Snapshot 19641
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Live Webinar Evaluating 3DS: Is It Worth It? Register now Home Products Customers Pricing Docs Resources Careers Log in Talk to an Expert Log in Talk to an Expert Privacy Policy Legal Last updated / January 28, 2026 Introduction Evervault is committed to protecting the privacy of users’ personal data while delivering secure, encrypted processing services. This policy outlines how we collect, use, share, and secure personal data in compliance with GDPR, CCPA, HIPAA (where applicable), UK GDPR, and POPIA. Purpose This policy aims to ensure transparency in how Evervault manages personal data, outlines customer rights, and details our use of third-party service providers. It forms part of our contractual commitment and regulatory obligations. Policy Statements Data Collection We collect and process the following categories of data: Identity & Contact Data (e.g. name, email, phone, roles specific professional information) Financial & Transaction Data Usage, Profile, and Device Data Marketing Preferences and Feedback Data is obtained directly, through interactions with our services, from cookies and tracking tools, and occasionally from third parties. Data Usage We process personal data to: Provide and improve our services Personalize user experiences Deliver support and security Comply with legal obligations Conduct research, training, and quality control Perform marketing within appropriate legal mechanism Facilitate service updates and communications Assess candidates for hiring We do not sell personal data. Data Sharing We share personal data only when necessary: Internally within Evervault With vetted third-party service providers (see table below) As authorized by users or required by law During mergers, acquisitions, or corporate changes We provide relevant customers 60 days’ notice before onboarding new sub-processors in our production stack. Customers may object in that window. We will offer alternatives if needed, as per GDPR requirements, or may terminate the contract. International Transfers Evervault may transfer personal data internationally. Such transfers will comply with applicable data protection regulations and rely on adequate safeguards, including Standard Contractual Clauses or adequacy decisions. Data Security & Retention We apply technical and organizational safeguards, including: PCI DSS Level 1 compliance External SOC 2 assessments Security, privacy and resilience by design Data is retained as long as required for service delivery, legal compliance, or legitimate interests in alignment with relevant regulatory requirements. Your Rights Depending on your jurisdiction, you may have the right to: Access, correct, or delete personal data Restrict or object to processing Withdraw consent Port your data Lodge a complaint with your regulator Contact: [email protected] to exercise any of the above. Roles and Responsibilities Role Responsibility Evervault (Data Processor & Controller) Manages data in accordance with applicable law and contractual obligations where Evervault are the direct Controller Customers (Data Controllers for End Users) Inform and manage rights of their own users where Evervault acts as processor Compliance Oversees compliance, handles rights requests, and engages with supervisory authorities Service Providers Process data under Evervault instructions, bound by contracts and data protection standards Users Maintain updated contact details and exercise rights as required Service Provider Table Provider Purpose Data Shared Google Analytics, collaboration User data HubSpot Analytics, CRM User data, contact data Customer.io, Plausible, Common Room, Amplemarket Monitoring, analytics, tag management Usage, traffic data Twilio, SendGrid Messaging Email, contact data Vercel Hosting, Analytics User and usage data Zoom, Slack Communication Conversational, internal data Stripe Payments Financial data Cloudflare Bot Prevention, Hosting Web traffic Alguna Invoicing Transaction Data OpenAI Page Protection,Contextualisation, Services Public facing website scripts and security Headers AWS Hosting User Data Clone Systems PCI DSS ASV Vulnerability Scan Data GitHub Code Repository Code Clickhouse Database as a Service Analytics Data Cybersource Payments Services Payments Data Launch Darkly Feature Flags Code Auth-0 Authentication Service Authentication Data Plain Support Chat Bot Service Support Queries Deel, Ashby Candidate Management Applicant Data ChargebackStop Payments Services Payments Data Changes to sub-processors are subject to 60-day notice to customers. Customers may opt out of such changes per their contracts and regulatory rights. Jurisdiction and Regulation Specific addendums HIPAA Where Evervault processes Protected Health Information (PHI), we adhere to HIPAA regulations by implementing appropriate safeguards, policies, and training to ensure the confidentiality, integrity, and availability of PHI. It must be noted of course that Evervault only ever processes HIPAA data. HIPAA related data is never stored persistently by Evervault. CCPA Under the CCPA, you have the right to request disclosure about the personal information we collect, request deletion of your data, and opt-out of sharing your personal information for targeted advertising. You can exercise these rights by contacting [email protected]. Subscribe to our newsletter Sign up to get access to the latest product insights. Legal & Compliance Terms of Service Privacy Policy Cookie Policy PCI Level 1 SOC 2 Type II Products Relay Functions Enclaves PCI DSS Compliance Page Protection ASV Scans Card Collection and Display Card Collection and Display 3D Secure Network Tokens Card Insights and Verification Card Account Updater Apple and Google Pay Company Company Blog Careers Pricing Customers Contact Us Partnerships Resources Documentation Guides Papers Press Legal & Compliance Terms of Service Privacy Policy Cookie Policy PCI Level 1 SOC 2 Type II © 2026 Evervault Inc. All rights reserved. All systems normal