1. In short
Vintaflip is a tool for people who buy and resell vintage items: you record the pieces you buy, your sales and your expenses, and the app works out your margins and statistics. To do that, we process some personal data.
In short: we don't sell your data, we don't use profiling cookies, and we have no analytics or ad-tracking system whatsoever. Your data lives on our servers, and you can delete your account and everything in it at any time from the app.
2. Data we collect
Account data, which you give us when you sign up or which we receive from the provider you log in with:
- Email address (required: it's your login identifier).
- Password, stored solely as an Argon2 hash: it can't be reversed and we can't read it.
- Display name and profile picture, if you set them or if they reach us from Google/Apple.
- Google or Apple identifier, if you log in with those providers, so we can recognise you on later logins.
- Default currency, language and your preference on receiving the monthly report.
- If you turn on two-factor authentication: the TOTP secret, encrypted with AES-256-GCM, and the recovery codes, stored only as SHA-256 hashes.
- Subscription data: active plan, status, renewal date and the customer and subscription identifiers assigned by Stripe.
- Your referral code, the user who invited you (if any) and the credit you've built up.
3. Content you enter yourself
The heart of the app is the data you upload: products (title, description, category, purchase and sales channel, purchase price and asking price, currency, date, notes), sales (price, fees, shipping, date, notes), expenses, custom categories and channels, and the photographs of your items.
This content is yours. We process it only to provide you with the service: we don't use it to profile you, we don't pass it on to third parties, and we don't use it to train artificial intelligence models.
4. Data we don't collect
By design, we don't keep your IP address, your phone number or your home address: there are no columns for that data in our database.
We don't use Google Analytics, or any other analytics tool, advertising pixel or behavioural tracking system. We don't profile users and we don't make automated decisions that produce legal effects concerning you.
5. Why we process your data and on what legal basis
- To provide you with the service and manage your account and your content: performance of the contract (Art. 6(1)(b) GDPR).
- To manage subscriptions, payments and tax obligations: performance of the contract and legal obligation (Art. 6(1)(b) and 6(1)(c) GDPR).
- To send you service emails (registration confirmation, password reset, subscription notices): performance of the contract.
- To send you the monthly report by email and push notifications: consent, which you can withdraw at any time from your settings (Art. 6(1)(a) GDPR).
- To keep the platform secure and prevent abuse: legitimate interest (Art. 6(1)(f) GDPR).
- To run the referral programme: performance of the contract.
6. Photo recognition using artificial intelligence
This is the point we'd ask you to read most carefully.
If you use the automatic item recognition feature, the photograph you upload is sent to the Anthropic API (Claude models) to get a suggestion for the title, category and estimated value. The photo therefore leaves our servers and is processed by Anthropic acting as a data processor.
We send the image alone: no identifier for your account, no email address, no data from your inventory travels with the photo. Under the terms of its commercial API, Anthropic does not use the content sent to it to train its models.
If you'd rather a photo weren't sent to an external provider, don't use automatic recognition on that item and fill in the fields by hand: the feature is optional and the rest of the app works without it.
7. Price search
The price search feature queries external sources, such as eBay's public APIs and the public pages of listings that have already sold, to show you what similar items sell for.
All we send to those sources is the search text. We don't send your identity, your email address or any data from your inventory. The same applies to barcode scanning, which queries the public Open Food Facts and Google Books databases sending only the code.
8. Photographs and CDN
The images you upload are processed on our servers: we convert them to WebP format, generate the variants for different screen sizes, and strip the EXIF metadata, including any GPS coordinates embedded by your phone.
The images are then served by our CDN, at cdn.vintaflip.com. One technical point is worth stressing: image URLs are public and not protected by authentication. Anyone who knows the exact URL of one of your images can view it. The URLs contain a random identifier that can't be guessed, and they aren't indexed by search engines, but don't upload documents or information you want to keep confidential in your product photos.
9. Payments
Payments made via the web are handled by Stripe. We send Stripe your email address, your display name and an internal identifier for your account. Your card details go straight to Stripe and never pass through or get stored on our systems: all we keep are the identifiers Stripe returns to us and the status of your subscription.
If you subscribe from the iOS or Android apps, payment is handled by Apple (App Store) and Google (Play Store) respectively, under their privacy policies. In those cases we keep the purchase receipt returned by the relevant store, which we need in order to check that the subscription is active.
10. Referral programme
If you invite other people to Vintaflip, we record the link between your account and the account of whoever signs up with your code, along with the date and any credit earned.
Please note, in your interest and in the interest of the people you invite: the referral page shows the inviter the email addresses of the people who signed up with their code. If you sign up through an invitation, the person who invited you will see your email address.
11. External providers
We use the following providers, which act as data processors and process the data only in order to provide us with the service indicated:
- Stripe — payments and subscriptions via the web (Ireland, with processing in the United States).
- Anthropic — recognition of product photographs (United States).
- Resend — sending service emails and the monthly report (United States).
- Google — Google sign-in, push notifications via Firebase Cloud Messaging, verification of Play Store purchases (United States).
- Apple — Apple sign-in and verification of App Store purchases (United States).
- eBay — public APIs for price search; receives only the search text (United States).
- The provider hosting our servers, where the database and the images reside (European Union).
12. Transfers outside the European Union
The database and the photographs reside on servers located in the European Union.
Some of the providers listed above are based in, or carry out processing in, the United States. Those transfers take place on the basis of the Standard Contractual Clauses adopted by the European Commission and, where applicable, the provider's participation in the EU-U.S. Data Privacy Framework.
13. How long we keep your data
We keep your account data and your content for as long as the account stays active.
When you request account deletion, the account is closed and made inaccessible right away, while the associated data is kept for 90 days. Within that window you can email us to cancel the deletion and reactivate the account. After 90 days the data is permanently erased from our database: the operation can no longer be undone and we don't keep copies of your products, sales and expenses.
The exception is data we're required to keep by law, in particular the accounting and tax records relating to subscriptions taken out, which must be kept for ten years under Art. 2220 of the Italian Civil Code. Those stay with Stripe and in our accounts, separately from the app.
Database backups are taken daily and kept for thirty days: once your data is erased at the end of the 90-day window, it also disappears from any backup copy within the following rotation cycle.
14. How to delete your account
You can delete your account yourself, without writing to us: from the app, in the Account section. If you log in with email and password you'll be asked for your password; if you log in with Google or Apple you'll be asked to type a confirmation word.
Deletion automatically cancels any active subscription and erases your products, sales, expenses, categories, channels, notifications and referral data.
15. Security
Traffic is encrypted in transit with TLS. Passwords are protected with Argon2, the recommended state-of-the-art algorithm. The two-step verification secret is encrypted at rest with AES-256-GCM and the recovery codes are stored only as hashes. The database can't be reached from outside: it's accessible only to our application services.
No system is invulnerable, though. If we were to suffer a data breach involving a high risk to your rights, we'd inform you without undue delay and notify the Garante as required by Arts. 33 and 34 GDPR.
16. Cookies and local storage
Vintaflip doesn't use cookies. We don't set technical, analytics or profiling cookies, which is why you won't see any consent banner: there's no need for one.
To keep you logged in we use the browser's local storage (localStorage), with the keys vintaflip.token, which holds your session token, vintaflip.user, which holds the basic details of your profile, and vintaflip.lang, which remembers the language you chose. This data stays on your device, isn't sent to any third party, and is cleared when you log out or clear the site's data. The iOS and Android apps use the equivalent system mechanisms.
If you reached this page from the “Cookies” link in the footer: the section you're reading is our complete cookie notice, because there are no cookies to declare.
17. Emails and push notifications
We send you service emails that the account needs in order to work, such as registration confirmation, password reset and subscription notices: you can't turn these off while the account is active, because they're part of the contract.
The monthly report by email and push notifications, on the other hand, are optional and can be turned off in the app's settings. For push notifications we keep the device token provided by Firebase Cloud Messaging and the device name.
18. Your rights
As a data subject you have the right to:
- access your data and obtain a copy of it (Art. 15 GDPR);
- rectify inaccurate data (Art. 16 GDPR);
- obtain erasure of your data (Art. 17 GDPR), which you can do directly from the app;
- restrict processing (Art. 18 GDPR);
- receive your data in a structured, machine-readable format (Art. 20 GDPR): write to us and we'll provide it within one month, free of charge;
- object to processing based on legitimate interest (Art. 21 GDPR);
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
19. How to exercise your rights and how to complain
To exercise your rights, write to info@tiber-valley.com. We'll reply within one month of your request, as required by Art. 12 GDPR.
If you believe the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority), Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or with the supervisory authority of the Member State where you live.
20. Minors
Vintaflip isn't aimed at children under 16 and we don't knowingly collect their data. If you become aware that a child under 16 has created an account, write to us: we'll delete it.
21. Changes to this policy
We may update this notice, for example if we introduce new features or change provider. The date at the top of the page always shows the last update.
If the changes are substantial, and in particular if they concern the purposes of processing or the external providers, we'll let you know by email or with a notice in the app before they take effect.