Privacy Policy
Effective date: [DATE — set on publication]
[LEGAL REVIEW REQUIRED] — This Privacy Policy is a working draft. The final policy will be reviewed by qualified legal counsel and published before public launch.
This Privacy Policy explains how Stamped Limited, a company registered in England and Wales (“Stamped”, “we”, “us”), collects, uses, shares, and protects personal data when you use the Stamped platform. Stamped Limited is the data controller for the processing described here, except where stated otherwise. This policy should be read alongside our Terms of Service and Acceptable Use Policy. Capitalised terms — Platform, Deal, Buyer, Artist, Stamp — have the meanings given in Section 1 of the Terms of Service.
1. Information we collect
- Account data — your email address and authentication session records (Stamped uses passwordless magic-link sign-in; we never store a password).
- Artist profile data — display name, bio, and profile photos you upload at onboarding.
- Deal records — Deal terms, amounts (in integer cents), status history, dispute records, and Stamp metadata.
- Delivered files — audio masters and stems uploaded by the Artist for a Deal.
- Payment and identity-verification (KYC) data — collected directly by Stripe, not by us; see Section 4.
- Technical data — server logs (IP address, user agent, timestamps, request paths) collected automatically for security and debugging.
We do not collect payment card details — those go directly to Stripe.
2. How we use it, and our lawful bases
Under UK GDPR we rely on the following lawful bases:
- Performance of a contract — operating your account, running deals, facilitating payments, delivering files, administering disputes, and minting Stamps.
- Legal obligation — financial record-keeping, tax reporting, anti-fraud and sanctions compliance.
- Legitimate interests — platform security, abuse prevention, service improvement, and maintaining the integrity of the public Stamp record.
- Consent — publication of the permanent public Stamp record described in Section 3. Your consent is captured at the moment the Stamp is minted, when you complete a Deal.
We do not use your data for marketing. The only emails we send are transactional: magic-link sign-in emails and deal notifications.
3. Public Stamps — permanence
Completed Deals mint a Stamp: an immutable, public verification badge recording the Deal facts (artist names, Deal terms, completion date), rendered as a generated image. Stamps are the core product of Stamped and are permanent and public by design — they cannot be edited or deleted, and they persist after account closure. Your consent to this permanence is captured at the moment the Stamp is minted, when you complete a Deal. Delivered audio is never part of a Stamp and is never public.
4. Processors and third parties
- Supabase — database, authentication, and file storage (account data, profiles and photos, deal records, delivered audio). Processor, hosted in the United States.
- Stripe — payment processing and payouts via Stripe Connect Express. For payment facilitation Stripe acts as our processor; for identity verification (KYC) Stripe acts as an independent controller under its own privacy policy.
- Resend — sends magic-link authentication emails only. No marketing email is sent through Resend or otherwise.
- Cloudflare — DNS and network proxy; processes IP addresses and request metadata in transit.
- OpenAI — generates the Stamp badge image from deal metadata (artist names, deal facts). No audio files and no personal data beyond the deal metadata are sent to OpenAI.
- Vercel — application hosting and server logs.
We share personal data with these providers only as needed to run the platform, and with authorities where the law requires it. We do not share personal data with anyone for advertising.
5. Delivered audio files
Delivered masters and stems are private to the Deal. They are downloadable only by the Buyer and the Artist, via signed URLs that expire after one hour. Files are automatically deleted 30 days after the Deal reaches a terminal state (completed, refunded, or expired). The Stamp record itself contains no audio and is unaffected by file deletion.
6. International transfers
Stamped Limited is a UK company; most of our users and all of our infrastructure providers listed in Section 4 are in the United States. Personal data is therefore routinely transferred from the UK to the US. For these transfers we rely on appropriate safeguards — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and, where a provider is certified, the UK Extension to the EU-US Data Privacy Framework.
7. Retention
- Account and profile data — retained while your account is active; deleted or anonymised after closure except as below.
- Stamps — retained indefinitely; they are immutable public records by design.
- Payment and deal records — append-only and retained indefinitely as financial records.
- Delivered audio — deleted 30 days after the deal reaches a terminal state.
- Server logs — retained for a short rolling window for security and debugging.
8. No sale of personal data
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act as amended by the CPRA.
9. Your rights
Under UK GDPR you may request access to, correction of, deletion of, or a portable copy of your personal data; you may object to or ask us to restrict certain processing; and you may complain to the UK Information Commissioner’s Office (ico.org.uk). If you are a California resident, you have corresponding rights under the CCPA/CPRA — to know, correct, delete, and to non-discrimination for exercising them; residents of other US states with comprehensive privacy laws may have similar rights. To exercise any right, email privacy@stampedfeatures.com. We respond within one month (UK GDPR) or 45 days (CCPA), as applicable.
Erasure applies to your account and profile data: on a valid request we delete or anonymise your email address, display name, bio, and photos. It cannot extend to minted Stamps or to append-only payment records, which are retained as records of completed transactions — permanence you expressly consented to at the moment each Stamp was minted (see Sections 3 and 7).
10. Cookies
Stamped sets essential cookies only: the Supabase authentication session cookies required to keep you signed in. They are httpOnly, secure, and same-site scoped. We set no analytics, advertising, or other optional cookies, and therefore do not show a cookie consent banner.
11. Children
Stamped is not for children. You must be at least 18 to use the platform. We do not knowingly collect personal data from anyone under 18; if we learn we have, we will delete the account and its personal data (Stamps already minted are addressed case by case with counsel).
12. Security
We use appropriate technical and organisational measures: encrypted storage and transmission (HTTPS only), row-level security on all database tables, time-limited signed URLs for file access, passwordless authentication, and least-privilege access to production systems. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the ICO as required by law.
13. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or in-app before they take effect.
14. Contact
Privacy questions and data-subject requests: privacy@stampedfeatures.com. General legal: legal@stampedfeatures.com.