RianVibe

Privacy & Cookie Policy

This Policy explains what personal data RianVibe uses, why it is used, who receives it, and how you can exercise your privacy choices and rights.

Version: 2026-07-16
Effective date: 2026-07-16
Last updated: 2026-07-16

1. Controller and scope

Privacy requests concerning RianVibe may be sent to hello@rianvibe.com.

This Policy applies to the RianVibe website, accounts, course access, learning activity, support, and payments. It does not govern independent third-party websites or tools you choose to use.

RianVibe determines why and how the platform-specific data described below is used, while some providers may act as independent controllers for their own legal, payment, security, or compliance purposes. This Policy should be read together with the User Agreement. It covers visitors, account holders, prospective purchasers, purchasers, learners, and people who contact support. It does not convert data entered directly into an independent third-party tool into RianVibe data merely because that tool appears in a lesson.

2. Data we process

We process only data reasonably needed to provide, secure, improve, and account for the service.

The categories above describe the ordinary records created by the current platform. A visitor who does not create an account normally produces fewer RianVibe records than a signed-in purchaser. Learning records are connected to stable course and lesson identifiers so progress and access can be restored consistently across supported languages. Transaction records contain payment state and provider references needed to reconcile an order, but sensitive card entry occurs on Stripe-controlled pages. Support content depends on what you choose to send, so please avoid passwords, full card details, identity documents, or unrelated sensitive information unless we specifically explain why it is required.

3. Sources of data

We receive data directly from you, from your browser and use of the platform, from Stripe concerning transaction state, and from service providers that operate authentication, hosting, and security.

Data may be created at different points in the service: when the browser requests a page, when you select language or currency, when Supabase authenticates a magic link, when you open or complete course material, when Stripe reports a payment event, and when you contact support. Information received from a provider is limited to what the integration and provider make available for the stated function. We do not purchase marketing lists or combine the current platform records with data-broker profiles. If another person pays while you use the learner account, transaction and account information may relate to different people and should be supplied accurately.

A legal basis describes why a particular use is permitted; it does not expand the data categories or purposes listed here. Contract-related processing is used where information is needed to create the requested account, deliver access, remember learning state, or answer purchase support. Legal obligations can require minimum tax, accounting, payment, security, or claim records. Legitimate interests, where available, are assessed against the effect on the individual and are used for proportionate security, troubleshooting, fraud prevention, and service protection.

5. Cookies and similar technologies

Necessary cookies provide authentication, security, language, and currency preferences. Blocking them may prevent sign-in or other core platform functions.

Cookies are small browser-stored values; similar browser mechanisms may perform the same essential preference or session function. The listed durations are maximum or typical periods and a cookie may disappear earlier because you sign out, clear browser data, use private browsing, or the provider rotates a session. We will update this Policy before activating a materially different cookie purpose.

6. Service providers and disclosures

We disclose data only as needed to operate the service, comply with law, protect rights, or complete a transaction. Current provider categories include Supabase for authentication and database services, Stripe for payments and fraud controls, Vercel for hosting and delivery, and email infrastructure used by authentication and service messages.

Providers process data under their own contractual, security, retention, and legal obligations. Stripe independently determines some payment and compliance processing. We may also disclose limited information to professional advisers, authorities, or courts when lawfully required. We do not sell personal data.

Each provider receives the information needed for its role rather than unrestricted access to every platform record. For example, authentication and database infrastructure handles account and learning records, payment infrastructure handles transaction and risk information, and hosting infrastructure processes requests and operational logs. Providers may use subprocessors and infrastructure in multiple regions under their published and contractual arrangements. If ownership or operation of RianVibe changes, relevant records may be transferred as part of that transaction subject to applicable notice, confidentiality, and data-protection requirements; this does not permit sale of personal data for advertising.

7. International transfers

RianVibe is operated from Thailand and uses global providers. Data may therefore be processed in Thailand, Vietnam, the United States, the European Economic Area, Singapore, or other locations used by our providers. Where required, we rely on contractual safeguards, adequacy mechanisms, provider transfer terms, consent, or another lawful transfer mechanism.

An international transfer means data is available to or processed by a provider outside the country where you are located. The exact processing location can change as a global provider updates its infrastructure, support, or subprocessors, so the country list is illustrative rather than a promise that every record visits every location. We consider the nature of the data, provider role, contractual terms, security controls, and legally available transfer mechanism. Where local law gives you information or objection rights concerning a transfer, you may contact us.

8. Retention

Account, entitlement, progress, and quiz data are generally kept while the account and course access remain active. You may request account deletion. We then delete or de-identify learning and account data that is no longer needed.

Minimal transaction, tax, refund/dispute, security, and User Agreement acceptance records may be kept for the period required by tax, accounting, payment, anti-fraud, limitation, and legal-claims rules. Provider logs and backups are retained for limited operational cycles under provider settings.

Retention is based on purpose, account and purchase status, legal requirements, fraud and security risk, limitation periods, provider capabilities, and whether a record can be deleted or de-identified without undermining another required record. Deleting an account does not mean every copy disappears instantly: active systems are handled first, while limited backups and logs age out through controlled cycles and are not restored for ordinary use. A retained acceptance or transaction record is separated from active learning access where practical and is kept only for the applicable evidentiary purpose. When a category is no longer reasonably needed, it should be deleted, anonymized, or allowed to expire under the relevant lifecycle.

9. Your rights

Depending on applicable law, you may ask to know about processing; access, correct, obtain, delete, or restrict data; object to certain processing; withdraw consent; and complain to a competent data protection or consumer authority. Send a request from the account email to hello@rianvibe.com.

We may need to verify identity and may retain data where deletion would conflict with a legal obligation, payment record, fraud prevention, or defense of legal claims. We will explain a lawful refusal or limitation. Account deletion ends access tied to that account.

A request should identify the account email, the right you wish to exercise, and enough context for us to find the relevant records. To protect the account, we may respond through the verified email or ask for proportionate confirmation; do not send unnecessary identity documents. We will assess the request under the law that applies to the person and processing, communicate the outcome, and explain a lawful restriction where required. Rights are not absolute: for example, deletion may be limited by a required transaction record, and access may not include another person's data or protected security information.

10. Security and age

We use access controls, row-level database restrictions, least-privilege service credentials, encrypted transport, provider security controls, and payment processing through Stripe. No system can guarantee absolute security; please protect access to your email account and report suspected compromise.

RianVibe is for adults aged 18 or older. We do not knowingly offer accounts or courses to children. If you believe a minor supplied data, contact us so we can investigate and delete it where required.

Security measures are selected for the current service and include separation between browser and trusted server operations, access checks, database row restrictions, least-privilege credentials, encrypted transport, provider controls, and payment collection through Stripe. They reduce risk but cannot eliminate phishing, compromised email accounts, malicious devices, internet failures, provider incidents, or every unknown vulnerability. Use an email account you control, do not forward magic links, and report suspicious activity without sending secrets. If we confirm a personal-data incident, we will assess containment, provider coordination, documentation, and any notice required by applicable law. The adult-only rule reduces but does not replace our duty to respond if child data is identified.

11. Changes and contact

We may update this Policy to reflect legal, provider, security, or product changes. The version and dates appear above. Material changes will be notified by email or a prominent platform notice. We will update this Policy before adding a materially different data use or cookie purpose.

Privacy requests and questions: hello@rianvibe.com

The version and dates help identify the Policy that described processing at a particular time. Editorial clarification may be made without changing the data use, while a material new purpose, provider category, advertising technology, or marketing channel requires review and an updated notice where applicable. Service messages about an important privacy change are not marketing. Questions may be submitted in English, Thai, or Vietnamese, and we will use reasonable efforts to respond in an appropriate supported language.