Privacy Policy
Versión en español →Last updated: 19 May 2026
This policy explains what personal data Streamea collects, why, and your rights under the General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).
1. Data Controller
The data controller is Marcos Hernandez, autónomo registered in Spain (NIF: [OPERATOR_NIF], address: [OPERATOR_ADDRESS]).
Contact: legal@streamea.live
2. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name, password hash | You |
| OAuth data | Google profile ID, profile picture URL | |
| Stream metadata | Title, tags, start/end times, viewer count | You (streaming) |
| Payment data | Stripe customer ID, last 4 digits, billing country | Stripe |
| Transaction records | Token purchases, tips, subscription payments | Platform |
| Usage data | Pages visited, features used, session timestamps | Automatically |
| Technical data | IP address, browser type, OS, country/region | Automatically |
| Content reports | Report text, reporter ID, reported content timestamp | You |
We do not collect sensitive personal data (health, religion, biometrics, etc.) and we do not collect data from children under 18.
3. Legal Basis and Purpose
| Purpose | GDPR legal basis |
|---|---|
| Providing and operating the service | Art. 6(1)(b) — contract performance |
| Age verification (18+ requirement) | Art. 6(1)(c) — legal obligation |
| Processing payments and payouts | Art. 6(1)(b) — contract performance |
| Fraud prevention and platform security | Art. 6(1)(f) — legitimate interest |
| Sending transactional emails | Art. 6(1)(b) — contract performance |
| Marketing emails (only if opted in) | Art. 6(1)(a) — consent |
| Legal compliance and regulatory obligations | Art. 6(1)(c) — legal obligation |
| Content moderation (evidence buffer on reports) | Art. 6(1)(c) — legal obligation / Art. 6(1)(f) — legitimate interest |
4. Sub-processors
We share your data with the following processors. Each is bound by appropriate data processing agreements.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (AWS eu-central-1) |
| Stripe | Payment processing, KYC, payouts | USA (SCCs apply) |
| LiveKit Cloud | Live video infrastructure | USA/EU (SCCs apply) |
| Cloudflare | CDN, WAF, geofencing | Global |
| Upstash | Redis cache (rate limiting, real-time state) | EU |
| Resend | Transactional email delivery | USA (SCCs apply) |
| Sentry | Error monitoring and diagnostics | USA (SCCs apply) |
Transfers to the USA are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission under Art. 46(2)(c) GDPR.
5. Data Retention
| Data type | Retention period |
|---|---|
| Account data | Active while account exists; deleted within 90 days of deletion request |
| Payment records | 7 years (Spanish tax law, Art. 30 Código de Comercio) |
| Stream metadata | 30 days after stream ends |
| Content report evidence buffer | 30 days if no action taken; 2 years if action taken |
| Usage and access logs | 90 days |
6. Your Rights (GDPR)
Under GDPR Articles 15–22, you have the following rights:
- Access (Art. 15): request a copy of your personal data.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): request deletion of your data ("right to be forgotten"), subject to retention obligations.
- Restriction (Art. 18): restrict processing in certain circumstances.
- Portability (Art. 20): receive your data in a structured, machine-readable format.
- Object (Art. 21): object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)): at any time, without affecting the lawfulness of prior processing.
To exercise any right, contact legal@streamea.live. We will respond within 30 days.
7. Cookies
We use strictly necessary cookies only — a session token cookie required for authentication. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
You cannot opt out of strictly necessary cookies without losing access to your account. No consent banner is required for strictly necessary cookies under the Spanish LSSI.
8. Complaints
If you believe we have processed your data in violation of GDPR, you have the right to lodge a complaint with the Spanish supervisory authority:
Agencia Española de Protección de Datos (AEPD)
www.aepd.es
We encourage you to contact us first at legal@streamea.live so we can try to resolve your concern directly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email at least 30 days before material changes take effect. The "last updated" date at the top of this page indicates when the policy was last revised.