Skip to content

Privacy

Privacy policy

What we collect, why we collect it, how long we keep it, who else touches it, and the controls you hold over all of it.

Effective
21 August 2026
Last updated
21 August 2026
Applies to
[Legal Entity Name, a Texas company] and the MyVesta service

Draft pending legal review

This document is a working draft written in plain language to describe how MyVesta actually operates. It has not yet been reviewed by counsel and is not legal advice. Wording may change before it becomes binding. The operating company is still being formed in Texas, so the entity name shown as [Legal Entity Name, a Texas company] is a placeholder and will be replaced once formation completes. Texas law will govern. If anything here matters to a decision you are making, write to privacy@myvesta.io and we will tell you exactly where the draft stands.

1. Who we are and what this covers

[Legal Entity Name, a Texas company] (“MyVesta”, “we”, “us”) provides a private household information hub. This policy covers the MyVesta marketing site, the MyVesta application, and the email we send you. Our postal address is [Registered address], Texas, United States and privacy questions reach a person at privacy@myvesta.io.

For the personal data of our own customers — your account details, your billing records, the contents of your vault — MyVesta is the data controller. Where an organization deploys MyVesta to its own clients under a white-label agreement, that organization is the controller and MyVesta acts as its processor under the Data Processing Addendum.

Two things we want stated at the top, without hedging: we do not sell personal information, and we do not use the contents of customer vaults to train machine-learning models — ours or anyone else's.

2. What we collect

Information you give us

  • Account details: your name, email address, household name, and a hashed form of your password. We never store your password itself.
  • Vault content: everything you choose to record — insurance policies, medical details, financial accounts, property and vehicle records, inventory, contacts, estate and legal information, pet records and shared lists — together with any files you attach.
  • Household members: the names and email addresses of people you invite, and the categories you grant them.
  • Billing details: your name, billing address and subscription history. Card numbers go directly to Stripe and never reach our servers.
  • Correspondence: the content of messages you send us through the contact form, the partner inquiry form, the affiliate application, or by email.

Information we collect automatically

  • Activity log entries recording who viewed, created, changed or deleted each record in your household, with a timestamp.
  • Security and operational logs: IP address, browser and device type, timestamps, and error traces.
  • Sign-in events, including failed attempts, so we can detect account takeover attempts.
  • Cookies, described in full in the Cookie Policy. The only non-essential cookie we set by default is none — analytics and the 60 days affiliate referral cookie are set only after you consent.

What we deliberately do not collect

  • We do not buy personal data from brokers or append third-party profiles to your account.
  • We do not run advertising trackers, social pixels or cross-site fingerprinting on any MyVesta page.
  • We do not read your vault content for product analytics. Usage metrics count actions, never contents.

3. Why we use it, and our lawful basis

As a Texas-based company we follow applicable US state privacy laws, and where the EU or UK GDPR applies to you we must have a lawful basis for each purpose. Here is every purpose we have, and the basis we rely on.

PurposeData usedLawful basis
Providing the vault: storing, displaying and syncing your records and filesAccount details, vault content, attachmentsPerformance of our contract with you
Account security: authentication, two-factor codes, password resets, fraud and abuse detectionCredentials, sign-in events, IP address, device dataContract, and our legitimate interest in keeping accounts secure
Accountability: the household activity logMember identity, record identifier, action, timestampLegitimate interest in giving households a verifiable record
Billing: taking payment, renewals, invoices, refundsName, email, billing address, subscription and payment metadataContract, and legal obligation for tax and accounting records
Support: answering your messagesCorrespondence, account identifiersContract, and legitimate interest in supporting our users
Service email: verification, security alerts, renewal and trial noticesName, email addressContract, and legal obligation for certain security notices
Product improvement: aggregate, non-content usage metricsEvent counts, page views, error tracesConsent, via the analytics cookie category
Affiliate attribution: crediting a referral to the partner who sent youReferral code, click timestamp, resulting sign-up and subscriptionConsent, via the affiliate cookie category
Legal defense and compliance: responding to lawful requests, establishing or defending claimsWhatever the specific matter requiresLegal obligation, and legitimate interest in defending our rights

Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing that already happened. Where we rely on legitimate interests we have weighed our interest against your rights, and you may object using the contact details below.

4. How long we keep it

DataRetention
Vault records and attachmentsUntil you delete them, or until your household is deleted
Deleted records and filesPurged from live systems immediately; encrypted backups holding them expire within 35 days
Account and household recordsFor the life of the account, then deleted on request or on household deletion
Deletion receiptKept indefinitely. It contains only a household identifier, the date, and the fact that deletion occurred — no personal content
Activity log24 months rolling, or until household deletion, whichever comes first
Security and operational logs90 days, then deleted or aggregated beyond identification
Billing and invoice records7 years, because tax law requires it
Support and inquiry correspondence24 months from the last message in the thread
Unverified or dormant unsubscribed accountsDeleted after 365 days of inactivity, after we email you first
Email suppression records (bounces, unsubscribes)Kept indefinitely, because forgetting them would mean emailing you again

5. Who processes data on our behalf

We keep the list of sub-processors deliberately short. Each is bound by a written data processing agreement, may only act on our instructions, and is reviewed before we onboard them.

Sub-processorWhat they doData handledLocation
Supabase (database, authentication and file storage)Hosts the application database, account credentials and file attachmentsAccount data, vault records, uploaded files, activity logsEuropean Union / United States
Cloudflare (application hosting and network)Serves the application and protects it from abuseIP address, request metadata, transport-level dataGlobal edge network
Stripe (payments)Processes subscription payments and stores card detailsName, email, billing address, payment card details, invoicesUnited States / European Union
Managed email delivery (notify.myvesta.io)Sends account, security and transactional emailName, email address, message content of transactional emailEuropean Union / United States

We will publish changes to this list on this page before a new sub-processor starts handling personal data. Business customers under the Data Processing Addendum receive advance notice by email and may object.

Beyond these, we disclose personal data only in three situations: when you tell us to, when a law or valid court order compels us (we will tell you unless legally forbidden), and in the event of a merger or acquisition, in which case the acquirer inherits these commitments and you will be told before anything transfers.

6. International transfers

MyVesta customer data is stored primarily in the European Union. Some of our sub-processors operate in the United States, so personal data may be transferred there or to other countries where they run infrastructure.

Where data leaves the UK or the European Economic Area, we rely on one of the following: an adequacy decision covering the destination country, the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or the EU–US Data Privacy Framework where the recipient is certified. In every case we carry out a transfer risk assessment and apply encryption in transit and at rest.

You can request a copy of the transfer safeguards we rely on for any named sub-processor by writing to privacy@myvesta.io.

7. Your rights, and how to use them

  • Access — ask what personal data we hold about you and receive a copy.
  • Portability and export — export your entire vault as a structured file at any time, from your account settings, without asking us.
  • Correction — fix anything inaccurate. Most fields you can edit yourself; write to us for the rest.
  • Deletion — permanently delete your household, its files and its member accounts, from your account settings or by asking us.
  • Restriction and objection — ask us to pause a particular use, or object to processing based on legitimate interests.
  • Withdraw consent — change or withdraw cookie consent at any time from the cookie preferences link in the footer.
  • Complain — to us first, we would hope, but you may go to your supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority in your country of residence.

How to exercise them

  1. Try your account settings first — export and deletion are self-service and immediate.
  2. Otherwise email privacy@myvesta.io from the address on your account, telling us which right you are exercising.
  3. We will acknowledge within 5 business days and respond in full within one month. If a request is genuinely complex we may extend by up to two further months, and we will tell you why within the first month.
  4. We may ask you to confirm your identity before acting, because handing your data to the wrong person would be worse than a slow reply. There is no charge unless a request is manifestly unfounded or repetitive.

If you use MyVesta through an organization's white-label deployment, that organization is the controller. Send your request to them; if it reaches us we will pass it on promptly and assist them in answering it.

8. Children's data

MyVesta is for adults. You must be at least 18 to create an account, and we do not knowingly allow anyone under that age to register or to be invited as a household member.

Households do commonly record information about their children — a child's medical details, school contacts, passport numbers. That data is yours to enter and yours to delete, it sits under the same encryption and household isolation as everything else, and we never use it for anything beyond providing the service to you.

If we learn that an account holder is under 18, we will delete the account and its data. If you believe a child has registered, tell us at privacy@myvesta.io and we will act quickly.

9. How we protect it

  • Encrypted in transit with TLS, and encrypted at rest at the storage layer.
  • File attachments live in a private bucket that is never publicly readable.
  • Every record is bound to a household, and database-level row security makes it structurally impossible for one household to read another's data. Automated checks verify this, so isolation is tested rather than merely intended.
  • A twelve-character minimum password policy with complexity requirements, and optional app-based two-factor authentication.
  • Staff access to production is limited, logged, and granted only when needed to run or support the service.

The Security page describes all of this in more detail. If you believe you have found a vulnerability, report it responsibly to security@myvesta.io and we will acknowledge within 48 hours.

10. Referral and affiliate data

If you arrive through an affiliate link, and only if you have accepted the affiliate cookie category, we store a referral code in a first-party cookie for 60 days and record the click. If you then sign up, the code attaches to your account so the referring partner can be paid.

Affiliates never see your identity. Their dashboard at affiliates@myvesta.io's program shows counts — clicks, sign-ups, paid conversions and commission owed — not names, email addresses or anything about your household.

11. How we notify you of changes

When we change this policy we update the “last updated” date at the top and keep the previous version available on request.

  • For minor changes — clarified wording, a corrected address, a formatting fix — the updated date is the notice.
  • For material changes — a new purpose, a new category of data, a new sub-processor handling vault content, or any change that reduces your rights — we email every account holder at least 30 days before the change takes effect.
  • Where a change requires your consent, we will ask for it rather than assume it. Continuing to use MyVesta after a material change means you accept the updated policy, and if you do not, you may export your vault and delete your household at any point.

Questions about this document? Write to privacy@myvesta.io or post to [Registered address], Texas, United States.