This Privacy Policy explains how CrownMe Media, LLC ("CrownMe Media," "we," "us"), collects, uses, shares, and protects information about you when you use our website, mobile applications, Battle Arena live video features, tournaments, and related services (the "Service"). It applies globally and incorporates rights granted by the EU/UK GDPR, California's CCPA/CPRA, Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, and other applicable privacy laws.
1. Information We Collect
1.1 Information you provide
- Account data: email address, username, password (hashed), date of birth, optional profile photo, bio, city/state/country.
- Content: photos, captions, comments, votes, direct messages, emotes, gift transactions, and metadata you provide.
- Live Session data: for Battle Arena and other live features, we process real-time camera and microphone streams, reactions, chat, presence, viewer counts, and pre-flight audio/video device checks. Live streams are transmitted in real time; we may record segments for safety, moderation, dispute resolution, or where required by law.
- Payment data: processed by Stripe and the Apple / Google app stores. We receive transaction confirmations, currency, and card last-4 / brand, never full card numbers.
- Subscription & Founder data: Royal Pass status, renewal date, Crown Shield ledger, Founder tier, and immutable financial audit records.
- Support & moderation communications: messages, reports, appeals, and identity-verification materials you send us.
1.2 Information collected automatically
- Device & technical: IP address, device type, OS, browser type, app version, language, time zone.
- Usage: pages viewed, votes cast, screens visited, session duration, tournament participation, moderation actions, crash reports, and performance metrics.
- Approximate location: derived from IP and any city/state you provide. We do not collect precise GPS unless you explicitly enable a feature that requires it.
- Cookies & similar: see our Cookie Policy.
1.3 Information from third parties
- Sign-in providers (e.g., Google, Apple) — we receive your email, name, and profile picture.
- Payment processors and app stores — to confirm and reconcile transactions and manage subscriptions, refunds, and chargebacks.
- Real-time media (LiveKit) — signaling and turn-server metadata required to route your Live Session.
- Analytics, crash reporting, and abuse-prevention providers.
2. How We Use Information
- Provide, maintain, and improve the Service, including feeds, battles, tournaments, and live streaming.
- Authenticate users and verify age (18+).
- Personalize feeds, recommendations, and rankings.
- Process payments for shekels, gifts, boosts, Crown Shields, and the Royal Pass, and reconcile Founder ledger entries.
- Detect and prevent fraud, vote manipulation, tournament collusion, abuse, CSAE, and security incidents.
- Send transactional messages (security alerts, receipts, renewal reminders) and, where permitted, promotional messages you can opt out of.
- Comply with legal obligations (including tax, consumer protection, DSA statements of reasons, and law-enforcement requests) and enforce our Terms.
3. Legal Bases (EEA/UK)
We rely on the following lawful bases under the GDPR/UK GDPR: (a) performance of a contract (providing the Service you signed up for and the Royal Pass); (b) legitimate interests (security, fraud prevention, product improvement, moderation, integrity of battles and tournaments); (c) consent (optional cookies, camera and microphone access for Live Sessions, push notifications, marketing); (d) legal obligations (tax, consumer-protection, CSAE reporting, DSA); and (e) vital interests (imminent safety threats).
4. How We Share Information
- Other users: profile information, posts, comments, votes, live-session audio/video, presence, and gifts are visible per your privacy settings and the audience of the feature.
- Service providers (subprocessors): hosting and database (Lovable Cloud), real-time media (LiveKit), payments and subscriptions (Stripe), Apple App Store and Google Play (in-app purchases), transactional email delivery, analytics, error tracking, content delivery, and customer support — all bound by contract to use data only on our instructions and with appropriate safeguards.
- Legal & safety: to comply with law, lawful requests, or to protect rights, property, or safety, including reporting CSAM to NCMEC and equivalent authorities.
- Business transfers: in connection with a merger, acquisition, financing, or asset sale, with notice to you.
- With your consent: any other sharing you authorize.
We do not sell your personal information for money. We may share limited identifiers with analytics providers which, under California law, can be considered "sharing" for cross-context behavioral advertising. You can opt out — see Section 8.
5. International Data Transfers
We are headquartered in the United States and process data in the U.S. and other countries where our service providers operate. For transfers from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, and supplementary measures as appropriate.
6. Data Retention
We retain data only as long as needed for the purposes described:
- Account data: while your account is active, plus up to 90 days after deletion for backups and legal obligations.
- Content (posts, comments, DMs): until you delete them or your account is closed; backups purged within 90 days.
- Live Session recordings (where captured): up to 30 days for routine safety review, longer where required to preserve evidence of prohibited conduct or comply with legal process.
- Payment and subscription records: retained for the period required by tax and financial-regulatory law (typically 7 years).
- Moderation and audit logs: retained for the lifetime of the underlying content and a reasonable period thereafter for regulator response.
- CSAE-related evidence: preserved as required by law for reporting to NCMEC and law enforcement.
7. Your Rights
Depending on where you live, you may have the right to: access your data; correct inaccurate data; delete your data; restrict or object to processing; data portability; withdraw consent; opt out of automated decision-making with legal or similarly significant effects; and lodge a complaint with your local data protection authority.
Submit requests to support@crownmemedia.com with the subject "Privacy Request." We will verify your identity before acting and respond within the timeframes required by applicable law (typically 30–45 days).
8. California Residents (CCPA/CPRA)
California residents have additional rights, including the right to know, delete, correct, limit use of sensitive personal information, and opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals. To exercise these rights, email support@crownmemedia.com with subject "California Privacy Rights." We do not knowingly sell or share personal information of consumers under 16, and CrownMe Media is not directed to anyone under 18.
9. Children & Age Verification
CrownMe Media is not intended for and does not knowingly collect personal information from anyone under 18. If we learn we have collected information from a minor, we will delete it and terminate the associated account. See our Child Safety Policy.
10. Security
We use industry-standard administrative, technical, and physical safeguards including encryption in transit (TLS), encryption at rest, role-based access control, row-level security on our database, immutable financial-integrity audit logs for Crown Shield and Founder ledgers, and continuous monitoring. No method of transmission or storage is 100% secure; you use the Service at your own risk. We will notify affected users and regulators of a personal-data breach where legally required and without undue delay.
11. Automated Decision-Making
We use automated systems to rank content, detect fraud, screen for CSAE, and flag potentially violating content for human review. We do not make decisions that produce legal or similarly significant effects on you solely by automated means; enforcement actions with meaningful impact are reviewed or reviewable by a human, and you may request human review by contacting us.
11A. Sensitive Content & Moderation Data
To operate our Sensitive Content system we process: your age-eligibility confirmation and timestamp; your Content Filter preference; per-post fields (is_sensitive, sensitive_reason, content_rating, moderation_status, moderation_notes, moderated_by, moderated_at); and a tamper-resistant audit log of every moderation change. Audit entries are accessible only to admins and moderators, retained for the lifetime of the post and a reasonable period thereafter for legal, safety, and regulator response, and may be exported to fulfil lawful requests. See our Sensitive Content Policy for the user-facing rules.
12. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated via the app or email at least 14 days before they take effect.
13. Contact / Data Protection Officer
CrownMe Media, LLC · Wisconsin, USA
Privacy / DPO contact: support@crownmemedia.com (subject: "Privacy Request")
