Privacy Policy
Last updated: August 24, 2026
1. Introduction
SafeCardVault ("we," "our," or "us") provides a secure card-on-file collection service for businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our service.
2. Information We Collect
2.1 Business Account Information
When businesses register for SafeCardVault, we collect:
- Business name and contact information
- Employee names and email addresses
- Authentication credentials (via Microsoft Entra ID)
2.2 Payment Card Data
Payment card data (card number, CVV, expiration date) is collected directly by our PCI-compliant vault provider via a hosted iframe. SafeCardVault never receives, processes, or stores raw card numbers or CVV codes. We store only:
- Card brand (e.g., Visa, Mastercard)
- Last four digits of the card number
- Expiration month and year
- Cardholder name
- An opaque token reference to the vault-stored card
2.3 Usage Data
We collect audit logs of actions performed within the service, including timestamps, IP addresses, user agents, and action types for security and compliance purposes.
3. How We Use Information
- To provide and maintain the SafeCardVault service
- To authenticate and authorize users
- To process payment card collection requests
- To maintain audit trails for compliance
- To detect and prevent fraud or abuse
- To communicate with you about the service
4. Data Sharing
We do not sell your information. We share data only with:
- Vault Provider: Card data is processed by our PCI DSS Level 1 certified vault provider
- Cloudflare: For content delivery and security (WAF, DDoS protection)
- Microsoft: For authentication via Entra ID (if configured)
- Legal Requirements: When required by law or to protect our rights
5. Data Security
We implement industry-standard security measures including:
- TLS 1.3 encryption in transit
- AES-256 encryption at rest
- PCI DSS Level 1 compliance (via vault provider)
- SOC 2 Type II audited infrastructure
- Role-based access control
- Complete audit logging
6. Data Retention
We retain business account data for the duration of the service agreement. Audit logs are retained for a minimum of 7 years for compliance purposes. Card token references are retained until revoked by the business or customer.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
8. Contact Us
For privacy-related inquiries, please contact us at our contact page.
