Privacy Policy
Last updated: August 18, 2026 · Effective date: August 18, 2026
1. Who we are
Valorist is a private community platform operated by its owner ("we," "us," or "our"). This Privacy Policy explains how we collect, use, and protect personal information when you use our platform (the "Service").
Data Controller: [YOUR NAME OR ENTITY] · [YOUR ADDRESS] · [YOUR EMAIL]
2. What data we collect
2.1 Account data
- Email address (used for authentication and account notifications)
- Username and display name (shown publicly within the community)
- Avatar image (if uploaded)
2.2 Content you create
- Feed posts, comments, thread titles, and thread replies
- Likes and reactions
- Course completion records and point history
2.3 Payment data
If subscriptions are enabled, payment is processed by Stripe, Inc. We do not store credit card numbers, bank details, or full billing addresses on our servers. Stripe processes payment data under their own privacy policy. We receive your Stripe customer ID, subscription status, and billing email.
2.4 Technical data
- IP address (collected by our hosting provider for security)
- Browser type and device information (server logs)
- Login timestamps and session activity
2.5 Consent records
When you accept our Terms of Service or Privacy Policy, we record the date, time, and version of the policy you accepted, along with your IP address.
3. How we use your data
We use personal data for the following purposes:
- Providing the Service — authentication, displaying your content, tracking progress, and processing payments.
- Community safety — moderation, content reporting, enforcing community guidelines, and preventing abuse.
- Communication — sending account-related emails (password resets, confirmations, subscription updates). We do not send marketing emails.
- Legal compliance — maintaining records required by GDPR, CCPA, and other applicable laws.
4. Legal basis for processing (GDPR)
Under the EU General Data Protection Regulation, we process your data on the following legal bases:
- Contract (Art. 6(1)(b)) — processing necessary to provide the Service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — keeping the community safe, preventing abuse, and improving the Service.
- Consent (Art. 6(1)(a)) — for any non-essential cookies or tracking we may add in the future (you will be asked before any tracking is enabled).
- Legal obligation (Art. 6(1)(c)) — retaining records required by law (e.g., transaction records for tax purposes).
5. Data sharing and processors
We do not sell your personal data. We share data only with the following service providers who process data on our behalf:
- Supabase (database and authentication) — data is stored in their infrastructure. Supabase supports EU-region hosting. Supabase Privacy Policy
- Vercel (hosting and serverless functions) — request logs may include IP addresses. Vercel supports EU regions. Vercel Privacy Policy
- Stripe (payment processing, if enabled) — payment data is processed entirely by Stripe and never touches our servers. Stripe Privacy Policy
We may disclose information if required by law, court order, or government request.
6. International data transfers
Our infrastructure may involve transferring data outside the European Economic Area (EEA). Where this occurs, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework (for US-based processors that have self-certified)
- Contractual commitments from our processors to protect data to EU standards
Where possible, we configure our infrastructure to use EU-region deployments.
7. Data retention
- Account data — retained for as long as your account exists. Deleted within 30 days of account deletion.
- Content — feed posts, comments, threads, and replies are deleted when your account is deleted.
- Payment records — Stripe retains transaction records as required by law (typically 7 years for tax/accounting). We retain only your subscription status.
- Server logs — automatically rotated and deleted within 30 days.
- Consent records — retained for 3 years after acceptance to demonstrate compliance.
8. Your rights
8.1 GDPR rights (EU/EEA/UK residents)
You have the right to:
- Access — request a copy of all personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Restrict processing — limit how we use your data.
- Object — object to processing based on legitimate interest.
- Withdraw consent — withdraw consent at any time (where processing is based on consent).
8.2 CCPA rights (California residents)
Under the California Consumer Privacy Act, you have the right to:
- Know — what personal information we collect, use, and disclose.
- Delete — request deletion of personal information.
- Opt out — opt out of the sale of personal information (we do not sell personal data).
- Non-discrimination — we will not discriminate against you for exercising your rights.
8.3 How to exercise your rights
To exercise any of these rights, contact us at [YOUR EMAIL]. We will respond within 30 days (or within the legally required timeframe for your jurisdiction). We may ask you to verify your identity before processing your request.
9. Account deletion
You may delete your account at any time from your account settings. Account deletion is permanent and includes:
- Removal of your profile, posts, comments, threads, and replies
- Deletion of your authentication credentials
- Cancellation of any active subscription (Stripe handles refunds per their policy)
Some data may be retained in anonymized form (e.g., thread structures with author removed) to preserve community content integrity, or as required by law.
10. Cookies
We use only strictly necessary cookies required for the Service to function:
- Session cookie — Supabase authentication token (httpOnly, Secure, SameSite=Lax). Required to keep you logged in.
We do not currently use analytics, advertising, or tracking cookies. If we add any non-essential cookies in the future, we will ask for your consent before setting them.
11. Children's privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Service before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact:
[YOUR NAME OR ENTITY]
[YOUR EMAIL]
[YOUR ADDRESS]
If you are in the EU and we have not resolved your concern, you have the right to lodge a complaint with your local data protection authority.