Privacy Policy
Last updated: August 10, 2026
What we collect
When a business ("the Customer") uses Vaultform to request documents, we collect: the requesting business's account information (name, email); the documents and information uploaded by the people the Customer sends requests to ("End Users"), including files, typed confirmations, drawn signatures, and the email address used to verify a confirmation or signature; and technical data generated automatically, including IP address, timestamps, and basic browser information, for security and audit purposes.
How we use it
Uploaded files and information are used solely to fulfill the document request between the Customer and their End User — we do not use End User content for any other purpose, including marketing, analytics, or model training. Technical data (IP, timestamps) is used for security, fraud prevention, and to maintain the audit trail Vaultform provides to Customers as a core feature.
Automated scanning
Every uploaded file is automatically scanned for malware via a third-party scanning service before being made available to the Customer. This scan is signature-based; it reduces but does not eliminate the risk of malicious files, and should not be treated as a complete security guarantee.
Third parties we share data with (subprocessors)
We use the following third-party services to operate Vaultform. Each processes data only as necessary to provide their specific function:
- Supabase — database and file storage hosting
- Vercel — application hosting
- VirusTotal — automated malware scanning of uploaded files
- Resend — transactional email delivery (request notifications, verification codes)
- Upstash (QStash) — background job processing for scanning
- Google Drive, Microsoft OneDrive, Dropbox, Salesforce, HubSpot, Slack, Microsoft Teams — only if and when a Customer explicitly connects these integrations; data is shared only with the specific service the Customer chose to connect
We do not sell End User or Customer data to third parties, and we do not share it for advertising purposes.
Data retention and deletion
Files are automatically deleted 90 days after a document request is completed or cancelled. Metadata about the request (labels, statuses, timestamps, and the audit log) is retained after file deletion, since maintaining an accurate audit trail is a core part of what Vaultform provides to Customers — but the underlying file content itself is removed. A Customer or End User may request earlier deletion at any time by contacting the Customer's organization directly, or Vaultform via our contact page (support@vaultform.net).
Your rights
Depending on your location, you may have rights to access, correct, or delete your personal information, or to object to certain processing. To exercise these rights, contact us. If you are an End User (someone who received a document request), you may also need to contact the business that sent you the request, since they are the party that initiated collection of your information.
Security
Files are stored in access-controlled storage with no public URLs; viewing a file requires a short-lived signed link generated on demand. Every action on a request — upload, scan result, approval, rejection, export — is logged. Vaultform is not currently SOC 2, HIPAA, or GDPR certified.
Governing law
This policy is governed by the laws of the Commonwealth of Virginia, without regard to its conflict-of-law principles. See the same provision in our Terms of Service for how disputes are resolved.
Contact
Questions about this policy: contact us or email support@vaultform.net.
