Privacy policy
Last updated: 13 September 2026
This notice explains how eeVault uses personal information when you visit our website, sign in, or keep trading-card inventory and sales records.
Who is responsible
eeVault is operated by Ryan, the service owner, who is responsible for personal information used to run the service. Contact ryan.raz@hotmail.com for privacy questions, account deletion or requests about your information.
Information we collect
- Account information: email address, account identifier, email verification status, and basic profile information supplied by your chosen sign-in provider, such as a name or profile picture.
- Your vault: card descriptions, images, quantities, purchase costs, grades, prices, sales, expenses, notes, preferences and saved revision history. Avoid entering unnecessary personal information about buyers or other people.
- Optional connected services: where a connection is available and you authorise it, listing and order information, transaction references and connection tokens. An optional Outlook connection reads messages to identify Vinted sales. Its Mail.Read permission permits mailbox reading; the import searches for relevant sales messages and extracts sale details. This connection is separate from signing in with Microsoft.
- Service information: request and error logs, IP addresses and browser/device information processed by our hosting and authentication providers, plus messages and optional screenshots you send us for support. Problem reports include the current page name, are stored with your account identifier, and are visible to the service owner. Replies appear in Help & account. Account-deletion requests are recorded for review; sending a request does not immediately erase saved records.
Google sign-in
Google sign-in requests basic identity permissions: openid, email and profile. We use this information to create or identify your account and sign you in through Supabase. Google sign-in does not grant eeVault access to Gmail, Google Drive, your contacts or your Google password.
We do not sell Google user data, use it for advertising or use it to train general-purpose AI models. eeVault’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access through your Google account connections. Revoking access does not itself delete records already saved in eeVault; contact us to request deletion.
Why we use information
We use account and vault information to provide the service you request, save and recover your records, perform searches and price checks, and provide authorised imports. Our lawful basis for these core functions is performance of our agreement with you. An email address and account identifier are needed to provide a signed-in vault.
We use necessary technical information to keep accounts secure, investigate faults and prevent abuse, based on our legitimate interests in operating a reliable service. We also use support correspondence to respond to you. Where a legal obligation requires processing, we rely on that obligation. Where we rely on consent for an optional use, you may withdraw it without affecting processing that already took place.
You can object to processing based on legitimate interests by contacting us. We do not make solely automated decisions with legal or similarly significant effects about you. Automated card matches and price estimates are suggestions you should review.
Who receives information
We use OpenAI/ChatGPT Sites and Cloudflare for hosting and storage, Supabase for authentication and supporting services, and email-delivery providers such as Resend for sign-in messages. Google or Microsoft processes your sign-in under its own policies when you choose that provider. Optional eBay, Outlook and Gmail connections exchange information with those services only when authorised.
Card search terms and card identifiers may be sent to external catalogue, image and marketplace providers to return results. Loading third-party images or following listing links can disclose your IP address and browser information to that provider. Do not put private information into public catalogue searches.
The operator may access information as needed for support, maintenance, security or legal requests. We do not sell your personal information. We may disclose information where legally required or necessary to protect the service and users.
Optional Gmail imports
If you connect Gmail, eeVault requests read-only mailbox access to find Vinted sale notifications and supported buylist submissions. It reads matching email content to extract item names, amounts, dates, references and links. Extracted records are stored in your private sales-matching inbox; full email bodies are processed during import and are not retained. Access tokens are encrypted on the server. The integration does not send, delete or mark messages as read.
You can disconnect Gmail in Settings → Connections. This removes the stored token and attempts to revoke Google access. Previously imported sales and recovery history remain until separately deleted or handled through an account-deletion request. You can also revoke access in your Google Account. Gmail data is used only for these user-facing import and matching features, not advertising or training general-purpose AI models.
Storage and international processing
Vault records and recoverable history are stored on the service’s hosting infrastructure. Authentication is handled by Supabase; the current authentication project is configured in the UK. This does not mean that every provider processes every item of data only in the UK. Our providers operate internationally and their hosting, support and subprocessors may involve processing outside the UK. Contact us for details of the arrangements and applicable transfer safeguards for your information.
How long information is kept
We keep account and vault information while needed to provide your account and its recovery features. Saved revisions can contain earlier values after a record is edited or removed. Removing a card from the current inventory is therefore not the same as requesting erasure of all its history.
Retention is assessed according to the purpose of the information, recovery needs, account status, security investigations and applicable legal requirements. There is no automatic account-deletion schedule advertised by this service. Contact us to close your account or request erasure; we will explain any information that must remain, the reason and applicable retention period, including backup or historical copies.
Cookies and browser storage
eeVault uses secure sign-in cookies to maintain your session and protect the login process. With “Keep me signed in” selected, the app sets persistent session cookies for up to 30 days; provider expiry, revocation or security checks can require earlier sign-in. Browser storage also holds preferences, cached results and recovery information. Shared-device users should sign out when finished. The app does not include advertising trackers in its current implementation.
Your choices and rights
You can edit your records and use available backup and export features. Depending on the processing and applicable law, you may request access, correction, deletion, restriction or a portable copy of your information, and object to certain uses. Email ryan.raz@hotmail.com. We may need to verify your identity before acting on a request. Rights are subject to applicable legal exceptions.
You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.
Changes to this notice
We will update this page when our data practices change and use an appropriate notice for material changes. The date above identifies this version.