ugcera.com – Privacy & Compliance Documentation

ugcera.com – Privacy & Compliance Documentation

Last updated: 16 August 2025

This page contains the complete, publication-ready privacy framework for ugcera.com. Replace [TO CONFIRM] placeholders with your specifics before publishing.

Main Privacy Policy (Global)

A. Introduction

We are [Company Legal Name, Inc./Ltd], registered at [Full Address]. We operate the ugcera.com website, creator/brand dashboards, APIs, and any mobile applications (collectively, the “Service”). This policy applies to creators, brands/agencies, visitors, and other users.

Effective date: 16 August 2025. We will post future changes here and provide in-product/email notices where changes are material.

B. What We Collect

1) Data you provide directly

  • Account details: name, username, email, hashed password, phone number [TO CONFIRM], two-factor settings.
  • Profile: bio, profile photo, links/handles, categories/skills/tags, location (if provided), rates [TO CONFIRM].
  • Communications: messages/chats, comments, support tickets, survey responses.
  • UGC uploads: text, images, videos, audio, captions, edit history, and metadata that may include personal data about you or others.
  • Payments: handled by [Payment provider(s) – e.g., Stripe, Adyen]. We receive tokens, status, last-4, brand, payout info, invoices, and tax/reconciliation data. We do not store raw card numbers.
  • Verification/KYC (if used): ID documents, selfies/biometrics [TO CONFIRM], proof-of-address, sanctions/PEP screening results via [Identity/KYC provider(s)].

2) Data collected automatically

  • Device and browser data (type, version, OS), IP address, language, time zone, user agent.
  • Identifiers (cookies/SDK IDs), session telemetry, performance/error logs.
  • Approximate location (derived from IP), time-on-page, referrers.
  • Fraud/abuse indicators (rate limits, velocity, header anomalies, reputation signals).

3) Data from third parties

  • Social/SSO (if enabled): ID, email, profile info subject to your settings [TO CONFIRM which providers].
  • Agencies/brands/partners providing creator details to manage campaigns.
  • Anti-fraud vendors, trust & safety lists, and public sources.

4) Special/Sensitive data

We do not intentionally collect special category data (e.g., health, political opinions, precise geolocation, biometric templates) unless strictly necessary for [TO CONFIRM purpose] and permitted by law. If required, we will obtain explicit consent and apply enhanced safeguards.

C. Why & How We Use Data (Purposes → Lawful Bases)

PurposeExamplesEU/UK Lawful BasisUS Business Purpose
Account provisioning & service delivery Register/login, profiles, workspaces, brief distribution, UGC hosting Contract performance; Legitimate interests for support Provide services; Customer service
Content moderation & platform safety Automated and human review; spam/fraud detection; abuse controls Legitimate interests; Legal obligation Security; Fraud prevention
Payments, invoicing, tax compliance Payouts to creators; invoices; chargebacks; 1099/IRS/VAT records [TO CONFIRM] Legal obligation; Contract performance Transactions; Compliance
Security & incident response Access controls, logging, anomaly detection, incident handling Legitimate interests; Legal obligation Security
Analytics & product improvement Usage metrics, funnel analysis, A/B tests Legitimate interests; Consent where required (e.g., EEA cookies) Analytics
Personalized recommendations/ads (if any) Content/creator suggestions; limited ad personalization [TO CONFIRM] Consent in EEA/UK; Legitimate interests where permitted Advertising/marketing
Legal obligations & record keeping Contracts, accounting, sanctions checks, law enforcement requests Legal obligation Compliance
Defending legal claims & enforcing terms Preserving evidence, investigating misuse Legitimate interests (balance test applied) Legal defense

D. Cookies & Tracking (Summary)

We use cookies/SDKs for strictly necessary functions, functionality, analytics, advertising, and fraud prevention. You can manage preferences in our Cookie Center and via your browser. We honor Global Privacy Control (GPC) signals where required. See the Cookie Policy for details.

E. Sharing & Disclosure

  • Service providers/sub-processors: hosting, payments, analytics, support, fraud prevention, AI moderation. See Annex B.
  • Advertising/analytics vendors: limited identifiers and events, subject to your settings/consent.
  • Corporate transactions: in M&A, financing, or sale, data may transfer with notice as required.
  • Legal and safety: to comply with law or protect rights, users, or the public.
  • User-public UGC: Some UGC may be visible to others (e.g., profiles/portfolios) [TO CONFIRM public scope]. Do not post others’ personal data without permission.

US state laws: We do not sell personal information for money. Some disclosures (e.g., cross-context behavioral advertising) may be considered “sale”/“sharing.” See Do Not Sell or Share to opt out.

F. International Transfers

Data may be stored/processed in [Hosting regions & backup locations] with [Regions/Cloud Provider]. Where transfers occur across borders, we rely on EU/UK Standard Contractual Clauses, the EU–US Data Privacy Framework/UK Extension (if applicable) [TO CONFIRM], and supplementary measures (encryption, access controls, minimization).

G. Security

We use layered administrative, technical, and physical safeguards (see Annex C). While these measures reduce risk, no method of transmission or storage is completely secure.

H. Data Retention

We retain data only as long as needed for the purposes in this policy and legal requirements. See the Data Retention Schedule. We may extend retention to establish, exercise, or defend legal claims, or to comply with tax/financial regulations.

I. Your Rights & Choices

  • EEA/UK: access, rectification, erasure, restriction, portability, and objection. You may withdraw consent at any time.
  • US states: know/access, delete, correct, opt-out of sale/sharing/targeted advertising, limit use of sensitive personal information, and appeal denials where provided by law.
  • All users: manage cookies; unsubscribe from marketing; adjust in-product settings (where available).

How to submit: use our webform [TO CONFIRM URL] or email privacy@ugcera.com. See DSR/DSAR Procedure.

J. Automated Decision-Making & Profiling

We use automated tools for fraud/spam detection and content/creator recommendations. Outcomes may affect visibility of content or access to certain features (e.g., anti-abuse rate limits). You can request human review where required by law. See Annex D.

K. Creator/Brand-Specific Notices

  • UGC rules: Upload only content you have rights to. Obtain releases/consents for any personal data of others. Remove personal data of others upon request unless an exemption applies.
  • Roles: We are a controller for our platform services. For brand-managed workspaces/campaigns where we process data on a customer’s instructions, we act as a processor under the Data Processing Addendum (DPA) (includes SCCs/UK Addendum).
  • Notice & action for privacy takedowns: We review requests alleging UGC contains personal data without a lawful basis and may remove, restrict, or seek counter-notice as appropriate.

L. Children & Teens

Minimum age: [Minimum age]. We do not knowingly allow children under this age to use the Service. Teen experiences (if any) follow applicable laws (e.g., UK Children’s Code, EU/US rules). We avoid targeted advertising to teens without required consent. Parents/guardians may exercise rights on behalf of minors.

M. Payments & Financial Data

Payments are processed by [Payment provider(s)] under their PCI-DSS compliance. We store payment tokens, payouts, invoices, and tax data. We do not collect or store full card numbers or CVC codes.

N. Communications & Marketing

  • Transactional: service, security, account notices (cannot opt out).
  • Marketing: opt-in where required (EEA/UK); opt-out anytime elsewhere. Use unsubscribe links or account settings.
  • SMS (if used): consent required; message/data rates may apply [TO CONFIRM].

The Service may link to third-party sites, SDKs, or embeds. Their privacy practices apply to those properties. Review their policies.

P. Changes to this Policy

We will update this page and provide clear notice for material changes (e.g., email or in-product banners), including an effective date and a changelog. See Version History.

Q. Contact & Complaints

Email: privacy@ugcera.com

DPO/Privacy Officer: [Name / “Not applicable”]. EU Rep (Art. 27): [Name/Entity]. UK Rep (Art. 27): [Name/Entity].

EEA/UK users may complain to their local supervisory authority, e.g., ICO (UK) or your EU authority. We encourage you to contact us first.