This policy explains what personal data we process when you use VAKA, why we need it, who we share it with, and what control you have over it. It applies to the website, the mobile app, and the communications we send you. We wrote it to be understood, not to hide anything: where a topic has its own document, we link to it so you can read the full detail.
Three documents complement this policy: the Cookie Policy (technologies in your browser), the Identity Verification and Biometric Data Policy (the most sensitive processing we do) and the Terms of Service (the general rules of the platform).
1. Who is responsible for your data
The entity responsible for processing your personal data is VAKA Inc., a company incorporated in the United States that operates the VAKA platform. Corporate registration data and, where applicable, local representatives by country will be added to this document as VAKA enables operations in each country.
For any privacy matter you can write to soporte@vakaland.com or use the channels at Contact.
2. What data we process
We process only the data necessary for a rental marketplace between neighbors to work safely. We group it by type so you know exactly what we're talking about.
2.1 Account and profile data
- Account: name, email, and password. The password is stored only as a cryptographic hash (never in plain text) through our authentication provider.
- Phone: your phone number and its verification status. To verify it we send you a one-time code (OTP) by SMS through Twilio.
- Profile: profile photo, city, and other optional fields you choose to complete. Optional means truly optional: you can leave it empty.
- Preferences: language, the currency you want to see prices in, country, and notification and privacy preferences.
2.2 Identity data and biometric data
To verify your identity we ask for a photo of your official document and a selfie. The comparison between your face and the document constitutes processing of biometric data, the most sensitive category of data we handle, and that's why we only do it with your express consent.
Today those images are stored securely in our private storage for review by authorized VAKA personnel. When we activate a specialized verification provider (Didit), that provider will process the verification on our behalf. The full detail — what we ask for, who sees it, how long it is kept, and how to revoke your consent — is in the Identity Verification and Biometric Data Policy. Other neighbors never see your document or your selfie: they only see the verification badge.
2.3 Payment and transaction data
- What VAKA keeps: your history of bookings and rentals, amounts, statuses, deposits, refunds, and withdrawals. We need it to operate the service, resolve disputes, and meet accounting obligations.
- What VAKA does not see: your full card number. Card data is captured and processed directly by Stripe, our payment processor; VAKA receives only transaction references and the last digits.
- Withdrawals: if you receive payments as an owner, your bank account data is transmitted to Wise to execute the transfer.
How the money flow works (charges, deposits, withdrawals) is described in the Payments Policy.
2.4 Content and evidence
- Listings: photos, descriptions, prices, and availability of the items you publish.
- Delivery and return evidence: the photos that owner and neighbor capture when handing over and returning an item include the date, time, and GPS coordinates of the place where they were taken. That location has an evidentiary purpose: to record that the delivery or return happened, where, and in what condition. We ask for location permission on your device before capturing them. This evidence is used in the claims.
- Chat photos: the images you send in conversations with an active booking.
- Reviews: the ratings and reviews you write and receive. They are public on profiles.
2.5 Messages
The content of your conversations with other neighbors is stored so the chat works. For community safety, messages pass through an automatic filter that detects and blocks attempts to share contact details (phones, emails, social media) before a booking exists that justifies it — it is one of our defenses against fraud and off-platform arrangements, described in the Anti-Fraud Policy. Blocked attempts are recorded.
No one on the team reads your conversations routinely. Human access to a chat happens only in specific cases: when one of the parties reports the conversation, during the resolution of a dispute or claim, or in a fraud or security investigation.
2.6 Technical and anti-fraud data
- Device fingerprint: we generate a technical identifier for your device using the FingerprintJS library, which runs in your own browser or phone. That identifier is sent to our servers — not to an external service — and we use it exclusively to prevent fraud: detecting multiple accounts, impersonations, and abuse patterns.
- IP address and approximate country: to show the content of the correct country and detect abuse.
- Device data: browser or operating system type, language, and time zone.
- Activity and security logs: logs of relevant actions (logins, account changes, security events) that let us audit what happened if something goes wrong.
- Error logs: when the app fails, a technical report is sent to Sentry (our monitoring tool) that may include your user identifier and device data, so we can fix the problem.
2.7 Data we receive from third parties
If you register with an external identity provider (for example Google), we receive your name and email from that provider. From Stripe we receive payment confirmations (never your full card number). When verification with Didit is active, we will receive the result of your verification from Didit.
3. What we use your data for
- Providing the service: creating and maintaining your account, showing you items, processing bookings, payments, deposits, and withdrawals, and delivering your messages. Basis: the contractual relationship with you.
- Security and fraud prevention: verifying identities, detecting fake or duplicate accounts, blocking scam attempts, and protecting the community's money and items. Basis: our legitimate interest in operating a secure platform and, where the law requires it, compliance with legal obligations.
- Identity and biometric verification: comparing your face with your document to confirm that you are who you say you are. Basis: your express consent — see Identity Verification Policy.
- Service communications: transactional emails (confirmations, reminders, security notices) through Resend, push notifications through OneSignal only if you enable them, and verification SMS through Twilio.
- Support: answering your queries and resolving disputes, using the history needed to understand your case.
- Improving the platform: understanding usage with aggregated data. Today we do not use third-party analytics tools — the detail is in the Cookie Policy.
- Legal compliance: meeting accounting and tax obligations and responding to valid requirements from competent authorities.
About automated decisions: some VAKA protections operate automatically, such as the contact-data filter in the chat or the amount limits according to your verification level. Our systems also calculate risk signals to prioritize reviews. Decisions with significant effects on your account — such as a suspension or the rejection of your identity verification — go through review by a person on the team, and you always have the right to appeal through Contact.
4. What we do not do with your data
- We do not sell your personal data to anyone.
- We do not show third-party advertising or build commercial profiles of you for advertisers.
- We do not use third-party analytics tools today. If that changes, we will update the Cookie Policy and we will notify you before activating them.
- We do not read your chats routinely or monitor your conversations with team members.
- We do not show your phone or email to other neighbors. Coordination between neighbors goes through the VAKA chat.
- We do not track your location in the background. Location is used only at specific moments and with your permission (for example, when capturing delivery evidence).
5. Who we share your data with
5.1 Providers that process data on behalf of VAKA
To operate we need specialized providers. Each one receives only the data needed for its function and is contractually obligated to protect it and not use it for its own purposes:
- Supabase — database, authentication, and file storage (including identity verification images and delivery evidence).
- Stripe — card payment processing. It is a US entity; your payment data is processed under its payment-industry certifications.
- Wise — execution of withdrawals and transfers to owners' bank accounts.
- Twilio — sending the SMS code to verify your phone.
- Didit — identity verification, when active. See Identity Verification Policy.
- OneSignal — delivery of push notifications, only if you enable them on your device.
- Resend — sending transactional emails.
- Railway — hosting our application servers.
- Vercel — hosting the website.
- Sentry — monitoring technical errors of the application.
If we add or replace a provider that processes personal data, we will update this list.
5.2 Other neighbors
VAKA is a community, and part of your information is visible to other neighbors: your name, your profile photo, your approximate city (never your exact address), your reviews and ratings, your trust badges, and, if you allow it, your public activity (completed rentals). You can control the visibility of your activity and whether you appear in name searches from Account > Privacy. When you have a booking with another neighbor, that person sees what's needed to coordinate the delivery through the VAKA chat — not your phone or your email.
5.3 Authorities
We provide data to competent authorities only upon a valid legal requirement, and limited to what the requirement demands.
5.4 Corporate changes
If VAKA participates in a merger, acquisition, or sale of assets, your data could be transferred as part of that operation. We would notify you before your data becomes subject to a different privacy policy.
6. International transfers
Our providers process data mainly in the United States and the European Union, so your data may be processed outside your country of residence. When that happens, we require contractual data-protection commitments from each provider (data processing agreements and, where applicable, standard contractual clauses). The specific legal framework for your country is in the Country Annex, which is completed and updated as VAKA enables operations in each country.
7. How long we keep your data
- While your account is active: we keep your data to provide you the service.
- If you delete your account: you can request deletion from Account > Privacy. The request opens a 30-day grace period during which you can change your mind and cancel it; once the period is over, deletion is final and irreversible: your account, your profile, your listings, your bookings, your messages, your favorites, and your notifications are erased from our systems.
- Exceptions to deletion: we may keep minimal records when a legal, accounting, or tax obligation requires it, or while there is an active dispute or claim that needs them. Payment processors (Stripe, Wise) keep their own transaction records according to their regulatory obligations, independent of VAKA.
- Identity verification images: are kept for a limited period, as detailed in the Identity Verification Policy.
- Delivery and return evidence: are kept linked to the booking while the claim windows run and while a related dispute remains open — see Claims Policy.
- Recidivism prevention: in cases of confirmed fraud we may keep minimal technical identifiers (such as the device fingerprint) to the extent permitted by applicable law, with the sole purpose of preventing someone suspended for fraud from returning with another account.
8. Your rights and how to exercise them
Regardless of the country from which you use VAKA, we recognize these rights over your personal data:
- Access: knowing what data we have about you and requesting a copy.
- Rectification: correcting inaccurate or incomplete data. Most of it you can correct directly from your profile.
- Deletion: deleting your account and your data. The deletion we offer is real, not a deactivation — see section 7 for the process and its exceptions.
- Portability: downloading your data in a structured, machine-readable format (JSON). It is available directly in Account > Privacy > Download my data.
- Objection: objecting to processing based on legitimate interest and disabling the visibility of your activity, your appearance in name searches, and the use of your activity for suggestions, from Account > Privacy.
- Withdrawal of consent: withdrawing permissions you granted — push notifications, location, and the biometric verification consent (with the consequences described in the Identity Verification Policy).
- Complaint to an authority: filing a complaint with the data protection authority in your country, where one exists — see the Country Annex.
To exercise any right that is not available directly in the app, write to us at soporte@vakaland.com from the email associated with your account or use Contact. To protect you, we verify that whoever is requesting is the account holder before acting. We respond within a maximum period of 30 days.
9. How we protect your data
- All communication with VAKA travels encrypted (TLS).
- Passwords are stored only as a cryptographic hash.
- The database applies row-level access rules, so each account can only read what belongs to it.
- Sensitive files (verification images, evidence) live in private storage: they are not accessible by public URL, only through signed links with temporary validity.
- Administrative access is restricted to authorized personnel, protected with reinforced authentication, and recorded in audit logs.
- We apply rate limits and monitoring to curb automated abuse attempts.
No system is infallible. If a security breach occurs that affects your personal data, we will notify you without undue delay and notify the authorities when applicable law requires it. If you find a vulnerability, write to us at soporte@vakaland.com.
10. Minors
VAKA is for those over 18. We do not intentionally collect minors' data and we do not accept minors' identity documents in verification. If we detect or you report that a minor has an account, we delete it along with their data. Reports: soporte@vakaland.com.
11. Changes to this policy
If we make substantial changes — new purposes, new types of data, new recipients — we will notify you by email or within the app at least 30 days in advance. Minor changes in wording or clarity are applied directly and are reflected in the last-updated date.
12. Country Annex
The body of this policy is common to all neighbors. This annex identifies the data protection framework of each country where VAKA operates or will operate. Each block is completed and updated as VAKA enables operations in each country; where local legislation recognizes rights additional to those in this policy, those rights prevail.
Honduras
As of the date of this policy, Honduras does not have a general personal data protection law in force. That changes nothing for you: VAKA applies the full standard of this policy equally as a contractual commitment with each neighbor. There are constitutional protections (habeas data) and sectoral rules that may be applicable; the exact framework and the competent authority, if applicable, will be specified in this section upon enabling operations in the country.
Guatemala
Guatemala does not have a general data protection law for the private sector; there are constitutional protections (habeas data) and sectoral provisions. VAKA applies the full standard of this policy as a contractual commitment. The applicable law and the competent authority will be specified in this section upon enabling operations in the country.
El Salvador
Reference framework: Personal Data Protection Law (approved in 2024). The competent supervisory authority and the applicable adaptation periods will be specified in this section upon enabling operations in the country.
Nicaragua
Reference framework: Law No. 787, Personal Data Protection Law. The competent supervisory authority and its operating status will be specified in this section upon enabling operations in the country.
Costa Rica
Reference framework: Law No. 8968 on the Protection of the Person regarding the Processing of their Personal Data, with PRODHAB as the supervisory authority. The database registration obligations that might apply will be specified in this section upon enabling operations in the country.
México
Reference framework: Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP). The recent reforms to the Mexican framework and the current supervisory authority will be specified in this section upon enabling operations in the country. The privacy notice in the terms required by Mexican law will be published before operating in Mexico.
13. Contact
For any question, request, or complaint about privacy: soporte@vakaland.com or the Contact. For general questions about the service there is the Help Center.