Privacy Policy
Version 2.0.0 · Last updated: July 15, 2026
This Policy describes how DataVibe handles personal data for the marketing site (datavibe.cc), the product app (app.datavibe.cc), and APIs. For Customer Content processed as a processor under GDPR, the DPA controls.
1. Roles: controller vs processor
- DataVibe as controller: account signup, billing contacts, website analytics (with consent), support tickets you send us, and security logs needed to run our business.
- DataVibe as processor: gate submissions, outbound payloads, review-queue records, and audit artifacts you submit so we can provide the Service on your instructions (see DPA).
- You as controller (or equivalent) of personal data about your end users that you include in gated content. You must have a lawful basis and required notices before submitting that data.
2. Information we collect
You provide: name, work email, company, role, billing details (processed by Stripe), support content, and configuration data.
Generated by use: API logs, gate submission metadata, verdicts, reviewer identity timestamps, usage metrics, IP addresses, and device/browser metadata for security.
Gate payloads: message bodies and metadata you send to /v1/gate/* or related endpoints. Treat these as Customer Content under the Terms.
3. How we use data
We use data to: (a) deliver and secure the Service; (b) bill and meter usage; (c) send transactional messages (invoices, security alerts, verification); (d) investigate abuse; (e) improve reliability using aggregated, de-identified telemetry. Marketing email requires separate opt-in.
We do not sell personal data.
4. Sub-processors
We use sub-processors listed at /legal/subprocessors and in the DPA (Neon, Render, Vercel/Cloudflare for app surfaces, Stripe, Resend, Upstash, Sentry, and optional inference providers you enable). Changes follow the DPA notice process for Enterprise customers bound by that DPA.
5. Cookies and tracking
Essential session cookies (authentication, security, Cloudflare Turnstile on signup) load as needed. Analytics (Google Analytics / first-party landing telemetry) load only after cookie-banner consent. See the Cookie Policy. We do not use third-party advertising cookies.
6. Sensitive and regulated data
Do not submit PHI, cardholder data (full PAN), government ID numbers, or children's data unless you have a written agreement covering that use (e.g., BAA) and have configured appropriate policies. We may delete or refuse processing of prohibited submissions that create undue legal risk.
7. Retention
Account data is retained for the subscription term plus up to 90 days after cancellation (then deleted from production systems), subject to legal holds. Billing records and security/audit logs may be retained up to 7 years where required. Configurable audit retention for gate records defaults to settings you choose (Growth/Enterprise may set longer retention for FINRA-style recordkeeping). Anonymized aggregates may be retained indefinitely.
8. Security
TLS 1.2+ in transit; encryption at rest via provider volume encryption; API keys stored as peppered hashes; passwords with bcrypt; RBAC and audit logging. See Security. No security program eliminates all risk.
9. Your rights (GDPR / CCPA / similar)
Depending on your location, you may access, correct, delete, restrict, port, or object to certain processing, and opt out of “sale”/“sharing” (we do not sell). Account holders can export or delete via Settings → Privacy & Data. Contact [email protected]. We respond within 30 days where required.
10. Breach notification
For personal data breaches where we act as controller, we notify affected individuals and authorities as required (including GDPR Art. 33/34 timelines where applicable). Where we act as processor, we notify the Customer under the DPA so you can meet your own obligations.
11. Children
The Service is not directed to individuals under 16. We do not knowingly collect their personal data. If we learn we have, we delete it.
12. International transfers
We and our sub-processors may process data in the United States and other countries. For EEA/UK personal data, we rely on SCCs and other lawful mechanisms described in the DPA.
13. India DPDPA
Where India's Digital Personal Data Protection Act applies, DataVibe acts as a Data Fiduciary for account and website data we collect directly. Consent records are timestamped where required. Grievances: [email protected] (acknowledge within 7 days; aim to resolve within 30 days). Cross-border transfers use contractual safeguards with listed sub-processors.
14. Changes
We may update this Policy. Material changes for account holders get at least 14 days' notice by email or in-app notice where practicable. Continued use after the effective date constitutes acceptance.
15. Contact
Privacy: [email protected] · Contact form