Privacy Policy
This Privacy Policy explains how VaultKey ("we", "us") collects, uses, and shares information when you visit our marketing website at getvaultkey.com, access our API, or use our wallet infrastructure platform. Please read this policy carefully. If you have questions, contact us at info@getvaultkey.com.
Who We Are
VaultKey operates the website at getvaultkey.com and the VaultKey API platform, which provides wallet infrastructure, signing services, and stablecoin transfer capabilities to developers and businesses. We are the data controller for the information described in this policy.
What We Collect
- Usage and device data (marketing site): We use privacy-friendly analytics to understand overall traffic and usage patterns such as pages visited, referrers, and device type. This data is aggregated and not used to identify you individually.
- Server and security logs: Our hosting providers may process IP addresses and basic request metadata transiently for security, reliability, and debugging purposes.
- Account data: When you sign up for VaultKey, we collect information such as your name, email address, and organization details necessary to create and manage your account.
- API usage and platform data: When you use the VaultKey API, we process data necessary to deliver the service, including API keys, wallet identifiers, blockchain addresses, transaction metadata, and job status records. We do not store private keys in plaintext — keys are encrypted at rest using a KMS provider.
- Blockchain data: Wallet addresses and transaction hashes are inherently public on blockchain networks. We are not responsible for information visible on public blockchains.
How We Use Information
- Provide, operate, and maintain the VaultKey platform and API.
- Authenticate requests and enforce API key access controls.
- Process wallet creation, signing, sweep, and transfer operations.
- Monitor platform health, security, and reliability.
- Understand aggregated usage to improve performance and features.
- Send transactional communications related to your account.
- Comply with legal obligations and enforce our terms.
Legal Bases
Where applicable (e.g., in the EEA/UK), we rely on contract performance to provide the API and platform services you sign up for, legitimate interests to operate and secure our infrastructure and measure aggregated site usage, and legal obligation where required by law.
Sharing and Processors
We share information with service providers who process data on our behalf, including:
- Hosting and infrastructure: Cloud providers for serving the API, database storage, and security.
- Key management: KMS providers (AWS KMS, GCP KMS, or HashiCorp Vault depending on deployment) for encrypting and decrypting wallet keys.
- Analytics: Privacy-friendly analytics for aggregated usage metrics on the marketing site.
- Blockchain networks: RPC providers to broadcast transactions and query balances on behalf of your wallets. Addresses and transaction data submitted to these networks become publicly visible on-chain.
We do not sell your personal information. We may disclose information if required by law, regulation, or to protect our rights, users, or the public.
Key Security
Wallet private keys generated through VaultKey are encrypted at rest using a KMS provider and are never stored or logged in plaintext. Signing operations are performed in memory and the decrypted key material is not persisted after the operation completes. You are responsible for securing your API keys and secrets, which grant access to your wallets.
Retention
We retain account and platform data for as long as your account is active or as needed to provide the service, comply with legal obligations, and resolve disputes. Aggregated analytics data does not identify individuals. Job and transaction records may be retained for audit and compliance purposes.
International Transfers
Our providers may process data in locations outside of your country of residence. Where required, we implement appropriate safeguards for cross-border transfers in accordance with applicable data protection law.
Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your information; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. Note that certain data — such as transaction records written to public blockchains — cannot be deleted by us. To exercise your rights, contact us using the details below.
Children
Our services are not directed to children, and we do not knowingly collect personal information from anyone under 18.
Changes
We may update this policy from time to time. The "Last updated" date below reflects the most recent changes. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.
Contact
For privacy requests or questions, email us at info@getvaultkey.com.
Last updated: 6/5/2026