Privacy
Policy
- Who we are & data controller
- What personal data we collect
- How we collect your data
- Lawful basis for processing
- How we use your data
- Marketing communications
- Who we share your data with
- International data transfers
- Your rights
- How long we keep your data
- Security
- Children's privacy
- Cookies & tracking
- California residents (CCPA)
- Changes to this policy
- Contact & complaints
Vault & Hide is a premium leather goods brand incorporated in the United States and operating globally, with manufacturing facilities in Karachi, Pakistan. We operate the website vaultandhide.com and all sub-pages associated with it.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (GDPR), Vault & Hide is the data controller — meaning we are responsible for deciding how and why personal data about you is processed.
We have designated a privacy lead responsible for data protection compliance. You can reach them at [email protected].
We collect only the data necessary to provide our services, fulfil your orders, and improve your experience.
- Full name, billing address, and delivery address
- Email address and telephone number
- Account username and encrypted password
- Order history including products purchased, quantities, prices, and dates
- Payment method type — we never store full card numbers
- Transaction reference numbers and payment status
- Returns, refunds, and warranty claim history
- Bespoke design specifications, measurements, and configuration choices
- Saved sizes, wishlist items, and recently viewed products
- Currency and language preferences
- Vault Rewards points balance and redemption history
- Product reviews and ratings submitted by you
- IP address, browser type, operating system, and device type
- Pages visited, time spent, clicks, and navigation paths
- Referral source (e.g. Google search, Instagram, direct)
- Session identifiers and cookie data — see our Cookie Policy
- Emails, live chat transcripts sent to or received from our team
- Customer service enquiry history and notes
- Survey responses and feedback submissions
- Directly from you — when you create an account, place an order, submit a bespoke design form, subscribe to our newsletter, submit a review, or contact our support team.
- Automatically — as you browse vaultandhide.com, we collect technical and usage data via cookies and similar technologies. See our Cookie Policy for full details.
- From third parties — we may receive data from payment processors confirming transaction status, from shipping carriers confirming delivery, and from analytics services that help us understand site usage.
- From your social media activity — if you tag us in a post or contact us via a social platform, we receive the information you make available through those interactions.
Under GDPR Article 6, every processing activity must have a lawful basis. The table below maps each category of use to its legal ground.
| Processing activity | Lawful basis | Detail |
|---|---|---|
| Processing and fulfilling your order | Contract | Necessary to perform the purchase contract between you and Vault & Hide. |
| Creating and managing your account | Contract | Necessary to provide and maintain your account and associated services. |
| Payment processing and fraud prevention | Contract Legitimate interests | Contract performance and our legitimate interest in preventing financial fraud. |
| Transactional emails (order confirmations, shipping updates) | Contract | Required to keep you informed about your order. |
| Customer support and warranty claims | Contract Legitimate interests | Contract performance and legitimate interest in maintaining customer relationships. |
| Marketing emails and newsletters | We send marketing only where you have explicitly opted in. You may withdraw at any time. | |
| Website analytics and performance monitoring | Legitimate interests | Our legitimate interest in understanding how the site is used to improve it. Analytics data is anonymised. |
| Personalisation (size suggestions, recently viewed) | Legitimate interests | Legitimate interest in improving your shopping experience. You can clear this data at any time. |
| Tax, accounting, and legal compliance | Legal obligation | Required by US, UK, and Pakistan tax and financial record-keeping regulations. |
| Responding to legal requests and court orders | Legal obligation | We must comply with lawful requests from courts, regulators, and law enforcement. |
Processing your payment, confirming your order, managing production for bespoke items, arranging delivery, handling returns, processing refunds, and managing warranty claims.
Maintaining your account, storing your wishlist, saving your size preferences, tracking your Vault Rewards balance, and providing order history.
Sending order confirmations, dispatch notifications, delivery updates, and responses to your customer service enquiries. These are transactional and cannot be opted out of while you have an active order.
Analysing anonymised usage data to understand how customers navigate the site, which products generate interest, and how we can improve the experience.
Monitoring for fraudulent orders, account takeover attempts, and payment fraud. We share flagged activity with our payment processors and, where necessary, law enforcement.
Maintaining financial and tax records as required by applicable law, responding to valid legal requests, and discharging obligations under consumer protection and customs regulations.
If you have opted in, we use your email address to send newsletters, new arrival announcements, promotional offers, and Vault Rewards programme updates. See section 6 for how to opt out.
We operate a strict opt-in marketing policy. We will never send you marketing emails unless you have explicitly given us consent — either by ticking the marketing opt-in box at checkout or subscribing via our newsletter form.
When you consent to marketing, you may receive: new arrival and seasonal drop announcements, exclusive subscriber discounts, Vault Rewards programme updates, leather care tips, and style guides.
- Clicking the Unsubscribe link at the bottom of any marketing email.
- Updating your preferences in your account under Account → Communication preferences.
- Emailing [email protected] with the subject line UNSUBSCRIBE.
Opt-out requests are processed within 5 business days. You may continue to receive transactional emails after opting out of marketing — these are required for contract performance.
We do not sell, rent, or trade your personal data to any third party. We share data only where necessary to provide our services or fulfil legal obligations. All third-party processors are bound by Data Processing Agreements (DPAs).
| Recipient | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe / PayPal / Klarna | Payment processing | Name, billing address, order total, payment token | USA (SCCs) |
| DHL / FedEx / UPS / local carriers | Order fulfilment & delivery | Name, delivery address, phone number, order declaration | Global (varies) |
| Google Analytics | Website analytics | Anonymised usage data, truncated IP address | USA (SCCs) |
| Marketing platforms (where applicable) | Advertising — consented only | Hashed email, pixel data, conversion events | USA / Global (SCCs) |
| Fraud detection services | Fraud prevention | IP address, device fingerprint, order data | Varies (DPA in place) |
| Tax & accounting software | Financial compliance | Name, billing address, transaction value | US / Pakistan |
| Legal & regulatory authorities | Legal obligation | As required by valid court order or regulatory request | Jurisdiction-dependent |
We may also share data with professional advisers bound by confidentiality obligations, and with any acquirer in the event of a merger or sale of our business — in which case you will be notified in advance.
Vault & Hide is headquartered in the United States and serves customers globally. Some third-party processors we use are located outside the EEA and United Kingdom. Where we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place including Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements (IDTAs) with all relevant processors.
We honour the following rights for all customers globally. All requests are free of charge and will be responded to within 30 days.
We will respond to all valid requests within 30 calendar days. For complex requests we may extend to 90 days with notice. We may need to verify your identity before processing a request.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected and comply with legal obligations.
| Data category | Retention period | Reason |
|---|---|---|
| Order and transaction records | 7 years from transaction date | Tax and financial record-keeping obligations |
| Account data (active accounts) | Duration of account + 3 years after closure | Warranty claims, dispute resolution, regulatory compliance |
| Bespoke order design specifications | 5 years from delivery | Potential remake requests and warranty reference |
| Customer support communications | 3 years from case closure | Dispute resolution and service improvement |
| Marketing consent records | 3 years after last interaction or opt-out | Evidence of consent in case of regulatory audit |
| Website analytics data | 26 months (Google Analytics default) | Trend analysis and performance benchmarking |
| Fraud and security logs | 5 years | Investigation of fraud patterns and legal proceedings |
| General enquiries (non-order) | 30 days after resolution | No ongoing business need after resolution |
| Closed accounts with no purchase history | 30 days after closure request | No outstanding legal basis for retention |
When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised. Anonymised data may be retained indefinitely for statistical purposes.
We have implemented technical and organisational measures appropriate to the risk, including TLS 1.2+ encryption in transit, AES-256 encryption at rest, strict access controls, PCI-DSS compliant payment processing, and a data breach response plan. In the event of a breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33.
While we take every reasonable precaution, no electronic storage method is completely secure. You are responsible for keeping your account password confidential. If you believe your account has been compromised, contact us immediately at [email protected].
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has submitted personal data to us, please contact us at [email protected] and we will delete it promptly.
We use cookies and similar tracking technologies to operate the website, remember your preferences, understand how you use the site, and — where you consent — to deliver relevant advertising. Full details of every cookie we set, its purpose, duration, and your controls are in our dedicated Cookie Policy.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific additional rights.
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected, used, or disclosed about you in the past 12 months.
- Right to delete: Request deletion of personal information we have collected, subject to certain exceptions.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out of sale or sharing: We do not sell or share personal information. No opt-out is required.
- Right to non-discrimination: You will not receive different service or pricing as a result of exercising any CCPA right.
To submit a CCPA request, email [email protected] with subject line CCPA REQUEST. We will verify your identity and respond within 45 calendar days.
We may update this privacy policy to reflect changes in our data practices or applicable law. When we make material changes, we will update the "last reviewed" date, display a notice on the website for at least 30 days, and notify registered account holders by email where changes materially affect how we use their data.
Previous versions are available on request by emailing [email protected].
For all privacy-related requests, questions, or concerns — including Subject Access Requests, erasure requests, and marketing opt-outs — please contact our privacy team directly.
We respond to all privacy enquiries within 5 business days and to formal data subject requests within 30 calendar days as required by GDPR Article 12. For urgent matters, mark your subject line URGENT PRIVACY.