Privacy

Privacy Policy

Last updated: July 2026

Vancore Group Limited ("Vancore", "we", "us") is committed to protecting your personal data and upholding your privacy rights under the UK General Data Protection Regulation (UK GDPR), EU GDPR, and applicable data privacy laws.

1. Information We Collect

Account & Identity Data: Name, business email address, encrypted password hash, role within your organization, and 2FA enrollment status.

Billing Information: Payment card processing is securely managed by our payment processor (e.g., Stripe). We do not store raw credit card numbers on our servers.

Test Execution Telemetry: Web URLs, DOM snapshots, network logs, console traces, screenshots, and execution run reports generated during automated testing sessions.

Secret Vault Metadata: Environment variables and secrets configured for test scenarios are stored using AES-256-GCM encryption and masked in output logs.

2. How We Use Your Information

We process your data for the following lawful purposes:

  • Executing automated browser test scenarios, two-pass domain grounding, and self-healing selector routines.
  • Managing user accounts, organization memberships, and billing subscriptions.
  • Improving platform performance, detecting operational anomalies, and securing system infrastructure.
  • Sending service updates, security alerts, and system notifications.

3. Data Sub-processors & Infrastructure

To deliver the Service, we utilize trusted cloud sub-processors under strict Data Processing Agreements (DPAs):

  • Supabase: Managed database, authentication, and encrypted storage.
  • Browserbase: Ephemeral headless browser infrastructure and session execution.
  • Large Language Model (LLM) Providers: AI model providers used strictly for real-time DOM grounding and self-healing during runs under zero-data-retention agreements.

4. Data Retention & Security

  • Account data is retained for the lifetime of your active subscription.
  • Test execution traces, public report links, and temporary browser recordings are retained according to your plan's retention policy (default 30 to 90 days) or until manually deleted by an Organization Admin.
  • You may request full account and data deletion at any time by contacting privacy@vancoregroup.com.

5. Your GDPR Rights

Under UK/EU GDPR, you have the right to access, rectify, port, or erase your personal data, as well as the right to restrict processing. To exercise these rights, contact our Data Protection team at dpo@vancoregroup.com.