1. Data fiduciary / controller
the individual proprietor operating SubsVault determines how SubsVault processes personal data. Public privacy and grievance contact: Email: Not yet published · Phone: Not yet published.
2. Information collected
- Account data: name, email, password hash, verification/reset records, role, avatar and session information.
- Seller data: legal name, date of birth, store profile, email, phone, WhatsApp number, experience, approval history and payout information.
- Marketplace data: listings, buyer needs, budgets, prices, orders, coupons, complaints, reviews, commission and payout records.
- Communications: text, voice notes, images, files, credentials, edits, deletions, read receipts and presence activity in order chat.
- Security data: IP/device and server logs, rate-limit events, timestamps and incident records where generated.
3. Purposes
Data is used to create and secure accounts, verify email, review sellers, publish listings, operate orders and chat, deliver credentials, calculate balances, prevent abuse, resolve complaints, enforce policies, send service notifications and comply with lawful duties.
4. Service providers
Depending on configuration, data may be processed through PostgreSQL on the VPS, Brevo for email, Ably for realtime events, Cloudinary or S3-compatible storage for media, Upstash for rate limiting, Cloudflare Turnstile for abuse prevention and Better Stack for availability monitoring. Each provider receives only data reasonably needed for its function.
5. Credentials and chat
Credential payloads designated as protected are encrypted at rest using AES-256-GCM. Encryption at rest does not make unsafe or unlawful credentials permissible. Order participants and authorized administrators may access order communications for delivery, safety, complaints and evidence review. A user-facing deletion marker may not immediately erase backups, security evidence or a third-party stored object.
6. Retention
Data is kept only as reasonably needed for the listed purposes and legal obligations. Registration information, removed content and associated records may be preserved for at least 180 days where applicable, and longer when an order, complaint, fraud investigation, tax obligation, legal hold or lawful direction requires it. Backup deletion may be delayed by the backup cycle.
7. Security
SubsVault uses password hashing, secure sessions, role checks, encrypted credential storage, rate limiting and restricted administration. No internet system is risk-free. Report suspected compromise immediately and never place payment-card data, government-ID images or unnecessary sensitive information in chat.
8. User requests
You may request access, correction, account closure or deletion of eligible personal data through the support contact. Identity verification may be required. Some records cannot be deleted immediately because of security, fraud, transaction, evidence or legal-retention duties.
9. Children and changes
SubsVault is for persons aged 18 or older and is not intended for children. Material policy changes will be versioned and communicated where required. Continued transactional use may require fresh acceptance.