VP Sendit Back to sign in

Legal

Privacy Policy

Effective: 1 September 2026 · Version 1.3

This Policy explains how personal data is processed when you use VP Sendit. The controller is the private administrator of VP Sendit who provided, or authorized, your invitation.

1. Data we process

  • Account data: username, account role, recovery email address, verification status, account timestamps and a password verifier. The readable password is not stored.
  • Security data: session identifier, expiry and activity times, approximate browser and device type, sign-in method, MFA status and, when supplied by Cloudflare, city and country. VP Sendit does not store a full IP address in its device list, although Cloudflare may process network information to deliver and protect the service.
  • Encrypted file data: encrypted file content and metadata, ciphertext size, upload time and the account storage path. For end-to-end encrypted files, names, MIME types and readable contents are encrypted in the browser.
  • Transfer data: sender and recipient account identifiers, send and expiry times and encrypted transfer data. The filename, description and content remain encrypted.
  • Recent-recipient data: for successful transfers, the sender and recipient account identifiers, last-send time, number of sends and an optional favorite status. This list contains no filename, description or file content.
  • Recovery and email data: verification or reset-token hashes, expiry and use times, and email delivery information handled by the email provider.
  • Invite-request data: the requested email address, request and decision times, status and the approving or rejecting administrator.
  • Operational data: limited security, error and rate-limiting data needed to prevent abuse and diagnose failures.
  • Human-verification data: on protected public forms, Cloudflare Turnstile processes browser and network signals and returns a short-lived verification result to VP Sendit. VP Sendit does not receive the underlying challenge signals.
  • Administrative audit data: role changes and invite creation, including the acting account, target account where applicable and time. Readable invite codes are not included.

2. Why we process it

Data is processed to review invite requests, create and secure accounts, store and route encrypted files, deliver requested email, prevent misuse, troubleshoot the service and comply with legal obligations. Processing needed to provide the requested service is based on steps requested before entering into and performance of the user agreement. Security and service-improvement processing is based on the legitimate interest in operating a safe and reliable private service. Data may also be processed where required by law.

3. End-to-end encryption

File content and protected file metadata are encrypted and decrypted in supported browsers. Cloudflare stores ciphertext. The server still needs limited routing metadata such as account identifiers, object sizes and timestamps. End-to-end encryption does not hide all account or network metadata and cannot protect data displayed on a compromised or unlocked device.

4. Service providers

VP Sendit uses Cloudflare for the website, Worker execution, D1 database, R2 storage, rate limiting and Turnstile human verification. Resend is used to deliver verification, security, password-reset and invitation email. These providers process data on behalf of the service under their applicable agreements and may use approved safeguards for international data transfers.

5. Retention

  • Login sessions expire no later than 12 hours after creation.
  • QR sign-in requests expire after 3 minutes.
  • Password-reset links expire after 15 minutes; verification links expire after 24 hours.
  • Invitation codes expire after 2 hours and can be used once.
  • Invite-request records are removed after 30 days.
  • Inbox transfers expire after 24 hours. Files are temporary and covered by the configured R2 lifecycle.
  • Up to 100 recent recipients are retained per account. A user can remove an entry at any time; older non-favorites are removed automatically when the limit is reached.
  • Account and recovery-email data remains while the account exists or while reasonably needed for security and legal obligations.
  • Infrastructure logs and backups follow the retention schedules of the relevant provider.

6. Sharing

Personal data is not sold and VP Sendit contains no advertising or cross-site tracking. Data is shared only with the infrastructure providers described above, with a recipient you deliberately select, when required by law, or when necessary to protect users and the service.

7. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. You may also lodge a complaint with the Dutch Data Protection Authority or your local supervisory authority. Contact the administrator who invited you to exercise a right. Identity may need to be verified before a request is completed.

8. Required information and consequences

A username, invitation and password verifier are required to create an account. A verified email address is required for email-based password recovery. If required data is not provided, the relevant account or recovery feature cannot be provided.

9. Changes and contact

This Policy may be updated as the service changes. The date and version above identify the current text. For privacy questions or requests, contact the VP Sendit administrator who provided your invitation through the same communication channel.

AboutFAQTermsPrivacyCookiesSecurity