Legal

Privacy Policy

Last updated: 17 September 2026

This policy explains what personal data is collected when you use newremit.io, why, and the choices you have. The controller of this data is Vacaloca Labs sp. z o.o., Al. Jana Pawła II 27, 00-867 Warsaw, Poland (“NewRemit”, “we”, “us”); KRS 0001230895, NIP 5273211425, REGON 544326520, Share capital PLN 5,000. We keep this policy deliberately short: we collect little, we sell nothing, and we run no advertising trackers.

Registered in the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, XIII Commercial Division (Sąd Rejonowy dla m.st. Warszawy w Warszawie, XIII Wydział Gospodarczy Krajowego Rejestru Sądowego).

Data we collect

  • Account data. Email address, name (if you provide one), and a hashed password when you create an account. We never store your plain-text password.
  • Product data. Corridors you save and alert preferences you set, so we can send the alerts you asked for.
  • Messages. What you send through the contact form, the access request form (email, company, role, and your note), or by email, so we can reply.
  • Technical logs. Standard server logs (IP address, user agent, requested pages) kept for security and debugging.
  • Usage measurement and error diagnostics. Aggregate, cookieless page-view statistics, and technical error reports when something in our software fails (the error message, the page it occurred on, and browser details). Your IP address and user agent are processed transiently; no identifier is stored in your browser and individual visitors are not profiled.

Why we process it

  • To provide the service (contract): accounts, saved corridors, and email alerts.
  • To keep the service secure and improve it(legitimate interest): logs, aggregate cookieless usage measurement, and error diagnostics.
  • To respond to you (legitimate interest): messages you send through our forms or by email.
  • To meet legal obligations (legal obligation): keeping accounting records for as long as tax and accounting law requires.

Who processes data for us

We use a small set of vendors to run the service. Supabase (database and authentication, hosted in the EU), Resend (transactional and alert email), Vercel (hosting), and PostHog (EU-hosted, cookieless usage analytics and error diagnostics) act as our processors — they handle your data only on our instructions. Maps on our locations pages load only when you choose to load one; when you do, your browser requests map tiles from Mapbox, which receives your IP address in the process. We do this on the basis of our legitimate interest in displaying the maps you request. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the EU standard contractual clauses or an adequacy decision (including the EU–U.S. Data Privacy Framework, where the vendor is certified).

Personal data in our location dataset

Our platform includes a dataset of physical agent and payout locations compiled from publicly available sources, such as provider websites and public location directories. Where an agent operates as a sole trader, a location record (business name, address, and associated provider networks) may constitute personal data. We process this data on the basis of our legitimate interest in providing market intelligence about publicly operated payment locations. We collect only information that is already public and business-facing; we do not enrich it with private data about the individuals involved. If you operate a listed location and want to object to its inclusion or correct it, email hello@newremit.io and we will respond within one month as the GDPR requires.

What we don’t do

We do not sell personal data, we do not share it with advertisers, and we do not run third-party advertising or cross-site tracking of any kind. We also make no automated decisions about you that produce legal or similarly significant effects.

Retention

Account data is kept while your account exists and deleted when you ask us to close your account — email hello@newremit.io. Server logs are kept for up to 30 days and then deleted automatically. Anonymous usage statistics and error reports are held by our analytics provider (PostHog, EU region) for up to 7 years, then deleted.

Messages you send us — through the contact form, the access request form, or by email — are kept while we handle your inquiry and for up to 12 months afterwards, in case of follow-up questions, then deleted.

Your rights

Under the GDPR you can request access to, correction of, deletion of, or restriction of processing of your personal data, ask for a portable copy, object to processing based on legitimate interest, and withdraw consent at any time where processing is based on consent (none of our current processing is). You can also lodge a complaint with your local supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO). To exercise any of these rights, email hello@newremit.io.

Children

NewRemit is not directed at children under 16 and we do not knowingly collect their data.

Changes

If this policy changes materially, we will note the new date at the top of this page and, for significant changes affecting account holders, tell you by email.

Contact

Privacy questions: hello@newremit.io.