Legal
Find Me Privacy Policy
Version 1.0 Β· Effective October 5, 2026
This Privacy Policy explains how Find Me LLC collects, uses, shares, retains, and protects personal information when you use Find Me. It also contains our Cookies and Tracking Policy (Section 17), our Biometric Data Policy (Section 6), our "Do Not Sell or Share" notice (Section 18), and our list of subprocessors (Appendix A).
You do not need to "accept" this Privacy Policy. We ask you to read it so you understand how your information is handled. Our Terms of Service, which you do accept, are available at /terms.
1. Introduction
1.1 What this policy covers
This policy applies to the Find Me website, web application, and related services, including account creation, profiles, portfolios, uploads, sharing, support, and billing (collectively, the "Service"). It applies to members, visitors to our website, people who contact our support team, and people whose information appears in content submitted to the Service.
1.2 Who we are
The Service is operated by:
Find Me LLC
4111 Rose Lake Dr
Charlotte, NC 28217
United States
Email: support@fyndme.net
Find Me LLC ("Find Me," "we," "us," or "our") is the controller (or "business," under California law) responsible for your personal information as described in this policy.
An EU representative (GDPR Art. 27) and/or UK representative (UK GDPR Art. 27) may be required because we offer the Service to individuals in the EEA/UK. Our EU/UK representative is to be appointed. Until a representative is appointed, you may contact us directly at support@fyndme.net for all privacy matters, including those arising under the GDPR or UK GDPR.
1.3 How to contact us
For any privacy question or request, email support@fyndme.net. Automated account emails (such as verification codes and account notices) are sent from no-reply@fyndme.net; please do not reply to that address, as it is not monitored.
2. Definitions
- Service β The Find Me website, web application, and related features and services operated by Find Me LLC.
- Account β The registered Find Me membership you create using an email address and password, or through Google or Apple sign-in.
- Profile β The information you provide when you sign up and set up your Account that identifies you on the Service: your name, username, occupation, bio, introduction, skills, and location (country, state or region, and city), and your profile color and verified badge. Your Profile is public (see Section 10).
- Portfolio β A collection of content (such as photos, media, and descriptions) that you create and manage within your Account. Each plan allows a maximum number of published Portfolios: Basic β 1 Personal portfolio only; Standard β 1 Personal portfolio + 2 portfolios in any category (3 total); Advanced β unlimited portfolios in any category. When a plan is downgraded, your Personal portfolio is always kept published first; additional Portfolios beyond the new limit are paused (hidden, not deleted) and can be restored on upgrade. See /pricing and the Terms for details.
- Face Discovery β A facial recognition feature that compares a face in a submitted image against the faces of members who have opted in (one-to-many, or "1:N," matching). Face Discovery is not currently available. It has been built but is disabled, and it will launch only after we give separate notice and obtain separate consent, as described in Section 6.
- Biometric template β A mathematical representation (for example, a numerical vector) derived from the geometry of a face in an image, used to compare faces. A biometric template is considered biometric data, biometric identifiers, and/or biometric information under applicable law.
- Account deletion β The permanent, irreversible removal of your Account and associated personal information, as described in Section 9.3.
- Subprocessor β A third-party service provider that processes personal information on our behalf and under our instructions to help us operate the Service (listed in Appendix A).
- Anti-abuse fingerprint β A pseudonymized value created by applying a keyed cryptographic hash function (HMAC) to a verified email address or phone number. It is used only to prevent repeat claims of free months and referral rewards, as described in Section 7.
3. Information We Collect
We collect the categories of information below. Some information you provide directly, some is collected automatically when you use the Service, and some is received from third parties you choose to use (such as Google or Apple sign-in).
3.1 Account data
- Name
- Email address
- Username
- Phone number (if provided or required for verification)
- Password, stored only as a salted cryptographic hash (we never store your password in plain text). When you set a password, we check it against known lists of breached passwords and reject passwords that appear on those lists. Passwords must be at least 8 characters.
- Multi-factor authentication (MFA) secret, if you enable an authenticator app (MFA is optional for members and mandatory for Find Me staff)
- Account settings and preferences
- Plan status (for example, Basic, free access period, referral credits)
- Terms of Service acceptance record and 18+ age attestation, including the version accepted and the date and time recorded
3.2 Profile and portfolio content
- Profile details from sign-up and profile setup: first and last name, display name, username, occupation, bio, introduction, skills, country, state or region, city, and profile color. These Profile details are always public and cannot be hidden (see Section 10). Your email address and phone number are not part of your public Profile.
- Portfolios you create, including titles, descriptions, and category
- Share settings and share links you create
3.3 Photos and media (including metadata)
- Photos, images, and other media you upload
- Metadata embedded in or associated with uploads, such as file name, file type, file size, dimensions, upload date, and, where present in the file, device information, date taken, and location (EXIF/GPS) data
We remove location and camera metadata (EXIF/GPS) from photos on upload. File name, type, size, dimensions, and upload date are retained.
3.4 Support communications
- Feedback and support tickets you submit, including message content and any attachments
- Emails you send to support@fyndme.net
- Signed-out "Account access help" requests, including the reply-to email address you provide and the username you claim
- Records of our responses and ticket status
3.5 Usage and device data
- IP address
- Device type, operating system, and browser type and version
- Pages and features accessed, and date and time of access
- Referring URL
- Crash logs, error reports, and diagnostic information
- Session and security logs (for example, sign-in events, sign-in location approximated from IP address, and active sessions)
3.6 Sign-in data (Google and Apple)
If you sign in with Google or Apple, we receive information from that provider, such as:
- A unique identifier for your account with that provider
- Authentication tokens required to sign you in
- Your email address and name (and, for Google, a profile photo if made available)
- Apple private relay: If you choose "Hide My Email" when using Sign in with Apple, we receive a private relay email address generated by Apple instead of your real email address. Emails we send to that address are forwarded to you by Apple. We do not receive your underlying email address.
3.7 Payment data
Payments are processed by Stripe. We will not receive or store your full card number or security code. We may receive and store limited payment information from Stripe, such as:
- Card brand, last four digits, and expiration date
- Billing country (and postal code, if required for tax or fraud purposes)
- Transaction history, plan, amount, currency, and payment status
If Find Me mobile apps launch and you purchase through the Apple App Store or Google Play, those companies will process your payment under their own privacy policies, and we will receive only purchase and subscription status information.
3.8 Anti-abuse fingerprint
A pseudonymized HMAC value derived from your verified email address and/or verified phone number. See Section 7.
3.9 Email verification data
- One-time verification codes or tokens sent to your email address
- The time a verification email was sent and whether and when the address was confirmed
3.10 Consent receipts
- Records of your cookie choices (including whether a Global Privacy Control signal was detected), and, if Face Discovery launches, your separate Face Discovery consent and any withdrawal
- Your marketing email choice: whether you opted in, the date and time of your choice, and the version of the consent text you saw; and the date and time you unsubscribed, if you do
- For each consent receipt: the choice made, the policy or notice version presented, the date and time, and a pseudonymous identifier linking the choice to your browser or Account
3.11 Biometric data
We do not currently collect biometric data. Face Discovery is disabled. If it launches, biometric templates will be created only for members who give separate, express consent, as described in Section 6.
3.12 Marketing contacts who are not members
- Name and email address of business and professional contacts in the United States who expressed interest in Find Me through LinkedIn or our earlier email campaigns, and whether they unsubscribed
- Whether our marketing emails to them were delivered or opened and which links were clicked
3.13 Information we do not collect
We do not use advertising identifiers, we do not use advertising cookies, and we do not buy personal information from data brokers.
4. How We Use Your Information
We use personal information only for the following purposes:
- Provide the Service β Create and maintain your Account, host your Profile and Portfolios, store and display your uploads, enable sharing, and remember your settings.
- Verify your email β Confirm that you control the email address you signed up with. Email verification is required before you can use the Service. Unconfirmed signups are automatically deleted after 30 minutes.
- Record Terms acceptance and age attestation β After your Account is created, record your acceptance of the Terms of Service and your attestation that you are 18 or older (including the version accepted) before you can use the Service.
- Security and fraud prevention β Authenticate you, support MFA, reject breached passwords, detect suspicious sign-ins, prevent unauthorized access, and protect the Service and our members.
- Content moderation β Detect, review, and act on content or conduct that violates our Terms of Service, including through our enforcement ladder and appeals process.
- Human portfolio review β Have trained staff review portfolios, including when content is reported or flagged.
- Anti-abuse β Prevent repeat claims of the free access period and referral rewards using the anti-abuse fingerprint (Section 7).
- Plans, free access, and referrals β Administer the Basic plan, the 3-month free access period, and referral credits, and (when launched) paid plans and billing.
- Communications β Send you service messages such as verification codes, security alerts, account deletion notices, plan changes, responses to support tickets, and notices of changes to our Terms or this policy.
- Marketing emails β We send product news and updates by email to members who opt in, and to business and professional contacts in the United States whose email addresses we collected from people who expressed interest in Find Me through LinkedIn and our earlier email campaigns. Members opt in with the marketing email box at signup or in Settings β Notifications; the box is unchecked by default and opting in is never required to use the Service. We use Brevo to send these emails; Brevo processes your name, email address and, for members, the profile details described in Appendix A on our behalf. Our emails may record whether they were opened and which links were clicked, so we can improve them. Every marketing email includes a one-click unsubscribe link, or you can email support@fyndme.net; members can also turn marketing emails off in Settings β Notifications. We honor unsubscribe requests within 10 business days and never sell your email address. Unsubscribing does not affect service messages.
- Support β Respond to Feedback, Support tickets, email inquiries, and signed-out "Account access help" requests.
- Improve and maintain the Service β Diagnose errors and crashes, maintain performance, and understand how features are used in aggregate.
- Legal compliance β Comply with applicable laws, respond to lawful requests, enforce our Terms, and establish, exercise, or defend legal claims.
What we do not do:
- We do not show advertising on the Service or use your information for targeted or cross-context behavioral advertising.
- We do not sell your personal information.
- We do not "share" your personal information as that term is defined under California law (sharing for cross-context behavioral advertising).
- We do not use your content or biometric data to train or tune any AI models, whether internal or third-party.
5. Legal Bases for Processing (EEA, UK, and Switzerland)
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal information only when we have a legal basis to do so:
- Contract β Processing necessary to provide the Service you signed up for under our Terms of Service.
- Consent β Where you have given consent, such as for marketing emails, non-essential cookies, or (if launched) Face Discovery. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Legitimate interests β Where processing is necessary for our legitimate interests or those of a third party, and those interests are not overridden by your rights and interests. You may object to processing based on legitimate interests (see Section 14.1).
- Legal obligation β Where we must process information to comply with the law.
| Purpose | Legal basis |
|---|---|
| Creating and operating your Account, Profile, and Portfolios | Contract |
| Email verification | Contract; legitimate interests (security) |
| Recording Terms acceptance and 18+ attestation | Contract; legitimate interests (demonstrating acceptance and age eligibility); legal obligation where applicable |
| Authentication, MFA, breached-password checks, session management | Contract; legitimate interests (security) |
| Security logging, fraud detection, and abuse prevention | Legitimate interests (protecting the Service and members) |
| Anti-abuse fingerprint (HMAC) | Legitimate interests (preventing repeat claims of free months and referral rewards) |
| Content moderation, human portfolio review, enforcement, and appeals | Legitimate interests (safe Service; enforcing Terms); contract; legal obligation where applicable |
| Free access period, referral credits, and plan administration | Contract |
| Payments and billing (when launched) | Contract; legal obligation (tax and accounting) |
| Service communications | Contract; legitimate interests |
| Marketing emails to members | Consent (we do not send marketing emails to non-members in the EEA, UK, or Switzerland) |
| Support tickets and account access help | Contract; legitimate interests (helping people regain access) |
| Essential cookies | Legitimate interests / strictly necessary (no consent required) |
| Functional and analytics cookies | Consent |
| Face Discovery (if launched) | Explicit consent (GDPR Art. 9(2)(a)) β see Section 6 |
| Safety and enforcement records retained after deletion (identity removed) | Legitimate interests (safety, preventing re-offending, defending claims); legal obligation where applicable |
| Billing records retention | Legal obligation |
| Responding to legal requests; establishing or defending legal claims | Legal obligation; legitimate interests |
| Aggregated, de-identified Service statistics | Legitimate interests |
6. Face Discovery (Biometric Data)
Face Discovery is not currently available. It has been built but is disabled, and it will launch only after we give separate notice. We do not currently collect, create, store, or use biometric data. This section describes how Face Discovery would work if launched, and serves as our public biometric data policy, including our retention schedule and destruction guidelines.
6.1 What Face Discovery would do
Face Discovery is a one-to-many ("1:N") facial recognition feature. When a scan is submitted, the Service would detect a face in the image, create a biometric template from it, and compare that template against the biometric templates of members who have opted in to be discoverable. If a likely match is found, the matching member's Profile could be shown.
6.2 Separate, express consent
- Face Discovery will be off by default.
- Consent to Face Discovery will be requested separately from the Terms of Service and this Privacy Policy. It will not be bundled with signup or any other agreement, and using the rest of the Service will never depend on consenting to Face Discovery.
- Before any biometric template is created, you will be shown a written notice describing (a) that biometric data is being collected, (b) the specific purpose, and (c) the length of time it will be retained, and you will be asked to provide a written release (for example, an electronic signature or affirmative "I consent" action) that we record as a consent receipt.
- You can withdraw consent at any time in Settings (see Section 6.6).
6.3 Scanning other people
Face Discovery is not currently available. When it launches, the following rules will apply:
- Scan only yourself β You may only scan your own face (for example, with a liveness check).
- Consenting enrolled user only β You may scan another person only if that person is also a Find Me member who has personally completed the Face Discovery consent flow on their own device.
- Geographic restrictions β Face Discovery will not be offered in the EEA, UK, or Switzerland, and may be restricted in Illinois, Texas, Washington, and other jurisdictions with biometric privacy laws.
We will publish the final scan-consent rules in a separate Face Discovery notice before the feature launches.
6.4 How biometric data would be used and protected
- Biometric templates would be used only to operate Face Discovery (matching faces against opted-in members).
- We will never sell, lease, trade, or otherwise profit from biometric data.
- We will never share or disclose biometric data to third parties for their own use. Biometric data will be disclosed only (a) to subprocessors acting on our behalf solely to operate Face Discovery, under contracts requiring equivalent protection; (b) with your consent; or (c) where required by law, a valid warrant, or subpoena.
- Biometric data will be stored, transmitted, and protected using a reasonable standard of care within our industry, and in a manner that is the same as or more protective than how we protect other confidential and sensitive information, including encryption in transit and at rest and restricted access.
- Scan images submitted for matching would not be retained after a template is generated and the match is completed.
6.5 Retention schedule and destruction guidelines
This retention schedule and these destruction guidelines are publicly available as required by 740 ILCS 14/15(a) and similar laws.
| Biometric data | Retention | Destruction |
|---|---|---|
| Your biometric template(s) (discoverability) | Only while Face Discovery is enabled on your Account | Deleted immediately when you withdraw consent, turn off Face Discovery, or delete your Account |
| Templates generated from a scan image | Only for the duration of the matching operation | Deleted immediately after matching completes |
| Scan images | Not retained after matching | Deleted immediately after matching completes |
| Biometric data of an Account that becomes inactive | 12 months | Deleted at the end of the inactivity period |
In all cases, biometric data will be permanently destroyed no later than the earliest of: (a) when the initial purpose for collecting it has been satisfied; (b) when you withdraw consent or delete your Account; or (c) within the maximum period permitted by applicable law β 3 years after your last interaction with Find Me under Illinois law, and within 1 year after the purpose expires under Texas law, or any shorter period required by law. Destruction means permanent deletion from active systems. Backups containing biometric data will be overwritten or purged within 7 days and will not be restored for any purpose other than disaster recovery, after which deletions will be reapplied.
6.6 Withdrawing consent
You can turn off Face Discovery at any time in Settings. When you do, your biometric templates are deleted immediately and your Profile is no longer discoverable through Face Discovery. You may turn it back on later by giving consent again.
6.7 Regulatory status
Remote biometric identification systems are listed as high-risk under Annex III of the EU AI Act (Regulation (EU) 2024/1689). Before Face Discovery is offered in the EEA, we will complete a GDPR Article 35 Data Protection Impact Assessment and any required conformity assessment and registration under the EU AI Act. Face Discovery will not launch in the EEA, UK, or Switzerland until these assessments are complete.
7. Anti-Abuse Fingerprint (HMAC)
To prevent people from repeatedly claiming the 3-month free access period or referral rewards (for example, by deleting and recreating accounts), we create an anti-abuse fingerprint.
- What it is: When you verify an email address or phone number, we apply a keyed cryptographic hash function (HMAC) using a secret key kept separately from the fingerprint. The result is a fixed-length value that does not reveal your email address or phone number on its face.
- Pseudonymized, not anonymized: Because we could determine whether a given email address or phone number matches a stored fingerprint by computing its HMAC, the fingerprint is pseudonymized personal data, not anonymized data. We treat it as personal information.
- Purpose: Used only to determine whether a verified email address or phone number has previously received free access months or referral rewards. It is not used for advertising, profiling, or any other purpose.
- Retention: Kept indefinitely, including after Account deletion. If it were deleted, the free access and referral limits could be bypassed by deleting and recreating an account.
- Legal basis (EEA/UK): Legitimate interests in preventing abuse of free offers and ensuring they remain fair and available. You may object (Section 14.1); we will consider your objection but may continue processing where we have compelling legitimate grounds.
- Not sold or shared: The fingerprint is never sold, shared, or disclosed to third parties except to subprocessors hosting our database.
- Rejoining: If you delete your Account, you may create a new one later. However, free access months and referral rewards already received will not restart.
8. Automated Decision-Making
We use automated tools in limited ways:
- Ranking β Search results are sorted by location proximity to you (city, then state, then country), then by followers, then by connections. We do not use personalized feeds or profiling.
- Fraud and security detection β Flagging suspicious sign-ins, breached passwords, and patterns associated with abuse (including anti-abuse fingerprint matches).
- Content moderation β Automated tools may help flag content for review.
No solely automated decisions with legal or similarly significant effects. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Enforcement actions such as removing portfolios, restricting, suspending, or deleting Accounts involve human review. Automated fraud checks may temporarily block an action (for example, a sign-in attempt or a duplicate free-month claim); you may request human review of any such decision by emailing support@fyndme.net or using our appeals process.
Where applicable law gives you the right to not be subject to solely automated decisions, to obtain human intervention, to express your point of view, and to contest a decision, you may exercise those rights by contacting us.
9. Data Retention
9.1 General principle
We keep personal information only as long as needed for the purposes described in this policy, then delete it. We do not keep records for a general fixed period and then "anonymize" them; each category has its own retention rule below.
9.2 Retention table
| Category | Retention period |
|---|---|
| Unconfirmed signups (email never verified) | Automatically deleted 30 minutes after signup |
| Email verification tokens/codes | Expire and are deleted 30 minutes after issue (or on use) |
| Account data (name, email, username, phone, hashed password) | While your Account is active; removed within minutes of Account deletion |
| Profile and Portfolios | While your Account is active; removed within minutes of Account deletion |
| Photos, media, and uploads (including metadata) | Until you delete them or your Account; removed within minutes of Account deletion |
| Shares and share links | Until you revoke them or delete your Account; removed within minutes of Account deletion |
| Sessions and login records | While active; removed within minutes of Account deletion |
| MFA secrets | Until you disable MFA or delete your Account; removed within minutes of Account deletion |
| Terms acceptance and 18+ attestation records | While your Account is active; deleted with the Account |
| Biometric templates (if Face Discovery launches) | Deleted immediately on opt-out, consent withdrawal, or Account deletion (see Section 6.5) |
| Anti-abuse fingerprint (HMAC) | Indefinitely, including after Account deletion (see Section 7) |
| Safety and enforcement records (e.g., reports, moderation decisions, enforcement history, appeals) | Retained after Account deletion with your identity removed for 3 years after the last related action |
| Staff moderation action records | Indefinitely; after a staff member is offboarded, their past actions are labeled "Former staff #<code>" |
| Admin-initiated account deletion audit records (recorded reason and audit entry) | 3 years |
| Support tickets (Feedback and Support, including attachments) | 24 months after resolution |
| Signed-out "Account access help" requests (reply-to email and claimed username) | Purged 30 days after the ticket is closed |
| Consent receipts (cookies; Face Discovery if launched) | Duration of consent plus 3 years |
| Cookie consent choice | Up to 12 months, after which we ask again (see Section 17) |
| Other cookies | See the cookie retention table in Section 17.10 |
| Billing and transaction records | 7 years after the transaction, for tax and accounting obligations |
| Security and server logs (IP, device, request data) | 12 months |
| Crash and error logs | 90 days |
| Analytics data (Google Analytics, only if you allow Analytics cookies) | Up to 14 months in Google Analytics, then deleted automatically |
| Notifications | 12 months |
| Marketing email choice and consent record (opt-in and opt-out dates, consent text version) | While your Account is active; removed within minutes of Account deletion. Your contact record at Brevo is deleted within 30 days of opting out or deleting your Account |
| Marketing contacts who are not members | Until they unsubscribe or ask us to delete their information; after that we keep only the email address on a do-not-email list so we never email it again |
| Backups | Daily backups retained 7 days, then overwritten; deleted data is not restored to active systems except for disaster recovery, after which deletions are reapplied |
We may retain information longer where required by law or where necessary to establish, exercise, or defend legal claims (for example, under a legal hold), and only for as long as that need lasts.
9.3 Deleting your Account
You can delete your Account at any time:
- Go to Settings β Delete account.
- Type the confirmation phrase "DELETE MY FIND ME ACCOUNT".
- Enter the code we email to you.
If you use an authenticator app, you must be signed in with it to delete your Account.
When you confirm:
- Your access is revoked immediately.
- Your Profile, Portfolios, uploads, shares, sessions, login records, and MFA settings are removed within minutes.
- There is no grace period, and deletion is irreversible. We cannot restore a deleted Account.
- Safety and enforcement records are kept with your identity removed.
- The anti-abuse fingerprint is kept as described in Section 7.
- Billing records are kept as required by law.
- Any active subscription is canceled.
If you want a copy of your data, use Download my data in Settings before deleting your Account.
9.4 Deletion by Find Me LLC
Find Me administrators may delete a member Account, for example for serious or repeated violations of our Terms. Each such deletion requires a recorded reason and creates an audit record. We will email the member a notice of the deletion. The same removal and retention rules in Section 9.3 apply.
9.5 Staff accounts
Find Me staff cannot delete their own staff accounts. When a staff member leaves, the account Owner offboards them. Their past moderation actions remain in our records labeled "Former staff #<code>" so that enforcement history remains accurate without identifying the former staff member publicly.
11. Subprocessors
We use a limited number of subprocessors to host and operate the Service. The current list, including purpose, data processed, and location, is in Appendix A. We require each subprocessor to protect personal information and to use it only to provide services to us. We will update Appendix A before adding or replacing a subprocessor.
12. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption β Encryption in transit (TLS/HTTPS) and encryption at rest for our databases and file storage.
- Password protection β Passwords stored only as salted hashes; minimum length of 8 characters; breached passwords rejected.
- Multi-factor authentication β Optional for members using an authenticator app; mandatory for all Find Me staff.
- Access controls β Access to personal information limited to staff and subprocessors who need it, based on least privilege, with administrative actions recorded in audit logs.
- Monitoring β Logging and monitoring of systems to detect unauthorized access and abuse.
- Incident response β Documented procedures for investigating and responding to security incidents.
- Breach notification β If a data breach affects your personal information, we will notify you and the relevant regulators as required by applicable law (for example, within 72 hours to supervisory authorities under GDPR where required, and without unreasonable delay to affected individuals under U.S. state laws, including North Carolina's Identity Theft Protection Act).
No method of transmission or storage is completely secure. Please use a strong, unique password and enable MFA. If you believe your Account has been compromised, contact support@fyndme.net immediately.
13. International Data Transfers
Find Me LLC is based in the United States, and our subprocessors primarily process data in the United States; our marketing email provider, Brevo, processes data in the European Union. If you use the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may not provide the same level of protection as your home country.
When we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as:
- The European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA), entered into with our subprocessors.
Find Me LLC is not certified under the EU-U.S. Data Privacy Framework. Transfers rely on SCCs and the UK Addendum. You may request a copy of the relevant safeguards by emailing support@fyndme.net.
14. Your Privacy Rights
Your rights depend on where you live. We extend the core rights of access, correction, deletion, and data portability to all members regardless of location.
14.1 EEA, UK, and Switzerland
You have the right to:
- Access β Obtain confirmation of whether we process your personal data and a copy of it.
- Rectification β Correct inaccurate or incomplete data.
- Erasure β Request deletion of your data, subject to legal exceptions (see Sections 7 and 9).
- Restriction β Ask us to limit processing in certain circumstances.
- Portability β Receive data you provided to us in a structured, commonly used, machine-readable format (JSON via "Download my data") and have it transmitted to another controller where technically feasible.
- Objection β Object to processing based on legitimate interests, including the anti-abuse fingerprint. You have an absolute right to object to direct marketing: members in the EEA, UK, and Switzerland receive marketing emails only if they opt in, we do not send marketing emails to non-members there, and anyone can unsubscribe at any time.
- Withdraw consent β At any time, where processing is based on consent, without affecting prior processing.
- Automated decisions β Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects (see Section 8).
- Complain β Lodge a complaint with your local data protection authority (for example, in the EEA, the supervisory authority in your country of residence or work; in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner). We encourage you to contact us first so we can try to resolve your concern.
14.2 California (CCPA/CPRA)
This section applies to California residents and supplements the rest of this policy.
Personal information we collect (last 12 months and going forward)
| Category of personal information (Cal. Civ. Code Β§ 1798.140) | Examples | Source | Business purpose | Recipients (service providers/contractors) | Retention |
|---|---|---|---|---|---|
| Identifiers | Name, email address, username, phone number, IP address, account ID, Google/Apple account ID, Apple private relay email | You; your device; Google/Apple sign-in; for non-member business contacts, LinkedIn and our earlier email campaigns | Provide the Service; verification; security; support; communications; marketing emails (members who opt in; U.S. business contacts) | Supabase, Cloudflare, Resend, Microsoft 365, Google, Apple; Brevo (marketing emails) | While Account is active; removed within minutes of deletion (IP in logs: 12 months) |
| Customer records (Cal. Civ. Code Β§ 1798.80(e)) | Name, email, phone, limited payment info (when launched) | You; Stripe | Provide the Service; billing | Supabase, Stripe | Account life; billing records 7 years |
| Characteristics of protected classifications | Age attestation (18+ only; no date of birth) | You | Confirm eligibility | Supabase | While Account is active |
| Commercial information | Plan status, free access period, referral credits, transactions (when launched) | You; our systems; Stripe | Plan administration; billing; anti-abuse | Supabase, Stripe | Account life; billing records 7 years |
| Biometric information | Biometric templates β not currently collected (Face Discovery disabled) | You, only with separate consent, if launched | Face Discovery only | Supabase (storage) | Deleted immediately on opt-out or deletion |
| Internet or other electronic network activity | Pages and features used, sign-in events, sessions, crash logs, browser and device data | Your device; our systems | Security; fraud prevention; debugging; service improvement | Cloudflare, Supabase | 12 months; sessions removed within minutes of deletion |
| Geolocation data | Approximate location derived from IP address | Your device | Security; providing the Service | Cloudflare, Supabase | Logs: 12 months; uploads removed within minutes of deletion |
| Audio, electronic, visual, or similar information | Photos and media you upload; attachments to support tickets | You | Provide the Service; support | Supabase, Microsoft 365 | Uploads: until deleted; support tickets: 24 months after resolution |
| Professional or employment-related information | Information you choose to include in Profiles or Portfolios (if any) | You | Provide the Service | Supabase | Until deleted; removed within minutes of Account deletion |
| Inferences | None | β | β | β | β |
| Sensitive personal information | Account login credentials (hashed password, MFA secret); biometric information (only if Face Discovery launches, with consent) | You; your device | Authentication and security; Face Discovery (if launched) | Supabase | Removed within minutes of Account deletion; biometric data deleted immediately on opt-out |
| Pseudonymized anti-abuse fingerprint (Identifiers) | HMAC of verified email/phone | Derived by us | Preventing repeat free months and referral rewards | Supabase | Indefinitely, including after deletion |
| Support communications (Identifiers; audio/electronic information) | Tickets, emails, attachments; signed-out access help email and claimed username | You | Support | Microsoft 365, Supabase | 24 months after resolution; access help: 30 days after close |
| Consent receipts (Internet activity) | Cookie choices, GPC detection, Face Discovery consent (if launched) | You; your browser | Demonstrating compliance | Supabase | Duration of consent plus 3 years |
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16. We disclose each category above to service providers and contractors for business purposes only, and may disclose any category to legal authorities as described in Section 10.
Your California rights
- Right to know and access β Request the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients.
- Right to delete β Request deletion of personal information, subject to legal exceptions (for example, security, anti-abuse, and legal obligations described in Sections 7 and 9).
- Right to correct β Request correction of inaccurate personal information.
- Right to opt out of sale or sharing β We do not sell or share personal information, so there is nothing to opt out of. We still honor opt-out requests and Global Privacy Control signals (Sections 18 and 19).
- Right to limit use of sensitive personal information β We use sensitive personal information only for purposes permitted under Cal. Code Regs. tit. 11, Β§ 7027(m) (such as providing the Service you request and security), so the right to limit does not apply. If Face Discovery launches, biometric information will be used only with your consent and only for that feature.
- Right to non-discrimination β We will not deny you service, charge different prices, or provide a different quality of service because you exercised your privacy rights.
- Authorized agents β You may use an authorized agent to submit requests on your behalf (see Section 15).
- Financial incentives β The Referral Program is a financial incentive under the CCPA/CPRA. For details, including the estimated value and how to opt in or withdraw, see the California Notice of Financial Incentive in our Terms of Service (Section 9.4(7)). The incentive is not conditioned on the sale or sharing of your personal information β it rewards you for introducing new members, and the only personal information involved is what is required to create and verify an Account.
Shine the Light (Cal. Civ. Code Β§ 1798.83): We do not disclose personal information to third parties for their direct marketing purposes.
14.3 Other U.S. states
Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, as applicable) may have rights to:
- Confirm whether we process their personal data and access it
- Correct inaccuracies
- Delete personal data
- Obtain a portable copy
- Opt out of sale, targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects (we do not engage in these activities)
- Consent before we process sensitive data (including biometric data)
- Appeal a decision on a privacy request by replying to our decision or emailing support@fyndme.net with the subject "Privacy Request Appeal." We will respond within the period required by law. If your appeal is denied, you may contact your state Attorney General.
Biometric privacy statutes. If Face Discovery launches, we will comply with applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code Β§ 503.001), Washington's biometric identifier law (RCW 19.375) and My Health My Data Act (RCW 19.373) to the extent applicable, and Colorado's biometric provisions (C.R.S. Β§ 6-1-1314). Section 6 serves as our publicly available written policy under these laws.
Nevada: We do not sell covered information as defined under Nevada law.
14.4 Brazil (LGPD)
If you are in Brazil, you have rights under the Lei Geral de ProteΓ§Γ£o de Dados (Law No. 13,709/2018), including confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, withdrawal of consent, and review of automated decisions. You may also file a complaint with the Autoridade Nacional de ProteΓ§Γ£o de Dados (ANPD). Our legal bases correspond to those in Section 5. Contact for our data protection officer (encarregado): Shabaan Hossain, support@fyndme.net.
14.5 Canada (PIPEDA)
If you are in Canada, you may request access to and correction of your personal information and withdraw consent (subject to legal or contractual restrictions). You may contact the Office of the Privacy Commissioner of Canada if you are not satisfied with our response. Residents of Quebec have additional rights under Law 25. Our privacy contact is reachable at support@fyndme.net.
14.6 India (DPDP Act)
If you are in India, you have rights under the Digital Personal Data Protection Act, 2023, including the right to access information about processing, correction and erasure, grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity.
Grievance Officer: Shabaan Hossain, Find Me LLC, 4111 Rose Lake Dr, Charlotte, NC 28217, USA β support@fyndme.net. We will respond to grievances within the period prescribed under the DPDP Act and its rules. If you are not satisfied, you may approach the Data Protection Board of India.
14.7 Other jurisdictions
If you live elsewhere, you may have similar rights under local law (for example, Australia, Japan, South Korea, Singapore, or Switzerland). Contact us at support@fyndme.net and we will respond in accordance with applicable law.
15. How to Exercise Your Rights
- Self-service download: Go to Settings β Download my data to receive a copy of your Account data in JSON format. The export includes your profile, portfolios, portfolio revisions, media file metadata (names, types, sizes β not the files themselves), shares, Terms/18+ records, and portfolio daily analytics. It does not include media files, contacts/follows, security tokens, or Face Discovery data. To request copies of your media files, email support@fyndme.net.
- Self-service deletion: Go to Settings β Delete account (see Section 9.3).
- Self-service correction: Update most Account and Profile information in Settings.
- Email: Send any request to support@fyndme.net. Please state the type of request and your jurisdiction, and send it from the email address associated with your Account if possible.
Response times. We respond within 30 days (or the shorter period required by local law), and within 45 days for California residents and residents of other U.S. states that provide a 45-day period. If we need more time, we may extend the period as permitted by law (for example, by up to two additional months under GDPR, or by an additional 45 days under the CCPA), and we will notify you of the extension and the reason within the original period.
Verification. To protect your information, we verify requests before acting on them, for example by confirming that you control the email address on the Account, requiring you to be signed in, or, for sensitive requests, requesting an emailed code or your authenticator code. We will only use information provided for verification to verify your request. Our "Forgot which email?" and account-access help processes never reveal whether an account exists for a given email address or username.
Authorized agents. You may designate an authorized agent to make a request on your behalf. We may require the agent to provide signed written permission from you or a valid power of attorney, and we may ask you to verify your identity directly with us or confirm that you gave the agent permission.
Cost. Requests are free. We may charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive, where permitted by law.
Denials. If we cannot fulfill a request, we will explain why (for example, a legal exception) and, where applicable, how to appeal.
16. Children's Privacy
The Service is for adults 18 years of age or older only. We do not knowingly collect personal information from anyone under 18. Every member must attest that they are 18 or older before using the Service. If we learn that a person under 18 has created an Account, we will terminate the Account and delete the associated personal information, subject only to the retention of safety and enforcement records with identity removed as described in Section 9. If you believe a minor has provided us personal information, please contact support@fyndme.net.
18. Do Not Sell or Share My Personal Information
Find Me LLC does not sell your personal information and does not share it for cross-context behavioral advertising. We have no advertising partners and do not work with data brokers.
- GPC: We honor Global Privacy Control signals automatically as an opt-out request.
- Formal request: If you would like written confirmation, or to submit a formal opt-out request, email support@fyndme.net with the subject "Do Not Sell or Share." You do not need an Account to submit this request.
- Authorized agents: An authorized agent may submit a request on your behalf as described in Section 15.
If our practices ever change, we will update this policy and provide any notice and opt-out mechanisms required by law before any sale or sharing occurs.
19. Global Privacy Control
Global Privacy Control (GPC) is a browser setting or extension that tells websites you do not want your personal information sold or shared. When we detect a GPC signal:
- We treat it as a valid opt-out of sale and sharing for that browser and, if you are signed in, for your Account.
- We keep non-essential cookies (Functional and Analytics) off for that browser.
- We record the signal in your consent receipt.
- If you previously chose "Accept All," the GPC signal takes priority for opt-out purposes. GPC overrides a prior "Accept All" for that browser; optional cookies turn off.
Because we do not sell or share personal information, GPC does not change how the core Service works for you.
20. Changes to This Policy
We may update this Privacy Policy from time to time. Each version is dated and numbered. If we make material changes, we will notify you by email (from no-reply@fyndme.net) and/or by a notice in the Service before the changes take effect. We will not use previously collected information in a materially different way without your consent where the law requires it. Face Discovery will not launch without separate notice and separate consent. Previous versions are available on request.
21. Contact
Find Me LLC
4111 Rose Lake Dr
Charlotte, NC 28217
United States
Email: support@fyndme.net
Privacy requests: support@fyndme.net
India Grievance Officer: Shabaan Hossain β support@fyndme.net
Brazil encarregado: Shabaan Hossain β support@fyndme.net
EU/UK representative: To be appointed β support@fyndme.net meanwhile
Copyright (DMCA) designated agent: Shabaan Hossain, Find Me LLC, 4111 Rose Lake Dr, Charlotte, NC 28217 β dmca@fyndme.net (see /terms)
Appendix A: Subprocessors
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting and content delivery network (CDN); security and bot protection | IP address, request data (URL, headers, device and browser information) | United States (global edge network) |
| Supabase, Inc. | Database, authentication, and file storage | Account data, profile content, portfolios, uploads, sessions, MFA data, anti-abuse fingerprints, consent receipts | United States (us-east-1) |
| Resend, Inc. | Transactional email delivery (from no-reply@fyndme.net) | Email address, email content (e.g., verification codes, account notices) | United States |
| Microsoft Corporation (Microsoft 365) | Support email | Support communications, attachments, sender email addresses | United States |
| Google LLC (Google Analytics) | Website analytics, only if you allow Analytics cookies | Pseudonymous browser identifier (_ga cookies), pages viewed, sign-up and checkout events, device and browser information, approximate location from an anonymized IP address. No name, email address or account identifier | United States |
| Google LLC | Sign-in (Google Sign-In) | Email address, name, profile photo, Google account identifier | United States |
| Apple Inc. | Sign-in (Sign in with Apple) | Email address (or Apple private relay address), name, Apple account identifier | United States |
| Sendinblue SAS (Brevo) | Marketing email delivery to members who opt in and to U.S. business and professional contacts (Section 4, item 10) | Name and email address; for members also username, profile role, profile photo link (or illustrated character), and opt-in status and date; unsubscribe status; and whether an email was delivered or opened and which links were clicked | European Union (France) |
| Stripe, Inc. | Payment processing | Payment data (card details held by Stripe; last four digits, expiration, billing country shared with us), transaction data, email | United States |
Any biometric processing vendor for Face Discovery will be added here before that feature launches. If mobile apps launch, Apple App Store and Google Play billing will be added here.
