Garage Vault – Privacy Policy

Section 01

Introduction & Scope

This Privacy Policy applies to the website garagevault.cloud and any related content or services operated under the Garage Vault name. It describes what information we collect when you visit, how we use it, who (if anyone) we share it with, and what rights you have over your own data.

The short version: We run an editorial automotive accessories review site with an Amazon affiliate program. We collect basic analytics data to understand how the site is used, email addresses from people who sign up for the newsletter, and we use standard cookies for analytics and affiliate tracking. We don’t sell your data. We don’t run advertising networks. We don’t have a sales team trying to monetize your personal information.

This policy applies to all visitors from all locations. For EU visitors with additional rights under GDPR, see Section 8.

Section 02

Information We Collect

We collect two types of information: what you give us directly, and what gets collected automatically when you use the site.

Information you give us directly:

  • Email address, if you sign up for the Vault Dispatch newsletter
  • Any information you include in a message if you contact us directly via email

Information collected automatically:

  • Pages visited, time on page, and navigation patterns — via Google Analytics 4
  • General geographic location (country/city level — not precise location)
  • Browser type and device type (for understanding how the site renders, not for profiling)
  • Referral source (where you came from before arriving on the site)
  • Clicks on Amazon affiliate links — tracked via Amazon’s own attribution system

What we don’t collect

We do not collect names, phone numbers, mailing addresses, payment information, or any government-issued ID. We have no account system and you cannot create an account on this site.

Section 03

How We Use Your Data

We use information collected on this site for the following purposes and nothing else:

  • Newsletter delivery: If you subscribed to the Vault Dispatch, we use your email address to send it. That’s the only use.
  • Site improvement: Analytics data helps us understand which content is useful, what devices people are reading on, and whether pages are loading correctly.
  • Affiliate tracking: When you click an Amazon link, Amazon’s tracking system records the referral so we can receive a commission on qualifying purchases. We receive aggregated commission reports — not individual purchase data about you.
  • Customer service: If you email us, we use the information in your email to respond to your message.

We do not use your data for behavioral advertising, profiling, or resale. We do not create personal profiles on individual visitors.

Section 04

Cookie Policy & Tracking Technologies

This site uses cookies. Here’s specifically what’s running and why:

  • Google Analytics cookies (_ga, _gid, _gat): These track visit counts, session duration, and page-level metrics. Data is anonymized before storage. You can opt out via Google’s tools or a browser extension.
  • Amazon affiliate cookies (tag, session-id): When you click an Amazon link, Amazon sets cookies to track whether a purchase is made within their attribution window. This is handled entirely by Amazon and subject to Amazon’s privacy policy.
  • Newsletter cookies: If you use a newsletter subscription form, your email service provider (e.g., Mailchimp or ConvertKit) may set functional cookies to manage the subscription process.

We do not use advertising cookies, remarketing cookies, or any third-party tracking outside of what’s listed above. You can manage cookie preferences through your browser settings. Refusing analytics cookies will not affect your ability to use this site.

Cookie Consent

By using this site after seeing our cookie notice, you consent to the use of the cookies described above. You can withdraw consent at any time by clearing cookies and adjusting browser settings.

Section 05

Amazon Associates Disclosure

FTC Required Disclosure

Garage Vault is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.

This means: when you click a link to an Amazon product on this site and make a qualifying purchase, we may earn a small commission at no additional cost to you. The price you pay is the same whether you click through our link or find the product yourself.

How this affects our editorial content: It doesn’t. Our policy is to test products before deciding whether to publish about them, purchase everything at retail price, and remove products from our recommendations if long-term testing shows they no longer earn it. Affiliate commission potential does not influence which products get tested, covered, or recommended. We have removed products from active recommendation pages after testing revealed durability problems — including products that were generating commission.

All affiliate links on this site are disclosed at the page level where they appear. You will see a disclosure notice near the top of any page that contains affiliate links.

Section 06

Third-Party Services & Data Sharing

We use a limited set of third-party services to operate this site. Each has access only to the information necessary to perform their function:

  • Google Analytics (Google LLC): Receives anonymized site usage data. Subject to Google’s Privacy Policy. IP anonymization is enabled.
  • Email service provider (Mailchimp or ConvertKit): Stores email addresses of newsletter subscribers and manages the sending of the Vault Dispatch. Your email address is stored on their servers and subject to their privacy policies.
  • Amazon.com: Receives referral click data when you follow an affiliate link. Manages their own tracking under their privacy policy.
  • Web hosting provider: Has access to server logs which include IP addresses and basic request data. These are standard server logs, not profiling data.

We do not sell, rent, or trade your personal information to any party under any circumstances. We do not share data with advertisers, data brokers, or marketing companies.

Section 07

Data Security Practices

We take reasonable steps to protect the information we store — though no internet-based service can guarantee absolute security, and we want to be honest about that rather than making claims that aren’t realistic.

What we do:

  • HTTPS encryption on all pages of this site
  • Access to newsletter subscriber data is restricted to site administrators only
  • We do not store payment information — no transactions happen on this site directly
  • Email addresses are stored with our email service provider’s security infrastructure, not in a custom database we maintain

If we ever become aware of a data breach affecting subscriber email addresses or any other personal information we hold, we will notify affected users within a reasonable timeframe and take steps to mitigate the impact.

Section 08

GDPR Compliance — EU Visitors

If you are visiting from the European Union or European Economic Area, the General Data Protection Regulation (GDPR) gives you specific rights regarding your personal data. Here’s how those apply to what we collect:

Legal basis for processing:

  • Newsletter emails: Processed on the basis of consent. You gave us your email address specifically to receive the Vault Dispatch. You can withdraw this consent at any time.
  • Analytics data: Processed on the basis of legitimate interest — understanding how people use the site so we can improve it. Analytics are anonymized and do not identify individuals.
  • Affiliate tracking: Processed on the basis of legitimate interest — operating the affiliate program that funds the site’s testing budget.

Data retention: Newsletter subscriber emails are retained until you unsubscribe. Analytics data is retained according to Google Analytics’ default retention settings (14 months for user-level data). Server logs are generally retained for 30 days.

Data transfers: Analytics data is processed by Google, which is a U.S.-based company. Google’s participation in the EU-U.S. Data Privacy Framework provides transfer safeguards. Email service providers used by this site also have GDPR-compliant data processing agreements in place.

Section 09

Your Rights & Choices

Regardless of where you’re located, you have the following options:

  • Unsubscribe from the newsletter: Every Vault Dispatch email contains a one-click unsubscribe link. No confirmation hoops, no dark patterns.
  • Opt out of analytics tracking: Use Google’s Analytics Opt-out Browser Add-on, or adjust your browser’s cookie settings.
  • Request your data: If you want to know what information we have associated with your email address, contact us at the address below. We’ll respond within 30 days.
  • Request deletion: If you want your email address removed from our newsletter list and any other records we hold, contact us and we’ll process the request.

EU visitors also have the right to lodge a complaint with their national data protection authority if they believe their data has been processed unlawfully.

Section 10

Children’s Privacy (COPPA)

Garage Vault is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are under 13, please do not submit any personal information through this site.

If a parent or guardian believes that their child under 13 has provided personal information to us, please contact us using the information below and we will delete it promptly.

The content of this site — automotive product reviews, testing data, purchase guides — is intended for adult consumers. The newsletter is not suitable for or marketed to minors.

Section 11

Updates to This Policy

We’ll update this policy when our practices change or when legal requirements make updates necessary. The “last updated” date at the top of this page reflects the most recent revision.

If we make changes that significantly affect how we handle your personal data — particularly newsletter subscriber data — we will notify subscribers via the Vault Dispatch before the changes take effect. Minor clarifications and non-material updates will be reflected in the policy without individual notification.

The current version of this policy is always available at garagevault.cloud/privacy-policy. Previous versions are available on request.