Your privacy is our priority. This policy explains how we collect, use, protect, and retain your personal data in compliance with UK and EU data protection laws.
Network Data: IP address, approximate geolocation (country/city level)
Cookies & Identifiers: Session tokens, preference cookies (see our Cookie Policy)
Children's Privacy
VibraXX is strictly for users aged 18+. We do not knowingly collect data from individuals under 18. If we discover that a minor has provided personal data, we will immediately delete it and terminate their account.
2. Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following lawful grounds under UK/EU GDPR:
Contract (Article 6(1)(b)): Processing necessary to provide quiz services, process payments, and award prizes as per our Terms & Conditions.
Legal Obligation (Article 6(1)(c)): Compliance with financial regulations (e.g., HMRC tax reporting), anti-money laundering laws, and data retention requirements.
Legitimate Interest (Article 6(1)(f)): Fraud prevention, platform security, service improvements, and marketing communications (with opt-out options).
Authenticate users and manage accounts via Supabase Auth
Enable participation in live quiz competitions
Calculate scores, generate leaderboards, and determine winners
Process payments for round purchases and distribute prize winnings
3.2 Security & Fraud Prevention
Detect and prevent cheating, multi-accounting, and automated bots
Monitor for suspicious payment activity and account abuse
Enforce age restrictions (18+ requirement) through automated checks
3.3 Communications
Send transactional emails via Zoho Mail (purchase confirmations, password resets, prize notifications)
Deliver platform updates and important service announcements
Provide customer support responses to user inquiries
3.4 Analytics & Improvement
Analyze aggregated usage patterns to optimize platform performance
Improve quiz difficulty balancing and question quality
Conduct A/B testing for feature enhancements (anonymized data only)
We Never Sell Your Data
Your personal information is never sold, rented, or shared with third parties for their marketing purposes. We only share data with trusted service providers as outlined in Section 5.
4. Automated Decision-Making
We use automated systems for the following purposes:
Quiz Scoring: Answers are automatically evaluated against correct responses to calculate scores in real-time.
Leaderboard Ranking: Players are ranked algorithmically based on total score, accuracy, and response times.
Anti-Cheat Detection: Automated systems flag suspicious patterns (e.g., impossibly fast answers, coordinated behavior) for manual review.
Age Verification: Date of birth is automatically checked to ensure compliance with our 18+ policy.
Right to Human Review
If you believe an automated decision (such as account suspension for suspected cheating) was made in error, you have the right to request human review. Contact team@vibraxx.com to appeal.
5. Third-Party Services & Data Sharing
We work with trusted service providers to deliver VibraXX. All processors are contractually bound to UK/EU GDPR standards:
5.1 Essential Service Providers
Supabase (Backend & Auth): Database hosting, user authentication, real-time data sync. Data Location: EU/US (Standard Contractual Clauses apply)
We conduct regular Transfer Impact Assessments (TIAs) to monitor data protection risks
5.3 Legal Disclosures
We may disclose personal data if required by law or to:
Comply with legal obligations (e.g., court orders, tax authorities)
Enforce our Terms & Conditions or investigate violations
Protect the rights, safety, or property of VibraXX, users, or the public
No Data Sales
We never sell, rent, or trade your personal data to third parties for marketing or advertising purposes. All data sharing is strictly limited to the service providers listed above.
6. Data Security
We implement industry-standard security measures to protect your personal data:
Encryption: All data in transit is protected with TLS 1.3 encryption. Sensitive data at rest is encrypted using AES-256.
Access Controls: Role-based access restrictions ensure only authorized personnel can access personal data.
Password Security: Passwords are hashed using bcrypt with individual salts (never stored in plain text).
PCI-DSS Compliance: Payment processing adheres to Payment Card Industry Data Security Standards via Stripe.
Regular Audits: We conduct periodic security assessments and vulnerability testing.
Incident Response: In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR.
Report Security Issues
If you discover a security vulnerability, please report it immediately to team@vibraxx.com. We take all reports seriously and will investigate promptly.
7. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this policy:
7.1 Active Accounts
Profile Data: Retained while your account is active
Quiz Performance: Stored for long-term statistical and historical purposes, including leaderboard history and analytics.
Session Logs: Kept for 90 days for technical support and fraud prevention
7.2 Financial Records
Transaction Data: Retained for 7 years to comply with UK tax law (HMRC requirements)
Prize Payouts: Records kept for 7 years for audit and legal compliance purposes
7.3 Closed Accounts
Account Deletion: When you close your account, we anonymize your profile data within 30 days
Anonymization: Historical quiz scores remain in aggregated form but are no longer linked to your identity
Legal Hold: Financial records are retained for 7 years even after account closure (HMRC requirement)
Request Account Deletion
To delete your account and personal data, email team@vibraxx.com with your registered email address. We will process your request within 30 days. Note: Financial transaction records will be retained for 7 years as required by law.
8. Your Privacy Rights (UK/EU GDPR)
Under UK and EU data protection law, you have the following rights:
Right to Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete information in your profile
Right to Erasure
Request deletion of your personal data (subject to legal retention requirements)
Right to Data Portability
Export your data in a machine-readable format (CSV/JSON)
Right to Restrict Processing
Limit how we use your data while disputes are resolved
Right to Object
Opt out of processing based on legitimate interest (e.g., marketing)
Right to Withdraw Consent
Revoke consent for optional data processing (e.g., analytics cookies)
Right to Lodge a Complaint
File a complaint with the UK Information Commissioner's Office (ICO) or your local data protection authority
Exercise Your Rights
To exercise any of these rights, email team@vibraxx.com with your request. We will respond within 30 days (or 60 days for complex requests).
You may also contact the UK Information Commissioner's Office (ICO): Website: ico.org.uk Phone: 0303 123 1113
9. Cookies & Tracking Technologies
We use cookies and similar technologies to improve your experience. For full details, see our Cookie Policy.
Types of Cookies We Use:
Essential Cookies: Required for authentication, session management, and core functionality
Performance Cookies: Anonymous analytics to improve platform performance
Preference Cookies: Remember your language, theme, and display settings
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make significant changes:
We will notify you via email at your registered address
A banner will appear on the website highlighting the updates
The "Last Updated" date at the top of this policy will be revised
We encourage you to review this policy regularly to stay informed about how we protect your data.