Privacy Policy

Your data, your business.

No legalese gymnastics. Here's what we collect, why we collect it, and what we do with it — in plain language.

Last updated: February 12, 2026

The Short Version

The gist

We only collect what we need to run the service

We never sell your data to anyone

You can export or delete your data anytime

Your client files belong to you, not us

Who we are

ClientVault is operated by Lasse Rafn ("we", "us", "our") — a bootstrapped, solo-founded company based in Denmark. We build white-label client portal software for freelancers and agencies.

If you have any questions about this policy, email us at [email protected]. You'll hear back from a real person.

What we collect

Account information

When you sign up, we collect your name, email address, and password. If you subscribe to a paid plan, our payment processor (Stripe) handles your billing information — we never see or store your full card details.

Content you upload

Files, documents, tasks, comments, and any other content you add to your client portals. This content is stored securely and is only accessible to you and the clients you invite.

Usage data

Basic analytics like page views, feature usage, and login times. This helps us understand which parts of the product need improvement. We don't track you across other websites.

Client portal visitors

When your clients access their portal, we collect their email address (for authentication via magic link) and basic access logs. We don't profile your clients or use their data for marketing.

How we use your data

We use your data to:

  • Run the service — Authenticate you, display your portals, deliver files to your clients, send notifications
  • Process payments — Manage subscriptions and billing through Stripe
  • Improve the product — Understand usage patterns to prioritize features and fix problems
  • Communicate with you — Send transactional emails (password resets, billing receipts) and occasional product updates

That's it. We don't run ads, we don't build marketing profiles, and we don't sell access to your data. Ever.

Data storage & security

Your files are stored on Cloudflare R2, a globally distributed object storage service. Your account data is stored in a PostgreSQL database on infrastructure we manage.

Security measures we take:

  • All connections are encrypted via TLS (HTTPS)
  • Passwords are hashed using bcrypt — we can't read them even if we wanted to
  • Daily database backups with point-in-time recovery
  • File access is scoped — clients can only see files shared with them

Third-party services

We use a small number of third-party services to run ClientVault. Each one has access only to the data it needs:

Stripe

Payment processing. Handles your billing info securely.

Cloudflare

File storage (R2) and CDN. Hosts your uploaded files.

Postmark

Transactional email delivery. Sends notifications and magic links.

Sentry

Error tracking. Helps us catch and fix bugs quickly.

We do not share your data with advertisers, data brokers, or any other third parties not listed above.

Cookies

We use cookies to keep you logged in and to remember your preferences. That's it. We don't use tracking cookies, retargeting pixels, or third-party analytics cookies.

The cookies we set are strictly functional — they're necessary for the application to work. You won't see an annoying cookie banner from us because we don't do anything that requires one.

Your rights

You have full control over your data. Here's what you can do:

  • Export — Download all your data at any time with one click. No fees, no waiting, no "contact sales."
  • Delete — Request full account deletion and we'll remove all your data permanently within 30 days.
  • Correct — Update your account information anytime from your settings.
  • Object — Opt out of product update emails with one click. Transactional emails (receipts, security alerts) will still be sent.

These rights apply regardless of where you're located — whether you're covered by GDPR, CCPA, or neither. We treat everyone the same.

Data retention

We keep your data for as long as your account is active. If you cancel your subscription, your data remains accessible for 90 days so you have time to export everything. After that, it's permanently deleted.

If you request account deletion, we'll remove your data within 30 days. Some data may be retained in encrypted backups for up to 90 additional days before those backups are rotated out.

Changes to this policy

If we make meaningful changes to this privacy policy, we'll email you before they take effect. We won't bury updates in a changelog and hope you don't notice.

Minor wording tweaks (typos, formatting) may happen without notice, but the substance of the policy won't change silently.

Questions about your privacy?

If anything in this policy is unclear, just ask. We'd rather over-explain than leave you guessing.