Who we are and what this covers
[[ENTITY]] (“VavaStone”, “we”, “us”) provides slab inventory, sales and delivery software to natural stone distributors. We are based in San Diego, California, and are part of the SDSharp group.
This policy applies to personal information we handle through:
- our website at vavastone.com and its subpages;
- our hosted application at portal.vavastone.com and any associated mobile, scanning or storefront applications;
- demos, trials, events, webinars and marketing communications; and
- our sales, onboarding, billing and support activities.
It does not apply to third-party websites we link to, or to how a VavaStone customer independently handles data in its own business — see section 18.
Our two roles: controller and processor
We handle personal information in two distinct capacities, and your rights differ depending on which applies.
| Role | When it applies | What it means for you |
|---|---|---|
| Controller (“business” under CCPA) |
Website visitors, prospects, demo requests, event attendees, account administrators, billing contacts, support requesters, job applicants. | We decide why and how the data is used. Exercise your rights directly with us under sections 15–17. |
| Processor (“service provider” under CCPA) |
Personal information inside a customer’s account — their staff records, their buyers, fabricators, contacts, delivery addresses, quotes and orders. | Our customer decides why and how that data is used. We act only on their instructions. Direct your request to them; see section 18. |
Summary
- We do not sell personal information for money, and we do not use it for cross-context behavioural advertising.
- We do not run advertising networks, retargeting pixels or ad-tech tags on our website.
- We use a small number of vendors: product analytics, live chat, meeting scheduling, contact-form delivery, hosting and email. They are listed in section 8.
- Our web fonts are served from our own domain, so loading a page does not disclose your IP address to a font provider.
- You can ask us for a copy of your data, to correct it, or to delete it — see section 17.
- We keep data no longer than we need it, on the schedule in section 12.
This summary is for orientation only. The sections below are the operative terms.
Information we collect
The table uses the categories defined by the California Consumer Privacy Act, as amended (“CCPA”), so you can map it to your statutory rights.
| Category | Examples | Source | Disclosed to |
|---|---|---|---|
| Identifiers | Name, business email, business postal address, telephone number, company name, job title, account username, IP address, device and cookie identifiers. | You; automatic collection. | Hosting, email, analytics, chat, scheduling and CRM providers. |
| Customer records (Cal. Civ. Code §1798.80) |
Billing contact details, purchase and payment records, signature on an order form, credit-check outputs where we run one. | You; payment processor; credit reference agency. | Payment processor, accountants, auditors. |
| Commercial information | Plan and subscription details, seat and yard counts, invoices, renewal and cancellation history, products and services considered or purchased, support tickets. | You; automatic collection. | Payment processor, support and CRM providers. |
| Internet or network activity | Pages viewed, referring URL, session duration, clicks and feature interactions, error and performance logs, browser type and version, operating system, screen and viewport size, language, approximate connection quality. | Automatic collection. | Analytics and hosting providers. |
| Geolocation data | Approximate city, region and country inferred from IP address. We do not collect precise GPS location from the website. Delivery and pickup addresses you enter in the application are Customer Data (section 18). | Automatic collection; you. | Analytics and hosting providers. |
| Professional or employment information | Employer, role, yard or branch, purchasing authority, industry segment, information in a job application. | You; publicly available business sources. | CRM and recruiting providers. |
| Audio, visual and similar | Photographs and imagery uploaded to the platform, product and yard photography, recordings of a demo or support call where we tell you in advance and, where required, obtain consent. | You. | Hosting and conferencing providers. |
| Communications | Contents of emails, contact-form submissions, live chat transcripts, meeting-booking notes and support correspondence. | You. | Email, chat, scheduling and support providers. |
| Inferences | Derived indicators such as likely fit for a plan, engagement level, or feature interest, used for our own sales and product decisions. | Derived by us. | CRM provider. |
We do not knowingly collect government identifiers, financial account numbers, precise geolocation, biometric data, health data, or data revealing racial or ethnic origin, religious belief, union membership, sex life or sexual orientation. Card details are entered directly with our payment processor; we never receive or store full card numbers.
How we collect it
5.1 Directly from you
When you fill in the contact form, book a demo, start a trial, create an account, subscribe, contact support, open a live chat, subscribe to updates, attend an event, or apply for a job.
5.2 Automatically
Through cookies, local storage, server logs, SDKs and similar technologies when you visit our website or use the application. See the Cookie Policy.
5.3 From third parties
From our customers (when they invite you into their account), from publicly available business sources and industry directories, from event and webinar co-hosts, from partners and resellers, from our payment processor, and from service providers that help us keep business contact records accurate. Where a third party gives us your information, we rely on their confirmation that they are permitted to do so.
Why we use it, and our legal bases
The “legal basis” column applies where the EU or UK GDPR governs the processing. Where it does not, the “purpose” column is the operative description.
| Purpose | Categories used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Provide, host, maintain and support the Service; authenticate users; process transactions you initiate | Identifiers, commercial, internet activity, communications | Performance of a contract; legitimate interests in operating our business |
| Bill you, collect payment, keep accounting and tax records | Identifiers, customer records, commercial | Performance of a contract; legal obligation |
| Respond to enquiries, demo requests, chat and support tickets | Identifiers, communications, professional | Performance of a contract; legitimate interests in responding to enquiries |
| Secure the Service, detect and prevent fraud, abuse and unauthorised access, keep audit logs | Identifiers, internet activity, geolocation | Legitimate interests in protecting our business and users; legal obligation |
| Understand how the Service is used, fix defects, measure performance, improve and develop features | Internet activity, identifiers, inferences | Legitimate interests in improving our products; consent where cookies require it |
| Send service and administrative messages (outages, security notices, billing, changes to terms) | Identifiers, commercial | Performance of a contract; legal obligation |
| Send marketing about our products to business contacts, and measure whether it was opened or clicked | Identifiers, professional, inferences | Consent where required; otherwise legitimate interests in direct marketing to business contacts, subject to an opt-out in every message |
| Produce aggregated and de-identified statistics, benchmarks and industry insight | Internet activity, commercial (de-identified) | Legitimate interests in understanding and improving our market and product |
| Establish, exercise or defend legal claims; enforce our terms; comply with law and lawful requests | All categories as relevant | Legal obligation; legitimate interests in protecting our legal rights |
| Corporate transactions — financing, audit, reorganisation, merger or sale of the business | Identifiers, commercial, customer records | Legitimate interests in operating and developing our business |
| Recruitment | Identifiers, professional, communications | Steps prior to entering a contract; legitimate interests in assessing applicants |
Where we rely on legitimate interests, we have assessed those interests against your rights and freedoms. You may object at any time — see section 16. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
Cookies and similar technologies
We use cookies, local storage and similar technologies for essential site function, for security, for remembering preferences, and to understand how the site and application are used. Full detail, including the categories in use and how to change your choices, is in our Cookie Policy. We do not use advertising or retargeting cookies.
Who we share it with
8.1 Service providers and processors
We share personal information with vendors that process it on our behalf and under contract, limited to what they need to perform their function, and prohibited from using it for their own purposes. Our principal vendors are:
| Vendor | Function | Data involved | Primary location |
|---|---|---|---|
| Framer | Website publishing, hosting and delivery, basic site analytics | Identifiers, internet activity | United States / EEA |
| PostHog | Product and website analytics | Identifiers, internet activity, inferences | United States / EEA |
| Crisp | Live chat and support messaging | Identifiers, communications | European Union |
| Calendly | Demo and meeting scheduling | Identifiers, communications | United States |
| Web3Forms | Contact-form delivery | Identifiers, communications | United States |
| Application hosting and storage providers | Running portal.vavastone.com, storing Customer Data and backups | All categories as applicable | United States |
| Payment processor | Subscription billing and payment collection | Identifiers, customer records, commercial | United States |
| Email, CRM and productivity providers | Business correspondence, sales records, document handling | Identifiers, communications, professional, commercial | United States |
A current list of subprocessors used to deliver the application is available to customers on request from privacy@vavastone.com. We may add or change vendors as our stack evolves; where we act as processor, we will notify affected customers as required by our Data Processing Addendum.
8.2 Our group and affiliates
We may share personal information within the SDSharp group where it is necessary for shared administration, finance, security, legal or product functions, subject to the purposes in section 6.
8.3 Professional advisers
Lawyers, accountants, auditors, insurers and consultants, under duties of confidentiality, where necessary for our legitimate business or legal purposes.
8.4 Corporate transactions
If VavaStone is involved in a merger, acquisition, investment, financing, reorganisation, insolvency, or a sale or transfer of all or part of its business or assets, personal information may be disclosed to counterparties, prospective counterparties and their advisers as part of due diligence, and may be transferred as part of that transaction. We will require any recipient to honour this policy for the information transferred, or to give notice before materially changing how it is used.
8.5 Legal and safety
We may disclose personal information where we believe in good faith it is necessary to: comply with law, a subpoena, warrant, court order or regulator; respond to a lawful request from a public authority; establish, exercise or defend legal claims; enforce our terms; investigate suspected fraud, security incidents or violations; or protect the rights, property or safety of VavaStone, our users or the public. Where we are legally permitted, and where the request concerns Customer Data, we will notify the affected customer before disclosure so that they can seek protective relief.
8.6 With your direction
Where you ask us to, for example by enabling an integration, publishing a storefront, or inviting a buyer into an account.
Sale and sharing of personal information
We do not sell personal information for monetary consideration, and we have not done so in the preceding twelve months. We do not disclose personal information for cross-context behavioural advertising, and we do not sell or share the personal information of anyone we know to be under 16.
Some US state privacy laws define “sale” and “share” broadly enough that certain analytics configurations can fall within them. Our position is that our use of analytics is a service-provider arrangement and not a sale or share. Even so, we honour opt-out signals: we recognise the Global Privacy Control (GPC) browser signal as a valid opt-out request for the browser that sends it, and you can additionally exercise the choices described in our Cookie Policy.
Sensitive personal information
We do not collect or process sensitive personal information as defined by the CCPA, and we do not process special-category data under Article 9 of the GDPR, for the purpose of inferring characteristics about you. Accordingly, the CCPA right to limit the use of sensitive personal information does not arise in practice. If this changes, we will update this policy and provide the required “Limit the Use of My Sensitive Personal Information” mechanism.
Artificial intelligence and analytics
We analyse how the Service is used in order to operate, secure and improve it, and we may use statistical, machine learning and artificial intelligence techniques to do so. Where we do:
- we work with aggregated and de-identified data wherever it is sufficient for the purpose;
- we do not train models for the purpose of identifying you, profiling you as an individual, or making a decision that produces a legal or similarly significant effect on you;
- we do not use one customer’s Customer Data to build features or outputs presented to another customer in any form that identifies the first customer, its buyers, its prices or its transactions; and
- where we use a third-party AI provider, we contract to prohibit that provider from using our data to train its own general models.
Our contractual rights over aggregated and de-identified data are set out in section 8 of the Terms of Use.
How long we keep it
We keep personal information only as long as we need it for the purpose it was collected for, plus any period required for legal, accounting, tax, audit, security or dispute-resolution purposes. Our working schedule:
| Data | Retention |
|---|---|
| Account and subscription records | For the life of the account, then 7 years from the end of the relationship (contract limitation and tax) |
| Billing, invoicing and tax records | 7 years from the end of the relevant tax year |
| Customer Data in the application | For the subscription term, then deleted after the 30-day export window described in the Terms of Use, subject to backup expiry |
| Backups and disaster-recovery copies | Up to 90 days on a rolling cycle, then overwritten |
| Support tickets and chat transcripts | 24 months from last contact |
| Contact-form and demo-request submissions | 24 months from submission, unless a relationship begins |
| Marketing contacts and preferences | Until you unsubscribe, plus a suppression record kept indefinitely so that we can honour the opt-out |
| Security, access and audit logs | 12 months, longer where an investigation requires it |
| Analytics data | Up to 24 months, in de-identified or aggregated form thereafter |
| Job applications | 12 months from decision, unless you ask us to keep them longer |
| Records relating to an actual or threatened legal claim | Until the claim and any appeal period are finally resolved |
Aggregated and de-identified data, which is no longer personal information, may be retained indefinitely.
How we protect it
We maintain administrative, technical and physical safeguards appropriate to the nature of the data and the risk, including encryption of data in transit, encryption at rest for stored data, role-based access control, least-privilege access for our personnel, multi-factor authentication on administrative systems, logging and monitoring, vendor due diligence, secure development practice, and staff confidentiality obligations and training.
No method of transmission or storage is perfectly secure. We cannot and do not guarantee absolute security, and any transmission is at your own risk. Your own conduct matters too: keep credentials confidential, enable available security features, and use up-to-date devices. Report a suspected incident to security@vavastone.com. Where the law requires it, we will notify affected individuals and regulators of a personal data breach within the applicable deadlines.
International transfers
We are based in the United States, and our vendors are located in the United States and the European Union. If you are in the EEA, the United Kingdom or Switzerland, your personal information will be transferred to and processed in the United States, which has not received an adequacy decision of general application.
Where we transfer personal information out of the EEA, the UK or Switzerland, we rely on one or more of the following safeguards:
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), incorporated into our contracts with the relevant recipient;
- the UK International Data Transfer Addendum to those clauses, or the UK IDTA, for transfers from the United Kingdom;
- the Swiss addendum to those clauses, for transfers from Switzerland;
- an adequacy decision, where one applies to the recipient country; or
- a derogation under Article 49 of the GDPR, where one is available and appropriate.
We carry out transfer impact assessments where required, and apply supplementary technical and organisational measures where our assessment indicates they are needed. You may request a copy of the relevant safeguard, with commercially confidential terms redacted, from privacy@vavastone.com.
Your US state privacy rights
Depending on your state of residence, you may have some or all of the following rights in respect of the personal information for which we are the controller or business:
- Right to know / access. To learn the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose, and the categories of third parties to whom we disclose it.
- Right to delete. To ask us to delete personal information we collected from you, subject to the exceptions the law allows.
- Right to correct. To ask us to correct inaccurate personal information.
- Right to portability. To receive a copy in a portable, readily usable format where technically feasible.
- Right to opt out of sale or sharing, and of targeted advertising and certain profiling. As stated in section 9, we do not sell or share personal information, and we honour the Global Privacy Control.
- Right to limit the use of sensitive personal information. As stated in section 10, this does not arise in practice, because we do not process sensitive personal information to infer characteristics.
- Right to non-discrimination. We will not deny you service, charge you a different price, or provide a different level of quality because you exercised a privacy right. We operate no financial incentive programme for personal information.
- Right to appeal. If we decline your request, you may appeal by replying to our decision with the word “Appeal”. We will respond within the period your state law allows, with reasons. In Virginia, Colorado, Connecticut, Texas, Oregon, Montana and other states with an appeal mechanism, if the appeal is denied we will tell you how to complain to your Attorney General.
Authorised agents. You may use an authorised agent. We will require written proof of authorisation signed by you and may require you to verify your identity with us directly.
Shine the Light. California Civil Code §1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
Your EEA, UK and Swiss rights
If the EU GDPR, UK GDPR or Swiss FADP applies to you, you have the right to:
- access the personal information we hold about you and receive a copy;
- rectify inaccurate or incomplete personal information;
- erase personal information where one of the statutory grounds applies;
- restrict processing in defined circumstances, for example while an accuracy dispute is resolved;
- data portability — to receive data you provided to us, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, on grounds relating to your particular situation; and to object at any time, absolutely, to direct marketing;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with your supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk); in the EEA it is the authority in your country of residence, place of work, or place of the alleged infringement; in Switzerland it is the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.
Representatives. Where Article 27 requires it, our EU representative is [[EU_REP]] and our UK representative is [[UK_REP]]. You may contact them on any matter relating to our processing of your personal information.
How to exercise your rights
Email privacy@vavastone.com with the subject line “Privacy Request”, or write to us at the address in section 23. Tell us which right you want to exercise and give us enough information to find your records.
- Verification. To protect you, we must verify your identity before acting. We will normally match the details you give against what we already hold, and may ask for additional information for a high-risk request. We will not use verification data for any other purpose.
- Timing. We acknowledge requests promptly and respond within 45 days under US state laws (extendable once by a further 45 days) or within one month under the GDPR (extendable by two further months for complex requests). We will tell you if we need an extension.
- Cost. Requests are free. We may charge a reasonable fee, or decline, where a request is manifestly unfounded, excessive or repetitive — and we will explain why.
- Limits. We may decline part of a request where the law requires or permits us to retain data, where it would adversely affect the rights of another person, or where an exemption applies. We will tell you which exemption we relied on.
When a VavaStone customer holds your data
If you are an employee, buyer, fabricator, supplier or contact of a business that uses VavaStone, and your details are in that business’s account, that business is the controller of your information and we are only its processor. We process it on their documented instructions and have no authority to grant access, correction, deletion or objection requests on our own initiative.
Please direct your request to that business. If you contact us instead, we will tell you so, and — where we can identify the relevant customer — we will pass your request to them and support them in responding, as our contract requires. This policy does not describe that business’s own privacy practices; ask them for their privacy notice.
Children
The Service is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children, and we do not direct the Service to them. If you believe a child has provided us with personal information, contact privacy@vavastone.com and we will delete it.
Third-party sites and integrations
Our website and application link to and integrate with third-party services. Those services have their own privacy policies, and their handling of your information is outside our control and not covered by this policy. Review their policies before you use them. Enabling an integration is your instruction to exchange the relevant data with that provider.
Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Where we use scoring or ranking to prioritise our own sales and support activity, a person remains responsible for any decision that affects you, and you may ask for human review by writing to privacy@vavastone.com.
Changes to this policy
We may update this policy to reflect changes in our practices, our vendors, or the law. We will post the updated version here with a new effective date. Where a change is material, we will give reasonable advance notice by email or an in-product notice, and where the law requires consent for a change, we will obtain it. Previous versions are available on request.
How to contact us
Privacy questions and rights requests: privacy@vavastone.com
Legal notices: legal@vavastone.com
Security reports: security@vavastone.com
General: sales@vavastone.com · +1 (858) 255-4146
[[ENTITY]] — Attn: Privacy
[[ADDRESS]]
San Diego, California, United States
See also the Legal overview, Terms of Use and Cookie Policy.