Your rights — start here
- Access: see all data we hold · 30-day SLA
- Correct: edit any data that's wrong
- Export: JSON or CSV download · 30-day SLA
- Delete: 30-day grace then permanent
- Restrict / object: stop specific processing without deleting your account
- Opt out: marketing emails — every email has unsubscribe
- Don't sell my info: we don't sell. CCPA opt-out at /account/privacy
What we collect
You give us
- Email address (account)
- Password (stored hashed — we never see your plaintext password)
- Optional: name, photo, preferences
- Content you create
- Payment info entered on Stripe-hosted checkout (we never see card numbers)
We observe
- IP address (for security · 90-day retention)
- Browser/device user-agent
- Aggregate usage patterns
- Errors during your session
Why we collect it
| Purpose | Lawful basis |
|---|---|
| Provide the service | Contract with you |
| Process payments | Contract |
| Send transactional emails | Contract |
| Send marketing emails | Your opt-in consent (unsubscribe anytime) |
| Operate the service securely | Legitimate interest |
| Recordkeeping | Legal obligation |
Who else sees your data
Only vendors who help us run the service. Each one has a Data Processing Agreement and is bound by confidentiality. Full list at /subprocessors. Material additions get 30 days advance notice.
We never sell your data. Not to advertisers, not to data brokers, not to anyone.
How long we keep it
| Data | Retention |
|---|---|
| Active account | While account is active |
| Account after cancellation | 30 days then permanent delete |
| Receipts (financial) | 7 years (US tax law) |
| Marketing opt-in records | 3 years past unsubscribe |
| Web access logs | 90 days |
| Auth audit logs | 1 year |
Regulator focus
US (50 states) · CCPA · veteran services PII handling
Children's data
Our service is not directed to children under 13 (US) or 16 (EU). We don't knowingly collect data from children.
Contact
Privacy questions: privacy@valuetovictory.com