Skip to content

Privacy Policy

How we collect, use, share and protect personal data, and the rights you have under the GDPR.

Version
1.0
Effective
10 August 2026
Last updated
10 August 2026
Applies to
digital-vault.store and all DigitalVault marketplace accounts

Abdulfattah Kabayare trading as DigitalVault · San Albert, Gzira, Malta · VAT 3287-2911

1. Controller and contact

The controller of personal data processed through DigitalVault is:

Operator (legal name): Abdulfattah Kabayare

Trading name: DigitalVault

Business type: Self-employed / sole trader

Business address: San Albert, Gzira, Malta

VAT number: 3287-2911

Contact email: digitalvault.businesse@gmail.com

Website: https://digital-vault.store

No data protection officer has been appointed. Data-protection questions and requests should be sent to the contact address above.

2. Account registration and authentication

Data: email address, password credentials handled by our authentication provider, account identifier, sign-in timestamps, and any name or profile details you add.

Purpose: creating and securing your account and signing you in. Legal basis: performance of a contract, and our legitimate interest in account security.

Recipients: our hosting and backend infrastructure provider (Supabase infrastructure used by the Lovable Cloud platform). Retention: for the life of the account, then deleted or anonymised except where records must be kept by law.

3. Buyer profiles, carts and library

Data: profile details, cart contents, purchased items, entitlements and download activity.

Purpose: operating the marketplace, giving you access to what you bought, and preventing abuse of download links. Legal basis: contract, and legitimate interest in preventing misuse.

Retention: entitlements and order-linked records are kept while your account exists and for as long as required for accounting and legal purposes.

4. Seller profiles and verification

Data: store details, contact information, country, seller type, payout-account status flags, and identity/business information collected by the payment provider during onboarding.

Purpose: operating your store, verifying sellers, paying out, preventing fraud, and meeting legal obligations. Legal basis: contract, legal obligation, and legitimate interest in fraud prevention.

Identity documents submitted during payment onboarding are collected and held by the payment provider; we receive verification status rather than the underlying documents.

5. Orders, payments and payment metadata

Data: order records, amounts, currency, item details, order status, billing email, payment session and payment intent identifiers, refund records.

Purpose: completing purchases, delivering files, refunds, dispute handling, accounting and tax records. Legal basis: contract and legal obligation.

Payments are facilitated through third-party payment service providers, currently Stripe. DigitalVault does not receive or store complete payment-card details. Stripe acts as an independent controller for its own payment, fraud-prevention and regulatory purposes.

Retention: financial and tax records are retained for the statutory retention period applicable in Malta.

6. Reviews, support and communications

Data: review content and rating, support and contact-form messages, notification records and transactional emails.

Purpose: publishing verified reviews, answering you, and sending service messages about your account, orders and listings. Legal basis: contract and legitimate interest; consent where a message is purely optional marketing.

7. Moderation, security and fraud logs

Data: listing moderation events and reasons, reports submitted about content, security and access logs, technical data such as IP address, user agent and timestamps.

Purpose: reviewing listings, handling notices, protecting the marketplace and its users, and meeting platform obligations. Legal basis: legal obligation and legitimate interest in platform safety.

8. Analytics

We record aggregate product-view counts for sellers. Repeat views within the same browsing session are de-duplicated using a value stored in your browser's session storage; this does not build a cross-site profile of you.

No third-party analytics or advertising tracking product is currently integrated in the application code. If one is added, this policy and our consent controls will be updated before it is enabled.

9. Processors and service providers

Categories of recipients: cloud hosting and database infrastructure, authentication, file storage and delivery, transactional email, and payment services.

We use these providers to run the service; they act on our instructions as processors except where they act as independent controllers (notably the payment provider for its regulated activities).

We maintain an internal register of the providers we use and the data-processing terms in place with them. You can request the categories of recipients relevant to your data by writing to digitalvault.businesse@gmail.com.

10. International transfers

Some of our providers may process data outside the EU/EEA. Where that happens, transfers rely on an adequacy decision or on Standard Contractual Clauses with supplementary measures where required.

We do not claim that all data is stored exclusively in the EU/EEA. If you would like to know the transfer mechanism relied on for a specific provider, write to digitalvault.businesse@gmail.com.

11. Whether you must provide data

Account and order data is necessary to enter into and perform the contract; without it we cannot create an account, complete a purchase or deliver files. Seller verification data is required by law and by the payment provider; without it we cannot pay you out.

12. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Our payment provider applies automated fraud screening to transactions as part of its own service; its outcomes may result in a payment being declined.

13. Your rights

You have the right to access your data; to rectification; to erasure; to restriction of processing; to data portability where processing is based on consent or contract and carried out by automated means; and to object to processing based on legitimate interests.

Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise a right, write to digitalvault.businesse@gmail.com. You also have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta, or with the supervisory authority of your habitual residence or place of work.

14. Security

We use access controls, row-level database security, private storage buckets with time-limited signed links, encrypted transport, and least-privilege server-side access to protect personal data. No system can be guaranteed completely secure.

15. Children

The service is not intended for anyone under 18. We do not knowingly collect data from children; if we learn that we have, we will delete it.

16. Changes

We will update this notice as the service changes and will indicate the date of the latest version.

Last updated: 10 August 2026.

Other policies

Back to Legal & Trust Center