Privacy Policy for GHL Vibe Sync
Effective Date: July 2, 2026
Last Updated: July 2, 2026
This Privacy Policy describes how GHL Vibe Sync ("we", "us", "our", or the "Software") collects, uses, processes, and protects the personal data of users ("User", "Developer", "Client", or "Data Subject") in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679), the California Consumer Privacy Act (CCPA/CPRA), and the Google Chrome Web Store and Mozilla Firefox Add-on Developer Privacy Policies.
1. Data Controller
The Data Controller for the personal data processed through the browser extension and licensing infrastructure is:
- Data Controller: GHL Vibe Sync
- Registered Office: Udine, Italy
- Privacy Contact Email: support@ghlvibesync.pegosystem.com (to be used for exercising GDPR/CCPA rights)
2. Types of Data Collected and Processing Methods
We only process personal data that is strictly necessary for the technical operation of the Software, the validation of active purchase licenses, and anti-piracy protection.
A. Data Provided Directly by the User
- Email Address: Collected during license activation inside the browser extension popup. The license key and the link to download the extension will be sent via email after a successful payment.
- License Key: A unique alphanumeric string generated at checkout and used to verify subscription or lifetime purchase validity.
B. Data Collected Automatically (System Data & Device Locking)
- Device ID (Cryptographic UUID): Upon initial activation, the extension generates a unique, persistent UUID v4 stored locally in chrome.storage.local (or browser.storage.local). This ID is transmitted to our serverless bridge to associate your license with your physical workstation ("Node-Locking").
- Browser Fingerprint Metadata: Non-sensitive technical parameters of the browser (screen resolution, language settings, timezone) required to validate device integrity and prevent concurrent fraud/license sharing across unauthorized workstations.
C. GHL Authentication Data (Local Processing Only)
- JWT Tokens and Session Cookies: The extension dynamically reads authentication tokens directly from the browser locally to communicate with GoHighLevel's Vibe Coder.
- Client-Side Processing Guarantee: This data is processed exclusively on the client-side (inside your browser). It is never stored, monitored, or transmitted to our serverless bridge on Vercel or any third-party infrastructure. All authentication tokens are sent directly and securely via TLS 1.3 to GoHighLevel’s official APIs (services.leadconnectorhq.com).
D. Source Code and Project Files (Stateless Architecture)
- Stateless Processing Guarantee: Our Vercel serverless bridge operates on a completely stateless architecture regarding your project source files (HTML, CSS, JS, React, etc.). All project files synchronized via "Push" or "Pull" transitions pass directly from your browser to GoHighLevel's servers in volatile memory. We do not store, log, inspect, or possess any copy of your source code, templates, or databases.
3. Legal Basis for Processing (Art. 6 GDPR)
We process personal data based on the following legal grounds:
- Contract Performance (Art. 6, para 1(b) GDPR): Processing of Email and License Key is strictly necessary to perform our contractual obligation to unlock, run, and maintain the features of GHL Vibe Sync.
- Legitimate Interest (Art. 6, para 1(f) GDPR): Processing of the Device ID and Fingerprint Metadata is necessary for our legitimate interest in protecting our intellectual property, preventing unauthorized concurrent license sharing, and defending against fraud or piracy.
4. Purpose of Processing
The data collected is processed exclusively for:
- Validation & Onboarding: Confirming active licenses and validating credentials.
- Fraud Prevention (Device Locking): Ensuring a license key is used by only one active device/browser at any given time.
- Technical Support: Assisting with technical issues, manual device resets, and critical system notifications.
5. Third-Party Processors and Data Recipients
We do not sell, rent, trade, or lease personal data to third parties. Data is processed exclusively by the following sub-processors under strict confidentiality terms:
- Vercel Inc. (USA / EU Edge Servers): Hosts our serverless gateway. Data is processed in transit over highly secure, encrypted TLS 1.3 channels. Vercel complies with Standard Contractual Clauses (SCCs) for cross-border data transfers.
- GoHighLevel Inc. (LeadConnector LLC - USA): Houses our customer database, activation tags, and device IDs. GHL applies high-grade industry security standards (SOC 2, encryption at rest and in transit).
- Stripe Inc. (USA/Global): Handles secure payment processing and subscription billing management. We do not store or have access to your raw credit card numbers.
6. Data Retention Period
- License & Registration Data: Retained for the active duration of your subscription or lifetime contract. Upon cancellation or termination, transactional logs are retained for up to 24 months to satisfy tax, accounting, and anti-fraud reporting requirements.
- Device ID / Fingerprint: Can be instantly erased by the User by clicking the "Scollega questo dispositivo / Disconnect device" button inside the popup or via the remote reset portal. Upon reset, the field is immediately cleared ("") from the CRM database.
- Server Connection Logs: System connection logs on Vercel (temporary IP addresses used for network diagnostics) are automatically purged within 30 days.
7. User Rights under GDPR and CCPA/CPRA
7.1. GDPR Rights (For European & UK Users)
In accordance with Chapter III of the GDPR, you have the right to request:
- Right of Access (Art. 15): To obtain confirmation of data processing and a copy of your personal data.
- Right to Rectification (Art. 16): To correct inaccurate or incomplete personal data.
- Right to Erasure / "To be Forgotten" (Art. 17): To request permanent deletion of your data when no longer required.
- Right to Portability (Art. 20): To receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): To object to data processing based on our legitimate interest.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your national Data Protection Authority (DPA).
7.2. CCPA/CPRA Rights (For California Residents)
- Right to Know/Access: Request details on categories and specific pieces of personal data collected over the past 12 months.
- Right to Delete: Request deletion of personal data collected, subject to legal exceptions.
- Right to Opt-Out of Sale/Sharing: We declare that we do not sell, share, or monetize your personal data with third parties.
- Right to Non-Discrimination: We will not deny services or charge different prices for exercising your privacy rights.
To exercise any of these rights, contact us at support@ghlvibesync.pegosystem.com.
8. Data Security
We implement robust technical and organizational security measures to protect your data:
- Encryption in Transit: All communications between the extension, Vercel, and GoHighLevel are strictly encrypted via TLS 1.3 (HTTPS).
- Data Minimization: We only request, process, and write the minimum number of data fields required to run the license check.
- Censored Displays: License keys are partially masked (XXXX-XXXX-...) inside the extension popup to prevent local visual snooping.
9. Changes to this Policy
We reserve the right to modify or update this Privacy Policy at our discretion to reflect regulatory updates or software enhancements. Any modifications will be posted here with an updated "Last Updated" date. By continuing to use the Software, you acknowledge and accept the updated terms.
