Legal

Privacy Policy

Your privacy is important to us. This policy explains how Vacancy Vibe collects, uses, and protects your personal data.

Last updated: September 23, 2026

1. Introduction

Vacancy Vibe is operated by Keystone Cognition Labs LLC, a limited liability company formed in the State of Georgia, United States ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service (the "Service").

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and a password if you sign up with one. We do not receive or store your card details — payments are handled by Stripe, and we keep only the customer reference and email Stripe returns to us.
  • Property Information: Property descriptions, images, addresses, calendar feed URLs, and booking platform details. Where you give us an address, we send it to our mapping provider to obtain coordinates.
  • Contact Lists: If you upload or import a list of your own past guests or contacts so the Service can email them on your behalf, that list includes other people's names and email addresses. Section 4.1 explains our respective responsibilities for it.
  • Social and Advertising Credentials: OAuth tokens and account information for connected social media and advertising platforms
  • Communications: Information you provide when contacting our support team

2.2 Information Collected Without an Account

Some parts of the Service work before you sign up, and they collect information too:

  • Free calendar scans: When you use the vacancy scanner we store the scan and its results, including the estimated revenue figures and sample posts we generate, plus the campaign parameters in the link that brought you. We store only a one-way hash of the calendar URL you paste, never the URL itself. If you give us an email address we store that too and send you the report and follow-up messages you can unsubscribe from at any time.
  • Contact form: The name, email address, and message you submit.
  • Advertising clicks: If you reach us by clicking one of our Google ads, we record the click identifier Google appends to the link so we can tell Google which clicks led to a signup. We delete these records after 90 days.

2.3 Information Collected Automatically

  • Usage Data: Pages visited, features used, and actions taken within the Service
  • Device Information: Browser type, operating system, IP address, and device identifiers
  • Cookies and Similar Technologies: See our Cookie Policy for details

2.4 Analytics, Session Recording, and Advertising

We want to be specific about this rather than leave it to the phrase "usage data":

  • Product analytics (PostHog): Records which pages and features you use, and creates a profile keyed to an identifier stored on your device.
  • Session recording (PostHog): Records a replay of on-screen activity — clicks, scrolling, and navigation — so we can see where people get stuck. Text on the page and anything you type are masked, so the replay does not capture your guests' details or the contents of forms.
  • Error monitoring (Sentry): Records diagnostic information when something breaks. It also records a masked replay of any session in which an error occurred, and of a small random sample of sessions (currently one in ten) regardless of errors. All text is masked in these replays.
  • Advertising measurement (Meta pixel): Meta receives a signal when a visitor signs up or starts a checkout. Meta is able to recognise the same browser on other websites that use its pixel, which means information about your activity is collected over time and across third-party sites. We do not send Meta your name or email address.

Analytics, session recording, and the Meta pixel load only after you accept cookies. See Section 4.1 of our Cookie Policy to change your choice at any time. Error monitoring runs regardless, because we rely on it to keep the Service working.

2.5 Information from Third Parties

  • Calendar data from integrated booking platforms (Airbnb, VRBO, etc.). Booking entries can contain a guest's name where the platform includes it. We store the entry as received, never display it, and replace the stored copy on each refresh; it is not used to generate content.
  • Profile information from connected social media accounts
  • Advertising performance data from Meta and Google for the campaigns you run through the Service

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Detect calendar vacancies and generate social media content
  • Post content to your connected social media accounts
  • Create and manage the advertising campaigns you configure in your own Meta and Google advertising accounts, and report back on how they performed
  • Send email to your own contacts on your behalf, where you have asked the Service to do so
  • Process payments and manage subscriptions
  • Send service-related communications and updates
  • Send marketing email about the Service, including the follow-up messages that go with a free scan. Every marketing message has an unsubscribe link.
  • Respond to your inquiries and provide customer support
  • Measure our own advertising, and understand which pages and features are used, so we can improve the Service
  • Prevent abuse of our public forms and keep the Service available
  • Comply with legal obligations

4. How We Share Your Information

We use the following categories of provider. They act on our instructions and are not permitted to use your information for their own purposes.

  • Hosting and infrastructure: Our database, authentication, and file storage provider; our application hosting provider; our content delivery and bot-protection provider; and our background job and rate-limiting providers.
  • Payments: Stripe, which handles checkout and card processing directly.
  • Email delivery: Our transactional and marketing email provider.
  • AI providers: To generate listing copy and images we send property details — name, location, amenities, selling points, target audience, and any website content you ask us to import — through our own AI gateway to third-party model providers. We do not send them your account credentials, your billing details, or your contact lists.
  • Mapping: Property addresses are sent to our mapping provider to obtain coordinates.
  • Social and advertising platforms: Meta (Facebook, Instagram, Threads, WhatsApp), Google, LinkedIn, X, and TikTok, to post content and to create and manage the campaigns you configure.
  • Analytics, error monitoring, and advertising measurement: As described in Section 2.4.
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal information for money. We should be precise about one thing rather than leave you to discover it: the Meta pixel described in Section 2.4 shares online identifiers with Meta for advertising measurement, and some privacy laws treat that as a "sale" or "share" even though no money changes hands. It loads only if you accept cookies, and you can withdraw that at any time from our Cookie Policy.

4.1 Contact Lists You Upload

Where you upload your own contacts so the Service can email them for you, you decide who is on that list and what is sent; we handle it only to carry out your instructions. You are responsible for having a lawful basis to email those people and for honouring their opt-outs. We will act on any unsubscribe request we receive, and we will pass on any request from someone on your list that we cannot resolve ourselves.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Secure authentication mechanisms
  • Access tokens for your connected accounts held in an encrypted vault. The exception is the few minutes it takes to pick an ad account: if the Meta or Google login you connect for advertising can reach more than one active ad account, its tokens are held outside the vault, in a short-lived cache, for no more than five minutes while you choose one (see Sections 12.3 and 13.2).
  • Automated database security checks on every change we ship, and automated monitoring for dependency updates
  • Database access controls so that only your account can read your data. Note that images and media used in your posts and ads are served from public links, because the social and advertising platforms must be able to fetch them.

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Where we can state a specific period, we do:

  • Advertising click records: deleted after 90 days.
  • Account activity logs: deleted after 90 days.
  • Calendar booking entries: replaced on every refresh, so only the current state of your calendar is stored.
  • When you delete your account: we delete your account and its content, and we remove your email address from our free-scan records and marketing sequences. We keep one minimal record of your email address marked "do not contact", so that a later scan or enquiry with the same address cannot put you back on a mailing list. Ask us at [email protected] if you want that record removed as well.
  • Billing records: retained by us and by Stripe for as long as tax and accounting rules require.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your personal data
  • Object to or restrict certain processing
  • Data portability (receive your data in a portable format)
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at [email protected] and we will respond within 30 days. You can delete your account yourself at any time from your account settings. There is no self-service export button today — ask us and we will compile and send your data.

8. California Privacy Rights

We extend the following to California residents, and in practice to everyone:

  • The right to know what personal information is collected — Section 2 lists it
  • The right to delete personal information
  • The right to opt out of the sharing of personal information for cross-context behavioural advertising. Our only such technology is the Meta pixel, which loads only if you accept cookies. To opt out, reject cookies from the banner or use the control in Section 4.1 of our Cookie Policy.
  • The right to non-discrimination for exercising privacy rights

We disclose the categories of information we collect and who receives it in Sections 2 and 4 rather than repeating them here.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

10. Children's Privacy

The Service is not intended for children under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. Your continued use after changes constitutes acceptance of the updated policy.

12. Google User Data

If you connect a Google Ads account, Vacancy Vibe accesses Google user data through the Google Ads API. This section describes that access specifically.

12.1 What We Access

We request a single scope, https://www.googleapis.com/auth/adwords, which grants access to the Google Ads accounts available to the person authorizing the connection. Within those accounts we read and write account and customer identifiers, campaigns, ad groups, ads, budgets, targeting settings, and performance metrics. This connection does not request access to your Google profile, your email address, or any other Google service.

Separately, if you choose to sign in with Google, we receive your name, email address, and profile picture from Google in order to create and identify your account. That is a different permission, granted at sign-in rather than here.

12.2 How We Use It

We use this data solely to create, update, pause, and report on the ad campaigns you explicitly configure in Vacancy Vibe, and to display their performance back to you. We do not use Google user data to advertise to you, we do not sell it, and we do not use it to train artificial intelligence or machine learning models.

12.3 How We Store It

OAuth access and refresh tokens are encrypted at rest in Supabase Vault. The one time they are held anywhere else is while you choose an account: if the Google login you connect can reach more than one active Google Ads account, both tokens and the list of those accounts are held outside the vault, in a short-lived cache, for no more than five minutes until you pick one. Campaign and performance data is stored in our access-controlled database and is readable only by members of the account that connected it.

12.4 How We Share It

We do not share Google user data with third parties, other than infrastructure providers who process it on our behalf (hosting, database, and that short-lived cache) and disclosures required by law. We never transfer it to data brokers or advertising networks.

12.5 Retention and Deletion

You can revoke our access at any time by disconnecting the Google Ads account inside Vacancy Vibe, or from your Google Account permissions page. Disconnecting deletes the stored tokens, and all associated data is deleted when you delete your Vacancy Vibe account. To request deletion directly, email [email protected].

12.6 Limited Use

Vacancy Vibe's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

13. Meta Data and Deletion

If you connect a Facebook Page, an Instagram account, a Threads account, a WhatsApp Business phone number, or a Meta advertising account, Vacancy Vibe accesses Meta platform data through Meta's APIs. This section describes exactly what we keep, why, and how to have it deleted.

13.1 What We Access

With the permissions you grant when you connect — through Facebook Login, or Threads' own sign-in for Threads — we access the Facebook Pages, Instagram or Threads accounts, and WhatsApp Business phone numbers you connect, publish the posts you schedule, and — where you enable advertising — read and write campaigns, ad sets, ads, budgets, targeting, and performance metrics in the Meta advertising account you choose. A WhatsApp number is used only as the contact option on your ads. We also receive the basic profile and account information Meta returns so we can show you which account is connected.

When you ask us to, we edit the text of a Facebook post we published, and we delete a Facebook or Threads post we published. Vacancy Vibe cannot delete Instagram posts; those must be deleted on Instagram.

When you open a published Facebook post in Vacancy Vibe, we read its current text, link, image, and publish time from Facebook, along with its most recent comments (each commenter's name, the comment, and when it was posted), to show them to you. We do not store the post content read this way or the comments.

13.2 What We Store and Why

We use Meta data only to operate the posting and advertising features you configure. We do not sell it, and we do not use it to train artificial intelligence or machine learning models. We store:

  • Connected accounts: for each Facebook Page, Instagram account, Threads account, or WhatsApp number, the ID Meta assigns to it, its name (and a Page's category), its username or phone number, a link to its profile picture (for a Page without one, the connecting user's), the permissions we requested, and whether the connection is working. For Facebook Pages and Instagram accounts we also store the ID and name of the Facebook user who connected them, and for Instagram the Page it is linked to. For Threads we store the profile bio; for WhatsApp, the verified business name and the IDs of the WhatsApp Business Account and Meta business that own the number. We keep this to show you what is connected and to publish to it.
  • Accounts offered for you to choose from: if Meta returns more than one Facebook Page, Instagram account, or WhatsApp number when you connect, we store every one of them, with the details above and its access token, while you choose which to connect. Confirming your choice deletes the ones you did not pick. If you close the chooser without confirming, all of them stay stored: they do not appear under Connected Channels and we do not publish to them. Section 13.3 explains when they are deleted.
  • Access tokens: the tokens that let us act on your behalf, stored encrypted in Supabase Vault. Our other database tables hold only a reference to the vault entry, not the token. If the Meta login you use for advertising can reach more than one active ad account, that token and the list of those ad accounts are held outside the vault, in a short-lived cache, for no more than five minutes while you choose one.
  • Post records: for each post we schedule or publish to a Meta account, its text and media links, when it was published (and, if you edited it from Vacancy Vibe, when it was last edited), the ID Meta returns for the live post and a link to it, and any error Meta reported. We keep this to show you your publishing history. If you delete a published post from Vacancy Vibe, we keep its record but remove the Meta post ID and link from it.
  • Advertising: your ad account's ID, name, and currency, and the Business Portfolio that owns it; and for each campaign we create, the campaign, ad set, and ad IDs Meta assigns, its status, budget, and schedule, and the spend, impressions, and clicks Meta reports for it. We keep this to manage your campaigns and report their results.

Our server and background-job logs can also record the IDs and names of the Facebook profile you connect with and of the Pages, Instagram and Threads accounts, and ad account you connect, the permissions a Facebook login granted, and the IDs Meta assigns to the posts and campaigns we create. We use these logs only to diagnose problems. Disconnecting does not remove them; they are kept for as long as our application hosting and background job providers retain logs.

13.3 Deleting Your Meta Data

You can delete this data yourself at any time. Open Businesses, choose the business, then go to Settings → Channels & Publishing. Deletions made there take effect immediately.

  • Facebook, Instagram, Threads, or WhatsApp: click Disconnect on the account under Connected Channels. We delete the connection record and its access tokens, together with every scheduled and published post record for that account. Posts still scheduled to it will not be published.
  • Meta ad account: in the Meta Ads panel, click the disconnect icon and confirm with Disconnect Account. We first try to pause, on Meta, each campaign we created that is active, paused, or in Meta's review, and mark it stopped; then we delete the ad account record and its access token. A campaign in review that exists on Meta is marked stopped only once Meta confirms the pause. If it does not, we leave it marked as in review, because it can still go live once Meta approves it. We do not pause, or mark stopped, a campaign that is still being created or is waiting for your approval. One waiting for your approval was created paused on Meta and cannot deliver ads, but one being created, or one in review that Meta did not confirm as paused, may already be active there. Check Meta Ads Manager for any of these and pause or delete them yourself if you do not want them to run. The campaign records listed in Section 13.2 are kept until you delete the business or your account, or ask us to delete them. The panel shows your connected ad account only while your plan includes ad boosting; if you have moved to a plan without it, email us and we will disconnect it for you.
  • Accounts you did not finish choosing: the ones left stored when you closed the chooser (Section 13.2) do not appear under Connected Channels, so you cannot disconnect them there. Connecting that platform to the same business again deletes any left from an attempt more than 15 minutes earlier, and confirming your choice then deletes the ones you do not pick. Otherwise they stay stored until you delete the business or your account, or ask us by email to delete them.
  • Everything at once: deleting a business deletes all of its Meta connections, tokens, post records, and campaign records. Deleting your Vacancy Vibe account deletes the businesses you own, and all of that with them.

Disconnecting does not delete posts that are already live on Facebook, Instagram, or Threads. While the account is still connected, you can delete a Facebook or Threads post we published: open the post's menu in Scheduled Content and choose Delete from Facebook or Delete from Threads. Vacancy Vibe cannot delete Instagram posts, so delete those on Instagram, and manage any post on Meta once you have disconnected.

Disconnecting also does not withdraw the permissions you granted on Meta's side. To withdraw them, remove Vacancy Vibe from Facebook Settings → Apps and Websites or, for Threads, from your Threads account's app settings. That stops our tokens from working, but Meta does not notify us when you do it, so it does not delete what we already hold: disconnect in Vacancy Vibe as well, or email us. A connection that expires or loses access stays stored until you disconnect it.

To have us delete your Meta-derived data instead — including campaign records and anything you cannot reach yourself — email [email protected] with the subject "Meta data deletion" and tell us which business or Meta account it concerns. We will delete it and confirm to you within 30 days.

14. Contact Us

For questions about this Privacy Policy or our privacy practices, contact us at:

  • Operator: Keystone Cognition Labs LLC, a Georgia limited liability company
  • Email: [email protected]

See also our Terms of Service and Cookie Policy.