Privacy Policy

Effective Date: March 16, 2026

1. Introduction

VaultBridgeFO ("Company," "we," "us," or "our") operates the VaultBridgeFO secure document portal (the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect information about individuals who use the Service, including financial professionals ("Professionals") and their clients ("Clients," and together with Professionals, "Users" or "you").

By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, you must immediately discontinue use of the Service.

This Privacy Policy is incorporated by reference into our Terms of Service. In the event of any conflict between this Privacy Policy and the Terms of Service regarding privacy matters, this Privacy Policy controls.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Registration: Name, email address, password, and role (Professional or Client).
  • Profile Information: Financial, tax, and personal information you voluntarily enter, including but not limited to date of birth, Social Security Number, Employer Identification Number, marital status, occupation, dependent information, business records, real estate holdings, and financial data.
  • Documents: Files, images, PDFs, and other documents you upload to the Service.
  • Questionnaire Responses: Answers to tax and financial planning questionnaires provided within the Service.
  • Communications: Messages, notes, and other communications sent through the Service.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, timestamps, IP address, browser type, and device information.
  • Log Data: Server logs, error reports, and activity logs generated in the course of providing the Service.
  • Cookies and Similar Technologies: Session tokens and authentication cookies necessary to operate the Service. We do not use advertising cookies or third-party tracking pixels.

2.3 Information We Do Not Collect

We do not knowingly collect information from children under 13 years of age. We do not use your information for targeted advertising. We do not sell your personal information to any third party.

3. How We Use Your Information

We use information collected solely as necessary to:

  • Create, maintain, and secure your account;
  • Provide, operate, and improve the Service;
  • Facilitate the assignment and permission-based sharing of documents between Clients and their authorized Professionals;
  • Send transactional and administrative communications (e.g., account verification, security alerts, notifications);
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Comply with applicable legal obligations; and
  • Enforce our Terms of Service and other agreements.

We do not use your information for marketing, profiling, sale to third parties, or any purpose not listed above without your explicit consent.

4. How We Share Your Information

4.1 With Authorized Professionals

Client information — including profile data, uploaded documents, and questionnaire responses — is shared exclusively with Professionals whom the Client has been assigned to and who have been granted permission to access specific categories of information. Clients control which categories of documents are accessible to each Professional. Sharing beyond the scope of these permissions does not occur.

4.2 With Service Providers

We use a limited set of infrastructure providers strictly necessary to operate the Service, including cloud hosting (Cloudflare), database, storage, and email delivery (Resend). These providers process data only on our behalf, under contractual data processing agreements, and are not permitted to use your data for their own purposes.

4.3 Legal Obligations

We may disclose information if required to do so by law, regulation, subpoena, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of VaultBridgeFO, our Users, or the public.

4.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, dissolution, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will provide notice prior to your information becoming subject to a materially different privacy policy.

4.5 No Sale of Personal Information

We do not sell, rent, license, or trade your personal information to any third party for monetary or other valuable consideration, now or at any future time without explicit notice and consent.

5. Data Security

We implement industry-standard technical and organizational measures to protect your information, including:

  • AES-256-GCM encryption of all sensitive profile fields, financial data, and questionnaire answers at rest;
  • Encrypted transmission via TLS/HTTPS;
  • Role-based access controls limiting data access to authorized personnel only;
  • Session-based authentication with server-side validation on every request;
  • Activity logging for all significant data access and modification events.

Disclaimer: No method of electronic storage or transmission is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security and expressly disclaim liability for unauthorized access, disclosure, alteration, or destruction of your information that results from circumstances beyond our reasonable control, including but not limited to cyberattacks, zero-day exploits, insider threats, or force majeure events.

You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account.

6. Data Retention

We retain your personal information and account data for ten (10) years following the last active use of the Service, or longer if required by applicable law, regulation, or legitimate legal hold. This retention period reflects the standard recordkeeping requirements applicable to tax and financial documentation.

After the applicable retention period, data is deleted or anonymized in accordance with our internal data lifecycle procedures. Retained data remains subject to the security controls described in Section 5.

Uploaded documents and questionnaire responses are retained as long as the associated account remains active and for the retention period thereafter, subject to valid deletion requests as described in Section 7.

7. Your Rights and Choices

7.1 Access and Correction

You may access and update your account profile information at any time by logging into the Service. For corrections to information you cannot update directly, contact us at admin@vaultbridgefo.com.

7.2 Data Deletion

You may request deletion of your account and associated personal information by contacting us at admin@vaultbridgefo.com. We will process verified deletion requests within thirty (30) days, subject to the following:

  • We may retain information as required by law, regulation, or applicable legal hold;
  • We may retain information necessary to resolve disputes, enforce agreements, or maintain records of completed transactions for the retention period described in Section 6;
  • Information shared with authorized Professionals prior to deletion may remain in those Professionals' own recordkeeping systems, over which we have no control.

7.3 Withdrawal of Consent

Where we process information based on your consent, you may withdraw consent at any time by contacting us. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal, and does not obligate us to delete information we are otherwise permitted to retain.

7.4 California Residents (CCPA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at admin@vaultbridgefo.com. We will not discriminate against you for exercising your privacy rights.

8. Third-Party Services and Links

The Service may contain references or links to third-party websites, tools, or services. This Privacy Policy does not apply to those third parties. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party service. We strongly encourage you to review the privacy policies of any third-party services you interact with.

9. Professional Responsibility

Professionals who access Client data through the Service are independently responsible for complying with all applicable laws and professional standards governing the handling of client information, including but not limited to IRS Circular 230, applicable state bar rules, SEC regulations, FINRA rules, and any other professional or regulatory obligations. VaultBridgeFO does not supervise Professionals and assumes no responsibility for their compliance or actions with respect to Client data.

10. Children's Privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at admin@vaultbridgefo.com and we will take prompt steps to delete it.

11. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Material changes will be communicated by updating the Effective Date above and, where feasible, by providing notice through the Service or via the email address associated with your account at least thirty (30) days before the change takes effect (or as required by law). Your continued use of the Service after the effective date of any change constitutes acceptance of the updated Privacy Policy. If you do not agree to a material change, you must discontinue use of the Service and request account deletion.

12. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the Commonwealth of Virginia, without regard to its conflict of law provisions, and subject to the dispute resolution provisions in our Terms of Service.

13. Contact Us

Questions, concerns, or requests regarding this Privacy Policy should be directed to:

VaultBridgeFO
Email: admin@vaultbridgefo.com

This Privacy Policy was last updated on March 16, 2026. Prior versions are available upon request.