Legal
Privacy Policy
This policy explains exactly what personal data Good Vibe Tribe collects, why, who else touches it, how long we keep it, and how you get it deleted.
Last updated 25 July 2026. Operated by AGENTIC INTERNATIONAL LTD, a company registered in England and Wales under number 16424508, registered office 128 City Road, London, EC1V 2NX, United Kingdom.
1. Who controls your data
AGENTIC INTERNATIONAL LTD is the data controller for the personal data described here. We are registered in England and Wales under company number 16424508 at 128 City Road, London, EC1V 2NX, United Kingdom. Because we are a UK company, we handle your data under the UK General Data Protection Regulation and the Data Protection Act 2018, wherever in the world you are.
For anything in this policy, including a request to see or delete your data, contact privacy@goodvibetribe.app.
2. What we collect and why
Everything below is data we actually hold. We have written it out field by field rather than in general categories so you can see the whole picture.
Account and profile
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Email address and password | To create your account, sign you in and send account emails. Passwords are hashed by our authentication provider and are never visible to us. | Contract |
| First name, last name and display name | To identify you to our review team, to venue staff on a guestlist, and to other members attending the same event, who see your first name only. | Contract |
| Date of birth | To confirm you meet the minimum age of 18 and any higher age set by a venue. | Legal obligation and legitimate interests |
| Biography text | Shown to our team when reviewing your application. | Contract |
| Instagram, Telegram and WhatsApp handles or numbers | To verify that an application is genuine, and to deliver notifications on the channels you opt into. | Contract and consent |
| Home city | To show you events and offers in the right place. | Contract |
| Profile photos | So our review team, venue staff at the door and members at the same event can recognise you. See the warning below about how these are stored. | Contract |
| Email verification status | To confirm the address is yours and to prevent fraudulent signups. | Legitimate interests |
Using the service
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Guestlist applications and bookings, including any note you add, your arrival time preferences, the QR token for your booking, and whether you checked in or redeemed a perk | To run the guestlist, share it with the venue you booked, admit you at the door and settle disputes about attendance. | Contract |
| Membership status, tier and reward points | To operate membership and the rewards ladder. | Contract |
| Notification channel preferences | So we only message you on the channels you chose. | Consent |
| Push notification device token | To deliver push notifications to your device via Apple. Deleted when you sign out or delete your account. | Consent |
| Notifications and queued messages sent to you, with their content and delivery status | So you can see your notification history and so we can retry or diagnose a failed message. | Contract |
| Which events you view, click and share | Aggregate interest data that tells venues and us which events are worth running. It is not used to profile you or to target advertising. | Legitimate interests |
| An internal priority score from 0 to 100 | A ranking our team uses when deciding between applicants. It is never shown to you or to other members and it is protected at the database level. | Legitimate interests |
Safety and moderation
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Reports you file about a member or a venue, and reports filed about you | To investigate and keep members and venue staff safe. The person you report is not told who reported them. | Legitimate interests |
| Warnings, including automatic no-show warnings | To operate the attendance system fairly and to show you your own record. | Legitimate interests |
| Suspensions and their reasons, and any appeal you submit | To enforce our Community Guidelines and to review appeals. | Legitimate interests |
| Members you have blocked | So we can hide you from each other. Only you can see your own block list, and the person blocked is not told. | Contract |
| An administrative audit log of actions our staff take on accounts | Accountability, and evidence if a decision is challenged. | Legal obligation and legitimate interests |
Before you have an account
If you request an invite from our website, we collect your name, email address and city so we can email you about launching in your area. You can unsubscribe from every one of those emails, and unsubscribing removes you from the list.
3. What we do not do
This is as important as the list above, and it is the same answer we give on Apple’s App Store privacy questionnaire.
- We do not track you across other companies' apps or websites. The app contains no advertising identifier, no tracking pixel and no cross-app tracking of any kind.
- We do not show advertising and we do not run an ad network SDK.
- We do not use an analytics SDK such as Google Analytics, Firebase, Mixpanel or Segment inside the iOS app.
- We do not use a crash reporting SDK such as Crashlytics or Sentry.
- We do not sell, rent or trade your personal data. Ever, to anyone.
- We do not share your data with advertisers or data brokers.
- We do not collect your device's precise location. The map screen asks for location only while you are using the app, to centre the map near you, and that position is never sent to us or stored.
- We do not collect payment card or bank details, because there is nothing to pay for in the app.
- We do not ask for or store identity documents.
4. Who else handles your data
We use a small number of specialist suppliers to run the service. They process data on our written instructions, only for the purpose listed, and they may not use it for their own ends.
| Supplier | What they do | Where |
|---|---|---|
| Supabase | Database, authentication and file storage — the core of the service | European Union |
| Vercel | Hosting for the website and the scheduled jobs that send messages | Global edge network |
| Apple | Delivery of push notifications to your iPhone via the Apple Push Notification service | United States and global |
| Resend | Sending transactional email such as confirmations and password resets | United States |
| Brevo | The mailing list for people who requested an invite before joining | European Union |
| Meta Platforms | Delivery of WhatsApp messages, only if you opt into the WhatsApp channel | United States and global |
| Telegram | Delivery of Telegram messages, only if you opt into the Telegram channel | Global |
| Cloudflare | Protecting our forms from automated abuse | Global |
We also share a limited amount of data with venues: when your booking is approved, the venue you booked receives your first name, last name, photo and check-in status so their door team can find you on the list. Venues receive nothing about members who have not booked with them, and they never receive your contact details, date of birth or moderation history.
Beyond that, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or where there is a genuine risk to someone’s life or safety.
5. Sending data outside the UK
Some of the suppliers above are outside the United Kingdom. Where personal data leaves the UK, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with the technical measures those clauses require.
6. How long we keep things
| Record | Retention |
|---|---|
| Your profile and account | For as long as your account is open |
| Everything erased on deletion — photos, biography, handles, phone number, date of birth, device tokens and your login itself | Erased at the point you delete your account |
| Booking and attendance records, anonymised so they no longer identify you | Up to 24 months, so venues can reconcile their own guestlists |
| Reports, warnings, suspensions and appeals | Up to 24 months after the account closes, so a pattern of harm can still be recognised |
| A one-way hashed form of your email address, held only where a suspension had not expired when you deleted your account | Until the suspension would have expired, and no longer |
| Administrative audit log | Up to 6 years, for accountability and legal claims |
| Invite mailing list entries | Until you unsubscribe, or 24 months of no engagement |
The full deletion picture, including what survives and why, is in the Account Deletion Policy.
7. Your rights
Under UK data protection law you have the right to:
- be told what we hold about you and get a copy of it;
- have inaccurate data corrected — most of it you can edit yourself in the app;
- have your data erased, which you can do yourself by deleting your account;
- restrict how we use your data while a dispute about it is resolved;
- receive the data you gave us in a portable, machine-readable format;
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent at any time, for example by turning off a notification channel in Settings or unsubscribing from an email — withdrawing consent does not undo anything done before you withdrew it;
- not be subject to a decision made purely by automated means with a legal or similarly significant effect. Our only automatic decision is the no-show warning, and it is always reviewable by a human if you appeal it.
Email privacy@goodvibetribe.app to exercise any of these. We respond within one month. We will not charge you or treat you differently for asking.
8. Keeping data secure
- All traffic between your device and our servers is encrypted in transit, and data is encrypted at rest by our hosting providers.
- Row-level security in the database means one member's account cannot read another's data, and sensitive fields such as the priority score are unreadable even to a signed-in member.
- Access by our staff is limited to the people who need it to run the service, and administrative actions are recorded in the audit log.
- Passwords are stored only as salted hashes and cannot be read back by anyone, including us.
No system is perfect. If a breach ever puts your rights at risk, we will tell the Information Commissioner’s Office within 72 hours and tell you without undue delay.
9. Children
The service is not for anyone under 18. We do not knowingly collect data about children. If you believe a child has created an account, tell us at privacy@goodvibetribe.app and we will delete it.
10. Cookies
The website uses only the cookies needed to keep you signed in and to keep the site secure. We set no advertising or analytics cookies, so there is no tracking to consent to.
11. Changes and complaints
When we change this policy materially, we will tell you in the app or by email before the change takes effect, and the date at the top of this page will change.
If you are unhappy with how we have handled your data, please tell us first at privacy@goodvibetribe.appso we can put it right. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk, or to the data protection authority where you live.