Privacy Policy & Global Data-Rights Addendum
Von Neumann Systems LLC — TheAwardVault.com
Effective Date: 2026-08-24 | Version v2.2
Privacy Section 1: Categories of Personal Information Collected
To operate the Platform and facilitate transactions, Von Neumann Systems LLC collects the following categories of personal information:
- Direct Identifiers: Account holder names, email addresses, and authentication credentials (credentials are managed by our identity provider — see Section 4).
- Recipient pseudonyms (hashes): For award delivery we derive a keyed cryptographic hash (HMAC-SHA256) of a Recipient's email. The hash is a pseudonym used for de-duplication, suppression (do-not-contact), rate-limiting, and surfacing unclaimed awards to the matching account holder. The plaintext Recipient email itself is not stored — see Section 2.
- Date of birth & age data: Where age-gating or COPPA handling applies, a date of birth is collected and stored encrypted at rest. For an account holder, we also retain the derived age bracket and age-transition schedule. If signup is denied because the person is under 18, no Platform account is created; the limited denial record described in Section 5 is used instead.
- Consent records: Email-preference opt-ins/withdrawals and legal-acceptance events, each logged with a timestamp, IP address, and method to an append-only ledger.
- Geographic data: Stated country/region and the source of that determination, plus a best-effort country inference (from email TLD or claim-time IP country) used for jurisdiction routing.
- Commercial information: Transaction histories, Platform balances, and records of issued, claimed, or revoked Digital Assets.
- Anti-abuse signals: A hash of the client IP used at account creation (signup-rate limiting) and a Stripe card-fingerprint token used for fraud correlation. We do not store full card numbers (no PAN).
- Minor-related data: Where a Recipient is a Minor, the name and (where provided) a parent/guardian email used solely for verifiable parental consent. Parent emails are stored as a hash, with the plaintext retained only while a consent link is pending or active and minimized thereafter.
- Device tokens (mobile): Where you use a mobile app, a push-notification device token.
Privacy Section 2: Third-Party Data & the "Unregistered Recipient" (Zero-Retention)
When a Granter inputs a Recipient's email to issue a Digital Asset, the Platform processes that data on the Granter's behalf on a strict zero-retention basis.
- Zero-retention of the Recipient email: The Recipient's email is normalized and keyed-hashed in memory, used once to dispatch a single notification, and then discarded. It is never written to our databases, application logs, or message queues. (It is therefore not "deleted from our databases" on request — it was never stored.) Our email-delivery provider may log it transiently under its own retention; we configure provider retention to the minimum.
- Notice at Collection: The notification constitutes a CCPA "Notice at Collection" and states that the data was provided by the Granter to deliver a Digital Asset. The award notification is transactional, not marketing.
- Encrypted pending name: For the optional printed-frame flow a Recipient's name may be held AES-256-GCM encrypted, visible only to the Granter who supplied it, for a short configured window (roughly 7–30 days for the email flow, up to 90 days once a frame is print-confirmed), then auto-deleted on claim, expiry, or a delete request.
- One-click "delete my information": Every notification contains a one-click mechanism. For an Unregistered Recipient this performs an erasure of their unclaimed awards and records a one-year cooldown blocking that same Granter from re-sending. It is distinct from Unsubscribe (the permanent do-not-contact opt-out): after a delete, a different Granter may still send a lawful, transactional award later. Account holders are routed to authenticated account-deletion instead.
- Granter warranties & attestation: By inputting a Recipient's details, the Granter warrants a lawful basis to contact them (and parental consent where the Recipient is a Minor). For Canadian Recipients the Granter must affirm a CASL basis; for certain Australian sends an inferred-consent basis is recorded (see Section 7).
- Scope of this section: the zero-retention commitment above governs an email address a Granter supplies to us in order to dispatch an award to someone else. It does not govern an address you give us yourself — for example when you contact support — which we hold in order to reply to you, under the retention described in Section 5.
Privacy Section 3: Email Preferences & Consent
We separate transactional mail from optional mail:
- Award notifications are transactional and are sent as part of delivering the service.
- Digest and marketing emails are optional, default-off, and may be granted or withdrawn at any time from your account's privacy controls (
/account/privacy). - Every consent grant or withdrawal is recorded to an append-only ledger with a timestamp, IP address, and method, so the state of your preferences is auditable.
Privacy Section 4: Sub-Processors & International Transfers
We integrate specialized infrastructure providers and share data strictly to perform necessary business functions. A maintained register is summarized below:
- Auth0 (Okta): account and employee authentication and login state.
- Stripe: payment processing. We retain only transactional metadata and balances and a card-fingerprint token for fraud correlation; no full card numbers are stored.
- Oracle (OCI Email Delivery): transactional email delivery. Bounce and complaint records are read back from the provider and hashed on receipt, so no plaintext recipient email is retained in our systems.
- Firebase Cloud Messaging (Google): mobile push notifications.
- OCI Vault (Oracle): management of encryption and hashing keys only (no personal data).
- MaxMind GeoLite2: a locally-bundled IP-to-country dataset used for jurisdiction routing (no personal data is sent to MaxMind at run time).
International transfers: the Platform is operated from the United States, and the providers above process data in the United States. Where personal data originates in the EEA, the UK, or another jurisdiction requiring a transfer mechanism, transfers rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework where the provider is certified.
Privacy Section 5: Data Retention
We apply per-activity retention rather than a single flat period:
- Recipient email: not retained (zero).
- Pending Recipient name (print flow): roughly 7–30 days (email flow) / up to 90 days (printed), then deleted.
- Send log (hash-keyed): approximately 3 years.
- Compliance send-records (hash-keyed): 3 years (5 years for Australian sends).
- Consent & legal-acceptance ledger: approximately 7 years.
- Suppression (do-not-contact) list: indefinite — a permanent do-not-contact list deliberately survives account deletion so that an opt-out is honored permanently.
- Date of birth & parental-consent records: account lifetime (encrypted); parental-consent records are kept for a period after the child reaches majority, then deleted.
- Denied under-18 signup: no Platform account is created. For up to 72 hours from the first denied submission, we retain an encrypted date of birth, an age bracket, a keyed one-way hash of the verified email address, and the authentication-provider identifier or identifiers needed to delete attempted identities. We use this record only to prevent immediate age-gate retries and to stop an award notification to the same address while the record is active. A retry does not extend the deadline. We do not retain the plaintext email in our database, use this record for marketing, or keep it to send a future invitation.
- Deletion timing: we request deletion of the denied authentication identity immediately where our environment permits destructive processing. The denial record becomes unusable at its 72-hour deadline and an automated sweep permanently deletes it. An operational outage may delay physical deletion, in which case the expired record remains ineligible for use and deletion is retried.
- Account & transactional records: retained for the account lifetime and for a period thereafter (generally up to three years) as necessary for legal, tax, dispute, and fraud purposes.
- Support requests: message content is retained for roughly 24 months after the last activity on the request for organization accounts, and roughly 90 days for requests from unregistered parents and other non-account holders. A hash-keyed record of the request itself, containing no message content, is kept for up to 3 years for fraud and dispute purposes.
Privacy Section 6: Your Privacy Rights (CCPA/CPRA, GDPR & Global)
Depending on your jurisdiction you may exercise the following rights. Authenticated requests can be made in-app at /account/privacy; we acknowledge requests within 24 hours and fulfill them within the deadline applicable to your jurisdiction.
- Access / Know: request the specific pieces and categories of personal information we hold, their sources, and the purposes of processing.
- Portability: receive a copy of your data in a portable format.
- Rectification: correct inaccurate personal information.
- Restriction: request that we restrict certain processing.
- Deletion / Erasure: request deletion of your personal information, subject to legal-hold exceptions (for example, billing/tax records and our permanent do-not-contact list, which survives deletion in your favor).
- Non-Discrimination: we will not deny service, change pricing, or degrade service because you exercised these rights.
One restriction, by age. If the account holder is under 13, we do not act on a deletion request submitted by the child themselves — that request is declined, and a parent or guardian must make it. Federal law (COPPA) gives the deletion right for that age group to the parent, and we cannot verify a child's instruction to erase an account a parent consented to. A parent can delete the account at any time from the parent portal or by contacting us, and we do not charge for it or delay it. From age 13 there is no such restriction: a 13–17 year old exercises deletion, access and portability directly, on the same terms as an adult and without a parent's involvement. The other rights above — access, portability, rectification — are available to a child under 13 through their parent.
Fulfillment deadlines follow your jurisdiction — for example, GDPR/UK roughly one month, California (CCPA/CPRA) 45 days (extendable), with other regions handled per their local standard. Where we cannot verify an identifier (Recipient emails are stored only as a hash), we verify a requester by their demonstrated control of the address or an authenticated session.
6.1 California (CCPA / CPRA)
California residents have the rights above and the right to opt out of the "sale" or "sharing" of personal information. Von Neumann Systems LLC does not sell or share personal information (including for cross-context behavioral advertising), runs no advertising, and deploys no advertising trackers. A "Do Not Sell or Share My Personal Information" election is therefore honored by default.
Privacy Section 7: International & Jurisdiction-Specific Handling
The Platform routes processing by the Recipient's jurisdiction:
- Canada (CASL): a Granter sending to a Canadian Recipient must attest to a lawful CASL basis (business, personal, or prior consent); attestations are recorded.
- Australia: an inferred-consent basis is recorded where applicable.
- Japan (APPI): a third-party provision record is maintained for applicable sends.
- South Korea: the Platform is not currently available in South Korea and signups/sends are blocked at every entry point; only a country code and timestamp are logged for a blocked attempt (no email, no account).
- Cross-border transfer: all processing occurs in the United States as described in Section 4.
Privacy Section 8: Data Security & Internal Audit Controls
Von Neumann Systems LLC implements security protocols designed to align with SOC 2 standards:
- Encryption & pseudonymization: sensitive personal data (including dates of birth and pre-claim names) is encrypted at rest with AES-256-GCM, and Recipient emails are pseudonymized with keyed HMAC hashing rather than stored in plaintext.
- Gated, least-privilege access: billing histories, balances, and PII are reachable only through authenticated dashboards under role-based access control.
- Compliance access logging: privileged lookups, exports, and data-subject-request actions by a designated compliance officer are recorded to an append-only, tamper-evident audit log (actor, hashed subject, mandatory reason, timestamp).
- Automated anti-abuse: we operate hash-keyed send logs and may automatically suspend a Granter's ability to send when rolling complaint or bounce rates exceed defined thresholds (with a human review/appeal path), and may blacklist disposable/spam domains. Cross-account correlation signals (pseudonymous hash overlap and Stripe fingerprint correlation) are flagged for human review and never trigger an automatic account block.
Privacy Section 9: Cookie Policy
Von Neumann Systems LLC uses local storage and first-party cookies strictly to provide essential Platform functionality, including maintaining secure authentication sessions via Auth0, facilitating payment processing via Stripe, and ensuring proper rendering of 3D and 2.5D Digital Assets. Because these technologies are strictly necessary, they cannot be disabled by the User.
Von Neumann Systems LLC does not deploy third-party tracking pixels, web beacons, or advertising cookies, and does not compile or share personal browsing histories to build targeted advertising profiles.
For information specific to minors and parental rights, also see:
Von Neumann Systems LLC
Santa Clara County, California, United States
Contact: legal@theawardvault.com · privacy@theawardvault.com
Last Updated: 2026-08-24