Skip to content

Legal · Privacy

Privacy Policy

This policy explains what personal information VavaStone collects, why we collect it, who we share it with, how long we keep it, and the rights you have — under California law, the other US state privacy laws, and the EU and UK GDPR.

Effective 6 September 2026 Version 1.0 Applies to vavastone.com & portal.vavastone.com

Who we are and what this covers

[[ENTITY]] (“VavaStone”, “we”, “us”) provides slab inventory, sales and delivery software to natural stone distributors. We are based in San Diego, California, and are part of the SDSharp group.

This policy applies to personal information we handle through:

It does not apply to third-party websites we link to, or to how a VavaStone customer independently handles data in its own business — see section 18.

Our two roles: controller and processor

We handle personal information in two distinct capacities, and your rights differ depending on which applies.

RoleWhen it appliesWhat it means for you
Controller
(“business” under CCPA)
Website visitors, prospects, demo requests, event attendees, account administrators, billing contacts, support requesters, job applicants. We decide why and how the data is used. Exercise your rights directly with us under sections 15–17.
Processor
(“service provider” under CCPA)
Personal information inside a customer’s account — their staff records, their buyers, fabricators, contacts, delivery addresses, quotes and orders. Our customer decides why and how that data is used. We act only on their instructions. Direct your request to them; see section 18.

Summary

This summary is for orientation only. The sections below are the operative terms.

Information we collect

The table uses the categories defined by the California Consumer Privacy Act, as amended (“CCPA”), so you can map it to your statutory rights.

CategoryExamplesSourceDisclosed to
Identifiers Name, business email, business postal address, telephone number, company name, job title, account username, IP address, device and cookie identifiers. You; automatic collection. Hosting, email, analytics, chat, scheduling and CRM providers.
Customer records
(Cal. Civ. Code §1798.80)
Billing contact details, purchase and payment records, signature on an order form, credit-check outputs where we run one. You; payment processor; credit reference agency. Payment processor, accountants, auditors.
Commercial information Plan and subscription details, seat and yard counts, invoices, renewal and cancellation history, products and services considered or purchased, support tickets. You; automatic collection. Payment processor, support and CRM providers.
Internet or network activity Pages viewed, referring URL, session duration, clicks and feature interactions, error and performance logs, browser type and version, operating system, screen and viewport size, language, approximate connection quality. Automatic collection. Analytics and hosting providers.
Geolocation data Approximate city, region and country inferred from IP address. We do not collect precise GPS location from the website. Delivery and pickup addresses you enter in the application are Customer Data (section 18). Automatic collection; you. Analytics and hosting providers.
Professional or employment information Employer, role, yard or branch, purchasing authority, industry segment, information in a job application. You; publicly available business sources. CRM and recruiting providers.
Audio, visual and similar Photographs and imagery uploaded to the platform, product and yard photography, recordings of a demo or support call where we tell you in advance and, where required, obtain consent. You. Hosting and conferencing providers.
Communications Contents of emails, contact-form submissions, live chat transcripts, meeting-booking notes and support correspondence. You. Email, chat, scheduling and support providers.
Inferences Derived indicators such as likely fit for a plan, engagement level, or feature interest, used for our own sales and product decisions. Derived by us. CRM provider.

We do not knowingly collect government identifiers, financial account numbers, precise geolocation, biometric data, health data, or data revealing racial or ethnic origin, religious belief, union membership, sex life or sexual orientation. Card details are entered directly with our payment processor; we never receive or store full card numbers.

How we collect it

5.1 Directly from you

When you fill in the contact form, book a demo, start a trial, create an account, subscribe, contact support, open a live chat, subscribe to updates, attend an event, or apply for a job.

5.2 Automatically

Through cookies, local storage, server logs, SDKs and similar technologies when you visit our website or use the application. See the Cookie Policy.

5.3 From third parties

From our customers (when they invite you into their account), from publicly available business sources and industry directories, from event and webinar co-hosts, from partners and resellers, from our payment processor, and from service providers that help us keep business contact records accurate. Where a third party gives us your information, we rely on their confirmation that they are permitted to do so.

Why we use it, and our legal bases

The “legal basis” column applies where the EU or UK GDPR governs the processing. Where it does not, the “purpose” column is the operative description.

PurposeCategories usedLegal basis (GDPR / UK GDPR)
Provide, host, maintain and support the Service; authenticate users; process transactions you initiateIdentifiers, commercial, internet activity, communicationsPerformance of a contract; legitimate interests in operating our business
Bill you, collect payment, keep accounting and tax recordsIdentifiers, customer records, commercialPerformance of a contract; legal obligation
Respond to enquiries, demo requests, chat and support ticketsIdentifiers, communications, professionalPerformance of a contract; legitimate interests in responding to enquiries
Secure the Service, detect and prevent fraud, abuse and unauthorised access, keep audit logsIdentifiers, internet activity, geolocationLegitimate interests in protecting our business and users; legal obligation
Understand how the Service is used, fix defects, measure performance, improve and develop featuresInternet activity, identifiers, inferencesLegitimate interests in improving our products; consent where cookies require it
Send service and administrative messages (outages, security notices, billing, changes to terms)Identifiers, commercialPerformance of a contract; legal obligation
Send marketing about our products to business contacts, and measure whether it was opened or clickedIdentifiers, professional, inferencesConsent where required; otherwise legitimate interests in direct marketing to business contacts, subject to an opt-out in every message
Produce aggregated and de-identified statistics, benchmarks and industry insightInternet activity, commercial (de-identified)Legitimate interests in understanding and improving our market and product
Establish, exercise or defend legal claims; enforce our terms; comply with law and lawful requestsAll categories as relevantLegal obligation; legitimate interests in protecting our legal rights
Corporate transactions — financing, audit, reorganisation, merger or sale of the businessIdentifiers, commercial, customer recordsLegitimate interests in operating and developing our business
RecruitmentIdentifiers, professional, communicationsSteps prior to entering a contract; legitimate interests in assessing applicants

Where we rely on legitimate interests, we have assessed those interests against your rights and freedoms. You may object at any time — see section 16. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

Cookies and similar technologies

We use cookies, local storage and similar technologies for essential site function, for security, for remembering preferences, and to understand how the site and application are used. Full detail, including the categories in use and how to change your choices, is in our Cookie Policy. We do not use advertising or retargeting cookies.

Who we share it with

8.1 Service providers and processors

We share personal information with vendors that process it on our behalf and under contract, limited to what they need to perform their function, and prohibited from using it for their own purposes. Our principal vendors are:

VendorFunctionData involvedPrimary location
FramerWebsite publishing, hosting and delivery, basic site analyticsIdentifiers, internet activityUnited States / EEA
PostHogProduct and website analyticsIdentifiers, internet activity, inferencesUnited States / EEA
CrispLive chat and support messagingIdentifiers, communicationsEuropean Union
CalendlyDemo and meeting schedulingIdentifiers, communicationsUnited States
Web3FormsContact-form deliveryIdentifiers, communicationsUnited States
Application hosting and storage providersRunning portal.vavastone.com, storing Customer Data and backupsAll categories as applicableUnited States
Payment processorSubscription billing and payment collectionIdentifiers, customer records, commercialUnited States
Email, CRM and productivity providersBusiness correspondence, sales records, document handlingIdentifiers, communications, professional, commercialUnited States

A current list of subprocessors used to deliver the application is available to customers on request from privacy@vavastone.com. We may add or change vendors as our stack evolves; where we act as processor, we will notify affected customers as required by our Data Processing Addendum.

8.2 Our group and affiliates

We may share personal information within the SDSharp group where it is necessary for shared administration, finance, security, legal or product functions, subject to the purposes in section 6.

8.3 Professional advisers

Lawyers, accountants, auditors, insurers and consultants, under duties of confidentiality, where necessary for our legitimate business or legal purposes.

8.4 Corporate transactions

If VavaStone is involved in a merger, acquisition, investment, financing, reorganisation, insolvency, or a sale or transfer of all or part of its business or assets, personal information may be disclosed to counterparties, prospective counterparties and their advisers as part of due diligence, and may be transferred as part of that transaction. We will require any recipient to honour this policy for the information transferred, or to give notice before materially changing how it is used.

8.5 Legal and safety

We may disclose personal information where we believe in good faith it is necessary to: comply with law, a subpoena, warrant, court order or regulator; respond to a lawful request from a public authority; establish, exercise or defend legal claims; enforce our terms; investigate suspected fraud, security incidents or violations; or protect the rights, property or safety of VavaStone, our users or the public. Where we are legally permitted, and where the request concerns Customer Data, we will notify the affected customer before disclosure so that they can seek protective relief.

8.6 With your direction

Where you ask us to, for example by enabling an integration, publishing a storefront, or inviting a buyer into an account.

Sale and sharing of personal information

We do not sell personal information for monetary consideration, and we have not done so in the preceding twelve months. We do not disclose personal information for cross-context behavioural advertising, and we do not sell or share the personal information of anyone we know to be under 16.

Some US state privacy laws define “sale” and “share” broadly enough that certain analytics configurations can fall within them. Our position is that our use of analytics is a service-provider arrangement and not a sale or share. Even so, we honour opt-out signals: we recognise the Global Privacy Control (GPC) browser signal as a valid opt-out request for the browser that sends it, and you can additionally exercise the choices described in our Cookie Policy.

Sensitive personal information

We do not collect or process sensitive personal information as defined by the CCPA, and we do not process special-category data under Article 9 of the GDPR, for the purpose of inferring characteristics about you. Accordingly, the CCPA right to limit the use of sensitive personal information does not arise in practice. If this changes, we will update this policy and provide the required “Limit the Use of My Sensitive Personal Information” mechanism.

Artificial intelligence and analytics

We analyse how the Service is used in order to operate, secure and improve it, and we may use statistical, machine learning and artificial intelligence techniques to do so. Where we do:

Our contractual rights over aggregated and de-identified data are set out in section 8 of the Terms of Use.

How long we keep it

We keep personal information only as long as we need it for the purpose it was collected for, plus any period required for legal, accounting, tax, audit, security or dispute-resolution purposes. Our working schedule:

DataRetention
Account and subscription recordsFor the life of the account, then 7 years from the end of the relationship (contract limitation and tax)
Billing, invoicing and tax records7 years from the end of the relevant tax year
Customer Data in the applicationFor the subscription term, then deleted after the 30-day export window described in the Terms of Use, subject to backup expiry
Backups and disaster-recovery copiesUp to 90 days on a rolling cycle, then overwritten
Support tickets and chat transcripts24 months from last contact
Contact-form and demo-request submissions24 months from submission, unless a relationship begins
Marketing contacts and preferencesUntil you unsubscribe, plus a suppression record kept indefinitely so that we can honour the opt-out
Security, access and audit logs12 months, longer where an investigation requires it
Analytics dataUp to 24 months, in de-identified or aggregated form thereafter
Job applications12 months from decision, unless you ask us to keep them longer
Records relating to an actual or threatened legal claimUntil the claim and any appeal period are finally resolved

Aggregated and de-identified data, which is no longer personal information, may be retained indefinitely.

How we protect it

We maintain administrative, technical and physical safeguards appropriate to the nature of the data and the risk, including encryption of data in transit, encryption at rest for stored data, role-based access control, least-privilege access for our personnel, multi-factor authentication on administrative systems, logging and monitoring, vendor due diligence, secure development practice, and staff confidentiality obligations and training.

No method of transmission or storage is perfectly secure. We cannot and do not guarantee absolute security, and any transmission is at your own risk. Your own conduct matters too: keep credentials confidential, enable available security features, and use up-to-date devices. Report a suspected incident to security@vavastone.com. Where the law requires it, we will notify affected individuals and regulators of a personal data breach within the applicable deadlines.

International transfers

We are based in the United States, and our vendors are located in the United States and the European Union. If you are in the EEA, the United Kingdom or Switzerland, your personal information will be transferred to and processed in the United States, which has not received an adequacy decision of general application.

Where we transfer personal information out of the EEA, the UK or Switzerland, we rely on one or more of the following safeguards:

We carry out transfer impact assessments where required, and apply supplementary technical and organisational measures where our assessment indicates they are needed. You may request a copy of the relevant safeguard, with commercially confidential terms redacted, from privacy@vavastone.com.

Your US state privacy rights

Depending on your state of residence, you may have some or all of the following rights in respect of the personal information for which we are the controller or business:

Authorised agents. You may use an authorised agent. We will require written proof of authorisation signed by you and may require you to verify your identity with us directly.

Shine the Light. California Civil Code §1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

Your EEA, UK and Swiss rights

If the EU GDPR, UK GDPR or Swiss FADP applies to you, you have the right to:

Representatives. Where Article 27 requires it, our EU representative is [[EU_REP]] and our UK representative is [[UK_REP]]. You may contact them on any matter relating to our processing of your personal information.

How to exercise your rights

Email privacy@vavastone.com with the subject line “Privacy Request”, or write to us at the address in section 23. Tell us which right you want to exercise and give us enough information to find your records.

When a VavaStone customer holds your data

If you are an employee, buyer, fabricator, supplier or contact of a business that uses VavaStone, and your details are in that business’s account, that business is the controller of your information and we are only its processor. We process it on their documented instructions and have no authority to grant access, correction, deletion or objection requests on our own initiative.

Please direct your request to that business. If you contact us instead, we will tell you so, and — where we can identify the relevant customer — we will pass your request to them and support them in responding, as our contract requires. This policy does not describe that business’s own privacy practices; ask them for their privacy notice.

Children

The Service is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children, and we do not direct the Service to them. If you believe a child has provided us with personal information, contact privacy@vavastone.com and we will delete it.

Third-party sites and integrations

Our website and application link to and integrate with third-party services. Those services have their own privacy policies, and their handling of your information is outside our control and not covered by this policy. Review their policies before you use them. Enabling an integration is your instruction to exchange the relevant data with that provider.

Automated decision-making

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Where we use scoring or ranking to prioritise our own sales and support activity, a person remains responsible for any decision that affects you, and you may ask for human review by writing to privacy@vavastone.com.

Changes to this policy

We may update this policy to reflect changes in our practices, our vendors, or the law. We will post the updated version here with a new effective date. Where a change is material, we will give reasonable advance notice by email or an in-product notice, and where the law requires consent for a change, we will obtain it. Previous versions are available on request.

How to contact us

Privacy questions and rights requests: privacy@vavastone.com
Legal notices: legal@vavastone.com
Security reports: security@vavastone.com
General: sales@vavastone.com · +1 (858) 255-4146

[[ENTITY]] — Attn: Privacy
[[ADDRESS]]
San Diego, California, United States

See also the Legal overview, Terms of Use and Cookie Policy.