Helping businesses spend smarter
← Back to Valyo

Privacy Policy

Version 3.0 · Last updated: 12 July 2026

This notice explains how MYSTARTUP LIMITED ("Valyo", "we", "our", "us") handles your personal data when you visit our website, create a member account, post to the community, or subscribe to our newsletter. It meets our obligations under the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

Who we are

  • Data controller: MYSTARTUP LIMITED
  • Registered office: 124 City Road, London, EC1V 2NX, United Kingdom
  • ICO registration number: ZB895726 (Tier 1, expires 05 May 2027)
  • Contact: now@joinvaylo.com

What data we collect

Depending on how you use Valyo, we may collect:

  • Account data: your name, email address and password (hashed).
  • Profile picture: if you choose to upload one, stored in a private storage bucket and shown alongside your community posts.
  • Saved deals: the deals you bookmark from your dashboard.
  • Community content: the posts, comments, likes and images you share on the community feed. Every post is reviewed by our team before it is published. Approved posts are visible to other signed-in Valyo members only — they appear on /community, are not shown to people who aren't signed in, and are not indexed by search engines. Each post is shown alongside your display name, your profile photo (if uploaded), the category and the date, so please don't post anything you wouldn't want other Valyo members to see linked to you. We can't stop another member copying or re-sharing your content outside Valyo. If you tick "Post as an anonymous member" when submitting a post or comment, we hide your display name and profile photo from other members and show the post as "Anonymous member" instead. This is pseudonymity, not full anonymity: we still store the link between the post and your account internally so our moderation team can enforce these terms, respond to complaints, and comply with legal requests. Anonymous posting is not available for the "Used an offer" category, where reviews must be attributable.
  • Offer email requests: when you use the "Email me this offer" button we record which deal, the recipient email, whether you were signed in, and the request time, as evidence that you asked for the email.
  • Marketing preferences: whether you've opted in to receive marketing emails, plus the date, source and exact wording of that consent.
  • Newsletter consent evidence: when you submit the newsletter form, your IP address and browser user-agent at the moment of opt-in.
  • Support correspondence: any messages you send to us via the contact form or email.
  • Strictly necessary cookie: a single session cookie used by our authentication provider to keep you signed in.

We do not knowingly collect personal data from anyone under 13.

Why we use it, and our lawful basis

Under UK GDPR we must have a lawful basis for every processing activity. Ours are:

  • Creating and operating your account · Contract (Art. 6(1)(b)) — we need your account data to provide the service you signed up for.
  • Community posts, avatars, likes and comments · Contract (Art. 6(1)(b)) — the community is part of the member service you signed up for.
  • Moderating community posts and handling abuse reports · Legitimate interests (Art. 6(1)(f)) — keeping the community safe, on-topic and free of spam.
  • Sending you an offer email you requested · Contract (Art. 6(1)(b)) — the "Email me this offer" action is a solicited service message, not marketing.
  • Sending marketing emails (deals, partner news, product updates) · Consent (Art. 6(1)(a) and PECR reg. 22) — only if you ticked the marketing box at signup or on the newsletter form.
  • Site security, fraud prevention and service improvement · Legitimate interests (Art. 6(1)(f)) — limited to what is necessary to keep Valyo safe and functional.
  • Meeting tax, accounting and other legal obligations · Legal obligation (Art. 6(1)(c)).

How long we keep it (retention)

We only keep personal data for as long as we need it. Our automated retention job runs daily and removes records that have passed their retention period.

  • Account data, saved deals, avatar: for as long as your account is active. Deleted when you close your account.
  • Community posts, comments and likes: visible while your account is active; removed when you delete your account or the post.
  • Offer email request logs: 90 days, then automatically deleted.
  • Contact form submissions: 12 months, then automatically deleted.
  • Resolved community abuse reports: 12 months after resolution, then automatically deleted.
  • Email delivery logs: 90 days, then automatically deleted.
  • Account deletion audit (hashed): 2 years, for accountability under Art. 5(2).
  • Newsletter consent records: while you are subscribed, plus up to 6 years after you unsubscribe (UK limitation period) so we can evidence consent if challenged.
  • Email suppression list (unsubscribes, bounces): kept indefinitely to make sure we never re-email you by mistake.

Who we share it with (our processors)

We do not sell your personal data. We use a small number of trusted processors to run the service, each under a written data-processing agreement:

  • Lovable — application hosting, build and delivery of this site.
  • Supabase — database, authentication and private file storage (accounts, saved deals, community content, avatars).
  • Mailgun — sends our transactional emails (welcome messages, requested offer emails, account notices) and, with your consent, marketing emails.
  • Legal or regulatory bodies: where we are required by law to disclose information.

Affiliate partner sites you click through to from Valyo are independent controllers; their own privacy notices apply once you leave our site.

Internal operational notifications: when you create a member account or subscribe to Valyo updates, a short internal notification (your email address, display name if provided, sign-up source, marketing opt-in status and timestamp) is sent to the Valyo team inbox so we can monitor service health, respond to onboarding issues and detect abuse. The lawful basis is our legitimate interest (UK GDPR Art. 6(1)(f)) in running the service safely. These notifications are not used for marketing.

International transfers

Some of our processors may store or process data outside the UK or European Economic Area, including in the United States. Where this happens we rely on UK GDPR safeguards: the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision made by the UK government. You can ask us for a copy of the safeguards in place by emailing now@joinvaylo.com.

Cookies

Valyo only sets strictly necessary cookies, which are exempt from the consent requirement under PECR reg. 6(4):

  • sb-…-auth-token — keeps you signed in to your member account. Removed when you sign out or clear your browser storage.

We do not currently use analytics, advertising or affiliate-tracking cookies. If that changes we will update this notice and introduce a cookie banner that lets you refuse non-essential cookies before any are set.

Marketing emails

If you tick the marketing consent box on the newsletter form or at signup, we'll email you Valyo deals, partner news and product updates. The lawful basis is your consent (UK GDPR Art. 6(1)(a) and PECR reg. 22).

When you opt in we record your email address, the date and time, the page you opted in from, the exact wording you agreed to, the version of that wording, and your IP address and browser user-agent, as proof that consent was freely given.

You can withdraw consent at any time by clicking the unsubscribe link in any marketing email, or by emailing now@joinvaylo.com. Withdrawing consent is as easy as giving it and won't affect any other service you receive from us.

'Email me this offer' — solicited service messages

When you click "Email me this offer" on a deal page we send that specific offer to the address you provide (or your account email, if you're signed in). This is a one-off service message you asked for; it is not marketing and does not require a marketing consent tick. We log the request (deal, email, timestamp) for 90 days for accountability, then it is automatically deleted.

On-site assistant ('Vay')

Our homepage assistant is a simple rule-based helper. It shows you buttons to pick your business type and returns matching deals from our catalogue. Your responses stay in your browser tab, are never sent to any server or third party, and are cleared automatically when you close the tab. No AI model is involved and no record of the conversation is kept. You can dismiss the assistant at any time; doing so is not recorded.

Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

Your rights

Under UK GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten") — you can do this yourself from your member dashboard, or by emailing us;
  • restrict or object to certain processing, including direct marketing;
  • data portability where applicable;
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  • complain to the Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, email now@joinvaylo.com from the email address on your account so we can verify it's you. We'll respond within one calendar month.

Deleting your account

You can permanently delete your account at any time from your dashboard, or by emailing now@joinvaylo.com. When you do:

  • Your profile, saved deals, avatar, community posts, comments, likes and contact submissions are removed.
  • Your newsletter subscription is switched to "unsubscribed" and your address is added to our suppression list so no further marketing can reach you.
  • A hashed record of the deletion (SHA-256 of your email, plus timestamp and any reason you supplied) is kept for 2 years for accountability. This hash cannot be reversed to identify you.

Data security

We use appropriate technical and organisational measures to protect your personal data, including encryption in transit (HTTPS/TLS), encryption at rest for our database and file storage, hashed passwords, role-based access controls, and row-level security policies that prevent users from accessing each other's data. Community media and avatars are stored in private buckets and served only via short-lived signed URLs. No system can be guaranteed fully secure, but we work to reduce the risk and will notify you and the ICO of any qualifying personal data breach within 72 hours as required by law.

Copyright and IP takedown

If you believe content on Valyo — including anything posted on the community — infringes your copyright, trade mark or other intellectual property rights, email now@joinvaylo.com with a description of the work, the URL where it appears on Valyo, your contact details, and confirmation that you're the rights holder or authorised to act for them. We aim to review takedown notices within 5 working days and will remove or restrict access to infringing content where the claim is valid. See our Community Guidelines for more.

Changes to this policy

We may update this policy from time to time. The version number and last-updated date at the top of this page will change. For material changes that affect how we use your personal data, we'll notify you by email or with a prominent notice on the site before the change takes effect.

Contact

  • Email: now@joinvaylo.com
  • Post: MYSTARTUP LIMITED, 124 City Road, London, EC1V 2NX