Legal

Privacy Policy

Version: 1.0  | Effective date: 23 July 2026  | Last updated: 23 July 2026

Applies to: getluxevault.com and all associated subdomains, applications, and services operated by GetLuxeVault.

1. Introduction

GetLuxeVault (trading as LuxeVault) is committed to protecting and respecting your privacy. This Privacy Policy sets out in full the basis on which any personal data we collect from you, or that you provide to us, will be processed. It applies to all individuals who interact with the LuxeVault platform, including:

  • buyers, prospective buyers, and site visitors who browse the platform, submit acquisition enquiries, use the AI Concierge, or participate in the AI Lifestyle Advisor;
  • partners — including luxury real estate dealers, hypercar specialists, yacht brokerages, private aviation firms, fine art dealers, armored vehicle manufacturers and dealers, watch specialists, builders, agencies, agents, and other service providers — who apply to, or are enrolled in, the LuxeVault partner network;
  • individuals who communicate with LuxeVault by email, telephone, or through the platform's contact forms;
  • subscribers to LuxeVault's newsletter or any follow-up email programme.

Please read this Privacy Policy carefully. By using getluxevault.com or any of our services, you acknowledge that you have read and understood this policy and agree to the practices described herein.

LuxeVault is committed to protecting personal information and has designed its privacy practices with applicable privacy laws, including GDPR, UK GDPR, PIPEDA, and similar regulations, in mind. Specific sections of this policy address the requirements of:

  • the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018;
  • the EU General Data Protection Regulation (Regulation 2016/679) (EU GDPR);
  • the California Consumer Privacy Act (CCPA) 2018, as amended by the California Privacy Rights Act (CPRA) 2020;
  • the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

Where differences in applicable law exist between these regimes, the relevant section of this policy addresses those differences. If you are unsure which regime applies to you, please contact us using the details in Section 17.

2. Who We Are

The data controller responsible for your personal data is:

GetLuxeVault

Trading as: LuxeVault

Website: getluxevault.com

Privacy enquiries: privacy@getluxevault.com

General contact: hello@getluxevault.com

LuxeVault is a curated luxury discovery and referral platform. We connect qualified, serious buyers with verified partner businesses across categories including premium residential and investment real estate, hypercars, private aviation, superyachts, fine art, armored vehicles, luxury watches, and specialist professional services. Our platform operates across multiple markets, including the United Kingdom, the European Union, North America, the Middle East, and Asia.

LuxeVault is not a transactional marketplace. We facilitate the introduction between buyer and partner. We are not a party to any transaction, do not hold any assets, and are not a licensed financial adviser, real estate agent, broker, or dealer. Our role is discovery, curation, and referral.

3. Scope of This Policy

This Privacy Policy applies to all personal data processed by LuxeVault across:

  • the LuxeVault website and all pages accessible at getluxevault.com;
  • the AI Concierge and AI Lifestyle Advisor tools hosted on the platform;
  • buyer enquiry submission forms, including general enquiries, product-specific acquisition requests, and armored vehicle enquiries;
  • the partner application and onboarding process, including the partner portal;
  • the builder application and builder portal;
  • seller onboarding, including listing submission, verification, and commission agreement workflows;
  • CRM and lead management activities in which LuxeVault processes or facilitates the transmission of buyer contact data to verified partners;
  • email communications sent by or through LuxeVault using Resend, including enquiry confirmation emails, AI-generated follow-up emails, partner routing notifications, and platform updates;
  • authentication and session management via Clerk;
  • payment processing for commission invoices and any applicable subscription services via Stripe;
  • analytics and performance monitoring tools;
  • cookies and related tracking technologies.

This policy does not apply to third-party websites, applications, or services linked from LuxeVault. Once you leave our platform by clicking a partner profile link, a product listing link, or any other outbound link, the privacy practices of that third-party site or service govern the processing of your data.

4. The Personal Data We Collect

LuxeVault collects personal data from multiple categories of individuals across different areas of the platform. We describe each category below.

4.1 Buyers, Prospective Buyers, and Site Visitors

When a visitor browses the LuxeVault platform or submits an enquiry, we may collect the following categories of personal data:

CategoryExamplesLawful Basis
Identity dataFirst name, last name, company name (if provided)Legitimate interests; contract performance
Contact dataEmail address, telephone number. For armored vehicle enquiries specifically, preferred contact method (Email, Phone, or WhatsApp) is also collected.Legitimate interests; contract performance
Enquiry dataCategory of interest, budget range, target location, timeline, specific asset or listing of interest, free-text message describing requirementsLegitimate interests; contract performance
Profile dataLifestyle quiz answers, investment preferences, saved collections, wishlist items, lifestyle tags selected via the AI Lifestyle AdvisorConsent; legitimate interests
Usage dataPages visited, links clicked, search queries entered, time spent on pages, scrolling behaviour, referral source (e.g. Google, direct), device type, operating system, browser type and versionLegitimate interests
Technical dataIP address, approximate geographic location derived from IP (city/country level), session identifiers, HTTP headersLegitimate interests
Communication dataContent of emails or messages you send to LuxeVault, responses to follow-up emails, preferences relating to email communicationsLegitimate interests; consent

4.2 Partner Applicants and Verified Partners

When a business or individual applies to join the LuxeVault partner network — whether as a luxury dealer, brokerage, builder, agency, agent, service provider, or in any other partner category — we collect the following:

CategoryExamplesLawful Basis
Business identity dataLegal business name, trading name, registered address, country of incorporation, business registration number, company type, VAT or tax identification number where providedContract performance; legal obligation
Contact dataPrimary contact name, email address, telephone number, website URLContract performance
Credentials and verification dataAuthorised dealer certificates, professional licences, regulatory authorisations, membership of professional bodies, portfolio documentation, prior transaction evidence, references — submitted during the verification processContract performance; legal obligation
Listing and inventory dataDescriptions, specifications, photography, pricing information, and supporting materials submitted by the partner for display on the platformContract performance
Profile dataPartner biography, company history, specialisms, global areas of operation, office locations, social media handles, verification levelContract performance
Commission and financial dataCommission rates agreed per enquiry, VAT status, invoice history, payment recordsContract performance; legal obligation
Authentication dataLogin credentials and session tokens managed via Clerk, access logs, portal activityContract performance
Communication dataContent of emails and messages exchanged with LuxeVault via the Partner Portal, email, or other channelsLegitimate interests; contract performance
Click-wrap acceptance dataTimestamp and version of Partner Agreement accepted via the Partner Portal click-wrap mechanism, partner name as logged at the time of acceptanceLegal obligation; contract performance

4.3 AI Concierge and AI Lifestyle Advisor Users

LuxeVault operates two AI-powered tools — the AI Concierge and the AI Lifestyle Advisor — that process user inputs to generate personalised recommendations, answer questions about the platform's inventory, and assist buyers in identifying relevant assets and partner profiles.

When you use either AI tool, we collect and process:

  • the text of your queries, questions, and messages entered into the AI Concierge or AI Lifestyle Advisor interface;
  • your responses to lifestyle and investment preference questions presented by the AI Lifestyle Advisor (such as preferred asset categories, budget range, geographic preferences, lifestyle priorities);
  • session metadata including session identifiers, timestamps, device type, and IP address;
  • the outputs generated in response to your queries (for quality improvement and support purposes);
  • any contact details you voluntarily provide during an AI session, including name and email address.

AI queries and outputs are processed using large language model infrastructure. Queries may be transmitted to third-party AI model providers as part of response generation. These providers are listed in Section 8 (Third-Party Service Providers). LuxeVault does not instruct its AI model providers to use session content for model training.

Your conversation history with LuxeVault's AI tools is stored in our database, linked to a session identifier. This enables the AI to maintain coherent context across steps and allows you to resume a session where you left off. AI conversation data is retained for 1 year from the date of last activity, after which it is deleted. To request earlier deletion, contact privacy@getluxevault.com.

4.4 CRM and Lead Management Data

LuxeVault operates an internal customer relationship management (CRM) system to manage the lifecycle of buyer enquiries from submission through to partner routing and follow-up. The CRM records:

  • the original enquiry data submitted by the buyer (see Section 4.1);
  • the partner or partners to whom the enquiry was routed, and the timestamp of each routing event;
  • the status of the enquiry (new, in progress, closed, followed up, unsubscribed);
  • partner notes and internal annotations relating to the enquiry;
  • follow-up communications sent on behalf of the platform, including AI-generated follow-up emails;
  • the buyer's email communication preferences, including any unsubscribe requests;
  • any signal data recorded by the buyer signal tracking system, including buyer interest signals such as listing saves, repeated views, or category selections;
  • deal records, where a transaction is closed and a commission event is recorded.

CRM data is accessible to LuxeVault staff and, where the enquiry has been routed to a specific partner, to that partner in respect of their own routed enquiries only. Partners are not able to view enquiries routed to other partners.

4.5 Seller Onboarding Data

LuxeVault facilitates a seller onboarding process for partners and asset owners who wish to list assets on the platform. In connection with seller onboarding, we collect:

  • details of the asset to be listed, including category, specifications, condition, provenance, asking price, and supporting photography;
  • ownership documentation or authorisation to list documentation, where requested;
  • the seller's contact details, as provided during the listing submission process;
  • commission rate agreements and invoice routing preferences;
  • listing status records (draft, pending_review, changes_requested, approved, published, archived, rejected).

4.6 Authentication Data (Clerk)

LuxeVault uses Clerk as its authentication and identity management provider for the Partner Portal and Builder Portal. When you create or use a portal account:

  • Clerk generates and manages your user account, including your email address, session tokens, and authentication state;
  • login timestamps, session duration, and device and browser information derived from the User-Agent header (e.g. 'Chrome on macOS') are recorded for security and audit purposes;
  • LuxeVault receives from Clerk only the data necessary to identify you and link your portal session to your partner record — namely your email address and Clerk user identifier.

Clerk acts as a data processor on behalf of LuxeVault in respect of authentication data. Clerk's own privacy policy, available at clerk.com/legal/privacy, governs their processing of data on their infrastructure.

4.7 Payment Data (Stripe)

LuxeVault uses Stripe as its payment processor for seller listing subscription plans. Commission invoices between LuxeVault and its partners are currently settled by direct bank transfer; card payment for commission invoices is not available at this time.

LuxeVault does not collect, store, or process payment card numbers. When a payment is made through Stripe's hosted checkout:

  • all card data (card number, CVV, expiry date) is entered directly into Stripe's secure, PCI DSS-compliant environment and never passes through LuxeVault's servers;
  • LuxeVault receives from Stripe a payment confirmation, a transaction reference, and non-sensitive billing metadata (e.g. billing name, last four digits of card, country);
  • Stripe retains payment data in accordance with its own privacy policy, available at stripe.com/privacy.

4.8 Email Communications Data (Resend)

LuxeVault uses Resend as its transactional email delivery service. Resend processes personal data on behalf of LuxeVault when sending:

  • buyer enquiry confirmation emails (sent to the buyer immediately upon submission of an enquiry);
  • partner routing notifications (sent to the matched partner when an enquiry is assigned to them);
  • AI-generated follow-up emails (sent to buyers after a defined period following an enquiry, based on the nature of the enquiry and the buyer's stated interests);
  • email responses to buyers on behalf of the platform, including additional information, property insights, or market updates relevant to their enquiry;
  • transactional account emails (e.g. partner portal access links, magic link authentication emails);
  • platform-wide administrative communications (e.g. terms updates, policy changes).

All emails sent via Resend that constitute buyer-facing commercial communications include a List-Unsubscribe header and a plaintext unsubscribe link in the footer, enabling one-click unsubscribe in supporting email clients. Unsubscribe requests are honoured within 10 business days and recorded in LuxeVault's CRM.

Resend processes delivery metadata including delivery status, open events (where tracked), and bounce information. LuxeVault uses this data to manage list hygiene and ensure emails are not sent to non-existent or unsubscribed addresses. Resend's privacy policy is available at resend.com/legal/privacy-policy.

4.9 Server Access Log Data

LuxeVault does not currently deploy any third-party analytics platform (such as Google Analytics, Plausible, or similar tools). No analytics JavaScript trackers or analytics cookies are active on the platform.

LuxeVault's web and API servers generate standard server-side access logs as a byproduct of normal operation. These logs record:

  • the URL of each HTTP request and the method used (GET, POST, etc.);
  • the HTTP response code returned;
  • the IP address of the requesting client;
  • the timestamp of the request;
  • the User-Agent string sent by the browser.

Server access logs are retained for 90 days and are used exclusively for security monitoring, incident investigation, and debugging. They are not used to build user profiles and are not shared with third parties for commercial purposes.

4.10 Cookies and Tracking Technologies

We collect data via cookies and similar tracking technologies. For a full description of the cookies we use, see Section 6 (Cookies and Tracking Technologies).

5. How We Collect Personal Data

LuxeVault collects personal data through the following channels:

5.1 Directly from You

  • Enquiry forms: When you submit a buyer enquiry, product-specific acquisition request, or any other contact form on the platform.
  • Partner application forms: When a business or individual applies to join the LuxeVault partner network, including by submitting a partner application, builder application, agency application, or agent registration.
  • Listing submission forms: When a partner submits a listing for review and publication on the platform.
  • AI Concierge and AI Lifestyle Advisor: When you enter queries, preferences, or other information into either AI tool.
  • Newsletter sign-up: When you subscribe to LuxeVault's newsletter or opt in to receive platform updates.
  • Email and telephone communications: When you contact LuxeVault directly by email or telephone.
  • Partner Portal interactions: When a verified partner logs in, updates their profile, manages listings, or views enquiries via the Partner Portal.
  • Click-wrap acceptance: When a partner accepts the LuxeVault Partner Agreement via the click-wrap mechanism in the Partner Portal.

5.2 Automatically

  • Cookies and browser storage: When you visit the platform, cookies and browser storage technologies automatically record session identifiers, consent preferences, and technical data as described in Section 6.
  • Server access logs: Our web and API servers automatically record HTTP request data, including IP addresses, request timestamps, response codes, and the URLs requested. These logs are retained for 90 days and used for security monitoring only.

5.3 From Third Parties

  • Authentication providers (Clerk): Clerk passes user identity data (email address, user identifier, session state) to LuxeVault to enable portal authentication.
  • Payment processors (Stripe): Stripe passes non-sensitive payment confirmation data and billing metadata to LuxeVault upon successful payment of a seller subscription.
  • Email delivery (Resend): Resend passes delivery status, bounce notifications, and open events to LuxeVault via webhook to enable list hygiene and deliverability monitoring.

6. Purposes and Lawful Basis of Processing

LuxeVault processes personal data only where we have a clear and documented lawful basis for doing so. Under UK GDPR and EU GDPR, the lawful bases available to us are: (a) consent; (b) performance of a contract; (c) compliance with a legal obligation; (d) protection of vital interests; (e) performance of a task in the public interest; and (f) legitimate interests, provided those interests are not overridden by your rights and interests.

The table below sets out the purposes for which we process personal data and the primary lawful basis for each.

PurposePrimary lawful basisNotes
Receiving, reviewing, and routing buyer enquiries to verified partnersLegitimate interestsOur legitimate interest is in facilitating introductions between serious buyers and verified partners, which is the core purpose of the platform.
Confirming receipt of a buyer enquiry and communicating with the buyer regarding their enquiryLegitimate interests; contract performanceWe have a legitimate interest in confirming receipt and managing the enquiry process. Where the enquiry is a step towards a contract, contract performance also applies.
Sending AI-generated follow-up emails to buyers based on their stated interestsLegitimate interests; consentFollow-ups are sent where there is a legitimate interest in progressing an active buyer enquiry. Where follow-up extends to general marketing, consent is the applicable basis.
Managing the partner onboarding and verification processContract performanceOnboarding data is necessary to enter into and perform the partner agreement.
Hosting partner profiles and listings on the platformContract performanceDisplay of listings and profiles is the core deliverable of the partner relationship.
Processing commission invoices and paymentsContract performance; legal obligationNecessary to fulfil financial obligations under the partner agreement and to comply with accounting and tax law.
Managing the CRM and enquiry lifecycleLegitimate interestsWe have a legitimate interest in tracking enquiry status, partner routing, and outcome to deliver the service and improve it.
Providing and improving the AI Concierge and AI Lifestyle AdvisorLegitimate interestsImproving AI tool quality serves the core platform purpose. We do not use AI session data for model training without consent.
Authenticating partner and builder portal users (via Clerk)Contract performanceAuthentication is necessary to provide access to the portal.
Analysing platform usage via server access logsLegitimate interestsWe have a legitimate interest in understanding how the platform is used to improve it. No third-party analytics platform is currently deployed. Analysis is based on server-side access logs only.
Detecting fraud, misuse, and security incidentsLegitimate interests; legal obligationWe have a legitimate interest in protecting the platform, our users, and our business from fraud and abuse.
Maintaining audit logs of partner agreement acceptance (click-wrap)Legal obligation; legitimate interestsRetaining records of binding legal agreements is both a contractual and compliance obligation.
Complying with applicable law, responding to legal requests, and enforcing our agreementsLegal obligation; legitimate interestsRequired to meet statutory obligations and to protect LuxeVault's legal position.
Sending newsletters and platform update emailsConsentNewsletter and non-transactional marketing emails are sent only where the individual has opted in.
Setting preference browser storage items (language, lifestyle settings, saved items)ConsentOptional browser storage items are written only where you have consented via our cookie consent banner.

6.1 Legitimate Interests Assessment

Where we rely on legitimate interests as our lawful basis, we have carried out a three-part legitimate interests assessment confirming: (a) the purpose is a genuine legitimate interest of LuxeVault; (b) the processing is necessary to achieve that purpose and could not reasonably be achieved by less privacy-intrusive means; and (c) the processing does not override the fundamental rights and freedoms of the data subjects concerned, taking into account their reasonable expectations and the safeguards we apply.

You have the right to object to processing based on legitimate interests. See Section 11 (Your Rights) for details.

6.2 Consent

Where we rely on consent as our lawful basis — for non-essential cookies, newsletter subscriptions, and follow-up marketing communications — your consent is obtained expressly, separately from any other acknowledgement, and you may withdraw it at any time without affecting the lawfulness of processing that occurred before withdrawal. Details of how to withdraw consent are set out in Section 11.

7. Cookies and Tracking Technologies

LuxeVault uses cookies and browser storage technologies to operate the platform and remember your preferences. This section describes what is set, its purpose, and how you can manage your preferences.

7.1 What Are Cookies?

A cookie is a small piece of data that a website sends to your browser, which your browser stores and sends back to the website on subsequent visits. Cookies serve a range of purposes, from keeping you logged in to measuring how many visitors a page receives. Some cookies are set directly by LuxeVault (first-party cookies); others are set by third-party services we use (third-party cookies).

7.2 Cookie and Browser Storage Inventory

The following is a complete inventory of the cookies and browser storage items currently set by the LuxeVault platform. No analytics cookies or third-party advertising cookies are set.

Strictly Necessary Cookies (HTTP)

Always active

These are real HTTP cookies transmitted in the Set-Cookie header. They are essential for platform security and authenticated sessions.

NamePurposeDurationSet by
luxe_csrf_tokenCSRF double-submit protection token. Required to authenticate state-changing API requests. Not HttpOnly — must be readable by page JavaScript to be echoed in the request header.12 hoursLuxeVault API server
luxe_admin_sessionAdmin portal session token (admin users only). HttpOnly; not accessible to JavaScript. Invalidated on logout or after 12 hours of inactivity.12 hours (idle)LuxeVault API server
Clerk session cookiesSession management for Partner Portal and Builder Portal authenticated users. Includes session tokens and authentication state. Set and managed entirely by Clerk via the LuxeVault API proxy.Managed by ClerkClerk (via LuxeVault proxy)

Functional Browser Storage (localStorage / sessionStorage)

Consent required (optional)

These are client-side browser storage entries — not HTTP cookies. They are never transmitted to our servers in request headers, but persist in your browser to remember your preferences and session state. They are set only after you accept cookies via our consent banner.

KeyPurposeDuration
lv_cookie_consentStores your cookie consent preference ('all' or 'essential') so the consent banner does not re-appear. Set immediately when you make a choice — before any optional storage is written.Persistent until cleared
i18nextLngStores your chosen interface language if you have selected a language other than English.Persistent until cleared
lv_partner_tokenPartner Portal magic-link authentication token (Partner Portal users only). Cleared automatically on logout.Until logout
luxevault_lifestyle_session_idSession identifier for your active AI Lifestyle Advisor session, enabling the advisor to maintain context between steps.Until preferences are reset
luxevault_lifestyle_emailEmail address you voluntarily provide during an AI Lifestyle Advisor session, used to follow up with recommendations if you request this.Until preferences are reset
lv_saved_{asin}Flags which product listings you have saved or wishlisted, enabling the saved state to persist across pages.Persistent until removed
LuxeVault does not use analytics cookies, advertising cookies, or any cookies for behavioural tracking or cross-site profiling. No third-party analytics platform is currently deployed on the platform.

7.3 Managing Your Preferences

When you first visit the LuxeVault platform, a cookie consent banner is displayed. You may choose to accept all browser storage ("Accept all") or accept essential items only ("Essential only"). Dismissing the banner without choosing sets essential items only.

You may withdraw or change your preference at any time by clearing your browser's cookies and localStorage (most browsers: Settings → Privacy → Clear browsing data) and revisiting the site. Note that clearing essential cookies will log you out of the Partner Portal or Admin Portal and require you to re-authenticate.

LuxeVault does not use cookies or browser storage for targeted advertising, behavioural advertising, or cross-site tracking, and does not share cookie data with advertising networks.

8. Third-Party Service Providers and Sub-Processors

LuxeVault works with a limited set of trusted third-party service providers who process personal data in connection with the services they provide to us. We take steps to ensure each provider processes personal data only as necessary for its stated purpose, by selecting providers whose privacy practices and security standards meet our requirements and, where available, by accepting the provider's standard data processing terms.

We do not sell, rent, or trade personal data with any third party for their own commercial or marketing purposes.

Purpose: Authentication, identity management, and session management for the Partner Portal and Builder Portal.

Data shared: Email address, user identifier, session tokens, login timestamps.

Location: United States (adequacy / SCCs apply).

Purpose: Transactional email delivery — buyer enquiry confirmations, partner routing notifications, AI-generated follow-up emails, and platform communications.

Data shared: Recipient email address, name (if personalised), email content, delivery status metadata.

Location: United States (SCCs apply).

Purpose: Payment processing for seller listing subscription plans. Commission invoice payments are settled by direct bank transfer and do not pass through Stripe.

Data shared: Billing name, email, non-sensitive payment confirmation data (e.g. last four digits, country). LuxeVault does not transmit card numbers — card data is entered directly into Stripe's hosted environment.

Location: United States and European Union (adequacy / SCCs apply).

OpenAI / AI model providers

openai.com/policies/privacy-policy

Purpose: Powering the AI Concierge, AI Lifestyle Advisor, and Deal Advisor features. User queries are transmitted to AI model providers to generate responses.

Data shared: Text of user queries as entered into AI tools. Personal data within queries (such as names, locations, or budget figures) is transmitted as part of the query content. We do not separately annotate queries with user identifiers.

Location: United States (SCCs apply). OpenAI offers EU data residency options.

Replit / Cloud infrastructure

replit.com/site/privacy

Purpose: Application hosting, compute, and managed database services. LuxeVault's application, APIs, and database are hosted on Replit's infrastructure.

Data shared: All personal data held by LuxeVault is stored on this infrastructure. Data is encrypted at rest and in transit.

Location: United States (SCCs apply).

8.1 Sharing with Verified Partners

When a buyer submits an enquiry through LuxeVault, their enquiry data — including name, email address, telephone number (where provided), and enquiry content — is shared with the specific verified partner to whom that enquiry is routed. This sharing is the core purpose of the platform and is disclosed to buyers at the point of enquiry submission.

Enquiry data is shared with one matched partner only. It is not shared with multiple partners simultaneously, nor made available to the general partner network, nor displayed publicly.

Verified partners receive enquiry data and are bound by confidentiality obligations under the LuxeVault Partner Agreement, including obligations to: use buyer data only to progress the specific introduction; not add buyer contact details to third-party mailing lists or CRMs without explicit buyer consent; store data securely; and comply with applicable data protection law.

8.2 Legal and Regulatory Disclosures

LuxeVault may disclose personal data to courts, regulators, law enforcement authorities, or other third parties where required by applicable law, court order, or governmental authority, or where we believe disclosure is necessary to protect the rights, property, or safety of LuxeVault, our users, or others.

8.3 Business Transfers

In the event of a merger, acquisition, reorganisation, asset sale, or other corporate transaction involving LuxeVault, personal data held by LuxeVault may be transferred to the acquirer or successor entity as part of that transaction. We will notify you of any such transfer and of any changes to this Privacy Policy that result from it, to the extent required by law.

9. International Data Transfers

LuxeVault is a global platform serving buyers and partners across the United Kingdom, the European Economic Area, North America, the Middle East, and Asia. Some of our service providers are located in countries outside the UK and EEA, including the United States.

The United Kingdom and the EU have each determined that some third countries provide an adequate level of data protection, enabling transfers to those countries without additional safeguards. Where no adequacy decision exists, we ensure that transfers of personal data outside the UK and EEA are protected by appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs): European Commission-approved model clauses incorporated into our data processing agreements with sub-processors located in non-adequate countries.
  • UK International Data Transfer Agreements (IDTAs): The ICO-approved addendum to SCCs for UK GDPR-governed transfers.
  • UK Addendum to EU SCCs: Where UK GDPR applies, we incorporate the ICO's UK Addendum to the EU SCCs where appropriate.

You may request a copy of the specific transfer mechanism applied to any given transfer of your data by contacting privacy@getluxevault.com.

For users located outside the UK and EEA — including in Canada, the United States, the Middle East, and Asia — your personal data is transferred to and processed in the United Kingdom (where LuxeVault is established) and, in some cases, in the United States and other countries where our service providers operate. We take steps to ensure your data is handled to a standard consistent with your rights regardless of where it is processed.

10. Data Retention

LuxeVault retains personal data only for as long as necessary to fulfil the purpose for which it was collected, to meet legal or regulatory obligations, or to defend or pursue legal claims. The specific retention periods we apply are set out below.

Data CategoryRetention PeriodRationale
Buyer enquiry data (name, email, phone, enquiry content)3 years from the date of enquiry submission, or until the enquiry results in a closed transaction (whichever is later)Sufficient to cover the typical timeline of a luxury asset acquisition and any reasonable follow-up.
AI Concierge and AI Lifestyle Advisor conversation data1 year from date of last activityConversation history is persisted to enable session resumption and contextual continuity. Deleted after 1 year of inactivity or on request.
CRM records relating to closed transactions7 years from the date of transaction closeFinancial record-keeping obligations under UK law; potential for contractual disputes.
CRM records relating to enquiries that did not result in a transaction3 years from last activityCovers reasonable follow-up and legitimate interest period.
Partner account data (profile, listings, portal access)Duration of the active partnership, plus 7 years following terminationFinancial record-keeping; commission audit requirements; contractual record obligations.
Commission and invoice records7 years from the date of the relevant invoice or transactionStatutory accounting and tax record-keeping obligations.
Click-wrap agreement acceptance records (partner)Duration of the partnership plus 10 years following terminationBinding legal agreements must be retained for long-term enforceability.
Authentication data (Clerk session logs)90 days rolling for active sessions; terminated session data anonymised after 90 daysSecurity monitoring and fraud detection.
Stripe payment records (seller subscription transactions)7 years from the date of transactionAccounting and tax law compliance.
Email delivery logs (Resend)13 months rollingList management, deliverability monitoring, and unsubscribe compliance.
Unsubscribe recordsIndefinitely (or until re-consent is given)To ensure unsubscribed individuals are not contacted again.
Server access logs90 daysSecurity monitoring, fraud detection, and incident investigation. No third-party analytics platform is currently active.
Seller onboarding documents (credentials, ownership records)Duration of active listing plus 5 yearsAudit trail for platform verification standards; contractual records.

Upon expiry of the applicable retention period, personal data is securely deleted or permanently anonymised so that it can no longer be attributed to an individual. Where we are unable to immediately delete data (for example, because it is stored in backup archives), we will isolate and protect it from further processing until deletion is possible.

11. Your Rights Under UK GDPR and EU GDPR

If you are located in the United Kingdom or the European Economic Area, you have the following rights in respect of your personal data. You may exercise any of these rights by contacting us at privacy@getluxevault.com. We will respond within one calendar month of receiving a valid request. Where requests are particularly complex or numerous, we may extend this period by a further two months, in which case we will notify you.

How requests are handled: LuxeVault does not currently offer self-service data access, export, or deletion tools. All data subject requests — including subject access requests, erasure requests, rectification requests, and portability requests — are handled personally by the LuxeVault founder. Please submit all requests by email to privacy@getluxevault.com with sufficient detail to identify your data. We aim to acknowledge receipt within 5 business days.

We will not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act.

11.1 Right of Access (Article 15 UK/EU GDPR)

You have the right to obtain confirmation of whether LuxeVault processes personal data about you, and if so, to receive a copy of that data and supplementary information about how it is used. This is commonly known as a Subject Access Request (SAR). To submit a SAR, email privacy@getluxevault.com with the subject line "Subject Access Request" and confirm the name and email address associated with your data. We handle all SARs manually and will provide the information in a commonly used format within one calendar month of receiving a verified request.

11.2 Right to Rectification (Article 16 UK/EU GDPR)

You have the right to request correction of inaccurate personal data we hold about you, and to have incomplete personal data completed. Partners may update their profile data directly via the Partner Portal; buyers may contact us directly at privacy@getluxevault.com.

11.3 Right to Erasure ("Right to Be Forgotten") (Article 17 UK/EU GDPR)

You have the right to request deletion of your personal data where applicable. Erasure requests are handled personally by the LuxeVault founder — email privacy@getluxevault.com with the subject line "Erasure Request". We will assess and action eligible requests within one calendar month. The grounds on which you may request erasure are:

  • the data is no longer necessary for the purpose for which it was collected;
  • you withdraw consent on which processing was based, and there is no other lawful basis;
  • you object to processing based on legitimate interests and your interests override ours;
  • the data has been unlawfully processed;
  • the data must be erased to comply with a legal obligation.

The right to erasure is not absolute. We may decline an erasure request where the data is necessary to comply with a legal obligation, to establish, exercise, or defend legal claims, or for other grounds permitted by applicable law. Where we cannot fulfil an erasure request in full, we will explain the reasons.

11.4 Right to Restriction of Processing (Article 18 UK/EU GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while a dispute about its accuracy is being resolved, or while we assess whether your objection to processing overrides our legitimate interests. Where processing is restricted, we will continue to store your data but will not use it for other purposes without your consent.

11.5 Right to Data Portability (Article 20 UK/EU GDPR)

Where processing is based on your consent or on performance of a contract, and the processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Portability requests are handled personally by the LuxeVault founder — email privacy@getluxevault.com with the subject line "Data Portability Request". We will compile and provide the data within one calendar month of a verified request.

11.6 Right to Object (Article 21 UK/EU GDPR)

You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as the lawful basis. Where you object, we must stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or that the processing is necessary for establishing, exercising, or defending legal claims.

You have an unconditional right to object to processing of your personal data for direct marketing purposes. If you object to direct marketing, we will cease immediately.

11.7 Right to Withdraw Consent (Article 7(3) UK/EU GDPR)

Where processing is based on your consent — for example, in respect of non-essential cookies, newsletter subscriptions, or follow-up marketing emails — you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal. You can withdraw consent to:

  • Cookies: by clearing your browser's cookies and revisiting the site, then selecting "Essential only" on the consent banner;
  • Email marketing: by clicking the "Unsubscribe" link in any marketing email we send, or by contacting privacy@getluxevault.com;
  • Follow-up emails: by using the one-click unsubscribe link in any follow-up email, or by contacting privacy@getluxevault.com.

11.8 Rights in Relation to Automated Decision-Making (Article 22 UK/EU GDPR)

LuxeVault does not make decisions that produce legal or similarly significant effects on individuals based solely on automated processing, including profiling. The AI Concierge and AI Lifestyle Advisor provide recommendations and information as decision-support tools, but human review is involved in all enquiry routing decisions. If this changes, we will update this policy and seek consent where required.

11.9 Right to Lodge a Complaint

If you are dissatisfied with how LuxeVault has handled your personal data, you have the right to lodge a complaint with a supervisory authority. The relevant supervisory authorities are:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk — telephone: 0303 123 1113
  • European Union: The data protection authority in your EU member state of habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is available at edpb.europa.eu.

We would encourage you to contact us at privacy@getluxevault.com in the first instance, as many concerns can be resolved directly and without formal complaint.

12. California Residents — Your Rights Under the CCPA / CPRA

This section applies exclusively to individuals who are residents of the State of California, United States, and supplements the rest of this Privacy Policy. California residents have specific rights under the California Consumer Privacy Act (CCPA) 2018, as amended by the California Privacy Rights Act (CPRA) 2020.

12.1 Categories of Personal Information Collected

In the preceding 12 months, LuxeVault has collected the following categories of personal information as defined under the CCPA:

  • Identifiers: real name, email address, telephone number, IP address, session identifiers.
  • Commercial information: records of services enquired about, acquisition preferences, budget range, partner interactions.
  • Internet or other electronic network activity: browsing history on the LuxeVault platform, search queries, pages visited, AI Concierge queries.
  • Geolocation data: approximate location derived from IP address (country and city level).
  • Inferences drawn from personal information: lifestyle preferences inferred by the AI Lifestyle Advisor based on your stated preferences and browsing behaviour.
  • Professional or employment-related information: business name and role, submitted by partners during onboarding.

12.2 Sources of Personal Information

LuxeVault collects personal information directly from you (via enquiry forms, partner applications, and AI tool interactions), automatically (via server access logs and browser storage technologies), and from third parties (Clerk, Stripe, and Resend), as described in detail in Sections 4 and 5.

12.3 Purposes for Collecting Personal Information

LuxeVault uses personal information for the purposes set out in Section 6 of this Privacy Policy.

12.4 Sale or Sharing of Personal Information

LuxeVault does not sell personal information to third parties, as the term "sale" is defined under the CCPA/CPRA. LuxeVault does not share personal information with third parties for cross-context behavioural advertising.

LuxeVault does share buyer enquiry data with verified partner businesses for the purpose of facilitating an introduction requested by the buyer — this is the core purpose of the platform and is disclosed to buyers at the point of enquiry. This sharing is limited to the single matched partner only and does not constitute a "sale" or "sharing" under the CCPA/CPRA.

12.5 Your California Privacy Rights

California residents have the following rights:

  • Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information LuxeVault has collected about you, the sources from which it was collected, the purposes for which it is used, and the categories of third parties with whom it has been shared.
  • Right to Delete: You have the right to request deletion of personal information we have collected about you, subject to certain exceptions (for example, where retention is necessary to complete a transaction, comply with a legal obligation, or for other purposes permitted by law).
  • Right to Correct: You have the right to request correction of inaccurate personal information LuxeVault holds about you.
  • Right to Opt-Out of Sale or Sharing: As noted above, LuxeVault does not sell or share personal information for targeted advertising purposes. No opt-out is required, but you may contact us to confirm this.
  • Right to Limit Use of Sensitive Personal Information: LuxeVault does not use or disclose sensitive personal information for purposes beyond those permitted by the CPRA without consent.
  • Right to Non-Discrimination: LuxeVault will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you services, charge different prices, or provide a different level of service because you exercised a privacy right.

12.6 How to Exercise Your California Rights

You may submit a verifiable consumer request by:

  • emailing privacy@getluxevault.com with the subject line "California Privacy Rights Request";
  • clearly stating the right you wish to exercise and, where relevant, the specific information to which your request relates.

We may ask you to verify your identity before processing your request. We will respond within 45 calendar days of receipt of a verified request. We may extend this period by a further 45 days where necessary, with notice.

You may designate an authorised agent to submit a request on your behalf. Authorised agents must provide written proof of authorisation, and LuxeVault may verify the consumer's identity directly.

13. Canadian Residents — PIPEDA and Provincial Privacy Law

This section applies to individuals located in Canada and supplements the rest of this Privacy Policy. LuxeVault processes personal data of Canadian residents in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy legislation including Quebec's Law 25 (Act respecting the protection of personal information in the private sector, as amended).

13.1 Accountability

LuxeVault is accountable for the personal information it collects, uses, and discloses. Responsibility for compliance with PIPEDA rests with LuxeVault as the organisation. Privacy-related enquiries from Canadian residents should be directed to privacy@getluxevault.com.

13.2 Identifying Purposes

LuxeVault identifies the purposes for which personal information is collected before or at the time of collection. These purposes are described in full in Section 6 of this Privacy Policy.

13.3 Consent

LuxeVault obtains meaningful consent for the collection, use, and disclosure of personal information, except where PIPEDA or applicable law permits collection without consent (for example, to investigate a breach of an agreement or to comply with a legal obligation). Where express consent is required — such as for marketing communications — we will obtain it explicitly. Implied consent may apply where the purpose for collecting personal information is obvious and the individual voluntarily provides the information (for example, submitting an acquisition enquiry).

You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal of consent may affect our ability to provide services to you.

13.4 Limiting Collection

LuxeVault collects only the personal information necessary for the identified purposes. We do not collect personal information indiscriminately.

13.5 Limiting Use, Disclosure, and Retention

Personal information collected by LuxeVault is used only for the purposes identified at the time of collection, or for purposes to which you subsequently consent, or as required by law. We do not sell personal information. Retention periods are as set out in Section 10.

13.6 Accuracy

LuxeVault takes reasonable steps to ensure that personal information held is accurate, complete, and up to date, insofar as may be necessary for the purposes for which it is used. Partners may update their profile information directly via the Partner Portal.

13.7 Safeguards

LuxeVault protects personal information by security safeguards appropriate to the sensitivity of the information. The security measures we employ are described in Section 14.

13.8 Openness

LuxeVault makes information about its personal information management practices available to individuals upon request. This Privacy Policy is publicly available and answers most questions about our practices.

13.9 Individual Access

Upon written request, LuxeVault will inform Canadian residents of the existence, use, and disclosure of their personal information and provide access to that information. We will respond within 30 days of a verified request. Requests should be submitted to privacy@getluxevault.com.

13.10 Challenging Compliance

You may challenge LuxeVault's compliance with PIPEDA by contacting us at privacy@getluxevault.com. If your concern is not resolved to your satisfaction, you may contact the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca or 1-800-282-1376.

Quebec residents may also contact the Commission d'accès à l'information (CAI) at cai.gouv.qc.ca regarding compliance with Quebec's Law 25.

14. Security Practices

LuxeVault takes the security of personal data seriously and implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. The measures we apply include:

14.1 Data in Transit

  • All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS) version 1.2 or higher. We enforce HTTPS on all pages.
  • API communications between the frontend, backend, and third-party services are encrypted in transit.
  • Where supported by the underlying hosting infrastructure, mutual TLS (mTLS) is used for internal service-to-service communications.

14.2 Data at Rest

  • Personal data stored in our database is encrypted at rest using industry-standard encryption.
  • Payment card data is not stored by LuxeVault at any point — all card processing is handled within Stripe's PCI DSS-certified environment.
  • Database backups are created daily, encrypted, and stored in durable cloud object storage. The 7 most recent daily backups are retained; older backups are deleted automatically.

14.3 Access Controls

  • Access to personal data is restricted to the LuxeVault founder and authorised service providers who have a legitimate need for that access to perform their specific function.
  • Partner portal access is managed via Clerk with authenticated sessions and session timeout controls.
  • Administrative access to production systems requires authentication and is subject to audit logging.
  • Third-party service providers are granted only the minimum access required for their specific function; no other individuals have standing access to personal data.

14.4 Application Security

  • Input validation and output encoding practices are applied to mitigate injection and cross-site scripting (XSS) risks.
  • CSRF (cross-site request forgery) protection is applied to all state-changing endpoints via a double-submit token.
  • IP-based rate limiting is applied to public-facing API endpoints to mitigate abuse and denial-of-service attempts.
  • Security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and others) are applied to all responses.

14.5 Breach Response

In the event of a personal data breach, LuxeVault has procedures in place to detect, contain, and assess breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority (ICO in the UK; relevant EU DPA for EEA users) within 72 hours of becoming aware. Where the breach is likely to result in a high risk to individuals, we will notify affected individuals without undue delay.

If you become aware of any security vulnerability affecting the LuxeVault platform, we ask that you report it responsibly to security@getluxevault.com.

14.6 Limitations

While we take all reasonable steps to protect personal data, no method of transmission over the internet or method of electronic storage is completely secure. LuxeVault cannot guarantee absolute security and accepts no liability for breaches that result from events beyond our reasonable control, subject to our obligations under applicable law.

15. Children's Privacy

LuxeVault's platform is not directed at and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe that your child under 18 has provided personal information to LuxeVault without your consent, please contact us at privacy@getluxevault.com and we will take steps to delete that information promptly.

Where any part of our platform may be accessible by users under 18 (for example, in connection with a family acquisition), we request that parents and guardians provide or oversee any personal data submissions made on behalf of or by minors.

16. Changes to This Privacy Policy

LuxeVault reserves the right to update or modify this Privacy Policy at any time. Changes may be made for a variety of reasons, including to reflect changes to the platform, to our data processing activities, to applicable law, or to regulatory guidance.

We will communicate material changes to this Privacy Policy by:

  • posting the revised policy on this page with an updated effective date;
  • where the change materially affects how we use your data, making reasonable efforts to notify verified partners by email after the updated policy takes effect.

The effective date at the top of this policy indicates when the current version took effect. We encourage you to review this policy periodically. Your continued use of the LuxeVault platform after the effective date of a revised policy constitutes your acceptance of that revision.

Where changes require fresh consent (for example, a new use of data previously collected on the basis of consent), we will seek that consent separately and will not assume acceptance based on continued use of the platform.

17. Contact Information and How to Exercise Your Rights

If you have any questions about this Privacy Policy, want to exercise any of your data subject rights, wish to raise a concern, or want to understand more about how LuxeVault processes your personal data, please contact us:

All enquiries are handled personally by the LuxeVault founder. Use the most appropriate address below so your message is routed and prioritised correctly — all addresses are monitored by the same person.

Privacy & Data Rights

privacy@getluxevault.com

Use this address for all data subject requests (access, erasure, portability, rectification) and general privacy enquiries. Please include the request type in the subject line and the name and email address associated with your data.

Security Vulnerability Reports

security@getluxevault.com

Use this address to report security vulnerabilities responsibly. Please do not share vulnerability details publicly before we have had the opportunity to investigate.

Partner & Commercial Enquiries

partners@getluxevault.com

For verified partners with questions about enquiry routing, commission records, or their partner account data.

General Contact

hello@getluxevault.com

For general questions about the platform, LuxeVault's services, or anything else not covered by the categories above.

We aim to respond to all privacy requests within 30 calendar days. For complex or extensive requests, we may require up to 3 months, and we will inform you if this is the case within the initial 30-day period.

GetLuxeVault — Privacy Policy v1.0 — Effective 23 July 2026