1. Who we are
StardomFans.org ("StardomFans.org", "we") is the data controller for the personal information described in this Policy.
2. Information we collect
Account information — email, name, role (artist / fan), artist name, genre, hashed password (bcrypt).
Waitlist & referrals — email, role, referral code, who referred you, referral count.
Usage data — IP address, device and browser metadata, pages visited, login attempts (for brute-force protection).
Cookies — strictly necessary cookies for authentication and a small consent flag. See our Cookie Policy.
3. How we use your information
To operate the Service (authenticate you, attribute referrals, show your rank), to keep the Service safe (brute-force protection, abuse prevention), to communicate with you about pre-launch updates, and to comply with legal obligations.
4. Legal bases (GDPR / UK GDPR)
We rely on (a) contract to operate the Service for registered users, (b) legitimate interests to secure the platform and improve it, and (c) consent for marketing communications, withdrawable at any time.
5. Sharing
We do not sell your personal information. We share it with vetted processors only as needed: cloud hosting, database, email delivery, payment processing (at launch), and AI providers used by our admin tooling (where prompts may include site content, never your private data). All processors are bound by appropriate data-protection agreements.
6. International transfers
Where data is transferred outside the UK / EEA, we use lawful transfer mechanisms including Standard Contractual Clauses.
7. Retention
Account data — for as long as your account is active, plus up to 24 months after deletion for backups and dispute resolution. Waitlist entries — until launch and up to 12 months after, unless you ask us to delete sooner. Login attempt logs — 30 days. We will honor erasure requests sooner where required.
8. Security
Passwords are hashed with bcrypt. Sessions use httpOnly, secure, SameSite=None cookies. We use TLS in transit, role-based access controls on admin endpoints, and rate-limited login.
9. Children
StardomFans.org is not intended for users under 13 (16 in the EU/UK). Do not use the Service if you are under the applicable age.
10. Changes
We will post any material changes to this Policy on this page with a new effective date.
