Privacy Policy
Effective: August 13, 2026
This Privacy Policy describes how BeMetrix (the "Service", "we", "us", "our") collects, uses, stores, transfers and protects personal data. We are committed to processing your information transparently and in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR and the California Consumer Privacy Act as amended by the CPRA. If you have any questions, contact us at privacy@bemetrix.com.
1. Introduction
Welcome to BeMetrix. This Privacy Policy explains how we handle personal data collected through our website, dashboard, mobile experiences, edge functions and connected integrations.
This policy applies to everyone who interacts with the Service, including:
- Visitors — people browsing our public marketing pages
- Studio account holders — organisations managing multiple creators
- Model Creator account holders — individual creators using the Service directly
- Team members invited into a studio (managers, operators, staff)
- Creators invited into a studio
- Salespersons invited to track their referred clients
By accessing or using BeMetrix, you acknowledge the practices described here. If you do not agree, please do not use the Service.
2. Definitions
For the purposes of this policy:
- Personal data means any information that identifies or may identify you, directly or indirectly, such as your name, email address or IP address.
- Processing means any operation performed on personal data, including collecting, storing, using, transferring and deleting it.
- Sensitive data means personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation.
- Controller is the party that decides why and how personal data is processed.
- Processor is the party that processes personal data on behalf of a controller.
- Sub-processor is a third party engaged by a processor to help perform the processing.
3. Our Role: Controller vs Processor
Because BeMetrix is a B2B platform, our legal role changes depending on the data:
When we act as Controller
We are the controller for data we collect about the person who signs up for or administers an account: account holders, invited team members, creators, salespersons and website visitors. This includes contact details, authentication data, billing data and usage analytics for the Service itself.
When we act as Processor
We act as processor on behalf of a Studio or Model Creator account for business data that the account uploads or synchronises into the Service — such as information about their members/fans, transaction histories, chat notes, performance metrics of their creators and data imported from third-party creator platforms. In that role, the account is the controller and decides the purposes and means of processing; we process such data only on their documented instructions and as necessary to provide the Service.
Data Processing Agreement (DPA)
Studio and Model Creator customers subject to GDPR may enter into our Data Processing Agreement by contacting privacy@bemetrix.com. The DPA incorporates the European Commission's Standard Contractual Clauses (Decision 2021/914) where applicable.
What we do not process
We do not perform age verification of performers and do not collect or store performers' identity documents. Customers must not upload identity documents or adult media to the Service. See the Terms of Service for the split of responsibility between us and our customers.
4. How We Collect Your Data
We obtain personal data in three ways:
Directly from you
- When you register an account, complete onboarding, or fill in a form
- When you accept an invitation as a team member, creator or salesperson
- When you contact support or reply to us
- When you upload content, configure integrations or enter business data
Automatically
- Technical data captured by your browser (IP address, user agent, timestamps)
- Cookies and similar technologies — see our Cookie Policy
- Server logs generated by our edge functions and hosting infrastructure
- Country inference at sign-up (via ipapi.co) to enable regional formatting and fraud prevention
From third parties
- Identity providers (Google OAuth) when you choose to sign in with them
- Creator platforms (e.g. Chaturbate) when you connect their API — earnings, event streams and public profile data
- Payment processors (Stripe, our crypto processor) — payment status, last four digits of the card, country
5. Information We Collect
The categories of personal data we process depend on your role.
Account & Identity Data
- Email address, hashed password, display name, avatar
- Account type (studio / model / creator / salesperson), timezone, preferred language
- Multi-factor authentication (MFA) enrolment factors — we store TOTP secrets encrypted at rest via Supabase Auth; we never see the plain secret or one-time codes
- OAuth identifier when you sign in with Google
Billing Data
- Subscription plan, status, trial state, renewal date
- Stripe customer ID and payment history metadata
- Crypto payment records (address, network, amount, transaction hash) when you pay with cryptocurrency
- We do not store full card numbers or CVV — Stripe handles those directly
Business Data (uploaded by the account)
- Creator profiles, schedules, shifts and earnings
- Members/fans tracked by the studio, including nicknames, spending history and segments
- Operator and staff KPIs, payouts and salaries
- Uploaded documents, screenshots and media
- Notes, chat coaching prompts and AI conversation history
Integration Data
- API tokens and credentials for connected creator platforms (encrypted at rest)
- Statistics, events and payouts synchronised from those platforms
- Telegram user ID when you connect Telegram for notifications
Usage & Technical Data
- IP address, sign-up country, user agent, device type
- Pages visited, features used, click and navigation events
- Login timestamps and active session metadata
6. If You Fail to Provide Data
Some data is necessary for us to provide the Service. If you do not provide it, we may be unable to create your account, deliver requested features or fulfil our contract with you. In particular, without a valid email address we cannot authenticate you, and without payment data we cannot activate paid features.
7. Sensitive Data
BeMetrix does not knowingly request or process special-category (sensitive) personal data as defined by Article 9 GDPR. You should not upload sensitive data about yourself or any third party to the Service.
If a Studio account chooses to store notes about a creator (for example about health absences) that qualify as sensitive data, the Studio remains the sole controller of that data and is responsible for having a valid legal basis under Article 9 GDPR.
8. Legal Bases for Processing (GDPR Art. 6)
We only process personal data where we have a lawful basis to do so:
Performance of a contract (Art. 6(1)(b))
- Creating and administering your account
- Providing dashboard, analytics and integration features
- Processing subscription payments and issuing invoices
- Providing customer support
Legitimate interests (Art. 6(1)(f))
- Securing the Service against fraud, abuse and unauthorised access
- Product analytics and improving features
- Directly marketing similar products to existing customers, subject to your right to object at any time
- Enforcing our Terms and defending legal claims
Legal obligation (Art. 6(1)(c))
- Tax, accounting and anti-fraud record-keeping
- Responding to lawful requests from public authorities
Consent (Art. 6(1)(a))
- Non-essential cookies and analytics tags
- Marketing communications to prospects
- Optional integrations (Telegram, connected creator platforms)
Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
9. How We Use Your Information
We use collected data for the following purposes:
- Delivering the Service — provisioning accounts, running the dashboard, syncing integrations, sending notifications you subscribed to
- Billing — charging your subscription, tracking trials, providing payment history
- Communications — transactional emails (invoices, security alerts, invitations), product updates you opted into, and support responses
- Analytics & product improvement — understanding feature adoption, diagnosing bugs
- Security & fraud prevention — detecting suspicious sign-ins, protecting against abuse, enforcing rate limits
- Legal compliance — meeting tax, accounting and regulatory obligations
- AI-powered features — see section 10
We do not sell your personal data.
10. AI Features and Automated Processing
BeMetrix offers optional AI-powered features (chat coaching, market pulse insights, AI profile generation, retention radar summaries). When you use these features:
- The prompt content and relevant business context are sent to our AI provider (Lovable AI Gateway, which routes requests to models such as Google Gemini and OpenAI GPT)
- We instruct providers not to use your prompts or outputs to train their base models, subject to their respective terms
- Conversation history is stored in your account so you can revisit it; you can delete conversations at any time
- AI outputs may be inaccurate. You are responsible for reviewing them before acting on business decisions
We do not use AI features to make solely automated decisions with legal or similarly significant effects on you within the meaning of Article 22 GDPR.
11. Data Sharing and Sub-processors
We share personal data only in limited circumstances and only with recipients bound by appropriate confidentiality and data protection commitments.
Within your studio
For Studio accounts, business data is visible to other authorised users of the same studio based on their role (studio admin, manager, operator, staff, creator, salesperson). Access is enforced at the database level via row-level security policies.
Legal disclosures
We may disclose personal data when required by a valid legal request, to protect our rights or the safety of users, to investigate fraud, or in connection with a merger, acquisition or asset sale, in which case we will notify affected users where feasible.
We do not sell personal data to third parties.
12. Payment Information
Card payments are processed by Stripe. We receive from Stripe a customer identifier, the last four digits of the card, card brand, expiry month/year, country and payment status. We never receive or store your full card number or CVV.
Cryptocurrency payments are processed by our crypto payment provider. We store the destination address, network, amount, transaction hash and confirmation status linked to your account.
Refunds and disputes are handled in accordance with our Refund Policy.
13. International Data Transfers
BeMetrix is operated from the European Union and our primary infrastructure is hosted in EU data centres (Frankfurt, Germany).
Some of our sub-processors are located outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we rely on one or more of the following safeguards:
- An adequacy decision of the European Commission for the recipient country
- The European Commission's Standard Contractual Clauses (Decision 2021/914)
- For transfers to the United States, certification of the recipient under the EU-US Data Privacy Framework (2023) where applicable
- Binding Corporate Rules approved by a competent supervisory authority, where applicable
You may request a copy of the safeguards applicable to a specific transfer by writing to privacy@bemetrix.com.
14. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy.
- Active account data — retained while your account is active
- After account cancellation — account and business data remain exportable for 90 days, then are permanently deleted from active systems
- Encrypted backups — retained for a further 30 days and then destroyed
- Billing and tax records — retained for up to 10 years where required by applicable accounting laws
- Security and audit logs — retained for up to 12 months
- AI conversation history — retained until you delete it or close your account
- Marketing consents and opt-outs — retained as long as needed to honour your preferences
- Anonymised, aggregated data — may be retained indefinitely as it no longer identifies you
15. Security of Your Data
We apply industry-standard technical and organisational measures to protect personal data, including:
- Encryption in transit — TLS 1.2+ for all connections
- Encryption at rest — for the database, storage buckets, MFA secrets and integration credentials
- Row-level security — database policies enforce role-based access inside each studio
- Multi-factor authentication — optional TOTP-based 2FA available to every account
- Least-privilege access — only authorised personnel may access production systems, and only for defined operational reasons
- Monitoring and logging — anomaly detection and audit trails
- Incident response — in the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by GDPR, and notify affected users when required
No system is completely secure. You are responsible for protecting your own credentials and enabling 2FA is strongly recommended.
16. Your GDPR Rights
Subject to applicable law, you have the following rights regarding your personal data:
- Right of access — obtain a copy of the personal data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion in the circumstances defined by GDPR
- Right to restriction of processing — limit how we process your data in specific situations
- Right to data portability — receive data you provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller
- Right to object — object to processing based on our legitimate interests, and to direct marketing at any time
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
- Rights related to automated decision-making — you are not subject to solely automated decisions with legal or similarly significant effects
To exercise any of these rights, contact privacy@bemetrix.com. We may need to verify your identity before responding. We will respond within one month; complex requests may take up to three months, and we will keep you informed.
Requests are handled free of charge, unless clearly unfounded, repetitive or excessive.
18. Third-Party Login (OAuth)
You may sign in to BeMetrix using a third-party identity provider such as Google. When you do, the provider shares with us your email address, name and a stable identifier so we can create or match your account.
Your use of the third-party service is governed by that provider's terms and privacy policy. We recommend reviewing them before enabling third-party sign-in.
19. Children and Age Restrictions
BeMetrix is intended exclusively for professional use by adults. Access is restricted to persons aged 18 or older (or the age of majority in their jurisdiction, whichever is higher).
We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will delete it and close the account. Please contact privacy@bemetrix.com if you believe a minor has provided us with personal data.
20. California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) gives you additional rights:
- Right to know — the categories and specific pieces of personal information we collect, use, disclose and share
- Right to delete — request deletion of personal information subject to statutory exceptions
- Right to correct — request correction of inaccurate personal information
- Right to opt-out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising, so there is no opt-out required, but you may confirm your preference by writing to us
- Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes that trigger this right
- Right to non-discrimination — we will not deny service or charge different prices for exercising your rights
- Authorised agents — you may designate an authorised agent to submit requests on your behalf with proof of authority
To exercise these rights, write to privacy@bemetrix.com.
21. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other reasons. We will post the updated version on this page and update the "Effective date" at the top.
For material changes, we will notify you by email or through the Service before the changes take effect. Continued use of the Service after changes become effective constitutes acceptance of the revised policy.
22. Complaints and Supervisory Authority
If you have concerns about how we handle your personal data, please contact us first at privacy@bemetrix.com so we can try to resolve the issue.
You also have the right to lodge a complaint with a data protection supervisory authority in the EU/EEA Member State of your residence, place of work or the alleged infringement. A list of national authorities is available at edpb.europa.eu.
23. Contact Us
Questions, requests or complaints about this Privacy Policy or our processing of personal data:
- Email: privacy@bemetrix.com
- Postal address: Vizone Ltd s.r.o. (IČO 03139964), Orebitská 66/6, Žižkov, 130 00 Praha 3, Czech Republic
If we have appointed a Data Protection Officer or an EU/UK representative under Article 27 GDPR, their contact details will be listed here.