Vayla

Privacy Policy

VAYLA INC.

Last Updated: March 1, 2026

Vayla Inc. (“Vayla”, “we”, “us”, or “our”) is committed to protecting personal information in accordance with the Act respecting the protection of personal information in the private sector (Québec) (“Law 25”), Canada's Anti-Spam Legislation (CASL), and other applicable Canadian privacy laws.

This Privacy Policy describes how we collect, use, disclose, retain, and safeguard personal information when you access or use the Vayla website, mobile application, and related services (the “Platform”).

By using the Platform, you consent to the practices described in this Policy.

1. Privacy Officer

In accordance with Law 25, Vayla has designated a person responsible for personal information.

Privacy Officer

Vayla Inc.

Email: [email protected]

All privacy-related inquiries, access requests, correction requests, and deletion requests must be directed to this email.

2. Personal Information We Collect

We collect only personal information reasonably necessary to operate the Platform.

2.1 Information You Provide

  • Full name
  • Email address
  • Date of birth (age verification)
  • Payment information (processed via Stripe)
  • Account credentials
  • Communications with us

2.2 Automatically Collected Information

  • IP address
  • Device type and operating system
  • Browser/app version
  • Log data and timestamps
  • Offer redemption activity
  • Usage analytics

2.3 Payment Processing

Payments are processed by Stripe, Inc. Vayla does not store full credit card numbers.

Stripe's privacy policy is available at: https://stripe.com/privacy

We retain limited transaction records for accounting, fraud prevention, and legal compliance purposes.

3. Purposes for Collection

We collect personal information to:

  • Create and manage user accounts
  • Process subscription payments
  • Provide access to offers
  • Verify eligibility (including age verification)
  • Detect and prevent fraud or abuse
  • Maintain security of the Platform
  • Improve functionality and user experience
  • Send service-related communications
  • Comply with legal and regulatory obligations

We do not sell personal information.

4. Consent

By creating an account, you provide express consent to the collection, use, and disclosure of personal information as described in this Policy.

You may withdraw consent at any time by contacting [email protected], subject to legal and contractual restrictions.

Withdrawal of consent may result in termination of Platform access.

5. Marketing Communications (CASL Compliance)

Vayla may send electronic communications including:

  • Promotional emails
  • Offer updates
  • Platform announcements

In compliance with Canada's Anti-Spam Legislation (CASL):

  • Marketing communications are sent only with express or implied consent.
  • Users may withdraw consent at any time.
  • Every marketing email includes an unsubscribe mechanism.
  • Unsubscribe requests are processed within 10 business days.

Consent records, including timestamp and source of opt-in, are retained for compliance purposes.

Service-related communications (billing notices, security alerts, policy updates) are not marketing communications and cannot be unsubscribed from while maintaining an active account.

6. Disclosure to Third Parties

We may disclose personal information to:

  • Payment processors (e.g., Stripe)
  • Cloud hosting providers
  • Analytics providers (e.g., Google Analytics, if applicable)
  • Fraud detection services
  • Professional advisors (legal/accounting)
  • Regulatory authorities when required by law
  • In connection with a merger, acquisition, or corporate restructuring

All service providers are contractually required to safeguard personal information.

7. Cross-Border Data Transfers

Personal information may be stored or processed outside Québec or Canada, including in the United States.

Where personal information is transferred outside Québec, Vayla conducts a Privacy Impact Assessment (PIA) in accordance with Law 25 and implements appropriate contractual and technical safeguards.

8. Data Retention

Vayla retains personal information only for as long as necessary to fulfill the purposes described in this Policy.

Retention periods include:

  • Account and billing records: minimum 5 years following account closure (tax and legal compliance)
  • Fraud and abuse monitoring records: up to 7 years
  • Marketing consent records: minimum 3 years (CASL compliance)
  • Analytics data: retained in aggregated or anonymized form where possible

When retention is no longer required, personal information is securely deleted or irreversibly anonymized.

9. Security Safeguards

We implement reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including:

  • Encrypted payment processing
  • Secure cloud hosting infrastructure
  • Access control restrictions
  • Authentication safeguards
  • Monitoring for suspicious activity

No method of transmission or storage is completely secure.

10. Automated Decision-Making

Vayla uses automated systems to detect fraud, suspicious activity, and abuse of the Platform.

These systems may result in temporary or permanent account suspension.

Users may request information regarding automated decisions affecting their account by contacting [email protected].

Vayla does not use automated decision-making systems that produce legal effects without human review.

11. Cookies & Tracking Technologies

The Platform uses:

Essential Cookies

Required for authentication and security.

Analytics Cookies

Used to understand Platform usage and improve performance.

We may use third-party analytics providers such as Google Analytics.

Users may disable cookies through browser settings; however, certain features may not function properly.

12. Your Rights Under Québec Law

Under Law 25, you have the right to:

  • Access your personal information
  • Request correction of inaccurate data
  • Request deletion of personal information
  • Withdraw consent
  • Request information regarding automated decision-making

Requests must be submitted to [email protected].

Vayla will respond within thirty (30) days, as required by law.

13. Account Deletion

Users may request permanent deletion of their account by:

Deletion requests will be processed within thirty (30) days, subject to legal retention obligations.

Certain information may be retained for tax, fraud prevention, or legal compliance purposes.

14. Children

The Platform is not intended for individuals under 18 years of age.

If we become aware that personal information of a minor has been collected, it will be deleted.

15. Confidentiality Incidents

In the event of a confidentiality incident presenting a risk of serious harm, Vayla will:

  • Notify affected individuals where required
  • Notify Québec's Commission d'accès à l'information (CAI) where required
  • Maintain a register of confidentiality incidents

In accordance with Law 25.

16. Changes to This Policy

We may update this Privacy Policy from time to time.

The “Last Updated” date reflects the most recent revision.

Continued use of the Platform constitutes acceptance of any updates.

17. Contact Information

For all privacy-related matters:

Vayla Inc.

Privacy Officer

Email: [email protected]