Privacy Policy
1. Who we are
The data controller for the Vybridge platform (vybridge.com) is Volodymyr Momot. Privacy and support contact: support@vybridge.com.
Vybridge is the name of the platform. There is currently no separate company or trade licence established specifically as “Vybridge”, so these pages do not state a Vybridge company registration number, tax number, or VAT number. No Data Protection Officer has been formally appointed. No registered business address is published here.
2. Data we process
- Account data — name, email, password (stored hashed), role (advertiser or publisher), profile country. Country is profile information, not a tax engine.
- Authentication — session identifier in the
vybridge_sessioncookie (HttpOnly, SameSite=Lax, Secure in production, up to 7 days). - Publisher website data — site URL/domain, slot geometry and settings, listings, availability, pricing, and integration status.
- Stripe — Stripe processes cards and payout accounts. Vybridge stores Stripe identifiers and limited status (for example connected-account country, payouts-enabled flags). Vybridge does not store full card numbers, IBANs, bank account numbers, or identity-document images.
- Bookings and payments — dates, targeting, quoted amounts, publisher price, platform fee, advertiser total, booking status, payment status, refund intents, and related events.
- Creatives — uploaded advertising images and metadata needed to review and serve them. Image files are stored with Cloudinary.
- Serving and measurement — for booked website placements, a minimal ledger of booking/serving attribution, impression or click, timestamp, and resolved country when available. This Booking measurement ledger does not persist raw visitor IP addresses.
- IP geolocation — visitor country may be derived from IP using MaxMind GeoLite data for targeting/eligibility. That IP is held in memory for the request and is not persisted by the GEO process.
- Legacy Deal clicks — a historical Deal click record may still store visitor IP and user agent for that older path. It is not used to build advertising profiles.
- Referral attribution — referral codes, website attribution history, assist cookie
vyb_ref(HttpOnly, SameSite=Lax, first-party, used after a referral link), and reward ledger rows when recorded. We process this data to attribute website referrals, administer the Affiliate Program, prevent fraud and abuse, and meet legal and compliance obligations. Stripe processes payout-account data if you complete Connect onboarding; that processing is separate from whether a referral reward is paid. - Support — emails you send to support@vybridge.com.
- Security logs — request metadata needed to operate and protect the service.
- Display preference — preferred display currency in
localStorageundervybridge.displayCurrency. Charges remain EUR.
3. Why we process it
We use this data to create accounts, run the marketplace, quote and book placements, collect advertiser payments, review creatives, serve ads on publisher sites, measure serving, settle eligible publisher amounts, attribute website referrals, prevent fraud, and communicate about your bookings. We do not sell personal data. We do not use third-party advertising pixels or cross-site behavioral advertising cookies on Vybridge pages.
4. Stripe
Advertiser Checkout and publisher Connect onboarding run on Stripe. Stripe’s processing is described in Stripe’s Privacy Policy. Stripe Checkout, when you pay, is Stripe-hosted and may set Stripe cookies on Stripe’s domains. That is not Vybridge advertising tracking.
5. Cookies and local storage
Vybridge currently sets:
vybridge_session— essential sign-in.vyb_ref— first-party referral assist after using a referral link (not a third-party ad cookie).
Publisher sites that install the Vybridge widget may use the widget’s own localStorage for UI state on that site (for example closing a creative). That happens on the publisher website, not as a Vybridge.com advertising cookie.
Vybridge.com pages do not load Google Analytics, Meta Pixel, or similar advertising trackers. Because non-essential third-party advertising tracking is not present on Vybridge pages, this policy does not add a marketing-cookie banner. If that technical situation changes, a consent mechanism would be required before those trackers load.
6. Processors
- Stripe — payments and Connect.
- Cloudinary — creative image hosting.
- Resend — transactional email when configured.
- Cloud hosting for the application.
- MaxMind GeoLite — in-memory IP-to-country lookup.
These providers may process data in countries other than yours. Where that involves an international transfer, it happens as part of using those processors. This policy does not publish a separate list of Standard Contractual Clauses.
7. Retention
Account data is kept while the account is active. You may delete your account from the profile page when you have no active bookings or deals in progress. Financial transaction records may be retained as required by tax and accounting law even after account deletion. No separate day-count retention schedule for logs, measurement events, or support mail is published here.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict personal data, or to object to certain processing. You can delete an eligible account in-product. Other requests: support@vybridge.com. We may need to verify the request. If applicable law gives you the right to complain to a data-protection authority, that right is not waived by this policy.
9. Children
Vybridge is a commercial advertising marketplace. It is not directed at children.
10. Changes
If processing changes in a material way, we will update this page and the effective date.