What we hold about you, and why.
A payment product cannot work without knowing who you are and what you spent. This is the whole of what we collect, who else sees it, and what you can make us do with it.
This policy
[LEGAL ENTITY] (“CardVault”, “we”, “us”) is the controller of the personal data described here. This policy covers the CardVault website, dashboard and cards.
It sits alongside the Terms & Conditions and forms part of them.
What we collect
We collect three kinds of data, and no more than each job needs:
- Account: your name, your email address, and your password, which is stored hashed.
- Identity, for a card issued in your name: date and place of birth, phone number, residential address, the type and number of the identity document you give us and a photograph of it, and your occupation, employment status, stated purpose for the account, annual income band and expected monthly volume.
- Cards and transactions: each card you create, its name, status and balance, and every authorisation, payment, fee and refund on it.
What the blockchain shows
Deposits reach us over a public network. The address we give you, every payment made to it, and the wallet that sent them are visible to anyone who looks and are recorded permanently.
That record is not ours. We cannot edit it, hide it or delete it, and a request to erase your data cannot reach it. Anyone who knows one of your addresses can see what has moved through it — which is worth knowing before you fund a card from a wallet that identifies you.
We do not sell your data
We do not sell personal data, and we do not share it with advertisers or data brokers. We do not use your transaction history to profile you for marketing.
How long we keep it
Account and transaction records are kept while your account is open and then for [RETENTION PERIOD] after it closes, because financial and anti-money-laundering rules require us to keep them.
Identity documents are kept for the period the same rules set, then deleted. Support messages are kept for two years. Technical logs are kept for 90 days.
How we protect it
Data is encrypted in transit and at rest. Passwords are hashed, never stored in a readable form, and two-factor authentication is available on every account.
Access inside our team is limited to the people whose job needs it, and is logged. No system is perfectly secure, but we will tell you and the relevant regulator without undue delay if a breach affects you.
Children
CardVault is not for anyone under 18. We do not knowingly collect data from children, and we delete it if we find we have.
Changes to this policy
We may update this policy. If a change materially affects how we use your data, we will tell you at least 30 days before it takes effect.
Contact
Privacy questions and rights requests go to [PRIVACY EMAIL]. Please write from the email address on your account so we can identify you.