Privacy Policy

Last Updated: August 13, 2025

Monthly Club ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our platform at www.monthlyclubhq.com (the "Platform").

By using the Platform, you agree to this Privacy Policy. If you do not agree, you must not use the Platform.

11. Who We Are

Monthly Club

96 Spencer Way

United Kingdom

Email: support@monthlyclubhq.com

We are the data controller for the personal data we collect, except where we process data on behalf of a Business (see Section 4).

22. Data We Collect

Personal Information

  • Email address (used for account login)
  • Profile information (e.g., display name, business name, description, slug, profile image URLs)
  • Subscription history (products you subscribe to)
  • Business content you upload (posts, images, links)

Payment Information

  • Payment details are processed securely by Stripe — we do not store card or bank account numbers.
  • Stripe may collect identity verification documents directly from Businesses.

Technical & Usage Data

  • IP addresses and device/browser details
  • Authentication tokens and session data
  • Usage logs and analytics
  • File upload metadata (e.g., image name, size, type)

33. How We Use Your Data

We process your data for:

  • Account management – authentication, security, and account settings.
  • Platform functionality – business creation, content posting, subscription management.
  • Payment processing – via Stripe Connect for subscriptions and Balance Builder payments.
  • Communication – transactional emails (e.g., confirmations, updates, notifications).
  • Analytics & improvements – monitoring usage and improving the Platform.
  • Compliance & enforcement – preventing fraud, enforcing our Terms, and complying with legal obligations.

44. Our Role vs. Business Role

When you interact with a Business through our Platform, that Business is the data controller for any personal data you provide to them directly (e.g., in messages or service delivery).

We act as a data processor for certain data on behalf of the Business (e.g., subscriber lists) and as a data controller for operating the Platform.

55. How We Share Your Data

We only share your data with:

  • Stripe – for payment processing, KYC, and fraud prevention.
  • Supabase – for database hosting and file storage.
  • Vercel – for hosting the Platform.
  • Law enforcement – if required by law or to protect rights, property, or safety.

We do not sell your personal data or share it with advertisers or data brokers.

66. Cookies & Tracking

We use:

  • Essential cookies – for login sessions and platform functionality.
  • Analytics cookies – to measure usage and improve performance.

We do not use advertising, social media, or third-party behavioural tracking cookies.

77. Data Retention

Retention Periods:

  • Account data: kept while your account is active. Deleted accounts are removed after [12 months] unless we must keep data for legal reasons.
  • Payment records: retained for at least 7 years for tax and compliance.
  • Logs: server logs kept 30–90 days; analytics for 1–2 years.

88. Data Deletion & Your Rights

Under the UK Data Protection Act and GDPR, you have the right to:

  • Access your data
  • Correct inaccuracies
  • Delete your data ("right to be forgotten")
  • Receive a copy ("data portability")
  • Object to processing

To exercise these rights, email support@monthlyclubhq.com. We will respond within 30 days.

99. International Data Transfers

Supabase and Stripe may process data outside the UK/EU.

Where applicable, we rely on Standard Contractual Clauses or equivalent safeguards for data transfers.

1010. Security

We protect your data through:

  • Row Level Security (RLS) in Supabase
  • Encrypted data transmission (HTTPS)
  • Secure authentication via Supabase Auth
  • Access controls limiting who can view your data

However, no system is 100% secure, and we cannot guarantee absolute security.

1111. Public Content

⚠️ Important Notice

Images uploaded to certain storage areas may be accessible via direct URL. While access is restricted in the Platform, anyone with the link could view them. Please do not upload sensitive content.

1212. Age Restrictions

The Platform is for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.

1313. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with a new "last updated" date. Your continued use of the Platform after changes are made constitutes your acceptance.

1414. Complaints

If you are unhappy with how we handle your data, you can contact the UK Information Commissioner's Office (ICO) at www.ico.org.uk or your local data protection authority.