UGC Moa

Working draft — not reviewed by a lawyer

Privacy Policy

This Privacy Policy explains how personal data is handled when you use UGC Moa. It is a working draft and must be reviewed by qualified counsel before launch.

Service provider
[LEGAL ENTITY NAME]
Registered address
[REGISTERED ADDRESS]
Contact
[LEGAL/PRIVACY CONTACT EMAIL]
Governing law
[GOVERNING LAW AND JURISDICTION]
Effective date
[EFFECTIVE DATE — YYYY-MM-DD]
Website
ugcmoa.com

1. Who is responsible

The service provider identified above is the controller or personal information controller for the processing described here, unless another party determines the purpose and means of a specific processing activity. Questions and rights requests should be sent to the contact address above.

2. Data we collect

  • Account data: email address, authentication identifiers, name, role, company name, account status, and social handles.
  • Profile and marketplace data: biographies, audience and rate information, portfolio uploads, campaign briefs, applications, messages, deliverables, approvals, referral records, and workspace membership.
  • Payment and payout data: customer, subscription, checkout, payment, refund, connected-account, and payout identifiers and statuses supplied by Stripe. We do not store full card numbers.
  • Technical data: a country code inferred from the request's IP address by the hosting network, the browser Accept-Language header, device/browser information contained in ordinary request logs, timestamps, security events, and operational logs.
  • Preferences and functional state: the language choice stored in localStorage, the HttpOnly active-workspace cookie, and temporary local booking state.

3. How we use data and our legal bases

  • Provide accounts, campaigns, bookings, messaging, escrow, subscriptions, refunds, payouts, and support: performance of a contract and steps requested before a contract.
  • Secure the service, prevent fraud, enforce rules, debug failures, and maintain records: legitimate interests and legal obligations.
  • Process payments, accounting, tax, sanctions, and legal requests: contract and legal obligations.
  • Remember language and active workspace: requested functional operation and legitimate interests. These are not advertising trackers.
  • Send campaign brief text to the AI provider when a user requests generation: performance of the requested service. Users should not include unnecessary sensitive personal data.

4. Processors and recipients

  • Supabase processes authentication identifiers and hosts account, profile, campaign, message, and file data.
  • Stripe processes subscription, card payment, refund, connected-account, identity/compliance, and payout data. Card numbers are collected by Stripe, not stored by UGC Moa.
  • Lovable Cloud hosts and operates the application.
  • Lovable AI processes campaign brief inputs and generated text when AI generation is requested.
  • Professional advisers, authorities, or a successor business may receive limited data where lawfully necessary.

5. AI and analytics

Campaign brief text and product information are sent to Lovable AI only when generation or analysis is requested. Do not submit confidential or sensitive personal information that is not needed for the brief.

UGC Moa does not currently run third-party advertising analytics or cross-site behavioral tracking. We use account and campaign records to provide in-product reporting to authorized workspace members, and operational logs and error reports to secure and maintain the service.

6. Cookies and local storage

There is no advertising-cookie consent banner because the application does not currently set advertising or cross-site tracking cookies. The active workspace is stored in a functional HttpOnly, SameSite=Lax cookie for up to one year. JavaScript cannot read this cookie. Authentication may use strictly necessary session storage managed by the authentication provider.

The language preference is stored in browser localStorage under ugcmoa.lang; it is not a cookie. A temporary booking identifier may also be stored locally while payment confirmation is pending. You can clear local storage through browser settings, but doing so may reset preferences or interrupt an unfinished checkout status check.

7. International transfers

The service is intended for international use. Data may be processed in countries other than your own, including the United States. Where required, transfers rely on recognized safeguards such as adequacy decisions, standard contractual clauses, equivalent processor terms, or another lawful transfer mechanism. The exact corporate contracting entities and transfer documentation must be confirmed before launch.

8. Retention

We keep account and active marketplace records while the account is open and as needed to provide the service. Payment, payout, dispute, fraud, tax, and transaction records may be retained for the period required by applicable law and financial providers. Deleted portfolio files and inactive account data are removed or de-identified within a reasonable operational period unless an open booking, dispute, security need, legal hold, or mandatory retention duty applies. Final retention periods must be confirmed for the governing jurisdiction before launch.

9. Your rights — GDPR

Where the GDPR or UK GDPR applies, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing relies on consent; and complain to your supervisory authority. You may also ask about safeguards for international transfers. Some rights are limited where we must keep records or protect another person's rights. We will verify identity and respond within the legally required period.

10. 대한민국 이용자의 권리 — 개인정보 보호법(PIPA)

대한민국 이용자는 개인정보 보호법에 따라 본인 개인정보의 처리 여부 확인, 열람, 정정·삭제, 처리정지 및 동의 철회를 요구할 수 있습니다. 개인정보가 다른 사람의 권리 또는 법령상 보존 의무와 관련된 경우에는 요청이 제한될 수 있으며, 그 사유를 안내합니다.

권리 행사는 위 연락처로 요청할 수 있습니다. 본인 또는 적법한 대리인인지 확인한 뒤 법정 기한 안에 처리 결과를 알립니다. 개인정보 침해에 관한 상담이나 신고는 개인정보침해신고센터, 개인정보분쟁조정위원회 등 관계 기관에 문의할 수 있습니다.

국외 이전이 발생하는 경우 이전받는 자, 국가, 항목, 목적, 시기·방법, 보유기간 및 거부 방법 등 개인정보 보호법상 필요한 사항을 별도로 고지하거나 동의를 받는 절차가 필요할 수 있습니다. 실제 이전 구조와 고지 항목은 출시 전에 확정해야 합니다.

11. Security and breach contact

We use access controls, row-level authorization, encrypted transport, restricted service credentials, and payment-provider controls intended to protect data. No system is completely secure. If you suspect unauthorized access or a personal-data breach, contact the address above immediately. We will investigate and notify affected people and regulators where law requires.

12. Children

UGC Moa is for people aged 18 or older. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us so we can investigate and delete it where appropriate.

13. Changes

We may update this policy as the service, processors, or law changes. Material changes will be announced through the service or by email where appropriate. The effective date and change log below will identify the current version.


Change log: Initial working draft — effective date pending.