Privacy Policy
Last updated 8 September 2026
This policy explains what personal data Vybrants collects, why, and what we do with it. Vybrants is operated from Singapore and handles personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA). Where we collect or use the personal information of people in Australia — which we do — we also handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. What we collect
From you: your email address, and your name if you sign in with Google. Anything you type into or upload to your site. Billing is handled by Stripe — we receive a customer reference and subscription status, never your card number.
About businesses: we collect publicly listed business information — name, address, phone number, opening hours, photographs and reviews — from Google Business Profiles and public business websites, in order to build and offer websites. Where that information identifies a person (a sole trader's name or mobile, say), it is personal information and this policy applies to it.
Automatically: basic technical and usage data when you use our site — IP address, browser, pages viewed.
2. Why we collect it
To build and host your website, to let you sign in and manage it, to take payment, to contact you about your account, and to contact businesses about a website we have built for them.
3. Who we share it with
Only the service providers we need to run the product: hosting and infrastructure, our database and file storage, email and SMS delivery, payment processing, and the AI provider that drafts page copy. Each receives only what it needs for that task. We do not sell personal information.
These providers store data outside Singapore and outside Australia, including in the United States and the European Union. Where we transfer personal data overseas we take reasonable steps to ensure it receives a comparable standard of protection, as the PDPA requires.
4. How long we keep it
For as long as your account exists, and afterwards only as long as we need it for legal, tax or dispute-resolution purposes. Business information we collected but never made contact about is deleted when it is no longer useful. This is also what the PDPA requires: we stop retaining personal data once the purpose we collected it for has ended.
5. Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Ask by replying to any email from us. We will respond within a reasonable time, and within 30 days.
If a business does not want us to contact them, or wants their listing removed from our system, they can tell us the same way and we will suppress it.
6. Security
Data is encrypted in transit and at rest with our providers. Access to production data is limited to the people who need it. No system is perfectly secure; if a data breach is likely to cause significant harm we will notify affected people and the relevant regulator as required — the PDPC in Singapore, and the OAIC where Australian personal information is involved.
7. Complaints
Tell us first — reply to any email from us and we will investigate. If you are not satisfied, you can complain to the Personal Data Protection Commission in Singapore at pdpc.gov.sg, or, if you are in Australia, to the Office of the Australian Information Commissioner at oaic.gov.au.