Rory Privacy & Data Retention Policy

Last Updated: September 8, 2026
Effective Date: September 8, 2026
Entity: Rory LLC ("Rory", "we", "us", or "our")
Contact: [email protected] / [email protected]
Websites & Services: joinrory.com, app.joinrory.com, rory.page, rorypay.com (the "Services")
Canonical Registry: https://legal.joinrory.com/en-us/privacy

Rory LLC is committed to protecting your privacy and maintaining the integrity and confidentiality of your personal information. This Privacy & Data Retention Policy explains what information we collect, why we collect it, how it is processed, with whom it may be shared, and our explicit statutory data retention periods.


1. Information We Collect

We collect information across three primary channels: directly from you, automatically through your use of the Services, and from authorized third-party verification partners.

1.1 Information You Provide Directly

  • Identity & Contact Data: Full legal name, preferred display name, email address, postal address, and telephone number.
  • Account Credentials: Username, password hash, multi-factor authentication (MFA/TOTP) keys, and WebAuthn/Passkey registration public keys.
  • Creator Profile & Media: Biographical descriptions, headline copy, linked social handles (Twitch, YouTube, X, Kick), profile avatars, banners, and audio/voice notes.
  • Payment & Banking Information:
    • Fans: Payment card billing details, card brand, last four digits, expiry, and PayPal account references (full credit card PAN and CVV are processed directly via PCI-DSS compliant processors and are never stored on Rory servers).
    • Creators: Bank routing and account numbers (encrypted at rest), tax identification numbers (SSN/EIN where required for Form 1099 compliance), PayPal email addresses, or Venmo handles.

1.2 Information Collected Automatically

  • Append-Only Ledger & Transaction Logs: Complete records of coin package purchases, coin spend transactions, platform fees, tips, recurring tier pledges, and creator USD payouts.
  • Device & Connection Telemetry: IP address, browser type and version, operating system, device identifiers, and timestamped request headers.
  • Interaction Data: Engagement with creator hubs, vanity links, and payout flows.

1.3 Information from Third-Party Service Partners

  • Identity Verification & Biometric Data Partners (KYC/IDV): Didit and Plaid provide identity verification outcomes, document validation signals, and name-matching verification to prevent money laundering and fraud. During creator verification, our identity partner (Didit) may process biometric facial geometry extracted from your government ID photograph and verification selfies to confirm authenticity. Rory does not store raw biometric templates on platform servers. Biometric data processed by Didit is permanently destroyed upon verification completion or within three (3) years of capture, in compliance with the Illinois Biometric Information Privacy Act (740 ILCS 14/) and Texas CUBI.
  • Social SSO Integrations: When you sign in via Twitch, Steam, Discord, Google, or Microsoft, we receive authenticated account identifiers and verified email addresses according to your permissions.

2. Legal Bases & Purposes for Data Processing

We process personal data under the following lawful bases:

Purpose of ProcessingCategories of DataLegal Basis
Operating the financial ledger, crediting coins, and executing payoutsLedger entries, identifiers, payment tokensContractual Necessity
Preventing fraud, chargeback abuse, and platform security exploitsIP logs, device telemetry, authentication credentialsLegitimate Interests
Complying with tax laws (1099 reporting), AML, and OFAC sanctionsLegal name, SSN/EIN, KYC verification reportsLegal & Statutory Obligation
Facilitating fan-to-creator messaging and audio notesAudio files, user messages, creator metadataConsent / Contractual Performance
Improving page performance and evaluating traffic qualityPrivacy-preserving analytics signals (Clarity)Consent

3. Comprehensive Data Retention Schedule

To ensure regulatory compliance, protect the integrity of our financial ledger, and satisfy statutory tax and anti-money laundering mandates, Rory enforces the following formal data retention periods:

Data CategorySpecific Records IncludedRetention PeriodStatutory Rationale
Financial Ledger RecordsImmutable ledger credits, debits, coin purchases, spends, fee schedules, receipts7 Years from transaction dateInternal Revenue Code (IRC § 6001), corporate audit standards, and state financial recordkeeping laws.
KYC & Identity VerificationGovernment ID validation outcomes, Plaid identity matches, legal names, SSN/TIN records5 Years following closure of accountBank Secrecy Act (31 U.S.C. 5318), FinCEN AML regulations, and statutory fraud prevention.
Biometric Verification DataFacial geometry comparison results processed by Didit during creator identity verificationUp to 3 Years or upon verification completionIllinois BIPA (740 ILCS 14/15), state biometric privacy statutes, and AML compliance.
Creator Payout RecordsForm 1099-K / 1099-NEC / 1099-MISC filings, bank transfer receipts, payout rail logs7 Years following the relevant tax yearIRS reporting obligations and statutory commercial code audit windows.
User Profile DataDisplay names, social links, bio, non-financial account preferencesDuration of active account + 30 days post-deletionProvision of platform features; deleted upon verified account closure request.
Direct Messages & Audio NotesFan messages, creator voice thank-yous, message media3 Years or until deletion requested by either partyCustomer dispute resolution, community safety, and platform terms enforcement.
Session & Security Logsrory_session cookies, CSRF tokens, IP access logs, failed login attempts7 to 90 DaysOperational security, DDoS mitigation, and session authentication.

When statutory retention windows expire, personal data is permanently deleted, overwritten, or cryptographically anonymized so that it can no longer be associated with an individual.


4. Third-Party Data Disclosures

Rory does not sell, rent, or trade your personal information. We disclose data solely to the following categories of trusted service providers under strict data protection agreements:

  1. Payment Gateways & Disbursers: PayPal, Venmo, card network processors, and Hyperwallet (solely for creator USD disbursements).
  2. Identity Verification & Banking Rails: Plaid Inc. (bank account authentication) and Didit (automated identity verification).
  3. Cloud Infrastructure & Communications: Amazon Web Services (AWS) for encrypted database storage and transactional email delivery (Amazon SES).
  4. Legal & Regulatory Authorities: When required by subpoena, court order, search warrant, or mandatory legal process, or to protect the safety, rights, and property of Rory LLC, our users, or the public.

5. Security & Technical Safeguards

  • Encryption at Rest & in Transit: All network communication is strictly enforced over HTTPS (TLS 1.3 / modern TLS 1.2). Sensitive database columns (including credentials and API tokens) are encrypted at rest using AES-256.
  • Server-Side Credential Isolation: Passwords utilize high-work-factor Argon2id or PBKDF2 hashing with unique cryptographic salts. Client sessions employ HttpOnly, Secure, and SameSite=Lax cookies.
  • Zero Raw PAN Storage: Rory never stores unencrypted credit card primary account numbers (PAN) or security verification codes (CVV/CVC).

6. Your Privacy Choices and Legal Rights

Depending on your jurisdiction (such as California under CCPA/CPRA, or other US state privacy laws), you may possess the following rights:

  • Right to Know / Access: Request details regarding the categories and specific pieces of personal data we have collected about you.
  • Right to Rectify: Request correction of inaccurate or incomplete personal records.
  • Right to Delete: Request deletion of your personal information, subject to mandatory statutory retention exceptions (such as our 7-year financial ledger retention mandate).
  • Right to Non-Discrimination: We will not discriminate against you in pricing, service quality, or platform availability for exercising your statutory privacy rights.
  • Opt-Out of Sale / Sharing: Rory does NOT sell your personal data or share your personal data for cross-context behavioral advertising.

To exercise any of these rights, email your request to [email protected] or [email protected]. We verify all requests against the authenticated account email before processing.


7. Contact Us

For questions, requests, or concerns regarding this Privacy & Data Retention Policy:

  • Data Protection Officer / Legal Inquiries: [email protected]
  • Corporate Entity: Rory LLC, Orange County, California, USA
  • Website: https://joinrory.com

Version History

  • Version 1 (Current)September 8, 2026