This Privacy Policy describes how Vault collects and uses the Personal Information (defined below) you provide on
any site owned and operated by Vault and including, but not limited to, any websites serving from the vault.co domain
(the “Website”). It also describes the choices available to you regarding our use of your Personal Information and how
you can access and update this information. As is true of most websites, we automatically gather information about
your computer such as your IP address, browser type, referring/exit pages, and operating system.

In this Privacy Policy, we use the term “Personal Information” to describe information that can be associated with an
individual and can be used to identify that individual. We do not consider Personal Information to include information
that has been anonymized or aggregated so that it does not identify an individual. You represent that if you give us
Personal Information on behalf of someone else, the person providing the Personal Information to you gave you
consent to provide their individual information to Vault. If someone else gives us Personal Information on your behalf,
you represent that you gave that person consent to provide your Personal Information to Vault.

This Privacy Policy applies if you: Agree to the Vault Payment Service End-User Agreement; Agree to the Vault Advisor Service End-User Agreement; Agree to the Vault Match Service End-User Agreement; Agree to the Vault

Tuition Service End-User Agreement; Agree to the Vault 529 Service End-User Agreement; Visit or utilize a Website
on which this Privacy Policy is posted; or Interact with Vault off-line or online.
Collection and Use of Personal Information

In order to provide services through our Website we may collect the following Personal Information from you:


 Contact information such as name, email address, mailing address, and phone number
 Financial information such as bank or brokerage account numbers, and types of investments
 Unique identifiers such as username, account number, and password
 Geolocation information, depending on the specific Vault services you use
 Other information that may be required under federal or certain state laws
 Demographic information such as education, gender, communication choices, and user preferences
 Adjusted gross income and spouse’s adjusted gross income
 Credit score – self-reported
 Employment information
 Interest in and use of advertising and marketing in conjunction with use of the services

We use this information to:


 Provide services through our Website
 Send you requested product updates or service information
 Respond to customer service requests
 Send you a newsletter
 Respond to your questions and concerns
 Improve our Website and our marketing efforts
 Conduct research and analysis
 Display content based upon your interests

Choice/Opt-Out.


Safe Harbor Requirements. We communicate with you through email, notices posted on our Website. Examples of these
communications include but are not limited to account and relationship details; communications regarding your
payment history; Vault’s newsletter; and marketing emails. You may choose to stop receiving our newsletter or
marketing emails by following the “unsubscribe” instructions included in these emails, or you can contact us at
genius@vault.co. Please note that you may not opt out of transactional messages or other mandatory service
communications. If you provide us Personal Information about another person (e.g., your spouse or child), or if another person provides us your personal information, we will only use that information for the specific reason for
which it was provided to us.
Information Sharing. We will share your Personal Information with third parties only in the ways that are described in
this Privacy Policy. We do not sell your Personal Information to third parties or share your individual student loan
account number, balance, or due date with your employer. We may provide your Personal Information to companies
that provide services to help us with our business. These companies are authorized to use your Personal Information
only as necessary to provide these services to us. However, in some cases, you may choose an optional service
provided by a third party, in which case such optional services shall be governed by that third party provider’s
separate privacy policy and any applicable terms of use for such optional services. We may also disclose your
Personal Information as required by law such, as to comply with a subpoena or similar legal process when we believe
in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate
fraud, or respond to a government request. We may share or sell your Personal Information in connection with a
merger, financing, acquisition, dissolution transaction, bankruptcy or proceeding involving sale, transfer, divestiture of
all or a portion of our business or assets. If another entity acquires our business or assets, that entity will have your
Personal Information collected by us and will assume the rights and obligations regarding your information as allowed
by this privacy policy.
Security. The security of your Personal Information is important to us. When you enter personal or sensitive
information on our Website, we encrypt the transmission of that information using secure socket layer technology
(“SSL”). We follow generally accepted practices to protect the information submitted to us, both during transmission
and once we receive it. No method of transmission over the Internet, or method of electronic storage, is 100% secure,
however. Therefore, we cannot guarantee its absolute security. We will retain your information for as long as your
account is active or as needed to provide you services. If you wish to cancel your account or request that we no
longer use your information to provide you services, contact us at genius@vault.co. We will retain and use your
information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. If you
have any questions about security on our Website, you can contact us at hello@vault.co.

It is the policy of Vault to comply with the requirements of the U.S.-EU Privacy Shield
Framework and the U.S.-Swiss Privacy Shield Framework, as set forth by the U.S. Department of Commerce
regarding the collection, use, and retention of personal information from European Union member countries and
Switzerland. Vault certifies that it adheres to the Privacy Principles of notice, choice, onward transfer, security, data
integrity, access, and enforcement with respect to all personal information transferred from the EU or Switzerland to
the US (personal information) within the scope of its Privacy Shield certification. In addition, certain personal
information may be subject to more specific privacy policies of Vault, which are also consistent with the requirements
of the U.S.-EU Privacy Shield Framework and the U.S.-Swiss Privacy Shield Framework.
Disclosure: It is Vault’s goal to apply Privacy Shield principles as they evolve and update. For your information,
Vault’s Website can be accessed from various locations outside of the U.S., including the EU and Switzerland.
However, Vault’s Services are exclusively used for User’s who have student loan debts in the U.S.
Cookies and Other Tracking Technologies. We may use cookies, for example, to keep track of your preferences and
profile information. Cookies are also used to collect general usage and volume statistical information that does not
include Personal Information. We use another company to place cookies on your computer to collect non-personally
identifiable information to compile aggregated statistics for us about visitors to our Website. We do not respond to
web browser “do not track” signals at this time. We await the result of work by the policy community and industry to
determine when such a response is appropriate and what form it should take.
Web beacons. Our Website pages contain electronic images known as “web beacons” (sometimes called single-pixel
gifs) and are used along with cookies to compile aggregated statistics to analyze how our Website is used and may
be used in some of our emails to let us know which emails and links have been opened by recipients. This allows us
to gauge the effectiveness of our customer communications and marketing campaigns. We use a third party to gather
information about how you and others use our Website. For example, we will know how many users access a specific page and which links they clicked on. We use this aggregated information to understand and optimize how our
Website is used.

Links to Other Websites. Our Website includes links to other websites whose privacy practices may differ from those
of Vault. If you submit Personal Information to any of those other websites, your information is governed by the
separate privacy statements of such other websites. We encourage you to carefully read the privacy statement of any
website you visit.


Your Rights As A California Resident California law permits residents of California to request certain details about
how their information is shared with third parties for direct marketing purposes. If you are a California resident and
would like to request such information, you may do so by emailing such request to hello@vault.co. We do not share
your Personal Information with third parties for such third parties’ direct marketing purposes unless you provide us
with consent to do so.


Your Rights as a Nevada Resident. Under Nevada Revised Statutes Chapter 603A, Nevada residents may have the
right to opt out of certain uses of data. If you are a Nevada resident and would like to make a request under this law,
you may do so by emailing such request to hello@vault.co.
Children’s Online Privacy. Vault is not intended to be used by anyone under the age of 18 and, as such, Vault does
not knowingly collect Personal Information from anyone under the age of 18. If you are under the age of 18, please
do not submit any Personal Information to Vault or use our services. If a parent or guardian becomes aware that his
or her child under the age of 18 has provided us with Personal Information without the parent or guardian’s consent,
he or she should contact us at genius@vault.co and we will delete such information from our files.
Modifications. We may update this Privacy Policy to reflect changes to our information practices. If we make any
material changes, we will notify you by email (sent to the e-mail address specified in your Vault account) or by means
of a notice on the Vault Website prior to the change becoming effective. We encourage you to periodically review this
page for the latest information on our privacy practices.
Accessing and Updating Personal Information; Vault Contact Information. When you use one or more of our services,
we make good faith efforts to provide you with access to your Personal Information and either to correct this data if it
is inaccurate, or to delete such data at your request if it is not otherwise required to be retained by law or for
legitimate business purposes. We ask individual users to identify themselves and the information requested to be
accessed, corrected, or removed before processing such requests, and we may decline to process requests that are
unreasonably repetitive or systematic, require disproportionate technical effort, jeopardize the privacy of others, or
would be extremely impractical (for instance, requests concerning information residing on backup drives), or for which
access is not otherwise required. Before we provide access to any data, including Personal Information, or make any
changes to it we will ask you to verify your identity or provide other details before we are able to provide you with any
information, correct any inaccuracies, or delete any information. We may keep a copy of information for our records.
In any case where we provide information access and correction, we perform this service free of charge, except if
doing so would require a disproportionate effort. Your right to review, update, correct, and delete your Personal
Information may be limited, subject to the law of your jurisdiction of residence: (i) if your requests are abusive or
unreasonably excessive; (ii) where the rights or safety of another person or persons would be encroached upon; or
(iii) if the information or material you request relates to existing or anticipated legal proceedings between you and us,
or providing access to you would prejudice negotiations between us or an investigation of possible unlawful activity.
Your right to review, update, correct and delete your information is also subject to our records retention policies and
applicable law, including any statutory retention requirements. You can contact us about this Privacy Policy or your

Personal Information by writing to us at the following address:
Vault
1801 E. 51st Street. Suite 365-274
Austin, TX 78723
Email: hello@vault.co