How SHVL handles your account and credit-control data.
This notice covers the SHVL website, one-off chase packs and signed-in credit-control workspace. SHVL uses business data only to provide, secure and improve those services.
Browser-side tools keep selected files in your browser where stated. Chase-pack generation and the recurring workspace use SHVL cloud services. Xero or FreeAgent and your connected mailbox remain the source of truth.
For the exact browser vs cloud boundary, current telemetry, and storage behaviour, see Data handling and Cookies & storage. For the public-site accessibility standard we are working to, see Accessibility. For site-level public terms, see Terms.
What SHVL stores
The data depends on which part of SHVL you use.
- Account details, workspace membership and billing references.
- Customer, invoice, payment, chase-status, note and reminder data imported from CSV, Xero or FreeAgent.
- Reminder text, relevant replies, delivery failures and the communication history shown in your workspace.
- Encrypted OAuth tokens and connected-account identifiers while a provider remains connected.
How SHVL uses it
SHVL processes this data to provide the service you request.
- Generate one-off chase-pack files after checkout.
- Synchronise overdue invoices and payments from Xero or FreeAgent.
- Prepare, send and reconcile reminders you activate.
- Prevent duplicate or incorrect sends, secure accounts and resolve service faults.
You choose which providers SHVL can access.
Xero and FreeAgent access is limited to accounting data needed to synchronise contacts, invoices and payments. Outlook.com or Hotmail access is used to send reminders and identify replies or delivery failures. Gmail is limited to approved accounts.
- SHVL does not use mailbox content to train a general model or learn your writing style.
- Provider access can be disconnected from workspace Data controls.
- You can also revoke SHVL in the provider's account settings.
Product analytics do not include debtor or message content.
SHVL needs product telemetry so we can see what workflows are valuable and what breaks in the real world. That does not require your message bodies.
- Useful telemetry: workflow started, workflow succeeded or failed, duration, steps completed, connector used.
- Useful site analytics: Google Analytics 4 measurement ID G-KQ4M2NMLQD, Ahrefs Web Analytics page views, plus selected SHVL funnel events like checkout clicks, demo requests, workflow views, and install intent. GA4 is loaded on public marketing pages with anonymised IP settings, Google signals disabled, ad personalisation signals disabled, and Consent Mode defaults set to denied for analytics and advertising storage.
- Signed-in product events may include page path and account id. Free tools do not require an account.
- Stripe handles chase-pack and subscription payments. SHVL receives checkout status, customer and subscription references, not full card details.
- Analytics events do not contain CSV rows, debtor details, invoice details or message bodies.
You can disconnect providers or delete the workspace.
Disconnecting a provider removes its stored connection and token, pauses reminders and keeps previously synced records and communication history for review. Workspace deletion permanently removes local recurring credit-control data after an active SHVL subscription is cancelled.
- Stripe may retain payment records to meet its own legal obligations.
- To request access, correction or deletion, email hello@shvl.app. You may also complain to the UK Information Commissioner's Office.
Want the bottleneck removed without handing over a content archive?
Tell us the repetitive request or admin loop you want SHVL to handle first. We can shape the workflow around a privacy-safe execution path from the start.
Related pages: Data handling, Cookies & storage, Terms, and Accessibility.