Privacy Policy
Last updated: September 2026
1. Who We Are and How to Contact Us
TribuShare is operated by SYLOE GROUP, SAS, registered in France (SIREN 898 633 409), with its registered office at 1 rue Albert Camus, 95130 Le Plessis-Bouchard, France. SYLOE GROUP, SAS is the data controller for personal data processed in connection with the operation of the TribuShare Service.
| Data Controller | SYLOE GROUP, SAS — 1 rue Albert Camus, 95130 Le Plessis-Bouchard, France |
| Privacy enquiries | privacy@tribushare.com |
| Data subject rights | privacy@tribushare.com — response within 30 days |
| Supervisory authority | CNIL — 3 place de Fontenoy, 75007 Paris — www.cnil.fr |
2. Scope and Application
This Privacy Policy applies to personal data collected and processed by SYLOE GROUP, SAS through the TribuShare platform, including the website (tribushare.com), web and mobile applications, APIs, and all related services. It applies to all Users: Viewers, Creators, and Partners.
TribuShare is the data controller for personal data of Viewers processed in connection with a purchase, being the seller of record of that purchase. Creators are controllers only for personal data TribuShare transfers to them and which they then use for their own purposes; where TribuShare processes personal data solely on a Creator's documented instructions, it acts as processor — governed by Data Processing Addendum.
TribuShare operates primarily within the European Union and is subject to GDPR (Regulation (EU) 2016/679). Where TribuShare processes data of individuals in other jurisdictions, TribuShare complies with applicable local data protection law to the extent required.
3. Personal Data We Collect
3.1 Data You Provide Directly
- Account registration: name, email address, password (hashed), country of residence, language preference
- Creator Account additional data: legal name or business name, tax identification number, payment account details (IBAN or equivalent), billing address
- Partner Account additional data: promotional channel information, website or social media URL
- Payment data: credit/debit card details and payment instrument data processed by Stripe (TribuShare does not store card numbers — Stripe acts as independent data controller for payment data)
- Communications: content of messages sent to TribuShare support, legal@tribushare.com, or privacy@tribushare.com
- UGC: reviews, comments, forum posts, and live event chat messages submitted through the Service
- Content metadata: for Creators, film titles, descriptions, cast/crew information, and territorial availability settings uploaded to the Service
3.2 Data Collected Automatically
- Usage data: pages visited, features used, content viewed, search queries, referral source, session duration
- Device and technical data: IP address, browser type and version, operating system, device identifiers, screen resolution
- Streaming data: playback events (start, pause, completion), buffering events, viewing duration, and quality metrics — used for service optimisation and Creator analytics
- Transaction data: purchase history, ticket purchases, donation amounts, referral conversions
- Log data: server access logs, error logs, security event logs — retained for a maximum of 6 months
- Cookies and tracking data: as described in Section 6
3.3 Data from Third Parties
- Payment confirmation and fraud signals from Stripe
- Social login data where you choose to authenticate via a third-party identity provider (Google, Apple, etc.) — limited to the data you authorise that provider to share
- Partner tracking data: click and conversion events generated through Partner Links, used for Commission attribution
4. How We Use Your Personal Data — Legal Bases
TribuShare processes personal data only where a valid legal basis under GDPR Art. 6 applies. Each processing activity has a single designated legal basis.
| Processing Activity | Legal Basis (GDPR Art. 6) | Retention Period | Primary Processor |
|---|---|---|---|
| Processing ActivityAccount creation and management | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) | Retention PeriodDuration of Account + 3 years | Primary ProcessorNeon DB (EU region) + application layer |
| Processing ActivityPayment processing and billing | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) | Retention PeriodDuration + 10 years (accounting) | Primary ProcessorStripe Inc. (DPF certified) |
| Processing ActivityContent delivery and streaming | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) | Retention PeriodDuration of access period | Primary ProcessorCloudflare CDN / TribuShare |
| Processing ActivityCreator Revenue Share calculation and disbursement | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) | Retention PeriodDuration + 10 years (accounting) | Primary ProcessorTribuShare / Stripe |
| Processing ActivityPartner Commission tracking and payment | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) | Retention PeriodDuration + 3 years | Primary ProcessorTribuShare Tracking System |
| Processing ActivityCustomer support and legal correspondence | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) | Retention Period3 years from last interaction | Primary ProcessorSupport CRM (EU-hosted) |
| Processing ActivityFraud detection and platform security | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) | Retention Period6 months (logs) / 3 years (fraud cases) | Primary ProcessorTribuShare / Cloudflare |
| Processing ActivityService analytics and performance optimisation | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) or Consent | Retention Period13 months maximum | Primary ProcessorPostHog |
| Processing ActivityTransactional email notifications | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) | Retention Period3 years | Primary ProcessorBrevo |
| Processing ActivityMarketing newsletter (opt-in) | Legal Basis (GDPR Art. 6)Consent (Art. 6.1.a) | Retention PeriodUntil consent withdrawn | Primary ProcessorBrevo |
| Processing ActivityTax and regulatory compliance | Legal Basis (GDPR Art. 6)Legal obligation (Art. 6.1.c) | Retention Period10 years | Primary ProcessorTribuShare accounting |
| Processing ActivityTechnical server and security logs | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) | Retention Period6 months | Primary ProcessorHosting provider (EU) |
| Processing ActivityCreator audience analytics (aggregate) | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) | Retention Period13 months | Primary ProcessorPostHog / TribuShare |
| Processing ActivityViewing status tracking (not started / in progress / completed) for withdrawal right determination | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) | Retention PeriodDuration of access period + 3 years (statute of limitations) | Primary ProcessorTribuShare application layer |
| Processing ActivityDRM and watermark attribution | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) | Retention PeriodDuration of content availability + 3 years | Primary ProcessorTribuShare |
| Processing ActivityMarketplace tax calculation and collection (VAT/GST/sales tax on Viewer purchases) | Legal Basis (GDPR Art. 6)Legal obligation (Art. 6.1.c) — EU OSS registration + applicable marketplace facilitator laws | Retention Period10 years (tax record retention requirement) | Primary ProcessorStripe Tax / TribuShare |
| Processing ActivityDAC7 platform operator reporting, Creator revenue reporting to tax authorities | Legal Basis (GDPR Art. 6)Legal obligation (Art. 6.1.c) — EU Directive 2021/514 (DAC7), applicable from threshold | Retention Period10 years | Primary ProcessorTribuShare accounting / SYLOE GROUP |
| Processing ActivityContent rating declaration storage (Creator-declared rating per film) | Legal Basis (GDPR Art. 6)Contract (Art. 6.1.b) — required for platform operation and legal compliance | Retention PeriodDuration of Content availability + 5 years (legal record) | Primary ProcessorTribuShare / Neon DB |
| Processing ActivityInternal AI content assessment score (platform-generated, not disclosed to Creator) | Legal Basis (GDPR Art. 6)Legitimate interests (Art. 6.1.f) — platform safety, AVMSD compliance, regulatory defensibility | Retention PeriodDuration of Content availability + 5 years | Primary ProcessorTribuShare (internal only — not shared with Creator or third parties) |
Legitimate interests pursued by TribuShare include: operating a secure and functional service; preventing fraud and abuse; improving the platform based on usage patterns; and enforcing our Terms of Service. Where legitimate interests are relied upon, TribuShare has conducted a balancing test confirming that these interests are not overridden by the data subjects' rights and freedoms.
5. Who We Share Your Data With
5.1 Sub-Processors (Service Providers)
TribuShare uses the following third-party service providers who process personal data on TribuShare's behalf. A Data Processing Agreement (DPA) is in place or in progress with each provider. DPA reference URLs are provided for transparency and can be verified independently.
| Provider | Purpose | Location | Transfer Basis | DPA URL |
|---|---|---|---|---|
| ProviderStripe, Inc. | PurposePayments & Stripe Connect | LocationUS (DPF certified) | Transfer BasisEU-US DPF + SCCs | DPA URLstripe.com/legal/dpa |
| ProviderNeon, Inc. | PurposePrimary PostgreSQL DB — all user & transaction data | LocationUS (EU region: eu-central-1) | Transfer BasisDPF + SCCs + UK Addendum + SOC 2 Type 2 | DPA URLneon.tech/partnerdpa |
| ProviderAmazon Web Services | PurposeVideo encoding (AWS Batch) | LocationGlobal (EU primary) | Transfer BasisSCCs | DPA URLaws.amazon.com/compliance/gdpr-center |
| ProviderCloudflare, Inc. | PurposeCDN, R2 storage, DDoS, security proxy, video delivery | LocationGlobal (EU primary) | Transfer BasisSCCs | DPA URLcloudflare.com/cloudflare-customer-dpa |
| ProviderBrevo (Sendinblue) | PurposeEmail: transactional & newsletter | LocationEU (France) | Transfer BasisEU — no transfer | DPA URLCGU Brevo — section DPA |
| ProviderPostHog (EU cloud) | PurposeProduct analytics | LocationEU (eu-central-1) | Transfer BasisEU — no transfer | DPA URLposthog.com/dpa |
| ProviderSentry (Functional Software, Inc.) | PurposeError monitoring and performance tracking | LocationUS (DPF certified) | Transfer BasisEU-US DPF + SCCs | DPA URLsentry.io/legal/dpa |
DPF = EU-US Data Privacy Framework. SCC = EU Standard Contractual Clauses (Commission Decision 2021/914). SOC 2 = independent annual security audit. TribuShare notifies users within 30 days of any sub-processor change. Full list: privacy@tribushare.com.
5.2 Creators, Access to Viewer Data
Creators have access to aggregated and anonymised audience analytics for their Content through the Creator Dashboard (e.g., total views, geographic distribution, engagement metrics). Creators do not have access to individually identifiable Viewer data (names, email addresses, payment details) unless the Viewer has explicitly consented to share their contact information with the Creator through the platform's opt-in mechanism.
Where a Viewer purchases access to a Creator's Content or registers for a Creator's live event, TribuShare may share the Viewer's email address with the Creator solely for the purpose of delivering that specific purchase or event — and only where this is necessary to fulfil the service. This processing is governed by the Creator's own privacy policy and the Creator's obligations as data controller under Data Processing Addendum.
Where a Viewer opts in to a Creator's marketing newsletter at account creation, TribuShare collects the email address as controller, and on opt-in confirmation transfers it to the Creator's designated email platform (Brevo, Mailchimp, or equivalent). From the point of transfer, the Creator becomes the sole data controller for that email address for marketing purposes. The Creator is solely responsible for operating their newsletter in compliance with applicable e-privacy and anti-spam law (including EU opt-in requirements).
5.3 Legal Disclosure
TribuShare may disclose personal data to law enforcement authorities, regulatory bodies, or courts where required by applicable law, court order, or regulatory instruction. TribuShare will endeavour to notify the affected User in advance where legally permitted. TribuShare will not disclose personal data in response to informal requests from law enforcement without a formal legal mandate.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of TribuShare's assets, personal data held by TribuShare may be transferred to the acquiring entity as part of the transaction, subject to equivalent data protection safeguards and notification to affected Users.
5.5 No Sale of Personal Data
TribuShare does not sell, rent, or trade personal data to third parties for their own marketing or commercial purposes. TribuShare does not allow third-party advertisers to target Users on the basis of their TribuShare activity.
6. Cookies and Tracking Technologies
6.1 What We Use
TribuShare uses cookies, local storage, and similar tracking technologies to operate the Service and, where you have consented, to analyse usage and improve the platform.
| Category | Can be disabled? | Purpose |
|---|---|---|
| CategoryStrictly necessary | Can be disabled?No — required for Service to function | PurposeAuthentication, session management, security, payment processing, streaming DRM |
| CategoryFunctional | Can be disabled?Yes — via consent banner | PurposeLanguage preference, playback settings, Creator dashboard state |
| CategoryAnalytics | Can be disabled?Yes — via consent banner | PurposeUsage statistics, performance monitoring, error tracking (PostHog where consented) |
| CategoryPartner tracking | Can be disabled?Yes — via consent banner (affects Commission attribution) | PurposeAttribution of referral traffic to Partner Links for Commission calculation |
6.2 Managing Your Preferences
At your first visit, a consent management banner allows you to accept or decline non-essential cookies. The banner provides equally prominent "Accept All" and "Reject All" options, in compliance with CNIL recommendations (2020, updated 2022). You may change your preferences at any time via the cookie settings link in the footer of the Service. Consent is valid for a maximum of 13 months, after which your preferences will be requested again. For detailed information about the specific cookies used on the Service, including their names, providers, and durations, please see our Cookie Policy.
7. Your Rights
If you are located in the European Union or European Economic Area, you benefit from the following rights under GDPR. TribuShare will respond to all valid requests within 30 days of receipt. Where a request is complex or numerous, the response period may be extended by a further 60 days with notice to you. All standard requests are free of charge.
| Right | What it means in practice |
|---|---|
| RightAccess (Art. 15) | What it means in practiceRequest a copy of all personal data TribuShare holds about you, including processing purposes and retention periods. |
| RightRectification (Art. 16) | What it means in practiceRequest correction of inaccurate personal data. Update most data directly through your Account settings. |
| RightErasure (Art. 17) | What it means in practiceRequest deletion of your personal data where: (i) it is no longer necessary for the purpose it was collected; (ii) you withdraw consent and no other basis applies; (iii) you object to processing and no overriding legitimate interest exists. Note: TribuShare may retain data where required by legal obligation (e.g., accounting records). |
| RightRestriction (Art. 18) | What it means in practiceRequest that TribuShare restrict processing of your data pending resolution of an objection or accuracy dispute. |
| RightPortability (Art. 20) | What it means in practiceReceive your personal data in a structured, commonly used, machine-readable format (CSV or JSON) for data processed by automated means on the basis of contract or consent. |
| RightObjection (Art. 21) | What it means in practiceObject to processing based on legitimate interests. TribuShare will cease processing unless it demonstrates compelling legitimate grounds that override your interests, rights, and freedoms. |
| RightWithdraw Consent (Art. 7.3) | What it means in practiceWithdraw consent for any processing based on consent (e.g., marketing emails, analytics cookies) at any time, without affecting the lawfulness of processing before withdrawal. |
| RightLodge a complaint | What it means in practiceLodge a complaint with the CNIL (France) or the supervisory authority of your EU country of residence, at any time, regardless of whether you have first raised the matter with TribuShare. |
8. International Data Transfers
TribuShare is based in France and processes data primarily within the European Union. Some sub-processors operate globally or in the United States. Where personal data is transferred outside the European Economic Area (EEA), TribuShare ensures that appropriate safeguards are in place:
- EU-US Data Privacy Framework (DPF) — for US-based processors certified under the DPF (including Stripe and Google)
- EU Standard Contractual Clauses (SCCs) — the 2021 Commission SCCs, incorporated into DPAs with processors in non-adequate countries
- Adequacy decisions — where the European Commission has determined that the destination country provides an adequate level of protection
TribuShare does not transfer personal data to countries without an applicable transfer mechanism. The sub-processor list in Section 5.1 identifies the transfer mechanism applicable to each provider. You may request a copy of the relevant SCCs by contacting privacy@tribushare.com.
9. Data Security
TribuShare implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
- Access controls: role-based access, least-privilege principles, multi-factor authentication for administrative access
- Regular automated backups with 90-day retention
- Security monitoring: intrusion detection, anomaly alerting, and regular vulnerability scanning
- Secure software development practices including code review and dependency auditing
- DRM protection for all streamed Content to prevent unauthorised copying
No system can guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, TribuShare will notify the CNIL within 72 hours of becoming aware of the breach, and will notify affected Users without undue delay where the risk to their rights is high.
10. Minors
The Service is intended for individuals aged 18 and over. TribuShare does not knowingly collect personal data from individuals under the age of 18. If TribuShare becomes aware that personal data has been collected from a minor without appropriate parental consent, TribuShare will delete such data promptly. If you believe that a minor's data has been collected, please contact privacy@tribushare.com immediately.
11. Changes to This Privacy Policy
TribuShare may update this Privacy Policy from time to time to reflect changes in the law, our data processing activities, or our services. Material changes will be notified by email and by a prominent notice on the Service at least 30 days before taking effect. The effective date is displayed at the top of this document.
