Skip to content
FanVault
Home / Privacy Policy
🛡️ GDPR & CCPA Compliant · Last Updated October 2026

Privacy Policy

FanVault is operated by Solotob Technologies LTD (“we”, “our”, or “us”), providing digital milestone time capsules and permanent community archives for online creators and their communities. We believe your memories, letters, and identity should remain private, encrypted, and handled with institutional rigor.

1. Information We Collect

We collect only the minimum personal data required to provide our time capsule vault services, verify transactions, deliver email notifications, and facilitate creator payouts.

A. Information Provided by Fans
  • Author Name or Pseudonym: Displayed on commemorative passes and letter headers.
  • Email Address: Used solely to dispatch your sealed keepsake link, unique claim token, and milestone reveal alerts.
  • Letter Content & Predictions: The confidential text and message you seal into the creator’s vault.
  • Optional City / Location: Placed optionally on your digital postcard pass.
  • Contribution Amount: The dollar amount chosen to champion the creator’s milestone.
B. Information Provided by Creators
  • Creator Name & Channel Handle: Public identifier for your vault URL (/with/{slug}).
  • Connected Platforms: Multi-platform links (YouTube, Twitch, TikTok, Kick, Podcast, Instagram, X/Twitter, Substack).
  • Creator Email Address: Used exclusively for magic login links and critical platform alerts.
  • Milestone Goals & Reveal Dates: Public target events and unlock schedules.
  • Stripe Connect Account Identifiers: Tokenized IDs required to deposit the 80% creator cut directly into your bank account.
C. Technical & Log Data

When you visit FanVault, our servers log standard HTTP request metadata including IP address, user-agent string, and timestamp. This data is used solely for DDoS prevention, rate-limiting, and fraud mitigation, and is automatically purged after 90 days.

2. How We Use Your Data & Legal Basis

Under the EU General Data Protection Regulation (GDPR) and UK Data Protection Act, our legal basis for collecting and processing your personal data is:

  • ✓
    Performance of a Contract: Providing the digital time capsule service, locking letters until milestone dates, delivering your commemorative passes, and transferring creator earnings.
  • ✓
    Legitimate Business Interests: Maintaining platform stability, preventing fraudulent charges, debugging software errors, and enforcing our terms of service.
  • ✓
    Legal Compliance: Maintaining financial ledgers and accounting records as mandated by applicable tax and commercial authorities.
We Never Sell Data: FanVault has never sold, rented, or monetized personal information, letters, email addresses, or browsing history to third-party data brokers or advertisers, and will never do so.

3. Payment Processing & Stripe Tokenization

All financial payments and card transactions are processed securely through Stripe, Inc., a certified PCI-DSS Level 1 Service Provider.

FanVault never views, handles, or stores raw payment card numbers, CVVs, or expiration dates on our application servers. Payment data is encrypted directly in your browser and transmitted straight to Stripe’s secure infrastructure. We receive only a tokenized payment reference (e.g., cs_live_...) and payment confirmation status.

Creator payouts are governed by Stripe Connect terms. Creators maintain their own payout accounts with Stripe and are subject to Stripe’s identity verification procedures.

4. Sub-processors & Infrastructure Partners

We partner with world-class cloud service providers to maintain the security, redundancy, and speed of our services:

Stripe, Inc. Payment processing, fraud mitigation & Stripe Connect creator payout routing.
Amazon Web Services (AWS) Encrypted cloud computing hosting, managed database storage, and automated backups.
SendlyAI / Amazon SES Transactional email infrastructure, encrypted SMTP delivery, and deliverability monitoring.
Cloudflare / Caddy Automated TLS 1.3 encryption, DDoS mitigation, and edge traffic routing.

5. Your Rights (GDPR & CCPA/CPRA Compliance)

Regardless of your geographic location, FanVault extends comprehensive privacy rights to all users:

Right to Access & Portability

You may request a machine-readable export of all letters, transactions, and account records associated with your email address.

Right to Erasure ("Right to be Forgotten")

You may request permanent deletion of your letters, author identity, or creator vault. See our Data Deletion Procedure.

Right to Rectification

You may update your channel handle, connected platforms, milestone details, or correct inaccuracies anytime.

Right to Object & Restrict

You may withdraw consent for optional marketing communications or restrict processing of specific records.

To exercise any of these rights, simply email our Data Privacy Officer at privacy@getfanvault.com. We respond to verified requests within 48 business hours with zero processing fees.

6. Security Architecture & Retention

We employ technical safeguards including AES-256 database encryption at rest, mandatory TLS 1.3 transit encryption, cryptographic token hashing (SHA-256) for fan letter claim links, and short-lived 30-minute magic login sessions.

For detailed lifecycle schedules regarding active letters, tax ledgers, and log rotation, please review our full Data Retention Policy.

Questions or Concerns?

If you have questions regarding this Privacy Policy or wish to lodge a formal data inquiry, please contact our Legal & Compliance Team: