VTuber Marketplace Privacy Policy

Pre-production draft. Recommend licensed attorney review before major scaling. Not legal advice.

Last updated: [LAST UPDATED DATE — set when you publish]

Effective date: [EFFECTIVE DATE — set when you publish]


1. Introduction

VTuber Marketplace ("we," "us") explains here how we collect, use, disclose, and protect information when you use the VTuber Marketplace mobile app, website, and related services ("Service") — a global marketplace for pre-made digital VTuber assets.

Operator: Moxie's Klubhouse LLC

Privacy contact: support@vtubermarketplace.com

This Privacy Policy is incorporated into our Terms of Service. By using the Service, you acknowledge this Policy.

We may update this Policy. We will revise the "Last updated" date and, for material changes, provide notice in the app or by email where appropriate.


2. Information we collect

We group data into the categories below (similar to how major marketplaces disclose data for app stores and state privacy laws).

2.1 Identifiers and account data

DataExamplesSource
Account identifiersUser ID, Google/Apple subject IDGoogle, Apple, or email sign-in
ProfileDisplay name, username, avatar URL, emailGoogle/Apple sync, or entered at sign-up
Phone (sellers only)Phone number, verification timestampYou (SMS OTP), required to unlock seller payouts
Terms acceptanceVersion id, acceptance timestampIn-app acceptance flow

2.2 Seller verification and payouts

DataPurpose
Stripe Connect Express account status`charges_enabled`, `payouts_enabled` flags used to gate publishing and payouts
Stripe identity/KYC dataCollected directly by Stripe during Connect onboarding (identity documents, date of birth, tax ID, bank/payout details) — we receive account status and identifiers from Stripe, not the underlying documents
Seller phone verificationPhone number and verification timestamp, required before a seller can publish listings or receive payouts

We do not collect or store home addresses, ZIP codes, or precise location for discovery — this is a global catalog, not a location-based feed.

2.3 Listing and commerce content

DataPurpose
Listing title, description, price, photos, demo video URL, category, asset/software compatibility tagsMarketplace catalog
License type (OTU/P2U) and seller-authored license textLicensing disclosure to buyers
Listing status, publish/pause history, mature-content (`is_mature`) flagLifecycle and moderation

2.4 Orders and licensing records

DataPurpose
Order records — what was purchased, price, commission tier appliedTransaction history, support, tax records
License acceptance record (`license_snapshot`)Immutable record of the exact license text a buyer accepted at checkout
Payment metadata via StripeCharge/payout status, application-fee amount — we do not store full payment card numbers; Stripe stores those
Link-health-check recordsURLs checked, pass/fail history, and buyer-reported link issues, used to enforce the seller strike system
Listing subscription workspace & billing recordsSubscription status, private seller notes, work status, seller-hosted delivery URLs, work-offer amounts, and Stripe subscription/payment IDs
Profile bulletin posts and commentsPublic profile updates and discussion
Seller portfolio URL, website, social links, showcase imagesPublic seller profile

2.5 Communications

DataPurpose
Direct messages between buyers and sellersContact, safety, abuse prevention
Text from active listing-subscription chats selected for translation, requested target locale, and cached translated viewProvide the optional paid auto-translation feature while preserving the original message
Reports, blocks, moderation notesTrust and safety
Support emailsCustomer support

2.6 Device and usage data

DataPurpose
Device type, OS, app versionDiagnostics
IP address (server logs)Security, fraud prevention
Authenticated sign-in security event (account ID, email/username snapshot, IP address, pseudonymous IP fingerprint, user agent, timestamp)Account protection, abuse correlation, fraud investigation
Product analytics eventsImprove the Service (e.g., PostHog)
Push notification tokenOptional alerts (e.g., order updates, messages)
Advertising ID (if ads enabled)Ad serving per applicable ad-network policies
Pseudonymous marketplace-banner visitor keyDeduplicate and count first-party banner impressions/clicks without retaining the visitor's raw IP address
Saved interface locale, optional listing locales, and banner audience localesLocalize the interface and apply user-selected language/audience filters without geographic discovery

2.7 Information from third parties

ProviderData received
Google / AppleSign-in profile (name, email, photo)
StripeConnect onboarding/KYC status, payment and payout status
YouTube Data APIMetadata used to validate each listing's required demo video (embeddable/made-for-kids checks)
Google Cloud TranslationText selected from an eligible subscription chat and the requested target language; the original message remains canonical
Google Web RiskExternal banner destination URL/domain used to screen for malware and social engineering before and while an ad is live
Email provider (e.g., Resend)Delivery status for transactional emails (verification, order receipts)

3. How we use information

We use information to:

  • Provide and improve the Service (catalog, listings, messages, search, checkout)
  • Authenticate users, verify sellers, and prevent fraud
  • Process orders, platform commission, and Pro Seller subscription payments via Stripe
  • Enforce Community Guidelines and respond to reports
  • Monitor seller download-link health and enforce the strike system
  • Send transactional SMS (seller phone verification) and service notifications
  • Comply with law and protect rights, safety, and property
  • Analyze aggregated usage to improve product decisions
  • We do not sell your personal information. We do not track your physical location — this is a global digital-asset catalog with no location-based discovery.


    4. How we share information

    RecipientWhy
    SupabaseDatabase, auth, storage, edge functions
    StripePayment processing and Stripe Connect seller onboarding/payouts
    Google / AppleSign-in; ad networks when ads are enabled
    YouTube Data APIDemo-video validation for listings
    Analytics provider (e.g., PostHog)Product metrics
    Email providerTransactional emails (verification, order receipts)
    Law enforcement / regulatorsValid legal process or to protect safety
    Business transfersMerger, acquisition, or asset sale (with notice where required)

    We may share public profile and listing content with other users as part of the Service (for example, seller name and license text on a listing).


    5. Your choices and privacy rights

    Depending on where you live (including California, Colorado, Virginia, and other U.S. states with privacy laws), you may have the right to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Opt out of certain processing (where applicable)
  • Appeal a denial of a privacy request (where applicable)
  • How to exercise rights: email support@vtubermarketplace.com or use in-app Delete account in Settings. We will verify your request and respond within timelines required by law (for example, 45 days under CCPA). See How to delete your account for step-by-step instructions, including how to request deletion without the app.

    Account deletion cancels subscriptions where possible, removes your profile, and triggers deletion of listings and content per our retention schedule. Completed order and payment records may be retained per §6 for tax, fraud, and legal-compliance purposes even after account deletion.

    We do not discriminate against you for exercising privacy rights.

    5.1 State-specific notices

    Some U.S. states require additional disclosures. If required by law, we will publish supplements at https://vtubermarketplace.com/privacy/states.


    6. Retention

    Data typeTypical retention
    Active listingsUntil unpublished by the seller, sold under an OTU license, or auto-paused by the strike/link-health system — there is no fixed listing expiry
    Removed/unpublished listingsDeleted per our standard content-deletion schedule, including images
    Account profileUntil you delete your account
    Direct messagesWhile accounts are active, plus up to 90 days after account deletion for safety and abuse investigations
    Cached translated message viewsNo longer than the associated message; deleted with the source message
    Per-conversation translation preferenceUntil changed by the user, the conversation is deleted, or the account is deleted
    Moderation logs~1–2 years for safety and legal defense
    Seller phone verification metadataWhile the seller account is active
    Stripe Connect KYC/account statusWhile the seller account is active, and as required by Stripe/financial regulation thereafter
    Order, license-acceptance, and payment metadataAs required for tax and fraud prevention (often ~7 years)
    Link-health-check recordsRolling window sufficient to evaluate the 12-month strike policy, plus a reasonable audit period
    Sign-in security eventsRaw IP address up to 30 days; pseudonymous event record, email/username snapshot, and user agent up to 180 days
    First-party marketplace-banner impression/click eventsUp to 7 days; anonymous events contain a keyed pseudonymous visitor value rather than a raw IP address
    Terms acceptance recordWhile account exists + legal hold period

    We may retain information longer when required by law or to resolve disputes.


    7. Security

    We use technical and organizational measures including encryption in transit, access controls, and database row-level security. No system is 100% secure. Protect your account credentials, and enable two-factor authentication where available.


    8. Children's privacy

    The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 (or a higher minimum age where local law requires it). A minor who is permitted to hold an account must use it with a parent or legal guardian's permission and involvement. Mature content is restricted to users who acknowledge they are at least 18. Contact support@vtubermarketplace.com to request deletion if you believe a child provided personal information without the required permission.


    9. International users

    VTuber Marketplace is a global marketplace operated from the United States. If you access the Service from elsewhere, your information may be processed in the U.S. where privacy laws may differ from your country.


    10. Cookies and similar technologies

    The mobile app does not use browser cookies. Our website (if any) and analytics providers may use cookies or similar technologies — disclosed on our website when published.


    11. Changes to this Policy

    We will post updates with a new "Last updated" date. Material changes may be notified in-app or by email. Continued use after notice means you accept the updated Policy where permitted by law.


    12. Contact

    Privacy: support@vtubermarketplace.com

    Support: support@vtubermarketplace.com