1. Scope and accountability
This Privacy Policy applies when you visit vanteloq.com, create or use a Vanteloq account, administer a workspace, connect a supported service, submit a form, or contact us.
LexEdge Consulting, operating as Vanteloq, is responsible for personal information under its control. The privacy contact is the Vanteloq Privacy Officer through our private contact form.
Vanteloq follows Alberta’s Personal Information Protection Act and Canada’s Personal Information Protection and Electronic Documents Act where each law applies.
2. Information we collect
Account and workspace information
We collect information you provide, such as your name, email address, password credentials handled by the authentication provider, business name, legal name, business contact details, role, location information, operating hours, and workspace settings.
Connected business information
Manual payroll accounting entries may contain aggregate wage costs, employer costs, payroll liabilities, and a reference to a customer-approved payroll report. The payroll screen does not connect to a payroll provider or collect employee bank instructions. Customers must limit entries to necessary accounting information and provide employees with any notices or other protections required for their use of the service.
When an authorized workspace user connects a supported provider or imports records, Vanteloq may receive sales, payment, refund, product, inventory, customer, supplier, location, purchasing, finance, and operational records. The exact fields depend on the source, the permissions granted, and the import selected by the user.
Google and Meta connections
After resource approval, detailed marketing reports may retrieve website traffic by channel, page and device; Search Console queries, pages, clicks, impressions and average positions; local Business Profile discovery measures and monthly search terms; and paid campaign measurements from Google Ads or Meta. Detailed report responses are not cached in Vanteloq's database. They are visible only within the user's permitted workspace and location scope. Refreshing a report does not change a campaign, publish content or grant new provider permissions. Meta paid-ad reporting does not include organic Facebook Page or Instagram insights.
A Google or Meta connection remains unavailable for measurement until an authorized user selects the exact eligible account, property, or owned business location, assigns it organization-wide or to an owned workspace location, and approves a warning-free sample. Vanteloq may retain encrypted authorization credentials while the connection is active, the selected provider and resource identifiers, the chosen workspace scope, connection and sync status, and derived daily measurements with source and freshness details. We use that information only to provide the connected reporting and operational features requested by the workspace.
For a selected Google Business Profile location, an authorized user may request the current review response queue. Review text, ratings, reviewer details, and reply content are fetched directly from Google for that request, are sent with a no-store response, and are not inserted into Vanteloq's database or aggregated into a customer profile. Vanteloq sends a reply to Google only after a user with marketing-management permission enters the reply and provides a separate, specific confirmation. Google remains the system of record for the review and reply.
Connected financial account information
When an authorized workspace owner chooses a bank connection, Vanteloq may use Plaid as a service provider to connect selected business accounts. Depending on the connection and consent shown, Vanteloq may receive account and institution names, masked account identifiers, account type, balances, transactions, transaction descriptions, pending or posted status, currency, provider item and account identifiers, and connection or sync status.
Bank sign-in information entered in Plaid Link is handled by Plaid and the financial institution. Vanteloq does not receive the online banking credentials entered in that flow. When a Plaid connection is configured and an authorized workspace user completes the provider consent flow, the connection uses only the read-only data products disclosed in that flow and does not allow Vanteloq to move money. We use connected records for bookkeeping review, reconciliation, supported cash context, connection support, security, and audit evidence.
QuickBooks Online connection
When an owner or administrator chooses to connect QuickBooks Online, Vanteloq records the selected company identifier, company name, authorization status, encrypted refreshable credentials, and security or audit metadata. The current sandbox stage verifies the selected company but does not import ledger records or enable dashboard calculations. Before a future accounting import is enabled, Vanteloq will identify the accounting records requested, the mapping and reconciliation controls, and any additional review required.
Vanteloq AI information
AI data-use notice update, September 16, 2026: Vanteloq AI handles business questions and app guidance in one conversation. With Workspace data enabled in AI Settings, answers may use permitted organization-wide BookLoQ ledger and cash summaries. Historical cash totals may include reviewed bank statement imports, with their reporting dates. Demonstration records, original documents and transaction descriptions are excluded. These are kept separate from dated retail KPIs; raw ledger records and identities are not attached. With Workspace data disabled, only your question, product guidance and optional matching history are attached. Workspace records are excluded. Changing this setting starts a new chat. A saved, current agreement must cover the selected data use before a request can be sent.
When Workspace data is enabled and an authorized user accepts the current data-use notice and asks Vanteloq AI a question, Vanteloq sends OpenAI the question, product guidance, dated aggregate sales, profit, units, labour, inventory-value and accounts-payable metrics where the user has the corresponding permission, connected-source status and freshness, and permitted aggregate cash context. Users with marketing access may also include synchronized traffic, search and advertising totals from their approved sources, with reporting periods and data-coverage limits. Search queries, page addresses, Google Business Profile content, advertising amounts without verified currency, raw provider credentials, full account numbers, customer names, invoice or receipt files, and raw transaction records are excluded from the automated evidence summary. Do not include personal information or secrets in your question.
Up to six recent conversation messages may be included only when their saved evidence and access context match the current request. When permissions, source evidence or location scope change, earlier messages are not forwarded as context. Changing the selected provider also prevents earlier messages from being forwarded.
When conversation memory is enabled, Vanteloq stores the question, the generated explanation, a limited evidence summary, the model identifier, and conversation timestamps so the authorized user can continue the conversation. With memory off, new questions and replies are not saved in the Vanteloq chat database. Advisor records are scoped to that user and workspace.
Uploaded bank statements, invoices, receipts, and other documents
Bank statements can supply historical bank movements after an authorized reviewer checks the account, dates, rows and opening-to-closing balance. Vanteloq retains the original document and import history. These imports do not automatically post journals, establish accounting profit or confirm today's available balance. Statement activity is withheld from combined cash reporting while an approved Plaid feed is active to avoid duplicate counting. Optional AI analysis receives only permitted dated aggregates under the current AI data-use agreement.
When available, an authorized owner or administrator with BookLoQ can separately enable a private document forwarding address after accepting its storage notice. Cloudflare Email Routing processes incoming messages, and an Email Worker sends supported attachments to Vanteloq's private quarantine. Vanteloq records the unverified sender address, receipt time and duplicate-check references, but does not keep the email body. The address can be replaced or disabled. Forwarding does not authenticate the sender as a Vanteloq user and never starts scanning, extraction, AI analysis or accounting posting. Those actions retain their separate permissions and review steps.
Forwarded originals follow the same document retention and deletion controls as uploaded originals. Deleting an original removes its sender address from the attachment receipt; a minimal receipt remains to prevent the same delivery from recreating the file. Failed uploads retain a private disposal reference until storage cleanup succeeds. Interrupted writes may require support review before cleanup can be confirmed. Cloudflare states that Email Routing does not store email content; this does not mean that Vanteloq's quarantined attachments, email-provider delivery metadata or copies in the sender's mailbox are not stored.
When a user uploads a business document, we may collect the original file, file name, type, size, cryptographic duplicate-check value, uploader, upload time, document category, storage reference, review status, and links to related transactions or records. If document extraction is enabled, we may also process proposed supplier, customer, date, amount, tax, currency, line-item, confidence, and source-page fields. Extracted fields remain subject to human review.
Service and security information
We may collect device and browser details, IP address, timestamps, authentication events, audit events, integration status, request identifiers, error details, and records of actions taken inside a workspace. This information supports sign-in, fraud prevention, troubleshooting, access control, and service reliability.
Website analytics
After a visitor explicitly allows analytics, Google Analytics may process page paths without URL query text, device and browser context, approximate region, timestamps, and configured interaction events. We use these measurements to understand public site use and improve navigation, content, and reliability. Advertising signals and ad personalization remain disabled, and Vanteloq does not intentionally send account details, form entries, contact details, or workspace records to visitor analytics.
Communications and billing information
We collect messages and support details that you send to us. Stripe provides subscription status, plan, billing contact, transaction identifiers, tax related checkout fields, and limited payment details. Stripe collects card information in its secure checkout. Vanteloq does not receive or store full card numbers.
Optional news and product updates
News, business tips and offers require a separate optional choice. Creating an account, accepting our terms or contacting support does not subscribe you. We record the consent notice, your choice, verification time and limited hashed request evidence. Unverified signup choices expire after 7 days. You can turn updates off in Settings or use the unsubscribe link without signing in. Account and security messages are separate. When an account closes, we remove its newsletter recipient profile and keep only minimal keyed suppression and unlinked consent evidence needed to honor your choice and answer compliance questions.
Address validation and transactional email
When you search for or verify a business address, Vanteloq sends the address search text and country to Canada Post AddressComplete and receives address suggestions and the selected address result. When an authorized user sends an invoice email, Resend processes the recipient, sender, subject, message content, attachment, and delivery metadata for that requested delivery.
3. How we use information
We use information to:
- create, authenticate, secure, and administer accounts and workspaces;
- import, organize, reconcile, display, and analyze records selected by authorized users;
- store and review uploaded source documents, detect duplicate files, and support document extraction where that feature is enabled;
- provide reports, calculations, alerts, audit context, and operational workflows;
- use the selected AI provider, after separate affirmative acceptance, to explain verified aggregate business evidence and identify missing inputs;
- maintain integrations and show their connection or verification status;
- respond to support requests and service communications;
- protect the service, investigate misuse, and meet legal obligations;
- measure and improve the public website after the visitor allows optional analytics;
- improve reliability and usability using the service and security information described above; and
- send commercial electronic messages only with express or implied consent, or when an applicable CASL exception permits the message, with the required sender information and unsubscribe method;
We do not sell personal information. We do not use workspace business data to create advertising profiles.
6. Processing outside Canada
Some service providers may process or store personal information outside Canada. Cloudflare may process web traffic through its global network for hosting, delivery, and security. Supabase processes authentication information in the configured project region and may use subprocessors in other countries. Stripe may process billing and supported payment information in the United States and other countries outside Canada when configured. Plaid may process authorized financial-connection information in the United States and other countries identified in its privacy materials when configured. Google may process consented website analytics and authorized Google integration data in countries described in Google's service materials. OpenAI is the enabled Vanteloq AI provider. OpenAI may process authorized AI requests in the United States and other countries described in its service materials; Canadian-only processing has not been established. A customer-selected integration may also process authorization and synchronized records in countries disclosed by that provider.
Information processed in another country may be subject to that country’s laws and lawful access rules. We assess providers and use contractual, technical, and organizational safeguards appropriate to the information and service. Contact the Privacy Officer through our private contact form to ask about a current service-provider location or safeguards relevant to a specific connection.
7. Retention and deletion
We keep information only as long as reasonably needed for the purposes described in this policy, to provide the service, protect the integrity of business records, meet legal requirements, resolve disputes, and maintain security or audit evidence.
Retention periods vary by record type. Account, transaction, audit, and accounting records may need different periods. When information is no longer required, we delete it, anonymize it, or securely isolate it until deletion is completed. Backup copies may remain for a limited period before being overwritten.
Provider access credentials are kept only while the connection is active and are revoked or deleted after disconnection. Scheduled collection then stops. After disconnecting Plaid, an owner can permanently delete unreviewed Plaid imports. For a transaction already approved, reconciled, or posted into a journal, the deletion workflow removes Plaid identifiers, pending links, and transaction descriptions while retaining the minimum accounting fields needed to preserve ledger integrity.
After a Google or Meta disconnection, Vanteloq removes the local access credential and stops collection. Selected resource identifiers, derived measurements, and limited audit evidence are deleted or retained only for the documented service, security, legal, or workspace recordkeeping purposes described in this policy.
After a QuickBooks disconnection, Vanteloq requests provider revocation, deletes the locally stored authorization credential, and stops access. Company references and limited audit evidence are deleted or retained only for the documented security, legal, or accounting recordkeeping purpose. A disconnection does not silently delete accounting entries that an authorized user later reviewed and posted.
Conversation memory is off by default whenever you open Vanteloq AI. With memory off, each request uses your current permitted evidence and question, and Vanteloq does not save new question or answer content in its chat database. If you enable memory, Vanteloq saves new messages and may include up to six recent messages from that conversation only while the evidence and access permissions match. Changing memory starts a fresh chat. Your data-use choice is stored against your account and workspace, and is checked against the current notice before a request. You can withdraw it in AI Settings; it is not required again for every message while that choice remains valid. Turning memory off stops future history use and saving; it does not delete chats already saved. Use Clear conversation or Manage saved chats to delete one or all of your saved chats in the current workspace from the active application database. Conversations inactive for 90 days are deleted when you next use the Advisor or open saved-chat controls. A limited deletion audit event remains without question or answer content. Provider safety logs and managed backups follow their separate retention periods.
The operational retention schedule is reviewed at least annually and after a material provider, product, infrastructure, or legal change. Quarterly reviews identify expired purpose, unresolved deletion requests, legal holds, and records eligible for deletion or de-identification. A verified legal hold suspends deletion only for the affected records and documented period.
Imported bank transactions, approved accounting records, original invoices and receipts, corrections, and review history may need a longer period because they support the customer’s books or legal obligations. Customers should export required records before closing an account and should confirm their retention duties with a qualified professional.
Unsubscribe and suppression information may be kept in a minimal form so that a prior marketing choice can continue to be honoured. Security, incident, and audit records may be kept for a documented period that is proportionate to the risk and any applicable legal requirement.
Optional website analytics remains disabled unless the visitor allows it. A visitor can withdraw that choice through Cookie settings. Google Analytics retention is controlled through the applicable property settings and Google's deletion tools, subject to legal and operational requirements.
Self service account and workspace deletion
If the protected deletion control is unavailable, contact the Privacy Officer using the address below. We will verify the request, explain any required retention or technical limitation, and arrange the applicable deletion process. Do not send passwords, authenticator codes, or identity documents in an ordinary email.
Authenticated users can open Settings, Account and login, or the account deletion page, to review protected deletion controls after recent multifactor authentication. A paid subscription is not required. A nonowner can remove their Vanteloq membership, personal profile, preferences and private Advisor history. A shared sign-in needed by another service is retained. Business records remain with anonymous authorship where needed for the customer's accounting, security or audit integrity. Ambiguous or suspended workspace relationships require verified assistance before deletion can proceed.
A workspace owner can permanently delete the workspace and its memberships after disconnecting providers and exporting required records. Vanteloq verifies the deletion scope, obtains separate confirmations, cancels the Vanteloq Stripe subscription and customer, and removes workspace records, uploaded files, local credentials and memberships. Other members' independent sign-in identities are not deleted by the owner's request. The requesting person's identity is removed only when it is not required by another workspace or the separate private console.
A confirmed deletion uses an encrypted processing record so an interrupted request can be retried. The browser keeps a private deletion-session key for that purpose; it is not included in links or analytics. The status page distinguishes pending work from confirmed completion. Processing identifiers are cleared when completion is confirmed. The retry session expires after 30 days; unresolved requests then require verified assistance from the Privacy Officer.
Deletion cannot remove records that Stripe, a connected provider, or another independent organization must retain under its own agreement or law. A pseudonymous receipt containing hashes, the deletion scope, result and general retained categories may be kept for 24 months. It does not contain the deleted name, email, workspace name, network address or provider account number. Hashes are not a guarantee of anonymity. Expired completed processing records and receipts are removed during privacy-request housekeeping. Backup copies and legally required records are subject to the managed retention cycle and any documented legal hold.
8. Safeguards
Vanteloq uses safeguards designed for the sensitivity of the information, including authenticated access, records separated and scoped by organization, role-based server permissions, protected provider authorization flows, encrypted credential storage, request controls, and recorded audit and security events for important actions.
Production browser, API, authentication, webhook, and provider traffic uses HTTPS. Vanteloq's production change control requires the managed edge to reject protocol versions below TLS 1.2 before Plaid production access is enabled. Stored application data is encrypted at rest by the managed database platform. Plaid access tokens and provider item identifiers receive an additional application-level AES-GCM encryption layer under a hosted key that is not stored with the database record. Vanteloq does not place raw Plaid credentials in browser storage, source control, ordinary connection-status responses, or application logs.
No online service can promise absolute security. Users must protect their credentials, use strong passwords, enable available account protections, and promptly report suspected unauthorized access.
9. Access, correction, and privacy requests
You may ask to access or correct personal information under our control, subject to legal exceptions. You may also ask about how information was used or disclosed, withdraw consent where applicable, or raise a privacy concern.
Workspace controls allow an authenticated user to permanently delete their account and allow an authorized owner to permanently delete the workspace after the warnings and confirmation steps described above. Other controls allow an owner to export records, disconnect a provider, or correct reviewable fields. A disconnection is not the same as deleting legally retained accounting records. We will explain any applicable limitation when responding to a verified request.
Send a clear request through our private contact form. Contact and custom plan forms collect your name, email address, optional phone number, business name when relevant, and the message you submit. Resend delivers these inquiries to our team so we can respond. Submitting a request does not enroll you in marketing. Avoid sending passwords, payment details, identity documents or customer records. We may need to verify your identity and authority before responding. If information is controlled by a Vanteloq customer, we may direct the request to that customer.
If a concern is not resolved, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada, depending on which law applies.
10. Analysis and human review
Vanteloq may organize records and produce calculations, alerts, or suggested next steps from available data. These outputs depend on the quality, completeness, timing, and definitions of the source records. Material business, financial, legal, tax, employment, or inventory decisions should be reviewed by an authorized person and, where appropriate, a qualified professional.
Vanteloq AI explains a bounded evidence snapshot; it does not receive authority to post journals, send payments, change inventory, contact customers, or take another business action. The generated explanation can be inaccurate or incomplete and does not replace qualified accounting, tax, legal or investment advice. Vanteloq displays source dates and missing inputs, and an authorized person must review the explanation before relying on it.
Document extraction can misread text, numbers, tax, dates, pages, suppliers, or other fields. Vanteloq keeps extracted values provisional until an authorized reviewer compares them with the original document. An extracted value is not an approved accounting entry, payment instruction, tax position, or professional conclusion.
When configured, Scan and Read sends the selected file to Microsoft Azure Blob Storage and Defender for Storage for malware scanning, then Microsoft Azure Document Intelligence for extraction after a verified clean result. The action includes a specific processing notice, and Vanteloq records who authorized it and when. Processing uses the configured Azure regions. See the service provider notice for purposes, temporary retention and recovery copies. This action does not send the document to OpenAI or change accounting balances.
If a customer uses Vanteloq activity, access, scheduling, task, or operational records to monitor employees, the customer is responsible for a reasonable business purpose, appropriate notice, lawful authority, proportional access, retention limits, and any consent or employment requirement. Vanteloq must not be used for covert surveillance or an automated employment decision.
11. Business users and children
Vanteloq is a business service for people authorized to act for an organization. It is not directed to children, and we do not knowingly collect personal information from children for their own use of the service.
12. Changes to this policy
We may update this policy when the service, providers, or legal requirements change. We will post the revised policy with a new update date. If a change materially affects how personal information is used, we will provide additional notice or seek consent where required.
™