Privacy Policy
LAST UPDATED · SEPTEMBER 25, 2026
1. Introduction
RocketVault ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
2. Information We Collect
We collect information in the following ways:
- Account Information: Name, email address, and the sign-in method you choose. Your password, when used, is handled by our sign-in service rather than stored in RocketVault's product database.
- Payment Information: Billing details processed securely through our payment provider.
- Card Images: Photos you upload for scanning and cataloging.
- Collection Data: Card information, pricing data, and listing details.
- Marketplace Contact and Delivery Information: The recipient name, email address, phone number, delivery address, and seller ship-from address needed to calculate shipping and tax, complete checkout, create labels, deliver an order, handle returns, and provide buyer protection. RocketVault can save the delivery address you used most recently so it is already filled in next time.
- Usage Data: How you interact with our platform after you sign in, including pages visited, the kind of action taken, whether it finished, and a limited error reference. This activity record does not include what you type, card images, payment details, private messages, sign-in credentials, or search terms.
- Device Information: Browser type, IP address, and device identifiers.
- Marketplace Launch Records: Whether an account qualifies for the existing-member offer, Marketplace access changes, and the fees applied to an order. Message history keeps the subject, status, time, and delivery receipt. It refers back to the account instead of copying the recipient's email address into that history.
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our services
- Process card scans and generate pricing estimates
- Create and manage RocketVault Marketplace and eBay listings at your direction
- Fill in your saved delivery address, calculate shipping and tax, complete Marketplace orders, create labels, provide tracking, handle returns, and resolve order issues
- Send you important updates and notifications
- Apply the existing-member launch offer, prevent duplicate messages, and confirm whether important messages were delivered
- Respond to your inquiries and provide customer support
- Analyze usage patterns to improve user experience
- Detect and prevent fraud or abuse
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your data with:
- Service Providers: Third parties that help us operate our services (e.g., cloud hosting, email delivery, analytics, and customer support).
- Marketplace Order Providers: Our payment processor receives the contact, billing, and order details needed to take payment, verify sellers, and send payouts. Our shipping and label provider receives the ship-from and delivery details needed for rates, labels, and tracking. Our tax calculation provider receives the delivery location and order amounts needed to calculate tax. We share only what each provider needs for that job.
- Marketplace Participants: After a paid order, the seller receives the delivery information needed to ship it. Your full delivery address is not shown on a public profile or public listing.
- eBay: When you authorize us to create listings on your behalf.
- RevenueCat: Older iOS subscription records may be checked through RevenueCat, which receives purchase history and an anonymized user identifier. Product access no longer depends on a subscription.
- Legal Requirements: When required by law or to protect our rights.
5. Data Security
We protect information with encrypted connections (TLS), access controls, limited production access, monitoring, and the security protections provided by our hosting, payment, tax, and shipping partners. No method of storing or sending information online is completely secure.
6. Your Rights
You have the right to:
- Access and download your data
- Correct inaccurate information
- Review or replace the saved delivery address before checkout
- Delete your account and associated data
- Opt out of marketing communications
- Request data portability
7. How Long We Keep Information
A saved delivery address remains available until you replace it, ask us to delete it, or delete your account. Order contact, delivery, payment, refund, and tax records remain with the order while they are needed to complete service, handle returns or disputes, prevent fraud, and meet accounting, tax, and legal requirements. Some order records may therefore remain after an account-deletion request, with access limited to those purposes.
Signed-in product activity details are kept for 90 days so we can find usability and reliability problems. After 90 days, we keep daily totals such as page views, uploads, and errors instead of the detailed activity trail.
You can replace your saved delivery address during checkout, download supported account data, or request account and address deletion through Settings or the contact link below. We will tell you if a specific order record must be kept for a legal or financial reason.
8. Cookies and Analytics
We use cookies and similar technologies to enhance your experience, analyze usage, and improve RocketVault. On your first visit you will see a consent prompt; analytics cookies do not load until you accept. You can change your choices below. Choices apply separately to each website and browser.
We use the following analytics tools:
- Google Analytics 4 — pageviews, conversion events, and cross-subdomain measurement between rocketvault.io and app.rocketvault.io. Configured with Google Consent Mode v2 (default-deny).
- Microsoft Clarity — session replay and heatmaps to understand how visitors interact with the site. Loads only after consent.
- PostHog — product events such as page, workflow, and error metadata used to find usability problems. Web events are forwarded only after consent and use a pseudonymous account identifier. The native app sends only a limited reliability and critical-workflow event set under a new pseudonymous identifier for each app session. Person profiles are disabled, and events exclude typed text, clicks, card data, filenames, payment data, search terms, request bodies, error messages, and contact information.
- Sentry — we use Sentry for crash and performance monitoring. Sentry receives error stack traces, request paths, browser/device metadata, and your account ID so we can diagnose and fix issues. Sentry does not use this data for advertising.
Meta advertising measurement requires a separate opt-in. After you allow it, RocketVault may send a confirmed signup or first Marketplace listing event, its time, an opaque deduplication identifier, a page path, your browser user agent and the Meta ad click identifier to Meta. We exclude names, email addresses, IP addresses, card details and payment amounts. On web guest checkout, this also measures a completed purchase after our payment system confirms it, using a random first-party browser identifier and an opaque event ID. Consented attribution is encrypted for up to 24 hours while awaiting payment and is removed when sent, withdrawn or expired. Delivery receipts retain only the opaque event ID and delivery state. A first-party ad click cookie can be shared between rocketvault.io and app.rocketvault.io for up to 90 days; each site still requires its own advertising consent. We honor Global Privacy Control. Declining deletes the ad click and browser cookies, clears queued guest-purchase measurement even after payment or order recovery, and stops future sharing; it does not recall previously sent events.
This section applies to RocketVault's websites. The native iOS app does not load Google Analytics or Microsoft Clarity and does not create analytics or attribution cookies. Its limited PostHog reliability events are used only to operate and improve RocketVault, not for advertising, attribution, or tracking users across other companies' apps or websites.
9. Children's Privacy
Our services are not intended for users under 13 years of age. We do not knowingly collect information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at: rocketvault.io/contact.