Privacy Policy
Last updated: January 2025
At VibeIndex, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website. By accessing or using VibeIndex, you consent to the data practices described in this policy.
1. Information We Collect
We collect several different types of information for various purposes to provide and improve our service to you:
Personal Data
While using our service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. This may include:
- Email address (when you create an account or subscribe to newsletters)
- Name and display name (for user profiles)
- Profile picture and bio (optional)
- Social media account information (if you connect via OAuth)
Usage Data
We automatically collect certain information when you visit our service:
- Device information (browser type, version, operating system)
- IP address (anonymized for voting, full IP for security)
- Pages visited, time spent on each page, and click behavior
- Referring website and search terms used to find us
- Date and time of each visit
Tracking & Cookies Data
We use cookies and similar tracking technologies to track activity on our service and hold certain information:
- Session cookies (to keep you logged in)
- Preference cookies (language, theme, city selection)
- Analytics cookies (PostHog, Google Analytics)
- Advertising cookies (Google AdSense)
- Browser fingerprinting (for anonymous voting integrity)
Voting Data
When you vote ("Vibe") on events, we collect:
- Hashed IP address (irreversible, for duplicate prevention)
- Browser fingerprint ID (from FingerprintJS)
- Vote timestamp
- Event ID that was voted on
- Browser user agent (for fraud detection)
Event Submission Data
If you submit events as a promoter, we collect:
- Contact email and phone number
- Business name and tax ID (if applicable)
- Event details (title, description, location, dates)
- Images and promotional materials you upload
2. How We Use Your Information
VibeIndex uses the collected data for various purposes:
- To provide, maintain, and improve our service
- To personalize your experience based on your preferences
- To communicate with you about service updates, events, and promotional content
- To monitor and analyze usage trends and patterns
- To detect, prevent, and address technical issues and fraudulent activity
- To maintain voting integrity and prevent manipulation
- To comply with legal obligations and enforce our terms
- For business operations, including event moderation and promoter verification
- To send you marketing communications (with your consent)
- To conduct research and development to improve our algorithms
- To serve relevant advertisements based on your interests
3. Legal Basis for Processing (GDPR & LGPD)
We process your personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose
- Contract: Processing is necessary for a contract we have with you, or to take steps at your request before entering into a contract
- Legal Obligation: Processing is necessary for us to comply with the law
- Vital Interests: Processing is necessary to protect someone's life
- Public Task: Processing is necessary for us to perform a task in the public interest
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party (unless there is a good reason to protect your personal data which overrides those interests)
4. How We Share Your Information
We may share your information in the following situations:
- Service Providers: We share data with third-party companies that perform services on our behalf (hosting, analytics, email delivery)
- Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business
- Legal Requirements: When required by law, subpoena, or other legal process
- Protection of Rights: To protect the rights, property, or safety of VibeIndex, our users, or others
- With Your Consent: When you have given explicit consent to share your information
- Aggregated Data: We may share anonymized, aggregated data that cannot be used to identify you
- Public Information: Event information and vote counts are public and displayed to all users
5. Third-Party Services
We use the following third-party services that may collect and process your information:
Infrastructure & Database
- Supabase - Database hosting and authentication (https://supabase.com/privacy)
Analytics & Tracking
- PostHog - Product analytics and user behavior tracking (https://posthog.com/privacy)
- FingerprintJS - Browser fingerprinting for voting integrity (https://fingerprint.com/privacy-policy/)
Advertising
- Google AdSense - Display advertising with personalized ads (https://policies.google.com/privacy)
Communication
- Email service providers for transactional and marketing emails
These third parties have their own privacy policies. We encourage you to read them to understand how they collect and use your information.
6. International Data Transfers
Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. If you are located outside Brazil and choose to provide information to us, please note that we transfer the data, including Personal Data, to Brazil and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
7. Your Data Protection Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: Request that we limit the processing of your data
- Right to Data Portability: Request transfer of your data to another organization or directly to you
- Right to Object: Object to our processing of your personal data
- Right to Avoid Automated Decisions: Not be subject to decisions based solely on automated processing
- Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your data
- Right to Lodge a Complaint: File a complaint with your local data protection authority
To exercise these rights, please contact us at contact@vibeindex.com.br. We will respond to your request within 30 days.
8. Brazilian Data Protection Rights (LGPD)
If you are a Brazilian resident, you have specific rights under the Lei Geral de Proteção de Dados (LGPD):
- Confirmation of the existence of processing
- Access to your data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary or excessive data
- Portability of data to another service provider
- Deletion of data processed with your consent
- Information about public and private entities with which we share data
- Information about the possibility of refusing consent and the consequences
- Revocation of consent
For LGPD-related inquiries, contact our Data Protection Officer at contact@vibeindex.com.br
9. Data Retention
We retain different types of data for different periods:
- Account Data: Retained as long as your account is active, plus 90 days after deletion
- Voting Data: Anonymized hashes retained indefinitely for statistical integrity
- Analytics Data: Aggregated data retained for up to 5 years
- Security Logs: Retained for 180 days for security and fraud prevention
- Legal Hold: Data subject to legal obligations retained until such obligations are fulfilled
- Marketing Data: Until you unsubscribe or withdraw consent
After retention periods expire, we securely delete or anonymize your data.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track the activity on our service and hold certain information. Cookies are files with small amounts of data which may include an anonymous unique identifier.
Essential Cookies
Required for the website to function properly. These cannot be disabled.
Session cookies, authentication tokens, security cookies
Functional Cookies
Enable enhanced functionality and personalization.
Language preference, theme selection, city selection
Analytics Cookies
Help us understand how visitors interact with our website.
PostHog analytics, page view tracking, user journey analysis
Advertising Cookies
Used to deliver personalized advertisements.
Google AdSense cookies, ad performance tracking
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service. To manage cookies, visit your browser settings or use our cookie preference tool (coming soon).
11. Do Not Track Signals
We do not currently respond to Do Not Track (DNT) signals because there is no industry standard for DNT compliance. However, you can control tracking through your browser settings and by opting out of third-party tracking services directly.
12. Data Security
The security of your data is important to us. We implement industry-standard security measures to protect your personal information:
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
In the event of a data breach affecting your personal information, we will notify you within 72 hours in compliance with LGPD and GDPR requirements.
13. Children's Privacy
Our service is not directed to children under the age of 13 (or 16 in some jurisdictions). We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent, we will take steps to remove that information from our servers within 48 hours.
14. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
Note: We do not sell personal information to third parties.
To exercise your CCPA rights, contact us at contact@vibeindex.com.br with "CCPA Request" in the subject line.
15. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any material changes by:
- Sending an email notification (if you have an account)
- Displaying a prominent notice on our website
- Updating the "Last updated" date at the top of this policy
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Continued use of our service after changes constitutes acceptance of the revised policy.
16. Contact Us & Data Protection Officer
If you have any questions about this Privacy Policy, want to exercise your data protection rights, or have concerns about how we handle your data, please contact us:
Email: contact@vibeindex.com.br: contact@vibeindex.com.br
Subject line: "Privacy Inquiry" or "Data Protection Request"
We will respond to all legitimate requests within 30 days
Our Data Protection Officer can be reached at the same email address for LGPD and GDPR-specific matters.