Privacy Notice
A draft GDPR-ready explanation of how Spotlist processes account, profile, payment and security data.
Draft updated 26 August 2026Data we use
We process account identifiers, public profile fields, uploaded media, validated social links, bid and payment ledger records, reports, moderation and security logs. Card details are handled by the payment provider and are not stored by Spotlist.
Purposes and retention
Data supports authentication, public directory delivery, payments, fraud prevention, moderation, analytics, legal compliance and incident response. Retention periods and lawful bases must be finalised for each launch country.
Your controls
The dashboard supports profile editing, account deletion and session revocation. A production export workflow, verified deletion SLA and data-subject intake channel must be configured before launch.
International processing
Supabase, Vercel, Stripe or another selected payment provider, and Mux may process data in multiple regions. Production transfer mechanisms, subprocessors and regional configuration require privacy review.