vivetileSign in
Menu

VIVETILE / LEGAL

Privacy

What information is involved, why it is used and where your choices fit in.

Public draft for review · 16 September 2026Prepared for ViveTile, operated under the AvelinLabs name. The standard policies below describe the current service. Full legal operator identification and postal address, together with the provider details noted in Privacy, remain to be completed; this is not a final legal notice.

1. Scope and responsibility

This draft covers the ViveTile website, account dashboard and hosted capabilities. It distinguishes account information used to operate ViveTile from content and form responses processed for website owners.

AvelinLabs is the operator name used for account and service administration; full legal identification is still to be supplied. Where a website owner decides why and how visitor data is collected, that owner will generally be the controller and ViveTile will process submissions on its instructions. For organisation-specific processing agreements, contact hello@vivetile.com before submitting personal data. No separate agreement is represented as already executed.

2. Information the service handles

  • Account information: sign-in identifier, profile name and email provided through Auth0, and records of the first dashboard visit. An administrator receives a registration notification containing name, email, verification status and first-visit time.
  • Website configuration: site names and URLs, allowed origins, VTile settings, image and form libraries, publication state and timestamps.
  • Uploaded content: original images, optimised versions, names, alt text and published messages.
  • Form submissions: the named fields sent by your website's form, submission time and notification status. The service stores what the form sends; avoid requesting unnecessary personal information.
  • Operational data: account/site/content identifiers, request counts, byte volumes, response status, duration and timestamps. These internal counters do not contain visitor identifiers. Separate infrastructure and authentication logs may process IP addresses and request metadata.
  • Billing: Stripe hosts checkout and payment-method management. ViveTile stores Stripe customer, checkout and subscription identifiers, plan and payment status, billing-period dates and processed event identifiers to manage access and renewals. Full card numbers and security codes are not stored by the ViveTile application.
  • Correspondence: information you send when contacting support.

3. Why information is used

Information is used to authenticate accounts, keep customers' configurations separate, store and deliver content, receive form responses, send requested notifications, manage subscriptions, reconcile payments, answer support requests and investigate operational or security problems.

Where a legal basis is required, processing is based on contract performance for providing an account and requested services; legitimate interests in security, abuse prevention and service operation; legal obligations where applicable. Where consent is required for an optional purpose, it must be obtained separately and be withdrawable.

Website owners determine the lawful basis for the information collected through their forms. Optional form notifications send the submitted values to the recipient chosen by that owner.

4. Recipients and service providers

The current implementation uses Auth0 for sign-in, Cloudflare for website hosting and content delivery, Resend for email delivery, and Stripe for subscription checkout, payment processing and the billing portal. Configuration, images and form responses are also stored on infrastructure operated for ViveTile. Authorised administrators can access data when needed to operate or support the service.

When a form notification is enabled, its submitted values are sent through Resend to the configured recipient and that recipient's email provider. A first-dashboard-visit notification is also sent to the ViveTile administrator. Public content is delivered to website visitors. When you use Stripe Checkout or the billing portal, Stripe processes the contact, billing and payment details you provide there. See Stripe’s Privacy Policy for its handling of this information.

Provider information: Auth0 / Okta, Cloudflare, Resend and Stripe. Access is limited to service needs, support and applicable legal obligations. The precise contracting entities, applicable processing agreements and processing locations for this deployment still require verification; these links are not a substitute for that verification.

5. International processing

The current Auth0 tenant uses a US region and the service uses global infrastructure providers. This draft makes no promise that all processing remains in the EU.

Sign-in data is processed in the United States; global providers may also process information in other countries. The full country list and safeguards applicable to the configured accounts remain to be verified. We do not claim that an adequacy decision, certification or contractual safeguard applies without that verification. Ask hello@vivetile.com for the available provider and transfer information before entrusting data subject to location restrictions.

6. Retention and deletion

Uploaded content and form responses persist in the service. Pausing a form or unpublishing an image does not delete stored content. The current form implementation has no automatic age-based response deletion. Capacity limits are not retention periods.

Account configuration and hosted content are retained while needed to provide the service and until a verified deletion or closure request is handled. Form responses remain stored for the website owner until deletion is requested; pausing a form is not deletion. Support and registration correspondence is kept as needed to handle the relationship, requests and disputes. Logs and metering records are retained as needed for security, troubleshooting and usage reconciliation; current metering does not have an automatic age-based purge.

After a verified deletion request, data no longer needed for service, applicable legal obligations or a specific dispute is removed from active systems through a manual process. Financial records that must be retained are kept for the applicable statutory period. Backup copies may remain until the relevant backup is retired; they are not used to resume ordinary processing of deleted account data. If a backup is restored, deletion requests must be reapplied. No fixed automatic backup-expiry period is promised. We explain any exception affecting your request.

7. Cookies and browser storage

Sign-in and infrastructure services can use cookies or similar mechanisms for authentication and security. The public interactive demo maintains a temporary draft in the browser. Operational counters measure service activity rather than unique visitors.

Authentication and checkout providers control some cookies or browser storage on their own services; see their notices and your browser controls for available choices. Blocking necessary storage may prevent sign-in or checkout. On the public website, optional Google Analytics 4 measures page visits only after you accept analytics. No Google Analytics script or analytics request is loaded before that choice. You can reject analytics or withdraw consent at any time using Privacy choices; withdrawal stops further measurement and removes the Google Analytics cookies set by this site. A complete deployment-level inventory of provider cookie names and lifetimes remains to be verified. Your analytics preference is saved in browser storage for up to 180 days. Analytics cookies (_ga and _ga_*) are configured with a 180-day lifetime. Analytics receives page paths, page titles, an originating website domain where available, browser/device information and cookie identifiers. Query strings, URL fragments, account identifiers and form contents are not included in our page-view events. Google may process network metadata to deliver the service. Enhanced measurement, advertising signals and advertising personalisation are disabled. Google Analytics is not installed in the signed-in dashboard or on customer VTiles. See Google Privacy Policy and Google Analytics data safeguards. A customer's own website may use additional tools covered by its own notice.

8. Your choices and rights

Depending on the applicable law and circumstances, you may request access, correction, deletion, restriction or portability of your personal data, object to relevant processing, and withdraw consent where processing relies on consent. You may also complain to a competent data protection authority.

For a submission made on another organisation's website, contact that website owner first: they control its purpose and recipient settings. For your ViveTile account, email hello@vivetile.com with the subject Privacy request. We may need proportionate information to verify a request.

We verify requests proportionately and aim to respond within 30 days, explaining any lawful extension. Identify your account and the requested action; do not send identity documents unless specifically needed and requested through an appropriate channel. In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC); any right to contact another competent authority remains unaffected. Requests and general enquiries: hello@vivetile.com.

9. Security and updates

Management features require authenticated access and enforce ownership checks. Public image URLs are not private storage links, and origin checks on public endpoints are not visitor authentication. Avoid including credentials or sensitive information in published content.

This version was updated on 16 September 2026. Material changes to processing or the operator will be communicated through the service and, where appropriate, by email before they apply. This provisional notice will be completed when the outstanding operator and provider details are verified.