Valverna
Legal

Privacy Policy

Last updated 2026-06-28 · GDPR compliant · EU/EEA

01

Who we are

Valverna AB ("we", "us", "our") is a Swedish company operating a transaction data repository service. We are registered in Stockholm, Sweden. For data protection enquiries, contact [email protected].

02

Our role under GDPR

For your account information (email, name, login credentials) we are the data controller.

For your business transaction data (the data we pull from the payment platforms you connect) we act as a data processor. Your business is the controller; we process the data on your behalf and under your instructions.

This distinction matters: transaction data is never shared, sold, or used by us for any purpose other than providing the service to you and the apps you authorize.

03

What data we collect

We collect the following categories:

Account data

Email address, display name, password hash, account creation date.

Lawful basis: contract (Art. 6(1)(b) GDPR)

Transaction data

Transactions received from payment platforms you connect (Stripe, Shopify, SumUp, etc.). Includes amounts, items, VAT, timestamps, merchant info.

Lawful basis: contract — processed as processor on your behalf

Usage data

Login timestamps, IP address, browser type, pages visited. Used for security and service improvement.

Lawful basis: legitimate interest (Art. 6(1)(f) GDPR)

Analytics data (optional)

Anonymized usage metrics via Google Analytics. IP addresses are anonymized, and we do not use advertising identifiers. Only collected after you accept analytics cookies.

Lawful basis: consent (Art. 6(1)(a) GDPR)

04

Cookies and tracking

We use three categories of cookies and similar technologies:

Strictly necessary

Authentication tokens, session management, CSRF protection. These cannot be disabled.

Functional

Theme preferences, language, last-viewed dashboard. Stored locally in your browser.

Analytics

Google Analytics cookies (_ga, _gid). Set only after you opt in. Anonymized IP. 14-month retention.

You can review and change your cookie preferences any time via the cookie banner, which reappears if you clear your browser storage.

05

Google Analytics disclosure

We use Google Analytics 4 to understand how our service is used. We have configured it with Consent Mode v2, meaning:

  • No analytics data is collected until you explicitly consent via our cookie banner.
  • IP addresses are anonymized before storage.
  • Advertising features are disabled (no remarketing, no ad personalization).
  • Data retention is set to 14 months.

Google may transfer data to servers in the United States. This transfer is based on Standard Contractual Clauses (SCCs) approved by the European Commission. You can opt out by declining analytics cookies, or by installing the Google Analytics opt-out browser add-on.

06

Who we share data with

We share data only in these cases:

  • Apps you authorize — via OAuth, with the scopes you grant.
  • Service providers acting as sub-processors (hosting, database, email delivery). A list is available on request.
  • Legal obligations — if required by Swedish/EU law or a court order.

We do not sell your data. We do not share it with advertisers or data brokers.

07

Data retention

We retain your data for as long as your account is active. After account deletion, we remove your account data within 30 days. Transaction data is deleted on your request or within 90 days of account closure, unless we are required to retain it for legal reasons (Swedish tax law requires bookkeeping records for 7 years for business customers).

Analytics data is retained for 14 months. Server logs containing IP addresses are retained for 30 days for security monitoring.

08

Your rights under GDPR

You have the right to:

  • Access — request a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — limit how we process your data
  • Portability — export your data in a machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — at any time, for processing based on consent

Email [email protected] to exercise any of these rights. We'll respond within 30 days.

You also have the right to lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY): www.imy.se.

09

Security

We implement industry-standard security measures: TLS encryption in transit, encryption at rest, strict access controls, and regular security audits. We use Firebase Authentication for credential management. No system is 100% secure — if a breach affects your data, we'll notify you within 72 hours as required by GDPR Article 33.

10

International transfers

Our primary hosting is in the EU. Some sub-processors (notably Google for Firebase and Analytics) may process data in the United States. Transfers to the US rely on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

11

Children's data

Valverna is not intended for users under 18. We do not knowingly collect data from children.

12

Changes to this policy

We'll notify you of material changes by email or in-app at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

13

Contact

Data protection enquiries: [email protected]
Postal: Valverna AB, Stockholm, Sweden