CastFace

Privacy Policy

Effective date: June 30, 2026  ·  Version 1.0

1. Who We Are

CastFace (“CastFace”, “we”, “us”, “our”) operates the marketplace at castface.net that enables individuals to list their facial likeness for licensing to brands and studios.

For the purposes of the EU General Data Protection Regulation (“GDPR”) and equivalent national laws, CastFace is the data controller of the personal data described in this Policy.

Registered address and company details: [TODO — insert legal entity name, company registration number, and registered address once the company is formally incorporated. Until then, contact the data controller at privacy@castface.net]

2. Data We Collect

We collect the following categories of personal data:

2.1 Account and Identity Data

  • Email address (collected at registration, used for authentication and communications).
  • Display name or company name.
  • Account role (person / company / admin) and account creation date.
  • Age confirmation (boolean flag — we do not collect your date of birth, only your self-confirmation that you are 18 or older).

2.2 Profile and Listing Data (Persons only)

  • Facial photographs and images that you upload.
  • Listing parameters: self-described age range, gender, appearance tags, and usage restrictions.
  • Pricing information you set for your listing.
  • Ownership consent and biometric consent records (timestamps and boolean confirmation).

2.3 Company Data (Companies only)

  • Company name and verification status.

2.4 Transaction and Communication Data

  • License request details: intended use description, territory, runtime, term, and message text.
  • Status history of license requests.
  • Communications between users and CastFace (e.g. support emails).

2.5 Technical and Usage Data

  • IP address and approximate geolocation derived from IP.
  • Browser type, operating system, and device type.
  • Pages viewed, features used, and timestamps of interactions.
  • Authentication session tokens managed by our authentication provider (Supabase).

3. Legal Bases for Processing

Where GDPR applies, we process your personal data on the following legal bases:

PurposeLegal basis (GDPR)
Account creation and authenticationArt. 6(1)(b) — Performance of a contract
Providing marketplace servicesArt. 6(1)(b) — Performance of a contract
Processing facial images for display in the catalogArt. 6(1)(a) / Art. 9(2)(a) — Explicit consent
Biometric data processingArt. 9(2)(a) — Explicit consent
Moderation and safetyArt. 6(1)(f) — Legitimate interests (platform integrity)
Compliance with legal obligationsArt. 6(1)(c) — Legal obligation
Fraud prevention and securityArt. 6(1)(f) — Legitimate interests
Improving the PlatformArt. 6(1)(f) — Legitimate interests
Sending service communicationsArt. 6(1)(b) — Performance of a contract

Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests are not overridden by your rights and freedoms, given the nature of the data and the purpose of processing. You have the right to object to processing based on legitimate interests (see Section 9).

4. How We Use Your Data

  • To operate the Platform: displaying listings in the catalog, facilitating license requests, managing your account and dashboard.
  • To moderate content: reviewing submitted listings to ensure compliance with our policies and legal obligations before publishing them.
  • To communicate with you: sending account-related emails (confirmation, notifications), responding to support enquiries, and notifying you of licence requests.
  • To ensure security: detecting and preventing fraud, unauthorised access, and misuse of the Platform.
  • To comply with law: retaining records as required by applicable law, and cooperating with law enforcement authorities where legally required.
  • To improve the Platform: analysing usage patterns (in aggregated, non-identifiable form where possible) to improve functionality and user experience.

We do not sell your personal data to third parties. We do not use your personal data for automated individual decision-making that produces legal or similarly significant effects without human review.

5. Biometric and Special Category Data

Facial photographs may constitute biometric data or special category personal data under applicable law, including:

  • GDPR (EU/EEA): Article 9 — biometric data processed for the purpose of uniquely identifying a natural person.
  • Illinois Biometric Information Privacy Act (BIPA): biometric identifiers including retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry.
  • Texas Capture or Use of Biometric Identifier Act (CUBI) and Washington My Health MY Data Act and similar US state laws.
  • UK GDPR and applicable national implementations in other jurisdictions.

We process biometric data only on the basis of your explicit, informed, and freely given consent, obtained at the time you submit your face listing through the consent checkbox in the listing form. You may withdraw this consent at any time (see Section 9). Withdrawal of consent will result in removal of your listing from the catalog and deletion of your photographs from our systems, subject to the retention requirements described in Section 8.

Please see our Biometric Consent Policy for full details of how we collect, store, use, and protect biometric data, and for the specific disclosures required under Illinois BIPA and similar laws.

We never use your facial images to train AI models, create synthetic likenesses, or for any purpose other than displaying your listing to verified Company users of the Platform.

6. Sharing with Third Parties

We do not sell, rent, or share your personal data with third parties for their own marketing purposes. We share data only in the following limited circumstances:

6.1 Service Providers (Processors)

We engage the following sub-processors who handle data on our behalf under data processing agreements:

  • Supabase, Inc. (USA) — database, authentication, and file storage. Your account data and facial images are stored on Supabase infrastructure. Supabase is SOC 2 Type II certified. Supabase Privacy Policy.
  • Vercel, Inc. (USA) — hosting and content delivery for the Platform. Vercel Privacy Policy.

6.2 Between Users

When a listing is approved and published, the listing details (photos, age range, gender, appearance tags, restrictions, and price) are visible to registered Company users. Your email address and personal identity are not disclosed to Companies.

When a Company submits a license request, the request details (intended use, territory, message) are shared with CastFace administrators who facilitate the introduction between the parties. Direct contact details are shared only with your consent.

6.3 Legal Requirements

We may disclose your personal data if required to do so by law, regulation, court order, or other governmental authority, or where we believe in good faith that disclosure is necessary to protect our legal rights, prevent fraud, or protect the safety of any person.

6.4 Business Transfers

If CastFace is involved in a merger, acquisition, asset sale, or similar transaction, your personal data may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.

7. International Transfers

Our service providers (Supabase and Vercel) are based in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data transfer restrictions, your personal data may be transferred to and processed in a country that does not provide the same level of data protection as your home country.

Where such transfers occur, we ensure they are protected by appropriate safeguards, including the EU Standard Contractual Clauses (SCCs) adopted by the European Commission under Decision (EU) 2021/914, or equivalent mechanisms recognised under applicable law.

You may request a copy of the applicable transfer mechanism by contacting us at privacy@castface.net.

8. Data Retention

We retain your personal data for the following periods:

Data CategoryRetention Period
Account and identity dataFor the duration of the account, plus 3 years after closure to handle any post-closure claims
Facial photographs (active listing)For the duration of the active listing, or until consent is withdrawn
Facial photographs (rejected or deleted listing)30 days after rejection or deletion, then permanently deleted
License request records5 years from the date of the request, for legal and audit purposes
Consent records (biometric consent, ownership consent)5 years from date of consent, as required for compliance purposes
Technical/usage logs90 days, then aggregated or deleted
Support communications3 years from the date of last communication

After the applicable retention period, data is securely deleted or anonymised. We may retain data for longer periods where required by law or where necessary to establish, exercise, or defend legal claims.

9. Your Rights

Depending on your location and applicable law, you may have the following rights with respect to your personal data. To exercise any of these rights, please contact us at privacy@castface.net.

Right of access (GDPR Art. 15)

You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to rectification (GDPR Art. 16)

You have the right to request correction of inaccurate or incomplete personal data.

Right to erasure / "right to be forgotten" (GDPR Art. 17)

You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent (where consent is the legal basis). Exceptions apply where retention is required by law or for legal claims.

Right to restriction (GDPR Art. 18)

You may request that we restrict processing of your data in certain circumstances, such as while a dispute about accuracy is resolved.

Right to data portability (GDPR Art. 20)

You may request your data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where technically feasible.

Right to object (GDPR Art. 21)

You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to withdraw consent (GDPR Art. 7(3))

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Rights under US state laws (CCPA / CPRA, BIPA, etc.)

If you are a California resident, you have additional rights under the CCPA/CPRA, including the right to know, the right to delete, the right to opt-out of sale (we do not sell data), and the right to non-discrimination. If you are an Illinois resident, you have rights under BIPA including the right to receive a written policy before data collection, and the right to deletion.

We will respond to rights requests within 30 days. We may request proof of identity before fulfilling a request to protect against fraudulent access. If your request is complex or numerous, we may extend the response period by a further two months and will notify you accordingly.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For EU residents, a list of supervisory authorities is available at the European Data Protection Board website.

10. Security

We implement technical and organisational measures designed to protect your personal data against unauthorised access, loss, destruction, or alteration, including:

  • Encryption of data in transit (TLS 1.2 or higher on all connections).
  • Encryption of data at rest for stored photographs and database records.
  • Private storage buckets with Row-Level Security policies — facial images are not publicly accessible and are served only via time-limited signed URLs to authenticated users.
  • Access controls restricting administrative access to authorised personnel only.
  • Regular review of security practices.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you in accordance with our obligations under applicable law (within 72 hours to the relevant supervisory authority under GDPR Art. 33, and without undue delay to affected individuals under GDPR Art. 34 where required).

11. Children

The Platform is strictly prohibited for persons under 18 years of age. We do not knowingly collect or process personal data from minors. If you believe that we have inadvertently collected data from a person under 18, please contact us immediately at privacy@castface.net and we will take prompt steps to delete such data.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised Policy on the Platform with an updated effective date and, where the changes are material, we will provide notice to registered users by email or through a prominent notice on the Platform.

We encourage you to review this Policy periodically. Your continued use of the Platform after the effective date of any revision constitutes your acceptance of the updated Policy.

13. Contact and DPO

For any questions, requests, or complaints regarding this Privacy Policy or our data processing practices, please contact us at:

CastFace

Privacy enquiries: privacy@castface.net

Legal enquiries: legal@castface.net

[TODO: Add registered address once company is incorporated]

If you are located in the EU/EEA and we are required to appoint a Data Protection Officer (DPO) or EU Representative under Article 27 GDPR, their contact details will be listed here. [TODO: Assess DPO/EU Rep requirement upon company incorporation and once user volume is established]