Legal
Privacy Policy
Last updated: July 22, 2026
This Privacy Notice for Vatforge AB (doing business as VatForge) ("we", "us", "our") describes how and why we may access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://vatforge.com or any website of ours that links to this Privacy Notice.
- Use VatForge — a subscription SaaS platform designed for EU-based digital creators, freelancers, consultants, and small SaaS companies with annual revenue between €10,000 and €500,000.
- Engage with us in other related ways, including marketing or events.
The service aggregates revenue data from connected platforms including Stripe, Gumroad, Lemon Squeezy, Patreon, and Substack. It then:
- Tracks the €10,000 pan-EU cross-border B2C threshold under Article 59c. Crossing this threshold changes the place-of-supply treatment: from that point on, destination-country VAT rates apply to your cross-border B2C digital sales. OSS is the optional EU-wide simplification for declaring destination-country VAT; VatForge helps you determine when destination-country VAT treatment applies and prepares your OSS return.
- Applies correct VAT rates across the 27 EU member states based on transaction date and customer location, using Vatstack for rates and ECB for FX conversion.
- Generates quarterly OSS return exports in formats accepted by national tax authorities (Sweden, Germany, Netherlands, Belgium, and France at launch, with additional MSI countries added based on customer demand).
- Monitors CESOP (Central Electronic System of Payment information) exposure, flagging payees who receive more than 25 cross-border payments per quarter.
- Maintains a 10-year audit-ready record of all transactions, VAT calculations, and supporting evidence of customer location.
VatForge operates as compliance software only. We do not provide tax advice, do not file returns on behalf of customers, do not act as a fiscal representative under EU VAT law, and do not guarantee the correctness of any calculation for a customer's specific circumstances. Customers remain responsible for reviewing and approving all filings before submission and for consulting qualified tax advisors for complex situations.
Questions or concerns? If you do not agree with our policies and practices, please do not use the Services. For questions, contact privacy@vatforge.com.
1. What information do we collect?
Personal information you disclose to us
- Names
- Email addresses
- Contact preferences
- Contact or authentication data
- Billing addresses
- Business registration details (company name and Swedish organisationsnummer used for customer invoicing)
- VAT registration number used on VatForge-issued invoices
- Business / VAT context preferences (seller country, fiscal year, OSS registration status) — used to configure the customer's compliance workflow
We do not process sensitive information.
Payment data. Payment processing is handled exclusively by Stripe, Inc. (and its EU subsidiary Stripe Payments Europe Limited for EU users). VatForge does NOT store, process, or have access to card numbers, CVV codes, or any other sensitive card data. See Stripe's privacy notice at https://stripe.com/en-se/privacy.
When you make a payment, you are redirected to Stripe's hosted checkout page on Stripe's own infrastructure. Stripe maintains PCI DSS Level 1 compliance. From Stripe, VatForge only receives: payment status (successful, failed, refunded); the last four digits of your card (for receipts); billing address and email; and invoice / transaction metadata.
For EU users, Stripe processes data within the EU (Stripe Payments Europe Limited, Ireland) in accordance with GDPR. A Data Processing Agreement between VatForge and Stripe is in place.
Information collected automatically. When you visit or use the Services we automatically collect log / usage data, device data, and approximate location data (IP-based). This is used for security, operation, and internal analytics. We also use cookies as described in our Cookie Notice at https://vatforge.com/cookies.
2. How do we process your information?
- To facilitate account creation, authentication, and account management.
- To deliver and facilitate delivery of the Services.
- To respond to user inquiries and provide support.
- To send administrative information (terms, policies, service notices).
- To fulfill and manage orders, payments, and invoices.
- To request feedback and improve the Services.
- To protect our Services, including fraud monitoring and prevention.
- To identify usage trends and determine the effectiveness of marketing.
- To save or protect an individual's vital interests where necessary.
- To ingest transaction data from your authorized platform connections (Stripe, Gumroad, Lemon Squeezy, Patreon, Substack, and others) into a unified ledger supporting VAT determination and OSS preparation.
- To determine applicable VAT rates per transaction using buyer country, transaction date, product category, and B2C/B2B status, with evidence-of-location data required under the EU VAT Directive.
- To generate quarterly OSS return exports in formats accepted by national tax authorities, which you submit via the relevant national OSS portal.
- To monitor CESOP compliance exposure by counting and flagging cross-border payments per quarter.
- To maintain audit-ready transaction records for 10 years as required under EU OSS rules and Swedish Bokföringslagen.
- For security incident response and audit logs (ledger_events) — retained 10 years.
- For our own financial record-keeping (subscription invoices, support interactions, internal reporting) — retained at least 7 years per Bokföringslagen.
3. What legal bases do we rely on?
Under GDPR and UK GDPR we rely on the following legal bases:
- Consent — which you can withdraw at any time.
- Performance of a contract — to provide the Services to you.
- Legitimate interests — e.g. analyzing usage, supporting marketing, diagnosing problems, and preventing fraud.
- Legal obligations — e.g. cooperation with regulators, defending legal rights, statutory record-keeping.
- Vital interests — to protect any person's safety where necessary.
4. When and with whom do we share personal information?
We share information with vendors and service providers under contract:
- Cloud computing — Supabase
- VAT rates & FX — Vatstack and the European Central Bank
- Invoice and billing — Stripe
- Authentication — Supabase Auth (passwordless magic-link)
- Web analytics — Plausible (privacy-friendly, cookieless)
- Website hosting — Lovable
- Daily foreign exchange reference rates — European Central Bank (ecb.europa.eu); public data feed, no personal information sent
- Email hosting — Zoho Corporation Pvt. Ltd. (zoho.com/mail) for info@vatforge.com, hello@vatforge.com and aliases (EU data residency)
- Transactional email — Resend (EU data residency), for VAT rate approval-gate proposals to approvers and customer notifications
We may also share information in connection with a business transfer (merger, sale of assets, financing, or acquisition).
5. Do we use cookies and other tracking technologies?
We use cookies and similar technologies to maintain security, prevent crashes, fix bugs, save preferences, and assist basic site functions. Details and choices are in our Cookie Notice at https://vatforge.com/cookies.
6. Is your information transferred internationally?
Our servers are located in Ireland. Your information may also be processed in facilities in Ireland, Germany, Sweden, Denmark, the United States, and other countries where our service providers operate.
Where required, we rely on the European Commission's Standard Contractual Clauses (SCCs) to safeguard transfers from the EEA, UK, or Switzerland. Copies of the SCCs are available on request.
7. How long do we keep your information?
We retain personal information only as long as necessary for the purposes described, unless a longer retention period is required by law (e.g. tax, accounting). No purpose requires retention longer than 120 months past account termination, except where legally required (10-year OSS audit retention; 7-year Bokföringslagen retention).
8. How do we keep your information safe?
We implement appropriate technical and organizational security measures. However, no transmission over the internet or storage technology can be guaranteed 100% secure.
9. Do we collect information from minors?
We do not knowingly collect data from or market to children under 18. If you believe we have collected data from a minor, contact info@vatforge.com.
10. What are your privacy rights?
In the EEA, UK, and Switzerland you have rights to access, rectify, erase, restrict processing, port your data, and object to processing, including a right not to be subject to automated decision-making. You can complain to your Member State data protection authority or the UK ICO. In Switzerland, contact the FDPIC.
Withdrawing consent. Where we rely on consent, you may withdraw it at any time. This does not affect prior lawful processing.
Marketing opt-out. Use the unsubscribe link in our emails, change preferences in Settings → Notifications, or email privacy@vatforge.com. We may still send service-related messages necessary for your account.
Account deletion. You can delete your account from Settings → Data. A 30-day grace period allows reactivation. After 30 days, personal account data is hard- deleted. Transaction data is retained 10 years per EU OSS legal obligations but is anonymized after the grace period.
11. Controls for Do-Not-Track features
No uniform DNT standard has been finalized. We do not currently respond to DNT browser signals.
12. Data controller and processor roles
VatForge acts as Data Controller for information about our direct users (account, billing, authentication data). VatForge acts as Data Processor for personal information contained within transactions you ingest from your connected revenue platforms (your customers' email, billing address, country code), where you remain the Data Controller. This is formalized in our Data Processing Agreement (DPA), which incorporates the EU Standard Contractual Clauses where applicable and is available to business customers on request.
Users acting as Data Controllers of their own customers' information are responsible for meeting their own GDPR obligations (lawful basis, transparency notice, data subject rights). VatForge provides the tooling and transparency mechanisms to support these obligations.
13. Do we make updates to this notice?
We may update this Privacy Notice from time to time. The updated version will be indicated by a revised "Last updated" date.
14. How can you contact us about this notice?
Email info@vatforge.com or write to us at:
Vatforge AB
Vasagränd 13
177 53 Järfälla, Stockholms län
Sweden
15. How can you review, update, or delete your data?
To request access, correction, or deletion of your personal information, email privacy@vatforge.com.