Version 3.0, September 4, 2026, DRAFT
Draft for Legal Review
This document is a working draft. It is not legal advice and has not been reviewed by counsel. It is drafted to adopted positions on every previously open question and awaits counsel's confirmation of the ten points recorded in Vale's Legal Decisions Record. It must be confirmed by a qualified privacy lawyer before this site handles real member data or accepts members. Section 9 sets out honestly which security controls exist today and the one that must be built before we accept anyone. Bracketed items are facts that do not yet exist.
Last updated: [FACT F1: publication date]
Vale exists because you should not have to think about the arrangements in your life. That means we hold information about you that is genuinely private, where you travel, who you travel with, what you need, and often, who you are. This policy explains what we hold, why, who else sees it, and what you can require of us. It is written to be read.
1.1 The Services are operated by [FACT F2: Vale operating entity; interim: DHZ Ventures, a British Columbia sole proprietorship, CBN 738104207BC0002] ("Vale", "we", "us"), [FACT F3: registered address], British Columbia, Canada.
1.2 Vale is the organisation accountable for your personal information, the "controller" where that term applies.
1.3 Privacy Officer. Dehan Zhang, reachable at privacy@thevale.io and at the address in Section 1.1. The Privacy Officer is the individual accountable for our compliance with this policy and with the privacy law that applies to you.
1.4 Scope. This policy covers personal information we handle through the Vale text message service, our website at thevale.io, our application process, and our correspondence with you and your Delegates.
Some of what makes the Services work is sensitive:
We treat all four as sensitive, whether or not the law where you live calls them that.
Health related details are recorded in your profile only when you ask us to keep them. If you mention an allergy while making a request, we use it for that request. We add it to your profile only if you tell us to. Saying "keep that on file" is enough, and we record that you did. You can ask us to remove it at any time. We collect other sensitive information only where it is necessary to do what you have asked, and we apply heightened protection to all of it.
2.2 Information about other people. If you give us information about companions, family members, guests, or Delegates, you confirm you are entitled to do so and that they know their information will be handled as described here. Tell us if you would like us to give them a copy of this policy.
Directly from you, in your application and in the message thread. From your Delegates. From Suppliers in the course of fulfilling a booking, for example a confirmation or a change notice. From publicly available sources and sanctions lists during membership assessment.
4.1 We do not sell your personal information, share it for cross context behavioural advertising, use it for advertising, or use advertising technology tracking. This is a design commitment, not only a legal position.
4.2 Your messages are not used to train AI. We do not use your message content to train general purpose AI models, and our agreement with our AI processor prohibits it from doing so. Our AI processor retains the content it processes for us for no longer than 30 days, and we are pursuing an agreement under which it retains nothing.
5.1 When you message the Vale Number, your message is processed in part by automated software systems, including large language model artificial intelligence systems. Those systems read the content of your messages in order to understand what you are asking for, draft replies, retrieve your preference profile, and complete bookings that can be completed automatically. Requests that cannot be handled that way are passed to a member of our concierge team.
We present a single service voice and do not label individual messages as automated or human. We will never tell you a message came from a person when it did not. If you ask whether you are communicating with a person, we will answer truthfully and connect you with one. This disclosure also appears in your welcome materials and in the reply to HELP.
5.2 Human involvement. Human concierges oversee the Services and handle complex, sensitive, or high stakes requests. You may ask at any point that a request be handled by a person, and we will do that.
5.3 Limits enforced independently of the AI. The automated systems cannot complete an irreversible or high value transaction, and cannot exceed your Spend Cap. Those limits are enforced by our systems separately from the AI system's output, so they hold regardless of what the AI produces.
5.4 No solely automated significant decisions. We do not make decisions producing legal or similarly significant effects about you by solely automated means. Membership decisions are made by people.
5.5 What you can ask. You can ask us what categories of information the automated systems used in handling a request, ask for human review of any outcome, and object to automated handling.
5.6 We learn from what you book. A core part of the service is that we build a private profile from your requests and, in particular, from the bookings actually made for you, the suppliers used, the arrangements kept, the options you declined. Over time this lets us stop asking what we should already know, and to propose arrangements before you ask. A proposal is never a booking; nothing is committed without your confirmation.
You can ask us what the profile holds, correct it, delete anything in it we are not required to keep, or ask us to stop recording a particular category. Categories you ask us not to record are listed on your profile and honoured by our team and our systems. We will tell you where that reduces the quality of the service rather than quietly degrading it.
6.1 Suppliers. When you ask us to arrange something, we give the Supplier what it needs to do it, typically your name, contact details, party size, and preferences relevant to that booking; travel document details where a carrier or border authority legally requires them. Never more than the request requires. Where discretion matters and the Supplier permits it, we will make arrangements without identifying you. Suppliers who receive booking level information about you are asked to sign our confidentiality terms, which prohibit them from disclosing your presence or location to anyone and from using your name or Vale's in their marketing.
6.1a Affiliation. To secure arrangements that are not otherwise available, we may tell a supplier the category of member we are booking for, for example, that we represent professional athletes and that a booking is for a professional athlete and their family. At onboarding we ask whether you permit this and we record your answer; you can change it at any time. We will not name you, or identify your team, club, or employer, without your specific permission for that booking.
6.2 Service providers. Companies that process information on our instructions under written contract, each bound to process only on our instructions and to protect the information:
We will update this list when it changes. The current version is always at thevale.io/privacy.
6.3 Professional advisers. Lawyers, accountants, auditors, and insurers, under duties of confidentiality.
6.4 Legal and safety. Where required by law, to respond to a lawful request, to enforce our Terms, or to protect the rights or safety of any person. Where we are permitted to tell you, we will.
6.5 Corporate transactions. In connection with a reorganisation, financing, or sale, subject to confidentiality and to this policy continuing to apply.
6.6 We do not sell. We do not sell your personal information and we do not share it for cross context behavioural advertising.
6.8 Other members. We do not tell you who else is a member, and we do not tell any member about you. If we ever offer to introduce you to another member, it will only be where both of you have separately agreed to that specific introduction. We will never disclose your presence, your location, or your identity to another member on the basis of a general permission, and never automatically.
7.1 Vale operates from Canada. Our service providers and the Suppliers you ask us to engage are located in Canada, the United States, and elsewhere. Fulfilling a request necessarily involves transferring information to the country where the service will be delivered.
7.2 Where we transfer personal information outside its country of origin, we do so under contractual protections appropriate to the destination and the sensitivity of the information, and we remain accountable for it.
7.3 Quebec. We do not currently admit members resident in Quebec. Before we do, we will complete the privacy impact assessment that Quebec law requires for communicating personal information outside Quebec, and we will offer this policy and our Terms in French.
7.4 European Union and United Kingdom. We do not currently admit members resident in the EU or the UK.
8.1 We keep personal information only as long as we need it for the purposes in Section 4, and then delete or anonymise it. The periods below are the rule; our full retention schedule is available on request.
8.2 Retention periods:
8.3 On request we will delete what we are not required to keep (Section 11). Where a legal claim, complaint, regulator request, or security incident is open, we suspend deletion of the records it concerns until it is closed.
9.1 In place today. All traffic to our website and service is encrypted in transit. Every inbound message is cryptographically verified as having come from our messaging provider before it is processed. Messages from numbers that are not on our member list are rejected before they reach any part of our system. Administrative access requires authentication and is closed by default. Everyone who works on the Services signs a perpetual confidentiality agreement before they can access anything about you. We have a written incident response plan that treats a disclosed itinerary as a safety matter, not only a data matter (Section 10).
9.2 Your messages are encrypted, not merely stored securely. The content of your messages, your address, who travels with you, your dietary and health related details, and any booking we are preparing are encrypted by us before they are written to our database, using a key held separately from it. Someone who obtained a copy of our database would hold unreadable text, not your travel plans. We do this because for our members an exposed itinerary is a safety matter, not only a privacy one.
9.3 Payment. Card details are entered directly with our payment processor and never pass through our systems. We hold only the card brand and last four digits, which we keep so you can recognise your own card. We never see, store, or transmit a full card number.
9.4 Still to come before we accept a member. Automated encrypted backups of our database. Until that is in place, we will not onboard a member or hold real member data.
9.5 What you must not send. Do not send card numbers, passwords, government issued identification images, or other credentials in a message. If you do, we will delete them and ask you to use a secure channel.
9.6 Honest limits. No system is perfectly secure. We do not claim that ours is.
10.1 If a breach of security creates a real risk of significant harm to you, we will notify you and the applicable regulator as required by law, and we will tell you what happened, what information was involved, what we are doing, and what you can do.
10.2 Your safety comes first. If we believe your current or future location may have been disclosed to someone it should not have been, we will call you, before we have finished investigating, and before we have told anyone else.
10.3 We maintain records of breaches as required, whether or not they are notifiable.
Your rights depend on where you live. We apply the following to everyone as a baseline, and we honour additional rights where the law gives them.
11.1 Canada (PIPEDA and BC PIPA). Access, correction, and withdrawal of consent subject to legal and contractual limits. You may complain to the Office of the Privacy Commissioner of Canada or, in British Columbia, the Office of the Information and Privacy Commissioner for British Columbia.
11.2 Quebec (Law 25). We do not currently admit Quebec residents (Section 7.3). When we do, you will additionally have the right to be informed of automated decision making and to submit observations, the right to data portability, the right to removal from search indexes in defined circumstances, and the right to complain to the Commission d'accès à l'information.
11.3 United States. Depending on your state of residence, you may have rights to know, access, correct, delete, obtain a portable copy, and opt out of sale, sharing, targeted advertising, and certain profiling; and a right against discrimination for exercising them. We do not sell or share personal information for advertising, so the opt out rights have nothing to operate on, but the access, correction, and deletion rights are live and we honour them for every member regardless of state. If your state gives you an appeal right where we decline a request, we will tell you how to use it.
11.4 European Union and United Kingdom. We do not currently admit EU or UK residents (Section 7.4).
11.5 How to exercise. Message the Vale Number or write to the Privacy Officer (Section 1.3). We will respond within 30 days. We may need to verify your identity; a request sent from your own Vale Number is verified by that fact. A Delegate cannot make a deletion request on your behalf.
12.1 Service messages are the Services. Promotional messages are separate and require a separate opt in you can withdraw at any time.
12.2 You may revoke consent to messages by any reasonable means, replying STOP, saying so in words in the thread, emailing us, or telling a concierge. We honour revocations promptly and in any event within 10 business days. Reply HELP for help.
12.3 You may revoke promotional messages only, and remain a Member with full service messaging.
12.4 Because the Services are a messaging service, revoking consent to all messages ends the Services, and we will treat it as a cancellation.
12.5 Our records. We keep a record of the consent you gave, when, in what words, and of any revocation. We keep those records after your membership ends because they are our evidence of compliance.
12.6 Your mobile information is not shared. We do not share your mobile number, or your consent to receive text messages, with any third party or affiliate for their marketing or promotional purposes.
13.1 Our website uses privacy preserving, cookieless analytics that count visits in aggregate. We do not set advertising cookies, do not track you across sites, and do not build a profile of you from your browsing. No personal information is sent to our analytics provider.
13.2 The message service does not use cookies.
The Services are for adults. We do not knowingly collect personal information from anyone under 18. If a booking involves a child travelling with you, we collect only what the Supplier or a border authority requires, from you, and we keep it no longer than the booking requires.
We will post changes here and date them. For changes that materially affect your rights we will notify you directly by message and by email and, where the law requires it, obtain your consent. We keep prior versions available.
16.1 Privacy Officer: Dehan Zhang, privacy@thevale.io, or by post to the address in Section 1.1.
16.2 If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada; the Office of the Information and Privacy Commissioner for British Columbia; or, if you reside in the United States, your state attorney general.