Privacy Policy

Last updated: 24 July 2026

Vibel (“Vibel,” “we,” “us”) provides an operations and analytics platform for Shopify merchants. This policy explains what data we collect, why, how long we keep it, and the rights you and your customers have over it. It applies to the Vibel app, its dashboard, and getvibel.com.

Who this applies to

Vibel is installed by a merchant (“you,” “the merchant”) on a Shopify store. In most cases you are the data controller for your store and customer data, and Vibel is a data processor acting on your instructions. For account and billing data about you directly, Vibel (operated by HAVA EXPORT B.V., registered in the Netherlands) is the controller.

What we collect

Account data: your name, email, and store domain, used to create and secure your Vibel account.

Store and commerce data: read via the Shopify API under the scopes you approve at install, orders, products, inventory, fulfillments, and the customer fields needed for order and shipping analytics (name, email, address, order history). We do not request scopes beyond what the product needs.

Connected-tool data: if you optionally connect Klaviyo, Meta, Google Ads, GA4, Search Console, TikTok, Pinterest, Stripe, AfterShip, Gorgias, Zendesk, Monday, or QuickBooks Online, we read performance, ticket, or accounting data from that tool, using the access you grant, solely to power your dashboard, watchers, and reports. We do not push your Shopify or customer data into these tools, we only read from them.

Meta (Facebook) Ads:when you connect Meta, we use the Marketing API to read the list of ad accounts you manage (so you can pick which one to connect) and that account's performance data (spend, impressions, clicks, conversions, and ROAS), shown only to you inside your own dashboard. Your Meta access token is stored encrypted in our secrets vault, never exposed to the browser or to other users, and deleted when you disconnect the source.

TikTok Shop:when you connect TikTok Shop, we read your shop's order information (which can include a buyer's name, delivery address, and contact details where TikTok provides them), product catalog, fulfillment and logistics status, returns and refunds, and settlement/payout data, using read-only API scopes. This data is used solely to show you your own operations dashboard, alerts, and reports. It is stored encrypted at rest in the EU, is never used for advertising, profiling, or model training, is never sold or shared with third parties beyond the subprocessors listed below, and is deleted when you disconnect TikTok Shop or delete your account. Your TikTok Shop access token is stored encrypted in our secrets vault and removed immediately on disconnect.

Usage data: log-in activity, feature usage, and error diagnostics, used to operate and improve the product. We record approximate sign-in location signals to protect accounts against abuse.

Content you send us: if you use the AI assistant or ask-anything bar, the prompts you write and the store data needed to answer them.

How we use it

To provide the service: compute your metrics, run the watcher engine, generate the priority feed, drafts, and digests, and respond to support requests. We do not sell personal data, and we do not use your data to train third-party AI models. AI processing (Anthropic's Claude API) is used only to rank, summarize, or draft content on your data; Anthropic does not train on data sent through its API.

How we protect your data

We apply the following safeguards to all merchant data, and in particular to sensitive data such as access tokens, API keys, and data read from your connected tools:

Encryption in transit: all traffic between your browser, Vibel, and every connected platform uses TLS (HTTPS); we make no unencrypted requests.
Encryption at rest: all stored data is encrypted at rest in our managed database (Supabase/PostgreSQL). OAuth tokens, refresh tokens, and API keys are additionally stored in an encrypted secrets vault, referenced only by opaque ids, decrypted server-side at the moment of an API call, and never sent to the browser, logged, or exposed to other users.
Tenant isolation:every table is protected by database row-level security, so one merchant's data can never be read by another merchant's account.
Least privilege: we request only read-only scopes from connected platforms, and only the narrowest scopes needed for the features you use.
Access control: production data access is restricted to authorized personnel for support, security, and legal compliance only, and is logged.
Deletion: disconnecting a source deletes its stored credentials immediately; uninstalling the app or deleting your account triggers deletion of your stored data (see Retention below).
Incident response: if a breach affects your personal data, we will notify you and the competent authorities without undue delay, in line with GDPR requirements.

Google user data (GA4 & Search Console)

Vibel's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect Google Analytics 4 (scope analytics.readonly) or Google Search Console (scope webmasters.readonly), we read only aggregated reporting data (sessions, engagement, conversions; query impressions, clicks, and positions) to display it in your own dashboard. This data is used solely to provide the analytics features you see; it is never used for advertising, never sold, never transferred to third parties except the subprocessors listed below as needed to run the service, and never used to train AI models. No human reads this data except with your consent, for security or abuse investigation, or where required by law. Your Google OAuth tokens are protected exactly as described above (encrypted vault, server-side only) and are deleted when you disconnect Google or uninstall Vibel; stored Google reporting data is deleted with your account.

Legal basis (GDPR)

Where GDPR applies, we process merchant account data under contract (providing the service you signed up for) and legitimate interest (product security and improvement). Store and customer data read through your connected tools is processed on your instructions as processor, under the contract between you and your own customers; you remain responsible for your own lawful basis to share that data with us.

Data processing agreement

If your business needs a formal Data Processing Agreement under GDPR Article 28 for your own procurement or compliance review, see our Data Processing Agreement, which sets out the terms above in contract form, and our sub-processor list.

Retention

Account and store data are retained for as long as your Vibel account is active. Uninstalling the app or deleting your account triggers deletion of your stored data as described below and in our Security page. Audit and billing records are kept longer where we have a legal or accounting obligation to do so.

Subprocessors

SubprocessorPurposeLocation
SupabaseDatabase, authentication, encrypted secrets vault, file storageEU (Germany) and US
VercelApplication hosting and edge networkUS
AnthropicAI processing (Claude API) for ranking, summaries, and draftsUS
ResendTransactional email (password reset, digests, alerts)US

We do not share personal data with the third-party connectors listed above (Klaviyo, Meta, etc.); those are sources you choose to read from, not recipients of your Shopify data.

International transfers

Some subprocessors operate in the United States. Where we transfer personal data originating in the EEA or UK to the US, we rely on Standard Contractual Clauses or an equivalent safeguard maintained by that subprocessor.

Shopify GDPR webhooks

As a Shopify app, Vibel implements Shopify's mandatory compliance webhooks:

customers/data_request:we log the request against the relevant store so you, the merchant, can fulfil your customer's access request; Vibel holds only order-linked fields (name, email, address, order history), not a separate customer profile.

customers/redact:we delete the stored customer's personal data (matched by customer ID or email) from our customer records and derived per-customer views for that store.

shop/redact:sent by Shopify 48 hours after uninstall; we delete that store's order data, product data, customer records, and derived customer projections, and mark the connection disconnected.

Cookies

Vibel's own app and marketing pages set only the session cookie required to keep you signed in (via Supabase Auth). We do not set third-party advertising or cross-site tracking cookies on getvibel.com or in the app. If you connect an analytics or ad source (e.g. GA4, Meta), any cookies on your own storefront are set by that provider under your own configuration, not by Vibel.

Your rights

If you are in the EEA, UK, or a jurisdiction with similar law, you may request access, correction, deletion, or export of your account data, or object to or restrict certain processing. For data about your store's customers, please route the request through your own store, since you are the controller of that data; contact us if you need our help fulfilling it. To exercise rights over your own Vibel account data, contact us below.

Merchant responsibilities

You are responsible for having a lawful basis to share your customers' data with Vibel and for your own privacy notice to your customers. Disconnecting a source or uninstalling the app stops further access and triggers deletion as described above.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the date above; continued use after an update means you accept the revised policy.

Contact

Questions about this policy or a data request: post@stephancolen.nl.

Back to sign in