Privacy Policy
Last updated July 27, 2026
This policy explains what personal data CableVault collects, why we collect it, how long we keep it and the choices you have. It applies to contractors who subscribe to CableVault and to the customer contacts they invite to the portal.
Who is responsible for your data
CableVault is the controller of account and billing data. For the closeout documents a contractor uploads, the contractor is the controller and CableVault acts as a processor on their instructions — see our Data Processing Addendum.
What we collect
Account data: name, job title, work email, company name, address, phone and website.
Content data: projects, buildings, customer records, uploaded documents and their metadata, QR code labels and activity log entries.
Billing data: subscription plan, status, renewal dates and invoice history. Card details are collected and stored by our payment processor, Stripe — we never see or store full card numbers.
Technical data: sign-in events, IP address, browser type and error diagnostics needed to keep the service secure and working.
Why we use it and our legal basis
To provide the service and perform our contract with you; to take payment and prevent fraud; to send service and billing emails (contract and legitimate interests); to secure the platform and comply with tax, accounting and other legal obligations. We do not sell personal data and we do not use your uploaded documents to train AI models.
Who we share it with
Sub-processors that make the service work: Supabase (database, authentication and file storage), Cloudflare (application hosting and delivery), Stripe (payments and invoicing) and Lovable's managed email service (transactional email). Each is bound by confidentiality and data protection obligations. We may disclose data where required by law.
International transfers
Our providers may process data in the United States and other countries. Where personal data leaves the EEA or UK, transfers rely on Standard Contractual Clauses or another approved safeguard.
How long we keep it
Account and content data is kept while your workspace is active. When you delete your account we remove workspace content and files, and delete the associated user accounts. Invoice and tax records are retained for the period required by law (typically seven years). Backups age out on their normal cycle.
Security
Data is encrypted in transit and at rest. Access is enforced at the database level so a workspace can only reach its own records, and customer portal users see only the projects belonging to their company. Uploaded files are stored in a private bucket and served through short-lived signed links.
Your rights
Depending on where you live, you may request access, correction, deletion, restriction, portability or object to certain processing, and you may withdraw consent where processing relies on it. California residents may request disclosure or deletion and are never subject to discrimination for exercising those rights.
You can download a complete copy of your data and delete your account at any time from Settings, or contact privacy@cable-vault.com. If a request concerns documents uploaded by a contractor, we will forward it to that contractor as controller. You also have the right to complain to your local supervisory authority.
Children
CableVault is a business tool and is not directed to anyone under 18.
Contact
Privacy questions: privacy@cable-vault.com. General support: support@cable-vault.com.