Privacy
Privacy policy
What we collect, why we collect it, how long we keep it, who else touches it, and the controls you hold over all of it.
- Effective
- 21 August 2026
- Last updated
- 21 August 2026
- Applies to
- [Legal Entity Name, a Texas company] and the MyVesta service
Draft pending legal review
This document is a working draft written in plain language to describe how MyVesta actually operates. It has not yet been reviewed by counsel and is not legal advice. Wording may change before it becomes binding. The operating company is still being formed in Texas, so the entity name shown as [Legal Entity Name, a Texas company] is a placeholder and will be replaced once formation completes. Texas law will govern. If anything here matters to a decision you are making, write to privacy@myvesta.io and we will tell you exactly where the draft stands.
1. Who we are and what this covers
[Legal Entity Name, a Texas company] (“MyVesta”, “we”, “us”) provides a private household information hub. This policy covers the MyVesta marketing site, the MyVesta application, and the email we send you. Our postal address is [Registered address], Texas, United States and privacy questions reach a person at privacy@myvesta.io.
For the personal data of our own customers — your account details, your billing records, the contents of your vault — MyVesta is the data controller. Where an organization deploys MyVesta to its own clients under a white-label agreement, that organization is the controller and MyVesta acts as its processor under the Data Processing Addendum.
Two things we want stated at the top, without hedging: we do not sell personal information, and we do not use the contents of customer vaults to train machine-learning models — ours or anyone else's.
2. What we collect
Information you give us
- Account details: your name, email address, household name, and a hashed form of your password. We never store your password itself.
- Vault content: everything you choose to record — insurance policies, medical details, financial accounts, property and vehicle records, inventory, contacts, estate and legal information, pet records and shared lists — together with any files you attach.
- Household members: the names and email addresses of people you invite, and the categories you grant them.
- Billing details: your name, billing address and subscription history. Card numbers go directly to Stripe and never reach our servers.
- Correspondence: the content of messages you send us through the contact form, the partner inquiry form, the affiliate application, or by email.
Information we collect automatically
- Activity log entries recording who viewed, created, changed or deleted each record in your household, with a timestamp.
- Security and operational logs: IP address, browser and device type, timestamps, and error traces.
- Sign-in events, including failed attempts, so we can detect account takeover attempts.
- Cookies, described in full in the Cookie Policy. The only non-essential cookie we set by default is none — analytics and the 60 days affiliate referral cookie are set only after you consent.
What we deliberately do not collect
- We do not buy personal data from brokers or append third-party profiles to your account.
- We do not run advertising trackers, social pixels or cross-site fingerprinting on any MyVesta page.
- We do not read your vault content for product analytics. Usage metrics count actions, never contents.
3. Why we use it, and our lawful basis
As a Texas-based company we follow applicable US state privacy laws, and where the EU or UK GDPR applies to you we must have a lawful basis for each purpose. Here is every purpose we have, and the basis we rely on.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the vault: storing, displaying and syncing your records and files | Account details, vault content, attachments | Performance of our contract with you |
| Account security: authentication, two-factor codes, password resets, fraud and abuse detection | Credentials, sign-in events, IP address, device data | Contract, and our legitimate interest in keeping accounts secure |
| Accountability: the household activity log | Member identity, record identifier, action, timestamp | Legitimate interest in giving households a verifiable record |
| Billing: taking payment, renewals, invoices, refunds | Name, email, billing address, subscription and payment metadata | Contract, and legal obligation for tax and accounting records |
| Support: answering your messages | Correspondence, account identifiers | Contract, and legitimate interest in supporting our users |
| Service email: verification, security alerts, renewal and trial notices | Name, email address | Contract, and legal obligation for certain security notices |
| Product improvement: aggregate, non-content usage metrics | Event counts, page views, error traces | Consent, via the analytics cookie category |
| Affiliate attribution: crediting a referral to the partner who sent you | Referral code, click timestamp, resulting sign-up and subscription | Consent, via the affiliate cookie category |
| Legal defense and compliance: responding to lawful requests, establishing or defending claims | Whatever the specific matter requires | Legal obligation, and legitimate interest in defending our rights |
Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing that already happened. Where we rely on legitimate interests we have weighed our interest against your rights, and you may object using the contact details below.
4. How long we keep it
| Data | Retention |
|---|---|
| Vault records and attachments | Until you delete them, or until your household is deleted |
| Deleted records and files | Purged from live systems immediately; encrypted backups holding them expire within 35 days |
| Account and household records | For the life of the account, then deleted on request or on household deletion |
| Deletion receipt | Kept indefinitely. It contains only a household identifier, the date, and the fact that deletion occurred — no personal content |
| Activity log | 24 months rolling, or until household deletion, whichever comes first |
| Security and operational logs | 90 days, then deleted or aggregated beyond identification |
| Billing and invoice records | 7 years, because tax law requires it |
| Support and inquiry correspondence | 24 months from the last message in the thread |
| Unverified or dormant unsubscribed accounts | Deleted after 365 days of inactivity, after we email you first |
| Email suppression records (bounces, unsubscribes) | Kept indefinitely, because forgetting them would mean emailing you again |
5. Who processes data on our behalf
We keep the list of sub-processors deliberately short. Each is bound by a written data processing agreement, may only act on our instructions, and is reviewed before we onboard them.
| Sub-processor | What they do | Data handled | Location |
|---|---|---|---|
| Supabase (database, authentication and file storage) | Hosts the application database, account credentials and file attachments | Account data, vault records, uploaded files, activity logs | European Union / United States |
| Cloudflare (application hosting and network) | Serves the application and protects it from abuse | IP address, request metadata, transport-level data | Global edge network |
| Stripe (payments) | Processes subscription payments and stores card details | Name, email, billing address, payment card details, invoices | United States / European Union |
| Managed email delivery (notify.myvesta.io) | Sends account, security and transactional email | Name, email address, message content of transactional email | European Union / United States |
We will publish changes to this list on this page before a new sub-processor starts handling personal data. Business customers under the Data Processing Addendum receive advance notice by email and may object.
Beyond these, we disclose personal data only in three situations: when you tell us to, when a law or valid court order compels us (we will tell you unless legally forbidden), and in the event of a merger or acquisition, in which case the acquirer inherits these commitments and you will be told before anything transfers.
6. International transfers
MyVesta customer data is stored primarily in the European Union. Some of our sub-processors operate in the United States, so personal data may be transferred there or to other countries where they run infrastructure.
Where data leaves the UK or the European Economic Area, we rely on one of the following: an adequacy decision covering the destination country, the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or the EU–US Data Privacy Framework where the recipient is certified. In every case we carry out a transfer risk assessment and apply encryption in transit and at rest.
You can request a copy of the transfer safeguards we rely on for any named sub-processor by writing to privacy@myvesta.io.
7. Your rights, and how to use them
- Access — ask what personal data we hold about you and receive a copy.
- Portability and export — export your entire vault as a structured file at any time, from your account settings, without asking us.
- Correction — fix anything inaccurate. Most fields you can edit yourself; write to us for the rest.
- Deletion — permanently delete your household, its files and its member accounts, from your account settings or by asking us.
- Restriction and objection — ask us to pause a particular use, or object to processing based on legitimate interests.
- Withdraw consent — change or withdraw cookie consent at any time from the cookie preferences link in the footer.
- Complain — to us first, we would hope, but you may go to your supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority in your country of residence.
How to exercise them
- Try your account settings first — export and deletion are self-service and immediate.
- Otherwise email privacy@myvesta.io from the address on your account, telling us which right you are exercising.
- We will acknowledge within 5 business days and respond in full within one month. If a request is genuinely complex we may extend by up to two further months, and we will tell you why within the first month.
- We may ask you to confirm your identity before acting, because handing your data to the wrong person would be worse than a slow reply. There is no charge unless a request is manifestly unfounded or repetitive.
If you use MyVesta through an organization's white-label deployment, that organization is the controller. Send your request to them; if it reaches us we will pass it on promptly and assist them in answering it.
8. Children's data
MyVesta is for adults. You must be at least 18 to create an account, and we do not knowingly allow anyone under that age to register or to be invited as a household member.
Households do commonly record information about their children — a child's medical details, school contacts, passport numbers. That data is yours to enter and yours to delete, it sits under the same encryption and household isolation as everything else, and we never use it for anything beyond providing the service to you.
If we learn that an account holder is under 18, we will delete the account and its data. If you believe a child has registered, tell us at privacy@myvesta.io and we will act quickly.
9. How we protect it
- Encrypted in transit with TLS, and encrypted at rest at the storage layer.
- File attachments live in a private bucket that is never publicly readable.
- Every record is bound to a household, and database-level row security makes it structurally impossible for one household to read another's data. Automated checks verify this, so isolation is tested rather than merely intended.
- A twelve-character minimum password policy with complexity requirements, and optional app-based two-factor authentication.
- Staff access to production is limited, logged, and granted only when needed to run or support the service.
The Security page describes all of this in more detail. If you believe you have found a vulnerability, report it responsibly to security@myvesta.io and we will acknowledge within 48 hours.
10. Referral and affiliate data
If you arrive through an affiliate link, and only if you have accepted the affiliate cookie category, we store a referral code in a first-party cookie for 60 days and record the click. If you then sign up, the code attaches to your account so the referring partner can be paid.
Affiliates never see your identity. Their dashboard at affiliates@myvesta.io's program shows counts — clicks, sign-ups, paid conversions and commission owed — not names, email addresses or anything about your household.
11. How we notify you of changes
When we change this policy we update the “last updated” date at the top and keep the previous version available on request.
- For minor changes — clarified wording, a corrected address, a formatting fix — the updated date is the notice.
- For material changes — a new purpose, a new category of data, a new sub-processor handling vault content, or any change that reduces your rights — we email every account holder at least 30 days before the change takes effect.
- Where a change requires your consent, we will ask for it rather than assume it. Continuing to use MyVesta after a material change means you accept the updated policy, and if you do not, you may export your vault and delete your household at any point.
Questions about this document? Write to privacy@myvesta.io or post to [Registered address], Texas, United States.
