Legal

Privacy Policy

This policy explains how feat. Inc. ("feat.", "we", "us") handles personal information when you use feat.press, the marketplace, storefronts, checkout, and related tools (the "Services"). You can read the marketplace, this policy, and the Terms of Service without an account.

We do not sell personal information. We do not share it for cross-context behavioral advertising. The Terms of Service govern use of the Services.

1. Information we collect

What we collect depends on how you use feat. We collect the categories below.

CategoryExamplesSource
IdentifiersName, email, handle, account id, and the organization you give usYou, and our sign-in provider
Commercial informationListings, prices, commissions, orders, refunds, and payout status. Not full card numbers.You, buyers at checkout, and Stripe
Content you submitProduct copy, brand kits, images, pitches, storefront text, and files you uploadYou
Internet activityPages viewed, referring link, approximate location from IP address, device and browser type, and product eventsAutomatically, when you use the Services
Audio or visualProfile photos and cover images you upload. Session replay records clicks and page paths with form inputs masked.You, and our analytics provider
Professional informationRole you choose (merchant, affiliate, or both) and the pitch you send a merchantYou

Account and sign-in. Accounts use WorkOS. We receive the identity details that flow through that sign-in, such as name, email, and a user id.

Listings, storefronts, and pitches. Merchants submit product and brand material. Affiliates submit pitches and profile details. Buyers may check out as guests. We store the order, the email used for delivery or receipts, and attribution to a storefront when a sale is tied to one.

Payments. Card numbers and bank details are collected by Stripe, not stored on feat. servers. If you connect Stripe to get paid, Stripe collects identity and payout details under the Stripe Privacy Policy. We receive account status and the fields Stripe returns so we can route a destination charge, a platform fee, and an affiliate transfer.

Waitlist and messages. If you join the waitlist or email us, we keep the address and the message. Optional waitlist fields are name, handle, and role.

AI features. When you use a feature that drafts or edits a listing, brand kit, storefront, or similar material, we send the content needed for that request to an AI provider (OpenAI or Anthropic, depending on the feature). We do not allow those providers to use that content to market to you.

We do not ask you for government identification to browse the site. Stripe may request identity documents when its rules require them for a connected account. We do not knowingly collect biometric identifiers for our own use.

2. How we use information

  • Run the marketplace: accounts, listings, approvals, storefronts, checkout, attribution, and payouts.
  • Generate or format pages and assets you ask the product to create.
  • Send transactional email, such as receipts, approval notices, and account messages, through our email vendor.
  • Keep the Services secure, detect fraud and abuse, and debug errors.
  • Measure how the product is used, so we can fix and improve it. This includes product analytics and, where enabled, session replay with inputs masked.
  • Comply with law, respond to lawful requests, and enforce our Terms.

We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you. A merchant approves or declines an affiliate. Charts rank public performance of storefronts. The platform fee shown to a merchant is computed from that merchant's commerce on feat., not from a hidden score.

If you are in the European Economic Area, Switzerland, or the United Kingdom, we rely on these bases: contract (to provide the Services you ask for), legitimate interests (security, fraud prevention, and product analytics that do not override your rights), consent where we ask for it, and legal obligation.

3. How we share information

We share personal information with service providers who process it for us, under terms that limit them to that work. The main providers are:

ProviderRole
StripePayments, connected accounts, and payouts
WorkOSSign-in and account authentication
PostHogProduct analytics, error tracking, and session replay with form inputs masked
VercelHosting and file storage for the site
MongoDBDatabase hosting
ResendTransactional email
OpenAI and AnthropicAI features you invoke, limited to the content needed for that request

A scheduling embed, such as Calendly, loads only on pages that include it, and that provider receives the information its embed collects under its own policy.

We also share information: with a merchant or affiliate when the product needs to, for example an order, a pitch, or a payout they are party to; if the law, a regulator, or legal process requires it; to protect the rights, safety, and property of feat., our users, or others; and with a buyer of feat.'s business in a merger, financing, or sale of assets, in which case this policy still describes the handling unless we give notice of a change.

Sale and sharing. We do not sell personal information for money. We do not share it for cross-context behavioral advertising, and we do not use advertising pixels for that purpose. Under the California Consumer Privacy Act, as amended, and similar state laws, "share" means disclosing personal information for cross-context behavioral advertising. We do not do that.

If your browser sends a Global Privacy Control signal (Sec-GPC or the equivalent preference), we treat it as a request to opt out of sale and sharing. Because we do not sell or share personal information, there is no separate advertising opt-out to apply. The signal does not turn off sign-in cookies or the payments flow.

4. Cookies and recording

  • Required. Sign-in cookies, security cookies, and a short-lived cookie used to verify a Stripe connection. The Services do not work properly without these.
  • Analytics. PostHog sets cookies or similar storage to measure product use and to record masked session replays where recording is enabled. Inputs are masked. We use this to understand product failures, not to advertise to you on other sites.

You can block cookies in your browser. Required cookies that are blocked will prevent sign-in and some checkout steps. We do not respond to the older "Do Not Track" header. We do honor Global Privacy Control as described above.

5. How long we keep information

We keep account and listing information while your account is open. We keep order, payout, and tax-related records for the period payment-network rules and tax law require, which is often several years after the transaction. Server logs and analytics are kept for a shorter operational period, then deleted or aggregated. We may keep a record of a privacy request so we can document that we honored it.

When you close an account, we delete or de-identify personal information we no longer need, except records we must keep for tax, fraud, disputes, and security.

6. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to appeal a denial, and to not be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with consumer privacy laws can use the same request path. We will not discriminate against you for making a request.

Email sandeepkondury@gmail.com with the subject line "Privacy request" and the email on your account. If you have an account, you can also update profile details in the product, which is the second way to reach us about information we hold in your account. We will verify the request using the account email or information we already have. We will respond within the time the applicable law requires. You may use an authorized agent if you provide proof of authority and we can verify you.

If you are in the EEA, the UK, or Switzerland, you may also object to processing based on legitimate interests, ask us to restrict processing, withdraw consent where consent was the basis, and complain to your data protection authority. Our contact for those requests is the same email.

We do not offer a financial incentive for personal information. There is no separate "Do Not Sell or Share" link because we do not sell or share personal information.

7. Security and international transfers

We use access controls, encrypted connections, and vendors with their own security programs. No method of transmission or storage is perfectly secure. You are responsible for the security of your email and devices.

We are based in the United States, and we process information in the United States. If you access the Services from another country, your information will be processed in the United States, where privacy laws may differ. Where the law requires a transfer tool, such as standard contractual clauses, we use one.

8. Children

The Services are not directed at children under 16, and we do not knowingly collect personal information from them. If you believe we have, email us and we will delete it.

9. Changes and contact

We will update the date at the top when this policy changes. For a material change, we will also post a notice on this page or email the address on your account. Continued use after the update means you accept the revised policy, where the law allows that.

feat. Inc., Austin, Texas. Privacy requests and questions: sandeepkondury@gmail.com.