← VISION ALERTS

Privacy Policy

As of 16 September 2026

Between:

Bayomi UG (haftungsbeschränkt), Winterhuder Weg 31, 22085 Hamburg, Germany, Commercial Register HRB 199083 Local Court Hamburg, represented by Managing Director Jonathan Jakob Greiter

(hereinafter “Provider”)

and:

The User of the Products (hereinafter “User”)

§ 1 SCOPE

(1) The Provider offers its Products internationally. This Privacy Policy explains how the Provider processes personal data of Users and visitors worldwide in connection with the website vision-alerts.com, the VISION ALERTS iOS application, the VISION ALERTS web application, the Discord community and subscriptions concluded via Whop or an app store (together the “Products”).

(2) This Privacy Policy supplements the Provider’s Terms of Service, EULA, and Return Policy.

(3) The Products are not directed at persons under the age of 18.

§ 2 CONTROLLER AND CONTACT

Controller for data processing:

Bayomi UG (haftungsbeschränkt)

Winterhuder Weg 31

22085 Hamburg

Germany

Commercial Register HRB 199083 Local Court Hamburg

represented by Managing Director Jonathan Jakob Greiter

Email (for privacy requests): support@vision-alerts.com

Privacy requests will only be processed via this email address. Postal inquiries are also possible but may result in longer processing times.

The Provider does not have a statutorily appointed Data Protection Officer. Please direct privacy requests to the email address above.

§ 3 LEGAL BASES

The Provider applies a uniform level of data protection to all processing worldwide, regardless of where the User is located. Processing is based on the following legal bases, referred to in this Privacy Policy by the terms in quotation marks:

  • Performance of a contract with the User – “Contract”
  • Legitimate interests of the Provider, in particular in the operation, security, analysis, improvement and marketing of the Products – “Legitimate Interest”
  • Consent of the User – “Consent”
  • Legal obligations of the Provider – “Legal Obligation”

§ 4 WHAT DATA IS PROCESSED

A. Data that Whop Transmits to the Provider

Data CategorySpecific DataPurpose
Master DataWhop username, name, email address, countryIdentification of the User, provision of access
Subscription DataActive subscription status, subscription type (monthly/annual), durationVerification of entitlement, access management
Payment DataPayment status (completed/pending/failed), amounts, chargeback statusDeactivation of access in case of default of payment, analysis
Attribution DataReferral and affiliate assignmentAttribution to campaigns and partners
Other DataOther data transmitted by WhopAs above

Legal Basis: Contract; Legitimate Interest

B. Data from App Stores

If the User subscribes via an app store, the Provider receives the following data from the app store operator: subscription status, subscription type, transaction identifiers, renewal, cancellation and refund status, and the country of the storefront. Payment data remains with the app store operator.

Legal Basis: Contract

C. Data Processed by the Provider Itself

Data CategorySpecific DataPurpose
Account DataEmail address, login credentials, account status, timestamps of registration and sign-inProvision and management of access
Profile and SettingsName, time zone, instrument and notification settingsProvision and personalization of the Products
Device DataDevice identifiers, IP address, operating system and app version, push notification token, languageDelivery of signals, enforcement of the device limit, prevention of misuse
Usage DataInteractions within the app and web application, features used, signals and analyses viewed, crash and diagnostic data, delivery and opening of push notificationsOperation, error analysis, analysis and improvement of the Products
Communication DataSupport inquiries and correspondence via Discord, Whop and emailHandling of inquiries, documentation
Discord DataDiscord User ID, roles, activity in channels operated by the ProviderAccess management and analysis of the Discord community

Legal Basis: Contract; Legitimate Interest

D. Website, Analytics and Advertising Data

Data CategorySpecific DataPurpose
Server Log DataIP address, date and time, pages accessed, referrer, browser and operating systemOperation and security of the website
Analytics DataPages viewed, time on page, scroll depth, clicks, taps and mouse movements, form inputs (excluding passwords and payment data), session recordings and heatmaps, A/B test variants, device and browser information, approximate location, referral source and campaign parametersAnalysis and improvement of the website and the Products
Advertising DataOnline identifiers, cookie and advertising IDs, conversion events including subscription value, hashed email addresses for customer lists, server-side transmission of eventsMeasuring and optimizing advertising campaigns, retargeting, creation of target and lookalike audiences
Attribution DataReferral, affiliate, campaign and creator codesAttribution of subscriptions to campaigns, creators and partners, commission settlement
Linked Data and ProfilesLinking of usage data across devices and with the customer account, segmentsAnalysis, personalization and marketing
Email Interaction DataOpens and link clicksMeasuring the effectiveness of emails
Embedded Third-Party ContentData transmitted when loading embedded videos or social media contentDisplay of embedded content

Legal Basis: Server Log Data – Legitimate Interest. All other data in this section – Consent where required by applicable law, otherwise Legitimate Interest. Details in § 6.

E. Payment Data

The Provider does not process payment card or bank account details. These remain with Whop, Stripe or the respective app store operator.

§ 5 PURPOSES OF DATA PROCESSING

The Provider processes the User’s data for the following purposes:

  • Contract Performance (Contract): provision of access to the app, the web application and the Discord community; management of subscriptions; delivery of signals and analyses, including push notifications; enforcement of the device limit.
  • Access Control and Prevention of Misuse (Legitimate Interest): automated subscription checks; detection of shared access and redistributed content; prevention of fraud and chargebacks.
  • Support and Communication (Contract; Legitimate Interest): answering inquiries via Discord, Whop and email; service messages about changes and disruptions.
  • Analysis and Improvement (Consent where required, otherwise Legitimate Interest): analysis of the use of the website, the app and the web application; error analysis; A/B tests; development of new features and products.
  • Marketing and Advertising (Consent where required, otherwise Legitimate Interest): measuring and optimizing advertising campaigns (e.g., via Whop Ads and Meta); retargeting; creation of target and lookalike audiences, including customer lists; attribution to campaigns, creators and affiliates, including commission settlement; segmentation and profiling for personalized content and offers.
  • Email Marketing: information about the Provider’s own similar products sent to existing customers (Legitimate Interest; the User may object at any time); newsletters to other recipients only with Consent.
  • Legal Obligations (Legal Obligation): retention of contract and billing data (statutory retention periods of up to 10 years); fulfillment of information obligations to authorities.
  • Legal Enforcement (Legitimate Interest): assertion, exercise and defense of legal claims, including chargebacks and disputes.

§ 6 COOKIES, ANALYTICS AND ADVERTISING TECHNOLOGIES

(1) The Provider uses cookies, pixels, tags, software development kits (SDKs), local storage and comparable technologies on the website, in the web application and in the iOS application, as well as server-side interfaces, for the purposes described in § 5.

(2) Where applicable law requires consent for storing or accessing information on a device (e.g., in the EU/EEA, the United Kingdom and Switzerland), technologies that are not strictly necessary are only used after the User has consented via the consent banner. Consent can be withdrawn at any time with effect for the future via the “Cookie settings” link on the website.

(3) Where no consent is required, these technologies are used on the basis of the Provider’s Legitimate Interest in analyzing and marketing its Products. The User may object at any time via the cookie settings or the settings of their browser or device.

(4) The Provider uses providers from the following categories: web analytics, heatmaps and session recording (e.g., Microsoft Clarity); advertising, conversion measurement and audience creation (e.g., Meta); attribution, affiliate and campaign tracking; app analytics and crash reporting; A/B testing; email delivery and analytics; consent management; hosting and content delivery. The providers currently used, their purposes and storage periods are listed in the cookie settings.

(5) Meta: Where the Provider uses Meta technologies (e.g., Meta Pixel, Conversions API, customer lists), the Provider and Meta Platforms Ireland Limited are jointly responsible for the collection and transmission of the data. The subsequent processing is carried out by Meta under its own responsibility. Email addresses for customer lists are transmitted in hashed form only. Further information: https://www.facebook.com/privacy/policy

(6) iOS Application: Tracking within the meaning of Apple’s App Tracking Transparency framework – i.e., linking data from the app with data from third-party apps or websites for advertising purposes – only takes place if the User has granted permission via Apple’s system prompt. This permission can be changed at any time in the iOS settings.

(7) The User can prevent the storage of cookies via the settings of their browser. In this case, the functionality of the website may be limited.

§ 7 AUTOMATED ACCESS CONTROL

(1) The Provider uses an automated access control. It automatically checks whether the User’s subscription is active, whether the payment status is current (no default of payment, no chargeback), whether the device limit is complied with, and whether there are indications of shared access.

(2) If any of these checks is negative, access is automatically deactivated.

(3) Legal Basis: Contract; Legitimate Interest. The User may request a manual review (see § 12).

§ 8 RECIPIENTS OF DATA

A. Whop Inc. (USA)

Whop acts as the Merchant of Record for purchases via Whop. The Provider transmits the access status and the subscription status of the User to Whop. Purpose: payment processing, subscription management, handling of refund applications (via Resolution Center) and, where Whop’s advertising services are used, running and measuring advertising campaigns.

B. Stripe, Inc. (USA)

Whop uses Stripe Inc. (USA) as its payment service provider. The Provider has no direct access to payment data. These are processed exclusively between Whop and Stripe.

C. Apple Inc. (USA)

For purchases via the Apple App Store and for the delivery of push notifications (Apple Push Notification service), data is processed by Apple. Apple processes payment data under its own responsibility.

D. Discord Inc. (USA)

If the User joins the Discord community, the following data is transmitted to Discord Inc.: Discord User ID (via the Provider’s bot) and server and role information. Purpose: automatic access management to the Discord community.

E. Hosting and Technical Service Providers

The website, the app backend, databases and email delivery are operated by external service providers who process data on behalf of the Provider under data processing agreements.

F. Analytics and Advertising Providers

See § 6.

G. Affiliates, Creators and Campaign Partners

Information required for attribution and commission settlement, in pseudonymized form where possible.

H. Advisors and Authorities

Tax advisors, lawyers and auditors; authorities where required by law.

I. Corporate Transactions

In the event of a merger, acquisition or sale of all or part of the business, data may be transferred to the acquirer.

§ 9 INTERNATIONAL DATA TRANSFERS

(1) Data may be processed in countries other than the User’s country of residence, in particular in the USA.

(2) Where required, such transfers are protected by appropriate safeguards, such as recognized adequacy mechanisms or standard contractual clauses.

(3) A copy of the safeguards can be requested at support@vision-alerts.com.

§ 10 STORAGE PERIOD

The Provider stores personal data only for as long as necessary for the purposes set out above or as required by statutory retention obligations.

Data CategoryStorage PeriodJustification
Account DataFor the duration of the account + 30 daysDeletion after closure of the account
Contract and Billing Data10 yearsStatutory retention obligations
Discord User IDFor the duration of the active subscriptionAutomatic removal from community upon subscription expiry
Device Data (IP, Device ID)For the duration of the active subscription + 90 daysPrevention of misuse, fraud prevention
Usage Data (app and web application)For the duration of the accountDeletion or anonymization after closure of the account
Server Log DataUp to 30 daysLonger in the event of security incidents
Analytics and Advertising DataAs stated per provider in the cookie settings, no longer than 24 monthsAnalysis and marketing
Profiles and SegmentsUntil objection, withdrawal of consent or closure of the accountAnalysis, personalization and marketing
Consent Records3 yearsProof of consent
Support Communication (Discord/Whop/email)3 yearsDocumentation of support inquiries, statutory limitation period

After expiry of the storage period, the data will be deleted or anonymized. Anonymized data may be retained without time limit.

§ 11 YOUR RIGHTS

All Users, regardless of their country of residence, have the following rights:

RightDescription
AccessYou may request confirmation of whether and what data concerning you is being processed.
RectificationYou may request the rectification of inaccurate data.
ErasureYou may request the erasure of your data, provided no statutory retention obligations apply.
RestrictionYou may request the restriction of processing.
Data PortabilityYou may receive your data in a machine-readable format.
ObjectionYou may object to processing on grounds relating to your particular situation.
Withdrawal of ConsentTo the extent processing is based on consent, you may withdraw it at any time, in particular via the cookie settings on the website or the iOS settings.

Right to Object to Direct Marketing

You may object at any time, without giving reasons, to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. Following an objection, your data will no longer be processed for these purposes. The objection can be sent to support@vision-alerts.com or declared via the cookie settings.

Account Deletion

You have the right to request the deletion of your account and all associated personal data at any time. You can initiate account deletion in the following ways:

  • In the App: You will find the account deletion option in your account settings. After confirmation, your account and all associated data will be deleted.
  • By Email: You can request deletion by emailing us at support@vision-alerts.com.

We will delete your account and all associated data within a reasonable period (typically within 30 days), unless we are legally obligated to retain certain data (e.g., for tax or regulatory purposes). In such cases, we will inform you of the nature and duration of the retention.

Deleting your account will result in the loss of access to our services. Please note that once an account is deleted, this action cannot be reversed.

Further Rights under Local Law

Users may have additional rights under the laws of their country or state of residence (e.g., in certain U.S. states). These can be exercised in the same way.

Contact for Data Subject Rights

support@vision-alerts.com. The Provider responds within one month.

Complaint to a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in your country of residence.

§ 12 MANUAL REVIEW OF AUTOMATED DECISIONS

(1) As described in § 7, the Provider uses an automated access control. It decides automatically on the deactivation of access.

(2) The User may request a manual review of an automated deactivation at any time. To do so, the User contacts the Provider via the Discord community or – for formal applications – via the Whop Resolution Center or by email to support@vision-alerts.com.

(3) The Provider will review the case manually and inform the User of the result within 14 days.

§ 13 DATA SECURITY

The Provider takes appropriate technical and organizational measures (TOM) to ensure data security:

  • Encryption: All connections to the website, the app and the web application are TLS-encrypted (HTTPS).
  • Access Control: Only authorized persons have access to the systems and data.
  • Pseudonymization: Where possible, data is processed in pseudonymized form.
  • Regular Security Updates: The systems are regularly updated.

Despite these measures, the Provider cannot guarantee absolute security.

§ 14 CHANGES TO THIS PRIVACY POLICY

(1) The Provider reserves the right to change this Privacy Policy at any time to adapt it to changed legal requirements or new processing purposes.

(2) The current version can be viewed on the Provider’s website and in the app.

(3) Changes take effect upon publication. Where a change requires consent by law, the Provider will obtain it.

↑