How we handle your data.
Last updated: 28 August 2026. This notice covers Seller Photo Prep on iPhone, iPad, and Mac, the website and browser photo checker, App Store purchases, the optional done-for-you pilot, the legacy direct Mac edition, licensing, recovery, and support.
Who is responsible
The data controller is Gareth Lee Wiggins, sole trader trading as VaultDevLabs, at 60 Artillery Gardens, Canterbury, CT1 1LG, United Kingdom. Privacy questions and rights requests can be sent to support@vaultdevlabs.com.
Product photos and local files
The app processes product photos on your device. On iPhone and iPad, it reads only photos or files you choose and presents completed exports through the native share sheet. On Mac, it reads folders you choose and writes exports only to a location you select. It does not upload product photos, photo filenames, SKUs, reports, analytics identifiers, advertising identifiers, or marketplace account credentials to VaultDevLabs.
The browser checker reads supported image dimensions, format, and filename in your browser. Photo bytes and filenames are not sent to VaultDevLabs. The selected-file state remains in the page while you use the checker and is discarded when the page is reloaded or closed.
App Store purchases
Apple supplies the App Store download and processes the optional Lifetime Pro non-consumable in-app purchase. VaultDevLabs does not receive your full payment-card details. The app asks StoreKit for the current entitlement and transaction status so it can unlock or restore Pro. A cancelled, pending, unverified, refunded, or revoked transaction does not unlock Pro. Apple processes App Store purchase data under Apple's own terms and privacy information.
Legacy direct-edition purchase and fulfilment data
Stripe processes payment and may make order information available to us, including your name, checkout email, required GB delivery address, billing details, payment status, currency, amount, tax amount and policy identifiers, and Stripe transaction or checkout identifiers. We do not receive your full payment-card number. We use the delivery country to enforce the pre-payment GB-only offer, and use the checkout email and verified immutable offer identifiers to prevent duplicate fulfilment, create or associate a licence, send the purchased release through a private time-limited download, and provide purchase support.
The Stripe receipt, private download email, and licence-key email are separate messages. The durable download confirmation contains the purchased offer, release, entitlement, compatibility, price, tax, territory, cancellation and consent record, and the exact versioned terms snapshot. Resend processes the recipient address and that message content to deliver it.
Licence activation, status, and recovery
The direct Mac app sends the following data to the licensing API when needed:
- The licence key supplied in your purchase email.
- A randomly generated installation or device identifier stored by the app.
- A short device or platform name reported by the app.
- Activation time, last-seen time, licence status, plan, entitlement result, and device-limit information.
- Signed offline-entitlement data needed to verify temporary offline access.
The app sends the licence key and device identifier again for status checks, protected downloads, and update eligibility. If you request licence recovery, it sends the email address you enter so the service can look for an active matching purchase and send a recovery message. Recovery responses do not disclose whether an account exists to unauthenticated callers.
On the Mac, the licence key, installation identifier, and signed offline-entitlement cache are held in protected local app storage, including the macOS Keychain where supported. Removing or resetting the licence clears the applicable local records; server-side purchase and activation records are handled under the retention criteria below.
Website analytics and technical logs
The website records limited first-party events such as page views, App Store clicks, checker starts and completions, aggregate ready/prepare/review counts, sample downloads, service-offer views and intake progress, direct-checkout clicks, support intent, and completed direct purchases. App Store click events contain only a bounded CTA label, platform label, and fixed destination label. Checker analytics includes the marketplace, file count, result totals, and rules version, but not photo bytes or filenames. Done-for-you analytics may include a marketplace, broad photo-count band, broad deadline band, and fixed page source; it does not include the email address or free-text project note entered in the enquiry form.
The done-for-you pilot does not accept photo uploads on this website. If you prepare an enquiry, your browser opens your own email application with the details you entered. If you send that email, VaultDevLabs receives the contact address and project details needed to assess and reply to the request. Product photos are requested only after a written scope and price are agreed, using the transfer method stated in that correspondence.
Before a first-party analytics event is stored or forwarded, the location is reduced to the route path without its query or fragment. Only the allowlisted campaign fields utm_source, utm_medium, utm_campaign, and utm_content, plus the coarse hostname of an external referring site, may be retained. Full page and referrer URLs, referrer paths or queries, other query parameters, and utm_term are not retained in the analytics event. Events use a rotating pseudonymous visitor-day hash and a broad device category. The analytics event does not store your IP address and is not used to build a cross-site advertising profile.
The website also uses Vercel Web Analytics for aggregate page-view reporting. Vercel documents this service as cookie-free and based on anonymised, daily-reset visitor data. Site operators can mark their own browser with a first-party preference cookie so those first-party events are classified as internal and excluded from customer totals; the Vercel Analytics script is not loaded for that browser.
As with most internet services, hosting, security, and API providers may process IP addresses, request headers, timestamps, and error or security logs to deliver the service, enforce rate limits, diagnose failures, and prevent abuse. This technical processing is separate from the first-party analytics event record.
Support data
If you contact support, we process your email address and the information you choose to send, which may include a Mac model, macOS version, marketplace preset, image count, screenshots, and troubleshooting details. Do not send licence keys, payment-card details, or product photos unless support specifically asks for information through an appropriate channel.
Why we use this data
- Contract: to take payment, deliver the purchased app, issue and verify a licence, recover access, provide eligible updates, and respond to purchase support.
- Legitimate interests: to secure the service, prevent fraud and duplicate fulfilment, enforce device limits, understand aggregate website use, diagnose faults, and improve the product without collecting customer photos.
- Legal obligations: to keep records required for accounting, tax, disputes, or lawful requests.
- Consent: where a specific optional use requires consent; you may withdraw it for future processing.
Service providers and transfers
Apple supplies App Store distribution, StoreKit purchase processing, and purchase restoration. For the legacy direct edition, Stripe provides hosted payment processing, Resend provides transactional email, Vercel hosts the public website and protected download service, and Render hosts the shared licensing API. These providers process only the data needed for their role under their own terms and data-protection commitments. They may process data outside the UK; where UK data-protection law requires a transfer safeguard, the relevant provider or controller must use an approved safeguard.
We do not sell personal data, use third-party advertising pixels, or connect to Etsy, Amazon, eBay, Shopify, or other seller accounts.
Retention
- Product photos and browser-checker files: not retained by VaultDevLabs because they are not uploaded for checking or app processing.
- Purchase, payment, and fulfilment records: kept for contract administration, fraud prevention, accounting, tax, and legal-claim periods, then deleted or anonymised when no longer required.
- Licence and device records: kept while needed to provide the purchased licence, enforce activation limits, recover access, establish update eligibility, and resolve disputes; obsolete records are then deleted or anonymised unless law requires longer retention.
- Recovery and support communications, including service-pilot enquiries: kept while the request is handled and afterwards only as needed for follow-up, fulfilment, security, service history, or legal claims.
- Analytics and technical logs: kept only for the operational, security, and aggregate reporting period for which they are useful, then deleted or aggregated so they no longer identify a visitor. The analytics visitor hash changes each day.
Exact periods can vary by record and legal obligation. You may ask for the period or criteria applying to your records by emailing the privacy contact.
Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to be informed, access your personal data, correct it, erase it, restrict its use, receive portable data, object to processing, and withdraw consent. These rights are not absolute; for example, some purchase records may need to be kept for legal obligations or claims.
Send a request to support@vaultdevlabs.com and state the right you want to exercise. We may request proportionate information to confirm your identity. You can also complain to the Information Commissioner's Office.
Changes to this notice
Material changes will be posted on this page with a revised date. A new notice will not retrospectively authorise a materially different use where the law requires another basis or fresh consent.