Privacy Policy
Last updated: 29 July 2026
1. Who is responsible for your data
Vascosupport@tryvibelarp.com
This operator is the controller of personal data processed through VibeLarp. Contact the address above for privacy requests.
2. Personal data we process
- Account data: email address, account identifier, email-confirmation state, and password hash managed by Supabase. We never receive your plain-text password.
- Subscription data: PayPal payer and subscription identifiers, billing email, plan, currency, status, and billing-period dates. We do not store full card or bank-account details.
- Security data: IP-derived hashed rate-limit identifiers, request timing, bot-verification results, session data, and limited technical logs needed to prevent abuse.
- Communications data: delivery status and content of essential account, security, and subscription notifications.
- Dashboard data: editable scenarios, uploaded display images, and tutorial preferences are currently stored locally in your browser, not in your VibeLarp account.
3. Why we use the data and our legal bases
- To create your account, provide paid access, and manage your subscription: performance of our contract with you.
- To prevent credential attacks, payment abuse, fraud, and service disruption: our legitimate interest in keeping the service and its users secure.
- To retain billing or transaction records when required: compliance with legal, accounting, and tax obligations.
- To send essential account, security, and subscription messages: performance of the contract, security interests, or legal obligations as applicable.
VibeLarp does not sell personal data and currently does not use it for third-party behavioural advertising.
4. Service providers and recipients
We use Supabase for authentication and database services, PayPal for subscriptions and payments, Upstash for abuse rate limiting, Cloudflare Turnstile for bot prevention, Resend for transactional billing email when configured, and our hosting and authentication email providers for delivery of the service. These providers process only the data needed for their role and may also act as independent controllers for parts of their own services, such as PayPal's legal and fraud obligations.
We may disclose information where required by law, to protect legal rights, or in a corporate reorganisation subject to appropriate safeguards.
5. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision or safeguards such as the European Commission's Standard Contractual Clauses. You may contact us for information about the safeguard relevant to your data.
6. Retention
- Account and membership data is kept while the account is active and normally deleted or anonymised within 30 days after a valid account deletion request, except where retention is legally required.
- Billing and transaction records are retained for the period required by applicable accounting, tax, chargeback, and anti-fraud rules.
- Rate-limit records expire with their short security windows. Operational security logs are normally retained for no more than 30 days, unless an incident requires longer preservation.
- Browser-local dashboard data remains until you reset it, clear site data, or remove the browser profile.
Backups may retain deleted data for a limited rolling period before automatic overwrite and are not used to restore individual deleted records.
7. Cookies and browser storage
VibeLarp uses strictly necessary authentication and security cookies. Browser storage keeps dashboard customisation and tutorial state on your device. PayPal and Cloudflare may set or access technical data when their checkout or security features are used. If optional analytics or marketing technology is added later, it will require a separate notice and consent controls where legally required.
8. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent where consent is the legal basis. We may need to verify your identity before acting on a request.
You may also lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), or with the competent authority where you live or work.
9. Security and automated protection
We use access controls, row-level database security, encrypted transport, bot checks, hashed rate-limit identifiers, and least-privilege server credentials. No internet service can promise absolute security. Automated abuse controls may temporarily reject a request, but they do not make decisions that produce legal or similarly significant effects.
10. Children
VibeLarp is intended only for people aged 18 or older. Contact us if you believe a child has provided personal data.
11. Changes and contact
We may update this policy when the service or legal requirements change. Material changes will be communicated through the service or by email where appropriate. Send questions or rights requests to the privacy contact listed in section 1.