Privacy Policy

    Last updated: 29 August 2026

    1. Who we are

    Vibe Code Fest ("we", "the Event") is a community unconference organised in Switzerland. You can reach us at hello@vibecodefest.ch for any privacy question or request.

    This policy explains what personal data we collect when you use this website, register for the Event, join the waitlist or newsletter, contribute a talk or activity, or purchase a ticket — and what we do with it. It is governed by the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU GDPR.

    2. What we collect

    • Registration & waitlist: name, email address, and optionally your LinkedIn profile URL, company, role and a profile photo.
    • Contributions & feedback: if you propose a talk, workshop or activity, the details you submit (topic, description, "why me"); if you vote or give feedback, your ratings and comments.
    • Preferences: food and dietary preferences you give us after checkout. These are used only to organise catering and are never published publicly.
    • Payments: ticket and sponsor purchases are processed by Stripe. We receive your name, email, billing details and the payment status — we never see or store your full card number.
    • Newsletter: your email address, only if you subscribe.
    • Analytics: we do not currently use Google Analytics or any other third-party analytics cookies. Server logs processed by our hosting provider may contain anonymised technical data (such as pages visited, browser type and approximate region) for security and reliability purposes only.
    • Media: photos and videos taken at the Event may include your image — see our Terms & Conditions for how to opt out.

    3. Why we process it

    • To organise and run the Event (tickets, badges, schedule, catering).
    • To communicate with you (order confirmations, updates, newsletters you asked for).
    • To show public participant and contribution lists, limited to the details you chose to share.
    • To process payments, issue invoices and meet accounting obligations.
    • To improve the website and future editions (aggregated analytics and feedback).

    4. Who processes your data

    We use a small number of trusted processors to run the Event:

    • Stripe — payment processing for tickets and sponsorships.
    • Supabase — database and file storage for registrations, contributions and photos you upload.
    • Resend — transactional and newsletter email delivery.
    • Google — sign-in for the internal organiser area only.
    • Bexio — invoicing and accounting for ticket and sponsor revenue.
    • Lovable / Cloudflare — website hosting and content delivery.

    Some of these providers process data outside Switzerland/EU. Where they do, transfers are covered by the providers' standard contractual safeguards. We never sell your data.

    5. Cookies & analytics

    We do not use analytics or advertising cookies. Only essential cookies required for security and site functionality may be set by our hosting provider. You can block or delete cookies in your browser settings at any time.

    6. How long we keep it

    Registration and order data is kept as long as needed to run the Event and meet legal accounting retention duties (in Switzerland, generally 10 years for financial records). Newsletter subscriptions are kept until you unsubscribe. Feedback and votes are kept in aggregated or pseudonymous form for improving future editions. You can ask us to delete your data earlier — see below.

    7. Your rights

    You can at any time:

    • Request a copy of the personal data we hold about you.
    • Ask us to correct inaccurate data (profile links we send you also let you edit your public profile yourself).
    • Ask us to delete your data, unless we must keep it for legal reasons.
    • Unsubscribe from the newsletter via the link in every email.
    • Object to appearing in event photos or videos (before, during or after the Event).

    Just email hello@vibecodefest.ch. If you believe your data protection rights have been violated, you also have the right to contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local EU supervisory authority.

    8. Security

    Access to personal data is restricted to the organising team. Administrative access is authenticated, sensitive preferences are excluded from public listings, and all traffic is encrypted in transit (HTTPS).

    9. Changes

    We may update this policy as the Event and its tooling evolve. The current version is always published on this page with its date.