VECTOR Privacy Policy

Effective date: August 2026 · Version: v1.0

This policy explains what personal data PNH Security Engineering Consultants ("PNH", "we") collects through the VECTOR application, why, how long it is kept, and what you can ask us to do with it. It sits alongside the VECTOR Terms of Use. PNH is the controller for the data described here.

1. What we collect. Only what the Service needs to run:

  • Account — your email address, and the name and organisation you choose to give. Your password is stored only as an Argon2id hash; we cannot read it.
  • Scenario inputs and results — the vehicle class, surface, approach geometry, impact angle, entry speed, driver-utilisation factor and setback you submit, and the results computed from them. Terms §A-7: you own your scenario inputs.
  • Reports — the project name, number, site or location, client and preparer you enter on a report, and the generated PDF. Each report is identity-stamped for traceability (Terms §A-8).
  • Technical records — the IP address and browser user-agent of a sign-in, the IP recorded when you accept these terms, and server logs of requests (method, path, status, duration, account identifier).
  • Billing — the plan you bought and a Stripe customer and payment reference. Payment card details are entered on Stripe's own checkout and never reach our servers.

We do not use advertising or analytics trackers, we set no third-party cookies, and the only cookie we set is the one that keeps you signed in — strictly necessary, and removed when you sign out.

2. Why we hold it, and on what basis.

  • To provide the Service — running analyses, generating and storing reports, managing your licence. Performance of our contract with you.
  • To keep it secure — rate limiting, sign-in throttling, and abuse investigation. Our legitimate interest in a service that is not trivially abused.
  • To take payment — through Stripe. Performance of contract, and our legal obligation to keep financial records.
  • To evidence acceptance — recording that you accepted the Terms and disclaimers before generating a report, because a VECTOR output can be relied on in a design decision. Our legitimate interest, and our legal obligation to keep the record.

3. Engineer-Reviewed & Signed reports. If you request one (Terms §A-9), your scenario, results and draft report are transmitted to a PNH protective design engineer for review. That review is professional work: PNH keeps its own record of what was submitted and what was signed, and that record is retained under PNH's professional obligations independently of your account.

4. Who else processes it. Only these, and only to run the Service:

  • Stripe, Inc. — payments and subscription management.
  • Our transactional email provider — delivery of verification, password-reset and report notifications. It receives your email address and the message.
  • Our hosting provider — the server the application and its database run on.
  • Have I Been Pwned — when you choose a password, we check it against a public corpus of passwords exposed in data breaches. Your password is never sent. Only the first five characters of its SHA-1 hash leave our server, which is shared by roughly one in a million of all possible passwords, and the comparison happens here. The service cannot learn your password or link the query to you or your account.

We do not sell personal data, and we do not share it for advertising. Where a processor is outside your jurisdiction, transfers rely on that provider's standard contractual clauses.

5. How long we keep it.

  • Account, reports and licence records — for as long as your account exists, then as described in §7.
  • Analysis history — 24 months, then deleted automatically.
  • Records of terms acceptance — 7 years, because they are the evidence that a report was generated under the stated disclaimers.
  • Sign-in records — up to 90 days after a session expires.
  • Payment-event records — 90 days in this application; Stripe keeps its own for as long as its financial obligations require.
  • Sent notification emails — a record of the message and when it was delivered, for 30 days.

6. Your rights. Subject to local law, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to our use of it, or receive it in a portable form. Two of these are self-service on your dashboard, and take effect immediately:

  • Download my data — a JSON file of everything described in §1.
  • Delete my account — see §7.

For anything else, or to complain, write to pnhsec@pnhsec.com. If you are in the UK or the EEA you may also complain to your data protection authority. California residents have the rights described in the CCPA, including the right not to be discriminated against for exercising them; we do not offer financial incentives for data.

7. What deleting your account does — and does not do. Deleting your account immediately and irreversibly removes your account record, your sessions, your licence and credit records, your analysis history, your acceptance records, and the database records of your reports. There is no grace period and no recovery.

The generated report PDF files themselves are not deleted from our report store. We are explicit about this because it is a real limitation rather than an oversight. An issued report is a documented engineering artefact that may already have been circulated to third parties, and a signed report additionally records a PNH engineer's professional review, which PNH is obliged to keep. Once your account is deleted, those files are no longer reachable through the application — nothing can serve a file whose report record is gone — and what remains is a file identified only by a random identifier that nobody holds a reference to. This is the exemption at UK/EU GDPR Article 17(3)(b) and (e). If you need a specific report file destroyed, write to us and we will consider the request against those obligations.

You must cancel any active subscription before deleting your account, or Stripe would continue to bill a licence with nothing left to use it. Stripe retains its own payment records regardless, as it is legally required to.

8. Security. Passwords are hashed with Argon2id. Session tokens are stored only as digests, so a database disclosure does not yield usable sessions. The application is served over HTTPS with HSTS and a content security policy, report files are written with restrictive permissions, and the report renderer is blocked from making any outbound network request. No system is perfectly secure, and we do not claim otherwise.

9. Children. VECTOR is a professional engineering tool and is not directed at, or intended for use by, anyone under 18.

10. Changes. We will post a new version here and, where the change is material, notify you by email or through the Service.

Contact: PNH Security Engineering Consultants · pnhsec.com · pnhsec@pnhsec.com · +1-818-253-9557

© 2026 PNH LLC. VECTOR and VVA-M-01 are proprietary to PNH Security Engineering Consultants.

VECTOR results are computed from user-supplied inputs and are not engineering advice or a certification of barrier performance. Use is subject to the VECTOR Terms of Use and the Privacy Policy.