Platform Privacy Policy
Last updated: 2026-05-17 (draft v1 — pre-launch counsel review pending)
Platform Privacy Policy — Lounge & Co.
🚧 DRAFT — Pre-launch counsel review required. This document is a working draft authored 2026-05-17 as part of the pre-launch legal-doc cascade. Do not publish without counsel review. Counsel review paired with MEMBER_TERMS_OF_SERVICE.md and DPA_VENUE_TEMPLATE.md.
Effective: [PENDING LAUNCH DATE] · Last revised: 2026-07-10 (draft v4)
1. About this Privacy Policy
This Privacy Policy describes how Lounge & Co., LLC (“Lounge & Co.”, “we”, “us”) collects, uses, and shares personal information when you use the Lounge & Co. platform (the “Platform”). It applies to all visitors and Members of the Platform.
Lounge & Co. operates under a split data-controller posture (CCPA Option C, established 2026-05-17):
- For your identity, authentication, and subscription billing data, Lounge & Co. is the controller (a “business” under CCPA / a “controller” under most state privacy laws). Members pay Lounge & Co. directly for their subscription, so the legal relationship is direct.
- For your content scoped to a specific venue you have joined (Visit items at that venue, venue-specific posts, venue-context ratings), Lounge & Co. acts as a service provider / processor on behalf of the venue under a per-venue Data Processing Agreement. The venue is the controller for that data scope.
- For your platform-wide content (palate profile, follow graph, DMs, Activity feed, concierge memory at the global scope), Lounge & Co. is the controller.
This split matters because the data you can request access to, deletion of, or opt-out from is governed by which scope it falls into.
2. Data we collect
2.1 Identity and authentication data (we are the controller)
- Email address
- Password hash (we never store your password in cleartext)
- Multi-factor authentication settings
- Token of Trust verification status (identity name + age — collected only to verify you are 21+; not retained in plain form beyond the verification check)
- Account creation date, last login date, IP addresses used to log in (for security)
- Subscription tier, billing history, payment method (via Stripe — we don’t store card data on our servers)
2.2 Profile data (we are the controller for platform-wide profile)
- Display name
- Profile photo
- Bio
- Multi-category palate preferences (cigar, bourbon, whiskey, rum, tequila, mezcal, gin, vodka, beer — entered during onboarding + refined over time)
- Follow graph (who you follow, who follows you)
- Notification + privacy preferences
2.3 Member content (split controller)
- Platform-wide content (we are the controller): DMs, Activity feed entries, follow relationships, platform-wide posts, concierge conversation history.
- Venue-scoped content (venue is the controller; we are the processor): Visit items at each venue you’ve joined, venue-context posts, venue-context ratings, your venue-membership profile data (if different from platform profile), in-venue presence (when you’re at the venue).
2.4 Usage data (we are the controller)
- Pages and features used
- Click and tap events (for product improvement, anonymized after 90 days)
- Device type, operating system, app version
- Approximate location based on IP (used for US-only geofence; not precise GPS). IP-to-country resolution uses the DB-IP IP-to-Country Lite database, licensed under Creative Commons Attribution 4.0 International, self-hosted on our infrastructure (not a sub-processor — no data leaves our systems for this lookup).
- If you opt in to geofence-based Visit auto-close: venue-level location (you arrived at venue X) — never raw GPS coordinates stored
2.5 Communications
- Emails you send to us (support, appeals, legal inquiries)
- In-app notifications you’ve received + interacted with
3. How we use your data
3.1 Provide the Platform
- Authenticate you (login, MFA)
- Process your subscription billing via Stripe
- Verify your age and identity at signup via Token of Trust
- Display your profile and content to you and to other Members per the visibility settings you choose
- Operate the concierge (cross-venue AI; presented as Sterlon or Aurelle per your pick) on the data scopes the concierge needs to do its job
- Operate cross-venue platform features (Activity feed, follow graph, DMs, Year-in-Drinks/Smokes recap)
- Operate venue-context features (Visit logging, venue feeds, venue events) under per-venue DPA
3.2 Improve the Platform
- Analyze usage patterns to improve features (anonymized after 90 days)
- Configure and refine the concierge (via our sub-processor Anthropic, under enterprise no-training-on-customer-data terms — configuration is via prompts, RAG, and our
concierge-memorypackage, not model retraining on your data) - Generate aggregate, anonymous analytics for venue admins (per venue DPA)
See our consolidated AI Feature Disclosure for a single-surface summary of every AI feature.
3.3 Communicate with you
- Service emails (billing receipts, security alerts, policy updates)
- Notification emails per your preferences (event reminders, DM notifications, etc.)
- Marketing emails if you’ve opted in (you can opt out at any time via the unsubscribe link)
3.4 Safety and moderation
- Process automated content moderation via our sub-processor Hive (image + text + video visual/audio classification, CSAM detection)
- Investigate reports of policy violations per the Moderation Policy
- Enforce age verification + US-only geofence
- Detect fraud, abuse, security threats
3.5 Legal compliance
- Respond to legal process (subpoenas, court orders)
- Cooperate with law enforcement when required by law (e.g., NCMEC reports for CSAM, per Moderation Policy §3.2)
- Defend our legal rights
4. Sub-processors (the parties we share data with)
Lounge & Co. uses the following sub-processors. Each is bound by data-processing terms that prohibit them from using your data for purposes beyond providing their service to us.
| Sub-processor | Purpose | Data shared | Substance-use data flow | Data residency | Transfer mechanism |
|---|---|---|---|---|---|
| Token of Trust | Identity + age verification at signup | ID document + biometric face scan (one-time at signup; retained ≤30 days post-verification per Lounge & Co.’s BIPA-compliant DPA — see Section 11) | None — TOT does not receive substance-use data | United States | US-only contract |
| Anthropic | AI concierge LLM provider (text + image multimodal; serves both Sterlon and Aurelle displays) | Concierge conversation content + relevant member context (palate, history) + member-attached image(s) sent per API call; enterprise no-training-on-customer-data terms | Receives substance-use data as part of the concierge’s recommendation context (member’s consumption history, palate model, current Visit context); images may depict tobacco/spirits products | United States | EU-US Data Privacy Framework certified + Standard Contractual Clauses backstop |
| Deepgram | Voice-input transcription for the concierge | Streamed audio when a member uses voice input on the concierge; raw audio is discarded server-side immediately after transcription completes (only the transcript text is retained); enterprise no-training-on-customer-data terms | Receives substance-use data when a member speaks a concierge turn that mentions tobacco or spirits products (transcript only — raw audio not retained) | United States | DPF + SCCs in Deepgram DPA |
| Stripe | Subscription billing + payment processing | Email, name, payment method, billing history | None — Stripe does not receive substance-use data | United States (with documented global mirroring per Stripe’s published infrastructure) | DPF + SCCs in standard Stripe DPA |
| Hive | Automated content moderation (image, text, and video visual + audio classification) + CSAM detection | Images, text, and video (visual + audio track) submitted to the platform; classification results returned; no retention by Hive beyond 30 days | Receives substance-use data within member posts subject to moderation (Visit logs may mention tobacco/spirits products being consumed; member video/audio may depict or mention them) | United States | US-only contract |
| Better Stack | Platform monitoring + uptime + status pages | Operational telemetry (no member content) | None — Better Stack receives only operational telemetry, no member content with substance-use signals | EU by default (DIN ISO/IEC 27001-certified data centers; Better Stack is HQ’d in Prague, Czech Republic). US-region custom data location available on Better Stack Enterprise tier; planned upgrade per ROADMAP N43. Lawful under US law for outbound operational telemetry from US-only members (G1 US-only at launch; no EU-origin member data exists). | Sub-processor DPA with contractual use-limitation; Better Stack is SOC 2 Type 2. DPF / SCCs do not gate this flow — they govern EU-origin data inbound to the US, which is not the direction here. |
| Resend (Phase 1) | Transactional + venue-broadcast email delivery | Email address + email contents | Receives substance-use data only when email content references it (e.g., Year-in-Drinks recap delivery, opt-in only; venue promotional broadcasts may reference the venue’s offerings) | United States | DPF + SCCs |
| Cloudflare | Bot-protection challenge for signup, password reset, and waitlist forms | IP address, request headers, session cookies set by Turnstile during the client-side challenge; api also forwards the user’s IP to Cloudflare’s siteverify endpoint server-side for token validation | None — Cloudflare does not receive substance-use data | Global edge (US-based contract) | DPF + SCCs in Cloudflare standard DPA |
| OAuth identity provider (Sign in with Google) | OAuth sub claim, email, optional profile name on each authentication round-trip |
None — Google receives only authentication-scope data | United States | EU-US Data Privacy Framework certified + Standard Contractual Clauses backstop | |
| Apple | OAuth identity provider (Sign in with Apple) | OAuth sub claim, email (real or Hide-My-Email relay address), optional name on first-consent only; Apple proxies outbound transactional email when relay is elected |
None — Apple receives only authentication-scope data + email relay routing | United States | EU-US Data Privacy Framework certified + Standard Contractual Clauses backstop |
| Cloudinary | Image and video transformation + CDN delivery of moderation-cleared member media | Moderation-cleared member images/video + derived transforms; Cloudinary public IDs. Receives cleared bytes only — media reaches Cloudinary only after passing the CSAM + content-moderation gates (per BUSINESS_MODEL.md §0.11); unscanned uploads never leave our infrastructure |
Cleared member media may depict tobacco/spirits products (e.g., Visit photos, event imagery); Cloudinary receives image/video bytes only — no palate model, consumption history, or text signals flow | US/global CDN (US-based contract) | Cloudinary standard data-processing terms (incorporated by reference into the vendor agreement); execution of a bespoke enterprise DPA is a tracked pre-launch counsel item |
| PostHog (planned post-launch — see §9) | Product analytics + funnel/event tracking + session replay (Zone A surfaces only) + feature flags + experiments. Not live at launch — listed here so the disclosure is complete when it ships; at launch there are no analytics cookies or session replay (see §9). | Pseudonymous member ID; platform-funnel event names with allowlisted properties (event name + funnel step + attribution-source from member.attribution_source); Zone A session-replay payloads from pre-auth marketing pages (other than /signup and /age-verify) and the first-time onboarding modal flow, with input masking on every text input + URL scrubbing on UTM params / invite tokens / verification state. No replay on authenticated surfaces (Zone B). No instrumentation on /age-verify or any client-side Token of Trust route (Zone C); server-side tot_outcome event emits a success/fail boolean only — no ID metadata, no biometric metadata, no provider payload |
Substance-adjacent events fire from Zone B surfaces (e.g., concierge_turn_sent, visit_logged, activity_post_created) but carry only event names + allowlisted properties — never content payloads, never product names, never the body of a Sterlon turn or a post. Zone A replay is gated to pre-auth landing/pricing/about/blog + onboarding modal, none of which surface substance-adjacent member content |
United States (PostHog Cloud US) | DPF + SCCs in PostHog Cloud US DPA. Platform-scope-only sub-processor per the scope ruling in BUSINESS_MODEL.md §0.5 (2026-06-02) — disclosed here in §4 only; not listed in DPA_VENUE_TEMPLATE.md §5.1 because PostHog never receives venue-scope Member Data |
| Sentry | Platform application error tracking + diagnostics (frontend + backend); optional performance monitoring deferred to post-launch | Pseudonymous member ID; exception payloads + sanitized stack traces; URL of the page or API route where the error fired; breadcrumbs (route changes, click events, network requests with method + status + scrubbed URL — never request bodies); release SHA tag; browser / device / OS metadata. Frontend SDK (@sentry/react + @sentry/browser) does not load on /age-verify or any client-side Token of Trust route; backend SDK (@sentry/node) scrubs request bodies for /api/auth/tot/* endpoints before breadcrumb capture so biometric metadata + provider payloads never reach Sentry |
None — Sentry captures only operational + diagnostic payloads. Member content (post bodies, Sterlon turn text, Visit-item details, palate notes, DMs) never appears in stack traces or breadcrumbs under the disciplined-implementation rule; the Sentry SDK’s beforeSend / beforeBreadcrumb hooks redact any such payload before transport |
United States (Sentry Cloud US) | DPF + SCCs in Sentry Cloud US DPA. Platform-scope-only sub-processor per the scope ruling in BUSINESS_MODEL.md §0.5 (2026-06-02) — disclosed here in §4 only; not listed in DPA_VENUE_TEMPLATE.md §5.1 because Sentry never receives venue-scope Member Data |
The current list is also maintained at lounge.app/subprocessors (post-launch).
We do not sell your personal information to third parties.
We may share information in the limited circumstances of legal compliance, fraud prevention, business transitions (merger or acquisition — your data remains protected by this Policy), or with your explicit consent.
5. Your privacy rights
You have the following rights regarding your personal information. The applicable rights depend on your state of residence (California’s CCPA/CPRA is the most extensive; many other states have similar laws).
5.1 Right to know / access
You can request a copy of all personal information we hold about you. We will respond within 45 days (or up to 90 days for complex requests) with either:
- An exportable bundle of your data (JSON + CSV format covering profile, posts, comments, DMs, Activity, Visits, concierge history, sub-processor data summaries), OR
- An explanation of which data we cannot provide (e.g., data we no longer hold, data that would compromise another Member’s privacy).
Request via Settings → Privacy → Request My Data in the Platform, or email Bcoulter@aoshi-labs.com.
5.2 Right to deletion
You can request deletion of your account and personal information. We will:
- Soft-delete your account within 7 days
- Hard-delete within 30 days
- Cascade deletion to sub-processors (Anthropic for concierge history; Hive for any pending moderation context; Stripe retains billing history per their data-retention policy, typically 7 years for tax/compliance purposes; this retention is mandated by law and not subject to deletion)
- Backup copies may persist for up to 30 days post-deletion for operational + audit purposes
Some data is retained beyond deletion:
- Aggregate, anonymized analytics (no longer identifiable to you)
- Records required by law (subscription billing records for 7 years per IRS retention; moderation action audit logs for 7 years per Section 230 defense)
Request via Settings → Privacy → Delete Account, or email Bcoulter@aoshi-labs.com.
5.3 Right to correct / rectification
You can correct inaccurate personal information directly in Settings → Profile. For data you cannot edit directly (e.g., concierge history), email Bcoulter@aoshi-labs.com.
5.4 Right to opt out of “sale” or “sharing”
We do not sell your personal information and we do not share it for cross-context behavioral advertising. Under Cal. Civ. Code §1798.120(a), the right to opt out attaches only to data flows that fall within the §1798.140(ad) definition of “sell” or the §1798.140(ah) definition of “share.” No Lounge & Co. data flow matches either definition: every disclosed sub-processor (see §4) is purpose-tagged for one named business purpose under per-vendor DPA; none is tagged as “cross-context behavioral advertising,” and we do not deploy ad-network SDKs, third-party pixels, behavioral-event brokers, or cross-member retargeting signals. Because §1798.120(a) does not attach, CCPA Regs §7026’s opt-out-request and Do-Not-Sell-or-Share-link operational requirements correspondingly do not apply.
The Settings → Privacy → Do Not Sell or Share surface is therefore a static affirmative disclosure of this posture, not an opt-out toggle — we do not invent a toggle for a flow that does not exist. The disclosure surface is the record of our posture, readable by you at any time. See BUSINESS_MODEL.md §0.9 for the full disclosure-surface rationale.
We honor Global Privacy Control (GPC) and Universal Opt-Out Mechanism (UOOM) signals as valid opt-out mechanisms for any data flow that may become subject to §1798.120(a) in the future; when your browser sends a recognized opt-out header to our privacy-settings endpoints (Settings → Privacy → GPC and Settings → Privacy → UOOM), we record the election and surface a status indicator on those pages. No member action required. Broader honoring of these signals across the rest of the app ships in our next milestone. The “election” wording is reserved here for real opt-out signals (GPC, UOOM); there is no election to record for the Do Not Sell or Share surface because there is no opt-out flow to elect against.
5.5 Right to non-discrimination
We will not discriminate against you for exercising any privacy right. You will continue to receive the same Platform features, prices, and service quality.
5.6 Authorized agent
You may designate an authorized agent to exercise your privacy rights on your behalf. We may verify the agent’s authority (typically via signed authorization or power of attorney).
5.7 California-specific rights
California residents have additional rights:
- Right to know the categories of personal information collected, used, disclosed
- Right to limit use of sensitive personal information. The sensitive personal information we collect under Cal. Civ. Code §1798.140(ae) is: (a) age-verification and identity data, including the one-time biometric face scan processed by Token of Trust at signup (see §4 and Section 11); (b) your IP address; and (c) substance-use / consumption signals — your palate model, consumption history, Visit items, tasting notes, and the content of concierge turns — which we treat as sensitive because they can reveal tobacco- and alcohol-consumption patterns and flow to the sub-processors enumerated in §4 (Anthropic, Deepgram, Hive). Each category is used only for the stated purposes; we do not use or disclose sensitive personal information to infer characteristics about you beyond providing the Platform.
- Right to know about automated decision-making (concierge recommendations + Hive moderation flagging — described in the Community Guidelines and Moderation Policy). The
Settings → Privacy → ADMTopt-out kill-switch currently pauses Sterlon/Aurelle (concierge recommendations) at every turn server-side, and that is the only ADMT process it suppresses today; Hive automated-moderation auto-action suppression for opted-out members is forthcoming and ships with our next milestone. Until then, an opted-out member’s Hive moderation flags follow the normal moderation path. To reverse an ADMT opt-out, emailappeals@lounge.co; we do not currently ship a self-service opt-back-in control.
5.8 Children
The Platform is restricted to adults 21+. We do not knowingly collect personal information from anyone under 21. If you believe we have inadvertently collected information from a minor, please email Bcoulter@aoshi-labs.com immediately so we can delete it.
6. Data retention
| Data category | Retention period |
|---|---|
| Active account data | While account is active |
| Soft-deleted account data | 30 days, then hard-deleted |
| Billing records | 7 years (IRS tax compliance) |
| Moderation audit logs | 7 years (Section 230 defense) |
| Aggregate, anonymized analytics | Indefinite (no longer identifies you) |
| Concierge conversation history | While account is active; cascade-deleted on account deletion |
Concierge memory (concierge-memory package fact entries) |
While account is active; cascade-deleted on account deletion |
| Web server logs (IP, user-agent) | 90 days |
| Email delivery logs (Resend) | 30 days |
| Hive moderation context | 30 days (per Hive DPA) |
| Token of Trust verification data | Not retained by Lounge & Co. after verification result is returned |
7. Data security
We implement industry-standard security measures:
- TLS 1.3 in transit
- Encryption at rest for sensitive data (PostgreSQL
pgcryptofor credentials; encrypted object-storage bucket policies for media) - Multi-factor authentication available for all Member accounts
- Token of Trust verification at signup
- Better Stack monitoring + 24-hour incident response SLA
- Quarterly penetration testing (Phase 2+)
- Annual ASV scans for our SaaS subscription billing PCI scope
In the event of a data breach affecting your personal information, we will:
- Notify affected Members within 72 hours of discovery (or per state law if shorter)
- Notify state Attorneys General as required by state breach-notification laws
- Provide details of the breach + recommended Member actions
Report security vulnerabilities to Bcoulter@aoshi-labs.com.
8. Geographic scope
The Platform is currently available only in the United States. Non-U.S. IPs are geofenced at signup. If you are accessing the Platform from outside the United States:
- We do not solicit your business
- Some features may not work
- You are responsible for compliance with your local laws
We do not currently transfer Member content outside the United States. Disclosed operational telemetry sent to sub-processors may be processed outside the US — currently Better Stack’s EU-default storage for monitoring/uptime data, until ROADMAP N43 (Phase 2) moves it to a US region. See §4 for the full sub-processor residency table, including each sub-processor’s data-residency posture and transfer mechanism.
9. Cookies and tracking
Lounge & Co. discloses every cookie the Platform sets at Settings → Privacy → Cookie Preferences, with purpose, expiration, and vendor for every cookie in the cascade.
Today’s posture — strictly necessary only. At launch, the Platform sets only strictly necessary cookies: the Better Auth session cookie, the Stripe Checkout cookies set during billing flows (__stripe_mid, __stripe_sid), and Cloudflare Turnstile cookies set during signup / password-reset / waitlist bot-protection challenges. These are required for the Platform to function and are not subject to opt-out. The Cookie Preferences surface lists each by name, vendor, and duration. The “Optional cookies” section ships with an empty-state at launch — we do not set analytics, advertising, or cross-site tracking cookies today.
Planned post-launch additions (see ROADMAP §N27). When PostHog product-analytics, the lounge_attr first-party UTM-attribution cookie, and any other non-essential cookie ships, each will appear in the Cookie Preferences “Optional cookies” section with a separate opt-out toggle, and we will provide 30-day prior notice per Section 10 below. PostHog session replay, when it lands, will be limited to Zone A surfaces (pre-auth marketing pages other than /signup + /age-verify, plus the first-time onboarding modal); no replay will run on apps/web authenticated surfaces. No PostHog instrumentation will run on /age-verify or any client-side Token of Trust route.
We honor Global Privacy Control (GPC) and Universal Opt-Out Mechanism (UOOM) signals as automatic opt-out for any future analytics cookie category per §5.4; when your browser sends a recognized signal to our privacy-settings endpoints, we record the election and surface a status indicator at Settings → Privacy → GPC and Settings → Privacy → UOOM. Broader honoring of these signals across the rest of the app — including the suppression of future non-essential cookies app-wide based on the detected signal — ships in our next milestone. We do not use advertising cookies or cross-site tracking, today or planned.
10. Updates to this Policy
We may revise this Privacy Policy. Material revisions (changes to data we collect, sub-processors, your rights, or retention periods) will be announced via in-app notification + email at least 30 days before they take effect. Non-material revisions (clarifications, formatting) take effect immediately with notice in the revision history below.
11. Biometric data (BIPA compliance)
This section addresses Lounge & Co.’s collection, use, retention, and destruction of biometric identifiers, as required by the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14 et seq., and as a matter of platform-wide consistency for all members.
What we collect. At signup, every member completes a Token of Trust identity verification flow that captures and processes biometric identifiers — specifically, face geometry templates derived from a one-time selfie matched against a government-issued ID photo. This data is processed by Token of Trust (our biometric processor under contract) on behalf of Lounge & Co.
Why we collect it. Solely to verify that you are at least 21 years of age — a precondition for any use of the Platform, given the premium tobacco and spirits vertical we serve. Verification supports our App Store Guideline 1.4.3 framing, our Section 230 + UGC posture, and our regulatory commitments to age-gate any platform feature involving tobacco or alcohol content. No other use of biometric identifiers is permitted under our contract with Token of Trust.
Affirmative consent. Before the Token of Trust scan begins, you are shown a brief on-surface disclosure at /age-verify identifying Token of Trust as the verification sub-processor and confirming that Lounge & Co. does not store the government ID itself, with inline links to this Privacy Policy and our Member Terms of Service. You must then affirmatively check a consent box labeled “I’m 21+ and consent to biometric processing per the [Terms], [Privacy Policy], and [AUP].” — and the two method buttons (Verify with ID / Verify with Selfie + ID) remain structurally disabled via the disabled HTML attribute + a JavaScript change listener until that checkbox is checked. The (a) what biometric data is collected / (b) why / (c) how long / (d) your right to decline detail required by BIPA §15(b) appears in full in the remainder of this Section 11 (immediately following). By checking the on-surface consent box, you affirmatively acknowledge that you have been directed to this Section 11 and have the opportunity to read it before consenting. (Whether this brief-on-surface + linked-PP posture is sufficient under BIPA caselaw — particularly Sosa v. Onfido — is under counsel review; if it is determined to be insufficient, the on-surface disclosure paragraph grows back to include the §15(b)(a)–(d) detail directly.)
Right to decline. You have the right to decline biometric collection by leaving the affirmative-consent checkbox at /age-verify unchecked. If you decline, the Verify with ID and Verify with Selfie + ID buttons remain disabled, the Token of Trust verification flow never starts, no biometric identifiers are collected, and signup cannot be completed (because age verification is a precondition for any use of the Platform — see “Why we collect it” above). Declining does not create a Lounge & Co. account, does not authorize any biometric processing, and does not result in any biometric data being captured, stored, or transmitted. You may close the page at any time before checking the consent box without consequence.
Retention. Biometric identifiers are retained no longer than 30 days post-verification. Token of Trust purges the data on the 30th day per its contractual commitment to Lounge & Co. Only the verification result (a boolean confirmation that you are 21+ and a verification ID) is retained on a long-term basis by Lounge & Co.
What Lounge & Co. does NOT store. Lounge & Co. does not store the government ID document image, the selfie image, or the face-geometry template at any point. Those artifacts are captured and processed entirely within Token of Trust’s infrastructure during the verification flow. Lounge & Co. receives only (a) the pass/fail verification result, (b) a verification ID linking back to Token of Trust’s record, and (c) a timestamp. The disclosure surfaced on /age-verify reflects this — “your government ID is processed by Token of Trust; Lounge & Co. only stores the verification status (whether you passed), never the ID itself” — and this section confirms the upstream commitment.
Destruction procedure. At day 30, Token of Trust executes its automated purge routine; deletion logs are retained for compliance review and reviewed quarterly. If you delete your account before day 30, the verification record + any biometric identifiers still held are destroyed within 7 days as part of the platform’s normal data-deletion cascade.
Sale and disclosure. Lounge & Co. does not sell, lease, trade, or otherwise profit from your biometric identifiers. We do not disclose your biometric identifiers to third parties except: (i) Token of Trust as the processor performing verification, (ii) as required by law (subpoena, court order), or (iii) with your separate written consent.
Security. Biometric identifiers in transit + at rest are protected by industry-standard encryption (TLS in transit; AES-256 at rest within Token of Trust’s infrastructure). Token of Trust’s security practices are reviewed quarterly under our sub-processor compliance program.
Your rights under BIPA. Illinois residents have specific rights under BIPA, including the right to: (a) know what biometric data we hold (Section 5.1 of this Policy); (b) request deletion (Section 5.2); (c) seek statutory damages for violations ($1,000 negligent / $5,000 intentional per violation under BIPA §20). Contact Bcoulter@aoshi-labs.com for BIPA-specific inquiries.
Why this policy is uniform across all states. Although BIPA is an Illinois statute, Lounge & Co. applies its consent + retention + destruction framework uniformly to all members regardless of state of residence. This avoids geofence-detection failures becoming liability vectors, supports forward-compatibility with similar statutes emerging in other states (Texas CUBI, Washington HB 1493), and reflects our broader posture of treating sensitive personal-information categories with elevated protection.
12. Contact
- General privacy inquiries:
Bcoulter@aoshi-labs.com - Security:
Bcoulter@aoshi-labs.com - Legal:
Bcoulter@aoshi-labs.com - Mailing address: Lounge & Co., LLC, [PENDING ADDRESS]
- Designated privacy officer: [PENDING NAME]
13. Revision history
| Date | Version | Changes |
|---|---|---|
| 2026-05-17 | draft v1 | Initial draft; pre-launch counsel review pending |
| 2026-06-02 | draft v2 | Added PostHog (product analytics + session replay + feature flags + experiments) to §4 sub-processor table; rewrote §9 to disclose two cookie categories (strictly necessary + analytics with opt-out + GPC/UOOM honoring); pre-launch — no member notice triggered. Companion to the BUSINESS_MODEL.md §0.5 (2026-06-02) ruling (archival: docs/internal/BUSINESS_ARCHITECTURE.md@5f24ca35 §13). Counsel review pending. |
| 2026-06-02 | draft v3 | Added Sentry (platform application error tracking + diagnostics; frontend + backend) to §4 sub-processor table. §9 unchanged — Sentry’s default JS SDK is cookieless. Pre-launch — no member notice triggered. Companion to the BUSINESS_MODEL.md §0.5 scope ruling as applied to Sentry (2026-06-02; archival: docs/internal/BUSINESS_ARCHITECTURE.md@5f24ca35 §13) (three-vendor observability split: Sentry errors + PostHog analytics/replay/flags + Better Stack uptime/logs). Counsel review batched with v2’s review. |
| 2026-07-10 | draft v4 | B2.7. Added Cloudinary (image/video transformation + CDN delivery of moderation-cleared member media) to §4 sub-processor table — receives cleared bytes only (post-CSAM + post-content-moderation per BUSINESS_MODEL.md §0.11); never unscanned uploads. Cloudinary operates under its standard data-processing terms; bespoke enterprise DPA execution is a tracked pre-launch counsel item. §4 Hive row extended to the counsel-cleared video scope (video visual + audio classification + CSAM detection; cleared 2026-07-01 per the ADR-021 PR-G amendment) with §3.4 aligned; §4 Resend purpose synced to include venue-broadcast delivery (PR1B drift correction). Companion rows in MEMBER_TERMS_OF_SERVICE.md §7 + DPA_VENUE_TEMPLATE.md §5.1 + subprocessors.json. Pre-launch — no member notice triggered. |