1. Scope and controller
Autono Labs, Inc., doing business as Foundable ("Foundable," "we," "us," or "our"), controls the personal information used to administer Foundable Creator Rewards (the "Program"). This Notice supplements Foundable's general Privacy Policy and applies to applicants, accepted Creators, Program submissions, attribution, verification, rights, and payments.
This Notice is presented at or before the Program application collects information. The Program is limited to natural persons age 18 or older who legally reside in the 50 United States or the District of Columbia.
2. Information we collect
- Application identity and contact information: legal or payout-verifiable name, display name, email, age-18-or-older attestation, U.S./D.C. residency attestation, application source, and optional source detail.
- Social-account information: TikTok and Instagram handles, profile URLs, account-control attestations and evidence, platform account IDs, and bounded provider profile, authorization, and connection records.
- Program content and analytics: public post URLs, platform post IDs, original publication times, submitted content and samples, content fingerprints, native analytics screenshots or recordings, qualified-view counts, traffic-source evidence, review decisions, and clearance materials.
- Agreement evidence: exact Program Terms, Rights Consent, and Privacy Notice versions, URLs, and SHA-256 hashes; exact checkbox labels and consent text; separate acceptance timestamps; application and account identities; source IP address; bounded browser user agent; and durable receipt delivery.
- Attribution and referral information: opaque Creator and link tokens, clicks, timestamps, platform source, UTMs, referral relationships, signup status, account-verification status, first-build or first-project status, qualification decisions, and aggregated progress.
- Payment, identity, and tax information: payment-provider IDs, recipient status, payment amount and currency, identity and residency status, tax-form status, payout and return events, accounting evidence, and anti-duplicate-payment records. Full bank-account and card numbers are handled by payment providers and are not stored by Foundable.
- Device, security, and operational information: request timestamps, IP address, bounded user agent, security and fraud signals, service logs, and audit events.
- Communications: application and agreement receipts, acceptance or decline notices, support requests, information requests, appeals, decisions, license notices, and payment communications.
Sources include you, your public posts and platform analytics, your device, social-account and payment providers you authorize, Foundable's product and attribution systems, and public platform information needed to administer the Program.
Please do not provide passwords, MFA codes, recovery codes, unnecessary government identifiers, precise geolocation, biometric templates, health information, or other information the Program does not request.
3. Why we use information
Foundable uses Program information to:
- Receive, authenticate, verify, and review applications.
- Confirm age and geography eligibility, account control, and Program standing.
- Provide the Creator portal, Program Requirements, assets, attribution links, referral links, and support.
- Validate URLs, publication times, cross-post groups, content eligibility, qualified organic views, signups, referrals, and exact measurement windows.
- Detect duplicate participation, artificial activity, abuse, account compromise, and fraud.
- Conduct human review, respond to appeals, and document decisions.
- Administer, track, and end organic and paid-media licenses.
- Make, reconcile, reverse, recover, and document payments and satisfy tax obligations.
- Send application, agreement, review, security, license, and payment communications.
- Secure, debug, audit, and improve the Program.
- Enforce the Program Agreement, protect legal rights, and comply with law.
Collection, use, disclosure, and retention are limited to what is reasonably necessary and proportionate for these disclosed purposes or a compatible purpose permitted by law.
5. Retention schedule
Foundable retains each category only for as long as reasonably necessary and proportionate for the purposes described in this Notice. The periods below are baseline recordkeeping periods or operational targets, not a promise that every copy is deleted on one exact day. Retention may continue while reasonably needed for an active application or participation, an unexpired license, payment, tax, or accounting, an appeal or support matter, security or fraud prevention, enforcement of the Program Agreement, establishing, exercising, or defending legal claims, a documented legal hold, or applicable law. When those purposes end, Foundable deletes, deidentifies, or restricts the information through its ordinary lifecycle.
| Information category | Retention period |
|---|---|
| Untouched application drafts with no agreement or operational evidence | Up to 30 days after creation. |
| Verified but declined or withdrawn application profile data | Generally at least 24 months after the final decision or appeal, and longer under the criteria above. |
| Minimal declined or withdrawn agreement and decision evidence | Generally at least 4 years after the final decision, and longer under the criteria above. |
| Accepted Creator profile and social-account information | During participation and generally at least 24 months after termination or last activity, and longer under the criteria above. |
| Social-provider credentials and live connection data | While connected and while needed to complete disconnect, cleanup, security, or provider reconciliation. |
| Raw analytics screenshots, recordings, and clearance files | Through final verification, appeal, and the applicable license, and generally at least 24 months afterward; longer under the criteria above. |
| Submitted content retained as an active marketing asset | Only during the applicable exact 12-month organic or exact 90-day paid-media term. |
| Nonpublic content copy, derived metrics, content fingerprint, eligibility, appeal, and license records | Generally at least 4 years after the later of the final decision, appeal, license expiration, or termination; longer under the criteria above. |
| Agreement document identities, exact acceptance labels, separate acceptance timestamps, source IP address, and bounded browser user agent | Generally at least 4 years after the later of the last submission, latest license expiration, final appeal, or Program termination. Direct identifiers may be removed or pseudonymized earlier when no longer needed. |
| Product-attribution and referral click or session identifiers | Through attribution, qualification, payment, and appeal and generally at least 13 months after the click; longer for reconciliation, duplicate prevention, fraud, or disputes. |
| Payment, tax, accounting, provider-reference, reversal, recovery, and anti-duplicate-payment records | At least 7 years after the calendar year of the final transaction, and longer when law, a dispute, or recovery requires. |
| Support and ordinary Program communications | Generally at least 3 years after closure. Payment, tax, or legal-dispute communications follow the applicable longer schedule. |
| Privacy-request records | At least 24 months after Foundable's response. |
| Core AWS service logs | Generally 30 days. |
| Hosted-application and web-application-firewall logs | Generally 14 days. |
| Deidentified and aggregated reporting | May be retained indefinitely when it cannot reasonably be linked to a person. |
Short-lived operational logs may contain an IP address or user agent for the shorter log periods above. The source IP address and bounded browser user agent retained as agreement evidence follow that agreement-evidence row, including its earlier-minimization and extension criteria.
Backups are not deleted record by record and expire under provider-configured rotation. Backup data is not used for ordinary operations. If restored for disaster recovery, applicable deletion or restriction instructions are reapplied.
A documented legal hold, tax duty, unresolved payment, security incident, fraud investigation, or dispute may extend retention for affected records until the purpose is resolved. Foundable will not publicly use content beyond its license merely because a private evidentiary copy remains.
6. Privacy rights and choices
Subject to applicable law, you may request access, correction, deletion, or a portable copy; object to or restrict certain processing; withdraw consent where processing relies on consent; and appeal a privacy decision.
California residents may also request the categories and specific pieces of information collected, request correction or deletion, opt out of a legally defined sale or sharing, limit certain uses of sensitive personal information, use an authorized agent, and exercise rights without discriminatory treatment.
A deletion request does not require Foundable to delete information it must or may retain for payment, tax, security, fraud prevention, contract, license, dispute, legal compliance, or another statutory purpose. Account deletion does not revoke an active organic or paid-media license or invalidate lawful prior processing.
To submit a request, email privacy@foundable.com. Foundable may verify your identity and authority before acting. Where the California Consumer Privacy Act applies, Foundable ordinarily responds within 45 days, subject to permitted extensions.
7. Age limit
The Program is limited to people age 18 or older. Foundable does not knowingly accept minors. If Foundable learns that a minor submitted Program information, Foundable will reject the application and delete the information unless a minimal record must be retained for security or legal compliance.
A Creator must obtain any legally required parent or guardian release before submitting content featuring a recognizable minor.
8. Security and automated review
Foundable uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of Program information. No storage or transmission system is perfectly secure.
Automated systems may flag possible duplicates, ineligible traffic, security threats, or inconsistencies for review. A human makes final application, eligibility, appeal, and payment decisions that materially affect a Creator.
9. Changes to this Notice
Foundable may update this Notice prospectively and will identify the current version and effective date. Material changes affecting existing Creators receive reasonable notice. A material change to Program economics, Creator rights, or license terms requires a new Program version and fresh acceptance before governing a new submission.
10. Contact
Privacy requests: privacy@foundable.com
Program support and appeals: support@foundable.com
Legal notices: legal@foundable.com
Postal address:
Autono Labs, Inc.
Attn: Privacy (Foundable Creator Rewards)
131 Continental Drive, Suite 305
Newark, DE 19713, USA