Privacy Policy
Last updated 20 August 2026.
Who we are
MoveVault ("MoveVault", "we", "us") provides software-as-a-service for removals, storage and man-and-van companies ("account holders", "tenants"), quoting, booking, scheduling, payments, a branded website, and related CRM tools. Account holders in turn use MoveVault to manage their own customers' details. Contact us about privacy matters at hello@movevault.online.
Data we process, and why
We process two categories of personal data:
Account holder data, the removals company itself: business name, contact name, login email, and billing details, used to provide the account holder's subscription and let them log in and use the CRM.
End-customer data, entered by an account holder about their own customers, on their instruction: name, email, phone, address, moving-job details, photos taken during a move (e.g. condition reports, storage manifest photos), quotes, and payment status. For this data, the account holder is the data controller and MoveVault is a data processor acting on their instructions, if you're a customer of a removals company using MoveVault and have a query about your own data, please contact that company directly in the first instance.
Payments
Deposit, balance and storage payments are processed by Stripe. MoveVault does not store full card details. Stripe handles card data directly under its own PCI-compliant infrastructure. We store only payment status and the resulting transaction references.
Optional integrations
An account holder can optionally enable the following, each of which involves sharing relevant data with that third party for the specific purpose described:
- Text messaging, via Twilio. Sends and receives SMS with an account holder's customers.
- Xero and/or QuickBooks. When connected, invoice records (customer name, email, and line-item amounts) are sent to the account holder's own accounting organisation. This is one-directional: MoveVault writes invoice data to these platforms and does not read data back from them beyond what's needed to confirm the connection.
- Email delivery, via Resend, used to send quotes, booking confirmations, payment links and review requests on an account holder's behalf. The recipient's email address and the message content pass through Resend in order to deliver it.
Knowing whether an email was opened
Emails sent on an account holder's behalf contain a small, invisible image. When a mail programme loads it, we record that the message was opened, when, and the browser or mail client identifier ("user agent") that requested it. This is how the CRM shows an account holder whether their quote or invoice reached the customer.
This is approximate rather than proof of reading: mailbox providers and privacy proxies routinely fetch that image on a recipient's behalf whether or not a person ever opened the message, and clients that block images never fetch it at all even after a genuine read. We label those automated fetches as such rather than reporting them as reads. Recipients who would rather not be counted can turn off automatic image loading in their mail programme.
Addresses, distances and maps
To price a job by distance and show the route, postcodes entered into a quote are sent to third-party services: postcodes.io to turn a postcode into coordinates, and an OSRM routing service to measure the road distance between them. Postcodes are sent. Not names, and not full addresses.
Maps are drawn using tiles from OpenStreetMap. Where a map appears in a browser, that browser requests the map tiles directly from OpenStreetMap, which means OpenStreetMap receives the visitor's IP address as part of serving them. Maps placed inside PDFs are rendered on our own servers instead, so no request is made from the recipient's device.
The MoveVault app
MoveVault's iPhone and Android app is a second way into the same account. It stores and shows the same data as the web CRM, and adds no separate collection of its own.
With permission, the app uses the camera and photo library so staff can attach condition and job photos on site; those photos are uploaded to the account holder's own job records. Permission is asked for at the point of use and can be withdrawn in the device's settings. The signed-in session is held in the device's secure keychain. The app contains no advertising and no third-party analytics or tracking software.
Where data is held, and who else touches it
MoveVault runs on servers hosted by DigitalOcean in the United Kingdom, and account and customer records are stored there.
Where an account holder uses the AI writing tools to draft website or guide copy, the text of that request is sent to Anthropic to generate it. These tools are for an account holder's own marketing copy and are not used to process their customers' personal data.
Logins
An account can have several people signed in under their own individual logins, each with their own name and email address, so an account holder can see who did what. Passwords are stored only as a one-way hash and cannot be read back by us or by anyone else.
How long we keep data
We retain account and customer data for as long as an account is active, and for a reasonable period afterwards to meet accounting, legal and tax obligations. An account holder can request deletion of their account and associated data by contacting us.
Security
Data is encrypted in transit (HTTPS) between your browser, MoveVault's servers, and the third-party processors listed above. Passwords are stored hashed, never in plain text. Access to a tenant's data within MoveVault is scoped to that tenant only.
Your rights
Depending on your location, you may have rights to access, correct, or request deletion of your personal data. For data entered by a removals company about you as their customer, please contact that company first, as they control that data; for MoveVault's own account holder data, contact us at hello@movevault.online.
Changes to this policy
We may update this policy as MoveVault's features change. Material changes will be reflected by updating the date at the top of this page.