Viva Social — Privacy Policy
Last updated: 2026-08-13 Effective: 2026-08-13
Technology Advantages LLC ("Viva Social," "we," "us") operates the Viva Social mobile application and the vivasocial.online website (together, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. By using the Service you agree to the practices described here.
If you do not agree, do not use the Service.
1. Who we are
Controller: Technology Advantages LLC, 28 Valley Road, Montclair, New Jersey 07042, USA. Contact: support@technologyadvantagesllc.com.
For users in the EEA/UK, our representative is to be designated before launch in the relevant region.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Identifiers | phone number, email, user ID (UUID), device push token | you, your device |
| Account & profile | first name, date of birth, age, gender identity, sexual orientation (array), height (optional), neighborhood, work title (optional), bio (optional), 6 profile photos, 3 prompt responses, preferences (age range, search radius, verified-only filter, hair colors, facial hair, height range), ethnicity (optional, array, display-only — never used to filter), religion (optional, display-only — never used to filter), hair color (optional), facial hair (optional) | you |
| Location | precise GPS coordinates while you have the map open, accuracy, timestamp | your device |
| Verification | Government ID document and a live selfie, collected and processed by Stripe Identity to confirm you are a real adult. We receive only the vendor session reference and the pass/fail outcome; we never receive or store your ID document or selfie images. | Stripe Identity (processor) |
| Invitations & plans | invitation history (proposed/accepted/declined/countered/expired), venue references, share-plans links and recipients | you |
| Chat | text + image + reactions exchanged after invite acceptance | you and your matches |
| Reservations | OpenTable click events with UTM attribution | you |
| Notifications | device push tokens, your per-category opt-ins, in-app notification history | your device, you |
| Safety | block list, reports filed by/against you, moderation actions, share-plans link metadata | you, Stream moderation, our admins |
| Telemetry | events you trigger in-app (e.g., map_opened, invite_sent), crash data, performance data | your device |
| Referrals | your referral code and, when a code is redeemed, the link between referrer and the new member (visible to both parties) | you |
| Waitlist | email address and an optional referral tag submitted on our marketing site before signup | you (marketing site) |
| Customer support | content of your messages to us | you |
Identity verification uses a government ID document and selfie, but Stripe Identity collects and holds those directly as our processor; we receive only the pass/fail result and a session reference, never the document or images (see the Verification row above and Stripe's own privacy policy).
We do not collect: financial or payment information, health/fitness data, your contacts, or your browsing or search history outside Viva Social.
3. How we use it
We process personal information to:
- Provide the Service — match you to nearby users, send/receive invitations, run chat, deliver pushes, generate reservations.
- Enforce safety — age gate, block/report flows, moderation review, NSFW screening on images, verification of identity.
- Communicate with you — in-app and push notifications (invite received, export ready, account activity), support replies, and transactional email where a provider is configured. Marketing emails only if you opt in.
- Improve the product — anonymous analytics on funnel conversion, error rates, performance. Crash diagnostics through Sentry with PII stripped before transmission.
- Comply with law — investigate violations, respond to subpoenas, prevent fraud, meet age-of-consent obligations.
4. Legal bases (EEA/UK users)
| Purpose | Legal basis |
|---|---|
| Account creation, login, profile | Contract (Article 6(1)(b) GDPR) |
| Map discovery, invitations, chat | Contract |
| Selfie verification | Consent (Article 9(2)(a)) — sensitive biometric processing requires explicit consent |
| Sexual orientation in profile + preferences | Explicit consent (Article 9(2)(a)) |
| Safety enforcement (block, report, moderation) | Legitimate interest + legal obligation |
| Marketing emails | Consent — opt-in required |
| Analytics | Legitimate interest (anonymised, opt-out via Settings) |
5. Who we share it with
We never sell personal information. We share with:
| Processor | Purpose | Region | Safeguards |
|---|---|---|---|
| Supabase, Inc. | Database, auth, storage, edge compute | US | DPA + SCCs for EEA users |
| Mapbox, Inc. | Maps + geocoding | US | DPA |
| Stream.io, Inc. | Real-time chat | US | DPA |
| Stripe, Inc. | Identity verification | US | DPA |
| Twilio, Inc. | SMS for OTP and share-plans | US | DPA |
| Resend, Inc. | Transactional email | US | DPA |
| Sentry (Functional Software, Inc.) | Crash + error logs (PII redacted before send) | US | DPA |
| PostHog, Inc. | Product analytics | US | DPA |
| OpenTable, LLC | Reservation deep-link clicks | US | Affiliate agreement |
| Apple, Inc. | Sign in with Apple, APNs push | US | Apple terms |
| Google LLC | Google OAuth, FCM push | US | Google terms |
Every processor above is required to have a data processing agreement in place before it processes any personal data of our members, and the current status of each is published on our Subprocessors page. That page is updated before a new subprocessor begins processing.
For EEA/UK users, transfers to the US rely on the EU-US Data Privacy Framework where the processor is certified, and on Standard Contractual Clauses otherwise.
6. How long we keep it
| Data | Retention |
|---|---|
| Profile data while account is active | Until you delete |
| Profile data after soft delete | 30 days (cancellable by re-signing in) |
| Profile data after hard purge | Deleted outright (profile row and all children removed); only a minimal audit log entry kept |
| Underage block records | Blocks the phone for 90 days; the record stores only a salted one-way hash of the phone number plus the reported age, no raw personal data |
| Chat messages | Until you delete the account (or 30-day soft delete completes) |
| Photos | Until you delete or replace; removed from Storage on hard purge |
| Telemetry events | 12 months rolling |
| Audit logs | 24 months (legal/safety requirement) |
| Backups | 30 days |
7. Your choices
- Pause profile. Settings → Privacy → Pause profile. Hides you from the map and inbox.
- Active on map toggle. Stop sharing your location without pausing your whole profile.
- Verified-only filter. Settings → Privacy.
- Notification opt-outs. Settings → Notifications, per category and channel.
- Export your data. Settings → Your data → Request export. A JSON file of your data plus signed links to your photos, delivered as a 24-hour signed link; you can request a fresh one at any time. Chat history is exported separately on request.
- Delete your account. Settings → Account → Delete account. 30-day grace period; cancel by signing back in. Hard purge deletes your profile, photos, and auth credentials outright.
- Marketing emails. Opt-in only. Unsubscribe link in every marketing email; toggle in Settings.
GDPR/UK rights (EEA/UK users)
You have the right to: access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge a complaint with your DPA. Email support@technologyadvantagesllc.com to exercise these rights; we respond within 30 days.
Sensitive personal information
Two categories we collect are treated as sensitive under California and most other US state privacy laws:
- Precise geolocation, while you have the map open and are sharing location.
- Sexual orientation, which you enter on your profile and in your preferences.
We collect both only because the product cannot work without them: precise location is what puts people near you on the map, and orientation is what makes matching mean anything. We use them for that and nothing else. We do not use, disclose, or infer anything from sensitive personal information beyond providing the Service, ensuring security and integrity, and complying with law, which are the permitted purposes under CCPA §1798.121. That is why there is no separate "limit the use of my sensitive personal information" control: there is no additional use to limit.
You can stop sharing location at any time with the Active on map toggle in Settings, and you can edit or clear orientation in your profile.
CCPA/CPRA rights (California residents)
You have the right to: know what we collect, delete, correct, opt-out of "selling/sharing" (we do not sell or share for cross-context behavioural advertising), limit the use of sensitive personal information (see above), and non-discrimination for exercising any of these. Submit a request at support@technologyadvantagesllc.com.
Nevada residents may direct us not to sell covered information under NRS 603A.340 by writing to support@technologyadvantagesllc.com, which is our designated request address. We do not sell personal information.
Other US state privacy rights
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, or another state with a comprehensive consumer privacy law, you have rights of the same shape: to confirm whether we process your data and access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling with legal effects. We do none of those three, so there is nothing to opt out of, but the right exists and we honour it.
Where your state requires opt-in consent to process sensitive data, your consent is what you give when you turn on location sharing or enter your orientation, and you can withdraw it as described above.
If we refuse a request: how to appeal
You can appeal any decision we make about a privacy request, and in Virginia, Colorado, Connecticut and several other states you have a statutory right to do so.
Email support@technologyadvantagesllc.com with the subject line "PRIVACY APPEAL" and the original request reference. A person who was not involved in the original decision will review it. We will respond in writing within 45 days of receiving the appeal, explaining the reasons for the decision. If we deny the appeal, we will tell you how to contact your state attorney general to lodge a complaint.
Verifying who you are
Before we act on a request about your data we need to be reasonably sure it is your data. We will normally verify by asking you to complete an action from the phone number or email on the account. We will not ask you for a government ID to verify a privacy request. An authorised agent may act for you with written permission, which we will ask to see.
8. Security
- TLS 1.2+ in transit, AES-256 at rest.
- Row-level security on every Postgres table.
- Stripe Identity processes selfie data — we never see the raw biometric features.
- Service-role credentials rotated quarterly.
- PII redacted before any third-party telemetry.
9. Children
The Service is 18+ only. We block accounts during signup if the DOB indicates an age under 18 and block the phone number for 90 days. If you believe a child has used the Service, email support@technologyadvantagesllc.com.
10. International users
The Service operates from the United States. By using it from outside the US, you consent to the transfer of your data to the US.
11. Changes
We will notify you of material changes 30 days in advance via in-app notice and email. Continued use after the effective date constitutes acceptance.
12. Related documents
- Subprocessors — who processes data on our behalf, kept current
- Biometric Data Policy — identity verification, in detail
- Child Safety Standards — our CSAE policy and reporting
- Law Enforcement Guidelines — what we require before disclosing anything
- Safety Disclosure — screening and what the Verified badge means
- Vulnerability Disclosure Policy
- Cookie Policy — cookies and similar technologies
- Data Retention Policy — how long we keep each category, in one place
- Content Moderation Policy — prohibited content and enforcement
13. Contact
Technology Advantages LLC — support@technologyadvantagesllc.com — 28 Valley Road, Montclair, New Jersey 07042, USA