Skip to main content

Privacy Policy

Effective Date: July 20, 2026

1. Introduction

Welcome to VR Goals, operated by BnB Ventures LLC (“VR Goals,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our websites, applications, APIs, communications tools, and related services (collectively, the “Service”).

VR Goals serves vacation-rental operators, property managers, hospitality businesses, and related service providers. Some features allow customers to send and receive SMS, MMS, and other communications through third-party communications providers such as Telnyx.

2. Roles

VR Goals acts as the business or controller for information we collect for our own account management, billing, sales, website, support, security, fraud prevention, legal compliance, platform analytics, and service-notification purposes.

For messages sent by a VR Goals customer to that customer’s recipients, the customer generally controls the purposes, recipient lists, message content, campaign use cases, and legal basis for the messaging. In that context, VR Goals generally acts as the customer’s platform provider, communications service provider, processor, or service provider, subject to independent processing needed for security, billing, fraud prevention, legal compliance, platform administration, abuse prevention, and enforcement.

Telnyx and other communications providers may act as downstream vendors, subprocessors, independent providers, or other legally appropriate roles depending on the service, data, and regulatory context.

3. Information We Collect

3.1 Account, Contact, and Business Information

We collect account and contact information such as names, email addresses, phone numbers, company names, role, login credentials stored in protected form, support details, and organization information. For messaging registration and verification, we may collect business identity information such as legal entity names, DBAs, EINs or other business registration numbers, business addresses, websites, authorized representatives, business contacts, support contacts, and related verification materials.

3.2 Platform and Customer Content

We collect information customers and users create, upload, send, receive, or store in the Service, including goals, projects, tasks, meeting notes, workflows, integrations, API data, audit activity, and operational records. Depending on customer use, this may include reservation, property, guest, owner, employee, vendor, contractor, lead, maintenance, support, temporary door-code, access-instruction, and hospitality operations data.

3.3 Messaging Information

Messaging information may include telephone numbers, recipient telephone numbers, campaign registration information, campaign descriptions, message flows, opt-in methods, sample messages, Privacy Policy links, Terms links, support information, consent records, opt-out and suppression records, inbound communications, outbound message content, MMS attachments, message metadata, delivery receipts, error records, carrier notices, HELP requests, STOP requests, campaign status updates, number provisioning records, porting records, and abuse or compliance records.

3.4 Billing, Transaction, Device, and Security Information

We collect billing and transaction information, payment status, invoice records, plan information, support requests, login events, device and browser data, IP addresses, audit logs, API logs, webhook metadata, authentication events, security alerts, and other technical data used to provide, secure, and administer the Service.

3.5 Cookies and Similar Technologies

We use cookies and similar tracking technologies to maintain sessions, remember preferences, support security, measure site performance, and improve the Service. Essential cookies may be required for the Service to function. You can manage cookie preferences through your browser settings, but blocking essential cookies may prevent the Service from working properly.

4. How We Use Information

We use information to:

  • Provide, maintain, secure, troubleshoot, administer, and improve the Service.
  • Register brands and campaigns; provision, assign, port, or manage numbers; submit verification information; and support 10DLC, toll-free, carrier, and registry processes.
  • Send and receive SMS, MMS, and other communications; route inbound messages; record delivery and error status; apply opt-outs and suppression lists; and maintain compliance records.
  • Provide customer support, respond to inquiries, manage accounts, send service-related notices, and process billing.
  • Detect, prevent, investigate, and remediate fraud, abuse, security incidents, spam, prohibited messaging, unauthorized access, and policy violations.
  • Respond to government, carrier, registry, Telnyx, legal, regulatory, or law-enforcement requests where legally required or appropriate to protect the Service.
  • Maintain audit records and business records, enforce agreements, and comply with legal obligations.
  • Analyze aggregate or de-identified usage to improve and administer the platform.

Customer messaging data is not used by VR Goals for unrelated third-party advertising.

5. Legal Basis for Processing

Where laws such as GDPR or similar privacy laws apply, we process personal information based on consent, contract performance, legitimate interests, legal obligations, and, where applicable, the instructions of our customer acting as controller or business. Our legitimate interests include providing and improving the Service, securing the platform, preventing fraud and abuse, managing billing, supporting customers, complying with carrier and legal requirements, and enforcing our agreements.

6. How We Disclose Information

We do not sell personal information in the traditional sense. We may disclose information as necessary to provide, secure, support, and operate the Service:

  • Communications providers: Telnyx, The Campaign Registry, wireless carriers, number providers, messaging aggregators, verification providers, fraud-prevention vendors, and other communications vendors involved in registration, verification, number provisioning, message delivery, compliance, filtering, and abuse prevention.
  • Infrastructure and platform providers: Hosting, storage, database, authentication, security, logging, analytics, and operational vendors such as Supabase and other providers used to operate the Service.
  • Payment processors: Stripe or other payment processors used for subscriptions and billing.
  • Customer-selected integrations: Systems a customer connects or directs us to use, such as PMS, CRM, accounting, messaging, workflow, support, or automation platforms.
  • Professional advisers: Attorneys, accountants, auditors, insurers, and other professional advisers.
  • Authorities and compliance parties: Government, law-enforcement, regulatory, carrier, registry, or dispute-resolution authorities where legally required, permitted, or reasonably necessary to protect rights, safety, security, deliverability, or compliance.
  • Corporate transactions: Successors or participants in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law.

SMS and mobile-data limitation. Mobile information and SMS opt-in data will not be sold, rented, or shared with third parties for their own promotional or marketing purposes. We may disclose mobile information and SMS consent records to service providers, communications platforms, telephone carriers, Telnyx, The Campaign Registry, verification vendors, fraud-prevention vendors, and other vendors that help us provide, operate, register, verify, deliver, secure, and enforce the messaging service.

Any general disclosure to affiliates, advertising partners, business partners, marketing vendors, analytics providers, or similar parties excludes SMS opt-in data, SMS consent records, and mobile information from unrelated promotional or marketing use.

7. Customer Data and End-User Data

VR Goals customers control the purposes, recipients, content, and legal basis for customer-created messages. Customers are responsible for giving their recipients legally required notices, obtaining legally sufficient consent, maintaining consent evidence, and honoring opt-out and privacy rights.

Recipients of customer messages should direct customer-specific privacy requests to the customer that sent the message. VR Goals may help customers respond to valid rights requests, investigate abuse, export data, delete data, or maintain suppression records, subject to applicable law, customer instructions, and independent legal or security obligations.

8. Data Retention

We retain personal information for as long as needed to provide the Service, maintain accounts, comply with legal and carrier obligations, resolve disputes, prevent fraud and abuse, enforce agreements, maintain audit and business records, and support customer instructions. We do not set arbitrary retention periods in this Policy where operational practices still need confirmation.

Suppression records may need to be retained after account closure to prevent future unlawful messaging and honor opt-outs. Some records may remain in backups or logs for a limited period before deletion according to backup and security practices.

[BUSINESS INPUT REQUIRED] Confirm retention schedules for message content, MMS attachments, consent records, campaign and brand records, delivery logs, suppression lists, porting records, deleted-account backups, security logs, and door-code or access-message content.

9. Security

We use technical and organizational safeguards designed to protect personal information, including controls appropriate for account data, EIN and business verification data, API credentials, telephone numbers, message content, consent evidence, guest and reservation information, door codes and access instructions, tenant separation, role-based access, audit logging, encryption, vendor access, and incident response.

  • Encryption of data in transit and, where implemented for the relevant system, data at rest.
  • Role-based access controls and authentication mechanisms.
  • Tenant-aware access restrictions and operational separation controls.
  • Logging, monitoring, and audit history for security and compliance-relevant activity.
  • Vendor access restrictions and review of subprocessors appropriate to the service.
  • Incident-response procedures for suspected security events.

No method of transmission or storage is 100% secure. We do not claim security certifications, insurance coverage, or specific technical controls unless separately stated in a signed agreement or current security documentation.

[BUSINESS INPUT REQUIRED] Confirm current encryption-at-rest coverage, audit-log scope, RBAC model, tenant separation controls, incident-response process, vendor access process, and whether any security certifications or cyber-insurance statements may be published.

10. International Data Transfers

Information may be processed in the United States and other countries where we or our service providers operate. Where required, we rely on legally recognized transfer mechanisms such as Standard Contractual Clauses, adequacy decisions, approved frameworks, contractual protections, or other safeguards available under applicable law.

11. Privacy Rights

Depending on your location and relationship with VR Goals, you may have rights to request access, correction, deletion, portability, restriction, objection, appeal, or withdrawal of consent. California and other U.S. state privacy laws may also provide rights to know, delete, correct, opt out of certain sales or sharing, limit certain sensitive personal information uses, and non-discrimination.

To exercise rights for information VR Goals controls directly, contact [email protected]. If your request relates to messages or data controlled by a VR Goals customer, we may direct you to that customer or assist the customer in responding.

12. Marketing Choices

You may opt out of VR Goals marketing emails by using the unsubscribe link in the email. You may opt out of VR Goals SMS programs as described in the VR Goals Messaging and SMS Terms. Customer messaging programs are controlled by the customer that sent the message.

13. Children’s Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16 through the Service. If you believe we may have collected such information, contact us at [email protected].

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy with a new effective date and, where appropriate, by sending a notification.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

16. Effective Date

This Privacy Policy is effective as of July 20, 2026.