Project Payments Privacy Preview
How the planned integration flow separates creator, buyer, coding-agent, and provider data.
1. Scope and controller
This draft supplements the main VibeNest Privacy Policy. Individual Entrepreneur Nikita Babenko Vladimir is the controller for account, pilot-access, integration, security, and simulator data processed by VibeNest. The creator remains responsible for personal data processed by the creator’s application. A future Merchant of Record processes buyer and payment data under its own privacy notice and legal role.
2. Data used by the preview
When you use the pilot, VibeNest may process:
- creator account, contact, pilot-access, project, repository, branch, and selected service metadata;
- the creator’s monetization intent, product manifest, synthetic catalog, and integration status;
- hashed one-time grants and session tokens, scopes, expiry, revocation, and security-audit metadata;
- exact commit identifiers, manifest digests, build/test results, preview URLs, and cleanup evidence;
- synthetic customer, transaction, subscription, cancellation, refund, and entitlement events;
- document version, digest, timestamp, locale, and hashed request evidence when a pilot document is accepted.
Access codes and tokens are designed to be shown only when necessary and stored as one-way hashes. VibeNest does not need a coding agent’s conversation transcript. Repository contents may be read only as authorized for inspection, verification, build, and deployment under the main Privacy Policy.
3. No real payment or identity data
Do not enter real card numbers, bank or wallet details, identity documents, tax identifiers, or production buyer records into the simulator. The preview does not collect full payment credentials and does not create payouts. Synthetic records are visibly separated from the existing VibeNest credits and hardware billing data.
4. Purposes and legal bases
- Contract and requested steps: prepare, test, and deploy the integration requested by the creator.
- Legitimate interests: secure scoped agent access, prevent cross-project access, diagnose failures, and preserve audit evidence.
- Consent or explicit acceptance: record a particular legal-document version where that basis is appropriate.
- Legal obligations: retain records that must be kept once a live commercial relationship exists.
5. Recipients
Data may be shared only as necessary with infrastructure and source-control providers already identified in the main Privacy Policy, and with the coding agent selected by the creator (for example, Codex or Claude Code). The creator controls what repository context is supplied to that agent and is responsible for the agent provider’s terms. No Project Payments seller or buyer data is sent to Paddle in the no-money simulator.
Before a future live launch, this notice will identify the Merchant of Record, KYC/KYB providers, data categories, international-transfer safeguards, and controller/processor roles actually approved for that flow.
6. Retention and security
Short-lived drafts, grants, access sessions, and disposable previews expire or are deleted according to their operational purpose. Security audits, consent evidence, integration revisions, and legally required transaction records may be retained longer under a documented retention schedule. Secrets use the same encryption and access controls as other protected VibeNest configuration; raw payment credentials are not stored.
7. Creator and buyer responsibilities
A creator must publish a project-specific Privacy Notice before live checkout and explain the application’s own buyer data collection, authentication, entitlements, analytics, support, and subprocessors. Installing VibeNest integration code does not make VibeNest the controller for every activity inside the creator’s app. Buyers should direct product-data requests to the project’s named controller and payment-data requests to the provider identified at checkout.
8. Your rights and contact
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing by emailing info@vibenest.net. We may retain a limited record where security, dispute, tax, accounting, or other law requires it. The complaint and regulator rights in the main Privacy Policy continue to apply.