Legal

Privacy Policy

Last updated: 18 August 2026

This policy explains what personal data is collected when you use newremit.io, why, and the choices you have. The controller of this data is Vacaloca Labs sp. z o.o., Al. Jana Pawła II 27, 00-867 Warsaw, Poland (“NewRemit”, “we”, “us”); company registry identifiers are listed in the imprint on our About page. We keep this policy deliberately short: we collect little, we sell nothing, and we run no advertising trackers.

Data we collect

  • Account data. Email address, name (if you provide one), and a hashed password when you create an account. We never store your plain-text password.
  • Billing data. Payments are processed by Stripe. We do not receive or store card numbers — we store only your subscription status and a Stripe customer reference.
  • Product data. Corridors you save and alert preferences you set, so we can send the alerts you asked for.
  • Messages. What you send through the contact form, the early-access request form (email, company, role, and your note), or by email, so we can reply.
  • Technical logs. Standard server logs (IP address, user agent, requested pages) kept for security and debugging.
  • Usage measurement and error diagnostics. Aggregate, cookieless page-view statistics, and technical error reports when something in our software fails (the error message, the page it occurred on, and browser details). Your IP address and user agent are processed transiently; no identifier is stored in your browser and individual visitors are not profiled.

Why we process it

  • To provide the service (contract): accounts, subscriptions, saved corridors, and email alerts.
  • To keep the service secure and improve it(legitimate interest): logs, aggregate cookieless usage measurement, and error diagnostics.
  • To respond to you (legitimate interest, or steps prior to a contract for early-access requests): messages you send through our forms or by email.
  • To meet legal obligations (legal obligation): keeping billing and accounting records for as long as tax and accounting law requires.

Who processes data for us

We use a small set of vendors to run the service. Supabase (database and authentication, hosted in the EU), Resend (transactional and alert email), Vercel (hosting), and PostHog (EU-hosted, cookieless usage analytics and error diagnostics) act as our processors — they handle your data only on our instructions. Stripe processes your payment data as an independent controller for payment processing and fraud prevention, under its own privacy policy. When you open a map on our locations pages, your browser requests map tiles from Mapbox, which receives your IP address in the process. We do this on the basis of our legitimate interest in displaying the maps you request. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the EU standard contractual clauses or an adequacy decision (including the EU–U.S. Data Privacy Framework, where the vendor is certified).

Personal data in our location dataset

Our platform includes a dataset of physical agent and payout locations compiled from publicly available sources, such as provider websites and public location directories. Where an agent operates as a sole trader, a location record (business name, address, and associated provider networks) may constitute personal data. We process this data on the basis of our legitimate interest in providing market intelligence about publicly operated payment locations. We collect only information that is already public and business-facing; we do not enrich it with private data about the individuals involved. If you operate a listed location and want to object to its inclusion or correct it, email hello@newremit.io and we will respond within one month as the GDPR requires.

What we don’t do

We do not sell personal data, we do not share it with advertisers, and we do not run third-party advertising or cross-site tracking of any kind. We also make no automated decisions about you that produce legal or similarly significant effects.

Retention

Account data is kept while your account exists and deleted when you ask us to close your account — email hello@newremit.io. Billing records are kept as long as tax and accounting law requires. Server logs are kept for up to 30 days and then deleted automatically. Anonymous usage statistics and error reports are held by our analytics provider (PostHog, EU region) for up to 7 years, then deleted.

Messages you send us — through the contact form, the early-access request form, or by email — are kept while we handle your inquiry and for up to 12 months afterwards, in case of follow-up questions, then deleted.

Your rights

Under the GDPR you can request access to, correction of, deletion of, or restriction of processing of your personal data, ask for a portable copy, object to processing based on legitimate interest, and withdraw consent at any time where processing is based on consent (none of our current processing is). You can also lodge a complaint with your local supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO). To exercise any of these rights, email hello@newremit.io.

Children

NewRemit is not directed at children under 16 and we do not knowingly collect their data.

Changes

If this policy changes materially, we will note the new date at the top of this page and, for significant changes affecting account holders, tell you by email.

Contact

Privacy questions: hello@newremit.io.