Privacy policy
What Vibeful processes, why it processes it, and how to ask for access, correction, deletion or a review.
On this page
Responsibility and contact
The Privacy Officer is the person responsible for privacy requests at Vibeful. Use the legal contact form linked below; no account or prior email conversation is required. Requests are stored in a restricted owner queue. Vibeful Team’s authorized business postal and telephone contact is available on the legal contact page. The public brand is not a claim of incorporation.
For customer-directed workspace data, the customer determines the permitted business purposes and Vibeful processes it to provide the service. Vibeful is responsible for its own account administration, security, billing and requests handling. These roles do not remove anyone’s legal duties.
Information and purposes
Account information includes your email, account name, workspace memberships, hashed password if configured, sign-in sessions and agreement acceptance records. We use it to authenticate users, manage access, maintain the service and document agreements.
Workspace information includes business profiles, publicly sourced business/contact information, source URLs and research, consent records, drafts, sent messages, routed replies, suppression records, campaign activity and settings. We process it for customer-authorized research and communications, troubleshooting and preventing unwanted contact. AI may classify or score business prospects; users must review outputs before decisions or sending.
Connected mailbox credentials are encrypted before storage and used to operate the connection. Legal requests contain your reply address, category and description, plus processing status and dates. Do not include passwords, card numbers, government identifiers or unrelated confidential information.
Technical data and payments
Cloudflare processes request information such as IP addresses, timestamps, requested URLs and security signals to deliver and protect the service. Application logs may contain errors and operational context. Short-lived keyed hashes support request-rate limits; these are not advertising identifiers. These are different from an advertising profile; hosting still involves personal-information processing.
For payments, Stripe receives payment and billing details through its hosted interfaces. Our server uses payment references, status, amount and related billing information; support certificates can use the supplied name. Raw card details do not pass through our application server. Payment and support records are not anonymous simply because the card form is provided by Stripe.
Sources and lawful use
Information comes from you, authorized workspace users, connected email systems, public business sources and service providers. We use information for the purposes explained when collected or another lawful purpose. Where consent is required, it must be meaningful and appropriate to the data and use.
Accepting terms is not marketing consent. We do not enroll legal-request submitters into marketing. You may withdraw consent subject to lawful limits and notice of any effect on requested services. Public business details and purchased data are not automatically exempt from privacy or anti-spam requirements.
Providers, AI and locations
Cloudflare hosts the application and storage and provides Workers AI where configured. Anthropic may process prompts and submitted content when configured. Your chosen email provider delivers messages; Stripe handles payment services. Personnel and providers receive access only for their assigned functions. We may disclose information when legally required or to protect rights and security as permitted by law.
Processing may occur outside your province or Canada, where different laws and lawful authority-access rules apply. No Canada-only residency is promised. Before regulated or sensitive processing, agree on required locations, provider terms, safeguards and any required privacy impact assessment.
We do not sell customer-submitted workspace content or legal requests to data brokers or use them for targeted advertising. We do not use customer content to train a Vibeful foundation model. External AI providers have their own retention and data-use terms; this policy does not claim that all providers have zero retention or never train on any data. Confirm the applicable provider arrangement before submitting sensitive material.
Cookies and device storage
The authenticated workspace uses an essential HttpOnly session cookie with a 30-day maximum age. Sign-out clears that cookie. Language preferences and the separate creative site’s theme, games and calculator preferences may remain in browser storage until cleared. Payment pages may use Stripe fraud-prevention technologies.
The current public business pages do not include advertising trackers or optional analytics scripts. If optional tracking is introduced, it must remain off until any required choice is obtained. See the cookie policy for practical controls.
Retention and deletion
We retain active account and workspace data for the requested service and documented legal or security needs. There is no universal automatic deletion deadline for every workspace record. On closure or a verified deletion request, we assess and remove or de-identify data no longer needed, explaining lawful exceptions.
Authentication sessions expire after 30 days; expired sessions and old sign-in tokens are cleaned by scheduled maintenance. Daily abuse-prevention hashes on the request form are cleared on subsequent submissions after the day changes. Suppression records may need to remain to prevent unwanted contact.
Billing, agreement, complaint and incident records may be retained for applicable accounting, limitation, dispute or incident-recordkeeping requirements. Backups and provider systems may follow separate deletion cycles. We do not promise immediate erasure from every backup or external system. A customer processing schedule should define its required retention and return/deletion process.
Your rights and complaints
Depending on applicable law, you may request access, correction, deletion, a copy or portability of eligible information, withdrawal of consent, or information about automated processing and human review. Use the legal contact form; we may verify identity proportionately without routinely requiring government ID. A rights request is not automatically a command to delete another customer’s data.
We respond within the time required by applicable law, generally 30 days for Canadian access requests, and explain any lawful extension, fee, refusal or retained records and available recourse. You may complain to the Privacy Officer and to the Office of the Privacy Commissioner of Canada or your provincial authority, including Quebec’s Commission d’accès à l’information where applicable.
Safeguards, incidents and changes
Access controls, workspace isolation, encrypted credentials, hashed passwords and transport encryption help protect information. No security guarantee is absolute. Suspected incidents are assessed, documented and escalated for notification and mitigation where required.
The service is intended for adults and business use. Contact us if a child’s information was submitted improperly. We will update this policy when practices materially change and obtain new consent where required. The date identifies the current policy; it does not certify that every legal obligation has been satisfied.