Data Deletion Policy
Vecti Tech Ltd ("we", "us", "our") Last updated: 16 May 2026 Effective date: 17 April 2026
1. Your right to delete your data
Under UK GDPR, you have the right to request deletion of your account and personal data, subject to any legal retention requirements.
2. How to request deletion
You can request deletion in two ways:
2.1 In the app
- Go to Profile > Delete Account
- Confirm the deletion prompt
- If you want a copy of your data first, use Profile > Export Data before deletion
2.2 By email
Email privacy@vecti.co.uk from the address linked to your account and request deletion. We may ask you to verify your identity before processing an email request.
3. What gets deleted
When your account is deleted, we remove your active product account and delete or deactivate personal data from active systems where no lawful retention requirement applies. This may include:
- profile information
- income, expense, mileage, invoice, VAT, CIS, and other tax records that are not subject to a tax, VAT, payment, accountant, dispute, legal, or audit retention reason
- uploaded receipt and document images that are not linked to retained records
- HMRC OAuth tokens and active connection data
- active accountant connection and collaboration access
- push notification tokens
- app settings and preferences
Deletion from active systems does not always mean all historic records are removed immediately. Some records may be retained with restricted access for the reasons below.
4. What we may keep and why
We may retain limited data where required by law or where a processor must keep its own regulatory records, for example:
- payment processor records retained by Stripe, Apple, or Google under their own legal obligations
- Self Assessment and MTD Income Tax records that must be retained for at least 5 years after the 31 January submission deadline of the relevant tax year
- VAT records that generally must be retained for at least 6 years
- tax or VAT records affected by late returns, HMRC checks, disputes, legal claims, chargebacks, fraud prevention, or other legal holds
- HMRC submission evidence, response IDs, rule/calculation snapshots, and audit records needed to explain old accepted submissions
- accountant service-order, payment, refund, dispute, review, permission, and historic access records where retention is needed for contract, payment, tax, dispute, or audit reasons
- support, privacy, export, deletion, or complaint request records needed to show how we handled your request
- minimal marketing suppression records so we do not re-add you to marketing after you opt out
- aggregate or anonymised operational statistics that no longer identify you
If analytics or crash monitoring are not enabled, there is no analytics or diagnostics data to retain for those systems.
Where records are retained, we aim to narrow access and keep only what is needed for the retention reason. Retained records are not used for ordinary product access after your account is deleted.
5. Timeline
| Step | Timing |
|---|---|
| Deletion request received | Day 0 |
| Account access disabled | Promptly after request is accepted |
| Data removed, deactivated, anonymised, or marked retained in active systems | Within 30 days, unless more time is allowed by law for complex requests |
| Backup expiry / overwrite | According to backup retention windows |
6. Connected services
When you delete your account:
- HMRC connection: the stored HMRC OAuth tokens and connection records are deleted from our database. We do not call HMRC's OAuth revoke endpoint, so any active access tokens HMRC issued to Vecti will remain valid until they expire on HMRC's side under HMRC's normal token lifetime.
- Stripe / app-store billing providers: billing processors may retain their own records under their legal obligations
- Accountant access: future collaboration access inside Vecti is removed. Historic permission, service, message, payment, dispute, or filing evidence may be retained where needed for legal, tax, payment, dispute, or audit reasons.
- Push notifications: stored push tokens are removed
If a backup containing deleted data is restored, the deletion and retention state must be reapplied so deleted data is not reactivated unless it is lawfully retained.
7. Reactivation
Once deletion is complete, it cannot be undone. If you want to use Vecti again later, you will need to create a new account.
8. App Store and Google Play subscriptions
Deleting your Vecti account does not automatically cancel an App Store or Play Store subscription. You must also cancel your subscription in the relevant store settings to stop future charges.
9. Contact us
For questions about deletion:
- Email: privacy@vecti.co.uk
- Post: Vecti Tech Ltd, Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom