Effective October 1, 2026 · Last updated October 1, 2026
PLACED
Privacy Policy
Discovery network for brands and concepts
Effective date: October 1, 2026 · Last updated: October 1, 2026
1. Introduction and scope
PLACED ("PLACED," "we," "us," or "our") takes privacy seriously. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have in relation to it.
This Policy applies to all users of the PLACED Platform — brands, scouts, brokers, and any visitor to placed.co. It covers data collected through our website, web application, and all related services.
We operate globally but are based in the United States. We describe our US obligations first, then the additional rights that apply to users in specific states and countries.
This Policy is a starting point for legal review. Before going live, have a qualified privacy attorney review it for your specific jurisdiction and business structure.
2. Data we collect
2.1 Data you provide
— Account data: name, email address, password (hashed), role (brand or scout), company name
— Brand profile data: brand name, pitch, category, placement priorities, markets, imagery (hero image, concept images, logo), traction points, links (website, social, press), representation status, F+B-specific fields (shelf life, certifications, allergens, distribution), Arts + Culture-specific fields
— Scout profile data: name, company, role type, category focus, markets, bio, commission structure (brokers), placement channels (brokers)
— Payment data: billing address, payment method details (processed and stored by Stripe — we do not store card numbers)
— Communication data: intro messages, thread messages, personal notes attached to intros
— Waitlist data: name, email, role, company submitted via waitlist or apply forms
2.2 Data we collect automatically
— Usage data: pages visited, features used, search queries run, brands saved, intros sent and received, session duration
— Device data: browser type and version, operating system, screen resolution, IP address
— Log data: server logs including timestamps, error logs, and access records
— Cookies: session cookies for authentication, preference cookies for UI settings (see our Cookie Policy)
2.3 Data we do not collect
— We do not collect sensitive personal data such as race, ethnicity, religion, health information, or sexual orientation
— We do not collect financial data beyond what Stripe needs to process payments
— We do not collect data from minors — the Platform is for users 18 and over
3. How we use your data
3.1 To operate the Platform
— Creating and managing your account
— Displaying your brand profile to scouts (brands) or your scout profile to brands (scouts and brokers)
— Calculating match scores between scouts and brands based on role, categories, and markets
— Processing subscription payments via Stripe
— Sending triggered notification emails (profile approved, intro received, thread opened, re-engagement)
— Operating the admin review queue for brand profile approval
3.2 To improve the Platform
— Analysing aggregate usage patterns to understand which features are used and which are not
— Debugging errors and improving performance
— Developing new features based on aggregate user behaviour
We do not use individual user data — including thread content, search history, or saved lists — to train machine learning models or algorithms without your explicit consent.
3.3 For legal and safety purposes
— Responding to reports of abuse, harassment, or policy violations
— Complying with legal obligations, court orders, and law enforcement requests
— Protecting PLACED's rights and the rights of our users
3.4 What we do not do with your data
— We do not sell your personal data to third parties
— We do not share your data with advertisers
— We do not use thread content for any commercial purpose
— We do not share your saved lists, search history, or intro history with other users
— We do not use your data to make automated decisions that produce legal or similarly significant effects
4. Thread content and messaging privacy
Thread content — messages exchanged between brands and scouts after an intro is accepted — receives the highest level of privacy protection on the Platform.
— Thread content is private between the two parties to the thread
— PLACED does not read thread content proactively or as a standard operating procedure
— Thread content is not used for product recommendations, matching, advertising, or any commercial purpose
— Thread content is not shared with third parties except as required by law
— Thread content is not used to train models or inform algorithms
PLACED may access thread content only in three limited circumstances: (1) in response to a safety report from one of the parties, reviewed by a human; (2) in response to a valid legal process such as a subpoena or court order; (3) for technical debugging by an authorised engineer, subject to documented internal approval and access logging.
This approach is consistent with how LinkedIn, Slack, and other professional communications platforms treat private message content.
5. Data sharing and third parties
5.1 Service providers
We share data with service providers who help us operate the Platform. Each is bound by data processing agreements that limit their use of your data:
— Bubble (no-code platform): hosts the Platform, database, and application logic. Data is stored in the United States. Bubble's infrastructure is SOC 2 Type II certified.
— Stripe: processes subscription payments. Stripe is PCI DSS Level 1 certified. We share your billing details with Stripe; we do not store card numbers.
— Postmark or Sendgrid: delivers transactional emails. We share your email address and the content of notification emails.
— Cloudinary: stores and serves brand imagery (hero images, concept images, logos). Images are hosted on Cloudinary's CDN.
5.2 Legal requirements
We may disclose your data if required to do so by law, court order, or governmental authority. Where legally permitted, we will notify you before complying with such a request.
5.3 Business transfers
If PLACED is acquired, merges with another company, or transfers its assets, your data may be transferred as part of that transaction. We will notify you via email and a Platform notice at least 30 days before any such transfer, and you will have the right to delete your account before the transfer takes effect.
5.4 With your consent
We may share your data for purposes not listed above with your explicit consent.
6. Data retention
— Active account data: retained for as long as your account is active
— Closed account data: deleted within 90 days of account closure, except where legal obligations require longer retention
— Payment records: retained for 7 years for tax and accounting purposes (Stripe retains transaction records independently)
— Log data: retained for 90 days for security and debugging purposes
— Legal holds: data subject to a legal hold is retained until the hold is released
You may request deletion of your account and associated data at any time. See section 8 for your rights.
7. Security
We implement technical and organisational measures to protect your data:
— All data in transit is encrypted using TLS 1.2 or higher
— Passwords are hashed using industry-standard algorithms and never stored in plain text
— Access to production data is restricted to authorised PLACED staff
— Admin accounts require two-factor authentication
— We conduct periodic security reviews of our infrastructure
No system is completely secure. We cannot guarantee the absolute security of your data. If we become aware of a breach affecting your data, we will notify you as required by applicable law.
8. Your rights — all users
Regardless of where you are located, you have the following rights:
— Access: request a copy of the personal data we hold about you
— Correction: request correction of inaccurate data
— Deletion: request deletion of your account and associated personal data
— Portability: request your data in a machine-readable format
— Objection: object to certain uses of your data
— Withdrawal of consent: where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at privacy@placed.co. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
9. United States — state-specific rights
9.1 Overview
Multiple US states have enacted comprehensive consumer privacy laws. The following describes the material rights available to residents of each state. Where a state's law is substantively identical to another state's, we group them together.
9.2 California — CCPA and CPRA
California residents have the most comprehensive US privacy rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), enforced by the California Privacy Protection Agency (CPPA).
— Right to know: request disclosure of what personal data we collect, use, share, and sell (we do not sell data)
— Right to delete: request deletion of your personal data, subject to legal exceptions
— Right to correct: request correction of inaccurate personal data
— Right to opt out of sale or sharing: we do not sell personal data. We do not share personal data for cross-context behavioural advertising
— Right to limit use of sensitive personal information: we collect minimal sensitive data; where collected, it is used only to operate the Platform
— Right to non-discrimination: we will not discriminate against you for exercising your rights
— Shine the Light: California residents may request a list of third parties to whom we disclosed personal data for direct marketing in the prior year. We do not disclose data for direct marketing.
To submit a California rights request: privacy@placed.co or [TOLL-FREE NUMBER]. We will verify your identity and respond within 45 days (extendable to 90 days with notice). You may authorise an agent to submit requests on your behalf.
9.3 Virginia — VCDPA
Virginia residents have rights under the Virginia Consumer Data Protection Act (VCDPA):
— Access, correct, delete, and portability rights as described in section 8
— Right to opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects — we do not engage in these activities
— Right to appeal a denial of a rights request: if we deny your request, you may appeal by emailing privacy@placed.co with the subject line "Virginia Rights Appeal." We will respond within 60 days.
9.4 Colorado — CPA
Colorado residents have rights under the Colorado Privacy Act (CPA), enforced by the Colorado Attorney General. Rights are substantively similar to Virginia's VCDPA, including the right to opt out of targeted advertising and sale, and the right to appeal. Contact: privacy@placed.co with "Colorado Rights Request" in the subject line.
9.5 Connecticut — CTDPA
Connecticut residents have rights under the Connecticut Data Privacy Act (CTDPA), effective July 2023. Rights are substantively similar to Virginia's and Colorado's, including access, deletion, correction, portability, opt-out of sale and targeted advertising, and the right to appeal. Contact: privacy@placed.co with "Connecticut Rights Request" in the subject line.
9.6 Texas — TDPSA
Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA), effective July 2024. Rights include access, correction, deletion, portability, and opt-out of sale and targeted advertising. We do not sell data or use it for targeted advertising. Contact: privacy@placed.co with "Texas Rights Request" in the subject line.
9.7 Florida — FDBR
Florida residents whose controllers meet applicable revenue and data thresholds have rights under the Florida Digital Bill of Rights (FDBR), effective July 2024. Rights include access, correction, deletion, and opt-out of sale and targeted advertising. Contact: privacy@placed.co with "Florida Rights Request" in the subject line.
9.8 Montana — MCDPA
Montana residents have rights under the Montana Consumer Data Privacy Act (MCDPA), effective October 2024, including access, correction, deletion, portability, and opt-out of sale. Contact: privacy@placed.co with "Montana Rights Request" in the subject line.
9.9 Oregon — OCPA
Oregon residents have rights under the Oregon Consumer Privacy Act (OCPA), effective July 2024, including access, correction, deletion, portability, and opt-out of targeted advertising and sale. Contact: privacy@placed.co with "Oregon Rights Request" in the subject line.
9.10 Washington — My Health MY Data Act
Washington's My Health MY Data Act primarily covers health data. PLACED does not collect health data. Washington residents with other privacy concerns may contact privacy@placed.co.
9.11 Nevada — SB 220
Nevada residents may opt out of the sale of their personal data. We do not sell personal data. Nevada residents with other privacy concerns may contact privacy@placed.co.
9.12 Utah — UCPA
Utah residents have rights under the Utah Consumer Privacy Act (UCPA), effective December 2023, including access, deletion, portability, and opt-out of sale and targeted advertising. Contact: privacy@placed.co with "Utah Rights Request" in the subject line.
9.13 New York — SHIELD Act
New York's SHIELD Act focuses on security breach notification rather than individual rights. We comply with SHIELD Act breach notification requirements. New York residents may contact privacy@placed.co for data inquiries.
9.14 Illinois — BIPA
Illinois's Biometric Information Privacy Act (BIPA) governs biometric data. PLACED does not collect biometric data. Illinois residents may contact privacy@placed.co for other data inquiries.
9.15 Other states
Privacy laws are evolving rapidly across the United States. We monitor new legislation and update this Policy when new state laws take effect. If your state enacts a privacy law not listed here, the rights described in section 8 apply to you, and you may contact privacy@placed.co to exercise them.
10. International — European Union and United Kingdom
10.1 Legal basis for processing (GDPR / UK GDPR)
If you are in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the General Data Protection Regulation (GDPR) or the UK GDPR respectively. Our legal bases are:
— Contract performance: processing necessary to provide the Platform services you have signed up for (account creation, profile display, subscription management, intro system)
— Legitimate interests: usage analytics for Platform improvement, security monitoring, fraud prevention — where these interests are not overridden by your rights
— Legal obligation: compliance with applicable laws
— Consent: where we ask for consent (e.g. non-essential cookies), you may withdraw it at any time
10.2 Data transfers
PLACED is based in the United States. When we transfer your personal data from the EEA or UK to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or the UK equivalent, as the transfer mechanism. Our key US-based processors (Bubble, Stripe, Postmark, Cloudinary) are covered by SCCs or participate in equivalent frameworks.
10.3 Your GDPR rights
In addition to the rights described in section 8, EEA and UK residents have:
— Right to restrict processing: in certain circumstances, request that we limit how we use your data
— Right to object: object to processing based on legitimate interests; we will stop unless we have compelling legitimate grounds
— Rights related to automated decision-making: we do not make automated decisions that produce legal or similarly significant effects
— Right to lodge a complaint: with your local supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office (ICO) at ico.org.uk
10.4 Data Protection Officer
We have appointed a Data Protection Officer (DPO) for GDPR purposes. Contact: dpo@placed.co · [PLACED LEGAL ENTITY NAME], [ADDRESS]
10.5 UK-specific
For UK residents, the UK GDPR and Data Protection Act 2018 apply. Our UK representative (if required) is [UK REPRESENTATIVE NAME AND ADDRESS]. You may lodge complaints with the ICO at ico.org.uk or 0303 123 1113.
11. International — Canada
11.1 PIPEDA and provincial laws
If you are in Canada, your data is processed in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy laws (Quebec Law 25, Alberta PIPA, British Columbia PIPA).
11.2 Your Canadian rights
— Right to access your personal information
— Right to challenge the accuracy of your personal information
— Right to withdraw consent (subject to legal and contractual restrictions)
— Right to lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca
11.3 Quebec — Law 25
Quebec residents have additional rights under Law 25 (Act respecting the protection of personal information in the private sector), effective September 2023, including enhanced rights regarding automated decision-making and data portability. Contact privacy@placed.co with "Quebec Rights Request" in the subject line.
12. International — Asia Pacific
12.1 Australia — Privacy Act 1988
Australian residents have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You may access and correct your personal data by contacting privacy@placed.co. Complaints may be lodged with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
12.2 Singapore — PDPA
Singapore residents have rights under the Personal Data Protection Act (PDPA), including the right to access and correct personal data. Contact privacy@placed.co with "Singapore Rights Request" in the subject line.
12.3 New Zealand — Privacy Act 2020
New Zealand residents have rights under the Privacy Act 2020, including access and correction rights. Contact privacy@placed.co with "New Zealand Rights Request" in the subject line.
12.4 Other Asia Pacific jurisdictions
We operate in a global market with brands and scouts across Asia Pacific. If your jurisdiction has a privacy law not listed here, the rights in section 8 apply to you. Contact privacy@placed.co for jurisdiction-specific inquiries.
13. International — Africa and Middle East
PLACED has brands and scouts across Africa and the Middle East. Privacy frameworks in these regions vary significantly by country. The rights described in section 8 apply to all users globally. Users in South Africa have rights under POPIA (Protection of Personal Information Act). Users in Nigeria have rights under NDPR (Nigeria Data Protection Regulation). Users in the UAE operate under the PDPL (Personal Data Protection Law). Contact privacy@placed.co with your jurisdiction in the subject line for jurisdiction-specific requests.
14. Cookies
PLACED uses cookies and similar technologies. A separate Cookie Policy is available at placed.co/cookies. In summary:
— Essential cookies: required for authentication and session management. Cannot be disabled.
— Preference cookies: remember your UI preferences. Can be disabled without affecting core functionality.
— Analytics cookies: we use privacy-respecting analytics to understand aggregate Platform usage. We do not use Google Analytics or other surveillance-based analytics tools. You may opt out.
— We do not use advertising cookies or cross-site tracking technologies.
EU and UK users will see a consent banner on first visit. Users in other jurisdictions may manage cookie preferences at any time via placed.co/cookies.
15. Children's privacy
PLACED is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe we have collected data from a minor, contact privacy@placed.co immediately.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice on the Platform at least 14 days before the change takes effect. The date at the top of this Policy indicates when it was last updated. Continued use of the Platform after changes take effect constitutes acceptance of the updated Policy.
17. Contact
For all privacy inquiries, rights requests, and complaints:
— Email: privacy@placed.co
— DPO (GDPR): dpo@placed.co
— Post: [PLACED LEGAL ENTITY NAME], [ADDRESS]
— Response time: 30 days for standard requests; 45 days for California requests; 72 hours for confirmed breach notification
PLACED is committed to responding to all privacy inquiries promptly and in plain language. We will not use legalese to deflect legitimate requests.