Privacy Policy
Effective Date: March 1, 2026
Your privacy is fundamental to our platform. This policy explains how SASS-Y collects, uses, and protects your personal information. We are committed to transparency and giving you control over your data.
1. Information We Collect
Information You Provide
- Account Information: Name, email address, phone number, date of birth, and profile details.
- Identity Verification: Government-issued ID, biometric data (facial recognition), and verification selfies for safety and compliance.
- Payment Information: Billing address, payment method details (processed by our payment partners).
- Communications: Messages, support requests, and feedback you send through our platform.
- Profile Content: Photos, videos, descriptions, and other media you upload to your profile.
Information Collected Automatically
- Device Information: Device type, operating system, browser type, and unique device identifiers.
- Usage Data: Pages visited, features used, time spent on platform, and interaction patterns.
- Location Data: Approximate location based on IP address. Precise location only with your explicit consent for safety features.
- Cookies & Tracking: See our Cookie Policy for details.
Biometric Data
We collect biometric data (facial recognition templates) solely for identity verification and safety purposes. This data is encrypted, stored securely, and never shared with third parties. You can request deletion at any time.
2. How We Use Your Information
- Provide Services: Enable bookings, payments, messaging, and platform features.
- Safety & Verification: Verify identities, prevent fraud, and maintain platform safety.
- Personalization: Customize your experience, recommendations, and notifications.
- Communications: Send service updates, security alerts, and (with consent) marketing messages.
- Legal Compliance: Meet regulatory requirements, respond to legal requests, and enforce our terms.
- Analytics: Improve our services, understand usage patterns, and develop new features.
3. Data Sharing & Disclosure
We never sell your personal data. We may share information with:
- Other Users: Profile information you choose to make public. You control visibility settings.
- Service Providers: Payment processors, cloud hosting, identity verification services, and customer support tools.
- Legal Requirements: When required by law, subpoena, or government request.
- Safety: To protect the safety of users, staff, or the public in emergency situations.
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users).
Agency Data Restrictions
Agencies connected to service providers have strictly limited data access. Real-time location, private messages, and client information are never shared with agencies. See our Agency Agreement for details.
4. Data Security
We implement industry-leading security measures:
- Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256).
- Biometric Security: Facial recognition data stored as encrypted, non-reversible templates.
- Access Controls: Strict role-based access with multi-factor authentication for staff.
- Monitoring: 24/7 security monitoring and regular penetration testing.
- Media Protection: Forensic watermarking on all media to deter unauthorized distribution.
- Incident Response: Documented procedures for security incidents with user notification.
5. Your Rights & Choices
You have the right to:
- Access: Request a copy of your personal data.
- Correction: Update or correct inaccurate information.
- Deletion: Request deletion of your account and personal data.
- Portability: Export your data in a machine-readable format.
- Opt-Out: Unsubscribe from marketing communications at any time.
- Restrict Processing: Limit how we use your data in certain circumstances.
- Withdraw Consent: Revoke consent for optional data processing.
To exercise these rights, visit your account settings or contact us at privacy@sassy.com.
6. Data Retention
- Active Accounts: Data retained while your account is active.
- Deleted Accounts: Most data deleted within 30 days. Some data retained for legal compliance (up to 7 years for financial records).
- Biometric Data: Deleted within 24 hours of account deletion.
- Anonymized Data: May be retained indefinitely for analytics.
7. International Transfers
Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards through Standard Contractual Clauses and equivalent mechanisms to protect your data in accordance with applicable privacy laws.
8. Contact Us
For privacy-related inquiries:
- Email: privacy@sassy.com
- Data Protection Officer: dpo@sassy.com
- Postal Address: SASS-Y Legal, 123 Safety Street, San Francisco, CA 94105
We may update this policy periodically. Material changes will be communicated via email or platform notification.