Privacy
Last updated: August 20, 2026
Vibe & Sell
Last updated: August 20, 2026
This explains what data of yours we keep, what for, where it lives, how long, and how you delete it. It's written so you can understand it without a lawyer next to you. If something isn't clear, write to us and we'll explain it.
Email for anything about your data: hello@vibensell.com. No form, no ticket. You write and a person answers.
1. Who's responsible for your data
Isabella Fernández, an individual, with a professional address in Madrid, Spain. Email: hello@vibensell.com Postal address: 1801 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, United States
Vibe & Sell is her brand. There's no company behind it, it's her.
Because she's established in the European Union, the European General Data Protection Regulation (GDPR) applies to all of your data, wherever you live. That works in your favor: it's the strictest standard there is. And if you live in California, your specific rights are further down.
2. What data we collect and why
If you're on the waitlist
| What we keep | What for | Legal basis |
|---|---|---|
| Your name | To write to you by your name | Your consent |
| Your email | To tell you when spots open and to send you the launch emails | Your consent |
| Your country | To know what times work for you and what language to write in | Your consent |
| The date and time you signed up | So we can prove when you gave permission | Legal obligation (GDPR requires us to be able to prove it) |
| The exact text of the box you accepted | Same | Legal obligation |
| Where you came from (which link or which network) | To know what's working | Our legitimate interest in understanding which channel brings people |
If you buy the challenge
On top of the above:
| What we keep | What for | Legal basis |
|---|---|---|
| That you bought, when and for how much | To give you your spot and to invoice | Performing our contract with you |
| The billing data the law requires | To comply with the Spanish tax authority | Legal obligation |
| Your entry form answers (time zone, state, what time of day you'll work, your idea's category, your level with tools, your audience today) | To build your pod with people who fit you | Performing our contract with you |
| Your daily check-ins and whether they're posted or not | To support you if you fall behind and to settle the guarantee without arguing | Performing our contract with you |
| Your phone number, if you join the WhatsApp groups | For the group and for your pod | Your consent |
| What you post in the community | It is the product: the community | Performing our contract with you |
| Recordings of the live sessions and Demo Day where you appear | So the cohort can watch them afterwards | Performing our contract with you |
| Your testimonial, your face or your app in sales material | Only to sell future cohorts | Your consent, asked separately and in writing. Without it, nothing gets used |
What we never see: your card details. Stripe handles that and it never reaches us.
What we don't do: we don't ask you for health data, political views, religion, ethnic origin, sexual orientation or anything like that. If you tell us in the community because you want to, that's yours and we don't store it anywhere separately.
3. The text you accepted, word for word
We keep the exact text of the box you ticked and the day you ticked it. These are the versions that have been published:
Since August 16, 2026 (waitlist):
"I agree to let Vibe & Sell store my name and my email to tell me when spots open. I can ask to have them deleted whenever I want."
Since August 20, 2026 (waitlist and purchase):
"I agree to let Vibe & Sell store my name, my email and my country to write to me about the challenge, the spots, and whatever Isa launches. I can unsubscribe from any email with one click, and I can ask to have my data deleted whenever I want."
If you signed up under the first version, we only write to you for what that first version says, until you say yes to the rest. Nobody is going to put you on a list you didn't say yes to.
4. Where your data lives
| Where | What's there | Located in |
|---|---|---|
| Supabase | The database with your name, email, country and consent, and separately the visit measurement lines from section 9 (those carry no name and no email) | Paris, France (European Union) |
| Vercel | The website server | United States and Europe |
| Stripe | The payment, the invoice and your card details (which we don't see) | United States and Ireland |
| WhatsApp (Meta) | The groups and your number, if you join | United States |
| SMTP.com | Your name and your email, so we can send you the emails | United States |
| Zoho Mail | The hello@vibensell.com inbox: what you write to us and what we write back | European Union (Netherlands, with backup in Ireland) |
| Zoho Meeting | The live sessions and their recordings | European Union (Netherlands, with backup in Ireland) |
About the ones in the United States (Vercel, Stripe, SMTP.com and WhatsApp): when your data leaves Europe, it's sent with the safeguards European law requires (the European Commission's standard contractual clauses, or the EU to US adequacy framework, depending on the company). We're telling you because you have a right to know, not because there's anything strange about it.
5. Who we give your data to
Nobody who wants to sell you something. We don't sell, rent or hand over your information to third parties so they can advertise to you. Ever.
Your data only reaches:
- The platforms in the table above, which work for us and can only use your data for what we ask them to.
- The other participants, in whatever you post in the community, and your phone number if you join a WhatsApp group. You control this: you post what you want and you can ask to stay out of WhatsApp.
- Whoever the law obliges us to, if one day a judge or the tax authority asks.
If we ever make a sale through an affiliate, that person knows how many sales they brought in, not who bought. We don't give them your name or your email.
Who can see the list from the inside, and how it's kept
The list with your name and your email is opened by whoever needs to write to you, which today is Isa, from a private dashboard. This is how it's protected:
- It asks for a key of its own, different from the one for the numbers dashboard. They're two separate keys on purpose: whoever holds the one for the numbers can't pull a single row of the list.
- The emails come out covered on screen (
ab•••@email.com). You have to uncover them deliberately. - It only allows reading. You can't search by email, or filter, or download the whole database: it pulls 100 rows at most each time.
- Every time it's opened, a record is kept of when it happened and how many rows came out. That record stores no emails and no IP addresses.
- The key stays saved on Isa's device so she doesn't have to type it every time. It's the only thing this site stores on a device, and it's hers, not yours.
6. How long we keep it
| What | How long |
|---|---|
| Waitlist data | Until you unsubscribe, or up to 24 months without you opening a single email. Whichever comes first |
| Proof of your consent (text and date) | 3 years after it ends, because it's what lets us prove you signed yourself up |
| Billing and purchase data | 6 years, which is what Spanish law requires for keeping the books |
| Your entry form answers | Up to 6 months after Demo Day |
| Your check-ins and your tracking sheet | Up to 12 months after Demo Day, so we can settle any guarantee claim |
| What you posted in the community | As long as the community exists, or until you ask for it to be deleted |
| Recordings of the sessions and Demo Day | Until at least October 20, 2027 |
| Your testimonial or your image in sales material | Until you withdraw permission |
When the deadline hits, it gets deleted or anonymized.
7. Your rights
You have all of them, and exercising them is free. You write to hello@vibensell.com and that's it. You don't have to explain why.
- Know what we have of yours and ask for a copy.
- Correct anything that's wrong.
- Delete everything. Without giving reasons. The only thing that can stay is what the law obliges us to keep, like an invoice, and we tell you exactly what stays and why.
- Take your data with you in a file you can open somewhere else.
- Object to us using it for something, or ask us to freeze it while something gets sorted out.
- Withdraw your consent whenever you want. What we did before you withdrew it stays valid, but going forward we stop.
- Unsubscribe from the emails with one click, in any email we send you. There's always an unsubscribe link and it always works.
- We don't decide anything about you with a robot. There's no automated profiling and no automated decisions.
How long we take: we answer within 3 business days and resolve it within 30 calendar days at the most, which is what the law allows.
If you think we got it wrong: you can complain to the Spanish Data Protection Agency (www.aepd.es), or to the data protection authority of the EU country where you live if that applies. And if you're in the United States, to your state's attorney general's office.
8. If you live in California
California law (CCPA and CPRA) gives its residents extra rights. Because of our size, we're not legally required to comply today (it applies to large businesses or to businesses that live off selling data, and we're neither). We give you these rights anyway, because it seems right and because it costs us nothing:
- Know what categories of your data we collected, where from, what for and who we shared it with. All of that is in sections 2, 4 and 5 of this page.
- Have it deleted.
- Correct it.
- Not be treated differently for exercising any of these rights. We won't charge you more or give you less.
About selling or sharing your information: we don't sell your personal information and we don't share it for cross-context behavioral advertising. We haven't done so in the last 12 months either. That's why you won't see a "do not sell my information" button, because there's nothing to switch off. If that ever changed, this page changes first and we tell you.
Your browser's signal: if you send Global Privacy Control, we honor it. The moment it arrives, we stop counting your visits entirely, as explained in section 9.
Sensitive data: we don't collect the categories California considers sensitive.
You can exercise all of this by writing to hello@vibensell.com, or through someone you authorize in writing.
9. Cookies and visit measurement
This site uses no advertising cookies and no third party tracking tools. There's no Meta pixel, no TikTok pixel, no Google Analytics. On your phone and your computer we store nothing: no cookies, no local storage, no browser fingerprinting. That's also why you don't get a cookie banner: that banner exists to ask your permission before leaving something on your device, and on yours we leave nothing.
There is one thing we do look at, and we're telling you even though it doesn't affect you. Our counter asks whether a mark of ours called vs_yo exists in the browser. That mark only exists on the devices of Isa and whoever works with her, and it's there so their own visits don't inflate the numbers. In your browser it doesn't exist, so the question goes unanswered: nothing of yours is read and nothing is written. It's a yes or a no, with no identifier and nothing that could be used to recognise you.
What we do is measure how the page is doing, with our own tool running on our own server. Every time a page is opened we store one line with this, and nothing else:
- The day and time.
- Which page was opened and in which language, based on the version you opened (Spanish or English).
- Which country you're in. The country and that's it: no city, no region, no address.
- Whether it was on a phone or a computer. No brand, no model.
- Where you came from: the domain of the site that brought you (
instagram.comor a search engine, for example), never the full address of that page, and the campaign tags the link carries (theutmones: which email, which network and which campaign you came from). - What happened on that page: whether you just opened it, whether you left your email for the masterclass, or whether you clicked the pay button. Careful, the button, not the purchase: what happens inside Stripe is known by Stripe.
- A visitor code that lasts one day, so we don't count you five times if you open five pages in a row, and so we can tell how you arrived before you left your email.
We do not store your IP address. Your IP and your browser type are used for an instant, inside the server, for four things: working out the country, knowing whether it's a phone or a computer, filtering out bots, and computing that daily code. Then they're discarded. They never enter the database and they don't stay in our logs.
That code isn't your name and it doesn't last. It's the result of a maths operation that can't be undone, made with a secret key and today's date. It changes on its own every night, so tomorrow it no longer recognises you: we can't follow you from one day to the next, or from one device to another, or anywhere outside this site. Even so, we're not telling you it's anonymous, because while the day lasts it's still data about you. That's why we're spelling it out in this much detail.
Where it lives and how long: in the same database as everything else (Supabase, Paris, European Union), in a separate table that has no name, no email and no IP of yours. It isn't shared with anyone, isn't sold, isn't used for advertising and doesn't leave there. It deletes itself after twelve months.
On what legal basis: our legitimate interest in knowing how many people come in and what's working. It's the minimum needed to keep this running, and we do it with the poorest data that still works.
And if you don't want us counting you, it takes one click and it actually works. If your browser sends the Global Privacy Control or Do Not Track signal, our counter switches itself off: not a single line of yours gets sent. Not the visit, not the signup, not the click on the pay button. It isn't that we store it and don't look at it, it's that it never leaves your browser and nothing ever reaches us. That signal is a checkbox in the privacy settings of several browsers, and some of them ship with it switched on. You don't have to write to us or ask our permission.
The limit, said just as plainly: whatever was counted before you switched that signal on stays counted. Since those lines contain no name of yours, no email and no IP, we can't tell which ones are yours to pull them out. It isn't that we don't want to, it's that they're built on purpose so that it can't be done. After twelve months they delete themselves, like everything else. If you'd rather talk it through with a person, you write to hello@vibensell.com and we answer.
If we ever add advertising, pixels or third party analytics, this page gets updated before that gets switched on, and you'll see a cookie notice with a real option to say no.
10. Minors
This is for people 18 and over. We don't knowingly collect data from minors. If we find out we have a minor's data, we delete it.
11. Security
Your data sits on servers with restricted, password protected access, and only the people who need to see it to do their job see it. Nobody is immune to an incident. If something ever happened that puts you at risk, we tell you and the relevant authority within 72 hours of finding out, as the law requires.
12. Changes to this policy
If we change something important, we tell you by email before it takes effect. The date at the top tells you when it was last updated.
13. Contact
hello@vibensell.com Isabella Fernández Madrid, Spain 1801 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, United States
This document was drafted following standard industry practice and is not a substitute for advice from a licensed attorney.