← Back to VibeTrust

VIBETRUST PRIVACY POLICY

Effective date: September 25, 2026

1. Who controls your data

Joziel Da Silva Claudiolino Donin, trading as VibeTrust, is the data controller for personal data described in this Privacy Policy. This means we determine why and how that data is used. Contact us at support@vibetrust.com.

2. Personal data we collect

  • Account data: name, business name, email address, login credentials, plan, and account settings.
  • Customer feedback: written reviews, voice recordings, star ratings, transcripts, translations, and optional contact details submitted through review forms.
  • Support data: messages, requests, and other information you provide when contacting us.
  • Usage and technical data: IP address, device and browser information, timestamps, pages or features used, security events, and diagnostic logs.
  • Cookie and local-storage data: authentication, security, session, and saved language preferences.

Public review links use a secure, masked Collector ID rather than exposing the business owner’s registration email.

3. Why we use data and our legal bases

  • To create accounts, provide private dashboards, collect and deliver testimonials, and administer subscriptions where processing is necessary to perform our contract.
  • To transcribe, translate, correct, and moderate feedback where necessary to provide requested features and, where required, based on consent.
  • To secure the service, prevent fraud and abuse, diagnose problems, and improve performance based on our legitimate interests in operating a safe and effective product.
  • To answer support requests and send essential service communications to perform our contract and support our legitimate interests.
  • To meet tax, accounting, consumer-protection, and other legal obligations.
  • To send optional marketing communications only with consent where the law requires it; consent may be withdrawn at any time.

4. Automated processing and account separation

Voice and text feedback may be securely sent to OpenAI services, including Whisper and ChatGPT, solely for requested transcription, translation, grammar correction, and related processing. We do not sell personal data and do not use customer reviews to train our own AI models. Business records are separated by unique account identifiers so one business cannot access another business’s testimonials through the service.

5. Who receives data

We disclose only the data reasonably necessary to:

  • hosting, infrastructure, automation, AI processing, analytics, communications, and customer-support providers acting under contractual obligations;
  • Paddle, our Merchant of Record, for product sales, subscription management, payment processing, tax compliance, fraud prevention, invoicing, customer service, and refunds;
  • legal, accounting, insurance, and other professional advisers; and
  • courts, regulators, law enforcement, or other authorities when required by law or needed to protect rights and safety.

Paddle handles payment-related information under its own privacy notice. We do not store full payment-card details.

6. International transfers

Some providers may process data outside your country, including outside the UK or European Economic Area. Where required, we use recognized safeguards such as adequacy decisions, Standard Contractual Clauses, and contractual and technical protections.

7. Retention

We retain account and testimonial data while an account is active and for as long afterward as reasonably necessary to provide exports, resolve disputes, enforce agreements, prevent fraud, and comply with legal, tax, and accounting duties. Support and diagnostic records are kept only while needed for those purposes. When data is no longer required, we delete or anonymize it. Backup copies may remain for a limited period until routinely overwritten.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy of your data; withdraw consent without affecting earlier lawful processing; and lodge a complaint with your local data-protection authority. You may also have rights to opt out of certain sales, sharing, or targeted advertising; VibeTrust does not sell personal data. Send requests to support@vibetrust.com. We may verify your identity and will respond within the period required by law, generally one month for UK/EEA requests.

9. Security

We use appropriate technical and organizational safeguards, including encrypted transmission, access controls, tenant-level record isolation, restricted administrative access, authentication controls, monitoring, and service-provider review. No online service can guarantee absolute security.

10. Cookies and policy updates

We use essential cookies and similar storage for login, security, session continuity, and language preferences. These are needed for the service to work. If optional analytics or marketing cookies are introduced, we will provide appropriate notice and preference controls where required. Browser settings can remove or block stored data, although essential features may then stop working.

We may update this Policy to reflect changes in our service or legal duties. We will post the revised version here and provide additional notice for material changes where required.