Who we are and scope
Da Aventura, Westblaak 7, Rotterdam, The Netherlands, KvK 94090904, operates Snackle and is the data controller for the personal data described in this policy.
This policy applies to Snackle account holders, creators, agencies and their authorized staff, people who contact us, and visitors who view or interact with public Snackle pages. It explains what we collect, where it comes from, why we use it, who receives it, how long we keep it, and the choices available to you.
This policy works together with our Terms of Service. Fanvue and any advertising, analytics, or other provider that a creator enables are separate services with their own terms and privacy policies.
Account and communications data
When you create or use a Snackle account, we process your email address, password hash, email-verification state, session information, account and model relationships, basic settings, and records needed to secure and administer the account.
When you contact us, we process your message, contact details, attachments you provide, and our response. We may also keep your email preferences and delivery records.
We send essential account, verification, security, billing-access, and service messages. We may also send optional product updates and performance-recap emails where permitted by law. Optional messages include an unsubscribe method; essential service messages remain part of the service while your account is active.
Fanvue data we process
When you connect Fanvue, Snackle uses OAuth. We never ask for or store your Fanvue password.
Depending on the permissions you grant and the features you use, we may process your Fanvue user and creator profiles, agency and creator roster, Fanvue tracking links and metadata, subscriber and follower events, purchase and revenue events, subscription status, and creator or fan identifiers needed for synchronization and attribution.
Fanvue OAuth tokens are encrypted at rest and used only on the server to provide the connection you requested. You can revoke access through Fanvue, but doing so can stop model synchronization, tracking-link management, subscription checks, and attribution from working.
Creator content and settings
Creators and agencies may upload images and configure names, public profile details, locations, presence text, social links, page styles, Fanvue destinations, and tracking settings. We store this content and configuration to render public pages and provide the dashboard and editor.
Public Snackle pages can be viewed, shared, cached, or indexed by others. Do not publish information or media that you do not want to make public.
We do not use creator content, names, likenesses, or uploaded images to market Snackle. Our use of creator content is limited to operating, securing, supporting, and technically delivering the creator's own Snackle pages and account.
Public-page, analytics, and attribution data
When someone visits or interacts with a public Snackle page, we may record the page and link involved, timestamp, selected A/B creative, referrer, browser and user-agent information, IP address, approximate city and country, UTM parameters, supported advertising click identifiers, a first-party lead identifier, and link interactions.
We may connect those records with Fanvue follower, subscriber, purchase, and revenue events and with the status of conversion deliveries sent to providers selected by the creator. Creators receive analytics and attribution results; they do not receive visitor account passwords, Snackle credentials, or Fanvue OAuth credentials.
We use this information to operate public pages, show performance analytics, attribute Fanvue outcomes to traffic sources and creative variants, avoid duplicate conversion handling, deliver configured conversion events, investigate abuse, and diagnose technical problems.
Marketing and conversion providers
Necessary first-party processing supports the requested link and internal attribution, including a short-lived first-party lead identifier. It continues when optional advertising and analytics are declined so that the page and Fanvue destination remain usable.
A creator may enable Meta, TikTok, Snapchat, Google Ads, Google Analytics 4, or a custom webhook for a model or page. All server-side deliveries to those providers are disabled until you choose “Allow analytics”. Browser tags are governed by the consent state sent to Google Tag Manager or by equivalent page-level controls. Depending on the provider, opted-in processing can include event type and time, page URL, source information, advertising click identifiers, normalized or hashed matching data where supported, purchase value and currency, and deduplication identifiers.
Snackle uses a site-wide Google Tag Manager container for optional analytics and advertising tags. The site-wide container loads on every page after a denied default consent state is set. Snackle sends your stored consent state to the container and updates it when your choice changes, so Google Tag Manager decides which configured tags may load or fire. Consent-aware Google tags may send limited cookieless consent and measurement signals while optional storage remains denied.
Your analytics choice is asked across Snackle and stored in the snackle_tracking_consent cookie under consent version v1 for 180 days. When you open a creator page after allowing analytics, Snackle confirms that remembered choice against the current visit and creates a model-scoped consent record before enabling that page's provider tags or deliveries. A denied choice applies across Snackle in this browser. You can change or withdraw it at any time through the site-wide “Privacy choices” control. Withdrawal applies globally to future processing and does not affect already completed lawful processing.
Separately from seven-day visitor click records, Snackle keeps a minimal consent audit record containing the pseudonymous consent subject, optional model scope, notice version, decision and decision or revocation time for two years, then deletes it. A global choice has no model scope; a confirmed creator-page choice does. This evidence is retained only to demonstrate that optional tracking was enabled or withdrawn lawfully.
Creators are responsible for providing required notices, establishing an appropriate legal basis, obtaining any required consent, honoring opt-outs, and complying with the rules of each provider they enable. Browser controls may limit cookies, although doing so can affect authentication or attribution.
How and why we use personal data
We process account, Fanvue, content, visitor, attribution, and provider-delivery data to perform our contract with account holders: creating and securing accounts, publishing pages, connecting Fanvue, providing analytics, and delivering configured integrations.
We also process data where necessary for our legitimate interests in protecting Snackle, preventing fraud and abuse, supporting users, measuring reliability, improving the service, enforcing our Terms, and establishing or defending legal claims. We balance those interests against the rights and expectations of affected people.
We process data to comply with legal obligations and requests from competent authorities. Where consent is the required legal basis, including for certain optional communications or tracking, consent can be withdrawn for future processing without affecting earlier lawful processing.
Sharing and service providers
We use Vercel for application hosting and Vercel Blob for media storage, Neon for database infrastructure, and Zoho for email delivery. These providers process data on our behalf as needed to operate Snackle.
We share relevant information with Fanvue to maintain the connection you authorize and with Meta, TikTok, Snapchat, Google Ads, Google Analytics 4, or a custom webhook only when a creator configures and enables that destination.
We may disclose limited information to professional advisers, insurers, auditors, or competent authorities where reasonably necessary or legally required, and to a successor involved in a merger, restructuring, financing, acquisition, or sale of the business, subject to appropriate confidentiality and privacy protections.
We do not sell personal data. We do not disclose Fanvue data to a marketing or analytics provider unless the creator has configured and enabled that provider for the relevant model or page.
Data retention
Visitor-level click and interaction records are aggregated into anonymous daily analytics and permanently deleted after seven days. Copied advertising click identifiers are cleared from fan-attribution records at the same seven-day boundary. Anonymous daily analytics may be retained for reporting.
Account, creator, Fanvue, attribution, conversion, provider-delivery, support, and communication records are retained while needed to provide the service and for reasonable periods afterward where necessary for reconciliation, security, fraud prevention, dispute resolution, accounting, enforcement, or legal obligations.
Deleted data may remain for a limited period in protected backups before those backups are overwritten. We do not restore deleted data to active systems except where required for disaster recovery, security, or legal compliance.
Your rights and deletion
Depending on applicable law, you may ask to access, correct, delete, restrict, or receive a portable copy of your personal data, object to certain processing, or withdraw consent. You may also opt out of optional marketing or performance-recap emails through the unsubscribe method in those messages.
Send a request to hello@snackle.fans. We may need to verify your identity and authority before acting. We complete verified deletion requests within 30 days, except where applicable law permits or requires us to retain limited information for longer.
You may lodge a complaint with the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, or with the privacy regulator where you live. We encourage you to contact us first so we can try to resolve your concern.
International transfers
Some service providers and connected platforms may process data outside the Netherlands or the European Economic Area. Where applicable law requires it, we use recognized safeguards such as an adequacy decision, standard contractual clauses, or another lawful transfer mechanism.
Security
Snackle uses HTTPS, server-side secret handling, encrypted storage for OAuth tokens and provider credentials, webhook signature verification, account-scoped access controls, and measures intended to limit unauthorized access.
No system can be guaranteed perfectly secure. If you believe you found a vulnerability or unauthorized access, contact us immediately.
Age requirement
Snackle account services are intended only for Fanvue creators, agencies, and authorized staff who are 18 or older. We do not knowingly permit a person under 18 to create or operate a Snackle account.
Public pages may link to age-restricted third-party destinations. Visitors must comply with the age rules and terms of the destination they choose to visit.
Changes to this policy
We may update this policy as Snackle changes or legal requirements develop. We will update the date shown on the page and provide reasonable additional notice of material changes where required.
Contact
For privacy questions or rights requests, email hello@snackle.fans.
Da Aventura, Westblaak 7, Rotterdam, The Netherlands, KvK 94090904.