Skip to content

Legal

Privacy Policy

This policy explains exactly what personal data Good Vibe Tribe collects, why, who else touches it, how long we keep it, and how you get it deleted.

Last updated 25 July 2026. Operated by AGENTIC INTERNATIONAL LTD, a company registered in England and Wales under number 16424508, registered office 128 City Road, London, EC1V 2NX, United Kingdom.

1. Who controls your data

AGENTIC INTERNATIONAL LTD is the data controller for the personal data described here. We are registered in England and Wales under company number 16424508 at 128 City Road, London, EC1V 2NX, United Kingdom. Because we are a UK company, we handle your data under the UK General Data Protection Regulation and the Data Protection Act 2018, wherever in the world you are.

For anything in this policy, including a request to see or delete your data, contact privacy@goodvibetribe.app.

2. What we collect and why

Everything below is data we actually hold. We have written it out field by field rather than in general categories so you can see the whole picture.

Account and profile

DataWhy we hold itLawful basis
Email address and passwordTo create your account, sign you in and send account emails. Passwords are hashed by our authentication provider and are never visible to us.Contract
First name, last name and display nameTo identify you to our review team, to venue staff on a guestlist, and to other members attending the same event, who see your first name only.Contract
Date of birthTo confirm you meet the minimum age of 18 and any higher age set by a venue.Legal obligation and legitimate interests
Biography textShown to our team when reviewing your application.Contract
Instagram, Telegram and WhatsApp handles or numbersTo verify that an application is genuine, and to deliver notifications on the channels you opt into.Contract and consent
Home cityTo show you events and offers in the right place.Contract
Profile photosSo our review team, venue staff at the door and members at the same event can recognise you. See the warning below about how these are stored.Contract
Email verification statusTo confirm the address is yours and to prevent fraudulent signups.Legitimate interests
Please read this before you upload a photo. Profile photos are stored in a publicly readable storage bucket. That means an image is served from a direct web address, and anyone who has that address can open it without logging in or being a member. The addresses are long and random, so they are not guessable and are not listed anywhere public, but they are not access-controlled either. Do not upload anything you would not be comfortable being seen outside the app. When you delete your account we delete these files from storage.

Using the service

DataWhy we hold itLawful basis
Guestlist applications and bookings, including any note you add, your arrival time preferences, the QR token for your booking, and whether you checked in or redeemed a perkTo run the guestlist, share it with the venue you booked, admit you at the door and settle disputes about attendance.Contract
Membership status, tier and reward pointsTo operate membership and the rewards ladder.Contract
Notification channel preferencesSo we only message you on the channels you chose.Consent
Push notification device tokenTo deliver push notifications to your device via Apple. Deleted when you sign out or delete your account.Consent
Notifications and queued messages sent to you, with their content and delivery statusSo you can see your notification history and so we can retry or diagnose a failed message.Contract
Which events you view, click and shareAggregate interest data that tells venues and us which events are worth running. It is not used to profile you or to target advertising.Legitimate interests
An internal priority score from 0 to 100A ranking our team uses when deciding between applicants. It is never shown to you or to other members and it is protected at the database level.Legitimate interests

Safety and moderation

DataWhy we hold itLawful basis
Reports you file about a member or a venue, and reports filed about youTo investigate and keep members and venue staff safe. The person you report is not told who reported them.Legitimate interests
Warnings, including automatic no-show warningsTo operate the attendance system fairly and to show you your own record.Legitimate interests
Suspensions and their reasons, and any appeal you submitTo enforce our Community Guidelines and to review appeals.Legitimate interests
Members you have blockedSo we can hide you from each other. Only you can see your own block list, and the person blocked is not told.Contract
An administrative audit log of actions our staff take on accountsAccountability, and evidence if a decision is challenged.Legal obligation and legitimate interests

Before you have an account

If you request an invite from our website, we collect your name, email address and city so we can email you about launching in your area. You can unsubscribe from every one of those emails, and unsubscribing removes you from the list.

3. What we do not do

This is as important as the list above, and it is the same answer we give on Apple’s App Store privacy questionnaire.

  • We do not track you across other companies' apps or websites. The app contains no advertising identifier, no tracking pixel and no cross-app tracking of any kind.
  • We do not show advertising and we do not run an ad network SDK.
  • We do not use an analytics SDK such as Google Analytics, Firebase, Mixpanel or Segment inside the iOS app.
  • We do not use a crash reporting SDK such as Crashlytics or Sentry.
  • We do not sell, rent or trade your personal data. Ever, to anyone.
  • We do not share your data with advertisers or data brokers.
  • We do not collect your device's precise location. The map screen asks for location only while you are using the app, to centre the map near you, and that position is never sent to us or stored.
  • We do not collect payment card or bank details, because there is nothing to pay for in the app.
  • We do not ask for or store identity documents.

4. Who else handles your data

We use a small number of specialist suppliers to run the service. They process data on our written instructions, only for the purpose listed, and they may not use it for their own ends.

SupplierWhat they doWhere
SupabaseDatabase, authentication and file storage — the core of the serviceEuropean Union
VercelHosting for the website and the scheduled jobs that send messagesGlobal edge network
AppleDelivery of push notifications to your iPhone via the Apple Push Notification serviceUnited States and global
ResendSending transactional email such as confirmations and password resetsUnited States
BrevoThe mailing list for people who requested an invite before joiningEuropean Union
Meta PlatformsDelivery of WhatsApp messages, only if you opt into the WhatsApp channelUnited States and global
TelegramDelivery of Telegram messages, only if you opt into the Telegram channelGlobal
CloudflareProtecting our forms from automated abuseGlobal

We also share a limited amount of data with venues: when your booking is approved, the venue you booked receives your first name, last name, photo and check-in status so their door team can find you on the list. Venues receive nothing about members who have not booked with them, and they never receive your contact details, date of birth or moderation history.

Beyond that, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or where there is a genuine risk to someone’s life or safety.

5. Sending data outside the UK

Some of the suppliers above are outside the United Kingdom. Where personal data leaves the UK, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with the technical measures those clauses require.

6. How long we keep things

RecordRetention
Your profile and accountFor as long as your account is open
Everything erased on deletion — photos, biography, handles, phone number, date of birth, device tokens and your login itselfErased at the point you delete your account
Booking and attendance records, anonymised so they no longer identify youUp to 24 months, so venues can reconcile their own guestlists
Reports, warnings, suspensions and appealsUp to 24 months after the account closes, so a pattern of harm can still be recognised
A one-way hashed form of your email address, held only where a suspension had not expired when you deleted your accountUntil the suspension would have expired, and no longer
Administrative audit logUp to 6 years, for accountability and legal claims
Invite mailing list entriesUntil you unsubscribe, or 24 months of no engagement

The full deletion picture, including what survives and why, is in the Account Deletion Policy.

7. Your rights

Under UK data protection law you have the right to:

  • be told what we hold about you and get a copy of it;
  • have inaccurate data corrected — most of it you can edit yourself in the app;
  • have your data erased, which you can do yourself by deleting your account;
  • restrict how we use your data while a dispute about it is resolved;
  • receive the data you gave us in a portable, machine-readable format;
  • object to processing we carry out on the basis of legitimate interests;
  • withdraw consent at any time, for example by turning off a notification channel in Settings or unsubscribing from an email — withdrawing consent does not undo anything done before you withdrew it;
  • not be subject to a decision made purely by automated means with a legal or similarly significant effect. Our only automatic decision is the no-show warning, and it is always reviewable by a human if you appeal it.

Email privacy@goodvibetribe.app to exercise any of these. We respond within one month. We will not charge you or treat you differently for asking.

8. Keeping data secure

  • All traffic between your device and our servers is encrypted in transit, and data is encrypted at rest by our hosting providers.
  • Row-level security in the database means one member's account cannot read another's data, and sensitive fields such as the priority score are unreadable even to a signed-in member.
  • Access by our staff is limited to the people who need it to run the service, and administrative actions are recorded in the audit log.
  • Passwords are stored only as salted hashes and cannot be read back by anyone, including us.

No system is perfect. If a breach ever puts your rights at risk, we will tell the Information Commissioner’s Office within 72 hours and tell you without undue delay.

9. Children

The service is not for anyone under 18. We do not knowingly collect data about children. If you believe a child has created an account, tell us at privacy@goodvibetribe.app and we will delete it.

10. Cookies

The website uses only the cookies needed to keep you signed in and to keep the site secure. We set no advertising or analytics cookies, so there is no tracking to consent to.

11. Changes and complaints

When we change this policy materially, we will tell you in the app or by email before the change takes effect, and the date at the top of this page will change.

If you are unhappy with how we have handled your data, please tell us first at privacy@goodvibetribe.appso we can put it right. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk, or to the data protection authority where you live.