This is a proposed draft for discussion, not an active policy or agreement. It requires legal and issuer review and confirmation of the details flagged below before taking effect.
1. About this policy
This proposed policy describes how [Vaultly legal entity] would handle personal information in connection with the Vaultly website, Merchant Checkout, its cardholder portal, the Corporate Prepaid business portal and employee app, and Loyalty membership and program administration. The final policy must reflect the services actually launched and identify the responsible entity, its address and privacy contact.
2. Information used to provide the service
Depending on your interaction with Vaultly, information may include contact details, order references, funding confirmations, card activity, balances, bank-transfer details and support correspondence. Technical information may include device and browser details, IP addresses and security logs.
The Merchant Checkout reloadable virtual card requires identity verification before funding or use. Information requested may include your name, date of birth, address and evidence of identity. Any additional document, image or biometric processing must be explained by the approved verification notice before collection.
For Corporate Prepaid, information may also include employee enrolment records provided by the corporation, payout instructions, corporate payment references and employee card activity. The final notice must explain the corporation’s and providers’ responsibilities and what employee information is visible to corporate administrators.
Loyalty member information
Loyalty information may include enrolment details, member identifiers, points balances, qualifying purchases or visits, rewards earned and redeemed, stated preferences, and communication choices. A birthday may be requested where a birthday reward is offered. Collect only information needed for the disclosed program purposes.
The final notice must explain the participating business’s and Vaultly’s roles, which member records each can access, and how information supports rewards, relevant offers, audience segmentation and program reporting. It must identify any connected systems and service providers.
3. How information is used and shared
We would use necessary information to assess eligibility, complete verification, process authorised payments, maintain card records, respond to enquiries and investigate fraud or disputes. Processing must have an appropriate basis under applicable law, including consent where required.
Information may be shared with the relevant merchant, issuer, funding provider, verification provider and contracted service providers where necessary for these purposes. Disclosure to authorities may occur where legally required. Each provider’s role and any separate privacy notice must be identified in the final program documentation.
4. Retention, protection and processing locations
Information should be retained only as long as needed for the stated purposes and applicable recordkeeping requirements. Appropriate access controls and other safeguards should protect it. Where providers process information in another country, the final policy must describe those arrangements and applicable protections. No transmission or storage system is completely secure.
5. Your choices and requests
Depending on applicable law, you may request access, correction or deletion, withdraw consent, or object to certain processing. Some records may need to be retained despite a request. Identity may need to be verified before a request is fulfilled. Privacy complaints and requests should use the designated privacy contact once published.
Loyalty members should receive clear choices for promotional communications and a way to change preferences or unsubscribe. Account and reward-service messages should be distinguished from marketing. The final program notice must explain how to request access, correction or closure and what happens to records and rewards after closure.
6. Website technologies and this preview
This preview does not issue cards, process funds, enrol loyalty members or award or redeem real points. Its enquiry form prepares a local draft rather than submitting an enquiry. Do not enter real card numbers, bank details or identity documents. Hosting and externally loaded resources may still receive technical connection information.
Before launch, Vaultly must publish an accurate inventory of cookies and similar technologies, explain any analytics or advertising use, and provide consent controls where required. Material privacy changes should be communicated with an updated effective date.
Legal entity and address; privacy contact and request channel; providers and processing countries; retention schedule; cookie inventory; marketing and sale/sharing practices; applicable regional rights and complaint routes.
Drafting references
Original sample wording informed by the coverage of these policies. Their practices do not establish Vaultly’s practices.