ViralTree

ViralTree Privacy Policy

Last updated 10 September 2026

ViralTree is a referral and waitlist service made by AiVanci Ltd, a company registered in England and Wales (company number 16823149, registered office Colony - Flint Glass Works, 64 Jersey Street, Manchester, England, M4 6JW). In this policy "we", "us" and "ViralTree" mean AiVanci Ltd. Questions and requests about personal data go to hello@viraltree.io.

This policy is written for three groups of people. Find your section.

You areRead
A visitor to viraltree.io§1 and §5–§9
An organiser who has an account and runs campaigns§2 and §5–§9
A participant who joined a campaign run by an organiser using ViralTree§3 and §5–§9

1. Visitors to viraltree.io

What we collect. Server logs at our hosting provider record your IP address, browser type and the pages you request. We keep these for 30 days for security and to keep the site running.

Cookies. The marketing pages (the home page, /pricing, /viral-loops-alternative) set no cookies of their own. Nothing on those pages tracks you across sites. We do not use advertising or third-party analytics cookies.

Lawful basis. Legitimate interest in running a secure website.

2. Organisers (account holders)

When you create an account and run campaigns, we are the controller of your account data.

What we collect and why

DataWhere it comes fromWhyLawful basis
Email address, display name, sign-in identifierGoogle sign-in or the email sign-in link you requestTo create and secure your account, and to send you the service emails described belowContract
Organisation name, workspace and campaign settings, brand assets you upload (logo, colours, copy)YouTo run your campaignsContract
Team invitations (the invitee's email)YouTo add members to your organisationContract, and our legitimate interest in letting teams work together
Billing status, plan, Stripe customer and subscription identifiersStripe, when you subscribeTo bill you and enforce plan limitsContract
Payment card detailsYou, on Stripe's hosted checkoutTo take paymentContract. We never see or store card numbers. Stripe holds them.
Usage of the dashboard and API (requests, timestamps, IP addresses)Your browser and API clientsSecurity, rate limiting, abuse prevention, diagnosing faultsLegitimate interest

Service emails we send you. Sign-in links, team invitations, plan-limit warnings at 80% and 100%, billing receipts and failures, and notices when a paid campaign is moved to the next tier. These are part of the service and cannot be switched off while you hold an account. We do not send marketing email to organisers without separate consent.

Sign-in providers. If you sign in with Google, Google tells us your email address and name and nothing else. We do not receive your Google password or access to your Google account beyond that.

3. Participants (people who joined an organiser's campaign)

If you joined a waitlist, referral programme or sign-up form on another company's website and that form was powered by ViralTree, that company (the "organiser") is the controller of your personal data. They decide what to ask you and what to do with your answers. ViralTree processes your data on their behalf as a processor, under a written agreement with them.

The organiser's privacy notice governs. The organiser should link their own privacy notice near the form. Questions about why you were asked for your data, or requests to see, correct or delete it, go to the organiser first. If you cannot reach them, contact us and we will help.

What ViralTree stores about participants. Only what the organiser's form collects, plus what the referral mechanism needs to work:

  • Email address, and if the organiser asks for it, your name, phone number and answers to their custom questions.
  • Your unique referral code and link, who referred you (if anyone), and who you have referred.
  • The time you joined, whether you confirmed your email, and which milestones you have reached.
  • Technical signals when you join and when someone follows your link: IP address, browser user agent, the page the link landed on, and click timestamps. These exist to detect fake referrals (for example the same browser signing up repeatedly through its own link). We do not build a browser fingerprint. We do not use these signals for advertising or profiling beyond fraud checks.
  • If the organiser connects a payment or ticketing platform, a record that a person with your email address converted (bought a ticket, paid) so the organiser can reward the referrer. We store the fact of the conversion and an external reference, not the payment details.

Cookies and local storage set by the ViralTree script on the organiser's site. These are first-party cookies on the organiser's domain. They are strictly necessary for the referral mechanism and are not used to track you across other sites.

NamePurposeLifetime
vt_aidAn anonymous random id so we can tell one browser's clicks from another's when scoring fraud365 days
vt_ref (first and last)Remembers whose referral link brought you to the site, so that person gets credit if you join90 days
vt_pidRemembers that you already joined, so the page can show you your own link instead of the form againSession of the campaign
vt:* in localStorageA mirror of the above for browsers that drop cookies quicklySame as the cookie

Confirmation email. If the organiser has turned on double opt-in, we send you one email with a confirmation link on the organiser's behalf. It contains no marketing.

What we do not do with participant data. We do not sell it, share it with other organisers, use it to train models, or contact you except as instructed by the organiser. There is no public leaderboard; your sign-up count and rank are shown only to you and to the organiser.

4. Where data is processed and who else touches it

Our servers run in London (Vercel, region lhr1). Our database and sign-in service run on Supabase in Dublin, Ireland (AWS eu-west-1). We use these sub-processors:

Sub-processorWhat they do for usLocation
Supabase, Inc.Database and authenticationIreland (AWS eu-west-1)
Vercel, Inc.Hosting and application serversLondon, with global edge for static assets
Stripe Payments Europe, Ltd. / Stripe, Inc.Payments and subscriptionsIreland / USA
Resend, Inc.Sends confirmation and service emailsUSA
Google LLCSign in with Google (organisers only)USA

Where a sub-processor is outside the UK, transfers rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or on an adequacy decision. We will update this table before adding a sub-processor and give organisers 30 days' notice under the Data Processing Agreement.

5. How long we keep data

DataKept for
Organiser account and campaign dataWhile the account exists. Deleted within 30 days of the organisation being deleted.
Participant dataWhile the organiser keeps the campaign. Deleted when the organiser erases the participant or deletes the organisation.
Billing records6 years after the transaction, as UK tax law requires. Held at Stripe and in our invoices.
Server and security logs30 days
Deletion audit recordsIndefinitely, but they hold no personal data (a one-way hash of the email and the date).

6. Your rights

Under UK GDPR and, where it applies, EU GDPR, you can ask to access, correct, delete or export your personal data, to restrict or object to processing, and to withdraw consent where consent was the basis. You can also complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

Organisers can do most of this themselves: export any campaign as a CSV, erase any participant from the participants page or through the API, and delete the whole organisation from the team page.

Participants should ask the organiser, who can erase you in one click. If you write to us instead, we will confirm which organiser holds your data and pass the request on, or act on it ourselves where the organiser cannot be reached.

We answer requests within one month.

7. Security

Data is encrypted in transit (TLS) and at rest by our sub-processors. Access to production data is limited to the people who run the service and is logged. API secret keys are stored hashed. Organisers are responsible for keeping their own sign-in and API keys private. If we discover a breach affecting your data we will tell affected organisers without undue delay and, where required, the ICO within 72 hours.

8. Children

ViralTree is not directed at children under 16. Organisers must not use it to collect data from children without a lawful basis of their own. If you believe we hold a child's data without such a basis, contact us and we will delete it.

9. Changes

We will post changes here and update the date at the top. For material changes affecting organisers we will email account holders at least 14 days before they take effect.