Legal

Privacy Policy

Last updated August 6, 2026 · Effective August 6, 2026

01About this policy

1.1This Privacy Policy explains how , a sole trader trading as “Vibora” (“Vibora”, “we”, “us” or “our”), collects and uses personal data, and the rights you have. We are the “controller” of the personal data described in this Policy.

1.2This Policy applies to personal data we control — for example, data about visitors to our website (vibora.tech), users of our applications (including vibora.flash), the people who set up and use Vibora accounts on behalf of clubs, and people who contact us. It does not form part of any contract.

1.3Tournament participant data. Where a club uses Vibora to run tournaments, participant data (such as players’ names and scores) is held locally on the device the club uses and is not transmitted to or stored by Vibora (see Section 12). The club controls that data; we do not have access to it.

1.4We are based in the United Kingdom, and this Policy is governed by UK data protection law, including the UK GDPR and the Data Protection Act 2018.

02The personal data we collect

2.1We may collect and use the following categories of personal data:

  • (a)Account and login data — to use the Service you log in with a non-personal account handle (a username, not your name or email) and a securely hashed password. This is the only account data stored in the Service itself; it is designed to hold no name, email address or other personal identifier.
  • (b)Billing and contact data — your name, email address, correspondence details, billing address, the subscriptions and invoices we issue, and amounts due and paid. This data is held in our separate billing and accounting records, not in the Service. Payment is collected by card through our payment processor, Stripe; Stripe collects and stores your card details directly on our behalf, and we do not see or store your full card number.
  • (c)Server log data — when you use the website and Service, our hosting provider automatically generates server logs that may include your IP address and basic device and browser information. We do not run application-level tracking or device fingerprinting.
  • (d)Communications data — the content of messages and enquiries you send us, and our replies.

2.2We do not currently run marketing campaigns and do not store marketing preferences. If we introduce marketing in future, we will update this Policy and give you a way to opt out before doing so.

2.3We do not seek to collect special category data (such as health data) about you through the Service. Please do not provide it to us unless we specifically ask for it.

03How we collect your personal data

3.1We collect personal data: (a) directly from you, when you create an account, use the Service, or contact us; (b) automatically, through the strictly necessary cookie described in Section 5 and through our hosting provider’s server logs; and (c) occasionally from third parties — for example, a club may give us contact details for billing or administration. We hold such details in our billing and correspondence records, not in the Service itself.

04How and why we use your personal data

4.1We use personal data only where we have a lawful basis to do so. The table below sets out what we do, the data we use and our lawful basis.

What we doPersonal data usedOur lawful basis
Create and manage your account and provide the Service to youAccount and login dataPerformance of our contract with you
Take payment for your subscription (via Stripe, our payment processor) and keep accounting recordsBilling and contact dataPerformance of our contract; compliance with a legal obligation (tax and accounting)
Provide support and respond to your enquiriesContact and communications dataPerformance of our contract; our legitimate interests in assisting users
Keep the Service secure, and maintain and improve itServer log dataOur legitimate interests in running, securing and improving our business
Send service and administrative messages (e.g. billing, security, changes to these terms)Contact dataPerformance of our contract; legal obligation; our legitimate interests
Comply with legal obligations and establish, exercise or defend legal claimsAny relevant personal dataCompliance with a legal obligation; our legitimate interests

4.2Where we rely on legitimate interests, we have considered the impact on you and do not use your data where your interests override ours.

4.3We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects for you.

05Cookies and similar technologies

5.1We use a single strictly necessary cookie to make the Service work: a signed, HTTP-only session cookie that keeps you logged in. It is essential to the Service and is always on.

5.2We do not use analytics, advertising or other non-essential cookies, and we do not track you across other websites. Because we only use a strictly necessary cookie, no cookie-consent banner is required.

06Who we share your personal data with

6.1We do not sell your personal data. We share it only as needed to run our business and provide the Service, with:

  • (a)service providers who process data on our behalf, in particular our hosting and infrastructure provider, Render (which hosts the application and database), our payment processor, Stripe, Inc. and its affiliates (“Stripe”), which collects and processes your card and billing details to take payment for your subscription, and our email delivery provider, Mailjet (part of the Sinch group), which sends the emails we send you (including responses to enquiries you make through our website);
  • (b)our professional advisers, such as our accountant and (where needed) legal advisers;
  • (c)authorities, regulators or other third parties where we are required to do so by law, or to establish, exercise or defend legal claims; and
  • (d)a buyer or successor, if we sell or transfer our business or assets.

6.2Payment processor. Stripe acts as our processor in collecting your payment, and separately as an independent controller of your payment data for its own purposes, such as fraud prevention and its own regulatory compliance. Stripe’s own privacy policy (stripe.com/privacy) explains how it uses data in that capacity.

6.3We require service providers acting as our processors to protect your personal data and to use it only for the purposes we specify.

07International transfers

7.1Our hosting provider (Render), our payment processor (Stripe) and our email delivery provider (Mailjet) may each process personal data outside the United Kingdom. Where they do, we make sure an appropriate safeguard recognised under UK data protection law is in place — such as a UK adequacy decision (Mailjet processes data within the European Economic Area, which the UK recognises as adequate), or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses).

08How long we keep your personal data

8.1We keep personal data only for as long as we need it for the purposes set out in this Policy, and then delete or anonymise it. In particular: (a) account data — for the life of your account and then deleted within 30 days of closure; (b) billing and accounting records — for at least 6 years, to meet UK tax and accounting requirements (Stripe separately retains payment and card data in accordance with its own policies and legal obligations); (c) enquiry and support data — for 2 years; and (d) server logs — kept by our hosting provider for up to 14 days.

8.2When an account is closed it is permanently deleted from the Service, which removes all account data we hold in the Service for it.

09How we keep your personal data secure

9.1We use appropriate technical and organisational measures to protect personal data, including:

  • (a)passwords stored only in strongly hashed form, never in plain text;
  • (b)signed, HTTP-only session cookies;
  • (c)encryption of data in transit; and
  • (d)access controls that limit access to those who need it.

9.2No system can be guaranteed completely secure, but we take reasonable steps to protect your data and to respond appropriately to any personal data breach.

10Your rights

10.1Under UK data protection law you have the right to: (a) access your personal data; (b) have inaccurate data corrected; (c) have your data erased in certain circumstances; (d) restrict or object to our processing in certain circumstances; (e) data portability; and (f) withdraw consent where we rely on it. These rights are not absolute and may not apply in every case.

10.2To exercise any of these rights, contact us using the details in Section 15. We will respond within the time limits set by law. There is normally no charge.

10.3Complaints. If you are a participant in a tournament run by a club, please contact that club first, as it controls your participant data and we do not hold it. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113, though we would welcome the chance to address your concerns first.

11Marketing

11.1We do not currently send marketing. If this changes, we will update this Policy and ensure you can opt out at any time. Opting out of any future marketing would not stop service or administrative messages that we need to send you.

12Tournament participant data

12.1When a club uses Vibora to run tournaments, participant data (such as players’ names, scores, standings and attendance) is stored locally in the browser or on the device the club uses to run the tournament. This data is not sent to, accessible by, or stored on Vibora’s servers. The club controls this data entirely. If a club shares a results link, the standings it shows (including participant names and scores) are encoded in the link itself; that data is not sent to or stored on our servers, and anyone with the link can read it.

12.2Because we do not receive or hold participant data, we cannot access, export or delete it. If you are a participant and want to access or delete your data, or have a question about how it is used, please contact the club that ran your tournament.

13Children’s privacy

13.1The Service is provided to clubs and their staff, and is not directed to children. Tournaments may include participants who are children; where they do, the club is responsible for having a lawful basis and any necessary parental consents for that participant data, which (as noted in Section 12) is held on the club’s own device. We do not knowingly collect personal data directly from children through the Service.

14Changes to this policy

14.1We may update this Policy from time to time. When we do, we will change the “Last updated” date above and, where the changes are significant, take reasonable steps to let you know.

15How to contact us

, trading as Vibora

Sole trader · Business name: Vibora

Email: hello [at] vibora.tech · Website: www.vibora.tech

You can also contact the UK Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113.