Your Data, Your Rights

Privacy Policy

We are committed to protecting the privacy and security of our creators and fans. This policy explains how we collect, use, and safeguard your personal data.

Last Updated: April 2026

1

Introduction

FanFusion ("Platform," "we," "us," or "our") is a creator monetisation platform operated in India. This Privacy Policy describes how we collect, use, disclose, store, and protect information about you when you use our website, mobile applications, and related services (collectively, the "Services").

We are committed to compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and all applicable Indian privacy regulations. By accessing or using FanFusion, you consent to the collection and use of your information as described in this policy.

This policy applies to all users of the Platform, including creators, fans, and visitors. If you do not agree with this policy, please do not access or use our Services.

2

Information We Collect

We collect different types of information depending on how you interact with the Platform:

Personal Information

Full name, email address, phone number, date of birth, profile photo, and KYC verification documents (Aadhaar, PAN, or government-issued ID) for creators. We collect this data when you register, create a profile, or verify your identity.

Financial Information

Bank account details, UPI ID, transaction history, payout records, and subscription billing information. Payment card details are processed and stored by our PCI-DSS compliant payment partners and are never stored on our servers.

Usage Data

Device information (type, operating system, browser), IP address, browsing patterns, pages visited, time spent on features, referral sources, and interaction data. This is collected automatically through cookies and similar technologies.

Content Data

Photos, videos, audio, text, and other content you upload or publish on the Platform. This also includes direct messages exchanged between creators and fans, and comments or interactions on published content.

3

How We Use Your Data

We process your personal data only for specific, lawful purposes:

Account Management

Creating, verifying, and maintaining your account. Managing your profile, preferences, and subscription settings.

Payment Processing

Processing subscriptions, fan payments, creator payouts, refunds, and generating financial reports and tax documents.

Platform Improvement

Analysing usage patterns, conducting research, fixing bugs, and developing new features to improve the Platform experience.

Personalisation

Recommending creators, content, and features tailored to your interests and activity on the Platform.

Security & Fraud Prevention

Detecting, preventing, and investigating fraud, abuse, security threats, and violations of our terms of service.

Legal Compliance

Meeting obligations under Indian law, including tax reporting, regulatory filings, responding to legal requests, and enforcing our terms.

4

Data Sharing

We share your data only when necessary and only with trusted partners:

Payment Processors

We share transaction data with licensed payment gateways and banking partners to process subscriptions, payouts, and refunds. These partners are PCI-DSS compliant and bound by strict data protection agreements.

KYC Verification Partners

Creator identity documents are shared with our KYC verification partners for identity validation and compliance with RBI guidelines. Documents are verified and not retained beyond the verification period.

Cloud Hosting (India Region)

Your data is hosted on cloud infrastructure located in India. Our hosting partners adhere to SOC 2 Type II and ISO 27001 standards and process data strictly in accordance with our instructions.

Law Enforcement

We may disclose data when required by law, court order, or government regulation, or when necessary to protect the rights, safety, or property of FanFusion, our users, or the public.

We never sell your personal data.

FanFusion does not and will never sell, rent, or trade your personal information to third parties for their marketing purposes.

5

Data Storage & Security

We employ industry-standard security measures to protect your data:

Encrypted at Rest & in Transit

AES-256 encryption for stored data, TLS 1.3 for all data in transit

India-Based Servers

All primary data storage on servers located within India, compliant with data localisation norms

Access Controls

Role-based access, multi-factor authentication for staff, and principle of least privilege enforced across all systems

Regular Audits

Periodic security audits, vulnerability assessments, and penetration testing by independent third-party firms

6

Cookies & Tracking

We use cookies and similar tracking technologies to enhance your experience:

Essential Cookies

Required for the Platform to function. These enable core features like authentication, session management, and security. They cannot be disabled.

Analytics Cookies

Help us understand how users interact with the Platform, which pages are most visited, and where users encounter errors. Data is aggregated and anonymised. You may opt out of analytics cookies.

Preference Cookies

Remember your settings and preferences, such as language, theme, and notification options. These improve your experience but are not strictly necessary. You may opt out at any time.

7

Creator-Specific Privacy

We provide creators with additional privacy controls over their content and data:

Content Visibility Controls

Creators have full control over who can view their content. You can set posts as public, subscriber-only, or tiered. You can also restrict content by geography or age. Deleted content is permanently removed from our servers within 30 days.

Earnings Data Privacy

Your earnings, payout history, subscriber counts, and revenue analytics are private by default. This data is visible only to you and authorised FanFusion personnel required for platform operations and support.

Subscriber Identity Protection

Creators can see subscriber display names and profile information that subscribers have chosen to make visible. Subscribers' real names, email addresses, and payment details are never shared with creators.

8

Fan-Specific Privacy

We take extra care to protect fan privacy and ensure a safe experience:

Subscription Privacy

Your subscriptions are private. Other users cannot see which creators you subscribe to unless you choose to make this information public. Your subscription activity is not visible on any public profile or feed.

Payment Information Never Shared with Creators

Your payment method details, billing address, and transaction amounts are never disclosed to creators. Creators only see that a subscription or tip was received, along with your chosen display name.

9

Your Rights

Under the DPDP Act 2023 and our commitment to transparency, you have the following rights:

Right to Access

Request a summary of the personal data we hold about you, the purposes of processing, and details of any third parties with whom we have shared it.

Right to Correction

Request that we correct inaccurate, incomplete, or outdated personal data. You can also update most information directly in your account settings.

Right to Deletion

Request deletion of your personal data, subject to legal retention requirements. We will process deletion requests within 30 days.

Right to Data Portability

Request a copy of your personal data in a structured, commonly used, and machine-readable format (JSON or CSV) for transfer to another service.

Right to Withdraw Consent

You may withdraw consent for data processing at any time. This will not affect the lawfulness of processing based on consent before its withdrawal. Note that withdrawing consent may limit your ability to use certain Platform features. To exercise any of these rights, contact us at privacy@fanfusion.in.

10

Data Retention

We retain your data only as long as necessary for the purposes described in this policy:

Active Accounts

We retain your personal data for as long as your account remains active and for a reasonable period thereafter to provide you with services, comply with legal obligations, and resolve disputes.

Post-Deletion (90 Days)

After you delete your account, we retain your data for up to 90 days to allow for account recovery, resolve any pending transactions, and address potential disputes. After this period, your personal data is permanently and irreversibly deleted.

Financial Records (8 Years)

Transaction records, invoices, payout details, and tax-related information are retained for 8 years as required under Indian tax law (Income Tax Act, 1961) and GST regulations. This data is stored securely and accessed only for compliance purposes.

11

Children's Privacy

FanFusion is intended for users who are 18 years of age or older. We do not knowingly collect, use, or store personal data from anyone under the age of 18.

If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data from our systems. If you believe a person under 18 has provided us with personal information, please contact us at privacy@fanfusion.in.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons.

When we make material changes, we will notify you by email and by posting a prominent notice on the Platform at least 30 days before the changes take effect. The "Last Updated" date at the top of this policy will be revised accordingly.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the revised policy. If you do not agree with the changes, you should discontinue use of the Platform and delete your account.

13

Contact Our Data Protection Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer:

Data Protection Officer, FanFusion
We aim to respond to all privacy-related enquiries within 72 hours and will resolve your request within 30 days.