Sub-processors

Last updated:

Vintique uses a small number of vetted third-party service providers ("sub-processors") to operate the Service. Each is bound by a written data-processing agreement, processes data only on our documented instructions, and is held to security standards consistent with our own. This page is referenced from our Privacy Policy and is updated whenever we add or change a sub-processor.

Current sub-processors

Sub-processor Purpose Data shared Processing location
Stripe, Inc. Subscription billing, payment-method storage, billing portal. Mall name, billing email, billing address, last4/brand of card on file, customer and subscription identifiers, invoice history. Full card numbers are collected and stored by Stripe; Vintique never sees them. United States
Amazon Web Services, Inc. (AWS) Application hosting (ECS Fargate), managed PostgreSQL database (RDS), object storage for saved item photos (S3, via short-lived presigned URLs scoped to a tenant-prefixed path), and transactional email delivery (SES — welcome, password reset, billing receipts, daily vendor digests, support replies). All Customer Data stored in the Service database (mall records, transactions, vendor profiles, gift-card balances, audit logs, etc.), saved item photos (stored under a tenant-prefixed path so a tenant cannot read or overwrite another tenant's objects), outbound email (recipient, sender, subject, body, delivery metadata), and application logs. Encrypted in transit and at rest. United States (us-east-1)
SerpAPI, Inc. (incl. Google Lens, Google Shopping, eBay results) Item-lookup and comparable-listing search results for the in-app and Extension Price Lookup feature. The image bytes or image URL and text query you submit for a single lookup. EXIF metadata is stripped from photo uploads before they leave Vintique. Lookup photos are processed in-memory only and are not persisted by Vintique once the search completes; the resulting comparable-listing data is cached briefly (see Privacy Policy §7) so the same search can be reused across the mall. SerpAPI does not receive your mall or user identifier. United States
Functional Software, Inc. (Sentry) Application error monitoring and crash reporting. Error events and diagnostic context. Personal data (emails, phone numbers, payment identifiers, names, and secrets/API keys) is redacted by an allowlist scrubber before events are transmitted. United States
BigDataCloud Pty Ltd Browser-side reverse geocoding for the optional "Nearby estate sales & auctions" dashboard feature — converts the device's approximate coordinates into a city/state. Approximate latitude/longitude from the browser's geolocation, sent directly from the user's browser (not from Vintique's servers) and only when an authorized user opts into the location feature. No mall or user identifier is sent. Australia / global CDN

Image lookups and the Google Lens / SerpAPI sub-processor

Photos you submit through the in-app or Extension Price Lookup feature are forwarded to our image-search sub-processor (SerpAPI, which in turn relays the query to Google Lens, Google Shopping, and eBay) so we can return comparable listings and a suggested price range. Before any lookup photo leaves Vintique, EXIF metadata (including camera make/model and any embedded GPS coordinates) is stripped. The lookup photo itself is ephemeral on Vintique's side: it is processed in memory for the duration of the search and is not stored in our database or object storage. Only the resulting comparable-listing data is cached briefly (see the Retention section of the Privacy Policy). Photos you choose to save to a Workspace as item photos are stored in our object storage and follow the saved-photo retention rules in the Privacy Policy.

Vintique does not perform facial recognition or any other biometric processing on uploaded photos and does not instruct any sub-processor to do so. Do not upload photos containing identifiable people, minors, government identification, or any other content that would trigger biometric-privacy laws (for example Illinois BIPA).

Notification of changes

When we add a new sub-processor or materially change how an existing sub-processor is used, we will update this page and bump the "Last updated" date above. For Customers on plans that include a written data-processing agreement, we will also provide notice by email to the Workspace's billing contact at least 14 days before the change takes effect, where reasonably practicable.

Questions or objections

To raise a question or formal objection about a sub-processor, reply to any email we have sent you or contact us through the Settings page in your Workspace.