Policies

YOUR RIGHTS REGARDING PERSONAL DATA

You have certain rights regarding the collection and processing of personal data. You may exercise these rights, to the extent they apply to you, by contacting us at the information provided at the end of this Privacy Notice, or by following instructions provided in this Privacy Notice or in communications sent to you.

Your rights vary depending on the laws that apply to you, but may include:

  • The right to know whether, and for what purposes, we process your personal data;
  • The right to be informed about the personal data we collect and/or process about you;
  • The right to learn the source of personal data about you we process;
  • The right to access, modify, and correct personal data about you (see the “Accessing, Modifying, Rectifying, and Correcting Collected Personal Data” section below for more information);
  • The right to know with whom we have shared your personal data with, for what purposes, and what personal data has been shared (including whether personal data was disclosed to third parties for their own direct marketing purposes);
  • The right to withdraw your consent, where processing of personal data is based on your consent; and
  • The right to lodge a complaint with a supervisory authority located in the jurisdiction of your habitual residence, place of work, or where an alleged violation of law occurred.

Personal Data We Share

In the past twelve (6) months, we shared with the following categories of third parties the following categories of personal data for a business purpose:

  • Identifiers (e.g. name, address, email address, phone number, IP address): Service providers.
  • Identifiers (e.g. account name): Other Creators and Fans.
  • Personal information categories listed in the Kenya Information and communication act (e.g. government ID, bank account numbers): Service providers.
  • Audio, electronic, visual, thermal, olfactory, or similar information (e.g. content you create): Service providers.

YOUR CHOICES

You have choices about certain information we collect about you, how we communicate with you, and how we process certain personal data. When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services. In addition, it is possible to change your browser settings to block the automatic collection of certain information.

a. Communications Opt-Out. You may opt-out of receiving email communications from us at any time by following the opt-out link or other unsubscribe instructions provided in any email message received, by contacting us as provided at the end of this Privacy Notice, or by changing your notification preferences in account setting. you wish to opt-out by sending us an email to the address provided below, please include “Opt-out” in the email’s subject line and include your name and the email address you used to sign up for communications in the body of the email. Note, that if you do business with us in the future, you may not, subject to applicable law, opt-out of certain automated notifications, such as order or subscription confirmations, based on business transactions (e.g., e-commerce).

b. Location Information. If you want to limit or prevent our ability to receive location information from you, you can deny or remove the permission for certain Services to access location information or deactivate location services on your device. Please refer to your device manufacturer or operating system instructions for instructions on how to do this.

c. Cookies and Web Tracking. Consult our Cookie Notice for more information about how to control and/or opt out of certain web tracking technologies.

5. PROTECTING PERSONAL DATA

We use reasonable and appropriate physical, technical, and organizational safeguards designed to promote the security of our systems and protect the confidentiality, integrity, availability, and resilience of personal data. Those safeguards include: (i) the encryption of personal data where we deem appropriate; (ii) taking steps to ensure personal data is backed up and remains available in the event of a security incident; and (iii) periodic testing, assessment, and evaluation of the effectiveness of our safeguards.

However, no method of safeguarding information is completely secure. While we use measures designed to protect personal data, we cannot guarantee that our safeguards will be effective or sufficient. In addition, you should be aware that Internet data transmission is not always secure, and we cannot warrant that information you transmit utilizing the Services is or will be secure.

6. RETENTION OF PERSONAL DATA.

We retain personal data for a period of six (6) months after a user closes their account, and certain personal data for longer periods to the extent we deem necessary to carry out the processing activities described above, including but not limited to compliance with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, and to the extent we reasonably deem necessary to protect our and our partners’ rights, property, or safety, and the rights, property, and safety of our users and other third parties. Under applicable law, we are required to retain certain financial information for seven (7) years.

7. OTHER IMPORTANT INFORMATION ABOUT PERSONAL DATA AND THE SERVICES.

a. Identity Verification. We require checks for Creators to ensure that we do not knowingly offer our Services to or collect personal data from anyone under 18 or anyone using a false identity, and offer checks as an option for Fans.

b. Payment Information. Payments made by Fans to access content are processed by our third party payment providers. For example, when you make a payment that is processed by a payment provider, you will provide that third party with your credit card number, credit card expiration date, and security code, which they process and store subject to their privacy policy and terms of service. We do not receive your full credit card number, credit card expiration date, or the security code. Instead, the payment provider provides us with a “token” that represents your account, your card’s expiration date, card type and the first two and last four digits of your card number. If you are required to provide your name and email address to the payment provider, then they also provide us with that information. Payments issued to Creators for their content are made by Spotlit using the bank account information that we have collected and stored.

c. Collection of Personal Data from Children. Our Services are not intended for anyone under 18. Anyone under 18 years of age is not permitted to use the Services, and we do not knowingly collect information from children under the age of 18. By using the Services, you represent that you are 18 years of age or older.

d. Third-Party Websites and Services. As a convenience, we may reference or provide links to third- party websites and services, including those of unaffiliated third parties, our affiliates, service providers, and third parties with which we do business (including, but not limited to, our service providers). When you access these third-party services, you leave our Services, and we are not responsible for, and do not control, the content, security, or privacy practices employed by any third-party websites and services. You access these third-party services at your own risk. This Privacy Notice does not apply to any third-party services; please refer to the Privacy Notices or policies for such third-party services for information about how they collect, use, and process personal data.

e. Business Transfer. We may, in the future, sell or otherwise transfer some or all of our business, operations or assets to a third party, whether by merger, acquisition or otherwise. Personal data we obtain from or about you via the Services may be disclosed to any potential or actual third- party acquirers and may be among those assets transferred.

f. Do Not Track. We currently do not use any cross-site tracking technologies and do not currently process or comply with any web browser’s “do not track” signal or similar mechanisms. Note, however, that you may find information about how to block or reject certain tracking technologies in our Cookie Notice.

g. International Use. Your personal data will be stored and/or processed in the United States, as well as in the European Union, Canada, Hong Kong, Russia, Singapore, Switzerland, Thailand, Ukraine and the United Kingdom. By your use of the Services, you acknowledge that we will transfer your data to, and store your personal data in, the above countries, which may have different data protection rules than in your country, and personal data may become accessible as permitted by law in the above countries, including to law enforcement and/or national security authorities in the those countries. For transfers of data into and out of the European Economic Area, pursuant to Article 46 of the General Data Protection Regulation, we use data transfer agreements subject to EU-approved standard contractual clauses.

8. MODIFICATIONS AND UPDATES TO THIS PRIVACY NOTICE

This Privacy Notice replaces all previous disclosures we may have provided to you about our information practices with respect to the Services. We reserve the right, at any time, to modify, alter, and/or update this Privacy Notice, and any such modifications, alterations, or updates will be effective upon our posting of the revised Privacy Notice. We will use reasonable efforts to notify you in the event material changes are made to our processing activities and/or this Privacy Notice, such as by posting a notice on the Services or sending you an email. Your continued use of the Services following our posting of any revised Privacy Notice will constitute your acknowledgement of the amended Privacy Notice.

9. APPLICABILITY OF THIS PRIVACY NOTICE

This Privacy Notice is subject to the Terms of Service and Acceptable Use Policy that govern your use of the Services. This Privacy Notice applies regardless of the means used to access or provide information through the Services.

This Privacy Notice does not apply to information from or about you collected by any third-party services, applications, or advertisements associated with, or websites linked from, the Services. The collection or receipt of your information by such third parties is subject to their own privacy policies, statements, and practices, and under no circumstances are we responsible or liable for any third party’s compliance therewith.

PRIVACY PRACTICES FOR OUR WEBSITES

Information We Collect Through the Spotlit Websites

  • Information You Disclose to Us

Website visitors may choose to provide their contact information, such as part of a registration or order form. Visitors may also provide payment information.

  • Automatically Collected Information

On our Websites, we or third parties may collect certain information by automated means such as cookies, Web beacons and JavaScript. This information may include unique browser identifiers, IP address, browser and operating system information, device information, Internet connection information, as well as details about individuals’ interactions with websites.

We and third parties may use automated means to read or write information to users’ devices, such as in various types of cookies and other browser-based or plugin-based local storage. Cookies are files that contain data, such as unique identifiers, that we or a third party may transfer to or read from a user’s device for purposes such as recognizing the device, service provision, record-keeping, analytics and marketing. You may choose to set your web browser to refuse certain types of cookies, or to alert you when certain types of cookies are being sent. However, if you block or otherwise reject our cookies, certain websites (including our own website and some of our clients’ websites) may not function properly.

In some cases, we facilitate the collection of information by advertising services administered by third parties. The ad services may track users’ online activities over time by collecting information through automated means such as cookies, and they may use this information to show users advertisements that are tailored to their individual interests or characteristics and/or based on prior visits to certain sites or apps, or other information we know, infer or have collected from the users. For example, we and the third-party vendors may use first-party cookies and third-party cookies together, as well as other automated means and other data (such as the data described above) (i) to recognize users and their devices, (ii) to inform, optimize, and serve ads and (iii) to report on our ad impressions, other uses of ad services, and interactions with these ad impressions and ad services (including how they are related to visits to specific sites or apps). To learn more about interest-based advertising generally, including how to opt out from the targeting of interest-based ads by some of our current ad service partners, click here. For controls specific to advertising and analytics services offered by Google, click herehere and here. If you replace, change or upgrade your browser, or delete your cookies, you may need to use these opt-out tools again.

  1. How We Use Information We Collect Through the Spotlit Websites

In addition to the uses described elsewhere in this Policy, we use the information we collect through the Spotlit Websites to provide, market, improve, and operate the Spotlit Websites, Spotlit Services, and any other products or services we have or may develop. This includes use of the information to:

  • Fulfill your requests;
  • Send information about our products and services, including marketing communications;
  • Respond to your questions, concerns, or customer service inquiries;
  • To create aggregate or de-identified information;
  • Comply with law and engage in fraud prevention, risk mitigation, and similar purposes;
  • Understand usage trends and preferences;
  • Otherwise analyze, improve, and provide products and services;
  • Customize the content and advertising you see on the Spotlit Websites, across the Internet, and elsewhere; and/or
  • Other purposes for which the individual provided it.
  1. How We Share Information We Collect Through the Spotlit Websites

We may share the information we collect through the Spotlit Websites in the following situations:

  • With your consent, including through this Policy;
  • With our affiliates or other entities that help us to operate our business and provide our Service;
  • To (1) comply in good faith with applicable laws, rules, regulations, governmental requests, court orders, or subpoenas, including for purposes of national security and law enforcement; (2) enforce our agreements; or (3) protect the rights, property, or safety of our users or any other person or entity; or
  • As part of a business sale, merger, consolidation, investment, change in control, transfer of substantial assets, reorganization or liquidation, or in connection with steps taken in anticipation of such an event (e.g., due diligence).

With respect to aggregated or de-identified information, we may share such information without restriction.

10. ADDITIONAL INFORMATION AND ASSISTANCE

If you have any questions or concerns about this Privacy Notice and/or how we process personal data, please contact us at [email protected].

In addition, we have appointed a data protection officer (“DPO”) who is responsible for, among other things, responding to questions, requests, and concerns in relation to this Privacy Notice and our use of personal data. You may contact the DPO as follows:

Data Protection Officer
[email protected]