Find Me

Legal

Find Me Privacy Policy

Version 1.0 Β· Effective October 5, 2026

This Privacy Policy explains how Find Me LLC collects, uses, shares, retains, and protects personal information when you use Find Me. It also contains our Cookies and Tracking Policy (Section 17), our Biometric Data Policy (Section 6), our "Do Not Sell or Share" notice (Section 18), and our list of subprocessors (Appendix A).

You do not need to "accept" this Privacy Policy. We ask you to read it so you understand how your information is handled. Our Terms of Service, which you do accept, are available at /terms.

1. Introduction

1.1 What this policy covers

This policy applies to the Find Me website, web application, and related services, including account creation, profiles, portfolios, uploads, sharing, support, and billing (collectively, the "Service"). It applies to members, visitors to our website, people who contact our support team, and people whose information appears in content submitted to the Service.

1.2 Who we are

The Service is operated by:

Find Me LLC
4111 Rose Lake Dr

Charlotte, NC 28217

United States

Email: support@fyndme.net

Find Me LLC ("Find Me," "we," "us," or "our") is the controller (or "business," under California law) responsible for your personal information as described in this policy.

An EU representative (GDPR Art. 27) and/or UK representative (UK GDPR Art. 27) may be required because we offer the Service to individuals in the EEA/UK. Our EU/UK representative is to be appointed. Until a representative is appointed, you may contact us directly at support@fyndme.net for all privacy matters, including those arising under the GDPR or UK GDPR.

1.3 How to contact us

For any privacy question or request, email support@fyndme.net. Automated account emails (such as verification codes and account notices) are sent from no-reply@fyndme.net; please do not reply to that address, as it is not monitored.

2. Definitions

  • Service β€” The Find Me website, web application, and related features and services operated by Find Me LLC.
  • Account β€” The registered Find Me membership you create using an email address and password, or through Google or Apple sign-in.
  • Profile β€” The information you provide when you sign up and set up your Account that identifies you on the Service: your name, username, occupation, bio, introduction, skills, and location (country, state or region, and city), and your profile color and verified badge. Your Profile is public (see Section 10).
  • Portfolio β€” A collection of content (such as photos, media, and descriptions) that you create and manage within your Account. Each plan allows a maximum number of published Portfolios: Basic β€” 1 Personal portfolio only; Standard β€” 1 Personal portfolio + 2 portfolios in any category (3 total); Advanced β€” unlimited portfolios in any category. When a plan is downgraded, your Personal portfolio is always kept published first; additional Portfolios beyond the new limit are paused (hidden, not deleted) and can be restored on upgrade. See /pricing and the Terms for details.
  • Face Discovery β€” A facial recognition feature that compares a face in a submitted image against the faces of members who have opted in (one-to-many, or "1:N," matching). Face Discovery is not currently available. It has been built but is disabled, and it will launch only after we give separate notice and obtain separate consent, as described in Section 6.
  • Biometric template β€” A mathematical representation (for example, a numerical vector) derived from the geometry of a face in an image, used to compare faces. A biometric template is considered biometric data, biometric identifiers, and/or biometric information under applicable law.
  • Account deletion β€” The permanent, irreversible removal of your Account and associated personal information, as described in Section 9.3.
  • Subprocessor β€” A third-party service provider that processes personal information on our behalf and under our instructions to help us operate the Service (listed in Appendix A).
  • Anti-abuse fingerprint β€” A pseudonymized value created by applying a keyed cryptographic hash function (HMAC) to a verified email address or phone number. It is used only to prevent repeat claims of free months and referral rewards, as described in Section 7.

3. Information We Collect

We collect the categories of information below. Some information you provide directly, some is collected automatically when you use the Service, and some is received from third parties you choose to use (such as Google or Apple sign-in).

3.1 Account data

  • Name
  • Email address
  • Username
  • Phone number (if provided or required for verification)
  • Password, stored only as a salted cryptographic hash (we never store your password in plain text). When you set a password, we check it against known lists of breached passwords and reject passwords that appear on those lists. Passwords must be at least 8 characters.
  • Multi-factor authentication (MFA) secret, if you enable an authenticator app (MFA is optional for members and mandatory for Find Me staff)
  • Account settings and preferences
  • Plan status (for example, Basic, free access period, referral credits)
  • Terms of Service acceptance record and 18+ age attestation, including the version accepted and the date and time recorded

3.2 Profile and portfolio content

  • Profile details from sign-up and profile setup: first and last name, display name, username, occupation, bio, introduction, skills, country, state or region, city, and profile color. These Profile details are always public and cannot be hidden (see Section 10). Your email address and phone number are not part of your public Profile.
  • Portfolios you create, including titles, descriptions, and category
  • Share settings and share links you create

3.3 Photos and media (including metadata)

  • Photos, images, and other media you upload
  • Metadata embedded in or associated with uploads, such as file name, file type, file size, dimensions, upload date, and, where present in the file, device information, date taken, and location (EXIF/GPS) data

We remove location and camera metadata (EXIF/GPS) from photos on upload. File name, type, size, dimensions, and upload date are retained.

3.4 Support communications

  • Feedback and support tickets you submit, including message content and any attachments
  • Emails you send to support@fyndme.net
  • Signed-out "Account access help" requests, including the reply-to email address you provide and the username you claim
  • Records of our responses and ticket status

3.5 Usage and device data

  • IP address
  • Device type, operating system, and browser type and version
  • Pages and features accessed, and date and time of access
  • Referring URL
  • Crash logs, error reports, and diagnostic information
  • Session and security logs (for example, sign-in events, sign-in location approximated from IP address, and active sessions)

3.6 Sign-in data (Google and Apple)

If you sign in with Google or Apple, we receive information from that provider, such as:

  • A unique identifier for your account with that provider
  • Authentication tokens required to sign you in
  • Your email address and name (and, for Google, a profile photo if made available)
  • Apple private relay: If you choose "Hide My Email" when using Sign in with Apple, we receive a private relay email address generated by Apple instead of your real email address. Emails we send to that address are forwarded to you by Apple. We do not receive your underlying email address.

3.7 Payment data

Payments are processed by Stripe. We will not receive or store your full card number or security code. We may receive and store limited payment information from Stripe, such as:

  • Card brand, last four digits, and expiration date
  • Billing country (and postal code, if required for tax or fraud purposes)
  • Transaction history, plan, amount, currency, and payment status

If Find Me mobile apps launch and you purchase through the Apple App Store or Google Play, those companies will process your payment under their own privacy policies, and we will receive only purchase and subscription status information.

3.8 Anti-abuse fingerprint

A pseudonymized HMAC value derived from your verified email address and/or verified phone number. See Section 7.

3.9 Email verification data

  • One-time verification codes or tokens sent to your email address
  • The time a verification email was sent and whether and when the address was confirmed
  • Records of your cookie choices (including whether a Global Privacy Control signal was detected), and, if Face Discovery launches, your separate Face Discovery consent and any withdrawal
  • Your marketing email choice: whether you opted in, the date and time of your choice, and the version of the consent text you saw; and the date and time you unsubscribed, if you do
  • For each consent receipt: the choice made, the policy or notice version presented, the date and time, and a pseudonymous identifier linking the choice to your browser or Account

3.11 Biometric data

We do not currently collect biometric data. Face Discovery is disabled. If it launches, biometric templates will be created only for members who give separate, express consent, as described in Section 6.

3.12 Marketing contacts who are not members

  • Name and email address of business and professional contacts in the United States who expressed interest in Find Me through LinkedIn or our earlier email campaigns, and whether they unsubscribed
  • Whether our marketing emails to them were delivered or opened and which links were clicked

3.13 Information we do not collect

We do not use advertising identifiers, we do not use advertising cookies, and we do not buy personal information from data brokers.

4. How We Use Your Information

We use personal information only for the following purposes:

  1. Provide the Service β€” Create and maintain your Account, host your Profile and Portfolios, store and display your uploads, enable sharing, and remember your settings.
  2. Verify your email β€” Confirm that you control the email address you signed up with. Email verification is required before you can use the Service. Unconfirmed signups are automatically deleted after 30 minutes.
  3. Record Terms acceptance and age attestation β€” After your Account is created, record your acceptance of the Terms of Service and your attestation that you are 18 or older (including the version accepted) before you can use the Service.
  4. Security and fraud prevention β€” Authenticate you, support MFA, reject breached passwords, detect suspicious sign-ins, prevent unauthorized access, and protect the Service and our members.
  5. Content moderation β€” Detect, review, and act on content or conduct that violates our Terms of Service, including through our enforcement ladder and appeals process.
  6. Human portfolio review β€” Have trained staff review portfolios, including when content is reported or flagged.
  7. Anti-abuse β€” Prevent repeat claims of the free access period and referral rewards using the anti-abuse fingerprint (Section 7).
  8. Plans, free access, and referrals β€” Administer the Basic plan, the 3-month free access period, and referral credits, and (when launched) paid plans and billing.
  9. Communications β€” Send you service messages such as verification codes, security alerts, account deletion notices, plan changes, responses to support tickets, and notices of changes to our Terms or this policy.
  10. Marketing emails β€” We send product news and updates by email to members who opt in, and to business and professional contacts in the United States whose email addresses we collected from people who expressed interest in Find Me through LinkedIn and our earlier email campaigns. Members opt in with the marketing email box at signup or in Settings β†’ Notifications; the box is unchecked by default and opting in is never required to use the Service. We use Brevo to send these emails; Brevo processes your name, email address and, for members, the profile details described in Appendix A on our behalf. Our emails may record whether they were opened and which links were clicked, so we can improve them. Every marketing email includes a one-click unsubscribe link, or you can email support@fyndme.net; members can also turn marketing emails off in Settings β†’ Notifications. We honor unsubscribe requests within 10 business days and never sell your email address. Unsubscribing does not affect service messages.
  11. Support β€” Respond to Feedback, Support tickets, email inquiries, and signed-out "Account access help" requests.
  12. Improve and maintain the Service β€” Diagnose errors and crashes, maintain performance, and understand how features are used in aggregate.
  13. Legal compliance β€” Comply with applicable laws, respond to lawful requests, enforce our Terms, and establish, exercise, or defend legal claims.

What we do not do:

  • We do not show advertising on the Service or use your information for targeted or cross-context behavioral advertising.
  • We do not sell your personal information.
  • We do not "share" your personal information as that term is defined under California law (sharing for cross-context behavioral advertising).
  • We do not use your content or biometric data to train or tune any AI models, whether internal or third-party.

6. Face Discovery (Biometric Data)

Face Discovery is not currently available. It has been built but is disabled, and it will launch only after we give separate notice. We do not currently collect, create, store, or use biometric data. This section describes how Face Discovery would work if launched, and serves as our public biometric data policy, including our retention schedule and destruction guidelines.

6.1 What Face Discovery would do

Face Discovery is a one-to-many ("1:N") facial recognition feature. When a scan is submitted, the Service would detect a face in the image, create a biometric template from it, and compare that template against the biometric templates of members who have opted in to be discoverable. If a likely match is found, the matching member's Profile could be shown.

  • Face Discovery will be off by default.
  • Consent to Face Discovery will be requested separately from the Terms of Service and this Privacy Policy. It will not be bundled with signup or any other agreement, and using the rest of the Service will never depend on consenting to Face Discovery.
  • Before any biometric template is created, you will be shown a written notice describing (a) that biometric data is being collected, (b) the specific purpose, and (c) the length of time it will be retained, and you will be asked to provide a written release (for example, an electronic signature or affirmative "I consent" action) that we record as a consent receipt.
  • You can withdraw consent at any time in Settings (see Section 6.6).

6.3 Scanning other people

Face Discovery is not currently available. When it launches, the following rules will apply:

  1. Scan only yourself β€” You may only scan your own face (for example, with a liveness check).
  2. Consenting enrolled user only β€” You may scan another person only if that person is also a Find Me member who has personally completed the Face Discovery consent flow on their own device.
  3. Geographic restrictions β€” Face Discovery will not be offered in the EEA, UK, or Switzerland, and may be restricted in Illinois, Texas, Washington, and other jurisdictions with biometric privacy laws.

We will publish the final scan-consent rules in a separate Face Discovery notice before the feature launches.

6.4 How biometric data would be used and protected

  • Biometric templates would be used only to operate Face Discovery (matching faces against opted-in members).
  • We will never sell, lease, trade, or otherwise profit from biometric data.
  • We will never share or disclose biometric data to third parties for their own use. Biometric data will be disclosed only (a) to subprocessors acting on our behalf solely to operate Face Discovery, under contracts requiring equivalent protection; (b) with your consent; or (c) where required by law, a valid warrant, or subpoena.
  • Biometric data will be stored, transmitted, and protected using a reasonable standard of care within our industry, and in a manner that is the same as or more protective than how we protect other confidential and sensitive information, including encryption in transit and at rest and restricted access.
  • Scan images submitted for matching would not be retained after a template is generated and the match is completed.

6.5 Retention schedule and destruction guidelines

This retention schedule and these destruction guidelines are publicly available as required by 740 ILCS 14/15(a) and similar laws.

Biometric dataRetentionDestruction
Your biometric template(s) (discoverability)Only while Face Discovery is enabled on your AccountDeleted immediately when you withdraw consent, turn off Face Discovery, or delete your Account
Templates generated from a scan imageOnly for the duration of the matching operationDeleted immediately after matching completes
Scan imagesNot retained after matchingDeleted immediately after matching completes
Biometric data of an Account that becomes inactive12 monthsDeleted at the end of the inactivity period

In all cases, biometric data will be permanently destroyed no later than the earliest of: (a) when the initial purpose for collecting it has been satisfied; (b) when you withdraw consent or delete your Account; or (c) within the maximum period permitted by applicable law β€” 3 years after your last interaction with Find Me under Illinois law, and within 1 year after the purpose expires under Texas law, or any shorter period required by law. Destruction means permanent deletion from active systems. Backups containing biometric data will be overwritten or purged within 7 days and will not be restored for any purpose other than disaster recovery, after which deletions will be reapplied.

You can turn off Face Discovery at any time in Settings. When you do, your biometric templates are deleted immediately and your Profile is no longer discoverable through Face Discovery. You may turn it back on later by giving consent again.

6.7 Regulatory status

Remote biometric identification systems are listed as high-risk under Annex III of the EU AI Act (Regulation (EU) 2024/1689). Before Face Discovery is offered in the EEA, we will complete a GDPR Article 35 Data Protection Impact Assessment and any required conformity assessment and registration under the EU AI Act. Face Discovery will not launch in the EEA, UK, or Switzerland until these assessments are complete.

7. Anti-Abuse Fingerprint (HMAC)

To prevent people from repeatedly claiming the 3-month free access period or referral rewards (for example, by deleting and recreating accounts), we create an anti-abuse fingerprint.

  • What it is: When you verify an email address or phone number, we apply a keyed cryptographic hash function (HMAC) using a secret key kept separately from the fingerprint. The result is a fixed-length value that does not reveal your email address or phone number on its face.
  • Pseudonymized, not anonymized: Because we could determine whether a given email address or phone number matches a stored fingerprint by computing its HMAC, the fingerprint is pseudonymized personal data, not anonymized data. We treat it as personal information.
  • Purpose: Used only to determine whether a verified email address or phone number has previously received free access months or referral rewards. It is not used for advertising, profiling, or any other purpose.
  • Retention: Kept indefinitely, including after Account deletion. If it were deleted, the free access and referral limits could be bypassed by deleting and recreating an account.
  • Legal basis (EEA/UK): Legitimate interests in preventing abuse of free offers and ensuring they remain fair and available. You may object (Section 14.1); we will consider your objection but may continue processing where we have compelling legitimate grounds.
  • Not sold or shared: The fingerprint is never sold, shared, or disclosed to third parties except to subprocessors hosting our database.
  • Rejoining: If you delete your Account, you may create a new one later. However, free access months and referral rewards already received will not restart.

8. Automated Decision-Making

We use automated tools in limited ways:

  • Ranking β€” Search results are sorted by location proximity to you (city, then state, then country), then by followers, then by connections. We do not use personalized feeds or profiling.
  • Fraud and security detection β€” Flagging suspicious sign-ins, breached passwords, and patterns associated with abuse (including anti-abuse fingerprint matches).
  • Content moderation β€” Automated tools may help flag content for review.

No solely automated decisions with legal or similarly significant effects. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Enforcement actions such as removing portfolios, restricting, suspending, or deleting Accounts involve human review. Automated fraud checks may temporarily block an action (for example, a sign-in attempt or a duplicate free-month claim); you may request human review of any such decision by emailing support@fyndme.net or using our appeals process.

Where applicable law gives you the right to not be subject to solely automated decisions, to obtain human intervention, to express your point of view, and to contest a decision, you may exercise those rights by contacting us.

9. Data Retention

9.1 General principle

We keep personal information only as long as needed for the purposes described in this policy, then delete it. We do not keep records for a general fixed period and then "anonymize" them; each category has its own retention rule below.

9.2 Retention table

CategoryRetention period
Unconfirmed signups (email never verified)Automatically deleted 30 minutes after signup
Email verification tokens/codesExpire and are deleted 30 minutes after issue (or on use)
Account data (name, email, username, phone, hashed password)While your Account is active; removed within minutes of Account deletion
Profile and PortfoliosWhile your Account is active; removed within minutes of Account deletion
Photos, media, and uploads (including metadata)Until you delete them or your Account; removed within minutes of Account deletion
Shares and share linksUntil you revoke them or delete your Account; removed within minutes of Account deletion
Sessions and login recordsWhile active; removed within minutes of Account deletion
MFA secretsUntil you disable MFA or delete your Account; removed within minutes of Account deletion
Terms acceptance and 18+ attestation recordsWhile your Account is active; deleted with the Account
Biometric templates (if Face Discovery launches)Deleted immediately on opt-out, consent withdrawal, or Account deletion (see Section 6.5)
Anti-abuse fingerprint (HMAC)Indefinitely, including after Account deletion (see Section 7)
Safety and enforcement records (e.g., reports, moderation decisions, enforcement history, appeals)Retained after Account deletion with your identity removed for 3 years after the last related action
Staff moderation action recordsIndefinitely; after a staff member is offboarded, their past actions are labeled "Former staff #<code>"
Admin-initiated account deletion audit records (recorded reason and audit entry)3 years
Support tickets (Feedback and Support, including attachments)24 months after resolution
Signed-out "Account access help" requests (reply-to email and claimed username)Purged 30 days after the ticket is closed
Consent receipts (cookies; Face Discovery if launched)Duration of consent plus 3 years
Cookie consent choiceUp to 12 months, after which we ask again (see Section 17)
Other cookiesSee the cookie retention table in Section 17.10
Billing and transaction records7 years after the transaction, for tax and accounting obligations
Security and server logs (IP, device, request data)12 months
Crash and error logs90 days
Analytics data (Google Analytics, only if you allow Analytics cookies)Up to 14 months in Google Analytics, then deleted automatically
Notifications12 months
Marketing email choice and consent record (opt-in and opt-out dates, consent text version)While your Account is active; removed within minutes of Account deletion. Your contact record at Brevo is deleted within 30 days of opting out or deleting your Account
Marketing contacts who are not membersUntil they unsubscribe or ask us to delete their information; after that we keep only the email address on a do-not-email list so we never email it again
BackupsDaily backups retained 7 days, then overwritten; deleted data is not restored to active systems except for disaster recovery, after which deletions are reapplied

We may retain information longer where required by law or where necessary to establish, exercise, or defend legal claims (for example, under a legal hold), and only for as long as that need lasts.

9.3 Deleting your Account

You can delete your Account at any time:

  1. Go to Settings β†’ Delete account.
  2. Type the confirmation phrase "DELETE MY FIND ME ACCOUNT".
  3. Enter the code we email to you.

If you use an authenticator app, you must be signed in with it to delete your Account.

When you confirm:

  • Your access is revoked immediately.
  • Your Profile, Portfolios, uploads, shares, sessions, login records, and MFA settings are removed within minutes.
  • There is no grace period, and deletion is irreversible. We cannot restore a deleted Account.
  • Safety and enforcement records are kept with your identity removed.
  • The anti-abuse fingerprint is kept as described in Section 7.
  • Billing records are kept as required by law.
  • Any active subscription is canceled.

If you want a copy of your data, use Download my data in Settings before deleting your Account.

9.4 Deletion by Find Me LLC

Find Me administrators may delete a member Account, for example for serious or repeated violations of our Terms. Each such deletion requires a recorded reason and creates an audit record. We will email the member a notice of the deletion. The same removal and retention rules in Section 9.3 apply.

9.5 Staff accounts

Find Me staff cannot delete their own staff accounts. When a staff member leaves, the account Owner offboards them. Their past moderation actions remain in our records labeled "Former staff #<code>" so that enforcement history remains accurate without identifying the former staff member publicly.

10. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:

  • Your public Profile, to anyone β€” Every member has a public Profile page (at fyndme.net/u/ followed by your username). Your Profile details (first and last name, display name, username, occupation, bio, introduction, skills, country, state or region, city, profile color, and verified badge) are always public. They are visible to anyone, including people who are not signed in, can be found through Find Me's people search by name or username, and may appear in search engine results (we allow search engines to index Profiles and list them in our sitemap). You cannot hide your Profile while your Account is active. Search engines and others may keep copies we do not control; removal from third-party search results after you delete your Account depends on those services. Your email address and phone number are never shown on your public Profile, in search results, or in our sitemap. If you block a member, that member can no longer see your Profile or find you in search while signed in.
  • Portfolios, at your direction β€” Each Portfolio is public only while you keep it published; you can hide or show each Portfolio individually. Portfolios you share or publish are visible to the people you share them with or, if public, to anyone. Only approved, published Portfolios are shown. Turning off Face Discovery (once available) affects only Face Discovery matching; it does not hide your Profile.
  • Other sharing at your direction β€” Content you choose to share (for example, share links) is visible to the people you share it with.
  • Subprocessors β€” Service providers that process information on our behalf under written contracts that restrict their use of it (see Section 11 and Appendix A).
  • Sign-in providers β€” If you use Google or Apple sign-in, those providers exchange authentication information with us under their own privacy policies.
  • Legal authorities and legal process β€” When we believe in good faith that disclosure is required by law, subpoena, court order, or other legal process, or is necessary to protect the rights, property, or safety of Find Me, our members, or others, including to respond to emergencies involving risk of death or serious physical injury.
  • With your consent β€” When you direct or consent to a disclosure.
  • Corporate transactions β€” In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, subject to this policy's commitments. We will notify you before your personal information becomes subject to a materially different privacy policy. Biometric data will not be transferred as part of a corporate transaction except as permitted by applicable biometric privacy laws.
  • Aggregated or de-identified information β€” Information that cannot reasonably be used to identify you, such as overall usage statistics. We will maintain and use de-identified information only in de-identified form and will not attempt to re-identify it, except as permitted by law.

11. Subprocessors

We use a limited number of subprocessors to host and operate the Service. The current list, including purpose, data processed, and location, is in Appendix A. We require each subprocessor to protect personal information and to use it only to provide services to us. We will update Appendix A before adding or replacing a subprocessor.

12. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption β€” Encryption in transit (TLS/HTTPS) and encryption at rest for our databases and file storage.
  • Password protection β€” Passwords stored only as salted hashes; minimum length of 8 characters; breached passwords rejected.
  • Multi-factor authentication β€” Optional for members using an authenticator app; mandatory for all Find Me staff.
  • Access controls β€” Access to personal information limited to staff and subprocessors who need it, based on least privilege, with administrative actions recorded in audit logs.
  • Monitoring β€” Logging and monitoring of systems to detect unauthorized access and abuse.
  • Incident response β€” Documented procedures for investigating and responding to security incidents.
  • Breach notification β€” If a data breach affects your personal information, we will notify you and the relevant regulators as required by applicable law (for example, within 72 hours to supervisory authorities under GDPR where required, and without unreasonable delay to affected individuals under U.S. state laws, including North Carolina's Identity Theft Protection Act).

No method of transmission or storage is completely secure. Please use a strong, unique password and enable MFA. If you believe your Account has been compromised, contact support@fyndme.net immediately.

13. International Data Transfers

Find Me LLC is based in the United States, and our subprocessors primarily process data in the United States; our marketing email provider, Brevo, processes data in the European Union. If you use the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may not provide the same level of protection as your home country.

When we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as:

  • The European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA), entered into with our subprocessors.

Find Me LLC is not certified under the EU-U.S. Data Privacy Framework. Transfers rely on SCCs and the UK Addendum. You may request a copy of the relevant safeguards by emailing support@fyndme.net.

14. Your Privacy Rights

Your rights depend on where you live. We extend the core rights of access, correction, deletion, and data portability to all members regardless of location.

14.1 EEA, UK, and Switzerland

You have the right to:

  • Access β€” Obtain confirmation of whether we process your personal data and a copy of it.
  • Rectification β€” Correct inaccurate or incomplete data.
  • Erasure β€” Request deletion of your data, subject to legal exceptions (see Sections 7 and 9).
  • Restriction β€” Ask us to limit processing in certain circumstances.
  • Portability β€” Receive data you provided to us in a structured, commonly used, machine-readable format (JSON via "Download my data") and have it transmitted to another controller where technically feasible.
  • Objection β€” Object to processing based on legitimate interests, including the anti-abuse fingerprint. You have an absolute right to object to direct marketing: members in the EEA, UK, and Switzerland receive marketing emails only if they opt in, we do not send marketing emails to non-members there, and anyone can unsubscribe at any time.
  • Withdraw consent β€” At any time, where processing is based on consent, without affecting prior processing.
  • Automated decisions β€” Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects (see Section 8).
  • Complain β€” Lodge a complaint with your local data protection authority (for example, in the EEA, the supervisory authority in your country of residence or work; in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner). We encourage you to contact us first so we can try to resolve your concern.

14.2 California (CCPA/CPRA)

This section applies to California residents and supplements the rest of this policy.

Personal information we collect (last 12 months and going forward)

Category of personal information (Cal. Civ. Code Β§ 1798.140)ExamplesSourceBusiness purposeRecipients (service providers/contractors)Retention
IdentifiersName, email address, username, phone number, IP address, account ID, Google/Apple account ID, Apple private relay emailYou; your device; Google/Apple sign-in; for non-member business contacts, LinkedIn and our earlier email campaignsProvide the Service; verification; security; support; communications; marketing emails (members who opt in; U.S. business contacts)Supabase, Cloudflare, Resend, Microsoft 365, Google, Apple; Brevo (marketing emails)While Account is active; removed within minutes of deletion (IP in logs: 12 months)
Customer records (Cal. Civ. Code Β§ 1798.80(e))Name, email, phone, limited payment info (when launched)You; StripeProvide the Service; billingSupabase, StripeAccount life; billing records 7 years
Characteristics of protected classificationsAge attestation (18+ only; no date of birth)YouConfirm eligibilitySupabaseWhile Account is active
Commercial informationPlan status, free access period, referral credits, transactions (when launched)You; our systems; StripePlan administration; billing; anti-abuseSupabase, StripeAccount life; billing records 7 years
Biometric informationBiometric templates β€” not currently collected (Face Discovery disabled)You, only with separate consent, if launchedFace Discovery onlySupabase (storage)Deleted immediately on opt-out or deletion
Internet or other electronic network activityPages and features used, sign-in events, sessions, crash logs, browser and device dataYour device; our systemsSecurity; fraud prevention; debugging; service improvementCloudflare, Supabase12 months; sessions removed within minutes of deletion
Geolocation dataApproximate location derived from IP addressYour deviceSecurity; providing the ServiceCloudflare, SupabaseLogs: 12 months; uploads removed within minutes of deletion
Audio, electronic, visual, or similar informationPhotos and media you upload; attachments to support ticketsYouProvide the Service; supportSupabase, Microsoft 365Uploads: until deleted; support tickets: 24 months after resolution
Professional or employment-related informationInformation you choose to include in Profiles or Portfolios (if any)YouProvide the ServiceSupabaseUntil deleted; removed within minutes of Account deletion
InferencesNoneβ€”β€”β€”β€”
Sensitive personal informationAccount login credentials (hashed password, MFA secret); biometric information (only if Face Discovery launches, with consent)You; your deviceAuthentication and security; Face Discovery (if launched)SupabaseRemoved within minutes of Account deletion; biometric data deleted immediately on opt-out
Pseudonymized anti-abuse fingerprint (Identifiers)HMAC of verified email/phoneDerived by usPreventing repeat free months and referral rewardsSupabaseIndefinitely, including after deletion
Support communications (Identifiers; audio/electronic information)Tickets, emails, attachments; signed-out access help email and claimed usernameYouSupportMicrosoft 365, Supabase24 months after resolution; access help: 30 days after close
Consent receipts (Internet activity)Cookie choices, GPC detection, Face Discovery consent (if launched)You; your browserDemonstrating complianceSupabaseDuration of consent plus 3 years

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16. We disclose each category above to service providers and contractors for business purposes only, and may disclose any category to legal authorities as described in Section 10.

Your California rights

  • Right to know and access β€” Request the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients.
  • Right to delete β€” Request deletion of personal information, subject to legal exceptions (for example, security, anti-abuse, and legal obligations described in Sections 7 and 9).
  • Right to correct β€” Request correction of inaccurate personal information.
  • Right to opt out of sale or sharing β€” We do not sell or share personal information, so there is nothing to opt out of. We still honor opt-out requests and Global Privacy Control signals (Sections 18 and 19).
  • Right to limit use of sensitive personal information β€” We use sensitive personal information only for purposes permitted under Cal. Code Regs. tit. 11, Β§ 7027(m) (such as providing the Service you request and security), so the right to limit does not apply. If Face Discovery launches, biometric information will be used only with your consent and only for that feature.
  • Right to non-discrimination β€” We will not deny you service, charge different prices, or provide a different quality of service because you exercised your privacy rights.
  • Authorized agents β€” You may use an authorized agent to submit requests on your behalf (see Section 15).
  • Financial incentives β€” The Referral Program is a financial incentive under the CCPA/CPRA. For details, including the estimated value and how to opt in or withdraw, see the California Notice of Financial Incentive in our Terms of Service (Section 9.4(7)). The incentive is not conditioned on the sale or sharing of your personal information β€” it rewards you for introducing new members, and the only personal information involved is what is required to create and verify an Account.

Shine the Light (Cal. Civ. Code Β§ 1798.83): We do not disclose personal information to third parties for their direct marketing purposes.

14.3 Other U.S. states

Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, as applicable) may have rights to:

  • Confirm whether we process their personal data and access it
  • Correct inaccuracies
  • Delete personal data
  • Obtain a portable copy
  • Opt out of sale, targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects (we do not engage in these activities)
  • Consent before we process sensitive data (including biometric data)
  • Appeal a decision on a privacy request by replying to our decision or emailing support@fyndme.net with the subject "Privacy Request Appeal." We will respond within the period required by law. If your appeal is denied, you may contact your state Attorney General.

Biometric privacy statutes. If Face Discovery launches, we will comply with applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code Β§ 503.001), Washington's biometric identifier law (RCW 19.375) and My Health My Data Act (RCW 19.373) to the extent applicable, and Colorado's biometric provisions (C.R.S. Β§ 6-1-1314). Section 6 serves as our publicly available written policy under these laws.

Nevada: We do not sell covered information as defined under Nevada law.

14.4 Brazil (LGPD)

If you are in Brazil, you have rights under the Lei Geral de ProteΓ§Γ£o de Dados (Law No. 13,709/2018), including confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, withdrawal of consent, and review of automated decisions. You may also file a complaint with the Autoridade Nacional de ProteΓ§Γ£o de Dados (ANPD). Our legal bases correspond to those in Section 5. Contact for our data protection officer (encarregado): Shabaan Hossain, support@fyndme.net.

14.5 Canada (PIPEDA)

If you are in Canada, you may request access to and correction of your personal information and withdraw consent (subject to legal or contractual restrictions). You may contact the Office of the Privacy Commissioner of Canada if you are not satisfied with our response. Residents of Quebec have additional rights under Law 25. Our privacy contact is reachable at support@fyndme.net.

14.6 India (DPDP Act)

If you are in India, you have rights under the Digital Personal Data Protection Act, 2023, including the right to access information about processing, correction and erasure, grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity.

Grievance Officer: Shabaan Hossain, Find Me LLC, 4111 Rose Lake Dr, Charlotte, NC 28217, USA β€” support@fyndme.net. We will respond to grievances within the period prescribed under the DPDP Act and its rules. If you are not satisfied, you may approach the Data Protection Board of India.

14.7 Other jurisdictions

If you live elsewhere, you may have similar rights under local law (for example, Australia, Japan, South Korea, Singapore, or Switzerland). Contact us at support@fyndme.net and we will respond in accordance with applicable law.

15. How to Exercise Your Rights

  • Self-service download: Go to Settings β†’ Download my data to receive a copy of your Account data in JSON format. The export includes your profile, portfolios, portfolio revisions, media file metadata (names, types, sizes β€” not the files themselves), shares, Terms/18+ records, and portfolio daily analytics. It does not include media files, contacts/follows, security tokens, or Face Discovery data. To request copies of your media files, email support@fyndme.net.
  • Self-service deletion: Go to Settings β†’ Delete account (see Section 9.3).
  • Self-service correction: Update most Account and Profile information in Settings.
  • Email: Send any request to support@fyndme.net. Please state the type of request and your jurisdiction, and send it from the email address associated with your Account if possible.

Response times. We respond within 30 days (or the shorter period required by local law), and within 45 days for California residents and residents of other U.S. states that provide a 45-day period. If we need more time, we may extend the period as permitted by law (for example, by up to two additional months under GDPR, or by an additional 45 days under the CCPA), and we will notify you of the extension and the reason within the original period.

Verification. To protect your information, we verify requests before acting on them, for example by confirming that you control the email address on the Account, requiring you to be signed in, or, for sensitive requests, requesting an emailed code or your authenticator code. We will only use information provided for verification to verify your request. Our "Forgot which email?" and account-access help processes never reveal whether an account exists for a given email address or username.

Authorized agents. You may designate an authorized agent to make a request on your behalf. We may require the agent to provide signed written permission from you or a valid power of attorney, and we may ask you to verify your identity directly with us or confirm that you gave the agent permission.

Cost. Requests are free. We may charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive, where permitted by law.

Denials. If we cannot fulfill a request, we will explain why (for example, a legal exception) and, where applicable, how to appeal.

16. Children's Privacy

The Service is for adults 18 years of age or older only. We do not knowingly collect personal information from anyone under 18. Every member must attest that they are 18 or older before using the Service. If we learn that a person under 18 has created an Account, we will terminate the Account and delete the associated personal information, subject only to the retention of safety and enforcement records with identity removed as described in Section 9. If you believe a minor has provided us personal information, please contact support@fyndme.net.

17. Cookies and Tracking

17.1 What cookies and similar technologies are

Cookies are small text files placed on your device by a website. Similar technologies include local storage, session storage, and pixels. We use these technologies to keep you signed in, keep the Service secure, and remember your choices. In this section, "cookies" refers to all of these technologies.

17.2 Types of cookies we use

TypePurposeConsent required?Default
EssentialSign-in and session management, security (including bot and abuse protection), load balancing, remembering your cookie choices, and delivering features you ask for (your language, saved portfolio drafts, your security, privacy and notification settings, dismissed tips, and crediting the referral link you clicked). The Service cannot function without these.No (strictly necessary)Always on
FunctionalOptional preferences that are not needed to deliver a feature you asked for. We do not currently use any functional cookies. Not in use; update this row if functional cookies are added.YesOff
AnalyticsUnderstanding how the Service is used in aggregate (pages viewed, sign-up and checkout steps) using Google Analytics 4. Only used if you allow Analytics cookies. We turn off Google's advertising features and do not send your name, email address or account identifiers to Google Analytics.YesOff

17.3 No advertising cookies

We do not use advertising, targeting, retargeting, or social media tracking cookies, and we do not allow third parties to place such cookies through the Service.

17.4 Third-party cookies and technologies

Some cookies are set by our service providers when they deliver parts of the Service:

  • Cloudflare β€” Essential security and performance cookies (for example, bot detection and traffic management).
  • Supabase β€” Essential authentication and session storage (for example, tokens stored in cookies or local storage to keep you signed in).
  • Google Sign-In and Sign in with Apple β€” Cookies set by Google or Apple on their own domains when you choose to sign in with them, governed by their privacy policies.
  • Resend β€” Used to deliver service emails. We do not use tracking pixels or link tracking in emails. We have disabled open and click tracking in our email provider.
  • Stripe β€” Essential cookies for fraud prevention and secure payment processing on checkout pages.
  • Google Analytics β€” Only if you allow Analytics cookies. Google Analytics 4 (Google LLC) sets the _ga and _ga_<id> cookies on our domain and receives page views and sign-up and checkout events. We use it with Google's advertising features and advertising signals turned off and with IP anonymization on, and we do not send your name, email address or account identifiers. It is not loaded if you choose Essential Only, before you make a choice, or when your browser sends a Global Privacy Control signal. If you later turn Analytics off, we stop sending data and remove the cookies.
  • When you first visit, a cookie banner lets you choose Accept All, Essential Only, or Manage Preferences.
  • Non-essential cookies (Functional and Analytics) are off until you consent.
  • You can change your choices at any time using the Cookie preferences link in the site footer or in Settings. Withdrawing consent is as easy as giving it.
  • We keep a consent receipt of your choice (see Section 3.10).

17.6 Global Privacy Control

If your browser sends a Global Privacy Control (GPC) signal, we treat it as a valid request to opt out of sale and sharing and to decline non-essential cookies for that browser, and we record it in your consent receipt. See Section 19.

17.7 Do Not Track

There is no uniform standard for "Do Not Track" (DNT) browser signals, so we do not respond to DNT. We honor GPC instead, and we do not engage in cross-site tracking.

We ask you to review your cookie choices every 12 months, and sooner if we materially change the cookies we use.

17.9 Browser controls

Most browsers let you view, block, and delete cookies in their settings. Blocking essential cookies will prevent you from signing in or using parts of the Service. Guides are available from your browser provider (for example, Chrome, Safari, Firefox, and Edge help pages).

All cookies and storage are first-party (set on our own domain, including the Google Analytics cookies described below). We do not use third-party cookies. Cloudflare does not set cookies on our behalf. Items marked "requested feature" are strictly necessary to deliver something you asked for, so they do not need your consent.

Cookie / storage itemTypePurposeRetention
sb-<project>-auth-token (Supabase session)EssentialKeep you signed inUntil sign-out or expiry
OAuth code-verifierEssentialSecure Google/Apple sign-in flowMinutes (during sign-in only)
fyndme-password-recoveryEssentialPassword reset flow15 minutes
fyndme-password-recovery-apiEssentialPassword reset flow (submitting the new password)15 minutes
fyndme-signup-originEssentialRemember where to send you after you confirm your email (post-signup redirect) and the referral handle you arrived with24 hours
fyndme-account-deletion-reauthEssentialRe-authenticate during account deletion5 minutes
fm_consentEssentialYour cookie choice (Accept All, Essential Only or custom), the notice version, and whether Global Privacy Control was detected12 months
fm_bidEssentialRandom consent browser identifier that links your consent receipts to this browser; it contains no personal information12 months
fm_gpcEssentialCopy of your browser's Global Privacy Control signal, set by our server so optional cookies stay off; removed when the signal is no longer sent12 months (removed when the signal is off)
Language preferenceEssential (requested feature)Remember the language you selectedPersistent until cleared or sign-out
Referral invite handleEssentialNeeded to credit the referral for the link you clickedPersistent until cleared or sign-out
Builder draftEssential (requested feature)Auto-save the portfolio draft you are editingPersistent until cleared or sign-out
Security, privacy, and notification preferencesEssential (requested feature)Remember the settings you chosePersistent until cleared or sign-out
Dismissed tipsEssential (requested feature)Remember the tips you dismissedPersistent until cleared or sign-out
Admin return pathEssential/AdminRemember which tab to return toTab session only
_gaAnalytics (only with your consent)Google Analytics: tells returning visitors apart so we can count visits in aggregate13 months
_ga_<id>Analytics (only with your consent)Google Analytics: keeps session state for our Google Analytics property13 months
Analytics sign-up marker (session storage)Analytics (only with your consent)Lets us count a sign-up that you finish after opening the confirmation email; it holds no personal informationUntil the browser tab closes
Advertisingβ€”Not in use β€” we do not run adsβ€”

18. Do Not Sell or Share My Personal Information

Find Me LLC does not sell your personal information and does not share it for cross-context behavioral advertising. We have no advertising partners and do not work with data brokers.

  • GPC: We honor Global Privacy Control signals automatically as an opt-out request.
  • Formal request: If you would like written confirmation, or to submit a formal opt-out request, email support@fyndme.net with the subject "Do Not Sell or Share." You do not need an Account to submit this request.
  • Authorized agents: An authorized agent may submit a request on your behalf as described in Section 15.

If our practices ever change, we will update this policy and provide any notice and opt-out mechanisms required by law before any sale or sharing occurs.

19. Global Privacy Control

Global Privacy Control (GPC) is a browser setting or extension that tells websites you do not want your personal information sold or shared. When we detect a GPC signal:

  • We treat it as a valid opt-out of sale and sharing for that browser and, if you are signed in, for your Account.
  • We keep non-essential cookies (Functional and Analytics) off for that browser.
  • We record the signal in your consent receipt.
  • If you previously chose "Accept All," the GPC signal takes priority for opt-out purposes. GPC overrides a prior "Accept All" for that browser; optional cookies turn off.

Because we do not sell or share personal information, GPC does not change how the core Service works for you.

20. Changes to This Policy

We may update this Privacy Policy from time to time. Each version is dated and numbered. If we make material changes, we will notify you by email (from no-reply@fyndme.net) and/or by a notice in the Service before the changes take effect. We will not use previously collected information in a materially different way without your consent where the law requires it. Face Discovery will not launch without separate notice and separate consent. Previous versions are available on request.

21. Contact

Find Me LLC
4111 Rose Lake Dr

Charlotte, NC 28217

United States

Email: support@fyndme.net

Privacy requests: support@fyndme.net
India Grievance Officer: Shabaan Hossain β€” support@fyndme.net

Brazil encarregado: Shabaan Hossain β€” support@fyndme.net

EU/UK representative: To be appointed β€” support@fyndme.net meanwhile

Copyright (DMCA) designated agent: Shabaan Hossain, Find Me LLC, 4111 Rose Lake Dr, Charlotte, NC 28217 β€” dmca@fyndme.net (see /terms)

Appendix A: Subprocessors

SubprocessorPurposeData processedLocation
Cloudflare, Inc.Hosting and content delivery network (CDN); security and bot protectionIP address, request data (URL, headers, device and browser information)United States (global edge network)
Supabase, Inc.Database, authentication, and file storageAccount data, profile content, portfolios, uploads, sessions, MFA data, anti-abuse fingerprints, consent receiptsUnited States (us-east-1)
Resend, Inc.Transactional email delivery (from no-reply@fyndme.net)Email address, email content (e.g., verification codes, account notices)United States
Microsoft Corporation (Microsoft 365)Support emailSupport communications, attachments, sender email addressesUnited States
Google LLC (Google Analytics)Website analytics, only if you allow Analytics cookiesPseudonymous browser identifier (_ga cookies), pages viewed, sign-up and checkout events, device and browser information, approximate location from an anonymized IP address. No name, email address or account identifierUnited States
Google LLCSign-in (Google Sign-In)Email address, name, profile photo, Google account identifierUnited States
Apple Inc.Sign-in (Sign in with Apple)Email address (or Apple private relay address), name, Apple account identifierUnited States
Sendinblue SAS (Brevo)Marketing email delivery to members who opt in and to U.S. business and professional contacts (Section 4, item 10)Name and email address; for members also username, profile role, profile photo link (or illustrated character), and opt-in status and date; unsubscribe status; and whether an email was delivered or opened and which links were clickedEuropean Union (France)
Stripe, Inc.Payment processingPayment data (card details held by Stripe; last four digits, expiration, billing country shared with us), transaction data, emailUnited States

Any biometric processing vendor for Face Discovery will be added here before that feature launches. If mobile apps launch, Apple App Store and Google Play billing will be added here.