This Privacy Policy explains how VaultyEmpire ("we", "us", "our") collects, uses, stores and protects your personal data when you use our website and members platform at vaultyempire.io (the "Service"). We are committed to processing your data lawfully, fairly and transparently in accordance with the EU General Data Protection Regulation (GDPR) and applicable data-protection laws.
Contents
1. Who we are
VaultyEmpire operates an invitation-limited platform that provides handmade, aged social-media accounts to its members. For the purposes of the GDPR, VaultyEmpire is the data controller responsible for the personal data described in this policy. You can reach our data contact at privacy@vaultyempire.io.
2. Data we collect
Information you provide
- Account details — your email address, a Telegram handle, and a password (stored only as a salted PBKDF2 hash; we never store your password in plain text).
- Optional two-factor authentication — if you enable it, a TOTP secret used solely to verify your login codes.
- Communications — the content of any message you send us by email or support channel.
Information collected automatically
- Technical & security data — IP address, browser user-agent, and request metadata, used to operate the Service, prevent abuse and secure accounts.
- Anti-abuse signals — a non-reversible device/identity fingerprint and proof-of-work data used to prevent automated account creation and fraud.
- Cookies — see the Cookies section below.
Payment information
Payments are made in cryptocurrency through a third-party payment processor. We receive confirmation of payment and a transaction reference, but we do not collect or store card numbers or wallet private keys.
3. How we use your data
- To create and manage your account and provide the Service;
- To process top-ups, orders and deliver purchased accounts;
- To secure the platform — preventing fraud, abuse, automated registration and unauthorised access;
- To respond to your enquiries and provide support and replacements;
- To comply with legal obligations and enforce our Terms of Service.
4. Legal bases for processing
We rely on the following GDPR Article 6 legal bases:
- Performance of a contract — to provide the Service you sign up for;
- Legitimate interests — to keep the platform secure, prevent abuse and improve our service, balanced against your rights;
- Legal obligation — where we must retain or disclose data to comply with the law;
- Consent — for optional cookies and any non-essential processing; you may withdraw consent at any time.
5. Cookies
We use cookies and similar local-storage technologies in two categories:
- Strictly necessary — required to sign you in (session cookie), remember your cookie choice, and protect the platform from abuse. These are always active and do not require consent.
- Optional — used only with your consent to understand how the site is used so we can improve it. No optional cookies are set unless you accept them.
When you first visit, a banner lets you accept all cookies or keep only the necessary ones. You can change your choice at any time via the Cookie settings link in the footer.
6. Sharing & processors
We do not sell your personal data. We share data only with trusted service providers ("processors") strictly as needed to run the Service, including:
- a cryptocurrency payment processor to handle top-ups;
- an email delivery provider to send verification and transactional emails;
- our hosting and network/security providers (including a CDN/DDoS-protection layer) to serve and protect the site.
Each processor acts on our instructions under a data-processing agreement. We may also disclose data where required by law or to protect our legal rights.
7. Data retention
We keep personal data only for as long as necessary for the purposes set out above. Account data is retained while your account is active and for a reasonable period afterwards to meet legal, security and accounting requirements, after which it is deleted or anonymised. Security logs are kept for a limited period and then purged.
8. Security
We apply appropriate technical and organisational measures to protect your data, including encrypted transport (HTTPS/TLS), hashed passwords, restricted internal access, network-level filtering and rate-limiting, and regular hardening of our infrastructure. No method of transmission or storage is completely secure, but we work continuously to protect your information.
9. International transfers
Some of our processors may store or process data outside your country or the European Economic Area. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision to ensure your data remains protected.
10. Your rights
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — ask us to correct inaccurate or incomplete data;
- Erasure — ask us to delete your data ("right to be forgotten");
- Restriction — ask us to limit how we process your data;
- Portability — receive your data in a portable format;
- Object — object to processing based on legitimate interests;
- Withdraw consent — where processing is based on consent, withdraw it at any time;
- Complain — lodge a complaint with your local data-protection supervisory authority.
To exercise any of these rights, email privacy@vaultyempire.io. We will respond within the timeframe required by law.
11. Children
The Service is intended only for users aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. Material changes will be communicated through the Service where appropriate.
13. Contact
For any privacy questions or to exercise your rights, contact:
VaultyEmpire — Data & Privacy
privacy@vaultyempire.io