Privacy Policy
Last Updated: May 2026
Privacy Policy
Effective date: May 1, 2026
Last updated: May 1, 2026
Version: 1.0
1. Who we are
This Privacy Policy describes how fam.work (“fam.work”, “we”, “us”, “our”) collects, uses, and shares information when you use our websites, APIs, and services (the “Service”).
Contact: hey@fam.work
We are the data controller for most personal data processed through the Service.
2. Scope
This Policy applies to personal data we process about:
- Visitors to our websites.
- Account holders (Buyers, Sellers, Premium Members, Referrers, Referees).
- Administrators of the platform.
- Users of our APIs.
It does not apply to:
- Third-party websites or services linked from our Service. Each third party has its own privacy policy.
- Content users publish through the Service (which is subject to the rules in our Terms of Service and may be visible to other users or publicly).
3. A note on public blockchain data
Some data you generate through the Service is written to the public Solana blockchain. Once on-chain, this data is:
- Public. Anyone in the world can read it forever.
- Permanent. We cannot delete it. The blockchain has no “forget me” button.
- Pseudonymous, not anonymous. Wallet addresses do not contain your name but can sometimes be tied back to real identities.
On-chain data we produce includes: wallet addresses of Buyers, Sellers, and Referrers; amounts and currencies of transactions; timestamps; escrow account states; dispute events; fee-update events.
You should assume anything on-chain is public forever. If this is not acceptable for a specific transaction, do not use the Service.
4. What personal data we collect
4.1 Data you provide
When you register and use the Service, you provide:
- Identity data: name, display username, email address, and (for social login) any profile information from Google or X that you consent to share with us.
- Authentication data: hashed password (we never see your plain-text password), two-factor-auth secret if enabled, authentication session tokens.
- Profile data: profile picture, cover image, bio, skills, country, portfolio items, custom call-to-action, social media links.
- Wallet data: the public address of any Solana wallet you link to your account. We never see your private key.
- Gig data: gigs you post, including titles, descriptions, prices, categories, gallery images, requirement questionnaires.
- Transaction data: gigs you purchase or sell, amounts, currencies, statuses.
- Communications: messages you send to other users, tickets you open with our support team, bug reports, comments and reviews you post.
- Survey and feedback data: if you respond to a survey or feedback request.
4.2 Data we collect automatically
When you use the Service, we automatically collect:
- Device and browser data: user agent, operating system, screen size, browser type.
- IP address. Recorded at each login and for security monitoring.
- Usage data: pages visited, features used, timestamps, referring URL, how you interact with elements on the page.
- Cookies and similar technologies. See our Cookie Policy.
- Performance data: errors, response times, API usage patterns.
4.3 Data from third parties
We may receive data from:
- Social login providers (Google, X) — profile information you consent to share.
- Blockchain explorers and RPC providers — transaction confirmations, account states, block timestamps.
- Payment verification services — transaction receipts we use to confirm on-chain events.
- Fraud prevention tools — risk signals tied to IP address or wallet address behaviour.
5. Why we use your data (legal bases, for EU/UK users)
Under the GDPR and UK GDPR we must tell you our lawful basis for each use of your personal data.
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account | Contract (Art. 6(1)(b)) |
| Processing Orders and Escrow transactions | Contract (Art. 6(1)(b)) |
| Enabling messaging and communication between users | Contract (Art. 6(1)(b)) |
| Providing support, investigating disputes | Contract + legitimate interest (Art. 6(1)(b), 6(1)(f)) |
| Security, fraud prevention, rate limiting | Legitimate interest (Art. 6(1)(f)) |
| Product analytics, improving the Service | Legitimate interest (Art. 6(1)(f)) |
| Marketing emails to existing users | Legitimate interest + opt-out (or opt-in where required) |
| Marketing to prospects, third-party advertising | Consent (Art. 6(1)(a)) |
| Responding to legal requests, enforcing our Terms | Legal obligation / legitimate interest (Art. 6(1)(c), 6(1)(f)) |
| Tax reporting and record retention | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest, you have the right to object (see §12.4).
5.1 What we actually do with the data
- Run the Service. Your account, gigs, transactions, messages, profile — all the data you explicitly give us so the platform can function.
- Keep you safe. Detect fraud, abuse, brute-force attacks, and respond to security incidents.
- Process payments. Verify on-chain transactions against amounts and addresses expected.
- Resolve disputes. Review evidence and issue a split decision per our Terms.
- Tell you things. Email you about orders, disputes, password resets, unread messages.
- Make the Service better. Understand which features people use, fix bugs, deprecate things nobody uses.
- Meet legal obligations. Respond to subpoenas, tax reporting, sanctions screening.
- Market. Email existing users about product updates. We will only use your data for targeted third-party marketing with your explicit consent.
6. What we do not do with your data
- We do not sell your personal data. (California residents: see §13.2.)
- We do not share your personal data with advertising networks for targeting purposes unless you explicitly consent.
- We do not read your messages with other users except where required by legal process, a security investigation, or to resolve a dispute you have opened.
- We do not use automated decision-making that has legal effects on you, except as described in §15.
7. Cookies and similar technologies
We use cookies, localStorage, and similar tools to remember your session, keep you signed in, and measure usage of the Service. For details, including which cookies are strictly necessary, which are functional, and which you can decline, see our Cookie Policy.
8. Who we share data with
8.1 Service providers and sub-processors
We use the following third parties to help us run the Service. Each is contractually bound to use your data only as instructed by us, to keep it secure, and (where required) to commit to appropriate international-transfer safeguards.
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Cloud infrastructure provider | Compute, storage, networking | All application data | EU / US |
| Mailgun Technologies, Inc. | Transactional and notification emails | Email address, name, email body | US |
| Pusher Ltd | Real-time websocket messaging | User IDs, channel names, ephemeral message payloads | UK / US |
| Public Solana RPC providers | Solana blockchain queries | Public wallet addresses, transaction signatures | Global |
| Google LLC | Social login (“Sign in with Google”) | OAuth identifiers, name, email (with your consent) | US |
| X Corp. | Social login (“Sign in with X”) | OAuth identifiers, name, email (with your consent) | US |
We will update this list when we add or remove sub-processors.
8.2 Other users
Your public profile data (username, profile picture, bio, gigs, portfolio, reviews of or by you) is visible to other users and (for the most part) to the public internet. Messaging content is visible to the recipient.
8.3 Administrators and support staff
fam.work staff with appropriate role-based permissions may access account data when necessary to provide support, investigate a report, resolve a dispute, or respond to a legal request.
8.4 Legal, regulatory, and law-enforcement requests
We may disclose personal data where required by law, to enforce our Terms, to protect the Service or other users, or to respond to valid legal process. Where permitted by law, we will attempt to notify affected users of any such request.
8.5 Business transfers
If fam.work is acquired, merged, or sold in whole or in part, personal data may be transferred to the successor entity as part of that transaction. We will require the successor to honour this Privacy Policy or give you an opportunity to object.
9. International transfers
Personal data may be processed in jurisdictions outside your country of residence. Where data leaves the European Economic Area (EEA), UK, or Switzerland, we rely on:
- European Commission adequacy decisions where the recipient country has one.
- Standard Contractual Clauses (SCCs) with non-adequate-country recipients.
- UK International Data Transfer Addendum where the source is the UK.
For questions about international transfers, contact hey@fam.work.
10. Security
We implement technical and organisational security measures designed to protect your data, including:
- TLS encryption for data in transit.
- Password hashing using bcrypt (we never store plain-text passwords).
- HttpOnly cookies for authentication tokens.
- Rate limiting on authentication and sensitive endpoints.
- Access controls, logging, and audit trails for administrator actions.
- Responsible disclosure process at hey@fam.work.
No security measure is perfect. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the applicable supervisory authority within 72 hours as required by the GDPR, and we will notify affected users without undue delay where required.
11. How long we keep your data
| Category | Retention |
|---|---|
| Active account data | While your account is active |
| Account data after you delete your account | 90 days (to allow reversal of accidental deletion), then permanent deletion |
| Transaction records | 7 years (for tax and financial record-keeping obligations) |
| Messages | While both sender and recipient accounts are active, then as part of account deletion |
| Server logs with IP addresses | 90 days |
| Security incident data | As long as needed to investigate and resolve the incident, plus a reasonable period for audit |
| Dispute evidence | 3 years after dispute resolution, unless legally required longer |
| Marketing data | Until you opt out, plus a short retention to respect your opt-out |
| On-chain blockchain data | Forever — we cannot delete it (see §3) |
12. Your rights
You have the following rights over your personal data. To exercise them, contact hey@fam.work. We will respond within 30 days (or earlier where required by local law).
12.1 Right of access
You may request a copy of the personal data we hold about you.
12.2 Right to rectification
You may ask us to correct inaccurate or incomplete personal data.
12.3 Right to erasure (“right to be forgotten”)
You may ask us to delete your personal data, subject to exceptions (legal obligations, exercise of legal claims, on-chain data we cannot delete).
12.4 Right to object
You may object to processing based on legitimate interest (see §5). We will honour the objection unless we have a compelling legitimate ground that overrides your interests.
12.5 Right to restrict processing
You may ask us to temporarily stop processing your personal data in certain circumstances (for example, while we verify the accuracy of a correction request).
12.6 Right to data portability
You may request your personal data in a portable, machine-readable format, or ask us to transmit it to another controller where technically feasible.
12.7 Right to withdraw consent
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
12.8 Right to lodge a complaint
You may lodge a complaint with a supervisory authority. For EU users, this is typically the Data Protection Authority of the country where you live or work, or where the alleged violation occurred. UK users can complain to the ICO at ico.org.uk.
12.9 No discrimination
We will not discriminate against you for exercising any of these rights. You will not be charged different fees or receive different service quality.
13. Rights under US state law
13.1 California Consumer Privacy Act (CCPA / CPRA)
California residents have additional rights. In the past 12 months we have collected the following categories of personal information: identifiers (email, name, wallet address), commercial information (transactions), internet activity (cookies, device data), inferences (product preferences).
You have the right to:
- Know what personal information we collect, use, and disclose.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
- Limit use of sensitive personal information. We do not use sensitive personal information for inference purposes beyond what is necessary to operate the Service.
To exercise your California rights, email hey@fam.work with “California privacy request” in the subject. We will verify your identity before responding.
13.2 Other state privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy laws have similar rights. Use the same contact channel above.
13.3 “Do Not Track” signals
Our Service does not currently respond to “Do Not Track” browser signals, but we honour Global Privacy Control (GPC) signals as an opt-out of sale/sharing where applicable.
14. Children
The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a child under 18, we will delete it. If you believe a child has provided us with personal information, contact hey@fam.work.
15. Automated decision-making
We use automated systems for:
- Fraud and abuse detection — some accounts may be flagged for review based on IP, wallet, or behavioural signals. Flagged accounts are then reviewed by a human.
- Rate limiting — automated blocking of traffic exceeding our thresholds.
- Search ranking — algorithmic ordering of gig search results.
We do not make solely automated decisions that produce legal effects on you within the meaning of GDPR Art. 22. A human administrator reviews all actions that could materially affect your account (suspension, ban, dispute resolution).
16. Changes to this Policy
We may update this Policy from time to time. When we do:
- We will post the updated Policy at this URL with a new version number and effective date.
- For material changes, we will notify you via email and prominent in-app notice.
- Continued use of the Service after an update constitutes acceptance, except where consent is required, in which case we will ask for fresh consent.
17. Contact
For all privacy-related questions, requests, or security reports:
Email: hey@fam.work
If any section of this Policy is unclear, contact us and we will explain in plain English. Privacy should not require a law degree to understand.