This Privacy Policy describes how IOMIXO (“we”, “us”) collects, uses, and protects information when you use IOMIXO Live Hub, our live event interaction service. By using IOMIXO you agree to the practices described here. If you do not agree, do not use the service.
1. Data we collect
We collect the minimum data needed to operate the service:
- Account data — email address, hashed password, account creation date.
- Event content — content you and your guests submit during live events, such as messages, dedications, poll responses, game answers, and photos.
- Billing data — handled by Stripe (we never see or store full card details). We retain plan, subscription status, customer ID, and payment history metadata.
- Usage data — plan, login timestamps, and basic technical logs (IP address, user agent) for security and abuse prevention.
2. How we use your data
- To run your live events and display the content you and your guests submit.
- To manage your subscription and billing.
- To provide customer support and respond to your requests.
- To detect abuse, fraud, and violations of our Terms of Service.
- To comply with legal obligations (tax records, lawful requests from authorities).
We do not sell your data or use your event content for advertising.
3. Storage and retention
- Event content remains available in your account until you delete it or close your account.
- Account and billing records are retained as long as your account is active, plus the period required by tax and accounting law (typically up to 10 years for invoices in the EU).
- Logs are retained for up to 90 days unless required longer for security investigations.
4. Sub-processors
We share data only with vendors strictly required to operate the service:
- Supabase — database, authentication, and storage (EU region).
- Render — backend and API hosting.
- Vercel — frontend hosting.
- Stripe — payment processing. Stripe's privacy policy applies to card data.
Each sub-processor is contractually bound to data protection terms compatible with GDPR.
5. Your rights (GDPR)
If you are in the European Economic Area you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data (subject to legal retention obligations).
- Export your data in a portable format.
- Object to processing or withdraw consent where processing is based on consent.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact us at privacy@iomixo.com. We respond within 30 days.
6. Security
We use TLS encryption in transit, encrypted storage at rest, scoped database access, and row-level security policies to limit data access. No system is perfectly secure: if we discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
7. Cookies
We use essential cookies for authentication and session management. We do not use third-party advertising cookies or cross-site tracking. Analytics, if any, are aggregated and anonymized.
8. Children
IOMIXO is not directed to children under 16. If you become aware that a minor has provided us personal data without parental consent, contact us and we will delete it.
9. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated via email to active account holders or via a notice on the service at least 14 days before they take effect.
10. Contact
Questions about this policy or your data: privacy@iomixo.com.