Vane Protocol
Privacy Policy
Draft pending legal review
Last updated: 22 August 2026
Who is responsible for your information
NZBN 9429052126352, trading as Vane Protocol, collects and handles personal information for Vane Protocol. The service address is PO Box 705, Cambridge 3450, New Zealand. Contact Vane Protocol at team@vaneprotocol.madethis.app.
Information collected
When you request the free Operational Risk Signal Check diagnostic, the site collects your first name, work email address, delivery-consent choice, optional marketing-consent choice, the exact consent wording shown, form version, server timestamp and IP address when it is available from the request. When an IP address is not available, the consent record records that as unavailable rather than creating one.
The site and its technical providers may also process technical information needed to operate and secure the service, such as browser and device information, request logs, pages requested, and authentication or session information for account and administrator access. When you choose analytics, PostHog may process browsing and interaction information as described in the Cookies and Analytics Notice.
Voluntary choices and use of information
Providing information is voluntary. Delivery consent is required only to send the requested Operational Risk Signal Check diagnostic. If you decline it, the form will not submit and Vane Protocol cannot send that diagnostic. Marketing consent is optional. If you leave it unticked, you can still receive the diagnostic and will not be enrolled for ongoing Vane Protocol operational-risk updates.
Vane Protocol uses information to provide the requested diagnostic, retain consent evidence, respond to privacy requests, operate accounts and downloads, maintain security, diagnose faults, and understand optional analytics where you consent. Ongoing marketing is currently disabled in this storefront.
Marketing withdrawal and suppression
If Vane Protocol operational-risk updates are enabled in the future, a marketing email will use a hosted one-click unsubscribe link. The link records a permanent suppression entry for that recipient and confirms the opt-out. Suppression entries are checked before a future marketing send. The current supported notification proxy does not provide custom outbound email headers, so this site does not claim List-Unsubscribe or List-Unsubscribe-Post header support.
Analytics are optional and do not load unless you allow them. You can change that decision at any time in the Cookies and Analytics Notice.
Service providers and overseas processing
The named services verified in the storefront code and deployment configuration are MadeThis, which provides the storefront platform, hosted file links, hosted checkout links and supported notification proxy; Vercel, which hosts the Next.js storefront and server route; Convex, which provides the configured application data and authentication backend; and PostHog, which is configured for optional storefront analytics only after consent. These providers may process information outside New Zealand or Australia. The wording and legal basis for overseas processing are Draft pending legal review.
No Google Analytics, Meta Pixel, direct Stripe browser SDK, or third-party email service SDK is included in this storefront code.
Retention
Draft pending legal review. Diagnostic delivery and contact data: 24 months after the request. Optional marketing-consent evidence: 24 months after the most recent recorded consent or withdrawal. Marketing suppression records: retained permanently unless Vane Protocol determines a lawful and documented reason to remove them. Transaction and order records: 7 years after the transaction. Analytics and technical logs: up to 14 months, subject to the configured provider retention settings. These are draft operational retention periods and are not a legal retention determination.
Access and correction
To request access to or correction of personal information, contact Vane Protocol at team@vaneprotocol.madethis.app.