Solvo

Legal

Privacy policy

What we process, why, with whom, and what you can require of us.

Last revised: 2026-09-13

1. Controller

Solvo is the operator of this service.

2. The principle: without an account, nothing leaves your browser

The calculators, the rent ledger, the deal pipeline and the practice book all run entirely in your browser, stored in the device's local storage. Without an account, none of it reaches our servers.

Only when you create an account and sync is enabled is your book also stored in our database, so you can open it on another device.

3. What we process

Account: your email address and, if you give it, your name. That is what a passwordless sign-in link and talking to you require.

Book (only with sync enabled): the properties, tenancies, transactions, mortgages, documents and receipts you enter, plus the tax profile you set at the start.

Saved calculations: when you ask us to email a calculation, we store the inputs, the result and the address you gave.

Subscription: your Stripe customer and subscription identifiers, plan, status and renewal date. Card details are handled by Stripe and never pass through us.

Bank connection (optional): the consent identifier at the provider, the bank's name, the list of accounts with the last four digits of the IBAN, and the transactions the bank reports. We do not store full IBANs or your banking credentials, which are entered only at the licensed provider.

Photographs of invoices: both the QR reading and the optical reading happen entirely in your browser. The image is not sent to us or to anyone else — what is downloaded is the text-recognition model, not your invoice.

Technical logs: the host records requests (IP address, time, route) for security and diagnostics.

4. On what basis

Performance of the contract: account, sync, subscription, bank connection, and the receipts and service alerts tied to them.

Legitimate interests: security, abuse prevention and technical maintenance, including host logs.

Consent: connecting your bank account, which you authorise at the provider and can revoke at any time, and deadline emails, which you can switch off in your account.

Legal obligation: retention of billing records.

5. Who processes data for us

Hosting and application runtime: Vercel.

Database: the managed PostgreSQL provider configured for the installation.

Transactional email (sign-in links, deadline alerts, renewal notices): Resend.

Payments and invoicing: Stripe, which acts as its own controller for payment data.

Bank data (if you connect a bank): Tink, licensed for account information services under PSD2.

We use Vercel's traffic analytics, which tells us how many visits each page had. It sets no cookies, does not follow you off this site, and builds no profile: the identifier that separates one visit from another is derived from the request and changes every day.

We use no advertising and no third-party tracking tools.

6. Cookies

We set one session cookie, strictly necessary to keep you signed in. The traffic analytics set no cookies and store nothing on your device, which is why you are not shown a consent banner.

Stripe's checkout, when you open it, sets Stripe's own cookies on Stripe's domain.

7. How long we keep it

Account and book: while the account exists. If you close it, we delete or anonymise within 30 days, except what we must retain by law.

Bank transactions in the review queue: we keep the transaction identifier even after it is dealt with, so the same payment is never offered to you twice.

Billing: for the statutory retention period.

Technical logs: a short period set by the host.

8. Your rights

You may request access, rectification, erasure, restriction, objection and portability, and withdraw consent where consent is the basis. Write to the address in section 1.

You can export your book at any time, without asking us, from settings.

If you believe we process your data improperly, you may complain to the Portuguese data protection authority, CNPD (www.cnpd.pt).

9. Security and transfers

Credentials for bank data access are stored encrypted (AES-256-GCM) and session identifiers are signed. Database access is restricted to the application.

Some processors may handle data outside the European Economic Area; where they do, GDPR safeguards apply, in particular standard contractual clauses.

10. Changes

If this policy changes materially we will say so in the service or by email. The date of the last revision is at the top of this page.


2026 rules, verifiedThe tables are checked against the legislation in force, and the rule version appears on every result.
Every number says where it came fromNo result appears without the law behind it and a plain statement of what it assumed.
Your data is yoursThe book lives in your browser. Without an account nothing leaves the device; with one, you can export everything whenever you like.