VALTE Privacy Policy
Effective Date: June 10th, 2026
1. INTRODUCTION
1.1 Effective Date and Last Updated
This Privacy Policy (the "Policy") is effective as of June 10th, 2026 and was last updated on the same date. We may revise this Policy from time to time as described in Section 11.
1.2 Scope
This Policy describes how VALTE LLC ("VALTE," "we," "us," or "our") collects, uses, discloses, and otherwise processes Personal Information in connection with the VALTE website, the VALTE mobile application, the VALTE marketplace, custody, vaulting, and ownership-transfer services, and any related products, features, content, or services made available by VALTE (collectively, the "Services"). The Services are intended for use only by individuals who are at least 18 years of age and located in the fifty United States and the District of Columbia.
1.3 Incorporation into the Terms of Service
This Policy is incorporated into and forms part of the VALTE Terms of Service (the "Terms"). Capitalized terms used but not defined in this Policy have the meanings given in the Terms. In the event of any conflict between this Policy and the Terms with respect to privacy, this Policy controls.
2. INFORMATION WE COLLECT
We collect the following categories of Personal Information in connection with the Services. Information categorized as Sensitive Personal Information, including biometric data, is addressed separately in Section 3.
2.1 Account Information
Name, email address, postal address, account username, and similar identifiers that you provide when you create an account or update your profile. If you sign in using Google, Apple, or Facebook, we receive basic profile information (such as your name and email address) from that provider. Additional identifiers, such as date of birth and phone number, are collected directly by Stripe if and when you complete seller payout onboarding.
2.2 Transaction Information
Records of purchases, sales, offers, listings, withdrawals, ownership records, transaction history, and payment-method information. Payment-method information (payment card details and bank account details) is collected and processed by Stripe, Inc. ("Stripe") through Stripe Connect Destination Charges; VALTE does not store full payment card numbers.
2.3 Identity Verification Information
Information collected in connection with identity verification, including government-issued identification documents and a face-match selfie. Because identity verification involves Sensitive Personal Information (including biometric data), the categories, sources, purposes, retention, and state-specific disclosures applicable to this information are described in Section 3.
2.4 Device and Usage Information
IP address, device identifiers, browser type, operating system, app version, session timestamps, interactions with the Services, crash logs, and similar log data. We collect this information automatically through cookies, SDKs, server logs, and analogous technologies.
2.5 Communications
Support requests, in-app messages, dispute submissions, and other communications you send to us or exchange through the Services.
3. SENSITIVE PERSONAL INFORMATION (INCLUDING BIOMETRIC DATA)
This Section describes the Sensitive Personal Information we collect or process in connection with identity verification and compliance, including biometric data processed by Stripe Identity. We recognize this category warrants heightened disclosure under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Illinois Biometric Information Privacy Act ("ILBIPA"), the Texas Capture or Use of Biometric Identifier Act ("TX CUBI"), and analogous state laws.
3.1 Categories of Sensitive PI Collected
- Government identifiers (driver's license, passport, state-issued identification);
- Biometric information (face-match selfie used to verify identity against the photo on a government-issued identification document);
- Account credentials (username, password, and multi-factor authentication factors); and
- Precise financial information (payment card details and bank account details, processed by Stripe).
3.2 Source of Biometric Data
Biometric data is collected and processed by Stripe through Stripe Identity solely for the purpose of verifying your identity when you set up seller payouts through Stripe Connect onboarding, and at other times where re-verification is required for fraud-prevention or compliance reasons. Buyers are not required to complete identity verification to create an account or make purchases. VALTE does not directly capture, store, or retain biometric identifiers. Stripe Identity retains and processes biometric data subject to Stripe's privacy practices, available at stripe.com/privacy and stripe.com/legal/identity. VALTE receives a verification result and limited verification artifacts (such as a pass/fail indicator and the identity attributes returned by Stripe Identity).
3.3 Purpose
We collect and process Sensitive Personal Information solely for: identity verification; fraud prevention; and regulatory compliance, including Know-Your-Customer ("KYC") obligations, anti-money-laundering ("AML") obligations, OFAC and sanctions screening, and tax reporting (such as IRS Form 1099-K). We do NOT use Sensitive Personal Information for marketing, advertising, profiling, or any other purpose.
3.4 Retention
Biometric data is retained by Stripe Identity for the period required by applicable law and Stripe's published retention policies (generally not longer than necessary to fulfill the verification purpose). Identity-verification records retained by VALTE (such as verification outcomes and the identity attributes returned by Stripe Identity) are kept for the period required by federal recordkeeping requirements, currently five (5) years following account closure under the Bank Secrecy Act (31 U.S.C. Section 5311 et seq.).
3.5 No Sale or Disclosure for Marketing
We do not Sell Sensitive Personal Information. We do not share Sensitive Personal Information with third parties for marketing, advertising, or any purpose other than the verification, fraud-prevention, and compliance purposes described in Section 3.3 and disclosures required by law.
3.6 Your Right to Limit
California residents and residents of other states with similar rights may request that we limit the use of Sensitive Personal Information to the permitted purposes listed in Section 3.3. To exercise this right, contact us at support@valte.io.
3.7 State-Specific Disclosures
Illinois Residents Pursuant to the Illinois Biometric Information Privacy Act (740 ILCS 14), your written, affirmative consent to the collection and processing of biometric data is obtained within Stripe’s hosted verification flow before any biometric capture occurs. Stripe Identity maintains a written retention schedule for biometric data, and biometric data is destroyed when the verification purpose is satisfied or upon expiration of the retention period, whichever occurs first. Texas Residents We comply with the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code Section 503.001) in the collection and processing of biometric data via Stripe Identity, including with respect to notice, consent, retention, and destruction of biometric identifiers.
4. HOW WE USE YOUR INFORMATION
We use Personal Information for the following purposes:
- Operate, maintain, and secure the Services;
- Process transactions via Stripe Connect (Destination Charges);
- Verify seller identity through Stripe Identity as part of Stripe Connect payout onboarding, and conduct compliance screening (KYC, AML, OFAC sanctions);
- Provide customer support and respond to your communications;
- Detect, investigate, and prevent fraud and protect platform integrity;
- Comply with applicable law, including tax reporting, government and regulatory requests, and recordkeeping requirements; and
- Improve the Services, including security monitoring, performance, and analytics.
5. HOW WE SHARE YOUR INFORMATION
5.1 Service Providers
We disclose Personal Information to Service Providers that process Personal Information on our behalf under a written contract that limits their use to providing services to us. Our current Service Providers include:
- Stripe, Inc. - payment processing through Stripe Connect, seller identity verification through Stripe Identity as part of Stripe Connect payout onboarding (including the biometric face-match described in Section 3), sanctions and OFAC screening, and fraud detection;
- Supabase, Inc. - database hosting and authentication infrastructure;
- Shippo, Inc. - shipping label generation, carrier integration, and shipment tracking;
- Resend, Inc. - transactional email delivery (such as account, support, shipping, and transaction notifications);
- Expo (650 Industries, Inc.) - mobile application infrastructure and push-notification delivery (push tokens and device identifiers); and
- Vercel, Inc. - web hosting and content delivery for the VALTE website and related services.
We do not currently use any third-party analytics or advertising SDKs in the Services. The device and usage information described in Section 2.4 is collected and stored directly by VALTE.
5.2 Legal and Compliance
We may disclose Personal Information when we have a good-faith belief that disclosure is necessary to respond to subpoenas, court orders, warrants, law-enforcement requests, regulatory inquiries, OFAC-mandated disclosures, or other legal process, or to enforce our agreements or protect the rights, property, or safety of VALTE, our users, or others.
5.3 Business Transfers
We may disclose Personal Information in connection with a contemplated or completed merger, acquisition, financing, reorganization, dissolution, or sale of all or substantially all of our assets. We will provide notice (where required by applicable law) before Personal Information becomes subject to a different privacy policy.
5.4 With Your Consent
Any other sharing of Personal Information requires your consent or your direction.
5.5 No Sale; No Cross-Context Behavioral Advertising
We do NOT Sell Personal Information for monetary or other valuable consideration. We do NOT Share Personal Information with third parties for cross-context behavioral advertising as defined under CCPA/CPRA and analogous state laws.
6. RETENTION
We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. Subject to legal holds and longer statutory retention requirements, we apply the following retention guidelines:
- Account information — Duration of account + 7 years post-closure (Tax / business records)
- Transaction records — 7 years (IRS recordkeeping requirements)
- Identity verification records — 5 years post-account-closure (Bank Secrecy Act (31 U.S.C. Section 5311))
- Biometric data (Stripe Identity) — Per Stripe Identity policy (ILBIPA / Stripe's published schedule)
- Customer support communications — 2 years (Operational)
- Device and usage logs — 12 months (then aggregated/anonymized) (Operational)
- Cookies — Per individual cookie expiration (Operational)
7. SECURITY
7.1 Safeguards
We maintain administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption of data in transit and at rest, role-based access controls, multi-factor authentication for administrative access, and physical security controls at our secure vault facility.
7.2 Breach Notification
No method of transmission or storage is fully secure. In the event of a security incident affecting your Personal Information, we will notify affected users and applicable regulators as and when required by law, in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and the requirements of any investigation needed to determine the scope of the incident and restore the integrity of the Services.
8. YOUR PRIVACY RIGHTS
8.1 Universal Rights
We grant the following rights to all users of the Services regardless of state of residence:
- Right to access the Personal Information we hold about you;
- Right to correct inaccurate Personal Information;
- Right to request deletion of Personal Information (subject to legal retention requirements described in Section 6);
- Right to data portability (Personal Information provided in a machine-readable format where applicable);
- Right to opt out of any Sale or Sharing of Personal Information (we do not Sell or Share Personal Information for cross-context behavioral advertising, as stated in Section 5.5);
- Right to limit the use of Sensitive Personal Information (see Section 3.6); and
- Right to non-discrimination for exercising any of the rights listed above.
8.2 State-Specific Rights
Various U.S. state privacy laws - including but not limited to California's CCPA/CPRA, Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, and similar laws in Utah, Oregon, Texas, Montana, Iowa, Indiana, Tennessee, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Kentucky, Maryland, Rhode Island, and Florida - provide residents with privacy rights. We honor the rights described in Section 8.1 for all U.S. users regardless of state residence. If your state law provides additional rights specific to your residency, contact us at support@valte.io and we will honor them as required by applicable law.
8.3 How to Exercise Your Rights
To exercise any right described in this Section, email support@valte.io describing the right you wish to exercise. We verify identity using account credentials and may request additional information to confirm your identity. We will respond within forty-five (45) days from receipt of a verifiable request, extendable by an additional forty-five (45) days with notice. Authorized agents may submit requests on your behalf with written authorization and proof of identity as required by applicable law.
8.4 Appeals
If we deny your request in whole or in part, you may appeal by replying to our response or emailing support@valte.io within thirty (30) days of our decision. We will respond to appeals within sixty (60) days. If your appeal is denied, you may contact the attorney general or applicable regulator in your state.
8.5 California "Shine the Light"
Pursuant to California Civil Code Section 1798.83, California residents may request a notice of the categories of Personal Information we shared with third parties for those third parties' direct marketing purposes. We do not share Personal Information for third-party direct marketing purposes.
9. COOKIES AND TRACKING TECHNOLOGIES
9.1 Cookies and Similar Technologies
We use cookies and similar technologies solely for the technical operation of the Services, authentication, and security (for example, keeping you signed in). We do not use third-party advertising or analytics cookies.
9.2 Managing Preferences
You can manage cookie preferences via your browser settings. Disabling certain cookies may affect the functionality of the Services.
9.3 Global Privacy Control
Because we do not Sell or Share Personal Information (see Section 5.5), there is no Sale or Sharing from which to opt out. To the extent applicable law treats a Global Privacy Control ("GPC") signal as a valid opt-out request, we honor it.
10. CHILDREN'S PRIVACY
10.1 Eighteen Plus Only
The Services are intended for, and directed exclusively to, individuals who are at least 18 years of age. We do not knowingly collect Personal Information from anyone under 18.
10.2 Deletion of Inadvertent Collection
If we learn that we have collected Personal Information from an individual under 18, we will promptly delete that information and close the associated account. Parents or legal guardians who believe a child under 18 has provided Personal Information to the Services may contact support@valte.io to request deletion.
11. UPDATES TO THIS POLICY
11.1 Revisions
We may update this Policy from time to time to reflect changes to the Services, our practices, or applicable law.
11.2 Material Changes
We will provide at least thirty (30) days' advance notice of material changes to this Policy via email to the address associated with your account and via in-app notification.
11.3 Continued Use
The effective date at the top of this Policy will be updated when revisions are published. Your continued use of the Services after the effective date of any revision constitutes your acceptance of the revised Policy.
12. CONTACT
12.1 Email
For privacy questions, to exercise your privacy rights, to submit appeals, or for general inquiries, contact us at support@valte.io.
12.2 Mailing Address
A service address for privacy correspondence will be provided upon request through support@valte.io.