Legal

Privacy Policy

Effective date: April 24, 2026 · Last updated: April 24, 2026

DRAFT — pending counsel review

This Privacy Policy describes how Vaultic Back Office ("Vaultic," "we," "us," or "our") collects, uses, shares, and protects information when you use our software-as-a-service platform and related services (the "Service"). We operate from Gallatin, Tennessee, USA.

The short version: We collect only what's needed to run the Service. Your transactional data belongs to you. We never sell it. We never use it to train AI models for anyone else.

1. Information We Collect

1.1 Account Information

When you sign up, we collect:

1.2 Payment Information

We never see, store, or process your credit card. All payment data is handled directly by Stripe, our payment processor. We receive only a Stripe customer identifier and subscription status. See Stripe's privacy policy at stripe.com/privacy.

1.3 Point-of-Sale and Operational Data

The Vaultic agent installed at your store uploads transaction data, shift reports, invoices, and inventory data to our servers so you can view analytics and generate reports. This data is encrypted in transit (TLS 1.3) and at rest.

1.4 Technical Information

We collect standard web server logs including IP address, browser user-agent, page URLs visited, timestamps, and error diagnostics. This helps us detect abuse, diagnose bugs, and improve performance.

1.5 Anti-Abuse Fingerprints

When you sign up, we store hashed (SHA-256, one-way) versions of your email and IP address in a "trial fingerprints" table to prevent fraudulent duplicate signups. We cannot reverse these hashes back to the original email or IP.

2. How We Use Your Information

3. Sub-Processors and Third-Party Services

To operate the Service, we share specific data with the following sub-processors. Each has its own privacy and security commitments.

ProviderPurposeData Shared
Stripe, Inc.
Payments
Subscription billing, payment method storageEmail, subscription status. No card data ever touches our servers.
Brevo (Sendinblue)
Transactional email
Welcome emails, password resets, trial warnings, contact form deliveryEmail address, message content
Anthropic, PBC
AI invoice scanning
Extract structured data from uploaded vendor invoicesInvoice images you upload to the Service (not customer transactions or card data)
DigitalOcean, LLC
Cloud hosting
Server hosting for the ServiceAll Service data, encrypted at rest
Cloudflare, Inc.
DNS and TLS
DNS resolution, TLS termination, DDoS mitigationRequest metadata (IP, user-agent, URL)

We do not share your data with advertisers, data brokers, or analytics companies. We do not use third-party tracking cookies for advertising.

4. What We Never Do

5. Data Security

We implement technical and organizational measures to protect your data:

6. Data Retention

We keep your data as long as your account is active. If you cancel your subscription:

You may request earlier deletion at any time by emailing support@vaulticbackoffice.com.

7. Your Rights

Regardless of jurisdiction, we honor the following rights for every user:

To exercise any of these rights, email support@vaulticbackoffice.com. We will respond within 30 days.

California (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of any "sale" of personal information. We do not sell personal information.

European Union (GDPR) and UK

If you are in the EU or UK, we process your data based on (a) contract necessity to deliver the Service, (b) legitimate interests in preventing fraud and securing the Service, and (c) your consent where applicable. You may lodge a complaint with your local data protection authority.

8. Cookies and Local Storage

We use a minimal set of cookies and browser storage:

We do not use third-party advertising, analytics, or tracking cookies.

9. Children

The Service is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

10. International Transfers

Our servers are located in the United States. If you use the Service from outside the US, your data will be transferred to the US for processing. By using the Service, you consent to this transfer. Brevo (EU-based) may process transactional email in the EU.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email to your account address at least 30 days before taking effect. We will also post the updated date at the top of this page.

12. Contact

Vaultic Back Office — Privacy Requests

Gallatin, Tennessee, United States

Email: support@vaulticbackoffice.com
Web: vaulticbackoffice.com/contact

This Privacy Policy is provided in draft form pending legal counsel review. If you require specific compliance documentation (DPA, SOC 2, etc.), please contact us.