Legal
Privacy Policy
This Policy explains how Life Development LLC, doing business as Virali, handles personal information in connection with our websites and Service.
Effective date: August 25, 2026 · Version 2026.09.01
1. Scope and our privacy roles
This Privacy Policy applies when Virali determines why and how personal information is processed, such as information about website visitors, account administrators, prospective customers, and support contacts. In those contexts, Life Development LLC is the business or controller.
Customers use Virali to manage creators, influencers, team members, campaigns, contracts, content, and payouts. When Virali processes personal information in a Customer workspace on that Customer's instructions, the Customer is generally the business or controller and Virali is its service provider or processor. In that context, the Customer's privacy notice and our Data Processing Addendum govern. Individuals whose information was submitted by a Customer should ordinarily contact that Customer first.
2. Information we collect
| Category | Examples |
|---|---|
| Identifiers and contact information | Name, business email, phone number, mailing address, account and organization identifiers, social handles, and support contact details. |
| Account and authentication data | Login identifiers, authentication events, role, permissions, invitations, session data, and account status. Password credentials are handled by our authentication provider. |
| Customer workspace data | Creator and influencer records, public profile and social content data, onboarding answers, campaign and content schedules, messages, briefs, contracts, signatures, payout records, notes, and customer-defined fields. |
| Commercial and billing information | Plan, subscription status, invoices, usage, billing contact, Stripe customer or subscription identifiers, and limited transaction metadata. Payment card details are collected directly by the payment processor, not stored by Virali. |
| Integration data | Configuration, connection status, scoped credentials stored in encrypted form, provider identifiers, synchronization history, and data returned by Customer-selected integrations. |
| Device, usage, and security data | IP address, browser and device information, pages or features used, timestamps, referral URL, request and error logs, security events, audit records, and diagnostic data. |
| Communications | Support requests, feedback, survey responses, demo inquiries, and related correspondence. |
| Inferences and outputs | Creator-fit signals, campaign performance summaries, renewal indicators, generated text, and other analyses derived from Customer Data. |
The Service is not designed to receive protected health information or other regulated health data, full payment-card data, bank-account credentials, government-issued identifiers, biometric identifiers or templates, genetic data, precise geolocation, children's data, or other highly sensitive or specially regulated information. Do not submit that information unless Virali has expressly agreed in a signed order and confirmed that the applicable feature supports it. Payment-card data must be entered only into Virali's authorized payment processor.
3. Sources of information
We collect information:
- directly from you, Authorized Users, and people who submit forms;
- from Customers that upload, import, or create workspace records;
- from public websites and social platforms at a Customer's direction;
- from creator and influencer onboarding and contract workflows;
- automatically through the Service, logs, cookies, and security tools;
- from Customer-selected integrations and service providers; and
- from business partners and public business sources.
4. How we use information
We use personal information to:
- provide, operate, authenticate, maintain, and support the Service;
- create and administer accounts, workspaces, permissions, and subscriptions;
- perform Customer-directed creator, campaign, content, contract, messaging, payout, and reporting workflows;
- connect and synchronize integrations selected by Customer;
- process payments, prevent fraud, and maintain transaction records;
- monitor performance, debug errors, secure the Service, and prevent abuse;
- respond to support, privacy, and security requests;
- improve features and develop new ones using aggregated or de-identified information where practical;
- communicate about the Service, material changes, and relevant business offerings; and
- comply with law, enforce agreements, and establish or defend legal claims.
Where European data-protection law applies and Virali acts as controller, our legal bases may include performance of a contract, legitimate interests in operating and securing a business service, consent where required, and compliance with legal obligations. You may contact us for information about the legal basis for a particular processing activity.
5. How we disclose information
We may disclose personal information:
- within a Customer workspace according to its permissions and instructions;
- to hosting, database, authentication, storage, email, analytics-workflow, monitoring, support, and payment providers that process it for us;
- to Customer-selected third-party integrations at Customer's direction;
- to professional advisers under confidentiality obligations;
- to authorities or other parties when reasonably necessary for law, safety, security, or legal claims;
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate protections; and
- with your direction or consent.
Our processors are contractually restricted from using personal information for purposes other than providing services to us. A current list is included in the DPA subprocessor schedule.
6. Sale, sharing, cross-site tracking, and targeted advertising
Virali does not sell personal information for money and does not use or disclose Customer Data for cross-context behavioral advertising. We do not knowingly sell or share the personal information of anyone under 18. If our practices change, we will update this Policy and provide legally required opt-out methods before the change applies.
We do not permit third-party cross-site tracking through our websites or Service over time and across unaffiliated websites or online services for those third parties' own cross-context behavioral advertising. Service providers may process limited device and usage information for first-party analytics, hosting, security, fraud prevention, and diagnostics under instructions and restrictions that prohibit their independent use of Customer Data for targeted advertising.
8. Retention
We retain personal information only as reasonably necessary for the purposes described in this Policy, Customer instructions, and legal obligations. We use category-specific criteria rather than a single retention period, including whether the account is active, the time needed to provide the Service, security and dispute needs, legally required recordkeeping, and a valid deletion request. In particular:
- account and workspace data while the workspace is active;
- workspace and account data for the active term plus a 30-day recovery period, unless a verified erasure request requires earlier active deletion;
- customer-uploaded creator, contact, content, message, and Gmail data on the workspace schedule;
- independently collected creator leads and Virali sales leads for 12 months after the relevant last meaningful use, verification, or substantive interaction;
- support records for two years after closure, audit logs for two years, and authentication/security logs for one year;
- application logs and provider logs for 90 days after creation, distinct from the longer security, audit, incident, and fraud records;
- security-incident records for seven years after closure and fraud-investigation records for four years after closure;
- billing and tax records for seven years after the applicable fiscal year and contracts/order forms for seven years after termination;
- subscription-consent evidence for four years after termination, privacy/marketing consent evidence for four years after withdrawal or last reliance, and privacy-request and minimized deletion-receipt records for 24 months after completion.
Provider backups use a maximum rolling 30-day schedule. We may retain de-identified information that cannot reasonably be linked to an individual. Actual retention may be shorter or longer where required by law, a legal hold, security needs, or a Customer's valid instructions.
9. Security
We use reasonable administrative, technical, and organizational safeguards, including server-side authorization, tenant-aware database access and row-level security, transport encryption, authenticated encryption for supported stored integration credentials, managed secret storage, rate limiting, audit logging, provider backup capabilities, automated dependency and secret scanning, and documented incident-response procedures. These controls vary by system and provider, and no method of transmission or storage is completely secure, so we cannot guarantee absolute security. Report suspected security issues to support@tryvirali.com.
10. International transfers
Virali is based in the United States. Personal information may be processed in the United States and other countries where we or our providers operate. Those countries may have different data-protection laws. Where required, we use an applicable adequacy decision, a verified Data Privacy Framework certification where available and applicable, the European Commission's Standard Contractual Clauses, the UK Addendum, or the UK International Data Transfer Agreement, as appropriate and as described in the DPA. Virali does not promise data residency unless an executed agreement expressly provides it.
11. Privacy rights and choices
Depending on your location and our role, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a denied request.
To submit a request, email support@tryvirali.com with “Privacy Request” in the subject and identify the right you want to exercise, the email address or workspace involved, and your state or country of residence. We will acknowledge receipt, explain any verification needed, and ordinarily respond within one calendar month after receipt. Where applicable law permits an extension, we may extend by no more than two additional calendar months and will give the reason and notice by the original deadline. A verified formal erasure request targets the approved scope in active systems within 30 days after verification and may bypass the normal workspace recovery period. Provider copies and protected backups follow their documented deletion and rolling-expiration process. We may verify identity and authority before responding, and verification data is used only for that purpose. Authorized agents must provide proof of authority. If we deny a request and applicable law provides an appeal right, reply with “Privacy Appeal” in the subject within 45 days and explain why you believe the decision should be reconsidered. We will not discriminate against you for exercising a privacy right. If Virali processes the information only for a Customer, we may direct the request to that Customer or assist it under the DPA.
Individuals in the EEA may lodge a complaint with the supervisory authority applicable to them. Individuals in the United Kingdom may complain to the Information Commissioner's Office and may seek available judicial remedies. We encourage you to contact us first so we can try to address a concern, but prior contact with Virali is not required before using those rights.
12. California disclosures
The table in Section 2 describes the categories of personal information we have collected and the business purposes for which we use and disclose them. We disclose those categories to the recipients described in Section 5. We do not use sensitive personal information to infer characteristics or for purposes that require a right to limit under California law.
California residents may request to know, access, correct, or delete covered personal information and may opt out of covered sale or sharing. As stated above, Virali does not sell personal information or share it for cross-context behavioral advertising. We do not offer financial incentives for personal information. If the California Consumer Privacy Act does not apply to Virali or an exemption applies, we may respond to requests voluntarily and may not be legally required to fulfill them.
California's “Shine the Light” law permits certain requests regarding disclosure for third parties' direct-marketing purposes. Virali does not disclose personal information to third parties for their own direct marketing as contemplated by that law.
13. Children
The Service is for business users and is not directed to anyone under 18. We do not knowingly collect personal information directly from children. If you believe a child submitted information to us, contact us so we can review and delete it where appropriate. Customers must not submit children's data to the Service.
14. Changes to this Policy
We may update this Policy as our practices or laws change. We will post the updated version with a new effective date and provide additional notice of material changes where required. Prior versions may be requested by email.
15. Contact
Questions, complaints, and privacy requests may be sent to:
Life Development LLC, doing business as ViraliAttn: Privacy
801 Spring Wood St
Thousand Oaks, CA 91320
support@tryvirali.com