Not a substitute for legal advice. This policy accurately describes what Vaultform actually does today and names Virginia as the governing jurisdiction, but it has not been reviewed by a lawyer. Have qualified counsel confirm it before relying on it for compliance with GDPR, CCPA, HIPAA, or any other regulation applicable to your business.

Privacy Policy

Last updated: August 10, 2026

What we collect

When a business ("the Customer") uses Vaultform to request documents, we collect: the requesting business's account information (name, email); the documents and information uploaded by the people the Customer sends requests to ("End Users"), including files, typed confirmations, drawn signatures, and the email address used to verify a confirmation or signature; and technical data generated automatically, including IP address, timestamps, and basic browser information, for security and audit purposes.

How we use it

Uploaded files and information are used solely to fulfill the document request between the Customer and their End User — we do not use End User content for any other purpose, including marketing, analytics, or model training. Technical data (IP, timestamps) is used for security, fraud prevention, and to maintain the audit trail Vaultform provides to Customers as a core feature.

Automated scanning

Every uploaded file is automatically scanned for malware via a third-party scanning service before being made available to the Customer. This scan is signature-based; it reduces but does not eliminate the risk of malicious files, and should not be treated as a complete security guarantee.

Third parties we share data with (subprocessors)

We use the following third-party services to operate Vaultform. Each processes data only as necessary to provide their specific function:

  • Supabase — database and file storage hosting
  • Vercel — application hosting
  • VirusTotal — automated malware scanning of uploaded files
  • Resend — transactional email delivery (request notifications, verification codes)
  • Upstash (QStash) — background job processing for scanning
  • Google Drive, Microsoft OneDrive, Dropbox, Salesforce, HubSpot, Slack, Microsoft Teams — only if and when a Customer explicitly connects these integrations; data is shared only with the specific service the Customer chose to connect

We do not sell End User or Customer data to third parties, and we do not share it for advertising purposes.

Data retention and deletion

Files are automatically deleted 90 days after a document request is completed or cancelled. Metadata about the request (labels, statuses, timestamps, and the audit log) is retained after file deletion, since maintaining an accurate audit trail is a core part of what Vaultform provides to Customers — but the underlying file content itself is removed. A Customer or End User may request earlier deletion at any time by contacting the Customer's organization directly, or Vaultform via our contact page (support@vaultform.net).

Your rights

Depending on your location, you may have rights to access, correct, or delete your personal information, or to object to certain processing. To exercise these rights, contact us. If you are an End User (someone who received a document request), you may also need to contact the business that sent you the request, since they are the party that initiated collection of your information.

Security

Files are stored in access-controlled storage with no public URLs; viewing a file requires a short-lived signed link generated on demand. Every action on a request — upload, scan result, approval, rejection, export — is logged. Vaultform is not currently SOC 2, HIPAA, or GDPR certified.

Governing law

This policy is governed by the laws of the Commonwealth of Virginia, without regard to its conflict-of-law principles. See the same provision in our Terms of Service for how disputes are resolved.

Contact

Questions about this policy: contact us or email support@vaultform.net.