
YOUR DATA · YOUR CONTROL
Privacy Policy
Last updated · August 30, 2026Scope
This policy explains how Vivo Night Life handles information through its iOS and Android applications, public website, customer account features, QR rewards, reservation requests, administrator and staff tools, email, push notifications and support channels in the United States.
Vivo Night Life is an adults-only nightlife discovery and operations service. Phase 1 does not sell tickets, process deposits or collect payment-card information.
Account and contact information
Creating a basic account requires your name, a verified account email, a 21+ declaration and the current Terms and Privacy acknowledgments. We also assign an internal authentication ID and a non-sequential public Member ID.
You may later add a username, contact email, mobile phone, WhatsApp number, city and full date of birth. Those fields remain optional for browsing and saved items, but a specific feature can require the relevant verified detail—for example, a verified phone for a reservation request or a full date of birth for Birthday Club and a QR campaign that explicitly requires age calculation.
If you choose Apple or Google sign-in, we receive the account identifier and profile information that provider makes available with your permission. Apple may provide a private relay email when you choose Hide My Email.
Activity you ask us to keep
We store saved businesses and events, reservation requests and their status history, QR claims and redemptions, communication preferences, birthday-message history, support requests and the information you submit in those flows. A reservation request is not a payment or guaranteed booking.
Business managers and authorized staff may also create business profiles, hours, events, media, reservation records, QR campaigns and staff assignments. Administrative changes, scanner actions and sensitive access decisions are recorded in private audit logs.
Date of birth and age eligibility
The basic account records your declaration that you are 21 or older without requiring a full date of birth. If you later provide a valid date of birth, VIVO uses it only for the feature you requested, such as Birthday Club or a QR campaign that requires server-side age calculation. Birthday marketing still requires a separate opt-in.
Your 21+ declaration and any date of birth you provide are eligibility signals, not legal identification. Neither replaces a valid government-issued ID required by a business. We do not place your full date of birth inside a QR code or show it to scanner staff, and we limit repeated birthday changes to reduce misuse.
Location and camera
Browsing, account access and Tonight Near You do not require location. If you choose “Use current location,” Tonight Near You can order participating businesses that are open or opening tonight by distance. Unlocking a customer live QR requires one fresh precise foreground reading to confirm that the device is inside the published venue radius.
If a live-QR location reading is denied or unavailable, the rest of VIVO remains usable and the promotion can be handled only through the separate, audited in-person process completed by authorized venue staff. We do not request background location, use location for advertising profiles or sell location data.
Camera access is used only in the private staff scanner experience to read a live QR after the staff member chooses to start the camera. A manual reference option remains available. Vivo does not record or store camera video through that scanner flow.
QR, device and security records
Live QR protection uses a random app-scoped installation identifier, stored locally on the device, and a server-side hash of that identifier. It is not the advertising identifier and is not derived from hardware characteristics. We also process session information, the QR challenge hash, claim and redemption timestamps, campaign and business IDs, staff and approved scanner-device IDs, outcomes and security events.
The visible QR payload is opaque and does not contain your email, phone, full birthday, reward description or inventory. A live challenge normally expires after 60 seconds; claim, redemption and security audit records may remain longer to prevent duplicate use, resolve support issues and document fulfillment.
Service and analytics records
Our infrastructure receives normal request information needed to deliver and secure the service, such as timestamps, network address, browser or app information, response status and error details. We minimize personal information in logs.
When VIVO tracking links are active, we may record actions such as a view, click, directions request, reservation lead or link destination together with the related business, event or campaign. Reporting is aggregated by default. We do not use these records for cross-company behavioral advertising.
How we use information
We use information to create and secure accounts, enforce 21+ eligibility, synchronize saved items, show relevant real-time content, process reservation requests, operate and audit QR rewards, prevent fraud, deliver messages you requested, honor opt-outs, support customers and businesses, measure service reliability and comply with applicable obligations.
We do not sell personal information. We do not upload customer lists to advertising platforms or create custom advertising audiences in Phase 1.
Email, birthday and push choices
Security and service messages are sent when needed to operate your account or a request. Marketing email, birthday-planning email and push notifications require the corresponding choice and can be turned off. Unsubscribe, suppression and bounce states are honored.
SMS and WhatsApp marketing delivery are disabled in Phase 1. Providing a phone or WhatsApp number does not subscribe you to those channels.
Service providers
Supabase provides authentication, database, storage, realtime updates and server functions. Cloudflare delivers and protects the website and APIs. Resend delivers email. Apple and Google provide sign-in when selected. Apple Push Notification service and Firebase Cloud Messaging deliver push notifications after opt-in.
Phase 1 does not connect customer accounts to Meta or Instagram and does not send customer lists, contact details, birthdays, location, device identifiers or activity to those platforms. A business may provide a public Instagram handle that VIVO displays only as an ordinary outbound contact link.
Sharing
We share information only with service providers that need it to perform their contracted role, with a participating business when needed to handle your reservation or fulfill a QR reward, at your direction, or when required to protect rights, safety or comply with law. Scanner staff see only the minimum fulfillment details: name, Member ID, reward, eligibility declaration and requirements—not email, phone or full date of birth.
Retention and deletion
Account and profile data is retained while your account is active. Operational records are kept only as long as reasonably needed for the service, fraud prevention, support, audit and applicable obligations. Short-lived QR secrets expire quickly and are stored as hashes rather than readable tokens.
When you delete your account, access ends and account-linked profile, preference and saved-item records are deleted under our database rules. Limited transaction, redemption, security or administrative audit records may be retained or de-identified when needed to prevent fraud, document a completed service, resolve disputes or meet legal obligations.
Your choices and rights
You can update profile details and communication preferences, decline location and camera access, unsubscribe from marketing, sign out, or delete your account from the signed-in Profile area. You can also review our Account & Data Deletion instructions and contact support for access, correction or deletion assistance.
Deleting your VIVO account does not delete your Apple or Google account. You may separately stop using Sign in with Apple or remove the VIVO connection in your Google Account settings.
Security and adults-only access
We use role-based access, business isolation, row-level database controls, short-lived credentials, encrypted transport and audit records appropriate to the service. No online system can promise absolute security.
Registration is limited to people age 21 or older. Businesses and events may impose additional admission, conduct and physical-ID rules.
Changes and contact
We will update the date on this page when this policy changes materially. Changes to data practices must also be reflected in the applicable store privacy disclosures.
For privacy questions, consent changes or account assistance, email support@vivonightlife.com.