Privacy Policy

Last updated: December 20, 2024

At Toy Soldiers Platform, we take your privacy seriously. This Privacy Policy explains how we collect, use, share, and protect your personal information.

1. Information We Collect

Personal Information

  • Email address and password
  • Full name and username
  • Date of birth (for age verification)
  • Payment method information (processed by Stripe)
  • Profile information and avatar

Content Data

  • Content you upload (audio, video, images)
  • Metadata about your content (titles, descriptions, genres)
  • Your viewing and listening history
  • Subscriptions and purchases

Automatically Collected Data

  • IP address and device information
  • Browser type and operating system
  • Pages visited and time spent on site
  • Referral source and links clicked
  • Cookies and similar tracking technologies

2. How We Use Your Information

  • Essential Functions: Processing transactions, delivering content, managing accounts
  • Communication: Sending important updates, responding to inquiries, sending newsletters (opt-in)
  • Improvement: Analyzing usage patterns to improve Platform features
  • Legal Compliance: Complying with laws and enforcing our Terms of Service
  • Safety: Detecting fraud, abuse, and security threats
  • Analytics: Understanding user behavior and Platform performance

3. How We Share Your Information

We share personal information only when necessary:

Service Providers

  • Stripe: Payment processing (PCI Level 1 compliant)
  • Supabase: Database hosting and authentication
  • Cloudflare R2: Content storage and delivery
  • Resend: Email delivery
  • Telnyx: SMS notifications (optional)

Legal Requirements

We may share information if required by law, court order, or to protect our rights and safety.

Business Transfers

If acquired or merged, your data may transfer to the successor organization (with notice).

4. Data Retention

Deleted Accounts

Personal data deleted within 30 days of deletion request. Content may be archived per legal requirements.

Financial Records

Retained for 7 years (tax and legal compliance).

Access Logs

Retained for 90 days for security purposes.

5. Your Privacy Rights

Depending on your location, you have rights including:

πŸ‡ͺπŸ‡Ί GDPR (European Users)

  • Right to access your data
  • Right to rectification (correct inaccurate data)
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

πŸ‡ΊπŸ‡Έ CCPA (California Users)

  • Right to know what personal data is collected
  • Right to delete personal data
  • Right to opt-out of "sale" of personal data
  • Right to non-discrimination for exercising rights

Other States (Virginia, Colorado, Connecticut)

  • Right to access personal data
  • Right to deletion
  • Right to correction
  • Right to opt-out of targeted advertising

To exercise these rights, email privacy@toysoldiers.com

6. Data Security

We protect your data using industry-standard security measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • JWT authentication tokens with secure expiration
  • bcrypt password hashing (not stored in plain text)
  • 24/7 security monitoring and intrusion detection
  • Regular security audits and penetration testing

7. Cookies and Tracking

We use cookies for:

  • Authentication: Keeping you logged in
  • Preferences: Remembering your settings
  • Analytics: Understanding how you use the Platform
  • Security: Detecting suspicious activity

You can manage cookies in your browser settings or adjust privacy settings in your account.

8. Children's Privacy

Toy Soldiers Platform is not designed for children under 18. We do not knowingly collect data from children. If we discover a child's account, we will delete it immediately and remove their data.

9. International Data Transfers

If you are outside the United States, your data may be transferred to and stored in the US.

For GDPR compliance: We use Standard Contractual Clauses (SCCs) and Privacy Shield mechanisms to ensure adequate protection when transferring data internationally.

Privacy Questions?

Email: privacy@toysoldiers.com

Data Requests: privacy@toysoldiers.com

GDPR Representative: EU users can submit requests through our privacy portal.