vintake.Join waitlist

Early access opening soon

Stop doing the busywork.Start curating.

Vintake turns a photo or an invoice into a ready-to-post listing with measurements, description, and price, formatted for wherever you sell.

Get early access

Capture

Photograph the piece or upload a supplier invoice, itemized or not.

Generate

Get a title, description, condition, measurements, and suggested price.

Publish

Review and prepare listings for Shopify, eBay, Depop, or Poshmark.

Join the waitlist

Tell us where to find you. We'll reach out when early access opens.

By joining, you agree to receive early access updates from Vintake. You can unsubscribe at any time.

By joining, you agree to the Terms and acknowledge the Privacy Notice.

Vintake
PrivacyTermsSupport

Privacy Policy

What Vintake collects, why, and what you can ask us to delete.

Privacy Policy

Effective Date: August 19, 2026Last Updated: August 19, 2026

1. Introduction

Built by Foundry, Inc., formerly known as Playpen Games, Inc. ("Foundry," "we," "us," or "our"), operates Vintake, a web application that helps secondhand sellers turn item photos and supplier invoices into listing drafts (the "Service"). This Privacy Policy explains how we collect, use, disclose, and retain information when you join the waitlist, create or join a workspace, connect a sales channel, or contact us about Vintake. It is a notice, not a contract. The Terms of Service govern use of the Service.This Privacy Policy describes the personal information we collect, where it comes from, why we use it, when we disclose it, and the choices available to you.Controller and contact: Built by Foundry, Inc. (f/k/a Playpen Games, Inc.), 2261 Market Street, Suite 86046, San Francisco, California 94114, United States. For privacy requests, email privacy@builtbyfoundry.io. For general questions: support@builtbyfoundry.io

2. Information We Collect

2.1 Waitlist Information

If you join the waitlist we collect your email address, store name, where you sell, and an optional website or Instagram handle. We stamp a consent version on the record (currently 2026-08-03) and a timestamp. We also store a one-way request fingerprint derived from the network address on the signup request, keyed so that the raw address is not retained, so we can rate-limit abuse. Submitting the same email in the same waitlist organization updates that record rather than creating a second place. Waitlist records are not a seller workspace. They exist so we can tell you when early access opens and so we can run the waitlist.

2.2 Account and Workspace Information

When you are invited into a workspace we collect the email address you use to sign in, membership and role (viewer, editor, or administrator), the workspace experience (seller or consignor), and settings you choose during onboarding, such as destinations you sell on, expected volume, and currency. Each seller works inside a private organization. Membership, items, photos, documents, costs, destination credentials, and activity are scoped to that organization. Sign-in uses an email link through our authentication provider. Some deployments still use a workspace session cookie for a named tenant. We store an active-workspace cookie so we can open the correct organization after sign-in.

2.3 Item Photos, Invoices, and Listing Content

You can photograph an item in the browser (the site asks the browser for camera access only on that capture) or upload photos you already have. Supported photo types are JPEG, PNG, WebP, HEIC, and HEIF, up to eight photos per item and 20 MB each. You can upload supplier invoices and other source documents as PDF, JPEG, or PNG, subject to a 25 MB total size limit. From those inputs Vintake stores item facts, measurements, condition notes, costs, generated listing copy, destination-specific drafts you review, and related inventory state. Photos and documents leave your device when you capture or upload them into Vintake. Avoid uploading documents that contain personal, banking, or tax information about other people unless you have a lawful basis to do so.

2.4 Automated Extraction and Photo Enhancement

When you ask Vintake to identify an item or extract an invoice, we send the minimum photos or document pages needed for that request through OpenRouter to a Google Gemini class model. We request zero-data-retention routing and deny provider data collection on that request. We do not write provider responses or raw photo or invoice content to application logs. Token counts, latency, and a provider request identifier may be stored for metering. When background removal is configured, a copy of a source photo is sent to fal.ai (Bria) to produce a transparent derivative, which we store with the item. Model and enhancement providers may retain or log inputs under their own terms. We do not guarantee that a provider will never use submitted data to improve its services.

2.5 Marketplace Connections

If you connect Shopify, we store the credentials and webhook evidence needed to prepare or reconcile listings for that shop. During the current beta, outbound writes to Shopify stay disabled in configuration even if a shop is connected. eBay, Etsy, Depop, Poshmark, and Whatnot listing copy can be prepared and exported as files for you to upload; those destinations do not currently use live marketplace APIs. Connecting a channel does not give us ownership of your inventory. Destination status shown in the product does not expose secrets.

2.6 Optional Sharing and Support Access

A seller may share a specific item with Seven Moods for curation when that destination is enabled. That share is purpose-bound, does not transfer ownership of the item, and does not open the rest of the workspace. A workspace may also invite consignors under a separate seller-network consent. A workspace administrator may grant time-bounded, audited support access to a named operator (15 minutes to eight hours, read-only). Operators do not browse seller inventory by default. The creator portal shows waitlist fields, account and usage aggregates, queue health, and voluntary feedback, not raw item photos or invoice text.

2.7 Automatically Collected Information

• Product analytics through PostHog: named funnel events we have defined in code, plus pageviews, autocapture, heatmaps, performance timing, and session recording with form inputs masked. Person profiles are created only for identified users. We strip property names that look like emails, item identifiers, or other forbidden fields before an event is sent
• Device and request metadata needed to keep the Service running, including browser type and coarse network information
• Sanitized error facts through Sentry when configured. Exception messages are replaced with a generic operation-failed string. Provider responses and raw photo or invoice content are not written to error reports

2.8 Communications and Optional Mirrors

Resend may deliver waitlist confirmation email and workspace sign-in or trial access links when configured. If Google Sheets is configured for the waitlist, we append consented waitlist fields (time, email, store name, website or Instagram, where you sell, organization, consent version) to that sheet as an operational mirror. Supabase remains the source of truth. A workspace may also import an inventory catalog from Google Sheets or a file you supply when that import path is configured.
Sources of information: We receive information from you, automatically from your device and use of the Service, and from any sign-in provider, marketplace, or other service you choose to connect. The categories above describe what we collected during the preceding 12 months; we do not collect a category unless the Service uses the related feature.

3. How We Use Your Information

• Save your place on the waitlist and email you when early access opens
• Create and isolate seller workspaces, including sign-in, roles, and invitations
• Extract listing facts from photos and invoices you submit, enhance photos you request, and show you drafts to review
• Prepare destination-specific listing copy, file exports, and (when writes are enabled) marketplace drafts
• Operate connected destinations you have authorized, within the write limits of the current beta
• Enforce usage allowances, detect abuse, debug failures, and keep the Service reliable
• Respond to support, export, and deletion requests from a workspace administrator
• Improve Vintake using aggregated or de-identified product analytics

4. Third-Party Service Providers

We disclose only the information reasonably needed to service providers and contractors that host, secure, analyze, support, or process purchases for the Service. They process information under their agreements with us and their own legal obligations.Infrastructure and Authentication: Vercel hosts the web application and background workers. Supabase stores accounts, database records, private file storage, queue data, and authentication. Data is processed in the United States.Model Gateway: OpenRouter is the model gateway for photo and invoice extraction, currently routed to a Google Gemini class model. Only the minimum photos or document pages needed for the requested extraction are transmitted. We request zero-data-retention routing. Provider retention remains governed by that provider's terms.Image Processing: fal.ai (Bria background removal) receives a source photo URL when enhancement is configured, and returns a transparent derivative we store with the item.Email: Resend may deliver waitlist confirmation and transactional account or access-link email when configured.Operational Spreadsheets: Google Sheets may receive a copy of consented waitlist fields when a spreadsheet is configured, and may be used as an inventory import source when a workspace connects one.Analytics and Errors: PostHog receives product analytics, including session recording with masked inputs. Sentry receives sanitized error facts when configured.No sale or behavioral-advertising sharing: We do not sell personal information for money or share it for cross-context behavioral advertising. We have not done so during the preceding 12 months. We may disclose information if required by law, to protect people or the Service, or as part of a merger, financing, or sale of the business, subject to appropriate safeguards.

5. International Data Transfers

Foundry is based in the United States. We and our providers may process information in the United States and other countries where privacy laws may differ from those where you live.EEA/UK/Swiss users: Where required, we rely on an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism. You can ask about safeguards for a particular transfer by contacting privacy@builtbyfoundry.io.

6. Data Retention and Deletion

We keep personal information only as long as reasonably needed for the purposes described here, including to provide the Service, maintain security, resolve disputes, and meet legal or accounting duties. Retention depends on the type of information, whether your account is active, and applicable law. When it is no longer needed, we delete or de-identify it. Copies may remain temporarily in backups or where law requires retention.Waitlist records remain until you ask us to remove them or we no longer need them for outreach and abuse prevention. We currently treat twelve months after last outreach as the operating outer bound. There is no automated daily purge of abandoned uploads; failed uploads are removed on a best-effort basis when the request that created them fails. Completed inventory, photos, invoices, and listing drafts stay while the workspace is active, because they are the seller's record. Product analytics and session recordings are kept only as reasonably needed during the beta, then deleted or aggregated. Sanitized error telemetry is kept only as reasonably needed to diagnose failures. Support-access grants and audit events are kept for the audit period. A verified organization administrator can request an organization-scoped export. Export packages are assembled in private storage, redact credential-shaped values, carry checksums, and are delivered through download links that expire in 15 minutes. A verified administrator can also request deletion. Deletion will not proceed while a destination listing is in an active publishing state or a legal hold exists. We do not currently run an automated workspace wipe after a deletion request is opened; operators process the request. Backups may retain copies for a limited period after eligible active data is deleted.

7. Your Privacy Rights

Depending on where you live, you may ask to access, correct, delete, or receive a copy of personal information, or object to or restrict certain processing. You may withdraw consent at any time where processing relies on consent, without affecting earlier processing.

Legal bases for processing

Legal bases: We process information as needed to provide the Service and perform our contract with you; for legitimate interests such as security, support, product improvement, and fraud prevention; with consent where required; and to comply with law.

EEA, UK, and Swiss users

You may also have rights to data portability and to complain to your local data protection authority. We may ask for information necessary to verify and complete your request.

United States state privacy rights

Residents of California and certain other states may have rights to know, access, correct, delete, or obtain personal information and to receive information about categories of recipients. We do not discriminate against you for exercising a privacy right. Where applicable, you may use an authorized agent and may appeal our response by replying to it.

How to Exercise Rights

Email privacy@builtbyfoundry.io with the Service name, the email or account identifier you used (if any), and your request. You may also use an account-deletion control where the Service provides that control. We will verify requests as reasonably necessary and respond within the time required by applicable law.Some information may be exempt from a request or retained where permitted by law. We may charge a reasonable fee or decline requests only where applicable law allows it.

8. Children's Privacy

Vintake is a business tool. It is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe we have information about a minor, email privacy@builtbyfoundry.io. We will investigate and delete that information when required.

9. Data Breach Notification

We maintain an incident-response process. If a security incident affects personal information, we will investigate, contain, and provide notices to regulators or affected people when and as required by applicable law.Report security concerns: privacy@builtbyfoundry.io

10. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls and protections offered by our hosting and authentication providers. No method of storage or transmission is completely secure.You should: Protect your device, credentials, and connected accounts and tell us promptly if you suspect unauthorized access.

11. Automated Outputs Are Drafts

Titles, descriptions, measurements, condition language, suggested prices, and background-removed photos are machine-generated drafts for you to review. They may be incomplete or wrong. This Privacy Policy describes the information used to produce them. It does not promise that an output is accurate or that a marketplace will accept it.

12. Operator Access Is Bounded

Built by Foundry operators do not receive a default inventory browser. Aggregate events, waitlist administration, usage allowances, and voluntary feedback are the default operator tools. Item-level access happens only when a seller shares a specific item or grants time-bounded support access. Support grants are audited.

13. Updates to This Policy

We may update this policy as the Service or law changes. The Last Updated date shows when it was revised. If a change materially affects how we use personal information, we will provide notice in the Service, by email when available, or by another reasonable method before the change takes effect where required.

14. Contact Information

Built by Foundry, Inc. (f/k/a Playpen Games, Inc.)Privacy requests: privacy@builtbyfoundry.ioGeneral inquiries: support@builtbyfoundry.ioWebsite: builtbyfoundry.io
This Privacy Policy describes how Foundry handles information for Vintake.