Information we process
Depending on how you use The Vault, we may process account information, name, email address, mobile number, passwordless authentication activity, concierge requests, preferences, partner profiles, budgets, consultation details, itinerary information, payment records, communications, support messages, SMS consent records, opportunity saves or applications, product feedback, experience reviews, and data-rights requests.
Planning and support may also involve event, place, vendor, reservation, route, weather, and calendar information needed for a requested experience. Do not submit card numbers, passwords, government identifiers, or unrelated sensitive information through feedback or support fields.
How we use information
We use information to authenticate accounts; respond to requests; schedule consultations; generate grounded Ace recommendations; plan, approve, book, and support experiences; process approved service fees and subscriptions; deliver opted-in service messages; maintain operational and communication history; investigate feedback; protect the service; and understand how the product performs.
Marketing communications are separate from transactional service communications. Marketing SMS is not active.
Ace and automated assistance
Ace may send the minimum relevant planning prompt and grounded product context to an AI service provider to generate suggestions. Ace is not authorized to claim that a reservation is confirmed, spend money, or replace manager review for higher-risk work. We record model, usage, and safety audit context without intentionally storing provider credentials or raw secrets.
Maps, weather, and calendar
Google Maps services may process locations used for geocoding, routes, and map embeds. The National Weather Service supplies weather information. A manager may connect a Google Calendar using the limited calendar.events.owned scope; sync is one-way from The Vault, and The Vault database remains the scheduling source of truth.
Payments
Stripe processes payment-card details. The Vault does not store raw card numbers, security codes, or full payment-card credentials. We may retain related transaction references, payment status, amounts, and records needed to provide support and maintain financial records.
Text messaging and mobile information
When you separately opt in, mobile information may be used for requested transactional and service communications. SMS consent is tracked separately from marketing permission. Message frequency varies, and message and data rates may apply. Reply STOP to opt out or HELP for help.
We do not sell mobile information or share mobile opt-in information or consent with third parties for their own marketing purposes. Service providers, including messaging infrastructure providers, may process mobile information only as needed to operate, secure, and support the requested service.
The Vault's transactional support SMS program is active for customers who separately opt in. Marketing SMS remains disabled. See the SMS Terms for program details.
Product analytics and attribution
We use first-party product analytics to understand meaningful lifecycle steps such as discovery views, planning starts, consultations, payments, completed experiences, and feedback. We record coarse device class, browser family, operating system, viewport, source channel, route, and deployment context. We do not use this system for cross-site advertising, capture IP addresses in the analytics record, or create a device fingerprint.
Direct Mail QR visits use a pseudonymous first-party identifier to connect scans with later Vault conversions during a limited attribution window. Google Business Profile and organic search may be distinguished through referral or campaign parameters without invasive tracking.
Service providers and disclosures
We may use service providers including Supabase for database and authentication, Vercel for hosting, Stripe for payment and subscription processing, Twilio for opted-in messaging, Google for Maps and manager Calendar sync, OpenAI for Ace assistance, and public or approved data sources for weather and discovery. They receive only the information reasonably needed to perform their services. We may also disclose information when required by law, to protect users or the service, or as part of a lawful business transaction.
Retention and security
We retain information for as long as reasonably needed to provide the service, maintain business and financial records, resolve disputes, enforce agreements, and meet legal obligations. Retention periods may vary by record type. We use administrative and technical safeguards, but no system can guarantee absolute security.
Your choices
You may decline optional marketing or SMS consent, and SMS consent is not a condition of purchase. Authenticated customers can submit an export or deletion request from the Profile page and track its status. A manager verifies identity before fulfillment. Certain records may need to be retained for operational, accounting, fraud-prevention, dispute, or legal reasons; the recorded outcome explains applicable retention.
You may also use Send Feedback to report a product concern. Review the Terms of Service for service boundaries.
Contact
Email Jean@ninelegacyholdings.com, call +1 (816) 816-2829, or use the same number for opted-in transactional support SMS.
