Privacy Policy
Last updated: December 2025
This Privacy Policy describes how Vatra Labs, operated by Vatra Labs Incorporated ("Company", "we", "us", "our"), collects, uses, and shares your information when you use our service.
1. Information We Collect
We collect information you provide directly to us, including:
- Discord Account Information: Username, user ID, email address, and avatar obtained via Discord OAuth authentication
- Payment Information: Processed securely through Stripe (we do not store full card numbers)
- Phone Number: Collected during checkout via Stripe for payment verification and account recovery only
- Subscription Data: Transaction history, subscription tiers, and billing records
- Communications: Messages sent to our support team
- Creator Profile Information: Display name, bio, and avatar (for creators only)
2. How We Use Your Information
We use collected information to:
- Process payments and manage subscriptions through Stripe
- Assign and manage Discord roles corresponding to your subscription tier
- Provide access to creator Discord communities
- Communicate with you about your account and transactions
- Verify your identity and prevent fraud
- Enable account recovery
- Improve and maintain our Service
- Generate analytics and insights for creators
- Comply with legal obligations
Phone Number Usage: Your phone number is collected during checkout via Stripe and is used solely for payment verification, fraud prevention, and account recovery. We do not use your phone number for marketing purposes without your explicit consent.
2.1 Platform Analytics & Data Processing
Vatra Labs processes connected account data (YouTube, Patreon, Discord) to provide analytics services for creators. This includes:
- Aggregating subscriber and revenue metrics for creator dashboards
- Generating predictive insights (e.g., at-risk subscriber alerts, growth opportunities)
- Platform-wide analytics to improve our services
- Internal reporting and business intelligence
- Creating anonymized, aggregated market research and industry reports
Data Access: Authorized Vatra Labs personnel may access aggregated and individual account data for platform operations, support, security, and service improvement. All access is logged and subject to our internal data governance policies.
2.2 YouTube API Services
When creators connect their YouTube account to Club Vatra, we access certain data through the YouTube API Services. By connecting YouTube, creators agree to be bound by the YouTube Terms of Service and Google Privacy Policy.
Data we collect via YouTube API:
- Channel Information: Channel name, subscriber count, video list, and video metadata
- Analytics Data: Views, watch time, traffic sources, and audience demographics
- Revenue Data: Estimated earnings, ad performance, and RPM (if creator grants monetary scope)
How YouTube data is used:
- To display analytics dashboards showing creators their own channel performance
- To generate content performance insights and growth recommendations
- YouTube data is never shared with or sold to third parties
How YouTube data is stored:
- OAuth credentials are encrypted at rest using AES-256-GCM encryption
- Access is restricted to the creator and authorized platform administrators
- Credentials are deleted immediately when a creator disconnects YouTube
How to revoke access:
- Creators can disconnect YouTube from their Club Vatra dashboard at any time
- Creators can also revoke access directly from their Google Account permissions page
- Upon disconnection or revocation, all stored YouTube credentials and cached analytics data are permanently deleted
3. Information Sharing
We share your information only as follows:
- With Creators: Creators can see your Discord username, display name, subscription tier, and subscription status. Creators do NOT have access to your email address, phone number, or payment details.
- With Stripe: Payment processing is handled by Stripe under their privacy policy. Stripe may access your payment information and phone number for transaction processing and fraud prevention.
- With Discord: We interact with Discord's API solely to verify your identity via OAuth, manage subscription tier roles in creator servers, and provide access to gated community channels.
- Legal Requirements: We may disclose information when required by law, court order, or to protect the rights, property, or safety of Vatra Labs, our users, or others.
We do not sell your personal information to third parties.
3.1 Cancellation Feedback
When you cancel a subscription, we may ask you to complete an optional exit survey. This feedback is shared with creators in aggregate form to help them improve their offerings. Your individual responses are not personally identifiable to the creator unless you choose to include identifying information in your comments.
3.2 Aggregated and Anonymized Data
We may create aggregated, de-identified datasets derived from platform usage patterns that cannot reasonably be used to identify any individual user. This anonymized data may be used for:
- Industry research, benchmarking, and market analysis reports
- Academic and research partnerships
- Improving our services and developing new features
- Business intelligence products and trend analysis
Important: This aggregated data contains no personally identifiable information (such as names, emails, Discord IDs, or payment details) and cannot be linked back to individual users. The creation and use of anonymized, aggregated data is separate from our commitment to never sell your personal information to third parties.
4. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit via HTTPS/TLS
- Encryption of sensitive data at rest
- Payment data processed and stored by PCI-compliant Stripe
- Row-level security policies in our database
- Regular security audits and monitoring
However, no method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
5. Data Retention
We retain your information according to the following schedule:
- Discord Data: Your Discord user ID, username, and avatar are retained for the duration of your active subscription(s). This data is deleted within 30 days of account deletion or upon your request.
- Account Information: Retained for as long as your account is active or as needed to provide services.
- Transaction Records: Payment and subscription records are retained for 7 years for legal, tax, and accounting purposes.
- Support Communications: Retained for 2 years after resolution.
You may request account deletion by contacting us at help@clubvatra.com.
6. Your Rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Opt out of marketing communications
- Export your data in a portable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at help@clubvatra.com.
6.1 Rights for EEA Residents (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the right to data portability and the right to lodge a complaint with a supervisory authority. Our legal basis for processing your data is contractual necessity (to provide our services) and legitimate interests (to improve our platform and prevent fraud).
6.2 Rights for California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. We do not sell personal information as defined under CCPA.
7. Cookies
We use essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies. Third-party services integrated with Vatra Labs (such as Stripe) may use their own cookies subject to their respective privacy policies.
8. Children's Privacy
Vatra Labs is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at help@clubvatra.com.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. We ensure appropriate safeguards are in place for such transfers.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will notify you of material changes via email or platform notification at least 30 days before the changes take effect. Your continued use of Vatra Labs after the effective date constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
© 2025 Vatra Labs. A product of Vatra Labs Incorporated. All rights reserved.
Questions? Contact us at