1. Who we are
Stratum is a live control platform for streamers and creator teams, operated by [LEGAL ENTITY NAME] (“we”, “us”), a company registered in [JURISDICTION] with its registered office at [REGISTERED ADDRESS]. This policy explains what we collect when you use the Stratum website, the Stratum app and control room, and the marketplace, and what you can do about it.
For data protection purposes, [LEGAL ENTITY NAME] is the controller of the personal data described here. Where we act as a processor on behalf of a creator or organisation that invited you into their workspace, that organisation’s own policy governs the data they put into Stratum.
2. Information we collect
Information you give us
- Account details — the email address, display name, and password or third-party login you sign up with.
- Workspace and staff details — role assignments (Owner, Producer, Moderator, Viewer) and the teammates you invite.
- Purchases — marketplace order history, Arena Coin balances, and the billing details our payment provider needs. We do not store full card numbers.
- Messages you send us — support requests, alpha access requests, and the project brief you submit through the contact form (name, email, company, service, budget, timeline, message, and where you heard about us).
Information from connected platforms
When you connect a streaming or community platform, we receive the data that platform’s API returns under the scopes you approve — for example your channel identity and the follow, subscription, cheer, and raid events shown in your event feed. You can disconnect a platform at any time; we stop receiving new events immediately.
Information collected automatically
- Cookies and similar technologies — the encrypted session cookie that keeps you signed in, the token that protects forms against cross-site request forgery, and the record of the cookie choice you make in the consent banner. Optional cookies are set only if you allow them. See our cookie policy.
- Server logs — IP address, browser and device type, pages requested, and timestamps, kept for security, abuse prevention, and debugging.
What we do not collect
We do not sell personal data, and we do not build profiles about you for other companies to advertise against. Any statistics or marketing cookies run only if you allow them, and you can withdraw that permission at any time. [CONFIRM AT LAUNCH: analytics provider, if any]
3. How we use information
- To operate the control room — authenticate you, keep you signed in, apply role permissions, and deliver live events to your feed and overlays.
- To run the marketplace — process orders, deliver downloads, manage coin balances, and handle refunds.
- To keep the platform safe — detect abuse, prevent fraud, rate-limit requests, and investigate incidents.
- To answer enquiries — respond to the briefs and support requests you send us and, during the alpha, follow up on feedback.
- To improve the product — understand which features are used, in aggregate, and fix what breaks.
- To send service messages — security notices, changes to terms, and, where you have opted in, product updates. You can unsubscribe from marketing at any time.
4. Cookies and similar technologies
Cookies that are strictly necessary — the encrypted session cookie, the CSRF protection token, and the record of your consent choice — are set so the site can function. Everything else is set only after you allow it in the consent banner, which is managed by Cookiebot and blocks non-essential cookies until you decide. The Cookie Policy lists every cookie in use, with its provider, purpose, and lifetime, and is where you go to change your choice.
5. Legal bases for processing (UK and EU)
- Contract — providing the account, control room, and marketplace you asked for.
- Legitimate interests — securing the platform, preventing abuse, answering enquiries you send us, and improving the service, balanced against your rights.
- Consent — optional communications and any non-essential cookies we introduce later. You can withdraw consent at any time.
- Legal obligation — tax, accounting, and lawful requests from authorities.
6. Sharing and disclosure
We share personal data only with the service providers that make Stratum work, and only on what they need: cloud hosting and edge delivery, our authentication and database layer, our payment processor, transactional email, error monitoring, and Cookiebot, which records and stores your cookie consent choice. [LIST NAMED SUB-PROCESSORS]
Other people in your workspace can see activity attributable to your role — that is the point of shared staff controls. We may also disclose data when required by law, to enforce our terms, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy.
7. International transfers
Stratum runs on a globally distributed network, so your data may be processed outside your country. Where we transfer personal data out of the UK or EEA, we rely on adequacy decisions or the UK Addendum and the EU Standard Contractual Clauses, with additional safeguards where needed. [CONFIRM MECHANISMS AND REGIONS]
8. How long we keep data
- Account and workspace data — for as long as your account is active, then deleted or anonymised within [N] days of closure.
- Session cookies — 7 days, matching the session lifetime, or until you sign out.
- Cookie consent record — 12 months, or until you clear it or withdraw consent.
- Live event history — [N] days rolling, unless you export it.
- Order and transaction records — as long as tax and accounting law requires, typically [N] years.
- Contact enquiries — [N] months after the conversation ends.
- Server and security logs — [N] days.
9. Security
Authentication tokens are held in an encrypted, signed, HTTP-only session cookie and are never exposed to browser JavaScript, which removes the token-theft surface that comes with browser storage. Form submissions are protected by a double-submit CSRF token, sensitive endpoints are rate-limited, and traffic is encrypted in transit. Role-based permissions limit what each teammate can reach.
No system is perfectly secure. Use a strong, unique password, keep your platform connections tidy, and tell us at [SECURITY EMAIL] if you find a vulnerability.
10. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, port it elsewhere, or withdraw consent you previously gave. We will respond within the time the law allows — one month under UK and EU rules.
Write to [PRIVACY EMAIL] to make a request. If you are unhappy with our answer, you can complain to your local supervisory authority; in the UK that is the Information Commissioner’s Office.
11. California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request access in a portable form, to request correction or deletion, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. The categories we collect are identifiers, commercial information, internet activity, and audio-visual content you upload; sources, purposes, and recipients are described in sections 2, 3, and 6. Submit a request to [PRIVACY EMAIL]; an authorised agent may act on your behalf with written permission. [CONFIRM VERIFICATION PROCESS]
12. Children’s privacy
Stratum is not for children. You must be at least 13 to use it, and at least 16 in the UK and EEA, or older where your local law requires — see [MINIMUM AGE] in our Terms. We do not knowingly collect personal information from children under 13, as defined by COPPA.
If you believe a child has given us personal information, contact [PRIVACY EMAIL] and we will delete the account and its data promptly. Creators who run channels aimed at children are responsible for their own compliance with COPPA and platform rules.
13. Changes to this policy
When we change this policy we update the date at the top of the page. For material changes we will notify you in the app or by email before they take effect, and where the law requires it we will ask for your consent again.
14. Contact us
Privacy questions and requests: [PRIVACY EMAIL]. Everything else: info@leveltwodesign.com or the contact form. Postal mail: [REGISTERED ADDRESS]. [APPOINT DPO / EU-UK REPRESENTATIVE IF REQUIRED]