Vanteloq logo™VanteloqLEGAL CENTRE
Legal centrePrivacyTermsCookiesData processing
Back to Vanteloq

PRIVACY POLICY

Your information should have a clear purpose.

This policy explains what Vanteloq handles, why it is needed, and the choices available to account holders and other individuals.
Last updated
September 16, 2026
Operator
LexEdge Consulting, operating as Vanteloq
Plain language, visible limits, real contacts.

These documents describe the service as it operates today. They do not claim certifications, providers, or rights that have not been verified.

LEGAL DOCUMENTSPrivacy PolicyTerms of ServiceCookie NoticeData Processing AddendumSubprocessorsLegal Centre

1. Scope and accountability

This Privacy Policy applies when you visit vanteloq.com, create or use a Vanteloq account, administer a workspace, connect a supported service, submit a form, or contact us.

LexEdge Consulting, operating as Vanteloq, is responsible for personal information under its control. The privacy contact is the Vanteloq Privacy Officer through our private contact form.

Vanteloq follows Alberta’s Personal Information Protection Act and Canada’s Personal Information Protection and Electronic Documents Act where each law applies.

2. Information we collect

Account and workspace information

We collect information you provide, such as your name, email address, password credentials handled by the authentication provider, business name, legal name, business contact details, role, location information, operating hours, and workspace settings.

Connected business information

Manual payroll accounting entries may contain aggregate wage costs, employer costs, payroll liabilities, and a reference to a customer-approved payroll report. The payroll screen does not connect to a payroll provider or collect employee bank instructions. Customers must limit entries to necessary accounting information and provide employees with any notices or other protections required for their use of the service.

When an authorized workspace user connects a supported provider or imports records, Vanteloq may receive sales, payment, refund, product, inventory, customer, supplier, location, purchasing, finance, and operational records. The exact fields depend on the source, the permissions granted, and the import selected by the user.

Google and Meta connections

After resource approval, detailed marketing reports may retrieve website traffic by channel, page and device; Search Console queries, pages, clicks, impressions and average positions; local Business Profile discovery measures and monthly search terms; and paid campaign measurements from Google Ads or Meta. Detailed report responses are not cached in Vanteloq's database. They are visible only within the user's permitted workspace and location scope. Refreshing a report does not change a campaign, publish content or grant new provider permissions. Meta paid-ad reporting does not include organic Facebook Page or Instagram insights.

A Google or Meta connection remains unavailable for measurement until an authorized user selects the exact eligible account, property, or owned business location, assigns it organization-wide or to an owned workspace location, and approves a warning-free sample. Vanteloq may retain encrypted authorization credentials while the connection is active, the selected provider and resource identifiers, the chosen workspace scope, connection and sync status, and derived daily measurements with source and freshness details. We use that information only to provide the connected reporting and operational features requested by the workspace.

For a selected Google Business Profile location, an authorized user may request the current review response queue. Review text, ratings, reviewer details, and reply content are fetched directly from Google for that request, are sent with a no-store response, and are not inserted into Vanteloq's database or aggregated into a customer profile. Vanteloq sends a reply to Google only after a user with marketing-management permission enters the reply and provides a separate, specific confirmation. Google remains the system of record for the review and reply.

Connected financial account information

When an authorized workspace owner chooses a bank connection, Vanteloq may use Plaid as a service provider to connect selected business accounts. Depending on the connection and consent shown, Vanteloq may receive account and institution names, masked account identifiers, account type, balances, transactions, transaction descriptions, pending or posted status, currency, provider item and account identifiers, and connection or sync status.

Bank sign-in information entered in Plaid Link is handled by Plaid and the financial institution. Vanteloq does not receive the online banking credentials entered in that flow. When a Plaid connection is configured and an authorized workspace user completes the provider consent flow, the connection uses only the read-only data products disclosed in that flow and does not allow Vanteloq to move money. We use connected records for bookkeeping review, reconciliation, supported cash context, connection support, security, and audit evidence.

QuickBooks Online connection

When an owner or administrator chooses to connect QuickBooks Online, Vanteloq records the selected company identifier, company name, authorization status, encrypted refreshable credentials, and security or audit metadata. The current sandbox stage verifies the selected company but does not import ledger records or enable dashboard calculations. Before a future accounting import is enabled, Vanteloq will identify the accounting records requested, the mapping and reconciliation controls, and any additional review required.

Vanteloq AI information

AI data-use notice update, September 16, 2026: Vanteloq AI handles business questions and app guidance in one conversation. With Workspace data enabled in AI Settings, answers may use permitted organization-wide BookLoQ ledger and cash summaries. Historical cash totals may include reviewed bank statement imports, with their reporting dates. Demonstration records, original documents and transaction descriptions are excluded. These are kept separate from dated retail KPIs; raw ledger records and identities are not attached. With Workspace data disabled, only your question, product guidance and optional matching history are attached. Workspace records are excluded. Changing this setting starts a new chat. A saved, current agreement must cover the selected data use before a request can be sent.

When Workspace data is enabled and an authorized user accepts the current data-use notice and asks Vanteloq AI a question, Vanteloq sends OpenAI the question, product guidance, dated aggregate sales, profit, units, labour, inventory-value and accounts-payable metrics where the user has the corresponding permission, connected-source status and freshness, and permitted aggregate cash context. Users with marketing access may also include synchronized traffic, search and advertising totals from their approved sources, with reporting periods and data-coverage limits. Search queries, page addresses, Google Business Profile content, advertising amounts without verified currency, raw provider credentials, full account numbers, customer names, invoice or receipt files, and raw transaction records are excluded from the automated evidence summary. Do not include personal information or secrets in your question.

Up to six recent conversation messages may be included only when their saved evidence and access context match the current request. When permissions, source evidence or location scope change, earlier messages are not forwarded as context. Changing the selected provider also prevents earlier messages from being forwarded.

When conversation memory is enabled, Vanteloq stores the question, the generated explanation, a limited evidence summary, the model identifier, and conversation timestamps so the authorized user can continue the conversation. With memory off, new questions and replies are not saved in the Vanteloq chat database. Advisor records are scoped to that user and workspace.

Uploaded bank statements, invoices, receipts, and other documents

Bank statements can supply historical bank movements after an authorized reviewer checks the account, dates, rows and opening-to-closing balance. Vanteloq retains the original document and import history. These imports do not automatically post journals, establish accounting profit or confirm today's available balance. Statement activity is withheld from combined cash reporting while an approved Plaid feed is active to avoid duplicate counting. Optional AI analysis receives only permitted dated aggregates under the current AI data-use agreement.

When available, an authorized owner or administrator with BookLoQ can separately enable a private document forwarding address after accepting its storage notice. Cloudflare Email Routing processes incoming messages, and an Email Worker sends supported attachments to Vanteloq's private quarantine. Vanteloq records the unverified sender address, receipt time and duplicate-check references, but does not keep the email body. The address can be replaced or disabled. Forwarding does not authenticate the sender as a Vanteloq user and never starts scanning, extraction, AI analysis or accounting posting. Those actions retain their separate permissions and review steps.

Forwarded originals follow the same document retention and deletion controls as uploaded originals. Deleting an original removes its sender address from the attachment receipt; a minimal receipt remains to prevent the same delivery from recreating the file. Failed uploads retain a private disposal reference until storage cleanup succeeds. Interrupted writes may require support review before cleanup can be confirmed. Cloudflare states that Email Routing does not store email content; this does not mean that Vanteloq's quarantined attachments, email-provider delivery metadata or copies in the sender's mailbox are not stored.

When a user uploads a business document, we may collect the original file, file name, type, size, cryptographic duplicate-check value, uploader, upload time, document category, storage reference, review status, and links to related transactions or records. If document extraction is enabled, we may also process proposed supplier, customer, date, amount, tax, currency, line-item, confidence, and source-page fields. Extracted fields remain subject to human review.

Service and security information

We may collect device and browser details, IP address, timestamps, authentication events, audit events, integration status, request identifiers, error details, and records of actions taken inside a workspace. This information supports sign-in, fraud prevention, troubleshooting, access control, and service reliability.

Website analytics

After a visitor explicitly allows analytics, Google Analytics may process page paths without URL query text, device and browser context, approximate region, timestamps, and configured interaction events. We use these measurements to understand public site use and improve navigation, content, and reliability. Advertising signals and ad personalization remain disabled, and Vanteloq does not intentionally send account details, form entries, contact details, or workspace records to visitor analytics.

Communications and billing information

We collect messages and support details that you send to us. Stripe provides subscription status, plan, billing contact, transaction identifiers, tax related checkout fields, and limited payment details. Stripe collects card information in its secure checkout. Vanteloq does not receive or store full card numbers.

Optional news and product updates

News, business tips and offers require a separate optional choice. Creating an account, accepting our terms or contacting support does not subscribe you. We record the consent notice, your choice, verification time and limited hashed request evidence. Unverified signup choices expire after 7 days. You can turn updates off in Settings or use the unsubscribe link without signing in. Account and security messages are separate. When an account closes, we remove its newsletter recipient profile and keep only minimal keyed suppression and unlinked consent evidence needed to honor your choice and answer compliance questions.

Address validation and transactional email

When you search for or verify a business address, Vanteloq sends the address search text and country to Canada Post AddressComplete and receives address suggestions and the selected address result. When an authorized user sends an invoice email, Resend processes the recipient, sender, subject, message content, attachment, and delivery metadata for that requested delivery.

3. How we use information

We use information to:

  • create, authenticate, secure, and administer accounts and workspaces;
  • import, organize, reconcile, display, and analyze records selected by authorized users;
  • store and review uploaded source documents, detect duplicate files, and support document extraction where that feature is enabled;
  • provide reports, calculations, alerts, audit context, and operational workflows;
  • use the selected AI provider, after separate affirmative acceptance, to explain verified aggregate business evidence and identify missing inputs;
  • maintain integrations and show their connection or verification status;
  • respond to support requests and service communications;
  • protect the service, investigate misuse, and meet legal obligations;
  • measure and improve the public website after the visitor allows optional analytics;
  • improve reliability and usability using the service and security information described above; and
  • send commercial electronic messages only with express or implied consent, or when an applicable CASL exception permits the message, with the required sender information and unsubscribe method;

We do not sell personal information. We do not use workspace business data to create advertising profiles.

4. Consent and workspace authority

We obtain consent where required and identify the purpose before or when information is collected. You may withdraw consent, subject to legal, security, and contractual limits. Withdrawal may prevent features that need the information from continuing to operate.

A workspace customer decides which authorized users and supported sources are added. The customer is responsible for having the authority to provide business records and personal information to Vanteloq. If Vanteloq processes personal information for a customer, that customer remains responsible for its own notices, permissions, and legal obligations.

Financial-connection consent

Before Plaid Link opens, Vanteloq shows a separate financial-data authorization that names the requested data categories, each processing purpose, the read-only limitation, retention consequences, and withdrawal choices. The authorization is not preselected. An authenticated user must actively accept it, and Vanteloq records the workspace, user identifier, acceptance time, provider, data categories, purposes, and versions of this Privacy Policy and the authorization notice. Plaid then presents the eligible institutions, accounts, and provider-specific permissions in Plaid Link.

A financial connection begins only after both steps are completed. A workspace owner can disconnect the connection, which stops scheduled access and causes stored provider access credentials to be revoked or deleted. The owner can then use the protected Plaid deletion control to delete unreviewed imports and remove bank/provider identifiers from accounting records that must remain. Approved, reconciled, or posted accounting fields and limited audit evidence may remain when needed for legal recordkeeping or a documented retention requirement.

For Google and Meta, authorization alone does not approve measurement collection. An authorized workspace user must complete the provider resource and owned-location selection described above before measurement sync can begin. Disconnecting stops scheduled access and removes the local authorization credential even if the provider's remote revocation service is temporarily unavailable.

Before QuickBooks authorization begins, Vanteloq shows a separate, unselected checkbox describing the company identity and future read only accounting categories, the purposes, the staging limitation, and the disconnection choice. Vanteloq records the workspace, user, provider, acceptance time, data categories, purposes, and notice versions. Intuit then presents its own company selection and authorization screen.

Vanteloq's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve the customer requested feature, is not sold, is not used for advertising, and is not transferred except to provide or secure the feature, comply with law, or as part of a transaction with appropriate safeguards.

Vanteloq AI data-use acceptance

Vanteloq AI uses OpenAI. Before the first request for a data-use purpose, the agreement starts unchecked. Your acceptance is saved for your account and workspace and checked against the current notice before each request. New chats and changes to conversation memory keep that agreement. Disabling Workspace data keeps business records out of the request while allowing app instructions and general financial or analytical guidance in the same assistant. You can decline the agreement or withdraw it in AI Settings to stop future AI requests while continuing to use other permitted workspace features. The workspace must have authority to use its imported records for this purpose; an employee agreement does not replace obligations to customers or staff.

OpenAI API content is not used for training by default unless the account opts in. The Vanteloq application does not enable training; provider-account administrators must keep optional training and data-sharing settings disabled for business analysis. Requests disable stored Responses API objects, but this is not zero retention: provider abuse-monitoring logs may retain content for up to 30 days, with exceptions described by OpenAI. Additional provider caching and legal obligations may apply. Clearing a conversation in Vanteloq deletes its active application records; it does not erase provider safety logs. OpenAI data controls.

The separate AI data-use notice describes the data categories, purpose, exclusions, conversation memory, and links to this Privacy Policy. Vanteloq records the workspace, user, provider, acceptance time, data categories, purposes, and versions of this Privacy Policy and the Advisor notice. A current agreement must cover the selected Workspace data setting. If no matching agreement exists, including after withdrawal or a notice-version change, Vanteloq asks for acceptance again before sending a request.

Commercial electronic messages require express or implied consent, or an applicable CASL exception. A purchase, transaction, customer profile, or imported contact does not automatically establish consent to receive those messages. Customers remain responsible for determining which rule applies and for their notices, sender identification, contact information, unsubscribe controls, consent evidence, and suppression lists.

5. When information is shared

We may disclose information:

  • to authorized users in the same workspace according to their roles and permissions;
  • to providers that support hosting, authentication, security, email delivery, payments, support, and connected services;
  • when an authorized user directs a connection, export, or disclosure;
  • to investigate security incidents or enforce the Terms of Service;
  • where required by law, court order, or lawful government request; or
  • as part of a business transaction, subject to appropriate confidentiality and legal protections.

Current infrastructure and product flows may involve Cloudflare for hosting and security, Supabase for authentication, Stripe for billing, Resend for authorized transactional email, Canada Post AddressComplete for address validation, Google Analytics after a visitor allows website measurement, Plaid for a bank connection selected by an authorized workspace owner, Google or OpenAI for a Vanteloq AI request affirmatively started by an authorized user, and the provider chosen by a workspace for another authorized integration. The current list and purposes appear in the Subprocessor and Connected Service Notice. Plaid also provides information about its handling of connected account data in its End User Privacy Policy.

6. Processing outside Canada

Some service providers may process or store personal information outside Canada. Cloudflare may process web traffic through its global network for hosting, delivery, and security. Supabase processes authentication information in the configured project region and may use subprocessors in other countries. Stripe may process billing and supported payment information in the United States and other countries outside Canada when configured. Plaid may process authorized financial-connection information in the United States and other countries identified in its privacy materials when configured. Google may process consented website analytics and authorized Google integration data in countries described in Google's service materials. OpenAI is the enabled Vanteloq AI provider. OpenAI may process authorized AI requests in the United States and other countries described in its service materials; Canadian-only processing has not been established. A customer-selected integration may also process authorization and synchronized records in countries disclosed by that provider.

Information processed in another country may be subject to that country’s laws and lawful access rules. We assess providers and use contractual, technical, and organizational safeguards appropriate to the information and service. Contact the Privacy Officer through our private contact form to ask about a current service-provider location or safeguards relevant to a specific connection.

7. Retention and deletion

We keep information only as long as reasonably needed for the purposes described in this policy, to provide the service, protect the integrity of business records, meet legal requirements, resolve disputes, and maintain security or audit evidence.

Retention periods vary by record type. Account, transaction, audit, and accounting records may need different periods. When information is no longer required, we delete it, anonymize it, or securely isolate it until deletion is completed. Backup copies may remain for a limited period before being overwritten.

Provider access credentials are kept only while the connection is active and are revoked or deleted after disconnection. Scheduled collection then stops. After disconnecting Plaid, an owner can permanently delete unreviewed Plaid imports. For a transaction already approved, reconciled, or posted into a journal, the deletion workflow removes Plaid identifiers, pending links, and transaction descriptions while retaining the minimum accounting fields needed to preserve ledger integrity.

After a Google or Meta disconnection, Vanteloq removes the local access credential and stops collection. Selected resource identifiers, derived measurements, and limited audit evidence are deleted or retained only for the documented service, security, legal, or workspace recordkeeping purposes described in this policy.

After a QuickBooks disconnection, Vanteloq requests provider revocation, deletes the locally stored authorization credential, and stops access. Company references and limited audit evidence are deleted or retained only for the documented security, legal, or accounting recordkeeping purpose. A disconnection does not silently delete accounting entries that an authorized user later reviewed and posted.

Conversation memory is off by default whenever you open Vanteloq AI. With memory off, each request uses your current permitted evidence and question, and Vanteloq does not save new question or answer content in its chat database. If you enable memory, Vanteloq saves new messages and may include up to six recent messages from that conversation only while the evidence and access permissions match. Changing memory starts a fresh chat. Your data-use choice is stored against your account and workspace, and is checked against the current notice before a request. You can withdraw it in AI Settings; it is not required again for every message while that choice remains valid. Turning memory off stops future history use and saving; it does not delete chats already saved. Use Clear conversation or Manage saved chats to delete one or all of your saved chats in the current workspace from the active application database. Conversations inactive for 90 days are deleted when you next use the Advisor or open saved-chat controls. A limited deletion audit event remains without question or answer content. Provider safety logs and managed backups follow their separate retention periods.

The operational retention schedule is reviewed at least annually and after a material provider, product, infrastructure, or legal change. Quarterly reviews identify expired purpose, unresolved deletion requests, legal holds, and records eligible for deletion or de-identification. A verified legal hold suspends deletion only for the affected records and documented period.

Imported bank transactions, approved accounting records, original invoices and receipts, corrections, and review history may need a longer period because they support the customer’s books or legal obligations. Customers should export required records before closing an account and should confirm their retention duties with a qualified professional.

Unsubscribe and suppression information may be kept in a minimal form so that a prior marketing choice can continue to be honoured. Security, incident, and audit records may be kept for a documented period that is proportionate to the risk and any applicable legal requirement.

Optional website analytics remains disabled unless the visitor allows it. A visitor can withdraw that choice through Cookie settings. Google Analytics retention is controlled through the applicable property settings and Google's deletion tools, subject to legal and operational requirements.

Self service account and workspace deletion

If the protected deletion control is unavailable, contact the Privacy Officer using the address below. We will verify the request, explain any required retention or technical limitation, and arrange the applicable deletion process. Do not send passwords, authenticator codes, or identity documents in an ordinary email.

Authenticated users can open Settings, Account and login, or the account deletion page, to review protected deletion controls after recent multifactor authentication. A paid subscription is not required. A nonowner can remove their Vanteloq membership, personal profile, preferences and private Advisor history. A shared sign-in needed by another service is retained. Business records remain with anonymous authorship where needed for the customer's accounting, security or audit integrity. Ambiguous or suspended workspace relationships require verified assistance before deletion can proceed.

A workspace owner can permanently delete the workspace and its memberships after disconnecting providers and exporting required records. Vanteloq verifies the deletion scope, obtains separate confirmations, cancels the Vanteloq Stripe subscription and customer, and removes workspace records, uploaded files, local credentials and memberships. Other members' independent sign-in identities are not deleted by the owner's request. The requesting person's identity is removed only when it is not required by another workspace or the separate private console.

A confirmed deletion uses an encrypted processing record so an interrupted request can be retried. The browser keeps a private deletion-session key for that purpose; it is not included in links or analytics. The status page distinguishes pending work from confirmed completion. Processing identifiers are cleared when completion is confirmed. The retry session expires after 30 days; unresolved requests then require verified assistance from the Privacy Officer.

Deletion cannot remove records that Stripe, a connected provider, or another independent organization must retain under its own agreement or law. A pseudonymous receipt containing hashes, the deletion scope, result and general retained categories may be kept for 24 months. It does not contain the deleted name, email, workspace name, network address or provider account number. Hashes are not a guarantee of anonymity. Expired completed processing records and receipts are removed during privacy-request housekeeping. Backup copies and legally required records are subject to the managed retention cycle and any documented legal hold.

8. Safeguards

Vanteloq uses safeguards designed for the sensitivity of the information, including authenticated access, records separated and scoped by organization, role-based server permissions, protected provider authorization flows, encrypted credential storage, request controls, and recorded audit and security events for important actions.

Production browser, API, authentication, webhook, and provider traffic uses HTTPS. Vanteloq's production change control requires the managed edge to reject protocol versions below TLS 1.2 before Plaid production access is enabled. Stored application data is encrypted at rest by the managed database platform. Plaid access tokens and provider item identifiers receive an additional application-level AES-GCM encryption layer under a hosted key that is not stored with the database record. Vanteloq does not place raw Plaid credentials in browser storage, source control, ordinary connection-status responses, or application logs.

No online service can promise absolute security. Users must protect their credentials, use strong passwords, enable available account protections, and promptly report suspected unauthorized access.

9. Access, correction, and privacy requests

You may ask to access or correct personal information under our control, subject to legal exceptions. You may also ask about how information was used or disclosed, withdraw consent where applicable, or raise a privacy concern.

Workspace controls allow an authenticated user to permanently delete their account and allow an authorized owner to permanently delete the workspace after the warnings and confirmation steps described above. Other controls allow an owner to export records, disconnect a provider, or correct reviewable fields. A disconnection is not the same as deleting legally retained accounting records. We will explain any applicable limitation when responding to a verified request.

Send a clear request through our private contact form. Contact and custom plan forms collect your name, email address, optional phone number, business name when relevant, and the message you submit. Resend delivers these inquiries to our team so we can respond. Submitting a request does not enroll you in marketing. Avoid sending passwords, payment details, identity documents or customer records. We may need to verify your identity and authority before responding. If information is controlled by a Vanteloq customer, we may direct the request to that customer.

If a concern is not resolved, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada, depending on which law applies.

10. Analysis and human review

Vanteloq may organize records and produce calculations, alerts, or suggested next steps from available data. These outputs depend on the quality, completeness, timing, and definitions of the source records. Material business, financial, legal, tax, employment, or inventory decisions should be reviewed by an authorized person and, where appropriate, a qualified professional.

Vanteloq AI explains a bounded evidence snapshot; it does not receive authority to post journals, send payments, change inventory, contact customers, or take another business action. The generated explanation can be inaccurate or incomplete and does not replace qualified accounting, tax, legal or investment advice. Vanteloq displays source dates and missing inputs, and an authorized person must review the explanation before relying on it.

Document extraction can misread text, numbers, tax, dates, pages, suppliers, or other fields. Vanteloq keeps extracted values provisional until an authorized reviewer compares them with the original document. An extracted value is not an approved accounting entry, payment instruction, tax position, or professional conclusion.

When configured, Scan and Read sends the selected file to Microsoft Azure Blob Storage and Defender for Storage for malware scanning, then Microsoft Azure Document Intelligence for extraction after a verified clean result. The action includes a specific processing notice, and Vanteloq records who authorized it and when. Processing uses the configured Azure regions. See the service provider notice for purposes, temporary retention and recovery copies. This action does not send the document to OpenAI or change accounting balances.

If a customer uses Vanteloq activity, access, scheduling, task, or operational records to monitor employees, the customer is responsible for a reasonable business purpose, appropriate notice, lawful authority, proportional access, retention limits, and any consent or employment requirement. Vanteloq must not be used for covert surveillance or an automated employment decision.

11. Business users and children

Vanteloq is a business service for people authorized to act for an organization. It is not directed to children, and we do not knowingly collect personal information from children for their own use of the service.

12. Changes to this policy

We may update this policy when the service, providers, or legal requirements change. We will post the revised policy with a new update date. If a change materially affects how personal information is used, we will provide additional notice or seek consent where required.

Vanteloq logo™VanteloqOperated by LexEdge Consulting
HomeResourcesPrivacyTermsCookiesData processingSubprocessors

Questions about these documents can be sent through our private contact form.