Privacy Policy
Last updated
Effective date: July 21, 2026
This Privacy Policy explains how Saras Holding ("Saras Holding," "ItemsInView," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use ItemsInView, including the websites and services available at itemsinview.com and itemsinview.app (collectively, the "Service").
1. Who we are
Saras Holding operates ItemsInView.
Postal address: 11430 NW 5th St, Plantation, FL 33325, United States
Privacy contact: info@sarasholding.com
For account, website, security, and platform-operating information, Saras Holding generally acts as the business or data controller responsible for deciding why and how that information is processed.
Vault customers and Vault Admins decide what records they and their invited Members place in a vault. To the extent vault content contains personal information about other people, the relevant vault customer may be the business or controller and Saras Holding processes that content to provide the Service. Requests concerning information placed in a vault may therefore need to be handled by the applicable Vault Admin.
2. Scope
This Policy applies to the public website, account creation, authentication, vault applications, support communications, transactional emails, and other interactions with the Service. It does not apply to third-party websites or services reached through external links.
3. Information we collect
Information you provide
Depending on how you use ItemsInView, you may provide:
- Account information: name, email address, password, and authentication settings. Passwords are stored as one-way hashes rather than plaintext.
- Security information: multi-factor authentication enrollment information, hashed recovery codes, password-reset records, and sign-in challenge records.
- Vault and membership information: vault name and address/slug, ownership contact, memberships, roles, invitations, and access status.
- Inventory information: item names and codes, descriptions, categories, locations, values and currencies, serial numbers, purchase and expiration dates, private notes, and lifecycle status.
- People information: names, relationships, and notes for beneficiaries, intended recipients, gift recipients, or gift givers.
- Files and coverage information: photographs, PDFs and other uploaded documents, materials, insurance information, warranty information, policy or reference numbers, coverage or premium amounts, and related notes.
- Activity and communications: check-in/check-out history, reasons for movements, audit records, emails or messages sent to us, and support-request information.
You decide what vault content to submit. Please do not upload information you do not have the right to use or disclose. If you enter information about another person, you are responsible for having an appropriate basis to do so and for providing any notice required by law.
Information collected automatically
When you use the Service, we may collect:
- IP address and browser or device user-agent information associated with account sessions and security controls;
- session identifiers, authentication status, timestamps, last activity, selected vault, and sign-in history;
- request, error, security, and operational logs generated by the Service or its hosting infrastructure;
- rate-limiting records derived from an email address, account identifier, or IP address;
- vault-level operational telemetry such as item, member, file, storage, and transaction counts and activity timestamps; and
- essential cookie and session-storage information described in our Cookie Policy.
ItemsInView does not currently use advertising cookies, behavioral tracking, or third-party analytics scripts.
Information from other users
A Vault Admin may provide your email address and intended role to invite you to a vault. Other vault participants may also add information about people connected to an item. We use invitation information to deliver and administer the invitation and use vault content only to provide and secure the relevant vault.
4. How we use information
We use personal information to:
- create and administer accounts, vaults, memberships, and roles;
- authenticate users, require multi-factor authentication, maintain sessions, and recover accounts;
- provide inventory, file, location, people, insurance, warranty, movement-history, and reporting features;
- deliver invitations, password resets, reminders, security messages, and other transactional communications;
- prevent fraud, abuse, unauthorized access, and cross-vault access;
- operate, debug, secure, maintain, and improve the Service;
- respond to questions, requests, and support issues;
- enforce our Terms & Conditions and protect users, Saras Holding, and others;
- comply with law, legal process, and regulatory obligations; and
- establish, exercise, or defend legal claims.
We do not use vault contents to serve targeted advertisements. We do not sell personal information or share it for cross-context behavioral advertising.
5. Legal bases for processing
Where applicable law requires a legal basis, we rely on one or more of the following:
- Contract: processing necessary to provide the Service and perform our agreement with you.
- Legitimate interests: securing and improving the Service, preventing misuse, supporting users, and operating our business, where those interests are not overridden by your rights.
- Legal obligation: processing needed to comply with applicable law, legal process, accounting, security, or regulatory requirements.
- Consent: processing based on consent where law requires it. You may withdraw consent, but withdrawal does not affect earlier lawful processing.
- Protection of rights and safety: processing necessary to protect vital interests or establish, exercise, or defend legal claims where applicable.
When Saras Holding processes vault content solely on behalf of a vault customer, the customer determines the applicable legal basis.
6. How we disclose information
We may disclose information in the following circumstances:
Within a vault
Vault content is available to active Members and Vault Admins of that vault according to their permissions. A person may have different roles in different vaults. Vault Admins can manage membership and access within their vault. Password and MFA credentials belong to the global account and may affect access to every vault.
Service providers
We use providers that process information for us to operate the Service, including:
- Vercel for hosting, server execution, deployment infrastructure, and private file storage;
- Neon for managed PostgreSQL database infrastructure; and
- Resend for transactional email delivery.
These providers may process technical, account, email, vault, or encrypted file information as needed to perform their services. We may replace or add providers as the Service evolves, subject to appropriate contractual and security safeguards.
Public exchange-rate and precious-metal data is retrieved by the ItemsInView server from external market-data endpoints. Stored vault values are aggregated by ItemsInView before display; we do not intentionally send your identity or item records to those market-data endpoints.
Legal, safety, and compliance disclosures
We may disclose information if we reasonably believe disclosure is required by law or legal process, or is necessary to detect or prevent fraud, security incidents, abuse, or threats to the rights, property, or safety of Saras Holding, our users, or others.
Business transactions
If Saras Holding is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may be disclosed or transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
At your direction
We may disclose information when you direct or authorize us to do so.
7. International processing and transfers
Saras Holding is located in the United States, and the Service and its providers may process information in the United States and other countries. Those countries may have privacy laws different from those where you live.
Where required, we use recognized safeguards for international transfers, such as contractual protections, adequacy mechanisms, or other lawful transfer tools. You may contact us for more information about safeguards relevant to your information.
8. Retention
We retain information for as long as reasonably necessary to provide and secure the Service, fulfill the purposes described in this Policy, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of information and how it is used:
- Accounts and memberships: retained while the account or membership remains active and afterward as reasonably necessary for security, legal, and audit purposes. Removing a membership from one vault does not delete the global account or other memberships.
- Vault content: retained until it is changed or removed by an authorized user, the vault is permanently deleted, or we process a valid deletion request, subject to legal and technical limitations.
- Soft-deleted items: retained indefinitely unless a Vault Admin restores or permanently purges them. Purging permanently deletes the item record and its associated files and cannot be undone.
- Deleted vaults: become inaccessible when soft-deleted. Permanent deletion is a separate operational step; do not rely on a particular automatic-deletion deadline unless the Service expressly confirms one.
- Uploaded files: retained with the associated vault record until an authorized permanent purge or vault deletion removes them, subject to backup and operational deletion cycles.
- Sessions: expire no later than 30 days after creation and may end earlier because of inactivity, sign-out, password reset, account action, or vault policy.
- MFA challenges: normally expire after approximately five minutes. Password-reset links normally expire after approximately 60 minutes.
- Invitations: invitation links normally expire after 30 days. Accepted, expired, or revoked invitation history may be retained for security and audit purposes.
- Rate-limit records: generally retained only for the applicable security window and daily cleanup cycle.
- Audit, security, and operational records: retained as reasonably necessary to preserve integrity, investigate incidents, demonstrate authorized actions, and meet legal obligations. Some audit attribution may be retained in anonymized form after a membership is removed.
- Backups: residual copies may remain for a limited period in protected backups or disaster-recovery systems before being overwritten or deleted.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information. Current measures include HTTPS/TLS in transit, encrypted infrastructure storage, application-level encryption for designated sensitive fields and uploaded file contents, one-way password and recovery-code hashing, mandatory multi-factor authentication for vault access, server-side sessions, membership checks, vault-scoped data access, database row-level security, and separate platform and vault audit records.
The Super Admin Console is designed without a feature for browsing customer item records, photos, documents, or financial reports. However, no system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for protecting your password, authenticator, recovery codes, and devices and for promptly notifying us of suspected compromise.
10. Your privacy choices and rights
Depending on your location and applicable law, you may have rights to:
- know whether and how we process your personal information;
- request access to or a copy of personal information;
- correct inaccurate or incomplete information;
- request deletion of information;
- restrict or object to certain processing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent;
- opt out of a sale, targeted advertising, or certain profiling;
- appeal a decision concerning a privacy request; and
- complain to a privacy or data-protection authority.
ItemsInView does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or make decisions producing legal or similarly significant effects based solely on automated processing.
To exercise a privacy right, email info@sarasholding.com and describe your request. We may need to verify your identity and authority before acting. If the request concerns information controlled by a vault customer, we may direct you to the relevant Vault Admin or assist that customer in responding. Authorized agents may submit requests where permitted by law, subject to verification.
We will not discriminate against you for exercising an applicable privacy right. Some information may be exempt from a request, and we may retain information where permitted or required by law. If we deny a request, you may reply to request an appeal where applicable.
California disclosures
In the preceding 12 months, we may have collected the categories described above, including identifiers; customer-record information; internet or network activity; approximate location inferred from IP address; commercial or financial information supplied in vault records; account credentials and other information that may be considered sensitive under applicable law; and inferences limited to operational or security status. We collect and disclose these categories for the business purposes described in this Policy, including providing, securing, maintaining, and supporting the Service.
We do not sell personal information and do not share personal information for cross-context behavioral advertising. We have not knowingly sold or shared personal information of consumers under 16 for those purposes. Where California law applies, California residents may exercise the rights to know, access, correct, delete, limit certain uses of sensitive personal information, opt out of sale or sharing, and receive equal service. Because we do not engage in sale or sharing for behavioral advertising, the Service does not currently provide a "Do Not Sell or Share My Personal Information" link.
Do Not Track and Global Privacy Control
Because ItemsInView does not currently engage in behavioral advertising, cross-site tracking, sale, or sharing for those purposes, changing a browser's Do Not Track or Global Privacy Control setting does not change the Service's current data practices. If those practices change, we will update this Policy and honor legally required browser-based opt-out signals.
11. Children and younger users
ItemsInView is a general-audience valuables-management service and is not directed to children. We do not impose a single worldwide minimum age. However, a person who cannot legally consent to data processing or enter into our Terms & Conditions independently may use the Service only through a parent or legal guardian who authorizes and supervises the use, controls the account, and accepts responsibility for information submitted through it.
We do not knowingly collect personal information directly from a child under 13 in the United States, or below the applicable digital-consent age elsewhere, without legally sufficient authorization. If you believe a child has provided personal information without appropriate parent or guardian involvement, contact info@sarasholding.com. We will investigate and take appropriate steps, which may include obtaining required authorization, restricting the account, or deleting the information.
Parents and legal guardians may contact us to request access to, correction of, or deletion of a child's personal information where applicable.
12. Third-party links
The Service may link to authenticator applications, app stores, or other third-party websites. Those third parties operate under their own terms and privacy policies. A link does not mean Saras Holding controls or endorses the third party's privacy practices.
13. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our practices. We will post the revised Policy with a new "Last updated" date and provide additional notice where required. Material changes apply prospectively unless applicable law permits otherwise.
14. Contact us
Questions or privacy requests may be sent to:
Saras Holding
11430 NW 5th St
Plantation, FL 33325
United States
Email: info@sarasholding.com