Privacy Policy
As of 16 September 2026
Between:
Bayomi UG (haftungsbeschränkt), Winterhuder Weg 31, 22085 Hamburg, Germany, Commercial Register HRB 199083 Local Court Hamburg, represented by Managing Director Jonathan Jakob Greiter
(hereinafter “Provider”)
and:
The User of the Products (hereinafter “User”)
§ 1 SCOPE
(1) The Provider offers its Products internationally. This Privacy Policy explains how the Provider processes personal data of Users and visitors worldwide in connection with the website vision-alerts.com, the VISION ALERTS iOS application, the VISION ALERTS web application, the Discord community and subscriptions concluded via Whop or an app store (together the “Products”).
(2) This Privacy Policy supplements the Provider’s Terms of Service, EULA, and Return Policy.
(3) The Products are not directed at persons under the age of 18.
§ 2 CONTROLLER AND CONTACT
Controller for data processing:
Bayomi UG (haftungsbeschränkt)
Winterhuder Weg 31
22085 Hamburg
Germany
Commercial Register HRB 199083 Local Court Hamburg
represented by Managing Director Jonathan Jakob Greiter
Email (for privacy requests): support@vision-alerts.com
Privacy requests will only be processed via this email address. Postal inquiries are also possible but may result in longer processing times.
The Provider does not have a statutorily appointed Data Protection Officer. Please direct privacy requests to the email address above.
§ 3 LEGAL BASES
The Provider applies a uniform level of data protection to all processing worldwide, regardless of where the User is located. Processing is based on the following legal bases, referred to in this Privacy Policy by the terms in quotation marks:
- Performance of a contract with the User – “Contract”
- Legitimate interests of the Provider, in particular in the operation, security, analysis, improvement and marketing of the Products – “Legitimate Interest”
- Consent of the User – “Consent”
- Legal obligations of the Provider – “Legal Obligation”
§ 4 WHAT DATA IS PROCESSED
A. Data that Whop Transmits to the Provider
| Data Category | Specific Data | Purpose |
|---|---|---|
| Master Data | Whop username, name, email address, country | Identification of the User, provision of access |
| Subscription Data | Active subscription status, subscription type (monthly/annual), duration | Verification of entitlement, access management |
| Payment Data | Payment status (completed/pending/failed), amounts, chargeback status | Deactivation of access in case of default of payment, analysis |
| Attribution Data | Referral and affiliate assignment | Attribution to campaigns and partners |
| Other Data | Other data transmitted by Whop | As above |
Legal Basis: Contract; Legitimate Interest
B. Data from App Stores
If the User subscribes via an app store, the Provider receives the following data from the app store operator: subscription status, subscription type, transaction identifiers, renewal, cancellation and refund status, and the country of the storefront. Payment data remains with the app store operator.
Legal Basis: Contract
C. Data Processed by the Provider Itself
| Data Category | Specific Data | Purpose |
|---|---|---|
| Account Data | Email address, login credentials, account status, timestamps of registration and sign-in | Provision and management of access |
| Profile and Settings | Name, time zone, instrument and notification settings | Provision and personalization of the Products |
| Device Data | Device identifiers, IP address, operating system and app version, push notification token, language | Delivery of signals, enforcement of the device limit, prevention of misuse |
| Usage Data | Interactions within the app and web application, features used, signals and analyses viewed, crash and diagnostic data, delivery and opening of push notifications | Operation, error analysis, analysis and improvement of the Products |
| Communication Data | Support inquiries and correspondence via Discord, Whop and email | Handling of inquiries, documentation |
| Discord Data | Discord User ID, roles, activity in channels operated by the Provider | Access management and analysis of the Discord community |
Legal Basis: Contract; Legitimate Interest
D. Website, Analytics and Advertising Data
| Data Category | Specific Data | Purpose |
|---|---|---|
| Server Log Data | IP address, date and time, pages accessed, referrer, browser and operating system | Operation and security of the website |
| Analytics Data | Pages viewed, time on page, scroll depth, clicks, taps and mouse movements, form inputs (excluding passwords and payment data), session recordings and heatmaps, A/B test variants, device and browser information, approximate location, referral source and campaign parameters | Analysis and improvement of the website and the Products |
| Advertising Data | Online identifiers, cookie and advertising IDs, conversion events including subscription value, hashed email addresses for customer lists, server-side transmission of events | Measuring and optimizing advertising campaigns, retargeting, creation of target and lookalike audiences |
| Attribution Data | Referral, affiliate, campaign and creator codes | Attribution of subscriptions to campaigns, creators and partners, commission settlement |
| Linked Data and Profiles | Linking of usage data across devices and with the customer account, segments | Analysis, personalization and marketing |
| Email Interaction Data | Opens and link clicks | Measuring the effectiveness of emails |
| Embedded Third-Party Content | Data transmitted when loading embedded videos or social media content | Display of embedded content |
Legal Basis: Server Log Data – Legitimate Interest. All other data in this section – Consent where required by applicable law, otherwise Legitimate Interest. Details in § 6.
E. Payment Data
The Provider does not process payment card or bank account details. These remain with Whop, Stripe or the respective app store operator.
§ 5 PURPOSES OF DATA PROCESSING
The Provider processes the User’s data for the following purposes:
- Contract Performance (Contract): provision of access to the app, the web application and the Discord community; management of subscriptions; delivery of signals and analyses, including push notifications; enforcement of the device limit.
- Access Control and Prevention of Misuse (Legitimate Interest): automated subscription checks; detection of shared access and redistributed content; prevention of fraud and chargebacks.
- Support and Communication (Contract; Legitimate Interest): answering inquiries via Discord, Whop and email; service messages about changes and disruptions.
- Analysis and Improvement (Consent where required, otherwise Legitimate Interest): analysis of the use of the website, the app and the web application; error analysis; A/B tests; development of new features and products.
- Marketing and Advertising (Consent where required, otherwise Legitimate Interest): measuring and optimizing advertising campaigns (e.g., via Whop Ads and Meta); retargeting; creation of target and lookalike audiences, including customer lists; attribution to campaigns, creators and affiliates, including commission settlement; segmentation and profiling for personalized content and offers.
- Email Marketing: information about the Provider’s own similar products sent to existing customers (Legitimate Interest; the User may object at any time); newsletters to other recipients only with Consent.
- Legal Obligations (Legal Obligation): retention of contract and billing data (statutory retention periods of up to 10 years); fulfillment of information obligations to authorities.
- Legal Enforcement (Legitimate Interest): assertion, exercise and defense of legal claims, including chargebacks and disputes.
§ 6 COOKIES, ANALYTICS AND ADVERTISING TECHNOLOGIES
(1) The Provider uses cookies, pixels, tags, software development kits (SDKs), local storage and comparable technologies on the website, in the web application and in the iOS application, as well as server-side interfaces, for the purposes described in § 5.
(2) Where applicable law requires consent for storing or accessing information on a device (e.g., in the EU/EEA, the United Kingdom and Switzerland), technologies that are not strictly necessary are only used after the User has consented via the consent banner. Consent can be withdrawn at any time with effect for the future via the “Cookie settings” link on the website.
(3) Where no consent is required, these technologies are used on the basis of the Provider’s Legitimate Interest in analyzing and marketing its Products. The User may object at any time via the cookie settings or the settings of their browser or device.
(4) The Provider uses providers from the following categories: web analytics, heatmaps and session recording (e.g., Microsoft Clarity); advertising, conversion measurement and audience creation (e.g., Meta); attribution, affiliate and campaign tracking; app analytics and crash reporting; A/B testing; email delivery and analytics; consent management; hosting and content delivery. The providers currently used, their purposes and storage periods are listed in the cookie settings.
(5) Meta: Where the Provider uses Meta technologies (e.g., Meta Pixel, Conversions API, customer lists), the Provider and Meta Platforms Ireland Limited are jointly responsible for the collection and transmission of the data. The subsequent processing is carried out by Meta under its own responsibility. Email addresses for customer lists are transmitted in hashed form only. Further information: https://www.facebook.com/privacy/policy
(6) iOS Application: Tracking within the meaning of Apple’s App Tracking Transparency framework – i.e., linking data from the app with data from third-party apps or websites for advertising purposes – only takes place if the User has granted permission via Apple’s system prompt. This permission can be changed at any time in the iOS settings.
(7) The User can prevent the storage of cookies via the settings of their browser. In this case, the functionality of the website may be limited.
§ 7 AUTOMATED ACCESS CONTROL
(1) The Provider uses an automated access control. It automatically checks whether the User’s subscription is active, whether the payment status is current (no default of payment, no chargeback), whether the device limit is complied with, and whether there are indications of shared access.
(2) If any of these checks is negative, access is automatically deactivated.
(3) Legal Basis: Contract; Legitimate Interest. The User may request a manual review (see § 12).
§ 8 RECIPIENTS OF DATA
A. Whop Inc. (USA)
Whop acts as the Merchant of Record for purchases via Whop. The Provider transmits the access status and the subscription status of the User to Whop. Purpose: payment processing, subscription management, handling of refund applications (via Resolution Center) and, where Whop’s advertising services are used, running and measuring advertising campaigns.
B. Stripe, Inc. (USA)
Whop uses Stripe Inc. (USA) as its payment service provider. The Provider has no direct access to payment data. These are processed exclusively between Whop and Stripe.
C. Apple Inc. (USA)
For purchases via the Apple App Store and for the delivery of push notifications (Apple Push Notification service), data is processed by Apple. Apple processes payment data under its own responsibility.
D. Discord Inc. (USA)
If the User joins the Discord community, the following data is transmitted to Discord Inc.: Discord User ID (via the Provider’s bot) and server and role information. Purpose: automatic access management to the Discord community.
E. Hosting and Technical Service Providers
The website, the app backend, databases and email delivery are operated by external service providers who process data on behalf of the Provider under data processing agreements.
F. Analytics and Advertising Providers
See § 6.
G. Affiliates, Creators and Campaign Partners
Information required for attribution and commission settlement, in pseudonymized form where possible.
H. Advisors and Authorities
Tax advisors, lawyers and auditors; authorities where required by law.
I. Corporate Transactions
In the event of a merger, acquisition or sale of all or part of the business, data may be transferred to the acquirer.
§ 9 INTERNATIONAL DATA TRANSFERS
(1) Data may be processed in countries other than the User’s country of residence, in particular in the USA.
(2) Where required, such transfers are protected by appropriate safeguards, such as recognized adequacy mechanisms or standard contractual clauses.
(3) A copy of the safeguards can be requested at support@vision-alerts.com.
§ 10 STORAGE PERIOD
The Provider stores personal data only for as long as necessary for the purposes set out above or as required by statutory retention obligations.
| Data Category | Storage Period | Justification |
|---|---|---|
| Account Data | For the duration of the account + 30 days | Deletion after closure of the account |
| Contract and Billing Data | 10 years | Statutory retention obligations |
| Discord User ID | For the duration of the active subscription | Automatic removal from community upon subscription expiry |
| Device Data (IP, Device ID) | For the duration of the active subscription + 90 days | Prevention of misuse, fraud prevention |
| Usage Data (app and web application) | For the duration of the account | Deletion or anonymization after closure of the account |
| Server Log Data | Up to 30 days | Longer in the event of security incidents |
| Analytics and Advertising Data | As stated per provider in the cookie settings, no longer than 24 months | Analysis and marketing |
| Profiles and Segments | Until objection, withdrawal of consent or closure of the account | Analysis, personalization and marketing |
| Consent Records | 3 years | Proof of consent |
| Support Communication (Discord/Whop/email) | 3 years | Documentation of support inquiries, statutory limitation period |
After expiry of the storage period, the data will be deleted or anonymized. Anonymized data may be retained without time limit.
§ 11 YOUR RIGHTS
All Users, regardless of their country of residence, have the following rights:
| Right | Description |
|---|---|
| Access | You may request confirmation of whether and what data concerning you is being processed. |
| Rectification | You may request the rectification of inaccurate data. |
| Erasure | You may request the erasure of your data, provided no statutory retention obligations apply. |
| Restriction | You may request the restriction of processing. |
| Data Portability | You may receive your data in a machine-readable format. |
| Objection | You may object to processing on grounds relating to your particular situation. |
| Withdrawal of Consent | To the extent processing is based on consent, you may withdraw it at any time, in particular via the cookie settings on the website or the iOS settings. |
Right to Object to Direct Marketing
You may object at any time, without giving reasons, to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. Following an objection, your data will no longer be processed for these purposes. The objection can be sent to support@vision-alerts.com or declared via the cookie settings.
Account Deletion
You have the right to request the deletion of your account and all associated personal data at any time. You can initiate account deletion in the following ways:
- In the App: You will find the account deletion option in your account settings. After confirmation, your account and all associated data will be deleted.
- By Email: You can request deletion by emailing us at support@vision-alerts.com.
We will delete your account and all associated data within a reasonable period (typically within 30 days), unless we are legally obligated to retain certain data (e.g., for tax or regulatory purposes). In such cases, we will inform you of the nature and duration of the retention.
Deleting your account will result in the loss of access to our services. Please note that once an account is deleted, this action cannot be reversed.
Further Rights under Local Law
Users may have additional rights under the laws of their country or state of residence (e.g., in certain U.S. states). These can be exercised in the same way.
Contact for Data Subject Rights
support@vision-alerts.com. The Provider responds within one month.
Complaint to a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in your country of residence.
§ 12 MANUAL REVIEW OF AUTOMATED DECISIONS
(1) As described in § 7, the Provider uses an automated access control. It decides automatically on the deactivation of access.
(2) The User may request a manual review of an automated deactivation at any time. To do so, the User contacts the Provider via the Discord community or – for formal applications – via the Whop Resolution Center or by email to support@vision-alerts.com.
(3) The Provider will review the case manually and inform the User of the result within 14 days.
§ 13 DATA SECURITY
The Provider takes appropriate technical and organizational measures (TOM) to ensure data security:
- Encryption: All connections to the website, the app and the web application are TLS-encrypted (HTTPS).
- Access Control: Only authorized persons have access to the systems and data.
- Pseudonymization: Where possible, data is processed in pseudonymized form.
- Regular Security Updates: The systems are regularly updated.
Despite these measures, the Provider cannot guarantee absolute security.
§ 14 CHANGES TO THIS PRIVACY POLICY
(1) The Provider reserves the right to change this Privacy Policy at any time to adapt it to changed legal requirements or new processing purposes.
(2) The current version can be viewed on the Provider’s website and in the app.
(3) Changes take effect upon publication. Where a change requires consent by law, the Provider will obtain it.