Privacy Policy

Effective date: 26 March 2026  ·  Applies to voca.co.nz and the Voca WhatsApp service

Voca is a WhatsApp-based invoice admin assistant for New Zealand sole traders. This policy explains what data we collect, how we use it, and how we protect it. We collect only what is necessary to run the service.

1. Who we are

Voca is operated as a sole-trader software service based in New Zealand. For privacy enquiries, contact us at support@voca.co.nz.

This policy is governed by the New Zealand Privacy Act 2020. Where Voca processes personal information of individuals in the European Economic Area, the UK GDPR also applies.

2. Information we collect

Category What we collect Why
Account details Phone number (E.164 format), email address Identify your account, send invoicing notifications
Voice recordings Audio files you send via WhatsApp Transcription and invoice extraction — audio is not stored after processing
Invoice content Extracted invoice data: contact names, line items, amounts, dates Create draft invoices in Xero on your behalf
Xero OAuth tokens Access and refresh tokens for your Xero organisation Authenticate with Xero to create and manage invoices
Subscription data Stripe customer ID, subscription status, trial usage counter Manage your subscription and enforce trial limits
Activity logs Invoice creation metadata (transcript excerpt, contact name, total, Xero invoice ID) Operational record-keeping — auto-deleted after 30 days

We do not collect payment card details. Card processing is handled entirely by Stripe. We do not collect or store the content of text messages you send outside of the specific processing flows described above.

3. How we use your information

We do not use your data for advertising, profiling, or any purpose unrelated to running Voca.

4. Third-party services

Voca integrates with the following third parties to deliver the service. Each is bound by their own privacy policies.

Service Purpose Data shared
Meta (WhatsApp) Messaging platform for inbound voice notes and outbound notifications Phone number, message content
Xero Accounting platform — invoice creation and management Invoice data, contact names, OAuth tokens
OpenAI Audio transcription (Whisper) and invoice data extraction (GPT-4o-mini) Audio recordings, transcribed text
Stripe Subscription payment processing Email address, phone number (as metadata)
Amazon Web Services (AWS) Cloud infrastructure — compute, database, encryption key management All data processed by Voca is hosted on AWS in the ap-southeast-2 (Sydney) region

We do not sell your personal information to any third party.

5. Data storage and security

6. Data retention

Data type Retention period
Account record (phone, email, subscription status) For the duration of your account. Deleted on request.
Xero OAuth tokens For the duration of your Xero connection. Overwritten on reconnect; deleted when your account is deleted.
Voice recordings (audio) Not retained. Discarded immediately after transcription.
Invoice activity logs 30 days — automatically deleted by database TTL.
Stripe subscription data Retained by Stripe per their data retention policy. Stripe customer ID retained on your account record.

7. Your rights

Under the New Zealand Privacy Act 2020, you have the right to:

To exercise any of these rights, email support@voca.co.nz. We will respond within 20 working days.

8. Cookies and tracking

The Voca web portal does not use advertising cookies or third-party tracking. Google Fonts is loaded from Google's CDN for typography — no analytics or tracking cookies are set by Voca.

9. Children's privacy

Voca is intended for use by business operators and sole traders. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you via WhatsApp or email before they take effect. The effective date at the top of this page will always reflect the current version.

Questions or concerns?

Email us at support@voca.co.nz — we aim to respond within 2 business days.

You may also contact the Office of the Privacy Commissioner (New Zealand) at privacy.org.nz if you have an unresolved concern.