Privacy Policy
Last updated:
VibeLink ("VibeLink," "we," "us," or "our") operates the VibeLink mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you use our Service.
By creating an account or using the Service, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree, please do not use the Service.
This Privacy Policy forms part of our Terms of Service.
1. Accountability
VibeLink Inc. ("VibeLink") is the entity accountable for your personal information and the controller of your personal data. VibeLink Inc. has designated a Privacy Officer who is accountable for our compliance with this Privacy Policy and applicable privacy legislation. You may contact the Privacy Officer at privacy@vibelinkapp.com, or by mail at the address in Section 19.
2. Information We Collect
2.1 Information You Provide Directly
Required information (necessary to create and maintain your account):
- Full name
- Email address
- Date of birth
- Gender
- Liveness verification selfie — during onboarding we ask you to take a short selfie, which is compared against your profile photo to confirm that you are a real person and that your profile is your own. The selfie is stored in a private, non-public location and is retained for the lifetime of your account (see Section 6).
Optional profile information (you may choose to provide this to enhance your experience):
- Phone number
- Profile photos
- A short bio
- Your city
- Social media handles — Instagram, Facebook, TikTok, and LinkedIn. These are optional, are displayed on your public profile if you provide them, and can be edited or removed at any time in your profile settings.
Sensitive personal information: The liveness verification selfie described above is sensitive personal information. Because we compare it against your profile photo to confirm that you are a real person, we are processing your facial image for the purpose of identifying you — which makes it biometric data under laws including the GDPR. We do not create or store a faceprint, face template, or any other mathematical representation of your face: the comparison is performed on the two images and only the images are retained. See Section 5 for the enhanced safeguards applied to this data.
Other information you provide:
- Messages and communications with other users through the Service
- Content you post, including activity descriptions and comments
- Feedback, support requests, or correspondence you send to us
2.2 Information from Third-Party Authentication Providers
When you create an account using a third-party provider (Google, Apple, Meta/Facebook, X/Twitter, or LinkedIn), we may receive:
- Your name and email address
- Profile photo
- Account identifier
We only receive information that you have authorized the third-party provider to share. We do not access your contacts, friend lists, or private messages on these platforms.
2.3 Information Collected Automatically
When you use the Service, we automatically collect:
- Device information: Device type, operating system, unique device identifiers, and mobile network information. Two of these identifiers are stored and linked to your account: a push notification token issued by Apple or Google, which lets us deliver notifications to your device, and an analytics device identifier generated by PostHog, which distinguishes one device from another. Neither is an advertising identifier, and neither is used for tracking or shared with advertisers.
- Usage data: Features used, actions taken, time spent, and interaction patterns
- Log data: IP address, browser type and version, access times, and referring URLs
- Crash and error diagnostics: Crash reports, stack traces, and error events, collected through Sentry. These events are scrubbed of personal information before they are transmitted, so they are not linked to your identity.
- Product-interaction analytics: Which features you open and which actions you take in the app, collected through PostHog and keyed to your account identifier. We use this to understand how the Service is used and to improve it.
- Location data: With your permission, we collect precise GPS location data to show you nearby activities. You may disable location services through your device settings at any time. When location services are disabled, we may infer approximate location from your IP address.
- Approximate location stored on your profile: during onboarding we convert your device location into a city name (for example, “Toronto”) and store that city on your account. This is separate from the approximate location we may infer from your IP address: the city is saved to your profile and kept for as long as your account exists. It is display-only — it is not used to filter or rank the activities you see.
2.4 Tracking Technologies — Mobile App vs. Website
The VibeLink mobile app and the VibeLink marketing website are two different surfaces, and they behave differently. We describe each one separately below so there is no ambiguity about which applies to you.
In the VibeLink mobile app. The app performs no third-party tracking. It uses no advertising identifiers (no IDFA on iOS, no Advertising ID on Android), runs no advertising SDKs, and shares no personal information with data brokers or advertising networks. This is what the App Store privacy label's "Used for tracking: No" declaration refers to — that declaration scopes to the app binary.
On this website (vibelinkapp.com). Our marketing website — including this page — uses the following third-party tags to measure the effectiveness of our pre-launch advertising and to understand site traffic. These apply to vibelinkapp.com only. They do not run in, and collect nothing from, the VibeLink mobile app.
- Meta Pixel (Meta Platforms, pixel ID 772210678718536): measures ad campaign performance and website conversions. You may manage your ad preferences through your Facebook account settings.
- Google Analytics / Google tag (Google LLC, delivered via googletagmanager.com, Google Analytics 4 measurement ID G-1B079QEZ8C): measures page views, traffic sources, and site interactions. You may opt out at tools.google.com/dlpage/gaoptout.
- Essential cookies: maintain session state and authentication.
You may control cookies through your browser settings. Disabling non-essential cookies will not affect the core functionality of the Service.
3. Legal Basis and Purposes for Processing
We collect and use your personal information for the following purposes and on the following legal bases:
| Purpose | Legal Basis (PIPEDA) |
|---|---|
| Creating and managing your account | Contractual necessity |
| Facilitating connections and activities between users | Contractual necessity |
| Sending transactional communications | Contractual necessity |
| Responding to support requests | Contractual necessity |
| Processing a reinstatement fee payment, where a suspended account holder chooses to pay one | Contractual necessity |
| Verifying your identity with the liveness selfie | Explicit consent |
| Collecting and using precise location data | Explicit consent |
| Sending marketing communications | Consent (opt-in) |
| Push notifications | Consent (opt-in) |
| Analytics and service improvement | Legitimate interest |
| Preventing fraud, abuse, and security incidents | Legitimate interest |
| Complying with legal obligations | Legal requirement |
We limit collection to information that is necessary for the identified purposes (PIPEDA Principle 4 — Limiting Collection).
4. How We Share Your Information
4.1 With Other Users
Your profile information (name, photos, and any optional details you have chosen to share) is visible to other VibeLink users. Activity descriptions and comments you post are visible to users who can view that activity.
4.2 With Service Providers
We share information with the following third-party service providers, who assist us in operating the Service:
- Supabase — database, authentication, and file storage; our primary region is Toronto, Canada.
- Twilio — SMS delivery for phone-number verification; receives your phone number only.
- AWS Rekognition — face detection and face comparison for the onboarding liveness selfie check; receives the selfie image and your profile photo for comparison.
- Resend — transactional email delivery; receives your email address and the content of the message being sent to you.
- Sentry — crash and error reporting; events are scrubbed of personal information before they are transmitted.
- PostHog — product analytics, keyed to your account identifier.
- Stripe — payment processing, used only when a suspended account holder chooses to pay a reinstatement fee to have their account restored. Stripe receives your email address, your name, and your account identifier so that it can create the checkout page and tell us which payment belongs to which account, and it collects your payment card details directly on its own checkout page. VibeLink never receives or stores your card number. VibeLink remains free to download and use, and Stripe is not involved in any other part of the Service.
- Meta Platforms and Google LLC — website-only advertising and analytics measurement on vibelinkapp.com, as described in Section 2.4. These do not run in the mobile app.
All service providers are contractually obligated to use your information only for the purposes we specify and to maintain appropriate security safeguards.
4.3 For Legal Reasons
We may disclose your information if required to do so by law, or if we believe in good faith that such disclosure is necessary to:
- Comply with a legal obligation, court order, or government request
- Protect the rights, property, or safety of VibeLink, our users, or the public
- Investigate or prevent fraud, security issues, or technical problems
- Enforce our Terms of Service
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via the Service or email before your information becomes subject to a different privacy policy.
4.5 What We Do Not Do
- We do not sell your personal information to third parties.
- We do not share your personal information with third parties for their own marketing purposes.
- We do not allow third parties to use your data to train machine learning or artificial intelligence models.
5. Safeguards for Sensitive Personal Information
The liveness verification selfie is the one category of sensitive personal information we collect (see Section 2.1). We apply enhanced protections to it:
- Explicit consent: The selfie is captured during onboarding with your affirmative consent, and it is the only purpose for which we ask you to take it.
- Never public: The selfie is stored in a private location that is not readable by other users. It is never shown on your profile, in the feed, or anywhere else in the app.
- No faceprint retained: Verification compares the selfie against your profile photo. We do not create or store a faceprint, face template, or other mathematical representation of your face.
- Access controls: Access is restricted to authorized personnel on a need-to-know basis.
- Encryption: Sensitive personal information is encrypted at rest and in transit.
- No secondary use: The selfie is used solely to verify that you are a real person. It is not used for advertising, analytics, profile display, or any other secondary purpose.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Active account data | As long as your account remains active |
| Inactive account data | 12 months after last login, then notified before deletion |
| Data after account deletion | Permanently deleted within 30 days, apart from the de-identified records described in the row below |
| Ratings and past activities after account deletion | Retained indefinitely in de-identified form: your name and any link to you are removed, and what remains is the rating or the activity record itself |
| Usage and analytics data | Anonymized within 24 months |
| Support correspondence | 2 years from resolution |
| Safety reports and moderation audit logs | 2 years from the date the report or log entry was created |
| Liveness verification selfie | Lifetime of your account; permanently deleted when your account is purged (day 30 after deletion) |
| Profile photo | Until you replace it or your account is purged (day 30 after deletion); the previous photo is deleted when you upload a new one |
| Payment and transaction records | 7 years (Canadian tax law) |
| Legal hold data | As required by legal proceedings |
When data is no longer needed, it is securely deleted or anonymized so that it can no longer be associated with you.
One exception to deletion, explained plainly. Ratings on VibeLink are a safety feature: other members rely on them when deciding whether to meet someone in person. If deleting an account also erased every rating that account had given or received, anyone could clear an unfavourable history simply by signing up again. So when your account is permanently deleted, we do not delete those records — we sever the link between them and you. Your name, profile and account identifier are removed, and what is left is a rating or a past activity that is no longer connected to any person. The same applies to activities you hosted: the activity record remains, with no host attached. These de-identified records are no longer personal information about you, and they cannot be traced back to you or used to rebuild your profile.
7. International Data Transfers
VibeLink is based in Canada. Our primary database and file storage are hosted with Supabase in the Toronto, Canada region. Your personal information may also be processed and stored in other countries where our service providers operate (including the United States) — for example, SMS delivery, transactional email, and the liveness selfie comparison described in Section 4.2 are handled by providers operating on United States infrastructure. If you are located in the European Economic Area or the United Kingdom, this means your personal information may transit through and be processed on United States infrastructure.
When your information is transferred outside of Canada, it may be subject to the laws of that jurisdiction. In such cases:
- We ensure that service providers are contractually bound to protect your information with safeguards comparable to those required under PIPEDA
- Where personal information of individuals in the European Economic Area or the United Kingdom is transferred outside those territories, we rely on the European Commission's Standard Contractual Clauses (SCCs) — and, for the United Kingdom, the UK International Data Transfer Addendum — as the legal basis for that transfer
- We conduct due diligence on service providers' privacy and security practices
- We inform you that foreign governments, courts, or law enforcement may be able to access your information under the laws of those jurisdictions
8. Your Rights Under Canadian Privacy Law (PIPEDA)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
- Access your information: Request a copy of the personal information we hold about you.
- Correct your information: Request correction of any inaccurate or incomplete personal information.
- Withdraw consent: Withdraw your consent at any time, subject to legal or contractual restrictions.
- Challenge compliance: File a complaint about our privacy practices.
- Know how your data is used: Request information about how your data has been used and to whom it has been disclosed.
To exercise any of these rights:
- Email: privacy@vibelinkapp.com
- In-app: Account Settings > Privacy > Data Request
Erasure. The primary way to have your personal information erased is the in-app Settings > Delete Account option. Deleting your account starts a 30-day recovery window: during that window you can restore the account simply by signing back in, and if you do not, your account and the personal information associated with it are permanently purged at the end of the window. Ratings you gave or received, and activities you hosted, are kept in de-identified form rather than deleted — stripped of your name and any link to you, for the safety reason explained in Section 6. See Section 6 for the full retention schedule.
We will respond within 30 days. If you are not satisfied, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the CCPA/CPRA:
- Right to know: Request details about personal information collected about you.
- Right to delete: Request deletion of your personal information.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out of sale/sharing: VibeLink does not sell or share your personal information as defined under the CCPA/CPRA.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at privacy@vibelinkapp.com or use the in-app privacy settings.
10. Marketing Communications and CASL Compliance
In accordance with Canada's Anti-Spam Legislation (CASL):
- We will only send you commercial electronic messages with your express opt-in consent.
- Every marketing message includes a clear unsubscribe mechanism.
- You may opt out at any time through the unsubscribe link, Account Settings > Notifications, or by contacting contact@vibelinkapp.com.
- Opting out of marketing will not affect transactional communications.
- We will process your opt-out request within 10 business days.
11. Push Notifications
With your consent, we may send push notifications including activity invitations, messages from other users, and marketing content (with separate opt-in). You may disable push notifications at any time through your device settings or in-app preferences.
12. Security
We implement commercially reasonable technical and organizational safeguards including:
- Encryption of data in transit (TLS) and at rest
- Access controls and authentication requirements
- Regular security assessments and vulnerability testing
- Employee training on data protection
- Secure server infrastructure with monitoring
- Incident response procedures
No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
13. Data Breach Notification
In the event of a data breach involving your personal information that creates a real risk of significant harm, we will:
- Notify affected individuals as soon as feasible
- Report the breach to the Office of the Privacy Commissioner of Canada
- Where the EU or UK General Data Protection Regulation applies, notify the competent supervisory authority within the 72-hour deadline set by GDPR Articles 33 and 34, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Maintain a record of every breach of security safeguards
- Take immediate steps to contain the breach and prevent recurrence
14. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. Age is checked at sign-up: you must enter your date of birth during onboarding, and an account that does not meet the 18+ requirement is not created. If we discover such collection, we will immediately terminate the account and permanently delete all associated information within 30 days, through the same purge process described in Section 6.
If you believe a minor has provided us with personal information, please contact us at privacy@vibelinkapp.com.
15. Third-Party Links and Services
The Service may contain links to third-party websites or services not operated by VibeLink. We are not responsible for the privacy practices of these third parties.
16. Data Portability
You may request a copy of your personal data in a structured, machine-readable format (e.g., JSON or CSV) by contacting privacy@vibelinkapp.com or through Account Settings > Privacy > Export My Data. We will fulfill your request within 30 days.
17. Deceased Users
Upon receiving verifiable proof of a user's death, VibeLink will deactivate the account and delete the user's personal information within 30 days, unless retention is required by law. Requests should be directed to privacy@vibelinkapp.com.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy, update the "Last updated" date, and notify you at least 14 days before changes take effect. Your continued use constitutes acceptance of the changes.
19. Contact Us
VibeLink Inc.
Attn: Privacy Officer
798 Richmond Street West, Apt 222
Toronto, ON M6J 3P3
Canada
Email: privacy@vibelinkapp.com
General inquiries: contact@vibelinkapp.com
If you are using the VibeLink app, you can also reach us from inside it at Settings > Send Feedback, which delivers your message directly to our team.
You may also file a complaint with the Office of the Privacy Commissioner of Canada:
Website: www.priv.gc.ca
Phone: 1-800-282-1376