Privacy Policy
Last updated:
This Privacy Policy explains how Vintique, Inc. ("Vintique", "we", "us", "our") collects, uses, shares, and protects information when you visit our marketing website, sign up for the Vintique point-of-sale and antique-mall management service, or otherwise interact with us (together, the "Service"). It applies to information about (a) prospective and current customers and their personnel ("Customers"); (b) booth owners and consignors, including independent vendors who create their own account without a mall; and (c) end shoppers whose transactions are recorded in the Service.
For most data inside a Customer's Workspace, Vintique acts as a processor on behalf of the Customer, who is the controller. This Policy describes our own practices; Customers should publish their own privacy notice covering how they use the Service.
1. Information we collect
Independent vendor accounts. We collect your name, email address and timezone, verify your email with a short-lived sign-in code, and keep a record of your signup acknowledgment. Your personal inventory, item photos, locations, manually recorded sales, refunds, expenses and reports belong to your independent account. Signing up does not share these records with a mall or enroll you in marketing. We use this information to provide and secure your account. You can export your records, sign out or request account deletion from Account in the app. No payment information is required for the free account. QuickBooks is a separate optional feature that is not connected at signup.
1.1 Information you give us
- Account & billing. Mall name, contact name, email address, password (stored only as a one-way cryptographic hash), phone number, mailing address, plan selection, and the last four digits and brand of the card on file. Full card numbers are collected and stored by Stripe through its hosted checkout. Do not enter full card numbers or security codes in Vintique notes, uploads, or other fields.
- Workspace data you enter. Booth owner and consignor profiles (name, email, phone, tax ID, commission rates), inventory and item photos, transactions, gift card numbers and balances, sales-tax settings, settlement reports, internal notes, and any other content you upload or type into the Service ("Customer Data").
- Image uploads. The Service handles two distinct categories of uploaded photo, with different purposes and retention windows:
- Lookup photos — a photo you submit through the in-app or Extension Price Lookup feature, for the sole purpose of returning a suggested price range and comparable listings. Lookup photos are stored temporarily in storage private to your Workspace, then removed as described in §7. We retain limited search-activity and deletion records. Comparable-listing results (titles, prices, source URLs) and a search identifier are kept briefly so the same search can be reused across the mall (see Retention below).
- Saved item photos — a photo you choose to attach to an item in your Workspace (for tagging, pricing, online listings, or vendor records). Saved photos are stored in object storage private to your Workspace and are retained for the life of the item record (see Retention below).
Deletion of uploaded photos. You can delete a saved item photo (and the item it is attached to) at any time from inside your Workspace; deletes are propagated to object storage in the ordinary course (typically within minutes, with scheduled retries if cleanup fails). Admins can also remove pending lookup photos from Settings without waiting for the scheduled cleanup. To request deletion of any other content attributable to you, contact us as described in §8 below. - Communications. Messages you send to support, feedback, survey responses, and any attachments.
1.2 Information we collect automatically
- Usage & device data. IP address, browser type and version, operating system, referring URL, pages viewed, features used, and timestamps. We use this to operate, secure, and improve the Service.
- Cookies & similar technologies. Session and security cookies support sign-in and protect requests. We save your privacy choice in your browser for up to 180 days. Optional Google Analytics measures website visits and interactions; optional AWS CloudWatch RUM measures page performance. Neither tool loads before you enable its category in Privacy choices, available on every marketing page. Rejecting either does not prevent use of the site. Google Analytics may set analytics identifiers; we disable its advertising signals. RUM is configured without persistent user cookies, session replay, form contents, or HTTP/error capture. Vendors also receive ordinary connection information such as your IP address. Browser or vendor settings can affect cookie lifetimes. You can withdraw permission using Privacy choices; this stops future collection, not data already sent.
- Logs. Server, audit, and security logs that record events such as logins, failed-login attempts, password resets, impersonation events, billing webhook deliveries, and errors.
1.3 Information from third parties
- Stripe. Subscription status, payment outcomes, last4/brand of card on file, and customer/subscription identifiers.
- SerpAPI / Google Lens / Google Shopping / eBay. When you use Price Lookup in the web app, Extension or Mobile App, we send the selected photo or a temporary photo URL and your query to SerpAPI for comparable-listing searches using Google Lens, Google Shopping and eBay. Results include listing titles, prices, source URLs and thumbnails. Photos may still contain metadata as described in §1.1. Our retention periods for lookup photos and search results are in §7. Providers apply their own terms and retention policies; deleting our copy does not itself delete copies held by a provider. We do not use lookup photos to train facial-recognition or biometric-identification models or instruct providers to do so. See our sub-processors page for provider details and policies.
- Vintique browser extension. Our optional Chrome extension connects to your Workspace and stores an authentication credential on your device. When you invoke the extension, it sends us the image URL or image bytes you select, your lookup query, and standard request metadata. The extension does not collect browsing history, page contents, or anything you do not explicitly submit.
1.4 Mobile app
The Vintique iOS app supports booth owners and staff. Available features depend on your role and installed app version.
- Camera and photos. We request device permission when you use photo features. We read or capture photos you select; we do not scan or upload your library in the background. You can revoke permission in your device settings.
- Notifications. Where supported by your app version, you can enable sales, schedule and rent notifications and choose categories in the app. Push is optional and also requires device permission. Expo and Apple's notification service receive a device push address, delivery metadata, a generic notification message, and identifiers used to open the right update after sign-in. Detailed sales and rent information is retrieved from Vintique after authentication.
- Device and account records. We use authentication tokens, device registration, app version and notification delivery records to operate the app. We do not use advertising identifiers or cross-app advertising tracking. Camera uploads follow the image processing rules above.
2. How we use information
- provide, operate, maintain, and secure the Service;
- authenticate users and protect against fraud, abuse, and unauthorized access;
- process subscriptions, billing, refunds, and dunning through Stripe;
- send transactional email (welcome, password reset, billing receipts, daily vendor digests, support replies);
- respond to your support requests and feedback;
- monitor and analyze usage to debug, improve features, and produce aggregated, de-identified statistics;
- comply with our legal, tax, accounting, and audit obligations and to enforce our Terms of Service.
We do not sell or rent personal information, and we do not use Customer Data to train machine-learning models offered to other customers or third parties.
3. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: contract(to provide the Service you signed up for), legitimate interests (to secure the Service, prevent fraud, improve features, and run our business), legal obligation (tax, accounting, responding to lawful requests), and consent where required (for example, for optional product update emails, which you can withdraw at any time).
4. How we share information
- Within your Workspace. Customer Data is visible to users in the same Workspace according to the role and permissions you assign (admin, cashier, booth owner). Access controls isolate private Workspace records from other malls.
- Sub-processors. We use vetted vendors to operate the Service:
- Stripe — subscription billing and payment-method storage
- SendGrid — transactional email delivery
- Amazon Web Services — object storage for saved item photos and uploads, application hosting, and the managed database
- SerpAPI (relays to Google Lens, Google Shopping, and eBay) — item-lookup comparable-listing results
- Vintique platform staff. A small number of authorized Vintique employees may access Customer Data when strictly necessary to operate, secure, or troubleshoot the Service, or to honor a Customer support request. We log privileged access. Support staff may view a Workspace as one of its users through a temporary impersonation session; that session is recorded in an audit log and shown to the Customer.
- Legal & safety. We may disclose information when required by law, subpoena, or court order, or when we reasonably believe disclosure is necessary to investigate fraud, protect the safety of any person, or enforce our Terms.
- Business transfers. If Vintique is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction. We will notify Customers in advance and any successor will be bound by terms no less protective than this Policy.
4.1 Private photos and public listings. Saved original photos are private to your Workspace and protected by access controls. When an authorized user lists an item on a public storefront, Vintique publishes smaller image copies and listing details so anyone can view them, including search engines and other mall users. Cross-listing tools also let you prepare or share listing content with marketplaces you choose. Publish only material you have permission to make public. Unpublishing removes the listing and starts removal of our public image copies; caches may serve a removed copy for up to one hour after storage removal. Copies already downloaded, indexed or shared by others are outside our control. We do not use your photos to train general-purpose machine-learning models.
4.2 Optional location features. For nearby events, your browser can use a city or ZIP you enter, the mall address, or device location if you expressly request it. Device coordinates are reduced to an approximate area before being saved or sent. BigDataCloud receives those approximate coordinates to find the area name; OpenStreetMap's Nominatim service receives address or city searches. These providers also receive your connection information. The chosen area is saved in this browser until you change or reset it. Device permission can be revoked in browser settings.
5. International transfers
Vintique is based in the United States and our infrastructure is located in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. Contact us before transferring data that requires a data-processing agreement or a specific international-transfer arrangement so the applicable terms and safeguards can be confirmed.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, password protection, controls that restrict access to private account data, and security logging. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you and applicable authorities as required by law.
7. Retention
We keep Workspace data while you use the Service. Canceling a subscription or suspension for nonpayment does not schedule deletion. We retain the Workspace for reactivation, export and customer-requested deletion until its admin asks us to delete it, subject to legal obligations. You can request an export or deletion at colin@getvintique.com even if you cannot access the Workspace. We assess continued retention when it is no longer needed for these purposes. To start the 30-day deletion recovery window, use Schedule deletion as described below or contact us.
- Lookup photos: stored temporarily in private storage, with a target of deletion 30 minutes after upload. Completion can take longer during failures, which require retry. Admins can request immediate cleanup from Settings. Saving a photo to an item creates a separate saved copy.
- Search results: reusable for 24 hours. Expired results and search-activity records older than 30 days are removed automatically; expiry and completed deletion may occur at different times.
- Saved photos: kept with item records until removed. Private originals, derived variants and public storefront copies are included in cleanup. Failed storage deletions are retried. Public cache and third-party copy limits are described in §4.1.
- Exports: generated ZIPs are private and expire from export storage after 30 days; Workspace erasure also removes them.
- Backups and legal records: automated database backups normally expire after 14 days; prior saved-photo versions normally expire after 30 days. Provider lifecycle removal is asynchronous. Recovery snapshots and records needed for billing, tax, security, disputes or legal holds may remain longer, with restricted access. If a backup is restored, deletion requests must be reapplied before the restored data is used.
7a. Account & data deletion path
You can delete data, and your entire Workspace, without leaving the Service:
- Per-record deletion (any time). Inside an active Workspace, admins and (where their role permits) cashiers and booth-owner users can delete individual records — saved item photos, items, draft intakes, booth-owner profiles, gift cards, holds, transactions, and so on — directly from the relevant page in the Service. Deleting a saved item photo also removes the underlying object from object storage in the ordinary course (typically within minutes, with scheduled retries if cleanup fails).
- Workspace deletion (admins). A mall-owner admin can request deletion of the entire Workspace from Settings → Danger Zone → Schedule deletion. The request requires typed-name confirmation and immediately flips the Workspace into a read-only "Scheduled for deletion" state for a 30-day grace window. During that window: (a) sign-in still works for admins so you can change your mind, request an export, or download the export ZIP; (b) changes to Workspace records are blocked with a "Workspace scheduled for deletion" notice; and (c) admins can Restore the Workspace at any time, which lifts the read-only state and cancels the scheduled deletion.
- What is deleted at the end of the grace window. When the 30-day grace window expires, we delete the Workspace's business records and remove private uploads, lookup photos, generated exports and public storefront copies from active storage. Failed removals are retried; we do not report deletion complete while storage cleanup remains pending. A restricted deletion record keeps account identification, who requested deletion, the reason and dates, cleanup results, and billing references and cancellation status needed to reconcile the closed account. Backup and legal-record exceptions follow §7.
- Data export before deletion. Before the grace window expires you can request an export of supported Workspace business records (CSV files bundled into a ZIP) from the same Settings → Danger Zone screen. The export is generated asynchronously and made available as a short-lived signed download URL.
- End shoppers and booth owners. If you are an end shopper or a booth owner whose information is held inside a Customer's Workspace, please contact that Customer first; we will assist them in responding. If you are not able to reach the Customer, contact us using the details in §12 and we will help where we can without violating the Customer's controller relationship described above.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to our processing of personal information about you, and to withdraw consent. Customers can exercise most of these rights directly inside the Service (edit profile, delete records, export reports, change password, cancel subscription). For end shoppers and booth owners whose information is held in a Customer's Workspace, please contact the Customer first; we will help the Customer respond. To make a request directly to Vintique, contact us using the details below. We will respond within 30 days (or sooner where required by law). You will not be discriminated against for exercising your privacy rights.
California (CCPA/CPRA). Where the CCPA/CPRA applies, California residents have the right to know what personal information we collect, to delete it, to correct it, to limit use of sensitive personal information, and to opt out of "sale" or "sharing". We do not sell personal information. We do not enable advertising personalization in our website analytics. You may reject optional analytics in Privacy choices; we also treat Global Privacy Control as an opt-out from all optional website measurement.
Email preferences. Product marketing is optional and has an unsubscribe link. Account essentials such as password resets and security notices remain available. Other categories, including billing alerts, compliance reports, onboarding and digests, can be controlled in Email preferences; mall-wide switches may also apply. Changing an email preference does not cancel a subscription or constitute consent to electronic delivery of tax statements.
9. Minimum age and children
Account holders and staff users (18+). The Service is built for businesses and adult professionals. Per our Terms of Service, all account holders and every individual invited into a Workspace — admins, cashiers, and booth-owner users — must be at least 18 years of age. We do not knowingly create or maintain accounts for anyone under 18, and we do not knowingly collect personal information from anyone under 18 in connection with operating a Workspace.
Children. The Service is not directed to and is not intended for use by children. We do not knowingly collect personal information from children under 13 (the threshold under the U.S. Children's Online Privacy Protection Act) or, in jurisdictions where a higher threshold applies, children below that age. If you believe a child has provided us personal information, please contact us using the details in §12 and we will delete it. If you are a parent or guardian and have questions about information that may have been submitted about your child by an end shopper at a participating mall, contact the mall directly first; the mall is the controller of that data and we will assist them in responding.
10. Browser privacy signals
We treat Global Privacy Control and a browser Do Not Track value of 1 as a request to keep optional website analytics and performance measurement off. This does not disable essential sign-in, security or preference storage.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify Customers by email to the address on file or by an in-app notice at least 14 days before the change takes effect. The "Last updated" date at the top reflects the most recent version.
12. Contact
For privacy questions, access, correction or deletion requests, or complaints, email colin@getvintique.com or write to Vintique, Inc., 17614 Brucker St, Grand Haven, MI 49417, United States. You do not need an account or a previous email from us. Please identify the relevant Workspace and request; do not email passwords, full card numbers or tax identification numbers. We may verify identity and authority using information appropriate to the request. Where applicable, you can use an authorized agent, appeal a decision by replying to our response, or complain to your data-protection authority.