Privacy Policy
Rory Privacy & Data Retention Policy
Last Updated: September 8, 2026
Effective Date: September 8, 2026
Entity: Rory LLC ("Rory", "we", "us", or "our")
Contact: [email protected] / [email protected]
Websites & Services: joinrory.com, app.joinrory.com, rory.page, rorypay.com (the "Services")
Canonical Registry: https://legal.joinrory.com/en-us/privacy
Rory LLC is committed to protecting your privacy and maintaining the integrity and confidentiality of your personal information. This Privacy & Data Retention Policy explains what information we collect, why we collect it, how it is processed, with whom it may be shared, and our explicit statutory data retention periods.
1. Information We Collect
We collect information across three primary channels: directly from you, automatically through your use of the Services, and from authorized third-party verification partners.
1.1 Information You Provide Directly
- Identity & Contact Data: Full legal name, preferred display name, email address, postal address, and telephone number.
- Account Credentials: Username, password hash, multi-factor authentication (MFA/TOTP) keys, and WebAuthn/Passkey registration public keys.
- Creator Profile & Media: Biographical descriptions, headline copy, linked social handles (Twitch, YouTube, X, Kick), profile avatars, banners, and audio/voice notes.
- Payment & Banking Information:
- Fans: Payment card billing details, card brand, last four digits, expiry, and PayPal account references (full credit card PAN and CVV are processed directly via PCI-DSS compliant processors and are never stored on Rory servers).
- Creators: Bank routing and account numbers (encrypted at rest), tax identification numbers (SSN/EIN where required for Form 1099 compliance), PayPal email addresses, or Venmo handles.
1.2 Information Collected Automatically
- Append-Only Ledger & Transaction Logs: Complete records of coin package purchases, coin spend transactions, platform fees, tips, recurring tier pledges, and creator USD payouts.
- Device & Connection Telemetry: IP address, browser type and version, operating system, device identifiers, and timestamped request headers.
- Interaction Data: Engagement with creator hubs, vanity links, and payout flows.
1.3 Information from Third-Party Service Partners
- Identity Verification & Biometric Data Partners (KYC/IDV): Didit and Plaid provide identity verification outcomes, document validation signals, and name-matching verification to prevent money laundering and fraud. During creator verification, our identity partner (Didit) may process biometric facial geometry extracted from your government ID photograph and verification selfies to confirm authenticity. Rory does not store raw biometric templates on platform servers. Biometric data processed by Didit is permanently destroyed upon verification completion or within three (3) years of capture, in compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14/) and Texas CUBI.
- Social SSO Integrations: When you sign in via Twitch, Steam, Discord, Google, or Microsoft, we receive authenticated account identifiers and verified email addresses according to your permissions.
2. Legal Bases & Purposes for Data Processing
We process personal data under the following lawful bases:
| Purpose of Processing | Categories of Data | Legal Basis |
|---|---|---|
| Operating the financial ledger, crediting coins, and executing payouts | Ledger entries, identifiers, payment tokens | Contractual Necessity |
| Preventing fraud, chargeback abuse, and platform security exploits | IP logs, device telemetry, authentication credentials | Legitimate Interests |
| Complying with tax laws (1099 reporting), AML, and OFAC sanctions | Legal name, SSN/EIN, KYC verification reports | Legal & Statutory Obligation |
| Facilitating fan-to-creator messaging and audio notes | Audio files, user messages, creator metadata | Consent / Contractual Performance |
| Improving page performance and evaluating traffic quality | Privacy-preserving analytics signals (Clarity) | Consent |
3. Comprehensive Data Retention Schedule
To ensure regulatory compliance, protect the integrity of our financial ledger, and satisfy statutory tax and anti-money laundering mandates, Rory enforces the following formal data retention periods:
| Data Category | Specific Records Included | Retention Period | Statutory Rationale |
|---|---|---|---|
| Financial Ledger Records | Immutable ledger credits, debits, coin purchases, spends, fee schedules, receipts | 7 Years from transaction date | Internal Revenue Code (IRC § 6001), corporate audit standards, and state financial recordkeeping laws. |
| KYC & Identity Verification | Government ID validation outcomes, Plaid identity matches, legal names, SSN/TIN records | 5 Years following closure of account | Bank Secrecy Act (31 U.S.C. 5318), FinCEN AML regulations, and statutory fraud prevention. |
| Biometric Verification Data | Facial geometry comparison results processed by Didit during creator identity verification | Up to 3 Years or upon verification completion | Illinois BIPA (740 ILCS 14/15), state biometric privacy statutes, and AML compliance. |
| Creator Payout Records | Form 1099-K / 1099-NEC / 1099-MISC filings, bank transfer receipts, payout rail logs | 7 Years following the relevant tax year | IRS reporting obligations and statutory commercial code audit windows. |
| User Profile Data | Display names, social links, bio, non-financial account preferences | Duration of active account + 30 days post-deletion | Provision of platform features; deleted upon verified account closure request. |
| Direct Messages & Audio Notes | Fan messages, creator voice thank-yous, message media | 3 Years or until deletion requested by either party | Customer dispute resolution, community safety, and platform terms enforcement. |
| Session & Security Logs | rory_session cookies, CSRF tokens, IP access logs, failed login attempts | 7 to 90 Days | Operational security, DDoS mitigation, and session authentication. |
When statutory retention windows expire, personal data is permanently deleted, overwritten, or cryptographically anonymized so that it can no longer be associated with an individual.
4. Third-Party Data Disclosures
Rory does not sell, rent, or trade your personal information. We disclose data solely to the following categories of trusted service providers under strict data protection agreements:
- Payment Gateways & Disbursers: PayPal, Venmo, card network processors, and Hyperwallet (solely for creator USD disbursements).
- Identity Verification & Banking Rails: Plaid Inc. (bank account authentication) and Didit (automated identity verification).
- Cloud Infrastructure & Communications: Amazon Web Services (AWS) for encrypted database storage and transactional email delivery (Amazon SES).
- Legal & Regulatory Authorities: When required by subpoena, court order, search warrant, or mandatory legal process, or to protect the safety, rights, and property of Rory LLC, our users, or the public.
5. Security & Technical Safeguards
- Encryption at Rest & in Transit: All network communication is strictly enforced over HTTPS (TLS 1.3 / modern TLS 1.2). Sensitive database columns (including credentials and API tokens) are encrypted at rest using AES-256.
- Server-Side Credential Isolation: Passwords utilize high-work-factor Argon2id or PBKDF2 hashing with unique cryptographic salts. Client sessions employ
HttpOnly,Secure, andSameSite=Laxcookies. - Zero Raw PAN Storage: Rory never stores unencrypted credit card primary account numbers (PAN) or security verification codes (CVV/CVC).
6. Your Privacy Choices and Legal Rights
Depending on your jurisdiction (such as California under CCPA/CPRA, or other US state privacy laws), you may possess the following rights:
- Right to Know / Access: Request details regarding the categories and specific pieces of personal data we have collected about you.
- Right to Rectify: Request correction of inaccurate or incomplete personal records.
- Right to Delete: Request deletion of your personal information, subject to mandatory statutory retention exceptions (such as our 7-year financial ledger retention mandate).
- Right to Non-Discrimination: We will not discriminate against you in pricing, service quality, or platform availability for exercising your statutory privacy rights.
- Opt-Out of Sale / Sharing: Rory does NOT sell your personal data or share your personal data for cross-context behavioral advertising.
To exercise any of these rights, email your request to [email protected] or [email protected]. We verify all requests against the authenticated account email before processing.
7. Contact Us
For questions, requests, or concerns regarding this Privacy & Data Retention Policy:
- Data Protection Officer / Legal Inquiries: [email protected]
- Corporate Entity: Rory LLC, Orange County, California, USA
- Website: https://joinrory.com
Version History
- Version 1 (Current)September 8, 2026