LEGAL

Privacy Policy

EFFECTIVE 1 JUNE 2026VERSION 2.4WE DON'T SELL YOUR DATA

Two kinds of people appear in Pattern Vault: our customers, and the local businesses in our listings database. This policy covers both, and says clearly which data comes from where.

NO SELLING
We never sell or share personal data for advertising.
NO TRAINING
Your boards and prompts don't train anyone's general model.
OPT OUT
Any listed business can have its record suppressed on request.
01

Who we are

IN SHORT · Pattern Vault, Inc. is the controller for customer data and for our listings database.

Pattern Vault, Inc. operates patternvault.com and the Pattern Vault application. For customer accounts we act as controller. For the leads you import into your boards and the messages you send, you act as controller and we act as your processor.

02

Data about our customers

IN SHORT · Account details, billing, and how you use the product.

We collect what you give us at signup, what your payment provider reports back, and product-usage events that tell us which features are worth keeping.

Account
Name, email, password hash, role, company name, time zone.
Billing
Plan, billing period, last four digits and card brand via Stripe. We never store full card numbers.
Usage
Scans run, categories searched, previews generated, features opened, error traces.
Support
Emails, chat transcripts, and any files you attach to a ticket.
Device
IP address, browser and OS, referring page, and session cookies.
03

Data about local businesses

IN SHORT · Business-level public information, not consumer profiles.

Our listings database contains business contact information gathered from public sources: directory and map listings, the business's own website, public registrations, and licensed third-party data providers.

These records describe organisations. Where a field could identify an individual — an owner's name on a sole proprietorship, or a personal mobile used as a business number — we treat it as personal data and honour deletion requests from that person.

We do not build consumer profiles, we do not buy consumer marketing lists, and we do not track visitors to the websites we crawl.

04

How we use data

IN SHORT · Run the product, bill for it, keep it secure, make it better.

We use customer data to provide and support the service, process payments, prevent abuse and fraud, meet legal obligations, and send service notices. Product analytics are used in aggregate to prioritise work.

We use listings data to compute signal scores, generate site previews on your instruction, and keep records current on our rolling re-scan cycle.

Marketing email goes only to customers and to people who opt in, always with a working unsubscribe link. We do not email the businesses in our database.

05

Legal bases

IN SHORT · Contract, legitimate interests, consent, and legal obligation.

Where GDPR or UK GDPR applies: providing the service is necessary for our contract with you; maintaining a B2B listings database, securing the platform, and improving the product rest on our legitimate interests, assessed against the limited privacy impact of business-level data; marketing to prospects relies on consent where required; retention of invoices rests on legal obligation.

06

AI and site previews

IN SHORT · Your prompts and the target's public data go to a model provider. Nothing trains on your boards.

Generating or editing a preview sends the public listing content and your written instruction to our model providers under agreements that prohibit using the content to train their general models.

We retain preview drafts and edit history in your account so you can reopen them. Delete a preview and it goes on the same 30-day deletion path as the rest of your data.

07

Sharing and processors

IN SHORT · A short list of vendors. No data brokers, no selling.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We share data only with processors who need it to run the service, plus with acquirers in a merger, or with authorities when a valid legal request compels it.

Infrastructure
AWS (us-east-1, us-west-2) — hosting and backups.
Payments
Stripe — subscriptions and invoices.
Email
Postmark — transactional email.
Analytics
Self-hosted, cookie-light product analytics.
AI
Model providers under no-training agreements, US regions.
08

Cookies

IN SHORT · Session, preference, and first-party analytics. No ad networks.

We set a session cookie required to keep you signed in, a preference cookie for interface settings, and first-party analytics cookies. There are no third-party advertising or social tracking pixels on the application. Marketing pages use one first-party analytics cookie you can decline without losing functionality.

09

Retention

IN SHORT · As long as you're a customer, then 30 days, then gone.

Account and board data live for the life of your account and 30 days after deletion, excluding backups which cycle out within 90 days. Invoices are kept seven years for tax law. Support tickets are kept three years. Aggregated, non-identifying statistics may be kept indefinitely.

Listings records are refreshed on a rolling 30-day cycle; records suppressed at a business's request are kept only as a hashed suppression entry so we don't re-add them.

10

Your rights

IN SHORT · Access, correct, delete, port, object — including if you're a listed business.

Depending on where you live you may have rights to access, correct, delete, or port your data, to object to or restrict processing, and to opt out of sale or sharing (we do neither). You can exercise most of these from account settings; anything else goes to privacy@patternvault.com.

California residents may designate an authorised agent, and we won't discriminate against you for exercising a right. EU and UK residents may complain to their supervisory authority; our EU representative details are available on request.

Business owners who find their listing in our database can request suppression at any time using the same address, without holding a Pattern Vault account.

11

International transfers and security

IN SHORT · US-hosted, encrypted, least privilege, SCCs where needed.

Data is processed in the United States. For transfers from the EEA, UK, or Switzerland we rely on Standard Contractual Clauses and the UK Addendum, with a transfer assessment on file.

We encrypt data in transit with TLS 1.2+ and at rest with AES-256, enforce SSO and MFA internally, scope access to least privilege, log administrative actions, and test the platform annually with an external firm. If a breach affects your data we notify affected customers within 72 hours of confirming it.

12

Children and changes

IN SHORT · Not for under-18s. We announce material changes.

Pattern Vault is a business tool and is not directed to anyone under 18; we don't knowingly collect their data.

When we change this policy materially we update the version and effective date above and email account holders at least 14 days ahead. Past versions are available on request.

PRIVACY REQUESTS

Email privacy@patternvault.com — including business owners who want a listing removed. We confirm within 5 business days and complete removals within 30. Pattern Vault, Inc., 1100 Larimer St, Suite 400, Denver, CO 80204.