This Privacy Policy explains how Inteclab ("PaidTier", "we", "us") collects, uses and protects personal data when you visit paidtier.com or use the PaidTier platform (the "Service").
If you have any questions about this policy or want to exercise your rights, contact us at privacy@paidtier.com.
1. Two roles: creators and members
PaidTier serves two different groups of people, and our responsibilities differ for each:
- Creators — people who sign up to build and sell courses. For creator data we are the controller: we decide why and how it is processed.
- Members — people who buy a creator's course and receive lessons. For member data we are generally a processor acting on the creator's instructions. The creator is the controller and their own privacy policy governs how they use that data.
If you are a member and want your data deleted, contact the creator you bought from first. We will help them action it, and you can always write to us at privacy@paidtier.com if you get no response.
2. Data we collect
Account data
- Name, email address and password hash.
- Business or brand name and country, where you provide it.
- Your plan, billing status and invoice history.
Course and member data
- Course content you upload: lesson text, images, video and files.
- Member records: name or handle, email, purchase date and the course purchased.
- Delivery and progress data: which lessons were sent, opened or completed.
Payment data
Payments are processed by Stripe. Card numbers never reach our servers — they go directly to Stripe, which is PCI-DSS Level 1 certified. We store only the identifiers and metadata Stripe returns to us: a customer ID, the last four digits, card brand, amount, currency and payout status. See Stripe's privacy policy.
Messaging platform data
When you connect Telegram or Discord, we store the tokens and channel or chat identifiers needed to deliver lessons on your behalf. We read only the messages required to operate the delivery bot — for example a member's /start command or an enrolment code. We do not read unrelated conversations, and we do not use message content for advertising.
Technical data
- IP address, browser type and operating system.
- Pages visited and referring site, via our self-hosted analytics.
- Server and error logs, retained for up to 30 days for security and debugging.
3. Cookies and analytics
We use a self-hosted instance of Plausible Analytics. It is cookieless, sets no persistent identifier, does not track you across sites and does not collect personal data. Analytics data is stored on infrastructure we control rather than sold or shared with an ad network. Because of this, we do not show a cookie consent banner for analytics.
We use Crisp for live chat. If you open the chat widget, Crisp sets a cookie to keep your conversation history and stores the messages, email address and name you provide. See Crisp's privacy policy.
Strictly necessary cookies are used to keep you signed in and to protect against cross-site request forgery. These cannot be disabled without breaking the Service.
4. Why we process your data
- To provide the Service — hosting courses, delivering lessons, processing payments. This is necessary to perform our contract with you.
- To bill you — managing subscriptions, commissions, invoices and refunds.
- To support you — answering questions over email and live chat.
- To keep the Service safe — fraud prevention, abuse detection and rate limiting, based on our legitimate interest in a secure platform.
- To improve the Service — aggregate, non-identifying usage statistics.
- To send product emails — service notices are contractual; marketing emails are sent only with your consent and every one has an unsubscribe link.
5. AI features
Paid plans include an AI course builder. When you use it, the prompts and course material you submit are sent to a third-party model provider to generate a response. We do not permit those providers to train their models on your content. Do not paste sensitive personal data about third parties into AI prompts.
6. Who we share data with
We do not sell personal data. We share it only with vendors that help us run the Service:
- Stripe — payment processing and payouts.
- Cloudflare — hosting, CDN and DDoS protection.
- Telegram and Discord — lesson delivery, where you have connected them.
- Crisp — customer support chat.
- AI model providers — only for content you submit to AI features.
We may also disclose data where required by law, to enforce our Terms, or as part of a merger or acquisition — in which case we will give you notice before your data becomes subject to a different policy.
7. International transfers
We are based in the United States and our vendors operate globally, so your data may be transferred outside your home country. For transfers of personal data out of the European Economic Area or the United Kingdom we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
8. How long we keep data
- Account and course data — for as long as your account is open, then 30 days after deletion so the account can be restored on request.
- Member records — until the creator deletes them or closes their account.
- Payment and tax records — seven years, as required by tax law.
- Server logs — 30 days.
- Support conversations — two years from the last message.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Delete your data, subject to records we must keep by law.
- Export your data in a portable, machine-readable format.
- Object to or restrict processing based on legitimate interests.
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a complaint with your local data protection authority.
California residents additionally have the right to know what personal information is collected and to opt out of its "sale" or "sharing". We do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right.
To exercise a right, email privacy@paidtier.com. We will respond within 30 days and may ask you to verify your identity first.
10. Security
We encrypt data in transit with TLS and at rest, hash passwords with a modern key-derivation function, and restrict internal access to staff who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority without undue delay, and within 72 hours where the law requires it.
11. Children
The Service is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has given us data, email us and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves. The "last updated" date at the top always reflects the current version. For material changes we will email account holders at least 14 days before they take effect.
13. Contact
Inteclab
Privacy enquiries: privacy@paidtier.com
Legal enquiries: legal@paidtier.com