Legal

Privacy Policy

This policy explains how Fader Club handles personal data across account, learning, purchase, creator, affiliate, communication, and security workflows under Brazil's General Data Protection Law (LGPD).

Working legal draft · Last updated August 22, 2026. Data requests may be submitted through Support. The operator's legal identity, registration, business address, and formal privacy contact must be published before commercial launch.

1. Scope, controller, and roles

This policy applies to Fader Club websites, authenticated workspaces, courses, digital products, support, and related communications. The Fader Club platform operator acts as controller for platform accounts, access, security, marketplace operations, and its own communications. A creator may act as an independent controller when processing personal data for that creator's own lawful purposes, including creator-selected advertising measurement for that creator's catalog when enabled. The exact controller, joint-controller, processor, or operator allocation between Fader Club, the relevant creator, and Meta for that measurement must be confirmed by qualified counsel and documented before commercial activation. The party responsible for a particular processing activity must be identified transparently when the context requires it.

2. Categories of personal data

Depending on how you use Fader Club, data may include name, email, password-related account records, phone or WhatsApp number, date of birth, country, address, language, time zone, company information, profile photo, public biography and links, enrollment and learning progress, reviews and questions, support messages, notifications, order and receipt details, billing and tax information, refund or dispute history, creator and affiliate applications, commissions, payout instructions, uploaded files, and administrative audit records. Identity screens may retain only masked document metadata and the last digits, while billing, tax, or payout workflows may retain identifiers you submit when legally or operationally necessary.

3. How data is obtained

Data comes from you when you register, complete a profile, buy or access content, upload material, submit a review, contact support, or join a creator or affiliate workflow. It may also come from other account participants, creators, payment and email providers, security and infrastructure services, referral links, and technical events generated when you use the platform. Fader Club does not intentionally purchase consumer data lists.

4. Why data is processed

Data is used to create and secure accounts; verify access and roles; deliver courses, downloads, receipts, support, and notifications; maintain learning progress; review and publish creator submissions; operate orders, refunds, commissions, and payouts; attribute eligible affiliate referrals; prevent abuse, fraud, and content theft; comply with legal duties; respond to rights requests; measure and improve product performance; and establish, exercise, or defend legal claims. Data is not sold.

5. Legal bases

The applicable LGPD basis depends on the purpose. Fader Club principally relies on steps requested before a contract and performance of a contract; compliance with legal or regulatory obligations; regular exercise of rights; protection of credit where applicable; legitimate interests such as platform security, fraud prevention, service integrity, and improvement after a proportionality assessment; and consent for optional analytics or marketing when consent is the appropriate basis. You may withdraw consent for future processing without affecting prior lawful processing.

6. Purchases, payments, and payouts

For purchases and creator or affiliate financial workflows, Fader Club may handle order values, currency, coupons, billing details, tax identifiers, payment status, provider references, receipts, refunds, chargebacks, commissions, revenue allocations, and payout instructions. Full card credentials are entered in the payment provider's protected interface and are not intended to be stored by Fader Club. Providers process transaction data under their own legal and security obligations; Fader Club retains the records needed to deliver access, reconcile the transaction, prevent duplicate charges, support the user, and comply with law.

7. Public profiles and user content

Information deliberately published in a creator profile, course or product page, review, rating, question, blog post, or other public surface can be viewed and shared by anyone. Public creator data may include a display name, photo, headline, biography, expertise, social links, embedded audio, and an uploaded performance or credits image. Do not publish confidential data or personal data of another person without a lawful basis. Removing a public item from Fader Club does not remove copies previously saved or independently shared by others.

8. Analytics and similar technologies

Fader Club stores separate product-analytics and advertising preferences on your device. Privacy-preserving aggregate web analytics may record anonymous page and performance totals without cookies or cross-site profiles. Optional PostHog product analytics starts only after affirmative product-analytics consent and may process page paths, selected product events, pseudonymous account identifiers, aggregate click or scroll positions, and masked session replay. Separately, creator-owned Meta Pixel in the browser and Meta Conversions API on the server start only after affirmative advertising consent to measure visits, course or product views, checkout, and payment-confirmed purchases for advertising performance and remarketing. This is not one global Fader Club creator-sales Pixel: an event is sent only to the active Meta dataset selected by the relevant course or product creator, and mixed-creator commerce events are separated so each destination receives only its creator's items and attributed value. Generic pages and another creator's catalog are not sent to that dataset. Meta may receive the first-party identifiers _fbp and _fbc and, when available for server matching, normalized email or phone values transformed with SHA-256 before transmission; hashing reduces direct exposure but does not make that data anonymous. Analytics URLs are limited to the site origin and pathname, without query strings or fragments. Either optional consent may be withdrawn for future processing at any time in Cookies and Analytics.

9. Sharing and service providers

Data is shared only as needed with authorized staff; creators or collaborators involved in a course, product, support conversation, or approved operational workflow; and providers for authentication, database and private storage, hosting, video or media delivery, payment, email, analytics, advertising measurement, monitoring, and security. PostHog receives optional product analytics only when that category is enabled. For optional Meta advertising measurement, the relevant creator and Meta may receive or access events in the creator-selected Meta dataset; a creator must not receive another creator's item or value through this integration. Data may also be disclosed to professional advisers, authorities, or courts when required by law or necessary to protect rights, and in a corporate transaction subject to appropriate confidentiality and continuity safeguards. Providers and creators must receive only data compatible with their role. The exact controller, joint-controller, processor, or operator status and applicable data-processing terms among Fader Club, each creator, and Meta must be confirmed and documented before commercial activation.

10. International transfers

Some infrastructure, analytics, and advertising providers, including PostHog or Meta when enabled, may process data outside Brazil. A relevant creator's selected Meta account or business tools may also make measured event data available across borders. When an international transfer occurs, the responsible party must use a mechanism permitted by the LGPD and ANPD rules, such as an adequacy decision, contractual clauses, certification, or another lawful safeguard, and apply security and access controls appropriate to the data and risk. The final Fader Club, creator, and provider agreements and international-transfer assessment remain activation requirements.

11. Retention and deletion

Data is retained for no longer than reasonably necessary for the stated purpose. Criteria include the life of the account or contract, access rights to purchased content, limitation periods, consumer and tax obligations, fraud and security needs, audit integrity, and pending disputes. Terms-acceptance evidence, transaction records, invoices or receipts, security logs, moderation history, and backup copies may remain for legally justified periods after account deletion. For Meta measurement, Fader Club keeps a service-only pseudonymous consent-authority record containing a random consent ID, version, status, and timestamps for up to 400 days solely to enforce withdrawal; after withdrawal, it acts as a technical tombstone that prevents delayed requests from restoring consent and is not sent to Meta. Temporary order matching identifiers are kept for at most seven days and removed earlier after successful Purchase delivery or withdrawal. A service-only, user-bound AddToCart receipt is valid for up to ten minutes and is consumed on first use so it cannot be replayed. Disconnecting a creator integration stops future use, cancels unsent events, and deletes the retained access token, but does not automatically erase events already delivered to Meta. Provider-side advertising records follow Meta and the relevant creator account's retention and deletion settings; the exact schedule, rights-request routing, and deletion workflow must be confirmed during creator, provider, and legal review before commercial activation. Data is deleted, anonymized, or access-restricted when the purpose and lawful retention basis end.

12. Children and adolescents

Fader Club is directed to adults. A minor may use it only through a parent or legal guardian as described in the Terms, with processing in the minor's best interests and the consent or other authorization required by article 14 of the LGPD. If data was submitted without appropriate authority, the responsible adult should contact Support so the account and data can be reviewed.

13. Security and incidents

Fader Club uses measures such as encrypted transport, role-based access, private storage, temporary signed delivery, provider-side payment interfaces, audit trails, and restricted administrative tools. No system is risk-free. Suspected unauthorized access should be reported promptly through Support. Relevant security incidents will be assessed, contained, documented, and communicated to the ANPD and affected people when required by applicable law.

14. Your LGPD rights

Subject to legal conditions, you may request confirmation and access; correction; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability; information about sharing and consent consequences; revocation of consent; review of a decision based solely on automated processing; and opposition to unlawful processing. You may also petition the ANPD or consumer-protection bodies. Submit a request through Support. Fader Club may verify identity and will explain any lawful limitation, such as mandatory retention or protection of another person's rights.

15. Automated rules, updates, and contact

Security and fraud rules may automatically flag, delay, or block an action. When a decision materially affects account or transaction access, you may request human review through Support. Material policy changes will be communicated through the platform or an appropriate account channel and may require renewed acknowledgment. Questions, complaints, and privacy requests currently use Support; the operator's formal identification and privacy contact remain mandatory launch information and will be added after approval.

16. Instagram comment automationOpen document

A creator who connects a professional Instagram account authorizes Fader Club to read selected account and media metadata, subscribe to comment webhooks, match eligible comment text in memory, and send one creator-configured private reply. Access tokens stay in restricted Vault storage. Fader Club stores the connected account ID and username, selected media and rule configuration, minimal provider event, comment and message identifiers, operational timestamps, delivery state, and daily aggregate counters. It does not persist raw webhook payloads, commenter usernames, raw comment text, recipient identity, IP addresses, user agents, or provider response bodies. Disconnecting blocks new replies, cancels work that has not started, asks Meta to remove the comment subscription, and deletes the retained credential and connected-account metadata only after Meta confirms removal. After confirmation, the creator may use Delete retained data to permanently remove the saved automations, rule history, delivery records, and aggregate results tied to that connection. A provider request already in progress may still complete, and messages or records already held by Instagram are controlled through Meta. Detailed instructions and retention limits are published on the Instagram Data Deletion page.