ViralTree

ViralTree Terms of Service

Last updated 13 September 2026

These terms are a contract between AiVanci Ltd (England and Wales, company number 16823149, registered office Colony - Flint Glass Works, 64 Jersey Street, Manchester, England, M4 6JW; "ViralTree", "we", "us") and the organisation or person who creates a ViralTree account ("you", the "Customer"). By creating an account, or by clicking to accept, you agree to them. If you are accepting on behalf of a company, you confirm you have authority to bind it.

Schedule 1 (the Data Processing Agreement) is part of these terms and applies whenever you use ViralTree to collect personal data from other people.

1. What ViralTree is

ViralTree lets you run referral campaigns, waitlists and sign-up forms on your own website, through a script you install and a dashboard you manage at viraltree.io. People who join your campaign ("Participants") get a personal link, and ViralTree counts who they bring in.

2. Your account

  • You must be at least 18 and give accurate account details.
  • You are responsible for everything done through your account and your API keys. Keep them secret. Tell us at once if you think a key or sign-in has been compromised.
  • One organisation may have several members. The owner is responsible for the members they invite.

3. Your responsibilities as a controller of Participant data

This is the clause that matters most. You decide what to collect from Participants and why. That makes you the data controller and us your processor. In particular you must:

  1. Have your own privacy notice and show it, or a link to it, wherever a Participant gives you their data. The ViralTree script provides a consent-notice element (data-vt-notice) and the campaign builder takes a terms link for this purpose, but the content of the notice is yours.
  2. Have a lawful basis for collecting and using each piece of Participant data, and for any marketing you send them afterwards. Turn on double opt-in where your basis is consent.
  3. Handle Participant rights requests (access, deletion, objection). The dashboard and API let you erase any Participant at once. We will forward any request that reaches us directly to you.
  4. Comply with the law that applies to you, including UK GDPR, EU GDPR, PECR and the equivalent rules in any country where your Participants live, and the rules of any platform you connect (for example Stripe, Eventbrite).
  5. Not collect special-category data (health, religion, sexual orientation and the like), payment card numbers, or government identifiers through campaign questions.
  6. Not collect data from children under 16 unless you have a lawful basis of your own and tell us.

We provide the tool, the Data Processing Agreement in Schedule 1, and the deletion and export functions. We do not provide legal advice, and we are not responsible for your compliance with data protection law in how you use the data you collect. If a regulator or Participant brings a claim against us because of something you did or failed to do under this clause, you will cover our reasonable costs.

4. Acceptable use

You must not use ViralTree to:

  • send or cause unsolicited bulk email or messages, or add people to lists without their agreement;
  • create fake Participants, referrals or conversions, or reward yourself through your own links;
  • run campaigns for illegal goods or services, or content that is defamatory, hateful, or infringes someone else's rights;
  • probe, overload or interfere with the service, or bypass plan limits or rate limits;
  • resell access to ViralTree, or use it to build a competing referral product.

We may suspend a campaign or account that breaks this clause. We will tell you why and, where the problem can be fixed, give you the chance to fix it first.

5. Plans, limits and fees

  • Free use and counting. Up to 250 stored Participants, with no time limit and no required card. We total Participant records across your organisation's workspaces. A person joining several campaigns in the same workspace counts once; the same email in two workspaces counts twice. Counts do not reset each month or campaign. Genuine deletion releases capacity. At the limit, new people pause unless you upgrade or have completed the optional advance authorisation below. Existing data, exports, confirmation and sharing remain available.
  • Starter. £27 per month for 1,000 total Participants, including the first 250. Starter is sold monthly; other paid plans may offer annual billing. Charges are collected through Stripe. Prices exclude VAT, which is added where applicable. Your payment details are handled by Stripe, not stored as raw card details in ViralTree.
  • Optional advance authorisation. An organisation owner may explicitly authorise recurring £27 monthly Starter billing and complete Stripe payment-method setup. Setup and reaching exactly 250 do not charge you. The first qualifying new person beyond 250 starts one Starter subscription. This authorisation is separate from merely storing a payment method and can be revoked in billing controls before activation. The subscription renews monthly until cancelled. The first billing period begins when Stripe creates the initial subscription invoice; if extra authentication delays payment, that does not restart the period. Paid capacity is available only after payment is confirmed. The accepted triggering person is retained while payment is pending, and further new people pause until activation succeeds.
  • Automatic growth. Paid auto-grow is a separate billing setting and authorisation. When enabled, crossing Starter's 1,000 limit moves the subscription to Growth (£77/month), prorated; further paid transitions follow the disclosed plan ladder for the same billing interval. You can turn it off in billing controls to pause new people at the plan limit instead. Advance Starter authorisation alone does not turn on or authorise this separate behaviour.
  • Changing and cancelling. Change plan or cancel through billing controls. Stripe shows the cancellation effective date and any remaining paid period before you confirm; access follows that subscription status. Once cancellation takes effect, free limits apply. Fees already paid are not refunded for unused time, except where the law requires a refund or we withdraw the service. Revoking unused advance authorisation is different from cancelling an active subscription.
  • Failed payments and recovery. We show payment-pending or failed status and email the owner when action is needed. Extra authentication or an updated payment method may be required. New capture is limited while unpaid; existing data remains accessible. Cancelled, expired or already-over-limit free accounts need an explicit current upgrade or resume action. Stored cards, deletion or a fresh visit do not automatically re-enrol you, and we do not charge retroactively for earlier free use.
  • Price changes. We will email you at least 30 days before a price change takes effect on your plan.

6. Your content and data

  • You own it. Your campaign copy, brand assets and Participant data are yours. You give us a licence to host, process and display them only as needed to run the service for you.
  • Export. You can export any campaign as a CSV at any time, on every plan.
  • Deletion. When you delete your organisation, we delete all of its data within 30 days, except records we must keep for tax or legal reasons and audit entries that contain no personal data.
  • Feedback you give us about the product may be used freely.

7. Our service and its limits

  • We aim for the service to be available and working, but we do not promise uninterrupted availability and no plan carries a service-level agreement.
  • We may change or retire features. We will give reasonable notice for anything that affects a running campaign.
  • The service is provided "as is". To the extent the law allows, we exclude implied warranties.
  • Liability. Nothing in these terms limits liability for death, personal injury, fraud, or anything else that cannot be limited by law. Otherwise, our total liability to you in any 12 months is capped at the fees you paid us in those 12 months (or £100 if you are on the Free plan), and we are not liable for lost profits, lost data that you could have exported, or indirect loss. Referral and fraud scoring is a best effort; we are not liable for a reward you choose to pay on a referral that later proves false.

8. Third-party services

Stripe, Google sign-in, ticketing platforms and anything else you connect are governed by their own terms. We are not responsible for them. If a third-party platform changes its API, an integration may stop working until we update it.

9. Suspension and termination

  • You can close your account at any time from the team page.
  • We may suspend or close your account for breach of clauses 3 or 4, for non-payment, or if required by law. Except in urgent cases we will warn you first.
  • On termination, clause 6 (deletion and export) applies. Clauses 3, 6, 7 and 11 survive.

10. Changes to these terms

We will email account holders at least 14 days before a material change. Continuing to use the service after the date given means you accept the new terms. If you do not, close your account before that date.

11. General

  • These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. Consumers in the EU keep any mandatory protections of their own country.
  • If any clause is found invalid, the rest stand.
  • These terms, the Privacy Policy and Schedule 1 are the whole agreement between us about ViralTree.
  • Notices to us: hello@viraltree.io. Notices to you: the owner's account email.

Schedule 1: Data Processing Agreement

This schedule applies to personal data of Participants that ViralTree processes on the Customer's behalf ("Customer Data"). Terms have the meanings in UK GDPR.

1. Roles. The Customer is the controller. ViralTree is the processor.

2. Details of processing.

Subject matterRunning the Customer's referral campaigns and sign-up forms
DurationThe life of the Customer's account
Nature and purposeCollecting sign-ups, issuing referral links, counting referrals and conversions, detecting fraudulent referrals, sending confirmation emails, presenting results to the Customer
Categories of data subjectParticipants: people who join the Customer's campaigns and people who click their links
Categories of dataEmail address; name, phone number and custom-question answers if the Customer asks for them; referral code and relationships; IP address, user agent, landing URL and timestamps; conversion records from connected platforms
Special category dataNone. The Customer must not collect any.

3. Instructions. ViralTree processes Customer Data only on the Customer's documented instructions, which are these terms, the campaign settings the Customer chooses in the dashboard, and the API calls the Customer makes. ViralTree will tell the Customer if it believes an instruction breaks data protection law.

4. Confidentiality. People with access to Customer Data are bound by confidentiality obligations.

5. Security. ViralTree applies the measures in the Privacy Policy §7: encryption in transit and at rest, access limited to staff who run the service, hashed API secrets, logged production access.

6. Sub-processors. The Customer authorises the sub-processors listed in the Privacy Policy §4. ViralTree will give 30 days' notice by email before adding or replacing one. If the Customer objects on reasonable data-protection grounds and no fix is found, the Customer may terminate and receive a pro-rata refund of prepaid fees. ViralTree remains liable for its sub-processors' performance.

7. Data subject rights. ViralTree provides the participant erase function in the dashboard and the DELETE /api/v1/participants endpoint, and CSV export, so the Customer can meet access, portability and deletion requests itself. ViralTree forwards any request it receives directly to the Customer within 5 working days and helps where the tooling is not enough.

8. Breach. ViralTree notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information the Customer needs to notify its regulator.

9. Assistance. ViralTree gives the Customer reasonable help with data protection impact assessments and regulator consultations concerning the processing, and may charge for anything beyond what the product already provides.

10. Deletion and return. On termination, the Customer may export Customer Data. ViralTree deletes Customer Data within 30 days of the organisation being deleted, save for records law requires it to keep.

11. Audit. Once a year, on 30 days' notice, ViralTree will answer the Customer's reasonable written security questions and provide available third-party reports for its sub-processors. On-site audits only where a regulator requires one.

12. International transfers. Transfers outside the UK take place only to the sub-processors in §4 of the Privacy Policy, under the UK IDTA or Addendum, or an adequacy decision.

13. Liability. Liability under this schedule is subject to clause 7 of the terms.