Privacy Policy
Version 1.2, effective 1 August 2026.
Who we are
VaultFerry is operated by [provider legal entity — to be completed before launch], [registered office — to be completed before launch] (the controller for the processing described in the “Our roles” section). Contact: privacy@vaultferry.com.
Our roles
- Processor — for the operational metadata generated when your clients access your links (access records, hashed IPs, regions, uploader identity, file metadata) and for your branding assets, we process on your behalf under the Data Processing Agreement; you are the controller.
- Controller — for your account data (email, subscription state, notification preferences, timezone, accepted-terms record, and any API keys you create), billing data, transactional emails, and the post-deletion security artifacts described under Retention, VaultFerry determines the purposes and is the controller. This policy is the Article 13 notice for that controller-side processing.
What we store
- Account. Your email address, your subscription state, your notification preferences, the IANA timezone your browser reports (captured when you save notification settings; used only to format email timestamps), the accepted-Terms version and date, an opaque subject identifier from our sign-in provider (Hanko), and — once you subscribe — a Stripe customer reference.
- Storage credentials. The credentials you provide for your own AWS S3 / Google Cloud Storage / Azure Blob buckets are encrypted with AES-256-GCM before they hit our database, and decrypted only in memory while a request is in flight. We never log them.
- API keys (Business plan). API keys are shown once at creation and cannot be retrieved afterward. We store a one-way hash of your key, never the key itself, together with the name you give the key and a short display prefix so you can recognise it in a list. Our security log records a key's internal identifier and that public prefix — never its name or any secret part of the key.
- Share links and downloads. We store the file path, the cached file name and size, the link's expiry and the bcrypt hash of its password (when the link is password-protected), and a count of downloads. For each download we keep an audit row with a one-way SHA-256 hash of the downloader's IP, their User-Agent header, and a success / failure flag. On Pro and Business plans the audit row also stores the approximate region — the country — derived from that IP; on Free it is left empty. There is no plaintext IP, no email address, and no name. For resumable downloads we also keep a download-session record (a hashed session token and refresh counters) until scheduled cleanup after the session window.
- Upload links and receipts. For file requests we store the link label, per-upload receipts (file name, size, timestamps, outcome), the uploader's name and email when — and only when — you enable “Require uploader identity”, a hashed IP per request, and password-attempt records (hashed IP + outcome) kept for 7 days. Connection and link display labels you type are stored with your configuration.
- Branding assets. On the Business plan, the logo you upload is stored in a VaultFerry-managed storage bucket (see the sub-processor registry) together with your company name, accent colour, and optional privacy-notice URL, and is displayed publicly on your branded pages.
Purposes and legal bases
- Providing the service (account, links, notifications settings) — performance of a contract (Art 6(1)(b)).
- Billing and tax records — legal obligation (Art 6(1)(c)) and contract.
- Transactional emails (subscription confirmations, security or deletion notices) — contract and legal obligation.
- Download/upload notification emails — our legitimate interest in delivering the product features you configure (Art 6(1)(f)); you can turn them off at any time in settings or via the unsubscribe link.
- Fraud prevention and security (deletion-audit record, replay-defence marker, rate-limit counters, API-key usage log) — our legitimate interests in preventing abuse and securing the service (Art 6(1)(f)).
- We do not sell personal data and run no advertising or analytics trackers.
How we process data
- Bytes never travel through our servers. When a client downloads one of your share links, we mint a short-lived pre-signed URL pointing at your own bucket and redirect the browser straight there. The file itself moves from your storage provider to your client — we don't see it.
- Country derivation and email notifications. On each public download and upload we process the accessor's IP address in memory to derive an approximate region — the country only. On Pro and Business plans that country is stored on the access record, and upload receipts persist the same field; on Free it is discarded. The IP itself is never written to durable storage or to our application logs; the infrastructure providers listed in the DPA's sub-processor annex may process it in transit and in their own edge or platform logs. That country is displayed only on Business-tier delivery receipts and activity, and Business customers can additionally enable an email when one of their share links is downloaded. Geolocation data provided by DB-IP under the CC-BY 4.0 license.
- Email reachability. Notification emails are sent through a transactional provider; the address used is the one on your account. There's a one-click unsubscribe link on every email and a toggle at
/settings/notifications. Either route silences the emails; your share links keep working unchanged. Business customers can also receive an upload notification when files arrive on a file-request link.
Recipients and sub-processors
Personal data is disclosed only to the sub-processors listed in Annex III of the DPA (hosting, database, edge network, authentication, email, billing, branding-asset storage, and application logging & uptime monitoring) and to no one else, except where the law requires disclosure or where you direct it: a tool you connect using one of your API keys receives the account and link data you route through it. Such a tool is chosen and instructed by you — it is not a VaultFerry sub-processor, and your use of that tool is governed by your agreement with it.
International transfers
Our database and backend are deployed in the EU (Amsterdam, Netherlands), though the hosting provider, Railway, is a United States-incorporated entity; several other sub-processors (edge network, email, billing, frontend hosting) are also United States entities. Transfers to them are made under the safeguards set out in the Data Processing Agreement — the EU Standard Contractual Clauses and, for UK data, the UK Addendum — or an applicable adequacy decision.
Cookies and local storage
hanko— the session cookie set by our sign-in provider's SDK; strictly necessary, lifetime bounded by the session.byos_theme,byos_mode— appearance preferences, set only when you pick a theme; kept for up to 2 years.- Stripe.js cookies (e.g.
__stripe_mid,__stripe_sid) — set on billing pages when the payment surface loads, used by Stripe for fraud prevention. - Our sign-in provider's SDK also keeps session-expiry bookkeeping in your browser's localStorage.
- We set no advertising or analytics cookies.
Retention
Audit rows are retained per your plan: 7 days on Free, 30 days on Pro, 365 days on Business. Terminated share and upload links (revoked, expired, or cap-exhausted) are purged 30 days after termination. Password-attempt records on upload links are kept for 7 days. Revoke an API key any time: revoked keys stop working immediately and their records are erased after 30 days. Billing event records are kept for 7 years, then deleted automatically. Residual copies of deleted rows can persist in encrypted backups for up to 7 days (disaster recovery only).
When you delete your account, VaultFerry permanently purges every row of your operational metadata, the encrypted cloud credentials, and your API keys — the keys you hold are revoked the moment deletion is scheduled, and their records (including the names you gave them) are purged with the account. Three items are handled separately: a deletion-audit record — a salted, non-reversible hash of your email address plus an internal reference and a timestamp, retained for 18 months under our legitimate interest in fraud-prevention and accountability, then purged; a replay-defence marker— an opaque identifier issued by our identity provider, not linked to your name or email within VaultFerry's systems, which we retain as a permanent security control to ensure a deleted account can never be re-animated by a stale session token; and billing and payment records— which may include the account email address and the last four digits of a payment card, contained in payment-processor (Stripe) event data — retained for the period required by applicable accounting and tax law, after which they are deleted; on deletion we redact the directly identifying fields from stored billing event records; the retained records keep the payment-processor customer reference (an opaque account identifier), and a corresponding customer record remains on Stripe's side, in each case for tax and chargeback history.
Your rights
You have the rights of access, rectification, erasure, restriction, portability, and objection over the personal data we control, and the right to withdraw consent where processing is based on it. Write to privacy@vaultferry.com— we respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority. For data we process on a customer's behalf (e.g. records about your download from someone's link), contact the sender — we route any request we receive to them.
Contact
Questions about this policy or about a specific data flow? Reply to any VaultFerry email or write to us at privacy@vaultferry.com. The terms that govern how we process this data are set out in our Data Processing Agreement, and your use of VaultFerry is governed by our Terms of Service.