Privacy Policy
Last updated: July 1, 2026
This Privacy Policy describes how Fanfluencer, LLC ("Fanfluencer", "we") collects, uses, shares, and protects information about you when you use MANAGR, our websites, mobile apps, and services (the "Service").
1. Information Stored in the Service
When you use MANAGR, you store data in your firm's private workspace. This stays under your control — it is not handed over to us to use, and we do not access it except to operate or support the Service (see 'Our Access', below). This includes: (a) Account identification — name, email address, password (stored as a one-way bcrypt hash we cannot reverse), and account role (owner, manager, assistant, artist, viewer). (b) Roster and business data — artist profiles, songs and metadata, releases, tours and shows, deals, contacts, calendar events, files, and financial records you enter. (c) Publishing and rights data — writer identities, publisher accounts, splits, and related identifiers you add. (d) Payment information — handled directly by Stripe. We store only your Stripe customer ID; we do not store card numbers, CVVs, or bank account details. (e) Mobile push token — if you grant notification permission, we store a device push-notification token. (f) Stored credentials — any third-party platform logins you save are encrypted with AES-256-GCM and are not readable by us in plain form.
2. Our Access to Your Data
Customer data is maintained within your firm's dedicated workspace. Our staff do not access, read, or use your roster, files, or financial records without your express permission — for example, when you ask us to investigate a reported issue. The only routine exception is automated system processing required to run the Service, such as backups and maintenance, which does not involve a person reviewing your data. When you grant support access, it is limited to the minimum necessary to resolve your request and is recorded in internal access logs. Third-party platform credentials stored in the Service are encrypted at the application layer and are not readable by our staff, including during support.
3. Information Collected Automatically
(a) Server logs — IP address, browser type, referring URL, pages visited, and timestamps, used for security and to debug operational issues. (b) Session cookies — required to keep you logged in. We do not use third-party advertising or cross-site tracking cookies. (c) Email engagement — whether you opened or clicked links in transactional emails we send.
4. Information from Third-Party Services
With your authorization, we may integrate third-party services to operate the Service, such as connected calendars and storage (e.g. Google Drive) and optional sign-in providers. We access only what is needed to provide the feature you enabled, and each provider has its own privacy policy.
5. How We Use Information
We use information to: (a) operate the platform — manage your roster, calendar, releases, deals, and files; (b) process payments and subscriptions via Stripe; (c) send transactional emails — account confirmations, password resets, team invites, onboarding and join notifications, and the weekly digest; (d) deliver push notifications you have opted into; (e) detect and prevent fraud, abuse, and violations of our Terms; and (f) improve and develop the Service.
6. How We Share Information
We do not sell your personal information. We share it only as follows: (a) Within your firm — team members and artists see data according to the role and portal permissions you assign. (b) Service providers (sub-processors): Stripe (billing), Resend (transactional email), Expo (mobile push delivery), Vercel and Neon (hosting and database), and AWS / Vercel Blob (file storage). (c) Legal requirements — in response to valid legal process or to comply with law. (d) Business transfers — if Fanfluencer is acquired or merged, your information may transfer to the successor entity, subject to this Policy.
7. Mobile App & Notifications
Our iOS and Android apps access the same account data as the website. Push notifications are optional and require your explicit permission; you can disable them at any time in your device settings. The app does not track your location or access your contacts, photos, or microphone.
8. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. After account closure, we retain transactional records (subscriptions, signed agreements, financial records) for the period required by applicable tax, accounting, and dispute-resolution law (typically 7 years in the United States). Other personal information is deleted within 90 days of account closure.
9. Your Rights
You have the right to: (a) access and export your personal information; (b) correct inaccurate information from your account settings; (c) delete your account and personal information, subject to the retention exceptions in §8; (d) withdraw consent for optional integrations at any time; and (e) opt out of non-essential email communications. To exercise these rights, email admin@managr.cc with the subject “Privacy request.” We respond to verified requests within 30 days. Residents of the EEA, UK, or California may have additional rights under GDPR, UK GDPR, or CCPA, which we honor equivalently for all users.
10. Children
The Service is not directed to children under 18. We do not knowingly collect information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it promptly.
11. International Data Transfers
The Service is operated from the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction.
12. Security
We use industry-standard practices to protect your information: TLS/HTTPS encryption in transit, encryption at rest, bcrypt password hashing, and principle-of-least-privilege access controls. Especially sensitive items, such as third-party platform login credentials you store in the Credentials Vault, are additionally encrypted at the application layer using AES-256-GCM before storage, so they are not readable in plain form by our staff. Our infrastructure runs on SOC 2-certified cloud providers (Vercel, Neon, and AWS). We conduct our own internal security reviews of the platform. No system is perfectly secure, and we cannot guarantee absolute protection. Promptly notify us if you believe your account has been compromised.
13. Breach Notification
In the event of a confirmed data breach affecting your personal information, we will notify affected customers without undue delay — our target is within 72 hours of confirming the incident — and will describe, to the extent known, the nature of the breach, the data involved, and the steps we are taking in response, consistent with applicable data-protection law.
14. Use of AI Features
Some features use artificial intelligence (powered by Anthropic's API) to draft, summarize, or parse content at your request. Your data is not used to train AI models — neither ours nor, per Anthropic's commercial API terms, Anthropic's. Data sent to these features is processed only to return a result to you.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email and/or in-app notice. The “Last updated” date above reflects the current version.
16. Contact
Privacy questions? Email Fanfluencer, LLC at admin@managr.cc with the subject “Privacy.” Mailing address available on request.