Privacy Policy
Most of the personal information involved in a Showcase transaction is collected and held by Stripe, not by us. This policy explains what we hold, what Stripe holds, what the Customer you buy from holds, and what you can ask each of us to do about it.
1. Who we are and what this covers
Showcase Secure, Inc. ("Showcase," "we," "us"), a Delaware corporation operating from California, provides the Showcase Platform. This policy explains how we handle personal information when you visit our websites, create or use an account, publish or purchase content, or contact us.
It covers two groups of people: Customers, the practitioners, artists, and publications who hold accounts and publish content; and Subscribers, the people who view or purchase that content. Where a rule applies to only one group, we say so.
This policy covers Showcase's own handling of personal information. It does not cover a Customer's handling of Subscriber information, which is governed by that Customer's own privacy notice as described in Section 2.4, and it does not cover the practices of any site we link to.
2. Our role, Stripe's role, and Customers' role
We are the controller of the information described in Section 3 that we collect through the Platform. Where we host content and account data on behalf of a Customer, we act as a processor or service provider for that Customer and handle the data on their documented instructions.
Stripe, Inc. and its affiliates process payments for the Platform. For payment transactions, identity verification, fraud prevention, and its own legal and regulatory obligations, Stripe acts as an independent controller of the personal information it collects, not as our processor. Stripe's handling of that information is governed by the Stripe Privacy Policy and, for Customers, by the Stripe Services Agreement. We cannot change how Stripe uses data in that capacity.
In practice this means the large majority of sensitive payment and identity information relating to a Showcase transaction is collected by Stripe through Stripe-hosted onboarding and checkout, is held in Stripe's systems, and reaches us only in the limited form described in Section 4. We never receive or store full payment card numbers.
Customers are independent controllers of their Subscriber relationships. When you purchase from a Customer, we disclose to that Customer the information needed to fulfil and account for your purchase — typically your name, email address, and the transaction record. From that point the Customer holds that information under its own privacy notice, which may differ from this one, including in whether the Customer shares or sells it. Showcase does not control, participate in, or take responsibility for a Customer's handling of Subscriber information, and a Customer's practices are not ours. Direct questions about a Customer's use of your information to that Customer.
3. Information we collect
Information you give us
- Account and contact details — name, email address, password (stored hashed), business or publication name, phone number, country.
- Eligibility information — professional credentials, licence or registration numbers, portfolio or publication history, and any supporting documents you submit so that we can verify that you qualify for access.
- Content and metadata — the media you publish, together with titles, tags, model and location labels, pricing, and access rules. Content may itself contain personal information about you or about people depicted in it; you are responsible for having the consents described in our Terms.
- Support and correspondence — messages you send us, and records of what we discussed.
Information we collect automatically
- Device and connection data — IP address, approximate location derived from it, browser and device type, operating system, language, and referring page.
- Usage data — pages and media viewed, playback and download events, purchases and unlocks, session timestamps, and feature interactions.
- Security and integrity data — authentication events, DRM licence requests, and signals from our page-integrity monitoring, which detects tampering with the player and its protections. This monitoring inspects the structure of the page in your browser; it does not read the content of other tabs or unrelated sites.
Information we receive from others
- From Stripe — the limited transaction and account data described in Section 4.
- From vendors — watermark identifiers and detection results from IMATAG, licence and playback events from EZDRM, and delivery logs from our hosting and CDN providers.
4. Payment data and Stripe Connect
Customers. To be paid, you open a Stripe Connected Account. Stripe collects your identity and business information directly, which under its know-your-customer and anti-money-laundering obligations typically includes legal name, date of birth, home and business address, government identification documents, tax identifiers, beneficial-ownership details, and bank account details. That information goes to Stripe. Showcase receives back a Connected Account identifier, the verification status of the account, the account's country and default currency, the business or display name, the email associated with it, and any requirements Stripe still needs satisfied. We do not receive your identification documents or full bank account numbers.
Subscribers. Card details are entered into Stripe-hosted payment fields and go directly to Stripe. Showcase receives a payment identifier, the amount, currency and status, the card brand and last four digits, the billing country and postal code where Stripe supplies it, and the email address used for the receipt. We use these to grant access to purchased content, issue receipts and refunds, and reconcile revenue.
Fraud and disputes. Stripe uses transaction and device signals for fraud prevention, including through Stripe Radar. Where a dispute or chargeback arises, we may exchange information about the transaction and the account with Stripe and, where necessary, with the card network and the Customer whose content was purchased.
Reporting. We draw transaction and fee data from Stripe's reporting to produce fee statements and revenue-share reporting for Customers. These contain business and transaction data rather than Subscriber identity data.
5. Watermarking and traceability
Content sold on the Platform may be individually watermarked. When a Subscriber purchases access to a watermarked item, a personalized copy is issued and we record which copy went to which account and transaction. The watermark is imperceptible and does not display personal information; it is an identifier that lets a leaked file be traced back to the account it was issued to.
We use those records only to investigate suspected unauthorized redistribution, to respond to a Customer's report of a leak, to enforce our Terms, and to respond to legal process. We may share the result of a trace with the Customer whose content was leaked.
DRM licence requests are logged so that playback can be authorized and abuse detected. These logs include the account, the item requested, and the time and device characteristics of the request.
6. How we use information
- To create and operate accounts, and to verify eligibility for access.
- To host, deliver, and protect content, including watermarking, DRM, and integrity monitoring.
- To process purchases and subscriptions, grant access, issue receipts, and handle refunds and disputes.
- To calculate fees, produce statements, and meet accounting and tax obligations.
- To provide support and respond to your requests.
- To detect, investigate, and prevent fraud, piracy, abuse, and security incidents.
- To measure and improve the Platform, using aggregated or de-identified data wherever it will do the job.
- To send service messages, and marketing messages where you have opted in or where permitted, with an unsubscribe link in each.
- To comply with law and to establish, exercise, or defend legal claims.
We do not sell personal information, and we do not use your content to train machine learning models for anyone else's benefit.
7. Legal bases
Where the GDPR or UK GDPR applies, we rely on: contract, to provide the Platform and complete transactions; legal obligation, for tax, accounting, and regulatory record-keeping; legitimate interests, for security, fraud and piracy prevention, product improvement, and business communications, balanced against your rights; and consent, for non-essential cookies and for marketing where consent is required. You may withdraw consent at any time without affecting processing already carried out.
10. International transfers
We are based in the United States and our vendors operate in the United States and the European Union. If you are in the EEA, the UK, or Switzerland, your information will be transferred to the United States. Where we do this we rely on the European Commission's Standard Contractual Clauses, the UK Addendum where applicable, and supplementary technical measures including encryption in transit and at rest. Stripe maintains its own transfer mechanisms for the data it controls. You may request a copy of the relevant safeguards from us.
11. Retention
| Data | Kept for |
|---|---|
| Account and profile data | The life of the account, then up to 12 months |
| Eligibility and verification records | The life of the account, then up to 3 years |
| Published content | Until you delete it; backups purge on their own cycle, within 90 days |
| Transaction and fee records | 7 years, for tax and accounting |
| Watermark issuance records | Up to 7 years, so that later-discovered leaks remain traceable |
| Security, DRM, and access logs | 12 to 24 months |
| Support correspondence | 3 years |
We keep information longer where a legal hold, investigation, or dispute requires it. Stripe and Customers apply their own retention periods to the data they control.
12. Security
We use encryption in transit and at rest, access controls and least-privilege administration, DRM and forensic watermarking on protected media, page-integrity monitoring, logging and alerting, and vendor review. Payment card data is handled by Stripe, which is certified as a PCI DSS Level 1 service provider; our own systems are scoped to avoid handling card numbers.
No system is completely secure. If a breach affecting your personal information occurs, we will notify you and the relevant authorities where the law requires it, within the timeframes it sets.
13. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, and opt out of marketing. You will not be treated differently for exercising these rights.
To make a request, email support@showcaseplatform.com. Please make requests by email rather than by post. We will verify your identity, usually through the email address on your account, and respond within the period the applicable law allows — 45 days under California law, extendable once, and one month under the GDPR. An authorized agent may submit a request on your behalf with written proof of authorization.
For personal information Stripe controls, including identity verification records and payment data, direct your request to Stripe through its privacy policy. For information a Customer holds about you as its Subscriber, direct your request to that Customer. We will point you to the right place if you ask us first.
If you are in the EEA or UK, you may complain to your local supervisory authority.
14. California notice
This section gives California residents the notice required by the CCPA as amended by the CPRA. In the last 12 months we collected the following categories of personal information, for the purposes in Section 6, from the sources in Section 3, and disclosed them for business purposes to the recipients in Section 9.
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, IP address, account ID | Yes |
| Customer records | Contact details, billing country, transaction records | Yes |
| Commercial information | Purchases, subscriptions, content accessed | Yes |
| Internet or network activity | Usage, playback, and security logs | Yes |
| Geolocation | Approximate location from IP address | Yes, coarse only |
| Professional information | Credentials, publication history, business details | Yes, Customers only |
| Audio, visual, or similar | Media you publish, which may depict people | Yes, Customers only |
| Sensitive personal information | Account credentials; government ID and financial account details are collected by Stripe, not by us | Limited |
| Inferences | Profiles built from the above | No |
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Our disclosure of a Subscriber's name, email address, and purchase record to the Customer they bought from is made to complete the transaction the Subscriber initiated; what that Customer does with the information afterwards is governed by the Customer's own notice, not by this one, as described in Section 2.4. We use sensitive personal information only for the purposes permitted without a right to limit — providing the service, security, and fraud prevention — so no "Limit the Use of My Sensitive Personal Information" link is required.
California residents may request to know, delete, correct, and opt out as described in Section 13, and may designate an authorized agent. California's "Shine the Light" law does not apply because we do not share personal information with third parties for their own direct marketing.
15. Age and minors
Customer accounts. The holder of a Customer account must be at least 18. This is a consequence of payouts running through Stripe Connect, which does not permit a minor to open a Connected Account. It is not a statement about the audience the Platform or any Customer's content is intended for.
Subscribers. Whether a Customer offers content to Subscribers under 18 is that Customer's decision under its own terms. A Customer that chooses to serve minors is responsible for age verification, for any parental consent the law requires, and for any restrictions that apply to its content. We do not verify the age of Subscribers on a Customer's behalf.
Children under 13. We do not knowingly collect personal information from children under 13, and we do not sell or share the personal information of anyone we know to be under 16. If we learn that we hold information from a child under 13 without the consent the law requires, we delete it. If you believe this has happened, contact us at support@showcaseplatform.com.
16. Changes and contact
We update this policy as the Platform and the law change. We will post the revised version with a new date, and where changes are material we will notify account holders by email or in the Platform before they take effect.
Privacy questions, rights requests, and general support: support@showcaseplatform.com. Email is our primary channel for privacy requests.
Showcase Secure, Inc.
251 Little Falls Drive
Wilmington, DE 19808
United States