Privacy Policy
Last updated: January 2025
1. Introduction
Florence and Leo ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information about you when you use our Platform. It also describes your rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.
2. Data We Collect
We collect the following categories of personal data:
- Account data: email address, password (hashed), subscription tier, section preference, and age verification status.
- Payment data: billing information is processed directly by Stripe (Friends tier) or Segpay (Lovers tier). We do not store raw card numbers on our servers.
- Usage data: pages visited, content viewed, video play events, and other interactions with the Platform, collected via PostHog analytics.
- Communications data: email address and subscription status for The Love Letter newsletter, managed via Loops.
- Technical data: IP address, browser type, device type, and operating system, collected automatically when you access the Platform.
- Consent records: timestamp of age gate confirmation and marketing opt-in, stored in our database.
3. How We Use Your Data
We use your personal data to:
- Provide and maintain the Platform and your subscription.
- Process payments and send billing-related communications.
- Send transactional emails (account confirmation, payment receipts, cancellation confirmations).
- Send The Love Letter newsletter, where you have opted in.
- Analyse usage patterns to improve the Platform (PostHog analytics, no PII in event properties).
- Detect and prevent fraud, bot activity, and abuse.
- Comply with legal obligations.
4. Third-Party Services
We share data with the following third-party service providers, each of whom processes data only as necessary to provide their service:
- AWS (Amazon Web Services): cloud infrastructure, database, media storage, and content delivery.
- Stripe: payment processing for Friends-tier subscriptions, merchandise, and prints.
- Segpay: payment processing for Lovers-tier subscriptions.
- Resend: transactional email delivery.
- Loops: newsletter list management and broadcast campaigns.
- PostHog: product analytics and session recording. No personally identifiable information is included in analytics event properties.
- theprintspace: fine-art print fulfilment. Shipping address is shared for print orders only.
We do not sell your personal data to third parties.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will anonymise or delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes (e.g. billing records for tax compliance).
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data, subject to legal retention obligations.
- Right to data portability: receive your personal data in a structured, machine-readable format.
- Right to object: object to processing of your data for direct marketing purposes.
- Right to restrict processing: request that we limit how we use your data in certain circumstances.
- CCPA rights (California residents): right to know what personal information is collected, right to delete, right to opt out of sale (we do not sell personal data), and right to non-discrimination.
To exercise any of these rights, please use the data export or account deletion options in your account settings, or contact us at privacy@florenceandleo.com.
7. Cookies
We use the following cookies:
- fl_age_verified: records that you have confirmed you are 18 or older. Valid for 365 days. HttpOnly, Secure.
- fl_session: authenticates your session after sign-in. HttpOnly, Secure.
- PostHog analytics cookies: used for product analytics. No PII is included in event properties.
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including HTTPS encryption, signed media URLs, HttpOnly session cookies, and AWS WAF bot protection. However, no method of transmission over the internet is 100% secure.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date.
10. Contact
For privacy-related enquiries, please contact our data controller at privacy@florenceandleo.com.