🛡️ Privacy Policy

Return to Steply

Effective Date: 7 August 2026 | Last Revised: 7 August 2026

Data Controller: Steply (“Steply”, “we”, “us”, or “our”) | Primary Contact: steply.legal@gmail.com

1. Introduction, Scope & Controller Identification

Steply respects your right to privacy and is committed to maintaining high standards of data protection across our digital ecosystem. This Privacy Policy (“Policy”) governs the processing of personal data collected through the Steply web platform, client applications, smart display/TV presentation modes, and API endpoints (collectively, the “Services”).

1.1 Data Controller Role: For the purposes of the General Data Protection Regulation (GDPR/UK GDPR), the Australian Privacy Act 1988 (Cth), and applicable global data protection laws, Steply is the Data Controller responsible for your personal information.

1.2 EU/UK Representative: Steply processes personal data of individuals in the EEA and UK in accordance with the GDPR and UK GDPR. As an entity established outside the EEA and UK whose processing is non-large-scale, low-risk, and incidental to core operations, Steply relies on the Article 27(2) exemption. Data subjects and supervisory authorities may contact our global compliance team directly at steply.legal@gmail.com.

1.3 Applicability: This Policy applies to registered account holders, workspace visitors, advertising partners, and TV/display hosts globally. By registering for an account, configuring workspace widgets, or interacting with our Services, you acknowledge the data collection, usage, and transfer practices outlined in this Policy.

2. Categories of Information We Collect

We collect information directly from you, automatically as you navigate our platform, and from linked third-party authentication and data services.

2.1 Information You Provide Directly:

  • Account Credentials & Profile Records: Unique Account ID (UUID), email address, assigned role (user, admin, advertising), contact name, business identifiers, theme preferences, and user-initiated configuration parameters.
  • Regional & Geographic Inputs: User-selected country/region codes (country_code) and explicit geographic verification indicators (has_confirmed_geo) used to localize workspace widgets.
  • Legal Consent Audit Trails: Timestamped records, IP snapshots, and policy version strings (terms_accepted_at, terms_version) documenting your explicit acceptance of our Terms & Conditions and this Policy.

2.2 Information Collected Automatically:

  • Display & Session State Identifiers: Full-screen presentation mode flags (isTvDisplayMode), local storage session keys, TV pairing tokens, and layout state buffers.
  • Telemetry & Network Analytics: Anonymous impression counters (p_impressions_count), ad engagement events, layout cycle frequencies, and widget render performance metrics used for ad network settlement and host wallet credit allocations.
  • Technical Infrastructure Logs: IP address, HTTP headers, user-agent strings, browser engine type, operating system build, edge node latency timers, and application error stack traces.

2.3 Cookies, Local Storage & Client-Side Persistence: We use client-side storage technologies (cookies, localStorage, sessionStorage) to maintain operational state:

  • Strictly Necessary Storage: Enables security handshakes, user authentication sessions, and core layout rendering. These cannot be disabled without breaking core functionality.
  • Preference & State Storage: Stores chosen layout themes, sidebar states, active widget arrays, and display options across browser reloads.
  • Telemetry & Security Storage: Tracks temporary tokens to prevent duplicate impression manipulation, fraudulent telemetry, and bot abuse.

Managing Your Cookie Preferences: Where required by applicable law (such as in the European Economic Area and the United Kingdom under the ePrivacy Directive and PECR), non-essential cookies and local storage technologies—including preference and telemetry cookies—are set only after receiving your explicit opt-in consent via our Cookie Preference Banner. You may adjust or withdraw your consent preferences at any time by managing your browser's storage settings.

2.4 Financial & Payment Data (Stripe Integration): All financial transactions, payment instrument details, subscription tiers (is_pro), and payout account information are processed directly by our merchant partner, Stripe. Steply does not collect or store raw payment card primary account numbers (PANs) or sensitive financial verification credentials on our primary servers. All payment activities are subject to Stripe's Privacy Policy.

2.5 Integrated Third-Party Credentials (Google OAuth): When you connect external integrations (such as Google Calendar or Google Drive), we store encrypted OAuth 2.0 access and refresh tokens in restricted serverless vaults.

Google API Limited Use Compliance: Steply's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Tokens are used solely to fetch and render user-authorized widget streams.

3. Purposes of Processing & Legal Bases

We process your personal information strictly for the purposes below under Article 6 of the GDPR:

  • Account Creation & Authentication: Contractual Necessity (Art. 6(1)(b))
  • Dashboard Localization: Contractual Necessity (Art. 6(1)(b))
  • Subscription & Payout Settlement: Contractual Necessity (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c))
  • Telemetry & Anti-Fraud Verification: Legitimate Interests (Art. 6(1)(f))
  • Platform Security & Infrastructure: Legitimate Interests (Art. 6(1)(f)) & Legal Obligation
  • Consent & Audit Logging: Legal Obligation (Art. 6(1)(c))
  • Direct Service Marketing: Consent (Art. 6(1)(a))

4. Sub-Processors & Data Sharing Protocols

Steply does not sell, rent, or monetize your personal information to third-party data brokers. Information is shared strictly with the sub-processors below, each bound by a Data Processing Agreement (DPA):

  • Supabase, Inc.: Primary database, authentication & edge functions (US / EU)
  • Stripe, Inc.: Payments & payout processing (Global / US)
  • Google LLC: OAuth authentication & calendar feeds (Global / US)
  • Open-Meteo: Regional weather data feed (EU)

Steply Ad Network (First-Party): The Steply Advertising Network operates strictly as a first-party ad server. Telemetry and impression counts are processed internally on Steply infrastructure. No user personal data, browsing profiles, or impression logs are sold, shared, or transmitted to third-party demand-side platforms (DSPs) or external ad exchanges.

5. Cross-Border Data Transfers & Global Safeguards

Steply operates globally across Australia, the United States, the European Union, and regional edge locations.

5.1 Australian Privacy Principle 8 (APP 8): We take reasonable steps to ensure overseas recipients handle personal data consistently with the Australian Privacy Principles.

5.2 EU / UK Standard Contractual Clauses (SCCs): Transfers outside the EEA/UK rely on the European Commission's SCCs and the UK International Data Transfer Addendum.

6. Region-Specific Rights Disclosures

6.1 Australian Rights (Privacy Act 1988): Entitled to access, update, and correct personal information or lodge a complaint under the APPs.

6.2 EEA & UK Rights (GDPR): Statutory rights to Access, Rectification, Erasure, Restriction, Objection, Data Portability, and Consent Withdrawal.

6.3 US State Rights (CCPA/CPRA): Right to Know, Right to Opt-Out of Sale/Sharing, Right to Limit Sensitive Data Usage, and Non-Discrimination.

7. Data Security Architecture & Retention Schedule

7.1 Security Safeguards: TLS 1.3 encryption in transit, AES-256 at rest, Supabase Row Level Security (RLS) policies, and encrypted serverless token vaults.

7.2 Data Retention Schedule: Profile records and settings are retained during active account lifespans and purged within 30 days of account deletion. Payment ledger logs are retained for 7 years under statutory tax requirements. OAuth tokens are purged immediately upon revocation.

7.3 Unclaimed Funds & Pending Affiliate Balance Forfeiture: Upon voluntary account deactivation or termination, any accrued Affiliate Cash, pending referral rewards, or publisher wallet credit balances that have not reached the mandatory withdrawal threshold ($100.00 AUD) shall be immediately and irrevocably forfeited. Because unreached thresholds do not constitute fully vested or payable debt obligations, Steply retains no liability or duty to disburse balances under $100.00 AUD once deactivation is initiated. If an account is reactivated within the 30-day grace period, pending balances held prior to deactivation will be restored to the user's wallet ledger.

8. Data Breach Protocol

In the event of a confirmed data breach likely to cause serious harm, we will notify competent supervisory authorities (including the OAIC) within 72 hours and inform affected users directly without undue delay.

9. Protection of Minors

Services are intended solely for individuals aged 18 or older. We do not knowingly collect information from minors below this age.

10. Data Subject Rights & Requests

Submit formal privacy requests to steply.legal@gmail.com. Requests are verified and fulfilled free of charge within 30 calendar days.

11. Dispute Resolution & Complaints

Contact us first at steply.legal@gmail.com. Unresolved complaints may be escalated to the OAIC (Australia), ICO (UK), local EU DPAs, or state Attorneys General (US).

12. Policy Updates

Material updates will be notified via platform announcements or email at least 14 days prior to taking effect.

13. Contact Information

Legal & Privacy Email: steply.legal@gmail.com
Jurisdiction & Governing Law: South Australia, Australia