Legal
Privacy Policy
Last updated 19 September 2026
1. Controller
V.O.F. HEAT ENTERTAINMENT (Vennootschap onder firma (V.O.F.)), trading as Vibra (“we”, “us”), is the controller of personal data collected on this site. Registered office: Bercylaan 111, 1031 KP Amsterdam, the Netherlands. KvK 42066099. VAT NL869551978B01.
Contact the controller: privacy@vibra-pulse.com. Statutory details: legal notice.
This policy covers the Vibra website and member platform at vibra-pulse.com. It is written for visitors in the EEA/UK (GDPR) and Brazil (LGPD — Lei nº 13.709/2018).
2. What we collect
- Account: email, password (handled by our auth provider), display name, username, and profile details you choose to add.
- Guest checkout: date of birth (to confirm you are 18+) and email for ticket delivery.
- Pulse and activity: points, level, check-ins, ticket orders, and similar product events needed to run loyalty and events.
- Payments: Stripe processes card data. We receive payment status, amount, and identifiers needed to issue tickets — not full card numbers.
- Technical: IP address and basic request logs on our host (Vercel) and database (Supabase), for security and abuse prevention.
- Cookies: a consent cookie, plus analytics/marketing cookies only if you allow them. See the Cookie Policy.
3. Why we use it (purposes and legal bases)
- Providing the service — accounts, events, tickets, Pulse, and member features. GDPR: contract / steps prior to contract (Art. 6(1)(b)). LGPD: execution of a contract (Art. 7, V).
- Promotional emails — events, perks, Pulse, and related offers, only if you opt in. GDPR: consent (Art. 6(1)(a)). LGPD: consent (Art. 7, I). You can withdraw at any time.
- Running the site and keeping it secure — GDPR: legitimate interests (Art. 6(1)(f)). LGPD: legitimate interest (Art. 7, IX) and/or compliance with a legal obligation.
- Legal, tax, and accounting — invoices, VAT, and dispute records. GDPR: legal obligation (Art. 6(1)(c)). LGPD: legal obligation.
- Measurement (Google Tag Manager / Analytics) — only with cookie consent. GDPR: consent (Art. 6(1)(a) and ePrivacy). LGPD: consent.
4. Who we share with
We do not sell your personal data. We use processors that help us operate:
- Supabase (database and auth) — stores accounts and product data.
- Vercel (hosting) — serves the site and API.
- Stripe — payment processing when you buy tickets. Event organisers receive the information needed to honour the ticket.
- Google (Tag Manager / Analytics) — only if you accept analytics or marketing cookies.
- An email provider, when we send transactional or opted-in promotional messages.
Some processors are outside the EEA and Brazil (for example the United States). Where required we rely on Standard Contractual Clauses or an equivalent transfer tool, plus the consent you gave for cookies/email.
5. How long we keep it
Account and product data are kept while your account is active and for a reasonable period afterward if needed for legal, tax, or dispute purposes. Ticket and payment records are kept as long as tax and consumer-law rules require. Marketing contacts are kept until you unsubscribe or ask us to delete them. Consent records are kept as long as needed to show we had a valid opt-in. Server logs are kept for a short security window.
6. Your rights
GDPR (EEA/UK): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may complain to the Dutch AP (autoriteitpersoonsgegevens.nl) or your local DPA.
LGPD (Brazil): confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excess data, portability, information about sharing, information about the possibility of refusing consent and consequences, and revocation of consent (Art. 18). You may complain to the ANPD (gov.br/anpd).
To exercise rights, email privacy@vibra-pulse.com. We will respond within the legal time limits (as a rule, one month under the GDPR). Withdrawing consent does not affect processing that already happened.
7. Children
This site is for adults (18+). We do not knowingly collect data from children.
8. Security
Access to personal data is restricted to operators who need it. Auth and database access go through our providers’ security controls. No method of transmission is 100% secure.
9. Changes
We will update this page when our practices change. For material changes to marketing or new purposes, we will ask for consent again where the law requires it.