Privacy Policy

Last updated: September 27, 2026

This Privacy Policy describes how VibeVaults (“we”, “us”, “our”) collects, uses, and protects personal data in connection with the use of our service, as described in our Terms of Service.


1. Who We Are

VibeVaults is a hosted feedback widget and administrative dashboard service. The data controller for the personal data described in this policy is:

Service name: VibeVaults
Operator: József Tar
Legal form: Sole trader registered in Hungary (Hungarian: egyéni vállalkozó, abbreviated “e.v.”)
Registration number: 61558557
Tax number: 91621728-1-33
Registered seat: Zápolya utca 16. 1/a, 2120 Dunakeszi, Hungary
Contact email: support@vibe-vaults.com
Location: Hungary, European Union

We have not appointed a Data Protection Officer. As a sole trader whose core activity is not large-scale monitoring or large-scale processing of special categories of data, we are not required to appoint one under GDPR Article 37. Data protection questions go to the contact address above.


2. Scope of This Policy

This Privacy Policy applies to:

  • visitors of our website
  • customers using the administrative dashboard
  • end users submitting feedback through embedded widgets

Use of the Service is also governed by our Terms of Service.


3. What Data We Collect

3.1 Admin Users (Customers)

We collect:

  • Email address
  • Authentication data (handled via Supabase, stored securely; includes Google OAuth profile data such as name and avatar if you sign in with Google)
  • Workspace and project details you enter, such as names, website addresses, logos, and the email addresses of people you invite
  • Content you create in the dashboard, including feedback entries, replies, and uploaded attachments
  • Subscription and billing status (handled by Stripe)
  • Correspondence you send us by email

We do not store full payment card details.

3.2 End Users (Feedback Widget)

The widget is invite-only or opened through a review link. It shows nothing to an anonymous visitor. When feedback is submitted through a widget, the following is collected and shown to the customer who owns the widget:

  • The feedback content submitted voluntarily, and any replies in the resulting conversation
  • Email address, and for review links a self-declared name, used to attribute the feedback and to send replies
  • Any files or screenshots the reporter chooses to attach
  • The address of the page the feedback was written on, and the position of the pin on that page together with a CSS selector for the element it was anchored to
  • Browser context: user agent string, screen and viewport size, and browser language
  • The last 50 browser console messages produced by the customer's own site while the reporter was on the page
  • Up to 15 failed network requests from the customer's own site, recorded as method, address, and outcome
  • Technical metadata such as IP address (for rate limiting and abuse prevention)

Query strings are removed before a page address is recorded. Only the origin and path are stored, because host site query strings routinely carry reset tokens, access tokens, and email addresses. Email-shaped path segments are replaced with a redaction marker. This stripping happens in the browser, before the entry is created, so the discarded part never reaches us. The full detail is published at docs/widget-data.

We also receive two operational signals from the widget that are not shown to customers and are used only to keep the widget working: crash reports raised by the widget's own code, and screenshot capture diagnostics (browser, graphics renderer, device pixel ratio, viewport, duration) used to measure a known browser rendering bug.

We do not require end users to create accounts, and the widget does not track end users across sites.

3.3 Website Visitors

On our own website we collect usage data through analytics only after you consent. See section 9.

3.4 Prospective Customers (Outreach)

We contact businesses that we think would benefit from VibeVaults, mainly design and web agencies. If you received an email from us and had no prior contact with us, this section is about you.

  • What we hold: your name, job title, business email address, employer, LinkedIn profile, and notes taken from your company's public website
  • Where we got it: your company's website and public LinkedIn profile, and Apollo, a business contact database. We did not get it from you
  • Why: to introduce a product relevant to your professional role. Legal basis is our legitimate interest in direct business-to-business marketing, Art. 6(1)(f)
  • Business contact data only. We do not collect personal addresses, personal phone numbers, or anything about your private life

You can object at any time and we will stop. Reply to any message from us, or write to support@vibe-vaults.com. We delete your details on request, except for the minimum needed to make sure we do not contact you again. We also delete contacts who never engaged after a reasonable period. You have the same rights over this data as anyone else in section 13, including the right to complain to a supervisory authority.

3.5 Setup Calls

If you book a setup call, we receive your name, email address, the time you picked, and anything you write in the booking form. Bookings are handled by Calendly and the call itself takes place on Zoom. We do not record these calls. We use this only to hold the call and follow up on it. Legal basis is taking steps at your request before entering into a contract, Art. 6(1)(b).


4. Data Controller and Data Processor Roles

  • Our customers act as data controllers for feedback collected through widgets embedded on their sites.
  • VibeVaults acts as a data processor for that feedback data, processing it solely on documented instructions from the customer.
  • For customer account data, billing data, and our own website analytics, VibeVaults is the data controller.

Customers are responsible for informing their end users about data collection and usage, and for having a lawful basis for it.

The processor terms in our Terms of Service, together with this policy and the sub-processor list in section 7, form the data processing agreement between us and our customers. We engage the sub-processors listed in section 7 and remain responsible for their performance. We will give customers notice of a new sub-processor before it starts processing their data, so they have an opportunity to object.


5. How We Use the Data

We use personal data only to:

  • Provide and operate the Service
  • Authenticate admin users
  • Store, display, and manage feedback
  • Prevent abuse, spam, and misuse
  • Process subscriptions and payments
  • Communicate service-related information
  • Diagnose faults and improve the Service

We do not use personal data for advertising purposes, and we do not sell personal data.


6. Legal Basis for Processing (GDPR)

For users in the European Union, we process personal data on these bases:

  • Contractual necessity (Art. 6(1)(b)): creating and running your account, delivering the Service, and sending service related messages.
  • Legitimate interest (Art. 6(1)(f)): keeping the Service secure, preventing abuse and spam, and diagnosing faults. We balance this against your interests and use the least data that achieves the purpose.
  • Legal obligation (Art. 6(1)(c)): retaining accounting and invoicing records, and responding to lawful requests.
  • Consent (Art. 6(1)(a)): analytics and session replay on our own website, and any optional marketing email. You may withdraw consent at any time, which does not affect the lawfulness of processing carried out before withdrawal. Analytics consent can be withdrawn through the “Cookie preferences” link in the footer.

Where we act as a processor for feedback submitted through a customer's widget, the legal basis for that processing is determined by the customer, not by us.


7. Third-Party Services (Sub-processors)

We rely on the following service providers, each under a data processing agreement:

  • Supabase – database, authentication, and file storage
  • Vercel – hosting and deployment infrastructure
  • Stripe – payment processing and subscription billing
  • Resend – transactional email delivery (notifications, digests)
  • Cloudflare Turnstile – anti-bot verification during authentication
  • PostHog – product analytics, session replays, and error tracking, on PostHog's EU hosting
  • GitHub – source control and automation, and the private storage location for our encrypted nightly database backups
  • Calendly – scheduling for setup calls you choose to book
  • Zoom – video calls for setup calls you choose to book

These providers process data only as necessary to deliver their services, on our instructions, and under their own privacy policies. We do not authorise them to use the data for their own purposes.


8. International Data Transfers

Some of the providers listed above are established in the United States and may process personal data outside the European Economic Area.

Where that happens, the transfer is covered by an appropriate safeguard under Chapter V of the GDPR: the European Commission's Standard Contractual Clauses, and, where the provider is certified, the EU–U.S. Data Privacy Framework. You can request a copy of the relevant safeguards by writing to the contact address in section 18.


9. Cookies and Analytics

We use cookies and similar technologies for:

  • Essential cookies – authentication sessions and workspace/project preferences. These are required for the Service to function and do not require consent.
  • Analytics (consent-based) – PostHog (EU-hosted) collects usage data, including page views, session replays, and error tracking, to help us improve the Service. These are loaded only after you accept via the cookie banner. Form inputs are masked by default in session replays. If you have an account and accept analytics, this usage data is linked to your account through an internal user ID (never your email), so we can understand how the Service is used.
  • Anti-bot verification – Cloudflare Turnstile may set cookies to verify human users during authentication. This is essential to prevent abuse.

Visitors from the EU, EEA, UK, and Switzerland see a consent banner on first visit. You can change your choices at any time via the “Cookie preferences” link in the footer.

The embedded feedback widget does not set analytics or advertising cookies on our customers' sites. It stores a single access token in the browser's local storage so an invited person stays signed in to the widget on that device.

We do not use cookies for advertising or third-party tracking.


10. Data Storage and Retention

Data is stored on secure servers provided by our infrastructure partners. We keep personal data only as long as it is needed for the purpose it was collected for:

  • Account data is kept while the account exists, and deleted when you delete the account.
  • Feedback and conversation data is kept until the customer deletes it or deletes the project it belongs to. Customers can delete it at any time from the dashboard.
  • Accounting and invoicing records are kept for 8 years, as required by Hungarian accounting law. This retention overrides a deletion request for those specific records.
  • IP addresses collected for rate limiting and abuse prevention are retained for up to 30 days, then purged or anonymized.
  • Widget access tokens that are never used are deleted automatically 30 days after they are issued.
  • Analytics data is retained for 1 year.
  • Prospect contact data is deleted on objection, and contacts who never engaged are removed periodically. An opt-out record is kept indefinitely, because that is what stops us contacting you again.
  • Setup call bookings are kept in our scheduling tool for as long as it holds them, so that we can follow up after the call.
  • Support correspondence is kept for as long as the mailbox holds it, so that we can pick up an old thread if you write again.

When we act as a processor, we delete or return customer feedback data on the customer's instruction, and after the end of the contract, subject to the legal retention above.


11. Data Security

We implement reasonable technical and organizational measures to protect personal data, including encryption in transit, row-level access control in the database, scoped access tokens for the widget, and restricted administrative access.

However, no system can be guaranteed to be 100% secure.


12. Automated Decision-Making

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile users within the meaning of GDPR Article 22.


13. Your Rights

Under the GDPR you have the right to:

  • Access your personal data and receive a copy of it
  • Have inaccurate data corrected
  • Have your data deleted (“right to be forgotten”)
  • Restrict processing
  • Object to processing based on legitimate interest
  • Receive your data in a portable, machine-readable format
  • Withdraw consent at any time, where processing is based on consent

Requests can be made by contacting us at the address in section 18. We respond within one month, which may be extended by two further months for complex requests, in which case we will tell you within the first month.

If your data was submitted through a widget on someone else's website, that website's operator is the controller. We will forward your request to them and assist them in answering it.

Right to lodge a complaint. If you believe we have handled your personal data unlawfully, you may complain to a supervisory authority, in particular in the EU country where you live or work. Our lead supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), naih.hu. You also have the right to an effective judicial remedy.


14. Children

The Service is not intended for children. You must be at least 16 years old to create an account or submit feedback. If we learn that we have collected personal data from a child under 16 without parental consent, we will delete it.


15. Data Breach Notification

In the event of a personal data breach likely to result in a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk, we will also notify affected users without undue delay. Where we act as a processor, we will notify the affected customer without undue delay after becoming aware of the breach.


16. California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA:

  • Right to know what personal information we collect and how we use it
  • Right to delete your personal information
  • Right to correct inaccurate personal information
  • Right to non-discrimination for exercising your rights

We do not sell or share your personal information for cross-context behavioral advertising, and we do not use it for targeted advertising. To exercise your rights, contact us at the address below.


17. Changes to This Policy

We may update this Privacy Policy from time to time.

Changes will be posted on this page with an updated “Last updated” date. Where a change materially affects how we process your personal data, we will notify account holders by email.


18. Contact

If you have questions about this Privacy Policy or data protection matters, contact:

József Tar e.v. (sole trader)
Zápolya utca 16. 1/a, 2120 Dunakeszi, Hungary
Email: support@vibe-vaults.com