Introduction
ENDsun Services, LLC (“Company,” “we,” “us,” “our”) respect your privacy and are committed to protecting it through our compliance with this policy. This policy describes how we collect, process, retain, and disclose personal data about you when providing services to you through our websites, applications, and services that link to this policy (our “Services”) and our practices for using, maintaining, protecting, and disclosing that information.
This policy applies only to information we collect:
Through the Services.
In communications, including email, text, chat, and other electronic messages, between you and the Services.
When you interact with our advertising and applications (including mobile apps) on third-party websites and services, if those applications or advertising include links to this policy.
It does not apply to information collected by:
Us offline or through any other means, including on any other website operated by the Company or any third party that does not link to this policy; or
Any third party, including through any application or content (including advertising) that may link to or be accessible from or through the Services.
We may provide additional or different privacy policies that are specific to certain features, services, or activities.
Please read this policy carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our Services or providing us with your information, you agree to the collection, use, and sharing of your information as described in this privacy policy. This policy may change from time to time (see Changes to Our Privacy Policy). Your continued use of the Services after we make changes as described here is deemed to be acceptance of those changes, so please check the policy periodically for updates.
Children’s and Minors’ Data
Our Services are not intended for, and we do not knowingly collect any personal data from, children under the age of 18. If we learn we have collected or received personal data from a child under 18 years old without verification of parental consent, we will delete that information.
The Personal Data That We Collect or Process
“Personal data” is information that identifies, relates to, or describes, directly or indirectly, you as an individual, such as your name, email address, telephone number, home address, or payment information (for example, account information such as name, postal address, and email address, credit card number, social security number, or any other identifier we may use to contact you online or offline).
The types and categories of personal data that we collect or process include:
Account and contact information, including name, stage name or alias, address, email address, phone number, username, and other contact information you provide us.
Payment information, including credit card or debit card information and information about the payment methods and services you use in connection with the Services. Payments are processed by third-party payment providers. We do not receive full payment card number, payment card expiration date, or security code. Our payment provider provides us with a “token” that represents your account, your payment card’s expiration date, payment card type, and the first six and last four digits of your payment card number.
Account history, including information about your subscription, account, transactions, earnings, purchases, order history, or payment history.
Demographic information, including your age, gender, or sexual orientation, if you have consented to that information collection.
Location information, including general geographic location such as country, state or province, or city.
Device information, including your IP address, device identifiers, operating system and version, preferred language, hardware identifiers, browser type and settings, and other device information.
Content and information you elect to provide as part of your profile or in any emails, chats, or other communications sent to us.
Images, voice recordings, and videos collected or stored in connection with the Services.
Identity document information, such as Social Security and driver’s license numbers and a copy of your passport, driver’s license, or other government-issued ID for identity and age verification purposes.
Biometric information, such as facial geometry, facial scans, or similar biometric identifiers, collected only with your prior consent where required by law. We handle biometric information in accordance with applicable biometric privacy laws, including but not limited to the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and the California Consumer Privacy Act (CCPA/CPRA). Biometric information is retained only for as long as necessary to complete the purpose for which it was collected (for example, identity verification) and is deleted or permanently deidentified within the time limits required by applicable law, unless a longer retention period is required by law.
Authentication information received from third-party sign-in providers, such as Google or X, which may include your name, email address, and public profile information.
If you are a California resident, to access our supplemental California privacy statement, visit the CCPA privacy notice for California Residents.
Some of the information identified above, including sexual orientation, identification document information, and biometric information, may be considered sensitive data under certain laws. If required under applicable law, we will collect and process sensitive personal data only with your consent. If you choose not to provide or allow us to collect some information, we may not be able to provide you with requested features, services, or information.
We also collect:
Statistics or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal data. For example, we may aggregate personal data to calculate the percentage of users accessing a specific Services feature.
Technical information. Technical information includes information about your internet connection and usage details about your interactions with the Services, such as clickstream information to, through, and from our Services (including date and time), products that you view or search for; page response times, download errors, length of your visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), or methods used to browse away from a page.
If we combine or connect non-personal statistical or technical data with personal data so that it directly or indirectly identifies an individual, we treat the combined information as personal information.
How We Collect Your Personal and Other Data
You Provide Information to Us
We collect information about you when you interact with our Services, such as when you create or update an account, subscribe, make a purchase, participate in surveys, sweepstakes, contests, or promotions, or create, upload, or post content to the Services, including reviews, media such as photos, videos, or audio recordings.
Automatically Through Our Services
As you navigate through and interact with our Services, we may use automatic data collection technologies to collect information that may include personal data. Information collected automatically may include usage details, IP addresses, operating system, and browser type, and information collected through cookies and web beacons, including details of your interactions with our Services, such as traffic data, location data, logs, and other communication data, and which resources and Services features that you access and use.
Using automatic collection technologies helps us to improve our Services and to deliver a better and more personalized experience.
The technologies we use for this automatic data collection may include:
To the extent any of these automated technologies are considered a personal data sale, targeted advertising, or profiling, under applicable laws, depending on where you live, you may opt out from use of these automated technologies for those uses by emailing us at privacy@loyalfans.com. Please note that some Services features may be unavailable as a result.
When you interact with the Services, there are third parties that may use automatic collection technologies to collect information about you or your device. These third parties may include:
Advertisers, ad networks, and ad servers.
Analytics companies.
Your device manufacturer.
Your internet or mobile service provider.
Fraud prevention and security vendors.
Payment and identity verification providers.
Content delivery networks (CDNs) and hosting providers.
Affiliate or referral program partners (for tracking referrals and commissions).
Email and customer communication platforms (e.g., for open and click tracking in emails).
These third parties may use tracking technologies to collect information about you when you use the Services. The information they collect may be associated with your personal data or they may collect information, including personal data, about your online activities over time and across different websites, apps, platforms, and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.
From Business Partners and Service Providers
We may receive personal data about you from other sources and combine that with information we collect directly from you. For example, we may obtain information about you from service providers that we engage to perform services on our behalf, such as email platform providers, content delivery services, payment processors, age verification providers, customer support and helpdesk providers, third-party authentication providers (such as Google or X, if you chose to sign in using your account with those platforms), affiliate and referral tracking platforms, and analytics, security and anti-fraud services.
How We Use Your Information
We use information that we collect about you or that you provide to us, including any personal data, to:
Provide you with the Services and any contents, features, information, products, or services that we make available through the Services.
Fulfill and manage subscriptions, purchases, and payments.
Fulfill any other purpose for which you provide it.
Provide you with notices about your account, including expiration and renewal notices.
Improve our Services, including by analyzing your information and creating aggregated data derived from your information) to develop, maintain, analyze, improve, optimize, measure, and report on our Services and their features and how users interact with them. Our analysis may include the use of technology like machine learning and large language models, which may include training these models or sharing with third parties for model training. We do not use sensitive personal content (such as private videos or chat logs) to train or fine-tune AI models without your explicit consent. Any AI-based processing is opt-in, and we will clearly disclose when user-uploaded content is used for AI training or model improvement.
Promote our Services, business, and offerings by publishing advertising on our own Services and by placing ads on third parties’ services. We may use your information to model, segment, target, offer, market, and advertise our Services.
Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
Notify you when Services updates are available and about changes to any products or services we offer or provide through them.
Detect, investigate, and prevent fraudulent, harmful, or unauthorized activity on the Services, including monitoring for violations of our Terms of Service and Acceptable Use Policy.
Verify your age and identity if you are a Creator and where required by law if you are a Fan.
Authenticate your account and allow you to log in using third-party services such as Google or X.
Respond to your inquiries, support requests, and disputes, and provide customer service.
Facilitate payouts to Creators and comply with financial, tax, and anti-money laundering obligations.
Respond to lawful requests from public authorities, including to meet national security or law enforcement requirements.
Report suspected illegal activity or content to law enforcement or appropriate organizations such as the National Center for Missing & Exploited Children (NCMEC), in accordance with applicable laws.
Facilitate communication between Fans and Creators, where permitted by the Services and applicable law.
In any other way we may describe when you provide the information.
For any other purpose with your consent.
The usage information we collect, whether connected to your personal data or not, helps us improve our Services and deliver a better and more personalized experience by enabling us to:
Estimate our audience sizes and usage patterns.
Store information about your preferences, allowing us to customize the Services according to your individual needs and interests.
Speed up your searches.
Recognize you when you return to our Services.
We may also use your information to contact you about goods and services that may be of interest to you. If you do not want us to use your information in this way, please adjust your user preferences in your account profile. For more information, see Your Rights and Choices About Your Information.
We use location information we collect to determine whether you are accessing the platform from a jurisdiction that requires age verification, to comply with applicable laws and regulations, to detect and prevent fraud, and to enforce our Terms of Service.
Who We Disclose Your Information To
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.
We may also disclose personal data that we collect or you provide as described in this privacy policy:
To our subsidiaries and affiliates.
To contractors, service providers, and other third parties we use to support our organization and who are bound by contractual obligations to keep personal data confidential and use it only for the purposes for which we disclose it to them.
To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of ENDsun Services, LLC’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal data held by ENDsun Services, LLC is among the assets transferred.
To fulfill the purpose for which you provide it.
For any other purpose disclosed by us when you provide the information.
With your consent.
We may also disclose your personal data:
To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
To enforce or apply our Terms of Service and other agreements, including for billing and collection purposes.
If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of our organization, our Users, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
The categories of personal information we may disclose include:
Account and contact information
Payment information
Account history
Location information
Device and technical information
Identity documentation
User content (where necessary for support, moderation, or legal compliance)
Biometric information (only when required and with your consent)
International Data Transfers
We are based in the United States of America. We may process, store, and transfer the personal data we collect in and to countries outside of your own, including to jurisdictions that may not provide the same level of data protection as your country of residence.
If you are located in Canada, please note that personal data transferred outside of Canada may become accessible to foreign law enforcement or other authorities under the laws of those jurisdictions.
If you are located in the European Economic Area (EEA), Switzerland, or the United Kingdom (UK), your personal data may be transferred to countries outside of those regions, including to the United States. Where required by applicable law, we implement appropriate safeguards—such as standard contractual clauses approved by the European Commission or other lawful mechanisms—to ensure an adequate level of protection for your personal data. For more information about these safeguards, please contact us at privacy@loyalfans.com.
Your Rights and Choices About Your Information
This section describes mechanisms you can use to control certain uses and disclosures of your information and rights you may have under state law, depending on where you live.
Advertising, marketing, cookies, and other tracking technologies choices:
Jurisdiction Specific Rights
Your State Privacy Rights
Depending on your state of residency, you may have certain rights related to your personal data, including:
Access and Data Portability. You may confirm whether we process your personal data and access a copy of the personal data we process. To the extent feasible and required by state law, depending on your state, data will be provided in a portable format. Depending on your state, you may have the right to receive additional information and it will be included in the response to your access request.
Correction. You may request that we correct inaccuracies in your personal data that we maintain, taking into account the information’s nature and processing purpose.
Deletion. You may request that we delete personal data about you that we maintain, subject to certain exception under applicable law.
Opt Out of Using Personal Data for Targeted Advertising, Profiling, and Sales. You may request that we do not use your personal data for these purposes.
Important: The exact scope of these rights vary by state. There are also several exceptions where we may not have an obligation to fulfill your request.
To exercise any of these rights, please email us at privacy@loyalfans.com. To appeal a decision regarding a consumer rights request you may reply to our response email and state the basis for your appeal. We will review your appeal and respond in writing within 45 days, including an explanation of the decision. If your appeal is denied, you may contact your state’s attorney general to lodge a complaint.
Some browsers and browser extensions support the Global Privacy Control (“GPC”) that can send a signal to process your request to opt out from certain types of data processing, including data “sales” as defined under certain laws. When we detect such a signal, we will make reasonable efforts to respect your choices indicated by a GPC setting as required by applicable law.
Nevada provides its residents with a limited right to opt out of certain personal data sales. Residents who wish to exercise their sale opt-out rights may submit a request to this designated address: privacy@loyalfans.com. However, please know we do not currently sell data triggering that statute’s opt-out requirements.
If you are a California resident, additional information applies to you. To access our supplemental California privacy statement and learn more about California residents’ privacy rights, visit the CCPA privacy notice for California Residents.
Your EEA/UK Privacy Rights and Disclosures
Controller
ENDsun Services, LLC is the controller and responsible for your personal data. You can contact us using the contact information at the end of this policy.
Lawful Basis for Processing Personal Data
We will only use your personal data when we have a lawful basis to do so. Our lawful basis for each purpose for which we use your personal data is specified below. Most commonly we will use your personal data in the following circumstances:
Consent. Where you have freely consented before the processing in a specific, informed and unambiguous indication of what you want. You can withdraw your consent at any time by contacting us (see Your Legal Rights below).
Performance of a contract. Where we need to process your personal data to perform a contract with you or where you ask us to take steps before we enter into a contract with you. Where we rely on performance of a contract and you do not provide the necessary information, we will be unable to perform your contract.
Legitimate interests. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
Legal obligation. Where we need to use your personal data to comply with a legal or regulatory obligation. Where we rely on legal obligation and you do not provide the necessary information, we may be unable to fulfil a right you have or comply with our obligations to you, or we may need to take additional steps, such as informing law enforcement or a public authority or applying for a court order.
Purpose or activity | Lawful basis for processing |
Provide access to the Services and manage your account | Performance of a contract |
Process payments and facilitate Creator payouts | Performance of a contract |
Verify your age and identity (for Creators or where required for Fans) | Legal obligation (to protect minors from harmful material under the EU Digital Services Act and the UK Online Safety Act of 2023) |
Identifying Referring Users and Referred Creators under the Referral Program set out in our Terms of Service. | Consent |
Monitor and review user-generated content, including uploaded media and chat messages, for compliance with our Terms of Service. | Performance of a contract |
Applying security measures to our processing of your personal data, including processing in connection with the Services | Legal obligation (applying appropriate technical and organizational measures under Article 32 of the UK GDPR and the EU GDPR) |
Monitor use of the Services and deploying appropriate security measures | Legitimate interests (running our business, provision of administration and IT services, network security, maintaining the security of our Services, providing a secure service to users and preventing fraudulent and other misuse of our Services) |
To administer, monitor and improve our business and Services including troubleshooting, data analysis, and system testing | Legitimate interests (for running our business, provision of administration and IT services, network security, maintaining the security of our Services, providing a secure service to users, and preventing fraudulent and other misuse of our Services) |
Maintaining a record of banned users, to prevent further access to our Services. | Legitimate interests (preventing fraudulent and other misuse of our Services) |
Improve, optimize, and personalize the Services | Legitimate interests (delivering and securing our Services) |
Provide marketing, promotional offers, or interest-based content | Consent |
Authenticate your account via third-party login (e.g., Google or X) | Performance of a contract |
Comply with tax, legal, or regulatory obligations (e.g., AML/KYC) | Legal obligation (to comply with tax laws and anti-money laundering laws) |
Enforce our Terms of Service or protect our legal rights | Legitimate interests |
Report suspected illegal content or activity to law enforcement or NCMEC | Legal obligation (to comply with 18 U.S.C. § 2258A, or applicable law) |
Respond to lawful requests from public authorities | Legal obligation (to comply with law enforcement or court orders) |
To notify you of changes to the Services, your purchases, and our terms and conditions for ongoing contracts | For ongoing or prospective contracts, Performance of a contract |
To notify you of updates to this privacy policy | Legal obligation (to inform you of our processing under Articles 13 and 14 of the UK GDPR and the EU GDPR) |
To respond to your requests to exercise your rights under this policy | Legal obligation (complying with data subject requests under Chapter 3 of the UK GDPR and the EU GDPR) |
To otherwise respond to your inquiries, fulfill your requests, and to contact you where necessary | Legitimate interests (service our users and prospective users) |
Share personal data with our third-party providers for purposes not otherwise set out above | Legitimate interests (for the purpose relevant to the recipient, as set out at “Who We Disclose Your Information To”) |
Automated Decision Making and Profiling
We do not make decisions based solely on automated processing or profiling that produce legal effects concerning you (or have similarly significant effects).
Criminal Offense Data and Special Category Data
We do not actively collect data relating to criminal convictions or offences. However, we may process and disclose personal data when required to comply with legal obligations, such as reporting suspected child exploitation or unlawful content to law enforcement or child protection authorities, including NCMEC.
Special Categories of Personal Data
Purpose or activity | Type of personal data | Lawful basis for processing | Processing condition |
To allow users to voluntarily share demographic or identity-related information in their profile or communications | Sexual orientation; other information that may reveal protected characteristics (e.g., gender identity) | Consent | Explicit consent |
Your Legal Rights
Under certain circumstances, you have rights under data protection laws concerning your personal data. Your rights may include the following:
Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully, or where we are required to erase your personal data to comply with local law. Note, however, that we might not always be able to comply with your erasure request for specific legal reasons that will be notified to you, if applicable, at the time of your request.
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation that makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information that override your rights and freedoms.
Request restriction of processing your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (1) if you want us to establish the data’s accuracy; (2) where our use of the data is unlawful, but you do not want us to erase it; (3) where you need us to hold the data even if we no longer require it as you need it to establish, exercise, or defend legal claims; or (4) you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information that you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we might not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Exercising Your Rights
If you wish to exercise any of the rights set out above, please contact us at privacy@loyalfans.com.
Fees
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to honor your request in these circumstances.
Verification
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information regarding your request to speed up our response.
Responding to Your Request
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will let you know and keep you updated.
Right to Lodge Complaint
If you believe our data processing practices violate your rights under the EU or UK GDPR, you may lodge a complaint with the supervisory authority in your country of residence or work. If you are in the EU, you can find your local supervisory authority here. For any unresolved complaints relating to the UK, you can reach out to the Information Commissioner's Office, and for Switzerland, to the Federal Data Protection and Information Commissioner. While you have the right to lodge a complaint directly with the supervisory authority, we welcome the opportunity to address your concerns and resolve any issues first.
How We Protect Your Personal Data
We use commercially reasonable administrative, physical, and technical measures designed to protect your personal data from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure. However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal data transmitted to, through, using, or in connection with the Services. In particular, email, texts, and chats sent to or from the Services may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of personal data is at your own risk.
The safety and security of your information also depends on you. You are responsible for taking steps to protect your personal data against unauthorized use, disclosure, and access.
How We Retain Your Personal Data
We retain the categories of personal data described in this policy for as long as necessary to fulfill the purposes for which they were collected, or as otherwise required or permitted by law. This includes purposes such as providing and maintaining the Services, operating our business, complying with legal obligations, resolving disputes, and ensuring safety, security, and fraud prevention.
When determining retention periods, we consider legal and business requirements, the potential risks of harm, and the nature of the personal data. At the end of the applicable retention period, we securely delete, destroy, or deidentify the personal data, unless we are legally required to keep it for a longer period.
Biometric information (such as faceprints, fingerprints, or other biometric identifiers) is retained only as long as necessary to verify identity or otherwise fulfill the purpose for which it was collected, and is then permanently deleted or deidentified unless a longer retention period is required by law.
If you are a California resident, visit the CCPA privacy notice for California Residents for more information about the retention periods that apply to the personal data categories we collect.
Changes to Our Privacy Policy
We may update this policy from time to time, and we will provide notice of any such changes to the policy as required by law. The date the privacy policy was last updated is identified at the top of the page. We will notify you of changes to this policy by updating the “last updated” date and posting the updated policy on the Services. We may email or otherwise communicate reminders about this policy, but you should check our Services periodically to see the current policy and any changes we have made to it.
Contact Information
To exercise your rights or ask questions or comment about this privacy policy or our privacy practices, contact us at:
4801 Gulf Blvd., Suite 193
St. Pete Beach, FL 33706
privacy@loyalfans.com
We have procedures in place to receive and respond to complaints or inquiries about our handling of personal data, our compliance with this policy, and with applicable privacy laws. To discuss our compliance with this policy please contact our privacy officer using the email address listed above.