Effective date: 26 March 2026 · Applies to voca.co.nz and the Voca WhatsApp service
Voca is a WhatsApp-based invoice admin assistant for New Zealand sole traders. This policy explains what data we collect, how we use it, and how we protect it. We collect only what is necessary to run the service.
Voca is operated as a sole-trader software service based in New Zealand. For privacy enquiries, contact us at support@voca.co.nz.
This policy is governed by the New Zealand Privacy Act 2020. Where Voca processes personal information of individuals in the European Economic Area, the UK GDPR also applies.
| Category | What we collect | Why |
|---|---|---|
| Account details | Phone number (E.164 format), email address | Identify your account, send invoicing notifications |
| Voice recordings | Audio files you send via WhatsApp | Transcription and invoice extraction — audio is not stored after processing |
| Invoice content | Extracted invoice data: contact names, line items, amounts, dates | Create draft invoices in Xero on your behalf |
| Xero OAuth tokens | Access and refresh tokens for your Xero organisation | Authenticate with Xero to create and manage invoices |
| Subscription data | Stripe customer ID, subscription status, trial usage counter | Manage your subscription and enforce trial limits |
| Activity logs | Invoice creation metadata (transcript excerpt, contact name, total, Xero invoice ID) | Operational record-keeping — auto-deleted after 30 days |
We do not collect payment card details. Card processing is handled entirely by Stripe. We do not collect or store the content of text messages you send outside of the specific processing flows described above.
We do not use your data for advertising, profiling, or any purpose unrelated to running Voca.
Voca integrates with the following third parties to deliver the service. Each is bound by their own privacy policies.
| Service | Purpose | Data shared |
|---|---|---|
| Meta (WhatsApp) | Messaging platform for inbound voice notes and outbound notifications | Phone number, message content |
| Xero | Accounting platform — invoice creation and management | Invoice data, contact names, OAuth tokens |
| OpenAI | Audio transcription (Whisper) and invoice data extraction (GPT-4o-mini) | Audio recordings, transcribed text |
| Stripe | Subscription payment processing | Email address, phone number (as metadata) |
| Amazon Web Services (AWS) | Cloud infrastructure — compute, database, encryption key management | All data processed by Voca is hosted on AWS in the ap-southeast-2 (Sydney) region |
We do not sell your personal information to any third party.
| Data type | Retention period |
|---|---|
| Account record (phone, email, subscription status) | For the duration of your account. Deleted on request. |
| Xero OAuth tokens | For the duration of your Xero connection. Overwritten on reconnect; deleted when your account is deleted. |
| Voice recordings (audio) | Not retained. Discarded immediately after transcription. |
| Invoice activity logs | 30 days — automatically deleted by database TTL. |
| Stripe subscription data | Retained by Stripe per their data retention policy. Stripe customer ID retained on your account record. |
Under the New Zealand Privacy Act 2020, you have the right to:
To exercise any of these rights, email support@voca.co.nz. We will respond within 20 working days.
The Voca web portal does not use advertising cookies or third-party tracking. Google Fonts is loaded from Google's CDN for typography — no analytics or tracking cookies are set by Voca.
Voca is intended for use by business operators and sole traders. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
We may update this policy from time to time. If we make material changes, we will notify you via WhatsApp or email before they take effect. The effective date at the top of this page will always reflect the current version.
Questions or concerns?
Email us at support@voca.co.nz — we aim to respond within 2 business days.
You may also contact the Office of the Privacy Commissioner (New Zealand) at privacy.org.nz if you have an unresolved concern.