Privacy & Data Protection Notice

Onflay LLC

Publication date: August 13, 2026
Effective date: August 17, 2026

This Privacy & Data Protection Notice explains how Onflay LLC collects, uses, discloses, retains, and protects personal information when people visit Onflay, create accounts, sell or purchase Offerings, use the API, attend a course or service, receive Payouts, or otherwise interact with the Platform. Beginning on the Effective date, this Notice supersedes earlier published versions prospectively. It does not retroactively change the purposes, disclosures, rights, or legal bases applicable to earlier processing.

It also includes the Data Processing Addendum that applies when Onflay processes personal data solely on a Creator’s documented instructions.


1. Who we are and scope

Onflay LLC is a Wyoming limited liability company located at:

1021 E Lincolnway, Suite 10028
Cheyenne, Wyoming 82001
United States

Privacy contact: support@onflay.com

This Notice applies to visitors; Buyers; Creators, Suppliers, Developers, and their personnel; Platform Subscription subscribers; AI Feature users; course, workshop, consultation, and event participants; support contacts; and other persons whose information is processed through Onflay.

It covers Onflay websites, dashboards, storefront and checkout interfaces, APIs, SDKs, webhooks, AI Features, Stripe Connect and other Supported Payment Provider integrations, Didit verification, Platform Subscriptions, AI Credits, analytics, communications, support, and related services.

Creator onboarding is currently considered for approved persons in the United States, the Dominican Republic, and Colombia. Buyers and other users may be elsewhere where the relevant service is enabled, so additional mandatory privacy laws may apply.

This Notice also includes the Data Processing Addendum in Section 18 for processing performed solely on a Creator’s documented instructions.

2. Onflay’s data-protection roles

Onflay’s role depends on the purpose, data flow, and Commerce Mode. Contractual labels do not override applicable privacy law.

2.1 Onflay as independent controller

Onflay generally determines the purposes and means of processing for:

  • Account administration, authentication, permissions, and security;
  • Commerce Mode review, selection, approval, acceptance, and change records;
  • Platform Subscription enrollment, billing, renewal, cancellation, plan, Pricing Page, custom-price, promotion, and acceptance records;
  • AI Feature operation for Onflay’s own service purposes, AI Credit purchases, balances, metering, fraud controls, and support;
  • Creator screening, identity, sanctions, KYC, tax forms, and risk;
  • Onflay accounting, legal compliance, audits, policies, analytics, communications, and Platform improvement;
  • prevention of fraud, abuse, security incidents, and prohibited activity; and
  • responding to authorities, legal claims, and regulatory requests.

For an Onflay-Managed Order, Onflay is generally an independent controller for its seller and Merchant-of-Record functions, including checkout, billing, Transaction Taxes, receipts, refunds, chargebacks, disputes, Supplier Fees, Reserves, Provider Costs, and Payouts.

2.2 Creator as independent controller

For a Creator Order, the Creator is generally an independent controller for its seller and Merchant-of-Record activities, including Buyer relationship, checkout purposes, payment-provider account, receipts, invoices, Transaction Taxes, fulfillment, support, refunds, disputes, legal notices, marketing, and regulatory duties.

A Creator is also generally an independent controller for operating its external SaaS, software, API, membership, community, course, workshop, event, consultation, and other Offering; using personal information for its own lawful purposes; and determining what information it submits to AI Features.

The Creator must provide its own privacy notice and obtain any consent or authorization required for its purposes.

2.3 Onflay as processor or service provider

Onflay acts as processor or service provider only when it processes personal data solely on a Creator’s documented instructions and not for an independent Onflay purpose. Section 18 applies to that processing.

The same data may be processed in different roles for different purposes. For example, Onflay may process order data as a processor for a Creator’s fulfillment workflow while independently processing limited records for security, billing, fraud prevention, legal compliance, or enforcement.

2.4 Supported Payment Providers and AI providers

A Supported Payment Provider, bank, payment network, identity provider, or AI provider may act as Onflay’s processor or service provider, the Creator’s processor, an independent controller, or another legally recognized recipient depending on the actual contract and purpose.

Provider-specific agreements and notices also apply, and a provider’s legal role may differ by purpose and configuration.

3. Personal information we collect

The exact information depends on the person, Commerce Mode, Subscription Plan, Offering, AI Feature, provider, and jurisdiction.

3.1 Account, authentication, and Workspace data

We may collect name, email, phone, country, language, password hash, one-time-code records, authentication-provider identifiers, Account and Workspace identifiers, role, permissions, team membership, login, session, device, security, recovery, administrator, and acceptance-authority information.

3.2 Creator, business, and Commerce Mode information

We may collect:

  • legal and display name, date of birth where required, residence, citizenship, operation, address, and contact details;
  • entity formation, registration, directors, representatives, beneficial owners, licenses, insurance, venue, professional information, website, and social profiles;
  • category, Offerings, pricing, transaction size, volume, expected activity, countries, currencies, and tax information;
  • requested and approved Commerce Mode, eligibility, limitations, provider configuration, mode-change history, reasons, risk classification, and review notes;
  • seller and Merchant-of-Record identity and disclosures; and
  • communications and documents submitted during review.

3.3 Identity, KYC, sanctions, tax, and provider-onboarding information

Onflay, Stripe, Didit, or another approved provider may collect or generate:

  • connected-account or merchant-account identifiers, country, account type, controller configuration, charge type, capabilities, requirements, restrictions, and status;
  • government ID details and images, facial image, liveness, identity-match, age, address, residence, citizenship, tax residence, and verification results;
  • business formation, representatives, directors, executives, beneficial owners, bank or settlement destination, and ownership evidence;
  • sanctions, politically exposed person, fraud, adverse-risk, verification score, reason, date, and document-expiration information;
  • Forms W-9, W-8BEN, W-8BEN-E, local tax identifiers, classification, withholding, treaty, reporting, and signature evidence; and
  • provider agreements, onboarding steps, account configuration, and capability history.

Where specific authorization is required for sensitive or biometric data, including under Colombian law where applicable, Onflay will request it separately. Accepting this Notice alone does not constitute such authorization.

3.4 Platform Subscription, Pricing Page, and acceptance data

We may collect and preserve:

  • Subscription Plan, features, limits, billing interval, currency, price, taxes, trial, promotion, discount, custom pricing, and renewal status;
  • Pricing Page version, effective date, displayed terms, account-specific pricing, order form, promotion identifier, and priority source;
  • enrollment, upgrade, downgrade, cancellation, grace period, payment retry, failed payment, suspension, and termination events;
  • Account, accepting user, legal version, acceptance timestamp, interface, device or IP evidence where lawful, and renewal authorization; and
  • price-change notice, delivery evidence, affected renewal, cancellation response, and grandfathered or promotional duration.

3.5 Onflay-Managed Order, Supplier Fee, and Payout data

For Onflay-Managed Commerce, we may collect:

  • Buyer identity and contact, billing and service address, tax number, IP and permitted location evidence;
  • Offering, Listing, Order, price, discount, currency, Transaction Taxes, payment and receipt identifiers;
  • Managed Fee Base, percentage and fixed rates, taxes included in the base, Managed Transaction Fee, Provider Costs, Supplier Fee, Reserve, setoff, negative balance, adjustments, and rate snapshot;
  • fulfillment, access, subscription, refund, cancellation, chargeback, dispute, evidence, and support history;
  • Payout destination, beneficiary, country, currency, amount, date, provider, conversion, bank charges, returned payment, delay, and reconciliation information; and
  • tax, accounting, audit, fraud, and legal records.

Raw card numbers and security codes are entered into provider-hosted or provider-controlled fields and are not stored by Onflay unless a future flow expressly states otherwise and is lawfully implemented.

3.6 Creator Order, payment-provider, and Provider Settlement data

For Creator-Managed Payments, we may receive or generate:

  • Creator and Buyer identifiers, Offering, price, currency, tax metadata, Order, entitlement, and subscription status;
  • Supported Payment Provider account, customer, payment, charge, refund, dispute, balance, transfer, and settlement identifiers;
  • Merchant Proceeds, Provider Settlement status, provider fees, reserves, holds, conversion, negative balances, and reconciliation data;
  • seller disclosures, receipt or invoice status, refund policy, support routing, and complaint records; and
  • technical events needed for white-label checkout, webhooks, analytics, fraud controls, subscription management, and evidence.

Onflay may not receive all provider data. Onflay does not treat Merchant Proceeds as Supplier Fees and does not charge a transaction fee, platform application fee, commission, or percentage of Creator Order value.

3.7 AI Feature, prompt, output, and AI Credit data

We may collect or generate:

  • prompts, instructions, uploaded files, images, text, metadata, context, and other inputs;
  • generated text, images, recommendations, classifications, transformations, and other outputs;
  • model, provider, version, safety classifier, feature, quality, size, duration, tokens, complexity, latency, error, and policy-block information;
  • user review, edits, approval, publication, feedback, and support records;
  • AI Credit package, purchase, price, taxes, balance, allocation type, reset, consumption, adjustment, refund, failed-operation restoration, and maximum-balance controls;
  • Included AI Credit cycle and non-rollover records; and
  • Purchased AI Credit and auto-replenishment authorization, trigger, amount, frequency or spending limit, cancellation, and confirmation.

Onflay and its AI providers process this information to provide the requested feature, maintain security, prevent abuse, troubleshoot, support users, evaluate quality, and improve Onflay services. Onflay does not use Creator inputs or outputs to train an Onflay general-purpose model unless that materially different practice is separately disclosed before the relevant use. A third-party provider’s retention or model-improvement practice depends on the applicable provider, contract, configuration, and feature disclosure.

3.8 SaaS, software, membership, entitlement, and usage data

We may collect external customer and Account identifiers; product, plan, seat, trial, subscription, entitlement, activation, renewal, cancellation, access, and webhook events; usage quantities used for Buyer billing, Platform limits, or AI metering; login or feature-use evidence; and technical data needed to reconcile access with payment.

3.9 Courses, workshops, consultations, events, and attendance

We may collect booking, date, time, time zone, location, participant, organizer, ticket, one-time QR or OTP, check-in, attendance, start, end, completion, scanner or staff identifier, venue, safety, incident, accessibility request, communication, and evidence concerning delivery, cancellation, or dispute.

We do not require continuous precise location, participant photos, or biometric attendance data by default.

3.10 Communications, support, device, analytics, and security data

We may collect messages, attachments, call or meeting metadata, support history, complaint and appeal information, IP address, browser, operating system, device, cookie and local-storage identifiers, pages, clicks, navigation, feature use, approximate location, campaign information, error, performance, diagnostics, session replay where enabled, security events, and fraud signals.

Sensitive fields should be masked or excluded from session replay and analytics where reasonably possible.

3.11 Information from third parties

We may receive information from:

  • Buyers, Creators, Suppliers, Developers, and Account administrators;
  • Stripe, other Supported Payment Providers, payment networks, acquiring banks, Payout providers, and receiving banks;
  • Didit and other identity, business, sanctions, fraud, and risk providers;
  • AI model and infrastructure providers;
  • tax, address, exchange-rate, accounting, and audit providers;
  • authentication, calendar, meeting, communications, cloud, analytics, and support providers;
  • public business and professional registries; and
  • authorities and persons submitting legal, consumer, privacy, or intellectual-property notices.

4. Why we use personal information

We use personal information to:

  • create, secure, authenticate, and administer Accounts and Workspaces;
  • evaluate, approve, record, and enforce Commerce Modes and mode changes;
  • screen Creators, Offerings, entities, owners, identity, sanctions, tax status, provider eligibility, and risk;
  • act as seller and Merchant of Record for Onflay-Managed Orders;
  • provide Platform technology for Creator Orders without assuming the Creator’s seller role;
  • process or route orders, subscriptions, payments, taxes, receipts, refunds, reversals, chargebacks, disputes, Supplier Fees, Provider Costs, Reserves, Payouts, Merchant Proceeds data, and Provider Settlements;
  • offer, bill, renew, change, cancel, and support Platform Subscriptions;
  • display and preserve Pricing Page, custom price, promotion, consent, renewal, and transaction-level rate records;
  • provide AI Features, send data to selected AI providers, meter usage, administer AI Credits, restore failed operations where applicable, prevent abuse, and provide support;
  • fulfill or facilitate SaaS, API, membership, course, workshop, event, consultation, entitlement, and attendance functions;
  • communicate legal, account, price, renewal, cancellation, tax, security, and service information;
  • maintain accounting, tax, contractual, provider, fraud, audit, and legal records;
  • comply with law, courts, regulators, consumer authorities, payment networks, financial institutions, and provider requirements;
  • enforce the Master Terms and Commerce, Safety & Refund Policy;
  • protect users, Onflay, Creators, providers, and the public; and
  • improve reliability, accessibility, features, models, workflows, and performance where lawful.

Where consent or another specific authorization is legally required, we use information for the additional purpose only after obtaining that authorization.

Where applicable law requires a legal basis, Onflay relies on one or more of:

  • Contract: processing needed to create an account, accept an order, deliver access, administer a subscription, pay a Supplier, or enforce an agreement.
  • Legal obligation: tax, accounting, sanctions, KYC, regulatory, consumer, recordkeeping, and lawful-request obligations.
  • Legitimate interests: fraud prevention, security, support, auditing, product improvement, enforcing rights, and operating a safe dual-mode commerce platform and providing Merchant-of-Record services where applicable, balanced against individual rights.
  • Consent: optional marketing, non-essential cookies where required, certain sensitive or voluntary information, or another purpose clearly presented at the time.
  • Protection of vital interests or public interest: only where applicable and necessary.

You may withdraw consent where processing is based on consent. Withdrawal does not affect earlier lawful processing and does not affect processing based on another lawful basis.

Where Colombian Law 1581 of 2012 applies, Onflay will obtain prior, express, and informed authorization when required and preserve evidence of that authorization. A privacy notice or policy does not replace a separate authorization where Colombian law requires one. Legal and contractual exceptions, including information required by a competent authority, may still apply.

6. How we disclose personal information

6.1 Buyers, Creators, Suppliers, and seller identification

For an Onflay-Managed Order, Onflay may disclose Buyer information to the Supplier only as reasonably needed for fulfillment, access, support, safety, tax, fraud, and dispute resolution. Onflay may disclose Supplier identity, brand, contact, and fulfillment information to the Buyer.

For a Creator Order, Onflay may disclose or route Buyer information to the Creator as seller and Merchant of Record and may display the Creator’s legal identity, contact, policy, and tax or invoice information. The Creator’s independent use is governed by its privacy notice and law.

Neither party may use shared data for unrelated marketing or another undisclosed purpose without a lawful basis.

6.2 Supported Payment Providers, payment networks, and financial infrastructure

We disclose information to Stripe and other Supported Payment Providers, payment networks, acquiring banks, Payout providers, receiving banks, correspondent banks, and related infrastructure to:

  • create, configure, enroll, connect, and administer merchant or connected accounts;
  • identify the Merchant of Record and use an appropriate charge configuration;
  • authorize, capture, route, settle, transfer, refund, reverse, or dispute payments;
  • calculate or reconcile fees, Provider Costs, Merchant Proceeds, Supplier Fees, Reserves, negative balances, Payouts, and Provider Settlements;
  • collect and verify identity, entity, tax, bank, country, capability, and beneficiary information;
  • prevent fraud, sanctions violations, abuse, and security incidents; and
  • satisfy network, bank, provider, legal, tax, and audit requirements.

Providers may share account, transaction, compliance, capability, risk, dispute, balance, fee, and settlement data with Onflay as permitted by their agreements and law.

6.3 AI model and infrastructure providers

We may disclose prompts, inputs, outputs, files, model parameters, Account or user identifiers, safety metadata, and technical information to AI providers selected to perform an AI Feature.

Providers may process information to generate output, secure the service, prevent abuse, troubleshoot, provide support, evaluate quality, and perform other purposes described in the applicable feature disclosure and provider arrangement. Their retention, geographic processing, legal role, and model-improvement practices depend on the provider, contract, and configuration.

Onflay does not use Creator inputs or outputs to train an Onflay general-purpose model unless that materially different practice is disclosed before the relevant use. We will provide additional notice or authorization where law requires it before a materially different AI use.

6.4 Identity, tax, compliance, and professional providers

We disclose information to Didit and other identity, sanctions, fraud, risk, tax, address, accounting, audit, insurance, and legal providers as needed for verification, compliance, advice, claims, and records.

6.5 Technology and operations providers

We disclose information to hosting, database, security, authentication, communications, analytics, customer-support, exchange-rate, monitoring, error-reporting, document, e-signature, and integration providers as needed to operate the Platform.

6.6 Authorities and protection of rights

We may disclose information to courts, regulators, tax bodies, law enforcement, consumer authorities, financial institutions, payment networks, or other persons where reasonably necessary to comply with law, respond to lawful process, prevent harm, enforce agreements, investigate fraud, protect rights, or resolve a claim.

We may notify a Supported Payment Provider or competent authority about a Creator Order even where Onflay is not the seller.

6.7 Corporate transactions

Information may be disclosed in connection with financing, due diligence, merger, acquisition, reorganization, sale of assets, insolvency, or transfer to an affiliate, subject to appropriate safeguards and applicable notice requirements.

7. Cookies, analytics, advertising, and similar technologies

7.1 Categories

Onflay may use:

  • Strictly necessary technologies for login, session security, checkout continuity, fraud prevention, preferences, and core functionality.
  • Analytics and performance technologies to understand use, diagnose errors, and improve the Platform.
  • Session-replay or product-research tools with masking and exclusion controls.
  • Advertising and attribution technologies to measure campaigns or reach audiences where enabled and lawful.

7.2 Choices

Where required, non-essential technologies will not be activated until consent is obtained. Where applicable law provides an opt-out right for sale, sharing, targeted advertising, or profiling, Onflay will provide the corresponding control.

Browser settings may block cookies, but blocking necessary technologies can prevent login or purchase completion.

Onflay will honor legally required browser-based preference signals where applicable and technically supported.

8. Automated analysis, AI Features, and consequential decisions

Onflay may use automated systems to identify fraud, sanctions risk, account takeover, prohibited activity, unusual payment or AI Credit behavior, provider eligibility, abuse, or security incidents and to prioritize human review.

Signals may include identity and account data, Commerce Mode, provider configuration, transaction and dispute history, device and network data, Offering category, AI usage, credit consumption, and third-party risk information.

Automated systems may temporarily block a payment, Payout, Provider Settlement routing, AI operation, Account feature, or publication. Where applicable law requires it, Onflay will provide information about significant automated decisions, permit human review, or offer a method to contest the result.

AI-generated recommendations or classifications are not necessarily final decisions. Onflay may use human review for material account, payment, safety, or legal actions.

9. International transfers

Onflay is based in the United States and supports Creators in the United States, the Dominican Republic, and Colombia. We use providers, including Stripe and Didit, that may process information in the United States and other countries. Personal information may therefore be transferred from the Dominican Republic or Colombia and processed outside the person’s country.

Where transfer restrictions apply, Onflay will use an available lawful mechanism, which may include:

  • an adequacy decision;
  • standard contractual clauses;
  • the UK addendum or International Data Transfer Agreement;
  • contractual safeguards recognized under applicable LATAM law;
  • consent where legally valid; or
  • another permitted transfer mechanism.

No transfer mechanism can eliminate every risk associated with foreign government access or different legal systems.

10. Data retention

Onflay retains information for the period reasonably necessary for the purposes described in this Notice, including:

  • Account and acceptance records while the Account is active and for the applicable limitation period;
  • Commerce Mode, seller identity, Pricing Page version, custom pricing, promotion, recurring authorization, and transaction-level fee records for contract, audit, tax, consumer, and dispute requirements;
  • Onflay-Managed Order, Creator Order, tax, receipt, refund, chargeback, Supplier Fee, Payout, Merchant Proceeds, and Provider Settlement records for legally required financial and tax periods;
  • KYC, sanctions, identity, and provider records as required by law, providers, risk, and audit needs;
  • Platform Subscription billing, cancellation, notice, retry, and price-change records for the subscription relationship and applicable claims period;
  • AI prompts, inputs, outputs, model metadata, AI Credit purchases, balances, consumption, and failed-operation records according to the feature disclosure, provider arrangement, security need, Account setting, and legal obligation;
  • support, safety, fraud, incident, and legal-claim records for investigation and limitation periods; and
  • processor data according to Section 18 and the Creator’s documented instructions, subject to legal exceptions.

Retention periods may differ by data type, Commerce Mode, country, provider, and legal duty. A legal hold, unresolved balance, tax audit, refund, chargeback, fraud investigation, or regulatory request may extend retention.

When no longer required, information is deleted, anonymized, or restricted using reasonable processes. Backups may persist until overwritten through ordinary cycles.

The exact retention and deletion configuration for AI inputs and outputs must be confirmed for each provider before the related feature is enabled.

11. Security

Onflay uses administrative, technical, and organizational safeguards designed for the nature and risk of the information, including as appropriate:

  • encryption in transit;
  • encryption or equivalent protection at rest;
  • password hashing;
  • access controls and role separation;
  • administrator authentication and logging;
  • secret and key management;
  • signed payment and webhook events;
  • secure development and vulnerability management;
  • backups and recovery procedures;
  • provider review;
  • incident response; and
  • masking or tokenization of sensitive identifiers.

No system is completely secure. You are responsible for protecting your credentials and promptly reporting suspected compromise.

12. Your privacy rights

Depending on your location and the law that applies, you may have rights to:

  • know or access personal information;
  • correct inaccurate information;
  • delete information;
  • object to or restrict processing;
  • withdraw consent or authorization where applicable;
  • receive portable data;
  • opt out of certain sale, sharing, targeted advertising, or profiling;
  • limit certain uses of sensitive information;
  • appeal a denied request;
  • receive information about recipients, uses, or sources; and
  • complain to a data-protection or consumer authority.

Rights are not absolute. Onflay may retain or continue processing information where necessary for orders, Stripe Connect administration, tax, accounting, fraud, KYC, sanctions, security, legal claims, or another lawful exception.

Submit a request to support@onflay.com. We may verify your identity and authority. An authorized agent may be required to provide proof of authorization.

12.1 Dominican Republic

Where Ley No. 172-13 applies, individuals may exercise available rights concerning access, rectification, update, suppression, or opposition, subject to lawful exceptions. Dominican individuals may also use remedies available before the competent authorities.

12.2 United States

Residents of states with comprehensive privacy laws may have rights provided by their state, including access, correction, deletion, portability, and applicable opt-outs.

Onflay does not sell personal information for monetary consideration. Certain analytics or advertising disclosures may be considered “sharing,” “sale,” or targeted advertising under a particular state law even where no money is exchanged; applicable opt-out methods will be provided when required.

12.3 Colombia

Where Ley 1581 de 2012 and related rules apply, a data subject may have the right to:

  • know, update, and correct personal information;
  • request proof of the authorization provided, except where an exception applies;
  • receive information about how the data has been used;
  • present complaints to the Superintendencia de Industria y Comercio after completing any required direct complaint procedure;
  • revoke authorization or request deletion where legally available; and
  • access personal information free of charge under applicable conditions.

Revocation or deletion may be denied or limited when a legal or contractual duty requires continued processing, including records needed for transactions, tax, accounting, fraud, sanctions, disputes, or legal claims.

12.4 European Economic Area and United Kingdom

Where GDPR or UK GDPR applies, individuals may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.

12.5 Brazil and other LATAM jurisdictions

Where LGPD or another LATAM privacy law applies, individuals may exercise the corresponding statutory rights, subject to verification and lawful exceptions.

13. Children

Onflay is not intended for people under eighteen. Creators may not target an Offering to children unless Onflay has expressly enabled a compliant program; no such program is authorized under the current Commerce, Safety & Refund Policy.

If Onflay learns that it collected a child’s information contrary to this rule, it may delete or restrict the information and account.

14. Communications choices

You may unsubscribe from marketing through the link provided in the message. You cannot opt out of necessary security, order, tax, payout, subscription, legal, or account communications while the relevant relationship exists.

15. Changes to this Notice

Onflay may update this Notice prospectively to reflect changes in Commerce Modes, Supported Payment Providers, Platform Subscriptions, Pricing Page records, AI providers, AI Credit practices, law, security, or operations.

Each version will state its version, publication date, and effective date. Material changes will receive reasonable advance notice where required. Onflay will request new consent or authorization when law requires it, including before materially different use of sensitive information or model training that is not covered by the existing disclosure and lawful basis.

A later Notice does not retroactively make an earlier collection or disclosure lawful.

16. Complaints

Contact support@onflay.com first so Onflay can investigate. You may also complain to a competent data-protection, consumer, or judicial authority where applicable.

17. Contact

Onflay LLC
1021 E Lincolnway, Suite 10028
Cheyenne, Wyoming 82001
United States


18. Data Processing Addendum

18.1 Application

This Data Processing Addendum (“DPA”) applies only when Onflay processes Personal Data solely on a Creator’s documented instructions as a processor or service provider.

It does not apply to Onflay’s independent-controller processing for Account administration, Commerce Mode approval, Platform Subscription billing, Pricing Page and acceptance records, AI Credit purchases and metering, security, fraud, legal compliance, or Onflay-Managed seller functions.

For Creator-Managed Payments, this DPA may apply to limited Platform processing performed solely for the Creator’s fulfillment, storefront, subscription-management, support, or workflow instructions, while both parties may separately act as independent controllers for other purposes.

If a separate signed DPA applies to the same processing, the signed DPA controls.

18.2 Definitions

“Controller,” “processor,” “personal data,” “processing,” “data subject,” and “supervisory authority” have the meanings provided by applicable data-protection law.

“Subprocessor” means a third party engaged by Onflay to process personal data covered by this DPA.

18.3 Processing details

  • Subject matter: hosting, storefront, checkout-interface, API, subscription-management, entitlement, workflow, communication, support, analytics, and other services performed solely under documented Creator instructions.
  • Duration: the service relationship and deletion or return period, subject to lawful retention.
  • Nature: collection, recording, organization, storage, retrieval, consultation, use, transmission, generation, restriction, deletion, and other instructed operations.
  • Purposes: providing the Creator-configured service, fulfilling Creator Orders or Offerings, administering entitlements, support, and other documented purposes.
  • Data subjects: Buyers, prospects submitted by the Creator, Creator personnel, members, students, attendees, customers, and authorized users.
  • Personal Data: identity, contact, account, transaction, subscription, entitlement, usage, support, attendance, communication, and other data configured by the Creator.
  • Sensitive data: not intended unless expressly supported, necessary, lawfully authorized, and documented.

AI prompts or data submitted to an AI Feature are included in this DPA only when the feature and provider arrangement are expressly designated for processor use on the Creator’s documented instructions. Otherwise, the applicable independent-controller or provider terms govern.

18.4 Documented instructions

Onflay will process covered personal data only on documented instructions contained in the Master Terms, this DPA, the Creator’s use of configured features, and lawful written instructions accepted by Onflay.

Onflay may process data where required by law and, unless prohibited, will inform the Creator of that requirement.

If Onflay believes an instruction violates applicable law, it may suspend the instruction and notify the Creator.

18.5 Creator responsibilities

The Creator represents that:

  • it has a lawful basis for the processing and instructions;
  • it has provided required privacy information;
  • its instructions are accurate and lawful;
  • data submitted is relevant and limited;
  • it will respond to data subjects and authorities; and
  • it will not use Onflay to process prohibited or unlawfully obtained data.

18.6 Confidentiality and personnel

Onflay will ensure that personnel authorized to process covered personal data are subject to appropriate confidentiality obligations and access restrictions.

18.7 Security

Onflay will maintain measures appropriate to the risk, which may include:

  • access control;
  • authentication;
  • encryption in transit and at rest where appropriate;
  • availability, backup, and recovery controls;
  • logging and monitoring;
  • incident-response procedures;
  • vulnerability and change management; and
  • provider security obligations.

The Creator remains responsible for secure configuration, its own systems, user permissions, and credentials.

18.8 Subprocessors

The Creator authorizes Onflay to use subprocessors for hosting, infrastructure, communications, support, security, analytics, payment-related technical services, and approved AI processing needed for the instructed service.

Onflay will maintain information about material subprocessors or categories and provide notice of a new subprocessor where required by the applicable agreement or law. The Creator may object on reasonable data-protection grounds within the stated period.

Onflay will impose appropriate contractual data-protection obligations on subprocessors. The label “subprocessor” applies only where the provider actually processes Personal Data on Onflay’s behalf for the Creator-instructed purpose. A Supported Payment Provider or AI provider acting independently is not converted into a subprocessor by this DPA.

18.9 Data-subject requests

Taking into account the nature of processing, Onflay will provide reasonable assistance so the Creator can respond to requests concerning covered personal data.

If Onflay receives a request that relates solely to the Creator’s controller activity, Onflay may direct the requester to the Creator unless law requires a different response.

18.10 Security incidents

Onflay will notify the Creator without undue delay after becoming aware of a confirmed personal-data breach affecting covered personal data.

The notice will include information reasonably available to Onflay concerning the nature of the incident, affected data, likely consequences, and mitigation. A notice is not an admission of fault.

The Creator is responsible for notifications or regulatory filings required because the Creator is controller, except where law assigns the duty to Onflay.

18.11 Assistance

Taking into account the processing and information available, Onflay will provide reasonable assistance with:

  • security obligations;
  • data-protection impact assessments;
  • regulatory consultations;
  • breach analysis; and
  • demonstrations of compliance.

Onflay may charge reasonable fees for extraordinary assistance caused by the Creator’s instructions, except where prohibited.

18.12 Return and deletion

After termination of the applicable processing, Onflay will delete or return covered personal data within a reasonable period, unless retention is required by law, backup cycles, fraud prevention, disputes, or independent-controller obligations.

18.13 Audits

Onflay will make information reasonably necessary to demonstrate compliance available through documentation, certifications, summaries, or responses.

A Creator may request an audit where required by law and where available documentation is insufficient. Audits must:

  • be reasonably scoped;
  • protect other customers and security;
  • occur no more than once annually unless a material incident justifies more;
  • use an independent qualified auditor;
  • avoid disruption; and
  • be at the Creator’s expense unless the audit identifies a material Onflay breach.

18.14 International transfers

Where Onflay transfers covered personal data across a restricted border, the parties will use a lawful transfer mechanism required by applicable law.

If European Commission Standard Contractual Clauses or a UK transfer addendum must be executed, they will be incorporated or completed through the process Onflay makes available, with the module and annexes corresponding to the parties’ actual roles.

18.15 U.S. state service-provider terms

Where a U.S. state privacy law applies and Onflay acts as a processor, contractor, or service provider, Onflay will not:

  • sell the covered personal data;
  • retain, use, or disclose it outside the permitted business purpose except as legally allowed;
  • combine it with unrelated data except where permitted; or
  • process it contrary to the Creator’s lawful instructions.

18.16 Dominican Republic and Colombia

Where covered processor activity is subject to Dominican Ley No. 172-13 or Colombian Ley 1581 de 2012 and related rules:

  • the Creator remains responsible for establishing a lawful basis or obtaining any required prior, express, and informed authorization;
  • Onflay will process covered personal data for the documented purpose and apply reasonable access, confidentiality, security, and assistance controls;
  • the parties will cooperate with lawful data-subject requests and competent authorities;
  • the Creator must not instruct Onflay to process sensitive or biometric information unless the processing is lawful and necessary; and
  • any international transfer or transmission must use the safeguards required by applicable law.

This section does not change Onflay’s independent-controller role for Stripe Connect administration, Merchant-of-Record billing, tax, fraud, KYC, Didit verification, sanctions, disputes, accounting, and compliance.

18.17 Conflict

If this DPA conflicts with another provision concerning covered processor activity, this DPA controls. For Onflay’s independent-controller processing, the main body of this Notice and the Master Terms control.