Privacy Policy
Last updated: March 1, 2025
1. Introduction
At Vaultik, your privacy is not an afterthought — it's a core design principle. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have over it.
By using vaultik.com or any Vaultik service, you agree to the practices described in this policy.
2. Who We Are
Data Controller: Vaultik, Inc. 651 N Broad St, Suite 201 Middletown, DE 19709 United States 📧 privacy@vaultik.com
3. Data We Collect
3.1 Data you provide directly
Account information: name, work email, company name, password
Billing information: payment method details (processed securely via Stripe — we never store card numbers)
Communications: messages sent through our contact form, support tickets, or email
3.2 Data collected automatically
Usage data: pages visited, features used, session duration, clicks
Technical data: IP address, browser type and version, operating system, device type
Cookies and tracking: session cookies, analytics cookies (see Section 7)
3.3 Data from third-party integrations
When you connect a third-party application (e.g. GitHub, Slack, Google Workspace) to Vaultik, we access only the data necessary to perform the backup service. We do not read, analyze, or share this data for any other purpose.
4. How We Use Your Data
We use your data for the following purposes:
Providing and improving our services — Contract performance
Sending transactional emails (receipts, alerts) — Contract performance
Responding to support requests — Legitimate interest
Analyzing usage to improve the product — Legitimate interest
Sending product updates and newsletters — Consent
Complying with legal obligations — Legal obligation
We never sell your personal data to third parties. Ever.
5. Data Retention
We retain your personal data for as long as your account is active, or as long as necessary to fulfill the purposes outlined in this policy.
Account data: retained for the duration of your subscription + 30 days after cancellation
Backup data: deleted within 30 days of account termination
Billing records: retained for 7 years to comply with accounting regulations
Support communications: retained for 2 years
6. Data Sharing & Third Parties
We only share your data with trusted third-party service providers strictly necessary to operate our service:
Stripe — Payment processing
Amazon Web Services — Cloud infrastructure & storage
PostHog — Product analytics
Resend — Transactional emails
Intercom — Customer support
All third-party providers are contractually bound to process your data only on our behalf and in accordance with this policy.
7. Cookies
Vaultik uses cookies to ensure the proper functioning of our platform and to understand how our website is used.
Essential cookies — Authentication and session management — Session duration
Analytics cookies — Usage tracking via PostHog — 12 months
Preference cookies — Language and UI settings — 12 months
You can manage or disable cookies at any time through your browser settings. Note that disabling essential cookies may affect the functionality of the platform.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Right to access — Request a copy of the data we hold about you
Right to rectification — Request correction of inaccurate data
Right to erasure — Request deletion of your personal data
Right to portability — Receive your data in a structured, machine-readable format
Right to object — Object to certain types of data processing
Right to withdraw consent — At any time, for consent-based processing
To exercise any of these rights, contact us at privacy@vaultik.com. We will respond within 30 days.
9. Data Security
Vaultik implements industry-standard security measures to protect your data:
AES-256 encryption at rest and in transit
SOC 2 Type II certified infrastructure
Role-based access control for internal teams
Regular third-party security audits
Automatic threat detection and alerting
Despite these measures, no system is completely immune to risk. We encourage you to use a strong, unique password and enable two-factor authentication on your account.
10. International Data Transfers
Vaultik operates globally. If you are located in the European Union, your data may be transferred to and processed in the United States or other countries. In such cases, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
Enterprise customers may choose their data residency region (EU-only, US-only, or APAC) to restrict where their data is stored and processed.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of our services after changes take effect constitutes your acceptance of the updated policy.