Privacy policy

PRIVACY POLICY VERSION 1.0
Last revised on: February 1, 2026

Vauxx Inc. ("Vauxx", "Vaux", "we", "our" or "us") puts great efforts in making sure that the personal data processed by us is safe and used properly, and that our data practices are properly communicated to our customers and users.

This Privacy Policy describes how we collect, store, use and disclose personal data relating to identifiable individuals ("Personal Data") who use the Vaux mobile application, platform, and other tools and features provided by us (collectively – "Services" or "Platform").

Specifically, this Privacy Policy describes our practices regarding–- Data Collection & Processing
- Data Uses
- Data Location
- Data Retention
- Data Sharing
- Cookies and Tracking Technologies
- Communications
- Data Security
- Data Subject Rights
- Additional Notice & Contact Details

If you are our user or visitor ("you"), please read this Privacy Policy carefully and make sure that you fully understand and agree to it.

You are not legally required to provide us with any personal data, and may do so (or avoid doing so) at your own free will. If you do not wish to provide us with your personal data, or to have it processed by us or any of our Service Providers (defined below), please avoid any interaction with us or use of our Services.

1. Data Collection & Processing

We collect and generate the following types of Personal Data concerning users of our Platform:

Account Information:
- Email address
- Hashed password
- Name
- Phone number (if provided)
- Zip code

Financial Account Data:
- Financial institution account credentials (processed securely through Plaid)
- Bank account and transaction information
- Account balances
- Transaction history and spending patterns
- Financial categorization and analysis

Contact Information:
- Phone contacts (if you grant permission for bill-splitting features)
- Names and contact details of individuals you choose to share expenses withProfile and Usage Information:
- Device type and operating system
- App version
- Language and locale settings
- Activity logs and event tracking
- Feature usage patterns
- Session data

Shared Expense Data:
- Transactions you designate as shared expenses
- Payment settlements between linked users
- Split payment arrangements

Communications:
- Direct interactions with us (emails, support requests, feedback)
- Communications regarding your use of the Services

We collect such data either automatically through your interaction with our Platform and Services, or when you voluntarily provide it to us.

2. Data Uses

We use your Personal Data for the following purposes:

- To provide and operate our Services: Including calculating your Available Spend, analyzing your financial patterns, facilitating bill-splitting and shared expenses, and providing personalized financial insights through our AI-powered decision framework

- To authenticate your identity and allow you secure access to our Services

- To provide customer support and respond to your inquiries

- To improve our Services: Understanding how users interact with our Platform to enhance user experience, develop new features, and optimize performance

- To communicate with you: Sending service-related notifications, updates, and important information about your account

- To send promotional communications: Notifying you about new features, offerings, and information we think may be valuable to you (as further described in Section 7 below)

- To ensure security: Preventing fraud, unauthorized access, and other illegal activities

- To comply with legal obligations: Meeting regulatory requirements and responding to legal processes

- To create aggregated data: Generating anonymized, non-identifiable statistical data for analytics and service improvement

We do not sell your personal information. We have never sold personal data and we never will.

If you reside or are using the Services in a territory governed by privacy laws under which "consent" is the only or most appropriate legal basis for processing Personal Data, your acceptance of our Privacy Policy and Terms of Use constitutes your consent to the processing of your Personal Data for all purposes detailed in this Policy. If you wish to revoke such consent, please contact us at alec@vauxlabs.io.

3. Data Location

We and our authorized Service Providers (defined below) maintain, store and process Personal Data in the United States of America.

While privacy laws may vary between jurisdictions, Vauxx and its Service Providers are committed to protecting Personal Data in accordance with this Privacy Policy and customary industry standards, regardless of any lesser legal requirements that may apply in their jurisdiction.

4. Data Retention

We retain your Personal Data for as long as your account is active or as reasonably necessary to provide you with our Services, comply with our legal and contractual obligations, resolve disputes, and enforce our agreements.

Upon account deletion or termination:
- We will delete or anonymize your Personal Data within 60 days
- Some data may be retained longer if required by law or for legitimate business purposes (such as fraud prevention, financial recordkeeping, or resolving disputes)
- Aggregated, anonymized data that cannot identify you may be retained indefinitely

If you have any questions about our data retention policy, please contact us at alec@vauxlabs.io.

5. Data Sharing

We share your Personal Data only in the following limited circumstances:

Service Providers:

We engage selected third-party companies to perform services complementary to our own (collectively, "Service Providers"). These Service Providers may have access to your Personal Data only to perform specific tasks on our behalf and are obligated to protect your information. Our Service Providers include:

- Plaid Inc.: For securely connecting to your financial accounts, retrieving transaction data, and verifying account information. Plaid's privacy practices are available at https://plaid.com/legal/

- Stripe, Inc.: For processing subscription payments and billing. Stripe's privacy practices are available at https://stripe.com/privacy

- PostHog Inc.: For analytics and understanding how users interact with our Services through event tracking. PostHog's privacy practices are available at https://posthog.com/privacy

- Email and SMS service providers: For sending transactional and promotional communications

- Cloud hosting and infrastructure providers: For secure data storage and platform operations

- Customer support tools: For providing user assistance

- Legal, financial and compliance advisors

Other Vaux Users (With Your Control):When you use bill-splitting or shared expense features:
- Other users you explicitly connect with can see shared expenses you've both tagged or designated
- Other users cannot see your full transaction history or account balances
- You control which expenses are shared and with whom
- You can revoke access to shared expenses at any time through your account settings

Legal Compliance:

We may disclose your Personal Data if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to:
- Comply with legal obligations
- Protect and defend our rights or property
- Prevent fraud or illegal activity
- Protect the safety of our users or the public

Business Transfers:

If Vauxx undergoes a merger, acquisition, sale of assets, or other change in control, your Personal Data may be transferred to the acquiring entity. We will notify you via email or prominent notice on our Services before your Personal Data is transferred and becomes subject to a different privacy policy.

With Your Consent:

We may share your Personal Data for other purposes with your explicit consent.

Anonymized Data:

We may share aggregated, anonymized data that cannot identify you with third parties for analytics, research, or other business purposes.

6. Cookies and Tracking Technologies

Our Services use limited tracking technologies for analytics and performance purposes.

PostHog Analytics:

We use PostHog for event tracking to understand how users interact with our Services.

This includes tracking:
- Feature usage patterns
- Navigation paths
- App performance metrics
- Anonymized user behavior

PostHog does not collect personally identifiable information without your consent. You can learn more about PostHog's privacy practices at https://posthog.com/privacy.

Mobile App Data:

Our mobile application may store local data on your device for:
- Authentication tokens (to keep you logged in)
- App preferences and settings
- Cached data for offline functionalityYou can manage these through your device settings or by uninstalling the application.

Do Not Track:

We do not currently respond to "Do Not Track" signals from browsers or mobile applications.

7. Communications

Service Communications:

We may contact you with important information regarding our Services, including:
- Account notifications and security alerts
- Transaction confirmations
- Password reset requests
- Changes to our Services or policies
- Billing and payment information
- Customer support responses

You cannot opt out of these essential service communications, as they are integral to your use of our Services.

Promotional Communications:We may send you promotional messages about new features, tips for using Vaux, special offers, and other information we think may interest you. We may send these via:
- Email
- SMS/text message
- Push notifications (if enabled on your device)
- In-app messagesOpting Out:You can opt out of promotional communications at any time by:
- Clicking "unsubscribe" in any promotional email
- Replying "STOP" to SMS messages
- Adjusting notification settings in the Vaux app
- Contacting us at alec@vauxlabs.io

Please note that even if you opt out of promotional communications, you will still receive essential service communications.

8. Data Security

We implement industry-standard security measures to protect your Personal Data, including:

- Encryption of data in transit and at rest
- Secure authentication and password hashing
- Regular security assessments and updates
- Access controls limiting who can view your data
- Secure infrastructure and hosting
- Partnership with Plaid for bank-level security of financial data

However, no method of transmission or storage is 100% secure. While we strive to protect your Personal Data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.If you suspect unauthorized access to your account, contact us immediately at alec@vauxlabs.io.

9. Data Subject Rights

You have rights concerning your Personal Data under applicable privacy laws, including the EU General Data Protection Regulation (GDPR), UK Data Protection Act, and California Consumer Privacy Act (CCPA).Your rights may include:

- Access: Request a copy of the Personal Data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your Personal Data (subject to legal retention requirements)
- Restriction: Request limitation on how we process your data
- Portability: Request a copy of your data in a structured, machine-readable format
- Objection: Object to certain processing of your data
- Withdraw Consent: Revoke previously given consent at any time
- Equal Services: Receive equal service and pricing regardless of exercising your privacy rights (CCPA)

Exercising Your Rights:

To exercise any of these rights, contact us at alec@vauxlabs.io.

Please include:
- Your name and email address associated with your account
- A description of your request
- Any information necessary to verify your identity

We will respond to your request within the timeframe required by applicable law (typically 30-45 days). We may need to verify your identity before fulfilling your request to protect your Personal Data from unauthorized access.

California Residents:Under the CCPA, California residents have additional rights. We do not sell your Personal Data and never will. For California-specific requests or questions, contact us at alec@vauxlabs.io.

EU/UK Residents:If you are in the European Union or United Kingdom, you have the right to lodge a complaint with your local supervisory authority if you believe we have processed your Personal Data unlawfully.

10. Additional Notices

Children's Privacy:

Our Services are not intended for individuals under the age of 18. We do not knowingly collect Personal Data from children. If you are under 18, do not use our Services or provide any information to us.If we learn that we have collected Personal Data from a child under 18, we will delete that information as quickly as possible. If you believe we have collected information from a child, please contact us at alec@vauxlabs.io.

Third-Party Links and Services:

Our Services may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information to them.

This Privacy Policy applies only to information collected by Vauxx through our Services.

Changes to This Privacy Policy:

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or legal requirements. When we make changes, we will:
- Update the "Last revised" date at the top of this policy
- Notify you via email or prominent notice in our Services if the changes are material
- Provide a reasonable notice period before the changes take effectYour continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

International Users:

Our Services are operated in the United States. If you are located outside the United States, please be aware that information we collect will be transferred to, stored, and processed in the United States. By using our Services, you consent to this transfer and processing.

California Privacy Rights:

California residents may request information about our disclosure of Personal Data to third parties for their direct marketing purposes. Since we do not share Personal Data with third parties for their direct marketing purposes, we are exempt from this requirement.Under California Civil Code Section 1798.83, California residents are entitled to request certain information regarding disclosure of Personal Data to third parties. To make such a request, contact us at alec@vauxlabs.io.

11. Contact Information

If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us:

Vauxx Inc.
447 Broadway, 2nd Floor Suite #3055
New York, New York 10013
United States

Email: alec@vauxlabs.io

For privacy-related requests (access, deletion, correction, etc.), please email alec@vauxlabs.io with "Privacy Request" in the subject line.Effective Date:

February 1, 2026

Copyright © 2026 Vauxx Inc. All rights reserved.