Legal

XPSR Privacy Policy

Effective Date:
September 18, 2026

XPSR · Operated by The.Media.Corp LLC · California, United States

support@xpsr.com

This Privacy Policy explains how The.Media.Corp LLC, a California limited liability company operating XPSR (“XPSR,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use XPSR, including xpsr.com, XPSR Accounts, Creator Profiles, the Creator Directory, opportunities, events, ticket purchases, livestream access, and related services.

By using XPSR, you acknowledge the practices described in this Privacy Policy.

1. Information We Collect

The information we collect depends on how you use XPSR.

Account information

When you create or use an XPSR Account, we may process information such as first and last name; email address; optional organization information; account identifier; onboarding status; reasons for joining XPSR; account context; and creative-journey or onboarding information you choose to provide.

XPSR Accounts are available only to individuals 18 years of age or older.

Passwords and authentication credentials are handled through our authentication infrastructure. XPSR application databases do not receive or store plaintext passwords.

Creator Profile information

Creating a Creator Profile is optional.

If you create one, you may provide information including display name; headline; biography; city and county; profile photograph; website; portfolio link; Instagram link; creative disciplines; opportunity preferences, such as the types of opportunities you are open to; and other professional or creative information you choose to provide.

Some Creator Profile information may become publicly accessible through the XPSR Creator Directory if you enable directory visibility and your profile satisfies XPSR’s publication requirements.

Jobs and opportunities

If you submit a job or opportunity, we may collect information including organization or company name; opportunity title and description; opportunity type; work arrangement; location; compensation information; application URL; contact email; application deadline; and applicable creative disciplines.

We also maintain internal information relating to submission ownership, moderation, review status, administrative notes, and moderation history.

Approved opportunity listings may publicly display the information intended for prospective applicants, including the designated job contact email.

Event and purchase information

When purchasing an XPSR event ticket, we may collect purchaser name; email address; optional phone number; ticket type; quantity; price and currency; order reference; ticket information; payment-related identifiers; refund information; and transaction and fulfillment history.

For livestream purchases, we also associate the purchase and livestream entitlement with the applicable XPSR Account.

Payment information

Payments are processed using third-party payment-processing services.

XPSR does not store your complete credit or debit card number, card security code (CVC), card expiration information, or other complete card credentials.

We may store payment-related identifiers and transaction information provided by our payment processor, such as checkout-session identifiers, payment identifiers, refund identifiers, amounts, currency, and payment status.

Communications and email records

XPSR sends operational communications such as account confirmation, password reset and authentication-related messages, purchase confirmations, and refund confirmations.

We may retain delivery-related information such as recipient address, message type, delivery status, attempts, failure information, provider message identifiers, and timestamps.

XPSR does not currently send newsletters, automated promotional campaigns, or behavioral marketing emails.

If you contact support@xpsr.com, we may collect the information contained in your communication and any information reasonably necessary to respond to or resolve your request.

2. How We Use Information

We may use personal information to create and operate XPSR Accounts; authenticate users and secure accounts; provide and manage Creator Profiles; operate the Creator Directory; display information users have chosen to make public; process and moderate job and opportunity submissions; process event purchases and refunds; issue and manage event tickets; provide livestream entitlements; send transactional and account-related communications; provide customer support; prevent fraud, abuse, and unauthorized access; maintain security and audit records; troubleshoot and improve XPSR; enforce our Terms and policies; maintain appropriate business and financial records; and comply with applicable legal obligations.

We may also use limited referral or campaign information to understand how a purchaser reached XPSR or an event offering.

We use XPSR’s first-party analytics, described in Section 5, to understand aggregate website traffic, engagement, and conversion activity, and to improve XPSR. Analytics information is not used for advertising or to build profiles of individual visitors.

3. Creator Directory and Public Information

XPSR provides an optional public Creator Directory.

When directory visibility is enabled and a Creator Profile meets XPSR’s publication requirements, information that may be publicly displayed includes display name; headline; biography; city and county; profile photograph; primary and additional creative disciplines; website; portfolio link; Instagram link; public Creator Profile address; and selected opportunity preferences or “open to” information.

Your account email, authentication information, internal account role, private onboarding information, account identifier, and other account-only information are not intended to appear publicly in the Creator Directory.

Directory visibility is user-controlled. When you disable directory visibility, your Creator Profile is removed from the public directory and its public profile page becomes unavailable, although the underlying Creator Profile information remains associated with your account unless subsequently deleted.

When creating a Creator Profile, directory visibility may initially be selected by default. XPSR provides a disclosure explaining the public visibility setting and that it may be changed later.

4. How We Disclose Information

We may disclose personal information to service providers that help us operate XPSR.

Current categories include providers supporting website/application hosting; database and file storage; authentication; payment processing; transactional email delivery; livestream delivery; and related infrastructure and security services.

Current providers used in operating XPSR include Lovable and its underlying platform services, Stripe for payment processing, StreamYard for livestream delivery, and Google Fonts for certain font resources.

These providers may process information as necessary to provide their respective services and may have their own privacy policies and legal obligations.

We may also disclose information where reasonably necessary to comply with law or valid legal process; protect XPSR, our users, or others; investigate fraud, abuse, or security incidents; enforce our agreements; protect legal rights; or facilitate a business transaction such as a merger, acquisition, financing, restructuring, or sale of assets, subject to applicable law.

5. Advertising, Analytics and Tracking

XPSR does not use advertising pixels, behavioral advertising trackers, session-replay software, heatmaps, fingerprinting, or third-party behavioral analytics tools.

We do not operate integrations with advertising networks for retargeting or cross-context behavioral advertising.

XPSR first-party analytics

XPSR operates its own first-party analytics to understand general website traffic, engagement, and conversion activity. Analytics information is collected and stored by XPSR within XPSR’s own infrastructure and is not shared with advertising networks or third-party analytics providers.

XPSR analytics records:

  • the page path visited on xpsr.com and the time of the visit
  • the host name of a referring website, such as a search engine or social platform, rather than the full referring address
  • campaign parameters present in a link, such as utm_source, utm_medium, utm_campaign, utm_content, and utm_term
  • a general device category of desktop, mobile, or tablet
  • a coarse country-level code provided by our hosting infrastructure
  • a randomly generated, short-lived session identifier stored only in your browser’s session storage for the current browsing session and reset after a period of inactivity
  • meaningful interaction and conversion events, such as selecting a ticket option, starting checkout, completing an account, publishing a Creator Profile, or submitting an opportunity

XPSR analytics does not store names, email addresses, account or user identifiers, raw IP addresses, precise or geographic location beyond a country-level code, device fingerprints, advertising identifiers, keystrokes, mouse movement, session recordings, or the contents of forms or messages. Analytics records are not linked to an individual person or account and are not used to build a persistent profile of any visitor.

XPSR analytics is not used for cross-site tracking or cross-context behavioral advertising, and is not sold or shared with third parties for advertising purposes.

Conversion events record that an action occurred, not who performed it. Information about your account, Creator Profile, opportunity submissions, and purchases is maintained in the separate XPSR systems described elsewhere in this Privacy Policy.

Analytics reporting is available only to authorized XPSR administrators and is presented in aggregate.

Raw analytics records, including page views, interaction events, and session records, are retained for up to 180 days. Before deletion, they are summarized into aggregate daily totals that contain no session-level detail, and those aggregate totals may be retained for longer-term reporting.

XPSR analytics does not use advertising cookies or third-party cookies. XPSR uses limited browser storage necessary for functions such as authentication, returning users to the appropriate page after checkout, remembering limited session/referral information, the short-lived analytics session identifier, and certain interface preferences.

Certain fonts may currently be loaded from Google Fonts. When your browser requests those resources, technical information ordinarily associated with an internet request, such as your IP address and browser information, may be transmitted to Google.

If XPSR introduces additional analytics, advertising, or other tracking technologies in the future, this Privacy Policy and any applicable consent mechanisms will be updated as appropriate.

6. Technical and Security Information

XPSR records timestamps and certain operational information associated with application records, administrative activity, payment notifications, email-delivery outcomes, and referral/campaign information.

XPSR application tables do not store visitor IP addresses, browser user-agent strings, or general web-request logs. XPSR’s first-party analytics records described in Section 5 store only a general device category and a coarse country-level code, never an IP address.

To protect discount codes from automated guessing, XPSR temporarily stores a keyed, one-way security value derived from the network address of a request that submits a discount code, together with whether the attempt succeeded and when it occurred. XPSR does not store the IP address itself. These security records are used only to limit abuse, are not linked to accounts, orders, Creator Profiles or analytics, and are automatically deleted within about two hours.

Our infrastructure and service providers may independently process technical information such as IP addresses, browser/device information, timestamps, security logs, server requests, payment-security information, and delivery logs as part of operating their services.

7. Data Retention

We retain personal information for as long as reasonably necessary for the purposes for which it was collected, including operating XPSR, maintaining appropriate business records, complying with legal obligations, resolving disputes, preventing fraud, and enforcing agreements.

Account and Creator Profile information is generally retained while the account remains active and thereafter as reasonably necessary to process a verified deletion request and satisfy legitimate legal or operational retention requirements.

Commerce and financial records, including transaction, ticket, payment, and refund records, may generally be retained for up to seven years or longer where required by applicable law, accounting requirements, dispute preservation, or another legitimate legal obligation.

Job and opportunity listings may cease to appear publicly when withdrawn, closed, rejected, or expired, while associated records may remain available internally for administration, moderation, security, or recordkeeping.

Support communications are retained for as long as reasonably necessary to address the request, maintain appropriate business records, resolve disputes, prevent abuse, or satisfy legal obligations.

Security, audit, and payment-notification records may be retained as reasonably necessary for security, fraud prevention, auditing, dispute resolution, financial recordkeeping, and legal compliance.

Raw first-party analytics records, including page views, interaction events, and session records, are retained for up to 180 days. A scheduled daily process summarizes older records into aggregate daily totals before deleting the underlying records. Aggregate totals contain no session-level detail and may be retained for longer-term reporting.

Some current XPSR systems do not automatically delete information according to fixed schedules. We will not represent information as automatically deleted where no such process exists.

8. Your Choices and Privacy Requests

Depending on your relationship with XPSR and applicable law, you may request assistance regarding personal information associated with you.

Requests may include access to applicable personal information; correction of inaccurate information; deletion of eligible information; a copy of applicable personal information; assistance changing the email associated with an account; or questions regarding XPSR’s privacy practices.

Requests may be submitted to:

  • support@xpsr.com

Please use “Privacy Request” in the subject line when possible.

XPSR may need to verify your identity before completing a request. Verification helps prevent unauthorized access, deletion, or disclosure of another person’s information.

Certain information may need to be retained even after a deletion request, including records reasonably necessary for legal compliance, financial recordkeeping, fraud prevention, security, dispute resolution, or enforcement of agreements.

Creator Profile users may also edit profile information and disable public directory visibility through available account controls.

XPSR does not currently provide automated self-service account deletion or data export.

9. California Privacy Information

XPSR is operated by The.Media.Corp LLC in California and may collect information from California residents.

California law may provide certain individuals with privacy rights depending on the circumstances and applicability of particular laws.

XPSR will respond to verified privacy requests as required by applicable law.

Based on XPSR’s current implementation, XPSR does not receive payment in exchange for personal information, does not sell or share personal information for cross-context behavioral advertising, does not use advertising networks to deliver cross-context behavioral advertising, and does not operate retargeting or advertising pixels. XPSR’s first-party analytics described in Section 5 is not used for advertising purposes and is not disclosed to advertising networks or third-party analytics providers.

We may update this section as XPSR’s services, business practices, or applicable legal requirements change.

10. Age Requirements and Minors

XPSR Accounts are available only to individuals 18 years of age or older.

XPSR does not knowingly permit individuals under 18 to create XPSR Accounts.

Certain in-person XPSR events may permit attendees who are 16 or 17 years old with the consent of a parent or legal guardian, subject to any event-specific requirements.

Allowing a minor to attend an eligible in-person event does not authorize that minor to create an XPSR Account.

Because livestream purchases require an XPSR Account, livestream purchasing and account-based livestream access are available only to eligible account holders who are 18 or older.

If we learn that an ineligible minor created an XPSR Account, we may take appropriate steps to restrict or remove the account and associated information, subject to applicable legal and recordkeeping obligations.

11. Information Security

XPSR uses administrative and technical safeguards intended to protect information against unauthorized access, misuse, alteration, or disclosure.

Current protections include authentication controls, role-based administrative access, row-level database access controls, restricted public data interfaces, server-side credentials, payment-notification signature verification, payment environment isolation, and protections limiting public access to Creator Profile information.

No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

12. Third-Party Links and Services

XPSR may contain links to websites, portfolios, social networks, application pages, payment services, or other services operated by third parties.

Their privacy practices are governed by their own policies. XPSR is not responsible for the privacy practices of independent third-party services.

13. Changes to This Privacy Policy

We may update this Privacy Policy when XPSR’s services, data practices, providers, or legal requirements change.

When appropriate, we may provide notice of material changes through xpsr.com, account communications, email, or another reasonable method.

The effective date at the top of this Privacy Policy identifies the current version.

14. Contact Us

Questions or requests regarding this Privacy Policy may be directed to:

  • XPSR
  • Operated by The.Media.Corp LLC
  • California, United States
  • support@xpsr.com