Privacy Policy

Last updated: September 18, 2026

This Privacy Policy describes how Abaza Business Services ("we", "us", or "our") collects, uses, and protects information when you use The Vault application and website (collectively, the "Service") available at myvaults.io and app.myvaults.io.

We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, and all applicable privacy laws.

1. Data Controller

The data controller for personal data processed through the Service is:
Abaza Business Services
Email: cards@myvaults.io

2. What Data We Collect

We collect only the data necessary to provide and improve the Service:

We do not collect payment information. We do not sell your personal data.

3. Legal Basis for Processing (GDPR)

We process your personal data under the following lawful bases:

4. How We Use Your Data

5. Public Profiles, the Feed and Reactions

Your collection is public by default. The Vault is a place collectors show each other what they own, so when you create an account your collection is visible to other people and you can make it private whenever you want. We tell you this on the sign-up screen, before you create the account, and the switch is in profile settings under Public profile.

Every account is given a web address in the form myvaults.io/u/yourhandle. The handle is generated for you and is never built from your name or your email address; you can change it to anything you like. A public page is public: anyone with the link can open it without an account, and search engines and other people may copy, cache or screenshot what is on it. Please treat anything you publish as permanently out of your hands.

While your collection is public, the page and the collectors' feed show:

Your email address is never shown — not on your profile, not in the feed, and not in your handle. If your display name happens to be an email address, we do not publish it; we show your handle instead.

The feed. Cards you add appear in a feed that other collectors see, with your handle and display name attached. Making your collection private removes them from it.

Making it private. Switching your profile off takes the page down and removes your cards from the feed immediately. Copies already made by search engines, caches or other people are outside our control.

Handles. If you change your handle, the old one keeps pointing at your profile for 30 days so that links people have already shared do not break, and is reserved for that period so nobody can immediately take it and inherit your traffic. After 30 days it becomes available again.

Reactions. Reacting to someone's card records that your account gave that reaction, so that you can take it back and so the same reaction cannot be counted twice.

The collector you react to sees your name. They receive a notification naming you and the card, and if your own collection is public they can open it from there. Everyone else sees only the total for each reaction: we do not publish a list of who reacted to what, and the counts shown on a public page are never attributed. If you would rather not be seen, do not react.

Reactions given before 17 September 2026 were given while reactions were anonymous, and they notify nobody. Only reactions from that date onward carry your name.

Reports. You can report a profile, a card in the feed, or a comment. We store the report and which account filed it, so that we can act on it and so that the reporting tool cannot be abused. Reports are readable only by us.

6. Data Retention and Account Deletion

We retain your account and collection data for as long as your account is active.

If you delete your account, then within 30 days, except where we are required to keep something by law:

Server logs are retained for up to 90 days for security and debugging purposes.

To delete your account, see Delete your account.

7. Cookies and Tracking

The website uses minimal cookies:

You can disable analytics cookies in your browser settings at any time without affecting core functionality.

8. Third-Party Services

We use the following third-party services to operate the Service. Each acts as a data processor under appropriate agreements:

9. International Transfers

Some of our third-party providers are based in the United States. Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including reliance on Standard Contractual Clauses (SCCs) or certification schemes such as the EU-US Data Privacy Framework.

10. Your Rights (GDPR)

Under the GDPR and UK GDPR, you have the following rights:

To exercise any of these rights, please contact us at cards@myvaults.io. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK, or your national supervisory authority in the EU).

11. Data Security

We implement industry-standard security measures including HTTPS encryption in transit, Firebase Security Rules restricting data access to authenticated owners, and regular review of access controls. Collections are private to their owner by default, and only the cards on a profile you have switched on are readable without signing in. No method of transmission over the internet is 100% secure, but we take reasonable steps to protect your data.

12. Children's Privacy

The Service is not directed at children under the age of 13 (or 16 where applicable under local law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes your acceptance of the updated policy.

Privacy enquiries & data requests

Email: cards@myvaults.io

We aim to respond to all privacy requests within 30 days.