Privacy Policy

Version 2026-08-15, in effect August 15, 2026

Flair ("we," "our," or "us"), operated by Flair Inc., is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use https://flair.community and the Flair application. We process personal data primarily in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules, and the issuances of the National Privacy Commission (NPC). For users in other jurisdictions, we also seek to honor applicable standards such as the EU GDPR and the California CCPA/CPRA.

1. Information We Collect

We practice data minimization and collect what is needed to operate the platform and its features. Depending on how you use Flair, we may collect:

  • Account and authentication data: username, email address, date of birth (self-declared at signup and stored encrypted, used to confirm the 18+ age requirement), account creation and login timestamps, OTP and verification logs, and trusted-device information.

  • Sign-in provider data: if you use "Sign in with Google," we receive your Google account name, email address, and account identifier to create and secure your account.

  • Profile and reputation data: the professional profile information you provide, verification badges, endorsements, and connections.

  • Content and media: photos, video (where available), and other materials you upload, together with technical metadata generated in processing them.

  • Messages and interactions: direct messages and related data (such as message requests, reactions, edit history, and reports), bookings, and applications (including responses to organization-defined forms and consent snapshots).

  • Usage and engagement data: behavioral-analytics signals such as impressions, taps, dismissals, and dwell time on items shown to you, which we use to rank your feed, search results, and recommendations. This is on by default with a one-tap opt-out; see Section 3.

  • Organization data: organization details, membership, roles, and invitations.

  • Platform-mechanics data: waitlist position and assigned or redeemed referral codes.

  • Device and log data: IP address, user-agent and device information, device fingerprints used for session security, push-notification tokens, mobile crash-report data, and authentication and security audit logs.

  • Payment and transaction data: when you make or receive payments, we and our payment processor collect billing and transaction information (such as amounts, booking references, and payment status). Payments are processed by our payment processor (currently Stripe) and, for mobile in-app purchases, by Apple or Google; we do not store full payment card numbers. Talent and organizations who receive payouts provide identity-verification (KYC) information to our payment processor. Transaction records are retained for ten (10) years in pseudonymized form to meet BIR bookkeeping requirements and survive account deletion.

  • Identity-verification data (upcoming): if and when identity or entity certification launches, we may collect government-issued identification, a verification selfie, and related attestations through a third-party verification provider. This is sensitive personal information and will be handled with specific notice and consent.

2. How We Use Your Information

  • Provide the service: registration, authentication (OTP), profiles, messaging, bookings, applications, verification and endorsements, discovery, organization features, waitlist, and referrals.

  • Personalize and rank: we use behavioral-analytics signals (items shown, taps, dismissals, dwell time, and the surface where an interaction happened) to rank your feed, search results, and recommendations. We do not use the words of your search queries for this purpose. Paid boosts affect ranking, and boosted content is labelled "Boosted." You can turn this off at any time in Settings → Privacy; see Section 3.

  • Process payments: to facilitate payments, payouts, platform fees, and refunds, to enable identity verification (KYC) for payouts, and to detect and prevent payment fraud.

  • Communicate with you: transactional and security messages, service notifications, and (with consent where required) updates.

  • Security and integrity: preventing fraud, abuse, impersonation, and unauthorized access, and maintaining system health.

  • Improve the platform: understanding usage to maintain and enhance features, including through aggregated or de-identified analytics.

  • Legal and compliance: meeting legal obligations and enforcing our Terms.

3. Behavioral and Engagement Analytics

To personalize your feed and understand how the platform is used, Flair records how you interact with the content shown to you inside the app. This section explains, in specific terms, what that analytics records, what it deliberately does not record, how long we keep it, and how you can turn it off.

When you use the app, we log content-interaction events — in plain terms, what was shown to you and what you did with it:

  • which items ("cards") were shown to you, and whether you tapped, scrolled past, or dismissed them;

  • where in the app the interaction happened (for example, the home feed, search results, a profile, or an opportunity);

  • what the item was about — that is, whether it referred to an opportunity, a person, or an organization;

  • how long you viewed an item (dwell time); and

  • when the interaction happened, and the account associated with it.

This behavioral-analytics dataset is deliberately narrow. It does not include:

  • the content of your messages, other text you type, or the words of your search queries (we record that an interaction happened on the search surface, and which result you acted on, but not what you searched for);

  • your location or GPS data;

  • your IP address or device-tracking identifiers for this purpose (your IP address and device information may be processed separately for session security and fraud prevention, as described in Section 1 under "Device and log data" — that processing is not part of feed personalization and is governed by a different purpose and legal basis);

  • your age, gender, or other personal or demographic characteristics; and

  • anything shared with third parties. This dataset stays within Flair; it is not sold, rented, or disclosed to outside companies, including for advertising.

We use this data for two purposes only: to personalize and rank each member's feed, search results, and recommendations, and to understand how the product is being used so we can improve it. We do not use it for advertising, and we do not use it for automated decisions that produce legal or similarly significant effects on you.

High-volume "impression" data (the record of what was shown to you) is kept for 30 days. Other engagement events (such as taps, dismissals, and dwell time) are kept for up to 180 days. Aggregated and de-identified summary metrics, which are not tied to any individual, may be kept for longer. See Section 7 (Data Retention).

This analytics is on by default, and you can turn it off at any time with a one-tap switch in Settings → Privacy. If you turn it off, we stop collecting this data for feed personalization and delete your existing activity data. If you delete your account, this data is deleted with it. Turning it off does not disable the strictly necessary logging we keep for security and fraud prevention.

We process this behavioral-analytics data on the basis of our legitimate interests in operating, personalizing, and improving the platform, balanced against your rights and freedoms — which is why the data is limited to interaction signals, excludes sensitive and demographic data, and is subject to a one-tap opt-out. You may object to this processing at any time using the opt-out described above; doing so is an exercise of your right to object under the Data Privacy Act.

4. Legal Bases for Processing

We rely on one or more of the following bases under the Data Privacy Act (and equivalent GDPR bases where applicable):

  • Performance of a contract / requested service: to provide account, reservation, messaging, bookings, applications, and related features you request.

  • Legitimate interests / functions: to secure the platform, prevent fraud, operate our community, and personalize and improve the feed through behavioral analytics (subject to a one-tap opt-out), balanced against your rights.

  • Consent: for sensitive personal information such as identity-verification data, and for any feature we specifically offer on an opt-in basis; you may withdraw consent where processing is based on it.

  • Legal obligation: where processing is required by law.

5. Communications and Anti-Spam Commitment

We use our transactional email provider (currently Resend) to deliver authentication messages (OTPs, login verifications), critical security notifications, and a one-time "platform readiness" or "launch invitation" message so you can claim a reserved handle. We do not send unsolicited marketing emails and do not use purchased, rented, or third-party marketing lists. We manage deliverability and maintain an internal suppression list for hard bounces and complaints to stop further sends to affected addresses.

6. How We Share Information

We do not sell or rent your personal data. We share it only as needed to operate the platform:

  • Other users and organizations: information you choose to make visible (such as your profile) is shared with other users; messages, bookings, and applications are shared with the parties you direct them to.

  • Service providers (processors): trusted providers who process data on our behalf under confidentiality and data-processing terms, including:

    • DigitalOcean — cloud hosting and file/object storage;

    • Cloudflare — security, bot mitigation, and content delivery;

    • Firebase Cloud Messaging (Google) — push notifications;

    • Firebase Crashlytics (Google) — mobile crash reporting (device data);

    • Google Sign-In (Google) — authentication;

    • Resend — transactional email delivery;

    • Google Analytics — website analytics (pseudonymous);

    • Stripe — payment processing and payouts for bookings and web purchases (acts as a payment processor and, for some purposes such as fraud and compliance, an independent controller);

    • Apple and Google — in-app purchase processing for mobile subscriptions and digital items;

    • Persona / Sumsub (upcoming) — identity verification, if and when that feature launches.

  • Legal and protection: where required by law or to protect rights, safety, and the integrity of the platform.

7. International Data Transfers

Some of our service providers process data outside the Philippines. Where personal data is transferred across borders, we take steps consistent with the Data Privacy Act and applicable law to ensure a comparable level of protection, including contractual safeguards with our providers. By using the platform, you understand that your information may be processed in other countries where our providers operate.

8. Data Retention

We keep personal data only as long as needed for the purpose it was collected, then delete or de-identify it. Our current retention periods are:

DataRetention period
Account and profile dataWhile your account is active or until you request deletion.
Private message contentUp to 2 years.
Notification records30 days.
OTP and security logsShort rolling windows.
Trusted-device records90 days.
Account deletion30-day grace period, then permanent (hard) deletion.
Audit trail and financial / transaction records10 years (write-once storage; actor identifiers pseudonymized after 1 year), to meet BIR bookkeeping requirements.
Behavioral-analytics impression data (what was shown)30 days.
Other behavioral-analytics engagement events (taps, dismissals, dwell time)Up to 180 days.
Aggregated / de-identified analytics summariesRetained longer; not tied to an identifiable person.

9. Data Security

We use technical and organizational safeguards appropriate to the risk, including encryption in transit (TLS), token-based authentication (JWT) with device binding, field-level encryption of selected sensitive data, media sanitization, access controls, and monitoring for abuse and unauthorized access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please avoid sharing highly sensitive information through direct messages.

10. Your Rights

Subject to applicable law, you have rights over your personal data, which under the Philippine Data Privacy Act include the rights to be informed, to access, to object, to rectify (correct), to erasure or blocking, to data portability, to file a complaint with the National Privacy Commission, and to damages. Users in other jurisdictions may have comparable rights under the GDPR or CCPA/CPRA (including access, correction, deletion, portability, restriction, objection, and, for California residents, the right to opt out of "sale" or "sharing" — noting we do not sell personal data).

Many of these are self-serve. In Settings → Privacy you can export your data, delete your account, correct your information, manage or turn off behavioral analytics (which stops collection for personalization and deletes your existing activity data — an exercise of your right to object), and review the purposes for which we process your data. If you cannot use the in-app tools, contact [email protected]. We will respond within the timeframes required by law and may need to verify your identity first. You may also complain to the National Privacy Commission at [email protected] or through https://privacy.gov.ph.

11. Children's Privacy

Flair is not directed to children and is intended for users who are at least eighteen (18) years old. We do not knowingly collect personal data from children. If we learn that we have collected such data without appropriate consent, we will take steps to delete it. Where content or events feature minor performers, the uploading user or organizer is responsible for obtaining verifiable guardian consent and all required permits, and our child-safety rules in the Terms of Service apply.

12. Data Protection Officer and Breach Notification

You may contact our Data Protection Officer regarding this Policy or your personal data at [email protected]. In the event of a personal-data breach that meets the thresholds under the Data Privacy Act and NPC rules, we will notify the National Privacy Commission and affected data subjects as required by law.

13. Cookies and Tracking

We use cookies and similar technologies for authentication, security, session management, and analytics. For details and your choices, see our Cookie Policy.

14. Updates to This Policy

We may update this Privacy Policy as we introduce new features or as the law changes. We will update the "Last Updated" date and, for significant changes, provide reasonable notice. Continued use after changes take effect constitutes acceptance.

15. Contact Us

Email: [email protected]

Website: https://flair.community