LossVault ("LossVault," "we," "us," or "our") provides tools that help organizations document property-loss jobs, organize photos and inventory, collaborate with team members, and create and share reports. This Privacy Policy explains how LossVault handles personal information through the LossVault iOS application, website, and related services (collectively, the "Services").
1. Scope and organizational accounts
This policy applies to information handled by LossVault through the Services. It does not apply to third-party websites, applications, or services that have their own privacy policies.
LossVault accounts may be associated with a company or other organization. When you use LossVault for an organization, that organization may control information submitted by its users and may have its own privacy obligations. You should only upload personal information, claim information, and images that you are authorized to collect, use, and share.
2. Information we collect
Depending on how you use the Services, we may collect account and organization information, content you provide, support communications, technical and diagnostic information, and website billing or transaction records needed to provide and secure the Services.
Payment details are submitted directly to Stripe. LossVault does not collect payment-card details in the iOS app or receive your full card number from Stripe.
The iOS app may request access to the camera or photo library when you choose to capture or select content. LossVault does not currently request access to your device's precise location.
How information is collected
Information may be provided by you or authorized organization members, collected from the app and service infrastructure as needed to operate and secure the Services, or received from providers that support authentication, storage, uploaded-content processing, email, diagnostics, hosting, app delivery, and website payments.
The iOS app may temporarily store queued photos, thumbnails, item-detail drafts, and upload state on your device so work can continue during interrupted network service.
3. How we use information
We use information to:
- Create, authenticate, secure, and administer accounts and organizations.
- Provide job, capture, upload, inventory, report, sharing, team, and support features.
- Synchronize content across authorized devices and workspace members.
- Organize and classify uploaded content, populate inventory information for review, and research replacement-cost information when applicable.
- Process website billing and maintain transaction records.
- Send service communications requested by or relevant to users.
- Diagnose operational problems and protect the Services from misuse.
- Comply with law and establish, exercise, or defend legal claims.
- Improve the reliability, usability, accessibility, and performance of the Services.
LossVault does not use personal information for third-party advertising or cross-app tracking.
4. How we disclose information
Within your organization
Authorized workspace members can access content according to their assigned role. Owners and administrators can manage members and roles, editors can create and update permitted content, and viewers have read-only access to permitted records.
At your direction
We disclose reports and related content when an authorized user downloads, emails, or creates a public report link. Anyone who receives a public link may be able to view the shared report until the link expires or is revoked.
Service providers
Providers that help operate the Services currently include:
- Supabase for authentication, databases, storage, and server functions.
- Sentry for crash reporting and diagnostic telemetry.
- Resend for transactional and support email delivery.
- Expo for application builds, delivery, and updates.
- Vercel for website hosting and related infrastructure.
- Stripe for website payment-method collection and payment processing.
- Third-party content-processing services that support inventory classification and replacement-cost research.
We may also disclose information when reasonably necessary for legal, safety, security, enforcement, or business-transfer purposes, subject to applicable law.
5. Sale, advertising, and tracking
LossVault does not sell personal information, use personal information for third-party targeted advertising, or track users across other companies' apps or websites for advertising purposes.
The website may use cookies or similar local storage necessary for authentication, security, session continuity, preferences, and core operation.
6. Data retention
We generally retain account, organization, job, photo, inventory, report, support, and billing information while an account or workspace remains active and afterward until deletion is requested or the information is no longer needed for the purposes described in this policy.
Some deletion actions initially make records unavailable through a soft-delete process. Limited information may be retained when reasonably necessary for security, audit integrity, backup recovery, legal compliance, dispute resolution, or enforcement.
Public report links expire and can be revoked. Expiration or revocation prevents future access through that link but cannot retrieve copies already downloaded or separately shared by a recipient.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network connections, private storage, role-based permissions, database access controls, controlled report links, audit logging, and separation of privileged server credentials from client applications.
No method of transmission, storage, or security is completely secure. You are responsible for protecting your credentials, using a secure device, assigning appropriate team roles, and reporting suspected unauthorized access.
8. Your choices and requests
Depending on your account and role, you may be able to:
- Review or update profile and organization information.
- Manage notification preferences, team members, and report-sharing links.
- Request a copy or export of applicable account or workspace data.
- Request deletion of your account or an authorized organization workspace.
Start a deletion or export request in the iOS app under Settings, or email support. LossVault may need to verify identity, ownership, authority, and request scope before acting. Deleting an individual account may not delete content controlled by an organization or needed by other authorized workspace members.
9. Children's privacy
The Services are intended for business and professional use and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13.
10. International processing
LossVault and its service providers may process information in the United States and other countries where they operate. Where required, we use appropriate measures for international transfers.
11. Changes to this policy
We may update this policy as the Services, providers, or legal requirements change. We will post the revised policy at lossvault.com/privacy and update the effective date.
12. Contact us
For privacy questions, requests, or concerns, email support@lossvault.com or visit the LossVault help center.