Legal

Privacy Policy

Last updated: 29 August 2026

1. Data controller

The data controller responsible for the processing of your personal data is DG1 Group Holdings Inc. ("we", "our", "us"). Contact: privacy@vibemycrm.com.

2. Personal data we collect

  • Account data: name, email, hashed password, workspace/organisation.
  • CRM content: contacts, companies, deals, activities, notes and files you upload.
  • Billing data: billing address and tax details (payment card data is handled directly by Stripe).
  • Usage & telemetry: IP address, device and browser info, session events, error logs.
  • Communications: emails you send us and in-app support conversations.

3. Purposes and legal bases (Art. 6 GDPR)

  • Providing the Service — necessary for the performance of our contract with you.
  • Billing and fraud prevention — contractual necessity and legitimate interests.
  • Product analytics and improvement — legitimate interests, balanced against your rights.
  • Marketing communications — consent, which you can withdraw at any time.
  • Legal compliance — where required by law.

4. Recipients & sub-processors

We share personal data only with vetted sub-processors, including:

  • Supabase (database, authentication, storage) — EU region.
  • Lovable Cloud (hosting infrastructure).
  • Stripe (payment processing).
  • AI providers (Google Gemini, OpenAI) via the Lovable AI Gateway, for assistant features.
  • Transactional email provider (Resend or equivalent).

A current list is available on request at privacy@vibemycrm.com.

5. International transfers

Where personal data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses adopted by the European Commission and, where appropriate, supplementary safeguards.

6. Retention

We retain personal data for as long as your Account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce agreements. CRM content is deleted within 30 days of Account deletion unless we are required to retain it by law.

7. Your rights (Art. 15–22 GDPR)

You have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") where legally applicable.
  • Restrict or object to processing based on legitimate interests.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with your national supervisory authority.

To exercise your rights, email privacy@vibemycrm.com. We respond within 30 days.

8. Cookies & similar technologies

We use strictly necessary cookies for authentication and session management, and, with your consent, analytics cookies to understand usage. You can manage your preferences in your browser or via any in-app cookie banner.

9. Security

We apply industry-standard technical and organisational measures: encryption in transit (TLS), encryption at rest, per-tenant isolation with row-level security, role-based access, audit logs, and least-privilege access for our staff.

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

11. AI features

When you use AI features (assistant, summarisation), prompts and relevant CRM context are sent to AI providers via the Lovable AI Gateway solely to generate the response. Prompts are not used to train third-party models.

12. Changes to this policy

We may update this Policy from time to time. Material changes will be announced by email or in-app notice. The "Last updated" date at the top reflects the most recent revision.

13. Contact & DPO

Privacy questions and requests: privacy@vibemycrm.com.
Controller: DG1 Group Holdings Inc.