Privacy
Last updated 2026-08-21
This policy describes what we collect, why, and for how long. It covers this website, the vibeplg application at app.vibeplg.com, and the analytics SDK our customers install on their own sites.
Two kinds of people are described here
Our customers are the people and companies with a vibeplg account. For their account data we are the controller.
The visitors of our customers' sites are measured by the SDK that our customer installed. For that data our customer decides what is collected and why; we process it on their behalf and under their instructions. If you are such a visitor and want your data removed, the fastest route is the site you were visiting — though you can also write to us and we will act on it.
What the SDK collects
Page views and custom events sent by the host application, batched in the browser and sent a few at a time.
A user identifier, when the host application calls identify() — typically the account id it already has for that person. Otherwise an anonymous identifier, and in cookieless mode nothing is stored in the browser at all.
With autocapture enabled: a click event for links and buttons, carrying the element's visible text and the link target. Form values and keystrokes are never captured — they are not collected and then filtered, they are never read.
What is derived from the request
At the edge, from the request itself rather than from anything the browser volunteers: country, region and city; browser, operating system and device class; language; the referring page and any campaign parameters on the URL.
IP addresses are stored. The client IP is recorded on each event row — it is what geography, rate limiting and abuse handling are derived from. We are telling you plainly because a privacy page that quietly omits this is the most common lie in this industry.
How long it is kept
Raw event rows, including the IP address, are deleted after 7 days on Free accounts.
On paid accounts raw rows are kept without an expiry, because row-level history is part of what the plan buys. That also means the storage clock does not run for you: if you want a shorter window, ask.
Aggregate daily rollups carry no personal data and are kept indefinitely on every plan.
Account data
For customers: an email address, the organisations you belong to and your role in them, and billing state held by our payment processor. Sessions are held in a cookie scoped to the application host and are never readable by another site.
This marketing website itself sets no cookies. If we enable our own analytics on it, it will run in cookieless mode — nothing stored in your browser.
Who else processes it
Only these, and only for what is listed:
Cloudflare — hosting, edge network, database, object storage.
Stripe — payments and subscription billing.
Your rights, and one honest limitation
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be erased.
A self-serve deletion control does not exist yet. It is specified and on the build list, and until it ships, erasure is handled by hand: write to the address on our contact page and we will confirm within 30 days. We would rather say this than describe a button you cannot find.
Changes
When this policy changes materially we will say so on this page and date it. The date at the top is the last change.