Privacy Policy

How Vistra collects, uses, stores, and protects your personal information.

Last updated: 14 September 2026

1. Introduction

Vistra (“Vistra”, “we”, “us”, or “our”) provides a digital field reporting and inspection platform that helps businesses capture information, organise evidence, create reports, and collaborate with teams and clients.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you use our website, applications, software, and related services (“Services”).

By using Vistra Services, you acknowledge that you have read and understood this Privacy Policy.

2. Information we collect

We collect information necessary to provide, maintain, and improve our Services. The types of information we collect include:

2.1 Account information

When you create an account, we may collect:

  • Full name
  • Business name
  • Email address
  • Phone number
  • Password credentials
  • Account preferences
  • Subscription information
  • Billing details

2.2 Business information

Depending on how you use Vistra, we may collect:

  • Company details
  • Team member information
  • Project information
  • Client information entered by users
  • Inspection details
  • Property or site information
  • Report information

2.3 Uploaded content

Users may upload content including:

  • Photos
  • Videos
  • Documents
  • Inspection notes
  • Checklists
  • Measurements
  • Annotations
  • Comments
  • Reports
  • Attachments

Users remain responsible for ensuring they have appropriate rights and permissions to upload this information.

2.4 Photo capture details

Photos taken with the Vistra app camera are stamped and recorded with details that help prove when and where evidence was captured (“chain of custody”):

  • The date and time of capture
  • GPS coordinates, if you have allowed the app to use your location — location access is optional, and a photo is still captured without it
  • A description of the capturing device (make, model and operating system version)
  • A digital fingerprint (hash) of the image file, used to detect later changes

The time stamp, and the GPS coordinates when available, are printed onto the photo itself and appear in exported reports. Photos added from your gallery are not stamped, but are recorded as unverified imports with a file fingerprint. You can turn location access off at any time in your device settings.

2.5 Technical information

When you use our Services, we may automatically collect:

  • IP address
  • Browser type
  • Device information
  • Operating system
  • The version of the Vistra app installed on your device, so we can support you and tell you when an update is required
  • Usage activity
  • Login history

2.6 Crash and performance data

The Vistra app can send crash reports and performance measurements (for example how long a screen takes to load, or that a report failed to save) to our diagnostics provider (Firebase Crashlytics and Performance Monitoring). This is off by default and is only enabled for a signed-in account after you agree to it in the app. You can withdraw that consent in the app’s settings at any time. Diagnostics data contains device and app details and technical error information; it does not contain your report content or photos.

2.7 Push notification token

When you sign in to the Vistra app and allow notifications, a device notification token is stored against your account so we can deliver notifications to that device. The token is removed when you sign out.

2.8 Payment information

Payments may be processed through third-party payment providers. We do not store complete payment card numbers.

Payment providers may collect and process payment information according to their own privacy policies.

3. How we use information

We use collected information to:

  • Provide and operate Vistra Services
  • Create and manage user accounts
  • Generate inspection reports
  • Store and organise uploaded content
  • Provide AI-assisted features
  • Improve platform performance
  • Provide customer support
  • Process payments
  • Communicate important service updates
  • Send notifications about activity on your reports (see section 4)
  • Detect fraud, abuse, and security issues
  • Develop new features

4. Notifications and marketing

We send two kinds of notification, and treat them differently:

  • Service notifications — activity on your reports and account, such as a comment on a report you share, a report shared with you, a team invitation, a scheduled visit reminder, or a notice about your subscription. These are part of providing the Services. In the app they are delivered as push notifications after you allow notifications on your device; you can turn them off in the app’s settings or in your device settings.
  • Product news and offers — occasional tips, feature announcements and offers from Vistra. We only send these by push notification or email if you have opted in: the “Product news & offers” setting is off by default and is turned on only by you, in the app’s settings or in your account settings on the web. You can opt out again in the same place at any time, and we will stop sending them.

We do not sell your information, and we do not send marketing on behalf of third parties.

5. AI processing

Vistra includes AI-assisted features designed to help users create reports and organise information.

Depending on the feature used, uploaded content may be processed by artificial intelligence systems to:

  • Generate descriptions
  • Improve report wording
  • Categorise information
  • Assist with documentation workflows

AI-generated outputs may not always be accurate. Users remain responsible for reviewing and approving all information before sharing reports with clients or third parties.

Vistra does not replace professional inspection judgement or human review.

6. Ownership of uploaded data

Users retain ownership of content uploaded to Vistra. We do not claim ownership of:

  • Inspection photos
  • Reports
  • Documents
  • Business records
  • Client information uploaded by users

Users grant Vistra a limited licence to process, store, and transmit uploaded content only as necessary to provide the Services.

7. How we share information

We may share information with:

Service providers

Trusted third parties that help us operate our platform, including:

  • Cloud hosting providers
  • Payment processors
  • Analytics providers
  • Crash reporting and performance monitoring providers (with your consent, see section 2.6)
  • Push notification delivery services (Firebase Cloud Messaging, and Apple’s notification service on iOS)
  • Email providers
  • Customer support systems
  • AI service providers

These providers are only permitted to process information necessary to provide their services.

Business transfers

If Vistra is involved in a merger, acquisition, asset sale, or business restructuring, information may be transferred as part of that transaction.

Legal requirements

We may disclose information when required to:

  • Comply with applicable laws
  • Respond to legal requests
  • Protect our rights
  • Prevent fraud or security threats

8. Data storage and security

We use reasonable technical and organisational measures to protect information. Security measures may include:

  • Encryption during transmission
  • Secure cloud infrastructure
  • Access controls
  • Authentication protections
  • Monitoring systems
  • Backup procedures

However, no internet-based service can guarantee absolute security. See our Security page for more detail.

9. Data retention

We retain information only for as long as necessary to:

  • Provide Services
  • Meet legal obligations
  • Resolve disputes
  • Enforce agreements

When information is no longer required, we may delete or anonymise it.

If your account is inactive for 90 consecutive days, your account and associated data are automatically and permanently deleted. Some records are retained for longer where the law requires it (for example billing records) — see Delete your account & data.

10. User rights

Depending on your location, you may have rights including:

  • Accessing your personal information
  • Correcting inaccurate information
  • Requesting deletion
  • Restricting processing
  • Exporting your information
  • Withdrawing consent where applicable — for example location access, diagnostics, or product news and offers, each of which you control in the app or device settings

Requests can be submitted through our support channels. To remove your account, see Delete your account & data.

11. International data transfers

Your information may be processed in countries where our service providers operate. Where required, we use appropriate safeguards for international transfers.

12. Children’s privacy

Vistra is designed for business users. We do not knowingly collect personal information from children under applicable legal age requirements.

13. Cookies

We use cookies and similar technologies as described in our Cookie Policy.

14. Third-party links

Our Services may contain links to third-party websites. We are not responsible for the privacy practices or content of external services.

15. Changes to this Privacy Policy

We may update this Privacy Policy periodically. Changes become effective when published on this page.

16. Contact us

For privacy-related questions:

Questions about this policy? Contact us or email hello@vistra.report.