Privacy policy
Draft pending legal review — last revised September 13, 2026
Stashtab, Inc. (the “Company”, “we”, “us”, and “our”) is committed to maintaining robust privacy protections for the people who use Vault by Stashtab. This Privacy Policy (“Privacy Policy”) is designed to help you understand how we collect, use, and safeguard the information you provide to us and to assist you in making informed decisions when using our Service.
For purposes of this Privacy Policy, “Site” refers to the Company’s website at vault.stashtab.gg. “Service” refers to the Vault by Stashtab custody and fulfillment service accessed through the Site, the partner console, and the versioned API, in which partner organizations place collectibles in Stashtab custody and instruct their fulfillment. “You” refers to you, as a user of our Site or our Service.
By accessing our Site or our Service, you accept our Privacy Policy and our Terms of Service (available at vault.stashtab.gg/terms), and you consent to our collection, storage, use, and disclosure of your information as described in this Privacy Policy.
Who this covers
Vault by Stashtab (“Vault”) is a custody and fulfillment service for platforms whose users win, buy, or hold real trading cards. Our customers are those platforms (each a “Partner Organization”), and the people who use Vault are their staff. This policy describes what Vault does with information about you as a member of a Partner Organization, and with the information your Partner Organization sends us about its own users so that we can ship items to them.
Information we collect
Personal information you give us. When a Vault identity is created for you we store your name, email address, a hashed password, and session records. We do not store your password in a form we can read. When your organization invites a colleague we store the invited email address, the role offered, and who sent the invitation.
Information collected through technology. Vault sets a session cookie so you stay signed in, and it records product usage events and error reports through the analytics and error-monitoring providers listed below, including the page you were on, your browser and device type, and the time of the event. These records are keyed to your identity or your organization’s identifier.
Organization and API records
For each Partner Organization we store its name, its members and their roles, and the API keys it creates. An API key’s secret is shown once when it is created and is then stored only as a one-way hash; we cannot recover it. For each API request we keep the key used, the request identifier, and, for idempotent requests, a record that lets us return the same result if the request is repeated.
Custody and fulfillment records
Catalog and manifests. The products your organization defines, the manifests it submits declaring what is being sent into custody, and the reconciliation of each manifest against what our staff received at the dock.
Items in custody. Each item’s identity (for a graded slab, its grader and certificate number), its status history from receipt through fulfillment, withdrawal, or transfer, and the photographs our staff take when digitizing it.
Addresses and shipments. The verified addresses your organization registers for withdrawals (a recipient name and postal address), and for every fulfillment a snapshot of the shipping address and any special instructions you supplied, plus the carrier, service, tracking number, and delivery status we record.
Webhooks. The endpoint URLs your organization subscribes and the events we delivered to them. Webhook signing secrets are stored only as a one-way hash.
Information about your users
When your Partner Organization instructs a shipment to one of its users, it sends us that person’s name and shipping address. We process that information only to prepare, ship, and track the parcel and to keep the record of the fulfillment; we do not contact those people, build profiles of them, or use their information for any other purpose. Your organization is responsible for giving its users the privacy notices their law requires before sending us their details.
What Vault does not collect
Vault does not collect payment card numbers, bank details, or payout information through the Site, console, or API, and it does not store the purchase price your users paid for an item. It does not read your organization’s own systems; it receives only what your organization sends.
How we use and share information
We use the information above to operate Vault for your organization: to keep you signed in, to receive and hold the items you send, to ship them where you instruct, to deliver the webhooks you subscribe, to respond to your requests, and to understand how Vault is used so we can improve it. We do not sell, trade, or rent your information or your users’ information, and we do not use it for advertising.
Shipping carriers receive the recipient name, address, and parcel details for each shipment your organization instructs, because that is what delivering it requires. Carriers are not our service providers for any other purpose, and their own privacy policies govern what they do with tracking data.
Service providers
Vault by Stashtab relies on the following providers to operate. Each processes information on our instructions and for no other purpose.
Neon — Managed Postgres database hosting
Partner identities, organization memberships, hashed API keys, catalog, manifest, custody, address, fulfillment, transfer, and webhook records.
Vercel — Application hosting
Application traffic for the website, partner console, and API.
PostHog — Product analytics
Product usage events from the website and console, keyed to a partner identity or organization identifier.
Sentry — Error monitoring
Error reports and diagnostic context from failed requests and background work.
How long we keep data
Identity, organization, and API key records are kept for as long as your organization’s account is open. Custody records — manifests, item histories, photographs, and fulfillment, withdrawal, and transfer records — are retained as the operational record of what we held and where it went, because they are how we and your organization prove chain of custody. Shipping address snapshots are retained with the fulfillment they belong to.
Deleting your data
To revoke an API key, remove a member, close a Vault identity, or request deletion of your organization’s data, email us at contact@stashtab.gg. We will verify the request with an owner of the Partner Organization. Custody records for items still in our possession cannot be deleted until those items have left custody.
How we protect information
Your password is stored only as a salted hash, and API key secrets and webhook signing secrets are stored only as one-way hashes. All traffic between your browser or systems and Vault travels over TLS, every API request is authenticated to a single Partner Organization, and our infrastructure providers restrict access to the systems that hold your data.
These measures do not guarantee that your information will never be accessed, disclosed, altered, or destroyed by a breach of our safeguards. We urge you to keep your account credentials confidential and to sign out after each session on a shared device. By using our Service, you acknowledge that you understand and agree to assume these risks.
Legal disclosures and business transfers
We may share information with outside parties if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to meet any applicable legal process or enforceable governmental request; to enforce our Terms of Service, including investigation of potential violations; to address fraud, security, or technical concerns; or to protect against harm to the rights, property, or safety of our users or the public as required or permitted by law.
In the event we undergo a business transaction such as a merger, acquisition by another company, or sale of all or a portion of our assets, your information may be among the assets transferred. You acknowledge and consent that such transfers may occur and are permitted by this Privacy Policy, and that any acquirer of our assets may continue to process your information as set forth in this Privacy Policy.
Your rights regarding your information
You may ask us at any time what information we hold about your account, ask us to correct it, or ask us to delete it, by emailing contact@stashtab.gg. We will verify that the request comes from the account holder before acting on it, and we will respond within the time applicable law requires.
We do not send promotional email. The email we send is administrative — for example a security notice, a service change, or a response to your request — and you cannot opt out of administrative email while your account is open.
Links to other websites
As part of the Service, we may provide links to or compatibility with other websites or applications. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain. This Privacy Policy applies solely to information collected by us through the Site and the Service. It does not apply to your use of a third-party website or service reached from our Site, and the privacy policy of that website or service governs your use of it. We encourage you to read the privacy statements of other websites before proceeding to use them.
Children’s privacy
The Site and the Service are business tools and are not directed to anyone under the age of 18. We do not knowingly collect or solicit information from anyone under the age of 13, or allow anyone under the age of 13 to sign up for the Service. If we learn that we have gathered personal information from anyone under the age of 13 without the consent of a parent or guardian, we will delete that information as soon as possible. If you believe we have collected such information, please contact us at contact@stashtab.gg.
Changes to this Privacy Policy
We reserve the right to change this Privacy Policy and our Terms of Service at any time. We will notify you of significant changes by sending a notice to the primary email address on your account or by placing a prominent notice on our Site. Significant changes will go into effect 30 days following such notification; non-material changes or clarifications take effect immediately. The revision date at the top of this page records the latest change, and you should check this page periodically for updates.
Contact us
If you have any questions about this Privacy Policy or the practices of this Site, contact us by email at contact@stashtab.gg.