Privacy Policy

Last Updated: May 2026

Privacy Policy

Effective date: May 1, 2026
Last updated: May 1, 2026
Version: 1.0

1. Who we are

This Privacy Policy describes how fam.work (“fam.work”, “we”, “us”, “our”) collects, uses, and shares information when you use our websites, APIs, and services (the “Service”).

Contact: hey@fam.work

We are the data controller for most personal data processed through the Service.

2. Scope

This Policy applies to personal data we process about:

  • Visitors to our websites.
  • Account holders (Buyers, Sellers, Premium Members, Referrers, Referees).
  • Administrators of the platform.
  • Users of our APIs.

It does not apply to:

  • Third-party websites or services linked from our Service. Each third party has its own privacy policy.
  • Content users publish through the Service (which is subject to the rules in our Terms of Service and may be visible to other users or publicly).

3. A note on public blockchain data

Some data you generate through the Service is written to the public Solana blockchain. Once on-chain, this data is:

  • Public. Anyone in the world can read it forever.
  • Permanent. We cannot delete it. The blockchain has no “forget me” button.
  • Pseudonymous, not anonymous. Wallet addresses do not contain your name but can sometimes be tied back to real identities.

On-chain data we produce includes: wallet addresses of Buyers, Sellers, and Referrers; amounts and currencies of transactions; timestamps; escrow account states; dispute events; fee-update events.

You should assume anything on-chain is public forever. If this is not acceptable for a specific transaction, do not use the Service.

4. What personal data we collect

4.1 Data you provide

When you register and use the Service, you provide:

  • Identity data: name, display username, email address, and (for social login) any profile information from Google or X that you consent to share with us.
  • Authentication data: hashed password (we never see your plain-text password), two-factor-auth secret if enabled, authentication session tokens.
  • Profile data: profile picture, cover image, bio, skills, country, portfolio items, custom call-to-action, social media links.
  • Wallet data: the public address of any Solana wallet you link to your account. We never see your private key.
  • Gig data: gigs you post, including titles, descriptions, prices, categories, gallery images, requirement questionnaires.
  • Transaction data: gigs you purchase or sell, amounts, currencies, statuses.
  • Communications: messages you send to other users, tickets you open with our support team, bug reports, comments and reviews you post.
  • Survey and feedback data: if you respond to a survey or feedback request.

4.2 Data we collect automatically

When you use the Service, we automatically collect:

  • Device and browser data: user agent, operating system, screen size, browser type.
  • IP address. Recorded at each login and for security monitoring.
  • Usage data: pages visited, features used, timestamps, referring URL, how you interact with elements on the page.
  • Cookies and similar technologies. See our Cookie Policy.
  • Performance data: errors, response times, API usage patterns.

4.3 Data from third parties

We may receive data from:

  • Social login providers (Google, X) — profile information you consent to share.
  • Blockchain explorers and RPC providers — transaction confirmations, account states, block timestamps.
  • Payment verification services — transaction receipts we use to confirm on-chain events.
  • Fraud prevention tools — risk signals tied to IP address or wallet address behaviour.

5. Why we use your data (legal bases, for EU/UK users)

Under the GDPR and UK GDPR we must tell you our lawful basis for each use of your personal data.

Purpose Legal basis
Creating and maintaining your account Contract (Art. 6(1)(b))
Processing Orders and Escrow transactions Contract (Art. 6(1)(b))
Enabling messaging and communication between users Contract (Art. 6(1)(b))
Providing support, investigating disputes Contract + legitimate interest (Art. 6(1)(b), 6(1)(f))
Security, fraud prevention, rate limiting Legitimate interest (Art. 6(1)(f))
Product analytics, improving the Service Legitimate interest (Art. 6(1)(f))
Marketing emails to existing users Legitimate interest + opt-out (or opt-in where required)
Marketing to prospects, third-party advertising Consent (Art. 6(1)(a))
Responding to legal requests, enforcing our Terms Legal obligation / legitimate interest (Art. 6(1)(c), 6(1)(f))
Tax reporting and record retention Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interest, you have the right to object (see §12.4).

5.1 What we actually do with the data

  • Run the Service. Your account, gigs, transactions, messages, profile — all the data you explicitly give us so the platform can function.
  • Keep you safe. Detect fraud, abuse, brute-force attacks, and respond to security incidents.
  • Process payments. Verify on-chain transactions against amounts and addresses expected.
  • Resolve disputes. Review evidence and issue a split decision per our Terms.
  • Tell you things. Email you about orders, disputes, password resets, unread messages.
  • Make the Service better. Understand which features people use, fix bugs, deprecate things nobody uses.
  • Meet legal obligations. Respond to subpoenas, tax reporting, sanctions screening.
  • Market. Email existing users about product updates. We will only use your data for targeted third-party marketing with your explicit consent.

6. What we do not do with your data

  • We do not sell your personal data. (California residents: see §13.2.)
  • We do not share your personal data with advertising networks for targeting purposes unless you explicitly consent.
  • We do not read your messages with other users except where required by legal process, a security investigation, or to resolve a dispute you have opened.
  • We do not use automated decision-making that has legal effects on you, except as described in §15.

7. Cookies and similar technologies

We use cookies, localStorage, and similar tools to remember your session, keep you signed in, and measure usage of the Service. For details, including which cookies are strictly necessary, which are functional, and which you can decline, see our Cookie Policy.

8. Who we share data with

8.1 Service providers and sub-processors

We use the following third parties to help us run the Service. Each is contractually bound to use your data only as instructed by us, to keep it secure, and (where required) to commit to appropriate international-transfer safeguards.

Sub-processor Purpose Data shared Location
Cloud infrastructure provider Compute, storage, networking All application data EU / US
Mailgun Technologies, Inc. Transactional and notification emails Email address, name, email body US
Pusher Ltd Real-time websocket messaging User IDs, channel names, ephemeral message payloads UK / US
Public Solana RPC providers Solana blockchain queries Public wallet addresses, transaction signatures Global
Google LLC Social login (“Sign in with Google”) OAuth identifiers, name, email (with your consent) US
X Corp. Social login (“Sign in with X”) OAuth identifiers, name, email (with your consent) US

We will update this list when we add or remove sub-processors.

8.2 Other users

Your public profile data (username, profile picture, bio, gigs, portfolio, reviews of or by you) is visible to other users and (for the most part) to the public internet. Messaging content is visible to the recipient.

8.3 Administrators and support staff

fam.work staff with appropriate role-based permissions may access account data when necessary to provide support, investigate a report, resolve a dispute, or respond to a legal request.

8.4 Legal, regulatory, and law-enforcement requests

We may disclose personal data where required by law, to enforce our Terms, to protect the Service or other users, or to respond to valid legal process. Where permitted by law, we will attempt to notify affected users of any such request.

8.5 Business transfers

If fam.work is acquired, merged, or sold in whole or in part, personal data may be transferred to the successor entity as part of that transaction. We will require the successor to honour this Privacy Policy or give you an opportunity to object.

9. International transfers

Personal data may be processed in jurisdictions outside your country of residence. Where data leaves the European Economic Area (EEA), UK, or Switzerland, we rely on:

  • European Commission adequacy decisions where the recipient country has one.
  • Standard Contractual Clauses (SCCs) with non-adequate-country recipients.
  • UK International Data Transfer Addendum where the source is the UK.

For questions about international transfers, contact hey@fam.work.

10. Security

We implement technical and organisational security measures designed to protect your data, including:

  • TLS encryption for data in transit.
  • Password hashing using bcrypt (we never store plain-text passwords).
  • HttpOnly cookies for authentication tokens.
  • Rate limiting on authentication and sensitive endpoints.
  • Access controls, logging, and audit trails for administrator actions.
  • Responsible disclosure process at hey@fam.work.

No security measure is perfect. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the applicable supervisory authority within 72 hours as required by the GDPR, and we will notify affected users without undue delay where required.

11. How long we keep your data

Category Retention
Active account data While your account is active
Account data after you delete your account 90 days (to allow reversal of accidental deletion), then permanent deletion
Transaction records 7 years (for tax and financial record-keeping obligations)
Messages While both sender and recipient accounts are active, then as part of account deletion
Server logs with IP addresses 90 days
Security incident data As long as needed to investigate and resolve the incident, plus a reasonable period for audit
Dispute evidence 3 years after dispute resolution, unless legally required longer
Marketing data Until you opt out, plus a short retention to respect your opt-out
On-chain blockchain data Forever — we cannot delete it (see §3)

12. Your rights

You have the following rights over your personal data. To exercise them, contact hey@fam.work. We will respond within 30 days (or earlier where required by local law).

12.1 Right of access

You may request a copy of the personal data we hold about you.

12.2 Right to rectification

You may ask us to correct inaccurate or incomplete personal data.

12.3 Right to erasure (“right to be forgotten”)

You may ask us to delete your personal data, subject to exceptions (legal obligations, exercise of legal claims, on-chain data we cannot delete).

12.4 Right to object

You may object to processing based on legitimate interest (see §5). We will honour the objection unless we have a compelling legitimate ground that overrides your interests.

12.5 Right to restrict processing

You may ask us to temporarily stop processing your personal data in certain circumstances (for example, while we verify the accuracy of a correction request).

12.6 Right to data portability

You may request your personal data in a portable, machine-readable format, or ask us to transmit it to another controller where technically feasible.

12.7 Right to withdraw consent

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

12.8 Right to lodge a complaint

You may lodge a complaint with a supervisory authority. For EU users, this is typically the Data Protection Authority of the country where you live or work, or where the alleged violation occurred. UK users can complain to the ICO at ico.org.uk.

12.9 No discrimination

We will not discriminate against you for exercising any of these rights. You will not be charged different fees or receive different service quality.

13. Rights under US state law

13.1 California Consumer Privacy Act (CCPA / CPRA)

California residents have additional rights. In the past 12 months we have collected the following categories of personal information: identifiers (email, name, wallet address), commercial information (transactions), internet activity (cookies, device data), inferences (product preferences).

You have the right to:

  • Know what personal information we collect, use, and disclose.
  • Delete personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
  • Limit use of sensitive personal information. We do not use sensitive personal information for inference purposes beyond what is necessary to operate the Service.

To exercise your California rights, email hey@fam.work with “California privacy request” in the subject. We will verify your identity before responding.

13.2 Other state privacy laws

Residents of Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy laws have similar rights. Use the same contact channel above.

13.3 “Do Not Track” signals

Our Service does not currently respond to “Do Not Track” browser signals, but we honour Global Privacy Control (GPC) signals as an opt-out of sale/sharing where applicable.

14. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a child under 18, we will delete it. If you believe a child has provided us with personal information, contact hey@fam.work.

15. Automated decision-making

We use automated systems for:

  • Fraud and abuse detection — some accounts may be flagged for review based on IP, wallet, or behavioural signals. Flagged accounts are then reviewed by a human.
  • Rate limiting — automated blocking of traffic exceeding our thresholds.
  • Search ranking — algorithmic ordering of gig search results.

We do not make solely automated decisions that produce legal effects on you within the meaning of GDPR Art. 22. A human administrator reviews all actions that could materially affect your account (suspension, ban, dispute resolution).

16. Changes to this Policy

We may update this Policy from time to time. When we do:

  • We will post the updated Policy at this URL with a new version number and effective date.
  • For material changes, we will notify you via email and prominent in-app notice.
  • Continued use of the Service after an update constitutes acceptance, except where consent is required, in which case we will ask for fresh consent.

17. Contact

For all privacy-related questions, requests, or security reports:

Email: hey@fam.work

If any section of this Policy is unclear, contact us and we will explain in plain English. Privacy should not require a law degree to understand.