LEGAL
Privacy Policy
Last updated: 1 June 2026
1. Who we are
VaultDrop Ltd is the data controller for personal information collected through vaultdrop.example. You can contact our privacy team at privacy@vaultdrop.example.
2. What we collect
- Contact details: name, email, phone, delivery address.
- Order data: products purchased, order value, payment status.
- Payment data: handled by our PCI-DSS compliant payment provider; we do not store card numbers.
- Account data: if you create an account, your password is stored securely hashed.
- Technical data: IP address, browser type, device, pages viewed.
- Age verification data: where required, the minimum information needed to confirm you are 18+.
3. Why we use it
- To process and deliver your order (contract).
- To verify your age and prevent fraud (legal obligation and legitimate interest).
- To respond to your queries (legitimate interest).
- To send marketing emails — only with your consent and only until you unsubscribe.
- To improve our website and services (legitimate interest).
4. Sharing
We share data only with: our payment processor, our delivery courier, our cloud hosting and analytics providers, and where required by law. We never sell your personal data.
5. Retention
Order records are kept for 6 years to satisfy UK tax law. Marketing data is kept until you withdraw consent. Technical data is kept for up to 24 months.
6. Your rights
Under the UK GDPR you have the right to access, rectify, erase, restrict or port your data, and to object to processing. To exercise any of these rights email privacy@vaultdrop.example. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
7. Cookies
We use strictly necessary cookies to operate the basket and checkout, and (with your consent) analytics cookies to improve the site. You can manage cookies through your browser settings.
8. International transfers
Where data is processed outside the UK, we rely on UK adequacy regulations or Standard Contractual Clauses.
9. Changes
We will post any updates to this policy on this page and, where material, notify you by email.