Legal center

Privacy Policy

Last updated: August 2026 · Controller: Vribe, Inc. (Delaware, USA)

This policy explains what data Vribe collects, what it uses it for and who it shares it with. It is written about what the product does today: every datum named here is genuinely collected, and every use described genuinely happens. It includes the uncomfortable part — we measure use of the platform and advertise outside it with third-party tools, when you accept those categories — because telling you is the only way you can decide. Which tools are running at any given moment can be checked in the help centre. If you find a difference between what this document says and what the app does, it is our error and we want to know.

1. Who the controller is

The data controller is Vribe, Inc., a company incorporated in Delaware, United States, operating in Guatemala City. It decides what data is collected and for what purpose, and it is who you may address any privacy question or complaint to, by writing to privacy@vribe.app.

2. Information we collect

The data we hold about you arrives through four distinct routes, and it is worth separating them: some data the Platform cannot function without, some you give if you want to, some is recorded automatically as you use the service, and some reaches us from third parties.

2.1 Data required to use Vribe

Without these we cannot verify you, charge you, or hold together a contract between two people who do not know each other. If you prefer not to provide them, you will not be able to book or list:

  • Identity data: full name, date of birth, document photo (DPI, passport or license), facial verification selfie.
  • Contact data: email address, phone number.
  • Financial data: payment method tokenized by Stripe. Vribe never stores full card numbers.
  • Valid driver's licence: photo and details, in order to rent or list.
  • Vehicle details, if you list: plate, registration document and insurance policy.
  • A customer identifier with our payment processor, created when you book in No-Deposit mode, linking your account to your stored payment methods and your charges.

2.2 Data you give only if you want to

These improve your experience or the confidence your profile inspires, but you can omit them and keep using Vribe normally:

  • Profile photo and personal description: they let the other party know who they will be dealing with.
  • Device location: only if you enable it, and only to order results by proximity.
  • Language and communication preferences, including which notifications you choose to receive.
  • Content you write yourself: reviews, messages and descriptions of your vehicles.

2.3 Data recorded automatically

Using the Platform leaves technical and activity records. You do not need to do anything to generate them. Those for security and operation are unavoidable; those for measurement and advertising depend on what you accepted:

  • Technical data: IP address, device type, operating system, session cookies.
  • Usage data: bookings, search history, ratings, in-platform messages.
  • Security records: sign-in attempts and actions on your account, to detect fraud.
  • Cookies in five categories — essential, personalization, analytics, advertising and one for first-party measurement — detailed in the cookies section. Only the essential ones are mandatory.

2.4 Data we receive from other services

If you create your account with Google, we receive from Google your name, your email address and your profile picture; we do not receive your password or the content of your account. From the payment processor we receive, besides the result of the charge, a technical fingerprint of the card you used: it is not the card number and does not allow it to be reconstructed, it is an identifier the processor itself generates. We store it for one thing only, and it is worth saying because it is a datum that persists between bookings: to prevent the same card claiming the welcome credit from several different accounts. If you invite an additional driver, the email you type is used only to locate an existing Vribe account: if there is none, the invitation is rejected and that email is not stored. The referral programme works with a link you share by your own means: Vribe does not receive your address book or anyone's contacts.

2.5 What we do not collect

It is worth stating what is absent too. None of this is collected, not even anonymously:

  • Your full card numbers: Stripe receives and stores them; we only see an identifier and the last digits.
  • Your password, if you sign in with Google: authentication happens at Google and never reaches us.
  • Your contact list, your calendar, your photos or any device file you do not upload yourself.
  • A history of your movements: location is used for the search at hand and is not accumulated.
  • Data about you bought from third parties: we do not acquire profiles, lists or information about you from data brokers. What we know about you, you gave us or it arose from your use of the platform.

3. Biometric data and facial verification

To verify your identity we ask for a photo of your ID document and a selfie. Both images are sent to our artificial intelligence provider for one purpose only: to check that the document is legible and genuine and that the person in the selfie matches the photo on the document. That facial comparison is sensitive data and we handle it under stricter rules: it is not used for advertising, it is not shared with hosts or travelers, and we do not build a biometric profile to recognize you outside that process. If the automated comparison is inconclusive, someone on our team reviews the case. The images are kept under the retention clause of this policy and may be released in the event of a reported incident, on the terms of the sharing section.

4. Legal basis for processing

We process your data on the basis of: performance of the contract (to provide the booking and payment service); compliance with legal obligations (identity verification, tax obligations, fraud prevention); our legitimate interest (platform security, service improvement, operational communication); and your consent, which is the sole basis for analytics and advertising cookies and which you may withdraw at any time from the preferences panel, without that affecting any of the above.

5. How we use your information

Every item we collect answers a specific purpose. These are all of them, and we do not use your data for anything outside this list. The last one is the only one that depends on your consent: switch it off and everything else keeps working the same.

  • Verify your identity and calculate your Trust Score
  • Process payments and refunds securely
  • Connect you with Hosts or Travelers for your bookings
  • Analyze inspection photos with artificial intelligence to document vehicle condition
  • Send you notifications related to your bookings and account
  • Improve the platform and personalize your experience
  • Comply with legal obligations in Guatemala
  • Retain your verification documents as evidence in a reported incident (for example, the theft of a vehicle) and disclose them under the terms of the sharing section
  • Measuring, with our own records, which campaign brought you to Vribe, so we know which advertising is worth paying for. This data does not leave Vribe.
  • Measuring our campaigns and showing you Vribe ads off the platform, with Google, Meta and TikTok — only if you accept that category. That measurement happens from your browser and also from our servers when a booking is confirmed; in both cases we check first that the category is still accepted, and your email never travels in the clear.

5.1 We do not train models on your data

Vribe does not train its own models on your data. The artificial-intelligence models we use to run the service come from external providers, invoked through their business interfaces, whose terms provide that content sent that way is not used to train their models. Advertising is a different matter: if you accept that category, Google, Meta and TikTok receive data about your browsing on Vribe and use it for their own ad-targeting models, under their own policies. One more reason to know that category switches off in one click.

6. Information sharing

We share data in the cases that follow, and only those. The first four are inherent to the service; among the processors, the three analytics and advertising providers are the only ones that depend on your accepting them:

6.1 Public profile

Your name, your photo, your Trust Score and level, whether your identity is verified, how long you have been part of Vribe and your published reviews are visible to anyone who opens your profile; if you are a host, so are your published vehicles. Your email, phone number and documents are not public.

6.2 With other users

we share your name, profile photo and Trust Score with Hosts/Travelers when you make or receive a booking.

6.3 Between the parties to a booking

The rental agreement both parties sign includes each party's name and ID document type and number, the traveler's license with its country and expiry date, and the names of any authorized additional drivers. The booking conversation stays in both inboxes. Vribe does not exchange phone numbers or email addresses between host and traveler: communication goes through the platform.

6.4 With the other party in an incident

if a vehicle is reported stolen, Vribe may hand the affected host the identity documents of the traveler and their authorized drivers so they can present them to the competent authority. Vribe authorizes this release case by case: it is not automatic and it is not at the host's discretion.

6.5 With data processors

Each receives only the data it needs for its function and handles it under its own business terms. We name the providers you see with your own eyes — the one that processes the payment and the advertising platforms you can switch off — and group the rest by category, which is what data protection law asks for: what matters is which kind of provider receives which data and why. If you want the full named list of our processors, write to privacy@vribe.app and we will send it to you. The last three receive nothing unless you accepted analytics or advertising:

  • Stripe — processes payments, holds the security deposit and issues refunds. Your full card details go to Stripe, not to Vribe; we name it because you see it at the moment you pay. If you book No-Deposit, Stripe stores your payment method in tokenised form for the booking's guarantee, the authorised damage charge and your future bookings; and when your bank replaces or renews your card, it may receive the new details from the payment networks so those charges are not interrupted.
  • Infrastructure providers — host the Platform and process every request you make, hold the database, your authentication and the files you upload, draw the maps, curb automated abuse and deliver the push notifications you accepted. All of them see your IP address, to differing extents: it is what your consent regime's country is inferred from, what requests are counted against to stop attacks, and when a map loads the coordinates of the area being shown are sent as well.
  • Artificial intelligence providers — verify your identity by reading the document and comparing it with the selfie, read your driving licence and the insurance policy, analyse inspection photos to detect damage, generate price suggestions for the host and vehicle recommendations, and power the support assistant and the translation of the Platform. They are invoked through their business interfaces, whose terms state that content sent that way is not used to train their models.
  • Transactional email — sends the emails for your bookings: confirmations, reminders, return notices and the notifications the system sends you. It receives your email address and the content of that message, nothing more.
  • Error monitoring — records the Platform's technical failures so they can be fixed, along with the page where the error occurred and technical data about your browser. It is essential and cannot be switched off: without it, a failure that is affecting you may stay invisible to us.
  • Google — Analytics to measure platform usage, and Google Ads to measure campaigns and show you ads.
  • Meta — the Facebook and Instagram pixel, to measure campaigns and show you ads on their platforms.
  • TikTok — pixel to measure campaigns and show you ads on their platform.

6.6 With authorities

only when required by applicable law or a valid court order.

7. Third-party privacy practices

This policy describes what Vribe does with your data. It cannot describe — or govern — what the other companies and people you come across while using the Platform do with it. The distinction matters the day you want to exercise a right: if the data is still in our hands we resolve it, and if it has passed to someone who decides on their own account, the claim has to go to them. Here is the map of who is who.

7.1 How far this policy reaches

It covers the processing Vribe decides on: what is collected, why, how long it is kept and who it is shared with. The providers in the previous section are covered, because they decide nothing on their own account: they process your data to provide us the service we contracted and nothing else. What falls outside is everything Vribe does not decide — companies that set their own purposes, and the people who use the Platform. That is what the three subsections below are about.

7.2 Third-party services inside the Platform

Some pieces of the Platform are operated by another company and run under its own rules. The form where you type your card details is served by the payment processor, and those details go straight to it: Vribe never sees them. The maps are drawn by their operator, which on loading receives your IP address and the coordinates of the area being shown. If you sign in with your Google account, the authorisation screen is Google's and it is Google that decides what it hands us. And push notifications are delivered by your browser's or operating system's service. In all four cases, what that operator does with what it receives is governed by its own privacy policy, not by this one.

7.3 Links and content that are not ours

The Platform may contain links to sites we do not control, and vehicle listings are written by hosts. A link does not mean we endorse that site, that we have reviewed its content, or that we answer for what it does with your data: clicking takes you out of Vribe and into a place with its own rules. Before giving any site your data, it is worth reading its privacy policy.

7.4 The other people on the Platform

This is the part most often overlooked. When a host and a traveler close a booking, each receives data about the other — name, means of contact and, when an incident is reported, the identification details set out in the sharing section — and from that moment each answers for what they do with it. Vribe cannot delete the phone number the other party wrote down, nor the contract both signed and keep. The same goes for the tracking device some hosts install in their vehicle, which belongs to the host and their provider — we do not install it, do not operate it and do not receive the position it records — and for the additional drivers you invite. If you believe someone misused your data, write to us anyway: we do not govern that processing, but we can act on the account of anyone who breaks the community rules. And on a trip with chauffeur, the chauffeur the host assigns sees your name and the booking details needed to provide the service, and you see their name, photo and trust level — never their phone number or documents.

8. Cookies

Vribe uses cookies in five categories: essential, personalization, analytics, advertising and one for first-party measurement. That last one is written by our server to know which campaign brought you, does not leave Vribe and does not appear in the panel: where prior consent applies, it is only written if you accepted analytics. Only the essential ones are mandatory — without them you cannot sign in or pay. The other three are yours to decide, which is why you will see a cookie notice the first time you visit. If you connect from the European Union, the United Kingdom, Switzerland or the European Economic Area, nothing beyond the essential is activated until you accept it. From the rest of the world, Guatemala included, the three categories come switched on and you can turn them off in one click; we say so here in plain words rather than leaving it buried in the banner. The operational detail — the real name of each cookie, its duration and what is deleted on revoking — is in the Cookie policy.

8.1 The cookies we use

These are the ones Vribe sets directly, with their real names, what they do and how long they last. Those from the analytics and advertising providers are listed separately, further down:

  • NEXT_LOCALE — functional. Remembers the language you chose. Lasts the session: it is deleted when you close the browser.
  • vribe_ref — functional. Records who invited you, so their referral can be credited if you sign up. Lasts 30 days and is HttpOnly, so no script can read it.
  • sb-…-auth-token — essential. Keeps you signed in. It only exists if you signed in, and is removed when you sign out.
  • Stripe cookies — essential. Stripe sets them during payment to prevent fraud. They appear only in the payment flow, not across the rest of the site.
  • vribe_geo — essential. Stores the country code our infrastructure infers from your IP, so we know whether the European consent regime applies to you or the rest-of-world one. Lasts 30 days. It is readable by JavaScript on purpose, because it is the browser that decides what to activate with it; it carries no data beyond the country.

8.2 What we do not use

Even with advertising and analytics, some things still do not happen. There are no cookies from advertising networks beyond Google, Meta and TikTok. We do not sell access to your data to third parties for money. We do not buy profiles of you from data brokers. None of the optional categories activates in Europe without your acceptance, and in the rest of the world they switch off in one click from the footer. When you switch a category off, besides stopping the flow of data we delete the cookies that tool had left in your browser. And because no uniform standard exists, the Platform does not respond to the browser's Do Not Track signal; use the preferences panel, which does take effect.

8.3 How to control them

You have two routes, and we recommend the first. From "Cookie preferences" in the footer of any page you switch categories off and the change applies immediately: we stop sending data and delete the cookies that tool had left. The second is your browser, where you can delete or block them all. Note the effect: without the session cookie you cannot stay signed in, without the language one the Platform reverts to the default language on each visit, and without the geo one we will not know whether the European regime applies to you. Signing out removes the authentication cookie, and the referral one expires on its own after 30 days.

9. Automated analysis of communications

Messages exchanged between host and traveler on the platform are processed automatically for two reasons. The first is security: they are cleaned of potentially harmful code before being displayed. The second is transaction integrity: we detect contact-data patterns — phone numbers, email addresses and messaging links — and flag the message to discourage taking the deal off Vribe, where there is no contract, no inspections and no backing if something goes wrong. The message is sent anyway: the system warns, it does not block. In the event of a reported incident, that booking's conversation becomes part of the case file. We do not analyze messages for advertising purposes and we do not use them to profile you.

10. Location: the three different things that word hides

"Location" is used for three things that have nothing to do with one another, and mixing them is the easiest way to say something false without meaning to. We separate them: your device's precise position, the country your connection appears to come from, and the GPS some hosts install in their vehicle. You control the first, the infrastructure infers the second, and the third is not even ours.

10.1 Your precise location — only if you enable it

Your device's exact position is used only if you grant the browser permission, and only to order a search's results by proximity. It is not stored: it is used for that query and discarded. We build no history of your movements and do not know where you have been. Without that permission, search works just the same, ordered by rating.

10.2 Your country — always inferred, and here is why

This is worth stating plainly, because it does not depend on any permission from you. Every time you load a page, our infrastructure provider infers from your IP address the country you are connecting from, and we store it for 30 days in a cookie called vribe_geo. It is not your precise location: it is a country code, nothing more — no city, no street, no coordinates. And it has a single function: deciding which consent regime applies to you. If you connect from the European Union, the United Kingdom, Switzerland or the European Economic Area, nothing beyond the essential is activated until you accept it; from the rest of the world, the categories come switched on and you can turn them off whenever you want. Without that datum we could not know which of the two to apply to you, so it is inferred before you can decide anything — because it is what makes deciding possible.

10.3 The vehicle's GPS — the host's, not ours

Some vehicles carry a tracking device installed by their host, and the listing says so before you book. That device belongs to the host and their provider, not to Vribe: we do not install it, do not operate it and do not receive the position it records. The host is responsible for that processing and for using it lawfully.

11. Data retention

We keep your data while your account is active and for as long as needed to fulfill the purposes described and our legal, tax and dispute-resolution obligations. Verification documents —travelers' ID document, selfie and driver's license; hosts' ID document and vehicle paperwork— are kept in private storage with restricted access while your account is active and for up to 5 years after your last booking, so we can establish the parties' identity in the event of an incident, a claim or a request from the authorities. If a dispute or criminal complaint is ongoing, they are kept until it is definitively closed. You may request deletion of your account as described in the rights section.

11.1 How long we keep each thing

The periods are not the same for everything. These are the specific ones:

  • Verification documents (identity and licence): five years from upload, as evidence against a reported incident.
  • Insurance policies: one year from upload, for oversight and to allow a past booking to be audited.
  • Bookings, payments and inspections: for as long as our tax and accounting obligations last, and the period in which a claim remains possible.
  • Messages from a booking: for as long as the booking exists in either party's history.
  • Technical and security records: the time needed to investigate incidents and detect fraud.
  • Data from closed accounts: deleted, except what the law requires us to keep or what forms part of the evidence in an open case.
  • The record that you accepted these documents: we keep it for as long as your account exists, because it is the proof of which version you accepted and when. The IP address and browser you accepted it from are deleted after one year: they serve to investigate fraud or impersonation, not to identify you later.
  • Evidence of a collection authorisation (the text you accepted, its version, the cap, the date and the technical details of your connection): for as long as the authorisation can be invoked and throughout the chargeback defence windows. Unlike other acceptance records, this one is not removed by the periodic automatic clean-up.
  • Damage collection case files (amounts, repair shop estimate, communications): for as long as the case and its handling remain live, and afterwards for the applicable legal periods.

11.2 What has already been shared

What has already been shared does not disappear when you close your account. Published reviews remain visible, messages stay in the other party's inbox, the contract both signed is kept as proof of the transaction, and an incident's case file is retained sealed under its own rules. In addition, residual copies may remain in our backups for a limited period, until the backup cycle overwrites them. And there is one case worth stating separately: if you accepted the advertising category, the data sent to those platforms while it was active is already in their systems and is governed by their policies, not by this one. Closing your Vribe account does not recover it or delete it from there. What you can do, at any time, is switch off that category so nothing further is sent, and exercise with each platform whatever rights it grants you.

12. Your rights

You have the right to access, rectify, erase (right to be forgotten), restrict or object to processing, to data portability, and to withdraw your consent at any time. To exercise them, write to privacy@vribe.app; we will respond within the timeframes required by applicable law. You may also lodge a complaint with your country's data protection authority. On selling and sharing: Vribe does not sell your data for money, and never has. But by sending data to Google, Meta and TikTok for advertising purposes, California law treats it as "shared" even without payment. Your opt-out mechanism is the preferences panel: switching off the advertising category stops that sharing, and the link to do so is in the footer of every page.

12.1 How to exercise them

Write to privacy@vribe.app from your account's email address. We may ask you to confirm your identity before acting, precisely so that nobody else can request your data by posing as you. We respond as soon as possible, within the time limits the applicable law requires. If your request conflicts with a legal obligation of ours — for example, deleting documents that are evidence in an open case — we tell you and explain why.

13. International transfers

Vribe, Inc. is based in the United States and several of our processors handle data in the U.S. and other countries. When we transfer data from your country, we do so with the safeguards required by applicable law (for example, standard contractual clauses). By using the platform, you understand that your data may be processed outside your country of residence.

14. Security

We use SSL/TLS encryption, secure authentication and secure storage on servers in the North America region. Identity documents are stored encrypted and access to them is restricted to the purposes in this policy: verification and, when Vribe authorizes it case by case, evidence in a reported incident.

14.1 Security breach notification

If a security breach affecting your personal data occurs, we will notify the competent authorities and affected individuals when required by law, without undue delay.

15. Minors

Vribe is not intended for people under 21 and we do not intentionally collect information from people under that age.

16. Changes to this policy

This policy may be updated when the product or the applicable law changes. The last-updated date appears above, and the version published on this page is the one in force. When a change is material — a new purpose, or a new provider receiving your data — we notify you before it takes effect, by email or within the Platform.

17. Contact

For privacy enquiries, write to privacy@vribe.app. The controller is Vribe, Inc., a company incorporated in Delaware, United States, with operations in Guatemala City. Vribe has no establishment in the European Union: if you connect from there, your request is handled at that same address and you retain the right to lodge a complaint with your country's data protection authority.

What we do NOT do with your data

We do not sell it for money or rent it. We do not buy it from data brokers. We do not train our own artificial-intelligence models on it. We do not build biometric profiles or use your selfie for anything other than confirming it is you. And we do not disclose your identity document to other users, except in the narrow reported-theft case described below. What we do, and this list used to deny: we use tools from Google, Meta and TikTok to measure how people reach Vribe and to show you our ads off the platform. That involves sharing data with them, it is explained in detail below, and you can switch it off entirely from the preferences panel.

Thanks for using Vribe!

In the event of any discrepancy between the translated versions of this document, the Spanish version prevails.