๐Ÿ“„ Legal

Follow'd Privacy Policy

Effective Date: March 23, 2025  ยท  Last Updated: March 23, 2025

Our Commitment: We built Followd to connect Creators and Fans. We collect only what we need, we don't sell your personal information to third parties for their marketing, and we give you real controls over your data. This policy explains what we collect, why, who we share it with, and how you can manage it.

SECTION 1 โ€” SCOPE AND CHANGES TO THIS POLICY

1.1 Who We Are

This Privacy Policy is published by Followd, Inc., a Delaware corporation ("Followd," "we," "our," or "us"). Followd is the data controller for the personal information described in this Policy. Our principal place of business is [โ—], [City], [State]. Questions about this Policy may be directed to privacy@followd.com.

1.2 What This Policy Covers

This Privacy Policy applies to personal information collected through followd.com, our mobile applications, APIs, and any other services or features that link to this Policy (collectively, the "Platform"). It does not apply to third-party websites, payment processors, shipping providers, or other services linked from the Platform โ€” those services have their own privacy policies.

1.3 Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will: (a) update the "Last Updated" date at the top of this page; (b) post a prominent notice on the Platform; and (c) for registered Users, send a notification to the email address associated with your account. Material changes take effect 30 days after notice is provided for existing Users, and immediately for new Users. Your continued use of the Platform after the effective date constitutes your acceptance of the updated Policy.

SECTION 2 โ€” INFORMATION WE COLLECT

2.1 Information You Provide Directly

We collect information you give us when you:

Account Registration

Creator Verification

Content and Transactions

Communications

2.2 Information We Collect Automatically

When you access or use the Platform, we automatically collect:

Device and Connection Information

Usage and Activity Data

Transaction Metadata

2.3 Information from Third Parties

SECTION 3 โ€” COOKIES AND TRACKING TECHNOLOGIES

3.1 Technologies We Use

We and our third-party partners use the following technologies to collect information about your use of the Platform:

3.2 Categories of Cookies

Category Purpose Can You Opt Out?
Strictly Necessary Authentication, security, fraud prevention, and core Platform functionality. Without these, the Platform cannot function. No โ€” required for the Platform to operate.
Functional Remembering your preferences, language settings, and login state. Yes โ€” via browser settings, though some features may be affected.
Analytics & Performance Understanding how Users navigate the Platform, measuring feature usage, and improving performance. Yes โ€” via our Cookie Preferences center or browser opt-out tools.
Advertising & Targeting Serving relevant Followd advertisements on third-party platforms and measuring campaign effectiveness. Yes โ€” via our Cookie Preferences center, NAI/DAA opt-out tools, or platform-specific ad settings.

3.3 Third-Party Analytics and Advertising

We use third-party analytics services including Google Analytics, and may use advertising platforms including Meta, Google, TikTok, and others to serve Followd advertisements. These providers may collect information about your activity across different websites and apps. We share only the minimum data necessary for these purposes and do not share sensitive Creator or Fan transaction data with advertising platforms.

You can opt out of personalized advertising from Google at adssettings.google.com, from Meta at facebook.com/settings/?tab=ads, and from other participating companies via the Digital Advertising Alliance (optout.aboutads.info) or Network Advertising Initiative (optout.networkadvertising.org).

3.4 Do Not Track

Some browsers send "Do Not Track" (DNT) signals to websites. Because there is no industry consensus on how to respond to DNT signals, we do not currently alter our data practices based on DNT signals, except where required by applicable law (such as the Global Privacy Control honored in applicable jurisdictions).

SECTION 4 โ€” HOW WE USE YOUR INFORMATION

4.1 Platform Operations and Service Delivery

4.2 Safety, Security, and Fraud Prevention

4.3 Communications

4.4 Platform Improvement and Research

4.6 Business Operations

SECTION 5 โ€” HOW WE SHARE YOUR INFORMATION

We do not sell your personal information to third parties for their own marketing purposes. Sharing is limited to what is necessary to operate the Platform, as described below.

5.1 Service Providers

We share personal information with third-party vendors who perform services on our behalf, including:

Service providers are contractually prohibited from using your information for their own purposes beyond the scope of services they provide to Followd.

5.2 Creator-Fan Transactions

We may disclose personal information when we have a good-faith belief that disclosure is required by or permitted under applicable law, including: (a) in response to a valid subpoena, court order, or other legal process; (b) to comply with applicable law or regulation; (c) to protect the rights, property, or safety of Followd, our Users, or the public; or (d) to detect, prevent, or address fraud, security, or technical issues. Where legally permissible, we will notify affected Users before disclosing their information in response to a legal request.

5.4 Business Transfers

If Followd is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of its assets, your personal information may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on the Platform prior to any such transfer and any change in how your information is used.

We may share your personal information with third parties in other circumstances when you have given us your informed, specific consent to do so (e.g., if you authorize a third-party integration or participate in a co-sponsored promotion).

5.6 Aggregated and De-Identified Data

We may share aggregated or de-identified information (which cannot reasonably be used to identify you) with third parties for research, analytics, industry reporting, or other purposes. We take reasonable technical and organizational measures to prevent re-identification of de-identified data.

SECTION 6 โ€” CREATOR-SPECIFIC DATA PRACTICES

6.1 What We Collect from Creators

In addition to the data described in Section 2, we collect from Creators: identity verification documents and results, tax identification information, banking and payout details, earnings and payout history, Creator Content metadata (upload timestamps, view counts, engagement metrics), Custom Request history, and Physical Goods inventory and fulfillment data.

6.2 Creator Analytics Dashboard

Creators have access to analytics about their own account, including subscriber counts, revenue by content type, Fan engagement rates, and payout history. This dashboard data is derived from Fan activity on your content but is aggregated in a way that does not individually identify specific Fans unless a Fan has consented to being identified (e.g., through public tipping or Custom Request attribution).

6.3 Creator Responsibility for Fan Data

Creators receive limited personal information about their Fans (e.g., usernames, subscription status, and order details) in connection with delivering their services. Creators must: (a) use Fan data only for the purpose of providing the subscribed content, benefits, or products; (b) not contact Fans outside the Platform using information received through the Platform; (c) not sell or share Fan data with any third party; and (d) comply with all applicable data protection laws, including as a potential data controller in their own right for any Fan personal information they process independently. Creators who use agents or management companies to operate their accounts remain personally responsible for how Fan data is handled by those agents.

6.4 Identity Verification Data

Government-issued ID and selfie data submitted during Creator verification is processed by our identity verification partner, which acts as an independent data controller for this data under its own privacy policy. Followd receives only the verification outcome (e.g., "verified" or "failed") and does not retain raw copies of your ID documents on our own systems beyond what is required by applicable law.

6.5 Tax Data

Tax identification information (e.g., Social Security Number or EIN) is collected for IRS compliance purposes and is transmitted to our tax reporting partner in encrypted form. This data is retained for as long as required by applicable tax law (typically seven years in the U.S.).

SECTION 7 โ€” FAN-SPECIFIC DATA PRACTICES

7.1 What We Collect from Fans

In addition to the data described in Section 2, we collect from Fans: subscription history (which creators you follow and subscribe to), purchase history (content purchased, Custom Requests submitted, Physical Goods ordered), tip history, payment method metadata (last four digits, card type, billing postal code โ€” full card data goes to our Payment Processor), and shipping addresses for Physical Goods orders.

7.2 Subscription and Purchase Data Shared with Creators

When you subscribe to or purchase from a Creator, we share your username and subscription/purchase details with that Creator. We do not share your email address, full legal name, payment card details, or other sensitive identifiers with Creators by default. If you voluntarily include personal information in Custom Request instructions or messages, that information is shared with the Creator as part of fulfilling the request.

7.3 Shipping Address for Physical Goods

When you purchase Physical Goods, your shipping name and address are shared with the Creator and any third-party shipping carrier involved in delivery. After delivery is confirmed, we retain shipping addresses only as long as needed for return/dispute resolution and applicable legal obligations.

7.4 Recommendation and Personalization

We use your subscription history, content views, and engagement patterns to personalize your experience on the Platform โ€” including creator recommendations, featured content, and search results. You can influence these recommendations through your account settings. We do not use sensitive categories of personal information (such as inferred health or political views) to personalize your experience.

SECTION 8 โ€” DATA RETENTION

Data Category Retention Period Reason
Account profile and login data Duration of account + 30 days post-deletion (then deleted or anonymized) Account functionality; fraud prevention
Transaction and payment records 7 years from transaction date Tax, accounting, and legal compliance
Creator identity verification data Duration of Creator relationship + 5 years Legal and regulatory compliance; dispute resolution
Tax information (TIN, W-9, W-8) 7 years from last tax filing year IRS requirements
Creator Content (uploaded files) Until Creator deletes or account is closed, then 90 days for backup purge Service delivery; Fan access to purchased content
Direct messages and communications Duration of account + 90 days post-deletion Service delivery; Trust & Safety
Usage and analytics data 24 months (aggregated/anonymized indefinitely) Platform improvement
Fraud and security logs 3 years Fraud prevention; legal defense
Shipping addresses (Physical Goods) 90 days post-delivery (unless dispute is pending) Returns and dispute resolution
Law enforcement hold data As required by legal process Legal obligation

When you delete your account, we begin the deletion process within 30 days. Some data may be retained longer where required by law, ongoing legal proceedings, unresolved disputes, or active fraud investigations. Deleted account data is not recoverable after the retention period expires.

SECTION 9 โ€” DATA SECURITY

9.1 Our Security Measures

Followd implements commercially reasonable administrative, technical, and physical safeguards to protect your personal information, including:

9.2 Your Responsibilities

No security system is impenetrable. You are responsible for: (a) maintaining the confidentiality of your account credentials; (b) logging out of your account on shared devices; (c) enabling two-factor authentication (available in your account settings, strongly recommended); and (d) promptly notifying us at security@followd.com if you suspect unauthorized access to your account.

9.3 Data Breach Notification

In the event of a data breach that is reasonably likely to result in risk to your rights and freedoms, we will notify you and applicable regulators as required by applicable law. We will provide notice via email and/or in-Platform notification and will include information about what happened, what data was affected, steps we are taking, and what you can do to protect yourself.

SECTION 10 โ€” CHILDREN'S PRIVACY

The Platform is intended solely for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal information from a person under 18, we will take immediate steps to delete that information and terminate the associated account.

If you are a parent or guardian and believe we may have collected personal information from your child under 18, please contact us immediately at privacy@followd.com with the subject line "Child Account Report." We will investigate and respond promptly.

Followd does not direct any marketing to children, does not knowingly allow minors to register, and uses age verification tools as part of Creator onboarding to help enforce this requirement.

SECTION 11 โ€” YOUR PRIVACY CHOICES AND RIGHTS

11.1 Account Information

You may access, review, and update most of your account information directly through your account settings at followd.com/settings. To correct information you cannot update yourself, or to close your account, contact privacy@followd.com.

11.2 Marketing Communications

You may opt out of marketing emails at any time by clicking the "Unsubscribe" link in any marketing email. You may opt out of marketing SMS by replying STOP to any SMS message from us. You may adjust push notification preferences in your device settings. Opting out of marketing does not affect transactional communications (receipts, security alerts, payout notifications) which are necessary for the Platform to function.

11.3 Cookies and Tracking

You can manage cookie preferences through our Cookie Preferences center (accessible from the footer of followd.com) or through your browser's privacy settings. Blocking certain cookies may affect Platform functionality. For mobile advertising opt-outs, use your device's "Limit Ad Tracking" (iOS) or "Opt out of Ads Personalization" (Android) setting.

11.4 Data Portability

You may request a copy of the personal information we hold about you in a portable format by submitting a request through your account settings or by emailing privacy@followd.com. We will respond within 45 days.

11.5 Account Deletion

You may request deletion of your account and associated personal information through your account settings or by contacting privacy@followd.com. Deletion is subject to our retention obligations described in Section 8. Note that some information (such as transaction records) must be retained for legal and regulatory compliance even after account deletion.

11.6 Objection to Processing

Where we process your personal information based on our legitimate interests, you may object to that processing. We will honor your objection unless we have compelling legitimate grounds that override your interests or where processing is necessary for legal claims. To exercise this right, contact privacy@followd.com.

SECTION 12 โ€” CALIFORNIA RESIDENTS โ€” CCPA/CPRA

This Section applies to California residents. It provides disclosures and rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

12.1 Categories of Personal Information Collected

In the last 12 months, we have collected the following categories of personal information (as defined under CCPA):

CCPA Category Examples Disclosed to Third Parties?
Identifiers Name, email, username, IP address, device ID, account ID Yes โ€” service providers, payment processors, legal/regulatory
Personal info (Cal. Civ. Code ยง 1798.80(e)) Name, address, payment card last-four, tax ID (Creators) Yes โ€” service providers, payment processors, tax partners
Commercial information Purchase history, subscription history, transaction amounts Yes โ€” service providers, Creators (limited)
Internet/electronic activity Platform usage, pages viewed, clicks, session duration Yes โ€” analytics providers, advertising platforms
Geolocation (approximate) Country and city derived from IP address Yes โ€” analytics providers
Biometric (Creator verification) Selfie matching during ID verification (processed by verification partner) Verification partner only; outcome shared with Followd
Professional/financial (Creators) Bank account info, payout history, tax ID Payment processors, tax reporting partners
Inferences Content preferences, creator affinity, engagement patterns Not shared with third parties for their use

12.2 Do We Sell or Share Personal Information?

We do not sell personal information for monetary compensation. We may share certain information (such as cookie identifiers and usage data) with advertising platforms for purposes of serving targeted Followd advertisements, which may constitute "sharing" under CPRA. California residents have the right to opt out of this sharing. To opt out, use our Cookie Preferences center, click "My Privacy Choices" in the footer of our website, or submit a request to privacy@followd.com with the subject line "CPRA Opt-Out โ€“ Do Not Share."

12.3 Sensitive Personal Information

We collect the following categories of Sensitive Personal Information (as defined by CPRA): government ID and biometric data (for Creator verification), financial account data (for Creator payouts), and SSN/TIN (for tax reporting). We use this information only as necessary to operate the Platform and comply with legal obligations โ€” we do not use or disclose Sensitive Personal Information for purposes other than those specified by CPRA ยง 1798.121.

12.4 Your California Rights

California residents have the right to:

12.5 How to Submit a California Request

Submit a verifiable consumer request by: (a) emailing privacy@followd.com with the subject line "California Privacy Request"; or (b) using the in-app Privacy Request tool in your account settings. We will verify your identity before processing requests. We respond to verifiable requests within 45 days (with a possible 45-day extension for complex requests, with notice). Authorized agents may submit requests on your behalf with appropriate power-of-attorney documentation.

12.6 Retention of Personal Information

We retain personal information for the periods described in Section 8. We do not retain personal information longer than reasonably necessary for the disclosed purpose.

SECTION 13 โ€” VIRGINIA, COLORADO, CONNECTICUT, AND OTHER U.S. STATE RIGHTS

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon, Montana, and other U.S. states with comprehensive consumer privacy laws have rights substantially similar to those described in Section 12, including rights to access, correct, delete, and opt out of targeted advertising and profiling. To exercise any such right, submit a request to privacy@followd.com with your state of residence and the right you wish to exercise. We will respond in accordance with applicable law (typically within 45 days). You may appeal a denial by emailing privacy@followd.com with the subject line "Privacy Request Appeal."

SECTION 14 โ€” NEVADA RESIDENTS

Followd does not currently sell covered information as defined by Nevada Revised Statutes Chapter 603A. Nevada residents may submit an opt-out request for any future sale by emailing privacy@followd.com with the subject line "Nevada Opt-Out." We will honor such requests consistent with Nevada law.

SECTION 15 โ€” EEA AND UK USERS โ€” GDPR

This Section applies if you are located in the European Economic Area (EEA) or the United Kingdom (UK). Followd, Inc. is the data controller. We process your personal data in compliance with the GDPR (EU) 2016/679 and the UK GDPR.

We process your personal data on the following legal bases:

Processing Purpose Legal Basis (GDPR Article)
Account creation, authentication, and core Platform delivery Performance of a contract (Art. 6(1)(b))
Processing subscriptions, purchases, and payouts Performance of a contract (Art. 6(1)(b))
Fraud detection and Platform security Legitimate interests (Art. 6(1)(f)) โ€” ensuring platform integrity
Analytics and Platform improvement Legitimate interests (Art. 6(1)(f)) โ€” improving our services
Marketing communications (where opted in) Consent (Art. 6(1)(a)) โ€” withdrawable at any time
Cookie-based advertising (non-essential cookies) Consent (Art. 6(1)(a))
Tax reporting and financial record-keeping Legal obligation (Art. 6(1)(c))
Creator identity verification Legal obligation (Art. 6(1)(c)) / Legitimate interests (Art. 6(1)(f))
Biometric processing for verification Explicit consent (Art. 9(2)(a)) โ€” collected during onboarding
Responding to legal requests from authorities Legal obligation (Art. 6(1)(c))

15.2 Your Rights Under GDPR

If you are in the EEA or UK, you have the following rights:

To exercise any of these rights, contact privacy@followd.com. We will respond within 30 days (with a possible 60-day extension for complex requests, with notice). We may require identity verification before processing your request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

15.3 EEA and UK Representative

[Followd will appoint an EEA representative (required under GDPR Art. 27) and a UK representative prior to accepting Users from these jurisdictions. Their contact details will be inserted here upon appointment.]

SECTION 16 โ€” INTERNATIONAL DATA TRANSFERS

Followd is based in the United States. Your personal information is collected, processed, and stored on servers located in the United States. If you access the Platform from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your home country.

For transfers of personal data from the EEA or UK to the United States (or other third countries), we rely on the following transfer mechanisms as applicable: (a) Standard Contractual Clauses (SCCs) as approved by the European Commission; (b) the EU-U.S. Data Privacy Framework (to the extent certified); or (c) your explicit consent where required. Copies of applicable transfer mechanisms are available upon request by contacting privacy@followd.com.

For transfers from other jurisdictions, we implement appropriate safeguards consistent with applicable law.

SECTION 17 โ€” CONTACT US / DATA PROTECTION INQUIRIES

17.1 How to Contact Us

For questions about this Privacy Policy or our data practices, to exercise your privacy rights, or to report a privacy concern:

Followd, Inc.

Attn: Privacy Team

Email: privacy@followd.com

Mail: [Physical Address โ€” to be inserted upon incorporation]

For security incidents or suspected unauthorized access to your account, contact: security@followd.com

For DMCA / copyright notices: legal@followd.com

For Trust & Safety issues: trust@followd.com

17.2 Data Protection Officer

Followd will designate a Data Protection Officer (DPO) prior to accepting Users from the EEA or UK. The DPO's contact information will be provided here upon designation. Until then, all privacy inquiries should be directed to privacy@followd.com.

17.3 Supervisory Authority Complaints

EEA and UK residents who are unsatisfied with our response to a privacy inquiry have the right to lodge a complaint with the data protection supervisory authority in their country of residence or place of work. A list of EEA supervisory authorities is available at edpb.europa.eu. The UK supervisory authority is the Information Commissioner's Office (ico.org.uk).

โ€” End of Privacy Policy โ€”

Followd, Inc. | followd.com | privacy@followd.com

ยฉ 2025 Followd, Inc. All rights reserved.