SLAYTES
This document is provided for informational purposes. Please consult a legal professional for specific advice.

Privacy Policy

Last updated: April 2026

1. Information We Collect

We collect the following categories of information when you use Slaytes ("the Platform"):

  • Account information: email address, display name, and profile picture.
  • Watch activity: viewing history, watch progress, likes, follows, and subscriptions.
  • Device and usage data: browser type, operating system, screen resolution, device identifiers, referring URLs, pages visited, and session duration.
  • IP-based location: approximate country and region derived from your IP address. We do not collect precise geolocation.
  • Payment information: payments are processed by Stripe. Slaytes does not store full card numbers. We receive only the information necessary to confirm transactions and manage subscriptions.
  • Communications: messages, feedback, and support requests you send to us.

2. Legal Bases for Processing

We process your personal data under the following legal bases, in accordance with applicable data protection laws including the GDPR:

  • Contract performance: providing the service, managing your account, and processing transactions.
  • Legitimate interests: improving the Platform, analytics, fraud prevention, and personalization of your experience.
  • Consent: marketing communications and optional cookies.
  • Legal obligation: tax reporting and responding to law enforcement requests.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery: operating and maintaining the Platform, authenticating users, and processing payments.
  • Personalization and recommendations: tailoring content suggestions and the browsing experience based on your viewing activity.
  • Analytics and improvement: understanding how the Platform is used so we can fix issues, develop new features, and improve overall quality.
  • Communication: sending service updates, security alerts, and opt-in marketing messages.
  • Safety and compliance: detecting and preventing fraud, abuse, and violations of our Terms of Service.
  • Creator revenue calculation: watch time data is used to calculate how subscription pool revenue is distributed to creators. This data is aggregated and is not individually identifying.

4. Third-Party Services (Data Processors)

We use the following third-party services to operate the Platform. Each acts as a data processor on our behalf:

  • Supabase: authentication, database, and storage (US-hosted).
  • Mux: video hosting, encoding, streaming, and playback analytics (US-hosted).
  • Vercel: web hosting, edge delivery, and performance monitoring (global CDN).
  • Stripe: payment processing (PCI DSS compliant).

All processors are bound by Data Processing Agreements. Data may be transferred to the United States. For users in the EEA and UK, international transfers rely on Standard Contractual Clauses (SCCs).

5. Cookies and Tracking

  • Essential cookies: login session, security tokens, and preferences. These are always active and cannot be disabled.
  • Analytics cookies: anonymous usage patterns, page views, and feature engagement. These can be disabled.
  • No advertising or tracking cookies. Slaytes does not serve ads.

You can manage cookies via your browser settings. Please note that disabling essential cookies may break core functionality of the Platform.

6. Data Retention

We retain your data according to the following schedule:

  • Account data: retained while your account is active, plus 30 days after deletion.
  • Watch history and activity: retained while your account is active and deleted with your account.
  • Viewer analytics events: retained for 90 days, then automatically purged.
  • Payment records: retained for 7 years to satisfy tax and legal requirements.
  • Support communications: retained for 2 years.
  • Anonymized and aggregated data: retained indefinitely.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request that we fix inaccurate or incomplete data.
  • Deletion: request deletion of your account and personal data, subject to applicable retention requirements.
  • Portability: request your data in a machine-readable format (JSON export).
  • Restriction: request that we limit processing of your data in certain circumstances.
  • Objection: object to processing based on legitimate interests.
  • Opt-out: unsubscribe from marketing communications at any time.

To exercise any of these rights, contact us at privacy@slaytes.com. We will respond within 30 days (GDPR: 30 days, CCPA: 45 days).

8. GDPR (EEA/UK)

If you are located in the European Economic Area or the United Kingdom, the lawful bases for processing your data are described in Section 2. International data transfers are conducted pursuant to Standard Contractual Clauses (SCCs). You have the right to lodge a complaint with your local supervisory authority if you believe your data has been processed unlawfully. Slaytes acts as the data controller for personal data collected through the Platform.

9. CCPA (California)

If you are a California resident, you have the right to know what personal information is collected about you, request deletion of your personal information, and opt out of the sale of your personal information. Slaytes does not sell personal information. We will not discriminate against you for exercising any of your CCPA rights.

10. Data Security

We implement reasonable technical and organizational measures to protect your personal data, including:

  • Encryption in transit (TLS) and at rest.
  • Access controls and least-privilege principles.
  • Regular security assessments.
  • Incident response procedures: affected users will be notified within 72 hours of a confirmed data breach.

Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.

11. International Transfers

Your data is primarily stored in the United States via Supabase and Vercel. If you are located outside the United States, your data will be transferred pursuant to Standard Contractual Clauses (SCCs) or other approved transfer mechanisms. By using the Platform, you consent to the transfer of your data to the United States.

12. Children's Privacy

The Platform is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that we have inadvertently collected such information, we will delete it promptly. Parents or guardians who believe their child has provided us with personal data may contact us at privacy@slaytes.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email or a notification on the Platform. Your continued use of the Platform after the updated policy takes effect constitutes your acceptance of the changes.

14. Contact

If you have questions about this Privacy Policy or wish to make a data protection inquiry, please contact us at privacy@slaytes.com.