and does not train on it. These providers may process the request in the United States or other countries. Venues can switch AI off at any time.
- Google (Google Workspace): our support mailbox, armaan@vfound.io, which receives the messages and requests people send us, and our own notices about venue accounts: sign-ups, trials, payments, cancellations and closures.
- IndexNow (used by Bing and other search engines): the addresses of our public pages and venue pages listed in our sitemap, when they are new or changed, so search engines find them sooner. Only those public addresses are sent, nothing from private records.
Optional shipping providers: only after a venue separately agrees and a guest requests delivery, Easyship receives dispatch and recipient contact details, addresses, parcel measurements, item description and customs details to obtain options, buy the label and track delivery. The chosen carrier and relevant customs authorities receive the details needed to deliver it. Your selected carrier is shown before payment. We do not send claim messages, proof photos or internal ownership notes to the shipping provider. Shipping providers may process delivery and transaction data in origin, destination and other service countries; their own shipping and legal-retention obligations can apply. The service is not enabled on a route until its provider terms, permissions and relevant transfer arrangements have been reviewed.
We may also disclose data where the law requires it, to protect our rights or someone’s safety, or to a buyer as part of a merger or sale of assets (you would be told beforehand). We never sell personal information.
Google Analytics: consented public marketing measurements only, under Google's analytics processing terms. Advertising personalisation, Google signals and user-provided data collection are disabled. Google may process this information in the United States and other countries. It is separate from the records we process for a venue under our DPA.
5. Where your data is held
Our application, database and uploaded files are hosted by OVHcloud in Singapore. An encrypted copy of our backups is kept in Canada, where we are based. Our AI, payment, bot protection, email delivery and support email providers may process data in the United States and elsewhere. Where personal data is transferred out of the EEA or the UK, we rely on an adequacy decision where one applies (such as for Canada), or on Standard Contractual Clauses (with the UK Addendum where relevant) together with appropriate safeguards.
6. How long we keep it
- Items and claims: for as long as the venue keeps them, under the retention and disposal policy the venue sets. Items expire from public view on the venue’s schedule. A venue can delete a guest’s details from a finished claim at any time.
- Parcels: while a parcel waits, and for 12 months after it is collected or returned; then the record, its label photo, pickup photo and any signatures are deleted. Finished outgoing parcels follow the same 12-month period. Expired delegate codes and served desk-arrival rows are deleted after 30 days. A venue can remove a person from its list at any time, which also removes their name from parcels already collected or returned.
- People and directory settings: a venue keeps people until it removes or deactivates them. Connected-directory details and people-list entries are deleted with the venue account after the 90-day closure period. Removing or deactivating a person, changing their email or resetting their link immediately invalidates their earlier My vFound links, and each link expires after 60 days. Open parcels, equipment checkouts, reservations and visitor records keep their normal retention periods and remain available to the authorised venue team for resolution.
- Checkroom tickets: deleted, with their piece records, hand-back proofs, photo and any signatures, 90 days after all the things are handed back; a ticket left at closing is kept 12 months from that closing. A self check-in nobody handed anything over for is deleted after two days. An event is deleted 12 months after it ends once no ticket refers to it. Station names, number ranges and storage locations stay until the venue deletes them or closes its account.
- Equipment: while the item is out, and for 13 months after it comes back or is marked lost; then the record, any photo taken on its return and any signature are deleted. Collected or cancelled reservations and completed stock-takes are also deleted after 13 months. Completed equipment-transfer records, including their venue, custody, location, status and note history, are deleted after 24 months. The items a venue hands out, with their photos, asset details and maintenance history, stay until the venue closes its account.
- Hotel stays: a stay with no linked item or parcel is deleted 13 months after its last known date (its departure, or if it has none its arrival, or if it has none the time it was last updated), whether or not the source ever marked it departed or cancelled. If an item or parcel still refers to it, its minimal context follows that record and is removed after the record no longer needs it. All remaining stay context is deleted with the venue account after the 90-day closure period.
- Visits: the venue chooses 7 to 365 days for the venue, with 365 days as the default, and may set a different period for a visitor type; a type without its own period follows the venue’s. That period starts when the visit ends (you are signed out, or an invitation is cancelled or not used); then the visit, its optional visitor photo, its staff visual-check record, its sessions, roll-call entries, courier link and any signature are deleted. Calendar invitation details with no visit are deleted after 30 days. Anyone still signed in after the day ends, in the venue’s time zone, is signed out automatically once they have been signed in for 12 hours.
- Lost reports: watched for 90 days, then kept with the venue’s records. Alerts (set before 7 October 2026; no new ones are made): 60 days from the day they were set, then deleted 30 days after they end.
- Customer groups: active group membership, venue-region mappings and policy templates remain while the group is active. Group activity records are deleted after 24 months. Closing a group removes group access immediately; its remaining membership, venue mapping, operating-policy versions, assignments, exceptions, acknowledgements and alert and completed equipment-transfer records are deleted 24 months later. A venue’s owner can take their venue out of a group at any time, which ends group access to it at once. Removing a venue from a group stops its policy assignments, exceptions and open alerts. Removing a venue or closing the group does not delete that venue's account or operational records.
- After an account is closed: the venue’s owners and managers can still sign in for 90 days to download the exports listed in the Data Processing Agreement, or ask us to reopen it. After 90 days we permanently delete the venue’s data, except billing records, the venue code, which stays reserved so a printed QR sign can never lead to someone else’s venue, and the sign-in of an owner who still has another venue (kept with this venue’s details emptied, and deleted when that other venue is deleted); copies in backups are deleted within 30 days after that.
- Paid return shipping: local address and parcel snapshots, payment snapshots and private label PDFs are removed 12 months after delivery or cancellation, or after dispatch if no final delivery callback arrives. They can be removed sooner with a finished claim or the venue account. Unsettled payments, refunds or disputes need resolution before deletion. Minimal transaction references, currencies, amounts and ledger entries are retained for six years after completion for accounting. Processed shipping callbacks are removed after 30 days. This local erasure does not erase a provider's or carrier's separately retained transaction records; we assist with provider requests where appropriate.
- Billing records: kept as long as applicable Canadian law requires, normally six years.
- Connector sync history: when a venue connects a hotel property system or a people directory, the time, outcome, counts and any error message of each sync run are deleted 90 days after the run.
- What vFound AI wrote for the team: item descriptions and search words, match verdicts for lost reports and weekly insights are deleted 13 months after they were written, like the records of AI use; the wording of the daily summary is deleted after 30 days. A claim check is kept with its claim and is deleted when the guest’s details on that claim are deleted or when the venue’s data is deleted.
- Whether an email was delivered: for each email we send, whether it was delivered, bounced or marked as spam, with the provider’s reason (any email or IP address removed), the recipient’s domain and a one-way hash of the address, never the address itself; deleted 90 days after the email was sent, or sooner with the venue’s data.
- Photos emailed to a venue’s address: the draft, its sender, subject, note and photo are deleted 30 days after they arrive, logged or not; the photo file goes sooner, as soon as the draft is logged or discarded.
- Logs: the logs our application, PHP and mail server write 7 days (the server’s system journal, which records service start and stop messages, is kept by the operating system under its own limits and is not part of that 7 days); the audit record of security-relevant actions 24 months; records of AI use 13 months; meeting invites forwarded to vFound Visitors 30 days; encrypted copies of the webhook deliveries a venue sends to its own systems 30 days; answers kept so an API request can be retried safely 24 hours; background tasks that could not finish, with the details they were working on, 30 days; the record of an AI assistant connection 90 days after it is disconnected; error reports 90 days after the error was last seen. An error report records a fault in vFound itself (on our server or in vFound’s own code in a browser): its type, where in our code it happened, the page’s address with any record numbers removed, and how often it happened. Before a report is stored, email addresses, numbers, codes and any quoted text are removed from its error message, and a database error keeps only the database’s reason, not the values being saved. It does not read what was submitted or your account. A report sent by a browser is counted against its sender’s address for 24 hours, so one sender cannot flood the reports; that count is kept under a keyed one-way hash and the address itself is never stored with a report. A plain-language reading of each new report, from the same AI providers named in section 4, is added for the owner. A private calendar link stops working when its owner replaces or removes it or leaves the team, and is deleted after 180 days without use.
- Browser alert addresses: until you turn alerts off on that device, the browser expires the address, the account or private record that authorised it is deleted, a host’s My vFound link is reset, their email changes or they are deactivated or removed (for alerts about their visitors), or delivery keeps failing. A failed address is deleted after 30 days. Access to the related venue and product is checked again before every alert.
- Backups: daily backups are kept for 30 days, so deleted data can remain in them for up to 30 days. Archives made when we moved vFound to new servers in September 2026, on our server, are kept only in case the move has to be undone, and are deleted once we confirm it is complete.
Website analytics: identifiable event and user data retention is set to 14 months without extending it on new activity. This setting does not delete Google's aggregate reports. Consent choices are remembered in local browser storage for 180 days. Analytics cookies expire after 180 days without renewal by our tag configuration; withdrawal removes them from this browser and stops further collection, but does not erase earlier reports.
7. How we protect it
Traffic is encrypted with HTTPS. Passwords are stored only as salted hashes, and sign-in is rate limited. Instead of the password, a person can ask for a one-time sign-in link by email: it works once, for 15 minutes, only on the address where it was asked for, and to check it we keep only a one-way hash, deleted 24 hours after the link is used or expires. Access is restricted to those who need it: every request is checked against the person’s venue or customer-group membership, group access is narrowed to an assigned region when applicable, every record query is limited to an authorised venue, and automated tests check that one venue or region cannot reach another’s records. Group summaries and downloads contain counts and venue settings, not item, claimant, visitor, borrower or parcel details. Security-relevant actions are recorded in an audit log, including the reads and refused changes a platform administrator makes while supporting a customer (the page and who, never the content). Directory CSV links are encrypted in the database, every redirect is checked again and downloads are limited to public HTTPS addresses and 10 MB. Daily backups are kept on our server with access limited to administrators, an encrypted copy is kept off the server, and restores are rehearsed. Public forms are protected against automated abuse. No system is perfectly secure, but if a breach affects your personal data we will notify the relevant supervisory authority and affected people as the law requires and without undue delay.
8. Cookies
We use essential cookies: vfound_token keeps you signed in for a limited time; vfound_session and XSRF-TOKEN protect forms against forgery and last two hours; vfound_lang remembers the language you pick on public and guest pages for a year. Your workspace language is also saved on your account and remembered in a separate language cookie, vfound_ui_lang, for a year. A paired visitor kiosk, which a venue can allow to sign visitors in and out, record parcel arrivals, hand out equipment for self check-out and take in coats and bags for self check-in, also uses one essential, revocable cookie, vfound_kiosk, for up to 400 days, renewed when the kiosk is used.
We also keep a few things in your browser’s own storage, which is not a cookie. Local storage stays until you clear it: vfound_legal_seen remembers that you dismissed the notice of an updated legal page, vfound_analytics_consent_v1 your analytics choice (for 180 days), vfound_sessions and vfound_install_hint how many visits you have made and whether the install hint was shown, and vfound_label_format the label size a team member chose. Session storage is cleared when you close the tab: vfound_venue remembers which venue you are working in, vfound_session_counted that this visit was counted, vfound_fab_closed that you closed the trial prompt, and vf-workspace-reload stops the workspace reloading itself twice for your language.
Optional Google Analytics cookies are used only after you accept analytics on the public marketing website. Accept and reject are equally available. Use Analytics preferences on a public page to change your choice. We do not enable advertising cookies or advertising personalisation.
9. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its use, receive it in a portable format, withdraw consent, and not be discriminated against for exercising these rights.
If your data relates to a claim, contact the venue handling it: the venue can correct, export or delete a guest’s details in vFound itself, and we will assist them. Otherwise write to armaan@vfound.io. We respond within 30 days and may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
You can also complain to a regulator: the Office of the Privacy Commissioner of Canada, or in the EEA/UK your local supervisory authority or the UK Information Commissioner’s Office. We would rather you raise it with us first.
10. Children
vFound is not intended for children. Venue accounts are for adults acting for a business. We do not knowingly collect data from a child; if you believe a child’s data has reached us through a claim, contact us and we will work with the venue to remove it.
11. A note for guests making a claim
Treat the private claim link we email you like a password: anyone with it can see that claim. Do not send passwords, card numbers or identity documents through a claim message or a general enquiry. Submitting a claim does not confirm ownership; the venue decides. The private link to a lost-item report works for 30 days; every email about the report carries a fresh one, and while the report is open the venue page can email a new one to the address it was made with.
12. Changes and contact
If we make a material change we will update the date above and tell account holders by email or in the product. The previous version, dated 4 October 2026, is available on request. For any privacy question or request, email armaan@vfound.io, or use our contact page. See also our Terms of service and Data Processing Agreement.
