Privacy Policy

Last updated: March 14, 2026

Overview

VanChat is a privately held communication platform. Each Community on VanChat is managed by its members, but the platform itself is owned and operated by VanChat. This policy describes the data practices of the VanChat platform.

VanChat is operated from Canada and is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). For users in the European Economic Area, VanChat also complies with the General Data Protection Regulation (GDPR).

Data We Collect

When you use VanChat, the following data is stored on VanChat’s servers:

  • Account information — username, email address, and hashed password. Lawful basis: contractual necessity (we need this to provide you an account).
  • Messages — text content and file attachments you send in channels and direct messages. Lawful basis: contractual necessity (delivering messages is the core service).
  • Presence data — online/offline status and last-seen timestamps. Lawful basis: contractual necessity (showing presence to community members).
  • Device tokens — push notification tokens if you enable notifications. Lawful basis: consent (you opt in to push notifications).
  • Profile information — display name, avatar, and any optional profile fields you provide. Lawful basis: consent (you choose what optional profile info to provide).

How Data Is Used

Your data is used to: deliver messages, manage your account, display presence to community members, send notifications you have opted into, enforce our Terms of Service and Community Guidelines, and respond to support requests.

VanChat does not sell your data. VanChat does not share your data with third parties for advertising or any other purpose unrelated to providing the Service.

Children’s Data

VanChat requires users to be of the age of majority in their jurisdiction, as stated in our Terms of Service. We do not knowingly collect personal data from anyone under the age of majority. If we learn that we have collected data from someone under the required age, we will terminate their account and delete associated data within 30 days. If you believe a user is underage, please contact support.

Data Storage

All data is stored on infrastructure controlled by VanChat, hosted in Canada. Passwords are cryptographically hashed and never stored in plain text. Data is encrypted in transit using TLS.

Data Retention and Deletion

Messages and account data are retained for as long as your account is active.

  • Deleted messages are removed from VanChat’s servers within 7 days.
  • Account deletion: when you request account deletion, your personal data will be permanently deleted within 30 days, except where retention is required by law or necessary to fulfill legal obligations (such as responding to law enforcement requests or mandatory reporting under child safety legislation).
  • Backups containing your data are rotated and purged within 90 days of account deletion.
  • Messages sent to other users may persist in those users’ conversation histories after your account is deleted.

Third-Party Services

VanChat uses the following third-party services, each governed by their own privacy policies:

  • Apple Push Notification Service (APNs) 🇺🇸 — delivers push notifications to iOS and macOS users. Data shared: device tokens, notification content.
  • Firebase Cloud Messaging (FCM) 🇺🇸 — delivers push notifications to Android users. Data shared: device tokens, notification content.
  • MailChannels 🇨🇦 — delivers transactional email (password resets, notifications). Data shared: email address, email content.
  • Apple App Store / Google Play 🇺🇸 — processes in-app donations and subscriptions. Data shared: transaction IDs, purchase amounts. Apple and Google handle all payment information directly; VanChat never receives or stores credit card numbers.

VanChat does not use any analytics, advertising, or tracking services.

Cookies and Local Storage

VanChat does not use tracking cookies, analytics cookies, or third-party cookies. VanChat uses browser localStorage to remember your preferences (such as theme selection, last-visited channel, and authentication tokens). This data stays in your browser and is not transmitted to any third party.

VanChat may disclose your data to law enforcement or government authorities when:

  • Required by a valid legal order (such as a court order or warrant)
  • Required by mandatory reporting obligations, including reporting suspected CSAM to the Canadian Centre for Child Protection (Cybertip.ca) and the RCMP under the Criminal Code (R.S.C., 1985, c. C-46)
  • Necessary to prevent imminent harm to a person

When legally permitted, we will notify you of such disclosures.

Breach Notification

In the event of a data breach that poses a real risk of significant harm, VanChat will:

  • Notify affected users within 72 hours of becoming aware of the breach
  • Notify the Office of the Privacy Commissioner of Canada as required by PIPEDA
  • Notify relevant European data protection authorities for affected EEA users as required by GDPR

Notifications will include the nature of the breach, the data affected, and steps you can take to protect yourself.

Your Rights

You have the following rights regarding your personal data:

  • Access — you can view your profile information and messages within the application at any time.
  • Correction — you can edit your profile information within the application.
  • Deletion — you can delete individual messages and request account deletion. Account deletion removes your personal data within 30 days.
  • Data portability — you can request an export of your data in a standard machine-readable format by contacting support. We will fulfill export requests within 30 days.
  • Withdrawal of consent — where processing is based on consent (push notifications, optional profile information), you can withdraw consent at any time by disabling the feature or removing the data.
  • Complaint — you may file a complaint with the Office of the Privacy Commissioner of Canada or, for EEA users, your local data protection authority.

Data on Termination

When your account is terminated (whether by you or by VanChat under our Terms of Service), your personal data is handled as described in the Data Retention and Deletion section above. Active subscriptions should be cancelled through your device’s app store before or after account deletion; VanChat cannot cancel app store subscriptions on your behalf.

International Data Transfers

VanChat stores all data in Canada. When you use push notifications, limited data (device tokens and notification content) is transmitted to Apple (United States) or Google (United States) servers. Canada has been recognized by the European Commission as providing adequate data protection.

Data Protection Officer

VanChat’s Data Protection Officer is Andy Moore (andy@prosocial.design). You may contact the DPO directly for any questions or concerns about how your personal data is handled, to exercise your data rights, or to file a complaint.

Contact

For general questions about this privacy policy or data practices, contact support.