How SHVL handles your account and credit-control data.
This notice covers the SHVL website, one-off chase packs and signed-in credit-control workspace. SHVL uses business data only to provide, secure and improve those services.
Browser-side tools keep selected files in your browser where stated. Chase-pack generation and the recurring workspace use SHVL cloud services. Xero, QuickBooks or FreeAgent and your connected mailbox remain the source of truth.
For the exact browser vs cloud boundary, current telemetry, and storage behaviour, see Data handling and Cookies & storage. For the public-site accessibility standard we are working to, see Accessibility. For site-level public terms, see Terms.
What SHVL stores
The data depends on which part of SHVL you use.
- Account details, workspace membership and billing references.
- Customer, invoice, payment, chase-status, note and reminder data imported from CSV, Xero, QuickBooks or FreeAgent.
- Reminder text, relevant replies, delivery failures and the communication history shown in your workspace.
- Encrypted OAuth tokens and connected-account identifiers while a provider remains connected.
How SHVL uses it
SHVL processes this data to provide the service you request.
- Generate one-off chase-pack files after checkout.
- Process CSV text submitted through the optional ChatGPT plugin to return review-only drafts and indicative calculations without storing that CSV in SHVL's database.
- Synchronise overdue invoices and payments from Xero, QuickBooks or FreeAgent.
- Prepare, send and reconcile reminders you activate.
- Prevent duplicate or incorrect sends, secure accounts and resolve service faults.
You choose which providers SHVL can access.
Xero and FreeAgent access is limited to accounting data needed to synchronise contacts, invoices and payments. Microsoft 365, Outlook.com or Hotmail access is used to send reminders and identify replies or delivery failures. Gmail uses send-only access. SHVL cannot read Gmail Inbox messages, replies or delivery failures.
- SHVL does not use mailbox content to train a general model or learn your writing style.
- Provider access can be disconnected from workspace Data controls.
- You can also revoke SHVL in the provider's account settings.
Gmail access is limited to sending reviewed reminders and invoice requests.
When an account connects Gmail, SHVL accesses the Google
account email address and OAuth credentials. SHVL requests
gmail.send and uses it only to send reviewed reminders
or explicitly approved invoice-blocker requests. A request may include
one clean, reviewed document selected and confirmed by the permitted workspace member.
The recipient, message, invoice links, document reference, approval and
follow-up date are retained in the case history. SHVL does not read, modify or delete Gmail
mailbox content, including Inbox messages, replies or delivery
failures.
- Sharing and disclosure. SHVL does not sell Google user data or share it with advertisers, data brokers, other customers or AI model providers. It is disclosed only to service providers needed to host and secure SHVL, to the intended email recipient when the workspace owner sends a reminder, or where disclosure is required by law.
- Protection. OAuth credentials are encrypted at rest and transmitted over HTTPS. Access is restricted to the systems and authorised staff needed to operate, secure and support the service.
- Retention and control. Disconnecting Gmail deletes the stored Google connection and OAuth credentials. The account owner can also revoke SHVL from Google Account settings.
ChatGPT receives only the data needed for the tool you choose.
The optional SHVL ChatGPT plugin accepts the aged-debtors CSV text, sender name and Bank Rate that you provide in ChatGPT. SHVL processes those inputs in memory to return review-only UK B2B chase drafts and indicative statutory-interest calculations.
If you sign in to the optional SHVL connection in ChatGPT, its protected read-only tools can also return a daily credit-control brief, a receivables-health summary, case search results and one selected case from your latest SHVL CSV import or completed accounting sync. Results can include customer names, invoice references, dates and balances, aggregate invoice and receivables-payment totals, payment-readiness state and limited reminder evidence. The receivables view is not a bank balance, cash-flow, profit or whole-business health report. Results exclude expenses, email addresses, message content, provider IDs and individual payment records. Every request is restricted to the signed-in SHVL workspace. The tools do not call an accounting provider live, change records, queue a reminder or send a message.
- The tool result repeats the debtor name, invoice number, due date and outstanding amount from the supplied CSV. It adds days overdue, statutory interest, fixed compensation, total claim, a subject line and a draft body. It does not return debtor email addresses or persist the submitted CSV in SHVL's database.
- The anonymous CSV tool does not send email, create an account, connect a mailbox or start a payment. The signed-in workspace tools are read-only and use the existing SHVL workspace connection.
- ChatGPT is a separate service. Its handling of conversation and uploaded-file data is governed by the terms and privacy settings that apply to your ChatGPT account.
Product analytics do not include debtor or message content.
SHVL needs product telemetry so we can see what workflows are valuable and what breaks in the real world. That does not require your message bodies.
- Useful telemetry: workflow started, workflow succeeded or failed, duration, steps completed, connector used.
- Useful site analytics: Google Analytics 4 measurement ID G-KQ4M2NMLQD, Ahrefs Web Analytics page views, plus selected SHVL funnel events like checkout clicks, demo requests, workflow views, and install intent. GA4 is loaded on public marketing pages with anonymised IP settings, Google signals disabled, ad personalisation signals disabled, and Consent Mode defaults set to denied for analytics and advertising storage.
- Signed-in product events may include page path and account id. Free tools do not require an account.
- If you allow analytics and create a recurring workspace, SHVL stores the first landing path, coarse acquisition channel and a sanitised campaign label captured in this browser. Without that choice, the source is recorded as unknown. It does not store the referrer URL, debtor data, invoice values or your email in that attribution row.
- Stripe handles chase-pack and subscription payments. SHVL receives checkout status, customer and subscription references, not full card details.
- Analytics events do not contain CSV rows, debtor details, invoice details or message bodies.
You can disconnect providers or delete the workspace.
Disconnecting a provider removes its stored connection and token, pauses reminders and keeps previously synced records and communication history for review. Workspace deletion permanently removes local recurring credit-control data after an active SHVL subscription is cancelled.
- Stripe may retain payment records to meet its own legal obligations.
- To request access, correction or deletion, email hello@shvl.app. You may also complain to the UK Information Commissioner's Office.
Want the bottleneck removed without handing over a content archive?
Tell us the repetitive request or admin loop you want SHVL to handle first. We can shape the workflow around a privacy-safe execution path from the start.
Related pages: Data handling, Cookies & storage, Terms, and Accessibility.