Privacy Policy

Effective Date: August 12, 2025

Introduction

This Privacy Policy applies to services provided by Good Creative Lab Inc. ("SupaClub," "we," "us"). It covers our public websites, including www.supaclub.app (the "Site"), product pages, mobile or web applications, and other digital products that link to or reference this Policy (collectively, the "Services").

For clarity, we use the following terms to refer to the different parties who interact with our Services:

  • A "User" is an individual who creates a universal SupaClub account.
  • A "Customer" is the individual, company, or other legal entity that purchases a subscription plan to build, manage, and administer an Organization.
  • An "End User" is a User who joins, interacts with, or is a member of a Customer's Organization.

This Policy applies to any User, Customer, or End User of our Services.

Our Role and Responsibilities with Your Data

It is critical to understand who controls your data. Your relationship with SupaClub and our Customers creates a two-part data structure that depends on your status in the user journey.

1. SupaClub Account Data (SupaClub is the Data Controller)

When you create or use your universal SupaClub account, we act as the Data Controller for the personal data required to create, maintain, and secure that account. This data is portable and used across the SupaClub platform. This data includes:

  • Your name, email address, and password.
  • Universal profile information (like a profile picture).
  • Information you provide when you first initiate the process of joining an Organization. This initial onboarding data is used to populate and enrich your universal SupaClub profile before you become a member of that specific Organization.
  • For Customers, billing and payment information for your subscription plan.
  • Platform usage data used for security monitoring, product improvement, and analytics.

2. Organization Data (The Customer is the Data Controller)

Once you have completed the initial joining process and have become a member of a Customer's Organization, that Customer acts as the Data Controller for all personal data you generate within that Organization. For this data, SupaClub acts strictly as the Data Processor on the Customer's behalf, as detailed in our Data Processing Agreement. This data includes:

  • Content you post within the Organization (e.g., messages, photos, files).
  • Your activity within the Organization (e.g., event RSVPs, membership status).
  • Any additional profile information you add or custom fields you answer after you have become a member of the Organization.

1. Information We Collect

We collect information about you in the following ways:

  • 1.1 Information You Provide to Us
    We collect information that you provide directly to us. This includes:
    • Account and Registration Information: When you create a User account, we collect your name, email address, and password. We may also collect your address, authentication credentials, profile picture, job title, and other pieces of information you choose to provide.
    • Transaction and Billing Information: If you are a Customer, we collect billing details to process your subscription payments. Your payment information is collected and stored by our third party payment processing company (the "Payment Processor"). As of the Effective Date, Stripe is the Payment Processor and its privacy policy is available at https://stripe.com/us/privacy.
    • User-Generated Content: We collect information when you submit information or feedback to our Site or Services.
    • Communications with Us: We collect information when you request a demo, fill out a contact form, participate in a survey, or otherwise communicate with us.
  • 1.2 Information We Collect from Customers (Data Migration)
    A Customer may provide us with personal information about their members to migrate an existing community to our Services. In this event, the Customer is the Data Controller and is solely responsible for ensuring they have the appropriate legal basis and consents to provide us with this information. We act only as a Data Processor, using this data to pre-populate User profiles for their first-time activation. When a User logs in for the first time and confirms or updates this pre-populated information, they adopt it as their SupaClub Account Data, for which we are the Data Controller. Please see our Data Retention policy for details on un-activated migrated accounts.
  • 1.3 Information We Collect Automatically
    When you access or use our Services, we automatically collect certain information, including:
    • Log and Usage Data: We collect information about your use of the Services, such as the type of browser you use, access times, pages viewed, features used, your IP address, and the page you visited before navigating to our Services.
    • Device Information: We collect information about the computer or mobile device you use to access our Services, including the hardware model, operating system and version, and unique device identifiers.
    • Information Collected by Cookies and Tracking Technologies: We use cookies and web beacons to collect information.
  • 1.4 Information We Collect from Other Sources
    We may obtain information from other sources, such as third-party integrations (e.g., Google login) or marketing partners, and combine it with information we collect directly.

2. How We Use Your Information

We use the information for which we are a Data Controller for purposes such as providing and improving our Services, communication, security, and research.

3. How We Share Your Information

We do not sell or share our users' private personal information for the purpose of cross-context behavioral advertising. We may share information with your Customer (when we are a Processor), with our vendors, in response to legal process, to protect rights, in connection with a business transfer, or with your consent.

4. Data Retention and Security

We retain your personal data as long as needed to fulfill the purposes for which it was collected and to comply with our legal obligations.

  • Un-activated Migrated Accounts: For accounts created via a Data Migration by a Customer, if a User does not log in to activate their account within ninety (90) days from the date of migration, we will automatically delete the associated personal data from our systems. It is the Customer's responsibility to inform their members of this activation requirement.

We take reasonable steps to protect your information, but no system is 100% secure.

5. Your Privacy Rights and Choices

You have rights and choices regarding your personal information:

  • Accessing and Correcting Your Information: You may review and update your SupaClub Account Data at any time by logging into your account. For Organization Data, you must contact the Customer (the Organization administrator) to exercise your rights.
  • Deleting Your Information: You may request to delete your SupaClub account by emailing us at help@supaclub.app. To delete your data from an Organization, you must contact the Customer.
  • Marketing Communications: You may opt out of receiving promotional emails from SupaClub by following the instructions in those emails.

6. International Data Transfers

SupaClub is based in the United States. By accessing or using the Services, you consent to the processing and transfer of your information in and to the U.S. and other countries.

7. California Privacy Rights

If you are a California resident, you have rights under the CCPA. This section describes those rights and how to exercise them. To exercise rights for your SupaClub Account Data, contact us. To exercise rights for Organization Data, contact the relevant Customer.

8. Other Important Information

  • 8.1 Children's Privacy
    The Services are not intended for individuals under the age of 16.
  • 8.2 Links to Other Websites
    Our Services may contain links to other websites. This Policy does not govern those third-party websites.
  • 8.3 Changes to this Privacy Policy
    We reserve the right to change this Policy at any time. We will notify you of any material changes by posting the new Policy on this page, revising the "Effective Date" at the top, and/or by sending notice to the primary email address specified in your account if you are a Customer.
  • 8.4 Contact Us
    If you have any questions about this Policy, you can contact us at help@supaclub.app.