Privacy Policy
Last updated September 30, 2026
This document is a draft and has not been reviewed by an attorney.
It is written to describe accurately how Vestly works, and it is not legal advice. Sections requiring a lawyer’s judgement are marked as such rather than filled in with template language. If you are relying on this document for anything that matters, write to us at contact@usevestly.com.
This policy is written from the actual database, table by table, rather than from a template. Where Vestly deliberately avoids storing something, that is stated too, because it is the more useful half of the answer.
Who this is about
Two kinds of people use Vestly. An owner registers a business and sets up bonuses. An employee is enrolled by an owner and sees their own balance. Both are covered here, and there is a section below on what an owner can and cannot see about an employee.
What we collect
About the business and its owner:
- Business name, and the trial or subscription status of the account.
- The owner’s name and email address.
- A Stripe customer identifier and subscription identifier — references, not payment details.
About each enrolled employee:
- Name, email address, and role (owner or employee).
- When they were invited, when they first signed in, and whether they were invited by email or given a code.
- Their enrollment: start date, status, and the bonus terms agreed — amount, length, cadence, waiting period, and the forfeiture terms the owner wrote.
- The vesting schedule: every scheduled date, its amount, and whether it has vested, been paid, or been forfeited.
- If employment ends: the last day, what had vested, and what was forfeited.
- If terms are corrected: the previous terms, the new terms, who made the change, and the reason they gave.
Documents and confirmations:
- The generated agreement and explainer, held as files in private storage, with a checksum and byte size so tampering is detectable.
- Whether an employee confirmed reading their agreement, when, and which account did it. That timestamp comes from the database clock and the identity from the signed-in session, so it cannot be backdated or submitted on somebody else’s behalf.
Operational records:
- A log of product emails we sent: recipient, kind, subject, and whether it succeeded. Signup, invite and password-reset emails are not in this log, because they are sent by our authentication provider and never pass through our code.
- An audit log of significant actions: who did what, to which record, and what changed.
- Access codes for employees who do not use email — stored only as a hash plus the first two characters, never the code itself.
- Identifiers of the billing events we have processed, so a repeated delivery cannot be applied twice.
What we deliberately do not store
- Card numbers or bank details. Payment happens on Stripe’s own pages. Card details never reach Vestly, which is why Checkout is used instead of our own payment form.
- Plaintext access codes. Only a hash is kept. The code exists in readable form once, on the screen where it is generated, and the page says so.
- Anything you type into the plan advisor. We record a one-way hash of the input and the number of tokens used, so cost can be reviewed. The figures themselves are not retained.
- Social security or national ID numbers. Vestly has no field for them. Do not put one in a free-text box.
- Analytics, advertising, or tracking. There is no analytics script, no advertising pixel, and no third-party tracker on any page. The only cookies are the ones that keep you signed in.
Who else sees it
Vestly is built on services that necessarily process some of this data. None of them receive it to use for their own purposes.
- Supabase — hosts the database, file storage and authentication, and sends signup, invite and password-reset email.
- Stripe — payments. Receives your business name, email and card details, which it collects directly.
- Resend — delivers product email, such as a notification that an amount has vested. Receives recipient addresses and message contents.
- Anthropic — powers the optional plan advisor. Receives only the numbers you enter for a suggestion: headcount, average wage, turnover rate and industry. No names, no email addresses, and no employee records are sent.
- Vercel — hosts the application and processes requests to it.
We do not sell your data, and we do not share it with anyone else except where the law requires it, or to establish or defend a legal claim.
What your employer can see
If you are an employee, this is the honest answer.
- They can see your name, your email address, your bonus terms, your balance, your full vesting history, and whether you have confirmed reading your agreement.
- They cannot see your password and cannot sign in as you. Your login is yours.
- They can end your enrollment, which records what you kept and what was forfeited. They cannot quietly change past terms: a correction keeps the original alongside the new one and requires a written reason.
Your employer is responsible for the bonus itself and for the terms they set. If you disagree with something recorded about you, raise it with them first — they are the only one who can change it.
How it is protected
- Every table enforces tenant isolation in the database itself, not only in application code, so one business cannot read another’s rows even if the application had a bug.
- Documents live in a private bucket with no public access. Reading one requires proving entitlement first, after which a link valid for sixty seconds is issued.
- Access codes and passwords are stored only as hashes.
- Traffic is encrypted in transit, and the application sends a strict content security policy.
No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, please tell us at contact@usevestly.com before disclosing it publicly.
Your choices
- Ask for a copy of what we hold about you.
- Ask us to correct something inaccurate.
- Ask us to delete your account. If you are an employee, note that your enrollment record is also your employer’s business record, so we will need to involve them.
- Product notifications can be turned off; email needed to run your account, such as a password reset, cannot.
Gap: retention periods and regional rights
No retention or deletion window is promised here, because nothing in the code enforces one and a policy that states a period it does not keep is worse than one that stays silent. Records are kept while an account is active and until deletion is requested. Specific rights under GDPR, the CCPA or other regimes are not enumerated, and no compliance with any of them is claimed. Both need an attorney, and the retention piece needs a product decision first.
Children
Vestly is for businesses and is not intended for anyone under 16. We do not knowingly collect information about children.
Changes
If we change what we collect or who it reaches, we will update this page and the date at the top, and notify account owners by email when the change is material.
Contact
Vestly is operated by Keith Lowery. Write to contact@usevestly.com. See also the terms of service.