Legal

Privacy Policy

Your privacy is important to us. This policy explains how Vacancy Vibe collects, uses, and protects your personal data.

Last updated: July 25, 2026

1. Introduction

Vacancy Vibe is operated by Keystone Cognition Labs LLC, a limited liability company formed in the State of Georgia, United States ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service (the "Service").

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and a password if you sign up with one. We do not receive or store your card details — payments are handled by Stripe, and we keep only the customer reference and email Stripe returns to us.
  • Property Information: Property descriptions, images, addresses, calendar feed URLs, and booking platform details. Where you give us an address, we send it to our mapping provider to obtain coordinates.
  • Contact Lists: If you upload or import a list of your own past guests or contacts so the Service can email them on your behalf, that list includes other people's names and email addresses. Section 4.1 explains our respective responsibilities for it.
  • Social and Advertising Credentials: OAuth tokens and account information for connected social media and advertising platforms
  • Communications: Information you provide when contacting our support team

2.2 Information Collected Without an Account

Some parts of the Service work before you sign up, and they collect information too:

  • Free calendar scans: When you use the vacancy scanner we store the scan and its results, including the estimated revenue figures and sample posts we generate, plus the campaign parameters in the link that brought you. We store only a one-way hash of the calendar URL you paste, never the URL itself. If you give us an email address we store that too and send you the report and follow-up messages you can unsubscribe from at any time.
  • Contact form: The name, email address, and message you submit.
  • Advertising clicks: If you reach us by clicking one of our Google ads, we record the click identifier Google appends to the link so we can tell Google which clicks led to a signup. We delete these records after 90 days.

2.3 Information Collected Automatically

  • Usage Data: Pages visited, features used, and actions taken within the Service
  • Device Information: Browser type, operating system, IP address, and device identifiers
  • Cookies and Similar Technologies: See our Cookie Policy for details

2.4 Analytics, Session Recording, and Advertising

We want to be specific about this rather than leave it to the phrase "usage data":

  • Product analytics (PostHog): Records which pages and features you use, and creates a profile keyed to an identifier stored on your device.
  • Session recording (PostHog): Records a replay of on-screen activity — clicks, scrolling, and navigation — so we can see where people get stuck. Text on the page and anything you type are masked, so the replay does not capture your guests' details or the contents of forms.
  • Error monitoring (Sentry): Records diagnostic information when something breaks. It also records a masked replay of any session in which an error occurred, and of a small random sample of sessions (currently one in ten) regardless of errors. All text is masked in these replays.
  • Advertising measurement (Meta pixel): Meta receives a signal when a visitor signs up or starts a checkout. Meta is able to recognise the same browser on other websites that use its pixel, which means information about your activity is collected over time and across third-party sites. We do not send Meta your name or email address.

Analytics, session recording, and the Meta pixel load only after you accept cookies. See Section 4.1 of our Cookie Policy to change your choice at any time. Error monitoring runs regardless, because we rely on it to keep the Service working.

2.5 Information from Third Parties

  • Calendar data from integrated booking platforms (Airbnb, VRBO, etc.). Booking entries can contain a guest's name where the platform includes it. We store the entry as received, never display it, and replace the stored copy on each refresh; it is not used to generate content.
  • Profile information from connected social media accounts
  • Advertising performance data from Meta and Google for the campaigns you run through the Service

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Detect calendar vacancies and generate social media content
  • Post content to your connected social media accounts
  • Create and manage the advertising campaigns you configure in your own Meta and Google advertising accounts, and report back on how they performed
  • Send email to your own contacts on your behalf, where you have asked the Service to do so
  • Process payments and manage subscriptions
  • Send service-related communications and updates
  • Send marketing email about the Service, including the follow-up messages that go with a free scan. Every marketing message has an unsubscribe link.
  • Respond to your inquiries and provide customer support
  • Measure our own advertising, and understand which pages and features are used, so we can improve the Service
  • Prevent abuse of our public forms and keep the Service available
  • Comply with legal obligations

4. How We Share Your Information

We use the following categories of provider. They act on our instructions and are not permitted to use your information for their own purposes.

  • Hosting and infrastructure: Our database, authentication, and file storage provider; our application hosting provider; our content delivery and bot-protection provider; and our background job and rate-limiting providers.
  • Payments: Stripe, which handles checkout and card processing directly.
  • Email delivery: Our transactional and marketing email provider.
  • AI providers: To generate listing copy and images we send property details — name, location, amenities, selling points, target audience, and any website content you ask us to import — through our own AI gateway to third-party model providers. We do not send them your account credentials, your billing details, or your contact lists.
  • Mapping: Property addresses are sent to our mapping provider to obtain coordinates.
  • Social and advertising platforms: Meta (Facebook, Instagram, Threads, WhatsApp), Google, LinkedIn, X, and TikTok, to post content and to create and manage the campaigns you configure.
  • Analytics, error monitoring, and advertising measurement: As described in Section 2.4.
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal information for money. We should be precise about one thing rather than leave you to discover it: the Meta pixel described in Section 2.4 shares online identifiers with Meta for advertising measurement, and some privacy laws treat that as a "sale" or "share" even though no money changes hands. It loads only if you accept cookies, and you can withdraw that at any time from our Cookie Policy.

4.1 Contact Lists You Upload

Where you upload your own contacts so the Service can email them for you, you decide who is on that list and what is sent; we handle it only to carry out your instructions. You are responsible for having a lawful basis to email those people and for honouring their opt-outs. We will act on any unsubscribe request we receive, and we will pass on any request from someone on your list that we cannot resolve ourselves.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Secure authentication mechanisms
  • Access tokens for your connected accounts held in an encrypted vault, never in plaintext
  • Automated database security checks on every change we ship, and automated monitoring for dependency updates
  • Database access controls so that only your account can read your data. Note that images and media used in your posts and ads are served from public links, because the social and advertising platforms must be able to fetch them.

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Where we can state a specific period, we do:

  • Advertising click records: deleted after 90 days.
  • Account activity logs: deleted after 90 days.
  • Calendar booking entries: replaced on every refresh, so only the current state of your calendar is stored.
  • When you delete your account: we delete your account and its content, and we remove your email address from our free-scan records and marketing sequences. We keep one minimal record of your email address marked "do not contact", so that a later scan or enquiry with the same address cannot put you back on a mailing list. Ask us at [email protected] if you want that record removed as well.
  • Billing records: retained by us and by Stripe for as long as tax and accounting rules require.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your personal data
  • Object to or restrict certain processing
  • Data portability (receive your data in a portable format)
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at [email protected] and we will respond within 30 days. You can delete your account yourself at any time from your account settings. There is no self-service export button today — ask us and we will compile and send your data.

8. California Privacy Rights

We extend the following to California residents, and in practice to everyone:

  • The right to know what personal information is collected — Section 2 lists it
  • The right to delete personal information
  • The right to opt out of the sharing of personal information for cross-context behavioural advertising. Our only such technology is the Meta pixel, which loads only if you accept cookies. To opt out, reject cookies from the banner or use the control in Section 4.1 of our Cookie Policy.
  • The right to non-discrimination for exercising privacy rights

We disclose the categories of information we collect and who receives it in Sections 2 and 4 rather than repeating them here.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

10. Children's Privacy

The Service is not intended for children under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. Your continued use after changes constitutes acceptance of the updated policy.

12. Google User Data

If you connect a Google Ads account, Vacancy Vibe accesses Google user data through the Google Ads API. This section describes that access specifically.

12.1 What We Access

We request a single scope, https://www.googleapis.com/auth/adwords, which grants access to the Google Ads accounts available to the person authorizing the connection. Within those accounts we read and write account and customer identifiers, campaigns, ad groups, ads, budgets, targeting settings, and performance metrics. This connection does not request access to your Google profile, your email address, or any other Google service.

Separately, if you choose to sign in with Google, we receive your name, email address, and profile picture from Google in order to create and identify your account. That is a different permission, granted at sign-in rather than here.

12.2 How We Use It

We use this data solely to create, update, pause, and report on the ad campaigns you explicitly configure in Vacancy Vibe, and to display their performance back to you. We do not use Google user data to advertise to you, we do not sell it, and we do not use it to train artificial intelligence or machine learning models.

12.3 How We Store It

OAuth access and refresh tokens are encrypted at rest in Supabase Vault and are never stored in plaintext. Campaign and performance data is stored in our access-controlled database and is readable only by members of the account that connected it.

12.4 How We Share It

We do not share Google user data with third parties, other than infrastructure providers who process it on our behalf (hosting and database) and disclosures required by law. We never transfer it to data brokers or advertising networks.

12.5 Retention and Deletion

You can revoke our access at any time by disconnecting the Google Ads account inside Vacancy Vibe, or from your Google Account permissions page. Disconnecting deletes the stored tokens, and all associated data is deleted when you delete your Vacancy Vibe account. To request deletion directly, email [email protected].

12.6 Limited Use

Vacancy Vibe's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

13. Meta Data and Deletion

If you connect a Facebook, Instagram, Threads, or Meta advertising account, Vacancy Vibe accesses Meta platform data through Meta's APIs. This section describes that access and how to have the data deleted.

13.1 What We Access

With the permissions you grant during the Facebook Login flow, we access the Facebook Pages and Instagram or Threads accounts you select, publish the posts you schedule, and — where you enable advertising — read and write campaigns, ad sets, ads, budgets, targeting, and performance metrics in the Meta advertising account you choose. We also receive the basic profile and account information Meta returns so we can show you which account is connected.

13.2 How We Use and Store It

We use it only to operate the posting and advertising features you configure. Access tokens are encrypted at rest and are never stored in plaintext. We do not sell this data, and we do not use it to train artificial intelligence or machine learning models.

13.3 Deleting Your Meta Data

You can disconnect a Meta account at any time from the integration settings inside Vacancy Vibe, which deletes the stored tokens for that account. You can also remove our access from Facebook Settings → Apps and Websites. All associated data is deleted when you delete your Vacancy Vibe account. To request deletion of your Meta-derived data directly, email [email protected] with the subject "Meta data deletion" and we will confirm within 30 days.

14. Contact Us

For questions about this Privacy Policy or our privacy practices, contact us at:

  • Operator: Keystone Cognition Labs LLC, a Georgia limited liability company
  • Email: [email protected]

See also our Terms of Service and Cookie Policy.