Privacy Policy

Last updated: 2026-05-03

Zero-Knowledge by design. Privacy Vault is a zero-knowledge multichannel retention platform. We process customer signals on behalf of merchants but possess no technical capability to access personally identifiable information (PII) in intelligible form. All PII is hashed with SHA-256 + a salt unique to each merchant; the salt itself lives inside an envelope-encrypted enclave (the "Dark Chamber"). Even if subpoenaed, we cannot produce plaintext we never stored. Patent BR 10 2025 022120 9 covers this architecture.

1. Who we are

Privacy Vault Technologies LLC ("Privacy Vault", "we", "us", "our") is a Florida limited liability company headquartered in Doral, Florida, USA. We operate the Privacy Vault platform — a privacy-by-architecture customer retention service for e-commerce merchants. This Privacy Policy explains how we collect, process, store, and protect personal data when:

2. Roles under GDPR / LGPD

ScenarioPrivacy Vault roleOther party
Visit to privacyvault.techController
Customer of a merchant who installed our platformProcessor (sub-processor under Shopify DPA)Merchant = Controller
Merchant using our portalController (admin email, billing data) + Processor (customer data on merchant's behalf)Merchant = Controller of their customer data

3. What data we process

3.1 Public website (privacyvault.tech)

3.2 Platform usage (merchant-side data)

When a merchant installs Privacy Vault, we receive customer signals from their store (Shopify, VTEX, Nuvemshop, etc.) so we can deliver retention messaging. We immediately hash all PII at the entry point. What we actually store:

Channels: Email (via AWS SES), WhatsApp (via Meta Cloud API), Web Push, On-site Banners. We do not use SMS — removed by an internal AI Council decision (DEC-004) because SMS lacks end-to-end encryption.

3.3 Merchant portal data

4. Lawful basis (GDPR Art. 6 / LGPD Art. 7)

5. The Dark Chamber: how zero-knowledge actually works

Privacy Vault implements Zero-Knowledge Vendor Architecture (ZKVA), covered by patent BR 10 2025 022120 9. Three architectural commitments make us materially unable to read merchant customer data:

  1. Per-merchant salt isolation. Each merchant's PII hashing uses a salt that exists only inside their tenant-isolated D1 database, encrypted at rest. Cross-merchant lookups are mathematically impossible.
  2. Blind Dispatcher. The central router that handles requests has zero database bindings. It cannot read tenant data — verifiable in 30 seconds via Cloudflare's binding inspector.
  3. Dark Chamber enclave. Decrypt operations require the merchant's owner-controlled key. The owner "lights the chamber" when explicitly authorizing access. Privacy Vault employees cannot unilaterally decrypt customer data — there is no master key.

What this means for you:

6. Sub-processors

We use the following sub-processors. All have signed DPAs and meet GDPR Art. 28 / LGPD Art. 39 requirements:

ProviderPurposeRegion
Cloudflare, Inc.Compute (Workers), storage (D1, KV, R2), DNS, WAFGlobal edge (200+ POPs)
Amazon Web Services (SES, S3 archive)Email delivery, log archiveus-east-1 / sa-east-1
Meta Platforms (WhatsApp Cloud API)WhatsApp message delivery (when merchant opts in)USA / EU
Anthropic, Inc.AI Council (technical decision support — never customer data)USA

A current list is available on request to admin@privacyvault.tech.

7. Retention

8. Your rights (GDPR Art. 15-22 / LGPD Art. 18)

You have the right to access, rectify, erase, restrict processing, port, and object to processing of your personal data, plus the right to lodge a complaint with a supervisory authority (e.g., ANPD in Brazil, your local DPA in the EU).

Two paths to exercise these rights:

  1. If you are a customer of a merchant who uses Privacy Vault, contact the merchant directly. They are the controller of your data. Privacy Vault will assist as a processor within 72 hours of receiving the merchant's instruction (Data Subject Access Request handler).
  2. If you are a merchant or a website visitor, write to admin@privacyvault.tech. We respond within 30 days (often within 7).

Shopify customers (GDPR webhooks): Privacy Vault honors the three mandatory Shopify GDPR webhooks — customers/data_request, customers/redact, shop/redact. When Shopify forwards a request, we hash-match, retrieve the cipher payload, and deliver/redact within the timelines in Shopify's Privacy Policy.

9. International transfers

Customer data is processed at Cloudflare's nearest edge location to the customer. For EU/UK residents, processing typically happens in EU edge POPs. Cross-border transfers (e.g., to Anthropic in the US for technical decision support, never customer data) rely on Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Cookies on privacyvault.tech

We use only essential cookies on this website (session persistence, security CSRF tokens). No marketing or third-party tracking cookies. We never integrate Google Analytics, Facebook Pixel, or any third-party analytics on the public site.

11. Security

12. Children

The Privacy Vault platform is not directed to individuals under 16. We do not knowingly process personal data of minors. Merchants using Privacy Vault confirm they comply with applicable child privacy laws (COPPA, GDPR Art. 8) at their storefront.

13. Changes to this Policy

We will notify you of material changes by email (for merchants) and via banner on this site (for visitors), at least 30 days before they take effect. The "Last updated" date at the top reflects the latest revision.

Contact us

Privacy Vault Technologies LLC
Doral, Florida, USA
Privacy & DPO: admin@privacyvault.tech

For Brazilian residents (LGPD Art. 41 — DPO contact): admin@privacyvault.tech with subject "DPO/LGPD".