Privacy Policy
Last updated 30 August 2026
ClientVault is a document collection tool for accountants and bookkeepers. This policy explains what we collect, why, and what we do with it. It covers two different groups of people: the firms who hold an account with us, and their clients who upload documents through a portal link.
Who controls your data
For account data belonging to a firm, Abdullah Abdul Jalil Munshi is the data controller.
For documents and information uploaded by a firm's clients, the firm is the controller and we are the processor. We store and transmit that material on the firm's instructions. We do not decide what is collected, we do not use it for our own purposes, and we do not sell it.
What we collect from firms
- Account details: name, email address, workspace name, and password (stored hashed, never in plain text)
- Client records you create: client name, email, company, phone
- Requests, checklists, and reminder history
- Billing information, handled by our payment provider — we never see or store card numbers
- Basic usage analytics: page views and traffic sources, without cookies or cross-site tracking
What we collect from clients uploading documents
Clients do not create an account and are not asked for a password. When someone opens a portal link we process only the documents and text responses they submit, the file names, and the time of submission.
Where it is stored
Data is held in Supabase (PostgreSQL and object storage) and the application runs on Vercel. Uploaded documents live in a private storage bucket. They are not publicly accessible, and are served only through short-lived signed links generated for the firm that owns the record. Transactional email is sent through Resend.
How long we keep it
Documents and records are kept for as long as the firm's account is active. A firm can delete individual clients, requests, or documents at any time. If an account is closed, its data is deleted within 30 days, except where we are required to retain billing records for tax purposes.
Your rights
You can request a copy of your data, ask us to correct it, or ask us to delete it. Email privacy@theclientvault.net and we will respond within 30 days. If a client of a firm wants their documents removed, the quickest route is to ask the firm directly, since they control that material.
Sub-processors
- Supabase — database, authentication, and document storage
- Vercel — application hosting and privacy-preserving analytics
- Resend — transactional email
- Paddle — payment processing and merchant of record
Cookies
We use a single cookie to keep you signed in. We do not use advertising or cross-site tracking cookies, which is why you are not asked to dismiss a consent banner. Our analytics measures page views without identifying individuals.
Changes
If this policy changes materially we will email account holders before the change takes effect.
Contact
Abdullah Abdul Jalil Munshi
privacy@theclientvault.net