Legal
Privacy Policy
Last updated: 4 September 2026
Summary. Memberra is the data controller for Operator (customer) accounts. For end customers who sign up through an Operator's portal, the Operator is the controller and Memberra is the processor. We never sell personal data.
1.
Who we are
Memberra ("we", "us", "our") is the controller of personal data we collect about Operators (our direct customers). For end-customer data flowing through Operator-branded portals, the Operator is the independent controller and Memberra acts as a processor on the Operator's documented instructions.
2.
Data we collect
- Account data: name, email, organisation, account preferences, roles and authentication/security state.
- Operational data: server endpoints, API tokens (encrypted at rest), webhook URLs, automation configurations, audit logs, support correspondence.
- Usage & device data: IP address, country, browser, operating system and device class for authentication, fraud prevention, account security and essential service diagnostics. We do not retain precise GPS location.
- End-customer data (processed on behalf of Operators): email, display name, payment status, subscription state, invite tokens, server-account identifiers, watch-analytics events configured by the Operator.
- Playback and media metadata: media and series titles, season and episode identifiers, library information, playback position, duration, bitrate, transcoding state, subtitles, client application, device, IP address and approximate location where an Operator enables analytics.
- Commercial and compliance data: the minimum order, invoice, payment status/reference, wallet, commission, referral, dispute and compliance records needed to operate the requested service and meet accounting, fraud-prevention or legal obligations.
- Communications: emails, in-app messages and support tickets you send to us.
3.
Payment data and financial security
Card and PayPal payments are entered into and processed by the selected payment provider, normally Stripe or PayPal. Memberra does not collect or store full card numbers, card security codes, online-banking credentials or PayPal passwords. We receive only the limited identifiers, status, amount, currency and account/transaction references needed to display billing state, reconcile a payment and trigger the service an Operator has configured. Operators connect their own merchant accounts, and end-customer funds are processed by the selected provider rather than held by Memberra.
4.
How we use data
To provide and operate the Service; authenticate users and prevent fraud; process Operator subscription payments; deliver transactional emails; respond to support requests; comply with legal, tax and accounting obligations; investigate abuse and security incidents; produce aggregate, de-identified analytics to improve the product; administer referrals and commissions; enrich configured media analytics; conduct due diligence; and enforce our legal and acceptable-use requirements. We do not sell personal data and we do not use end-customer data for our own marketing.
5.
Legal bases (UK/EU GDPR)
- Contract: account creation, service delivery, billing.
- Legitimate interests: security, fraud prevention, product analytics, network and information security, direct B2B communication with Operators.
- Legal obligation: tax, accounting, anti-money-laundering, responding to lawful requests.
- Consent: marketing emails and non-essential cookies (withdrawable at any time).
6.
Service providers
We use carefully selected providers for infrastructure and security, managed data and authentication, payment processing, communications, and integrations you choose to enable. We disclose provider names and processing purposes separately for transparency and data-processing compliance; this list does not disclose credentials, network addresses or security configuration. Our Subprocessor List describes current categories and transfer safeguards.
7.
Data retention and minimisation
Account and core contract data is retained for the life of your account. Tax, invoice and material transaction records may be retained for up to 7 years after the relevant period. We collect only fields needed for the requested feature, account security, support, or a stated legal obligation. Routine operational logs are normally retained for up to 90 days. Authentication security events are automatically removed after 12 months. Backups are rotated on a 30-day cycle. End-customer data is retained for as long as the Operator's account is active and is deleted (or returned) on Operator instruction or within a reasonable window after account termination, subject to legal holds, backup rotation and required retention. Some identifiers may be retained to prevent fraud, repeat abuse or duplicate trials. Operators must configure proportionate retention for optional viewing analytics.
8.
Your rights
Under UK/EU GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right not to be subject to solely automated decision-making producing legal effects. To exercise these rights, email [email protected]. We may request proportionate information to verify identity before disclosing or changing data. End customers should contact the Operator they signed up with for requests relating to their account; Memberra will forward such requests if received in error. You may also complain to the UK ICO (ico.org.uk) or your local supervisory authority. To complain about our use of personal data, email the same address with the subject “Data protection complaint”. We will acknowledge the complaint within 30 days, investigate it appropriately and respond without undue delay. This does not restrict your right to complain to the ICO.
9.
International transfers
Personal data may be processed outside the UK/EEA by our subprocessors. Where this happens, we rely on the UK International Data Transfer Agreement (IDTA), EU Standard Contractual Clauses, UK Addendum, or an adequacy decision, together with appropriate technical and organisational safeguards.
10.
Cookies
We use essential cookies for authentication, session management and security. We use storage only where it is necessary for security and requested functionality. Any non-essential analytics or similar storage must remain disabled until valid consent is obtained. See our Cookie Notice.
11.
Security
Encryption in transit using current TLS configurations and encryption at rest where supported, role-based access control, least-privilege service accounts, audit logging, row-level security on tenant data, encrypted secrets storage, optional 2FA, and security testing. No system is 100% secure; we will notify affected users without undue delay of any breach materially affecting their personal data, as required by law.
12.
Children
The Service is not directed to children under 16 (or under 13 in the US). We do not knowingly collect data from children. Operators must not configure their portals to collect data from children except in compliance with applicable law.
13.
Changes to this policy
Material changes will be notified by email or in-app at least 30 days before they take effect. The "last updated" date above always reflects the most recent revision.
14.
Contact
Fine print. Where this Policy describes a processor relationship, our Data Processing Terms govern the precise scope of processing. In case of conflict with marketing or in-product copy, this Policy controls. Memberra's final legal-entity and postal disclosures will be added before live contracting begins.