Effective Date: 7 August 2026 | Last Revised: 7 August 2026
Data Controller: Steply (“Steply”, “we”, “us”, or “our”) | Primary Contact: steply.legal@gmail.com
Steply respects your right to privacy and is committed to maintaining high standards of data protection across our digital ecosystem. This Privacy Policy (“Policy”) governs the processing of personal data collected through the Steply web platform, client applications, smart display/TV presentation modes, and API endpoints (collectively, the “Services”).
1.1 Data Controller Role: For the purposes of the General Data Protection Regulation (GDPR/UK GDPR), the Australian Privacy Act 1988 (Cth), and applicable global data protection laws, Steply is the Data Controller responsible for your personal information.
1.2 EU/UK Representative: Steply processes personal data of individuals in the EEA and UK in accordance with the GDPR and UK GDPR. As an entity established outside the EEA and UK whose processing is non-large-scale, low-risk, and incidental to core operations, Steply relies on the Article 27(2) exemption. Data subjects and supervisory authorities may contact our global compliance team directly at steply.legal@gmail.com.
1.3 Applicability: This Policy applies to registered account holders, workspace visitors, advertising partners, and TV/display hosts globally. By registering for an account, configuring workspace widgets, or interacting with our Services, you acknowledge the data collection, usage, and transfer practices outlined in this Policy.
We collect information directly from you, automatically as you navigate our platform, and from linked third-party authentication and data services.
2.1 Information You Provide Directly:
country_code) and explicit geographic verification indicators
(has_confirmed_geo) used to localize workspace widgets.terms_accepted_at, terms_version)
documenting your explicit acceptance of our Terms & Conditions and this Policy.2.2 Information Collected Automatically:
isTvDisplayMode), local storage session keys, TV pairing tokens, and
layout state buffers.p_impressions_count), ad engagement events, layout cycle frequencies, and
widget render performance metrics used for ad network settlement and host wallet credit
allocations.2.3 Cookies, Local Storage & Client-Side Persistence: We use client-side storage technologies (cookies, localStorage, sessionStorage) to maintain operational state:
Managing Your Cookie Preferences: Where required by applicable law (such as in the European Economic Area and the United Kingdom under the ePrivacy Directive and PECR), non-essential cookies and local storage technologies—including preference and telemetry cookies—are set only after receiving your explicit opt-in consent via our Cookie Preference Banner. You may adjust or withdraw your consent preferences at any time by managing your browser's storage settings.
2.4 Financial & Payment Data (Stripe Integration): All financial
transactions, payment instrument details, subscription tiers (is_pro), and
payout account information are processed directly by our merchant partner, Stripe. Steply
does not collect or store raw payment card primary account numbers (PANs) or sensitive
financial verification credentials on our primary servers. All payment activities are
subject to Stripe's Privacy Policy.
2.5 Integrated Third-Party Credentials (Google OAuth): When you connect external integrations (such as Google Calendar or Google Drive), we store encrypted OAuth 2.0 access and refresh tokens in restricted serverless vaults.
Google API Limited Use Compliance: Steply's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Tokens are used solely to fetch and render user-authorized widget streams.
We process your personal information strictly for the purposes below under Article 6 of the GDPR:
Steply does not sell, rent, or monetize your personal information to third-party data brokers. Information is shared strictly with the sub-processors below, each bound by a Data Processing Agreement (DPA):
Steply Ad Network (First-Party): The Steply Advertising Network operates strictly as a first-party ad server. Telemetry and impression counts are processed internally on Steply infrastructure. No user personal data, browsing profiles, or impression logs are sold, shared, or transmitted to third-party demand-side platforms (DSPs) or external ad exchanges.
Steply operates globally across Australia, the United States, the European Union, and regional edge locations.
5.1 Australian Privacy Principle 8 (APP 8): We take reasonable steps to ensure overseas recipients handle personal data consistently with the Australian Privacy Principles.
5.2 EU / UK Standard Contractual Clauses (SCCs): Transfers outside the EEA/UK rely on the European Commission's SCCs and the UK International Data Transfer Addendum.
6.1 Australian Rights (Privacy Act 1988): Entitled to access, update, and correct personal information or lodge a complaint under the APPs.
6.2 EEA & UK Rights (GDPR): Statutory rights to Access, Rectification, Erasure, Restriction, Objection, Data Portability, and Consent Withdrawal.
6.3 US State Rights (CCPA/CPRA): Right to Know, Right to Opt-Out of Sale/Sharing, Right to Limit Sensitive Data Usage, and Non-Discrimination.
7.1 Security Safeguards: TLS 1.3 encryption in transit, AES-256 at rest, Supabase Row Level Security (RLS) policies, and encrypted serverless token vaults.
7.2 Data Retention Schedule: Profile records and settings are retained during active account lifespans and purged within 30 days of account deletion. Payment ledger logs are retained for 7 years under statutory tax requirements. OAuth tokens are purged immediately upon revocation.
7.3 Unclaimed Funds & Pending Affiliate Balance Forfeiture: Upon voluntary account deactivation or termination, any accrued Affiliate Cash, pending referral rewards, or publisher wallet credit balances that have not reached the mandatory withdrawal threshold ($100.00 AUD) shall be immediately and irrevocably forfeited. Because unreached thresholds do not constitute fully vested or payable debt obligations, Steply retains no liability or duty to disburse balances under $100.00 AUD once deactivation is initiated. If an account is reactivated within the 30-day grace period, pending balances held prior to deactivation will be restored to the user's wallet ledger.
In the event of a confirmed data breach likely to cause serious harm, we will notify competent supervisory authorities (including the OAIC) within 72 hours and inform affected users directly without undue delay.
Services are intended solely for individuals aged 18 or older. We do not knowingly collect information from minors below this age.
Submit formal privacy requests to steply.legal@gmail.com. Requests are verified and fulfilled free of charge within 30 calendar days.
Contact us first at steply.legal@gmail.com. Unresolved complaints may be escalated to the OAIC (Australia), ICO (UK), local EU DPAs, or state Attorneys General (US).
Material updates will be notified via platform announcements or email at least 14 days prior to taking effect.
Legal & Privacy Email: steply.legal@gmail.com
Jurisdiction
& Governing Law: South Australia, Australia