Privacy Policy
Effective date: [EFFECTIVE DATE, e.g. August 1, 2026]
This Privacy Policy explains what personal data [COMPANY LEGAL NAME, e.g. Example Media LLC] (“we,” “us,” “our”) collects when you use [https://www.example.com] (the “Site”), how and why we use it, who we share it with, how long we keep it, and the choices and rights you have. Because of the nature of the Site, we treat the fact that you are a member as sensitive information, and we design for minimal data collection. This policy is accessible without logging in or making a payment.
1. Data we collect
- Account data: your email address and a hashed password. We do not require your real name to create an account.
- Billing data: payments are handled by our payment services provider. We receive your subscription status, transaction identifiers, amounts, currency, approximate location/country derived from the transaction, and the email used at checkout — never your full card number, which is collected and stored by the processor, not by us.
- Usage and device data: server logs including IP address, user agent, and pages requested, retained for security and fraud prevention; and strictly necessary session cookies that keep you logged in.
- Communications: messages you send to support and our replies.
We do not knowingly collect any special-category data beyond what is inherent in membership itself, and we ask that you not send us additional sensitive information.
2. Cookies and similar technologies
We use only strictly necessary cookies — chiefly a session cookie that keeps you signed in and a cookie that helps protect against fraud and abuse. We do not use advertising cookies, third-party marketing trackers, or cross-site tracking, and we use privacy-preserving, cookieless analytics that do not identify you or follow you across other sites. Because we set only essential cookies, no consent banner is required; you can still block cookies in your browser, though the Site may not work if you block the session cookie. We do not respond differently to “Do Not Track” signals because we do not track you across sites in the first place.
3. How we use data, and our legal bases
- Providing, maintaining, and securing your membership — to perform our contract with you.
- Processing payments, renewals, refunds, and chargebacks through our processor — to perform our contract and to comply with legal and financial-record obligations.
- Preventing fraud and abuse, enforcing our Terms, and establishing or defending legal claims — our legitimate interests and, where applicable, legal obligations.
- Sending transactional messages such as receipts, renewal notices, password resets, and material changes to our policies — to perform our contract. We do not send marketing email without your separate opt-in consent, which you can withdraw at any time.
4. Who we share data with
- Payment processing: our payment services provider, which acts as an independent controller of the checkout and card data you provide to it and processes that data under its own privacy policy.
- Infrastructure: our hosting and content-delivery providers, which act as our processors under contract and may process data only on our instructions.
- Fraud and chargeback prevention: services used by us and the card networks to prevent and contest fraudulent transactions.
- Legal and safety: authorities or others where required by law, court order, or to protect our rights, safety, or property. We may transfer data as part of a merger, acquisition, or sale of assets.
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We never rent or trade member lists.
5. International transfers
We and our providers may process data in countries other than yours, including outside the EEA and UK. Where we transfer personal data across borders, we rely on an appropriate safeguard such as an adequacy decision or the applicable Standard Contractual Clauses, and we take steps to ensure your data remains protected.
6. Retention
We keep account data while your account exists and delete or anonymize it within 30 days after account deletion, except: transaction records, which we retain as required for tax, accounting, and chargeback-defense purposes (typically several years); records required by law, including under 18 U.S.C. 2257 where applicable; and server logs, which we retain for no more than 90 days.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent. To exercise any of these rights, email [support@example.com]. We verify requests using your account email and respond within the period required by law. You will not be treated differently for exercising your rights.
EEA and UK residents: our legal bases are described in Section 3, and you may lodge a complaint with your local data-protection authority.
California and other US state residents: the categories of personal information we collect are identifiers (email), commercial information (transaction records), and internet/network activity (logs), as detailed in Section 1; we collect them for the purposes in Section 3 and disclose them to the service providers in Section 4. We do not sell or share personal information as those terms are defined under California and other state privacy laws. You may request access to or deletion of your information, and, where your state provides it, you may appeal a decision by replying to our response or emailing [support@example.com]. You may use an authorized agent to submit a request, subject to our verification.
8. Children
The Site is strictly for adults. We do not permit anyone under 18 to use the Site and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a minor, we will delete it and terminate the account.
9. Security and breach notification
All traffic is encrypted in transit (TLS). Passwords and session tokens are stored only as salted hashes. Access to production data is restricted, logged, and limited to what is necessary to run the Service. No system is perfectly secure, but if a breach affecting your personal data occurs, we will notify affected users and the relevant authorities as required by law.
10. Automated decisions
We use automated checks to help detect fraud and abuse. These do not produce legal or similarly significant effects about you without human review; where such a decision would, you may request human review by contacting [support@example.com].
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced on the Site or by email, and the “Effective date” above will be updated.
12. Contact
Data controller: [COMPANY LEGAL NAME, e.g. Example Media LLC], [REGISTERED BUSINESS ADDRESS]. Privacy contact: [support@example.com] · [SUPPORT PHONE, e.g. +1 (555) 000-0000]. See also our Terms of Service.