GUMMY
Legal
Effective 2 September 2026 · Last updated 2 September 2026
This Privacy Policy explains how Ultron Technology Limited ("Ultron", "Gummy", "we", "us", or "our"), an Ontario corporation, collects, uses, discloses, stores, and otherwise processes personal information when you use the Gummy website, mobile or web applications, and related services (together, the "Service"). It also explains the choices and rights available to you.
Gummy is a platform for discovering, joining, operating, and paying for recurring in-person clubs and events. People may use the Service as guests, members, attendees, creators, promoters, or club and event hosts ("Hosts").
This Policy applies to personal data processed by Gummy through the Service, including when you create an account, sign in with Google or another identity provider, join a club, subscribe to a membership, book or attend an event, communicate through the Service, become a Host, submit a report, contact support, or visit our websites.
This Policy does not govern a third-party website, venue, social network, payment service, or other service that has its own privacy policy. Hosts may also process attendee or member information for their own purposes as explained in Section 3.
At launch, transactional features are offered only in Canada (excluding Quebec), the United States (excluding Connecticut, Nevada, and Washington), Australia, New Zealand, Singapore, and the Hong Kong Special Administrative Region. The public marketing website may remain technically accessible elsewhere, but access does not mean that registration, hosting, bookings, payments, or other transactional features are offered there. This Policy still applies to personal information that Gummy receives from a visitor to either website.
Ultron Technology Limited, an Ontario corporation under corporation number 1000823664, is the organization responsible for personal information processed for the operation of Gummy and is the data controller where that term applies. Our registered office is 25 Royal Troon Crescent, Markham, Ontario, Canada.
Our Privacy Officer is Aosong Guo. He is also the designated contact for privacy matters in Canada, Singapore, Australia, New Zealand, Hong Kong, and the United States. Privacy questions, complaints, and rights requests should be sent to privacy@gummyfan.com or to our registered office.
Gummy does not currently direct or intentionally offer transactional features in Quebec, Connecticut, Nevada, Washington, Japan, Mexico, the European Economic Area ("EEA"), the United Kingdom, or any other market not listed in Section 1. We do not accept Hosts, events, bookings, subscriptions, or payments from an excluded market and do not direct local marketing there. Before enabling an excluded market, we will complete the additional legal, language, consent, transfer, representative, or consumer-health-data work required for that market and update this Policy where necessary.
Gummy controls personal data used to provide accounts, platform features, recommendations, safety systems, payments infrastructure, analytics, support, and compliance.
A Host may be a separate controller for personal data the Host receives or creates to organise its club, fulfil a membership benefit, run an event, communicate with attendees, comply with local legal obligations, or keep lawful operational records. This may include permitted registration answers, attendance information, messages sent to the Host, and Host-created member notes. A Host must use that information only for lawful club or event purposes, follow Gummy's data-use restrictions, and provide any additional point-of-collection notice required by law. Hosts may not use Gummy to request medical diagnoses, health records, reproductive or sexual-health information, biometric identifiers, precise personal location, government identifiers, account credentials, or other sensitive information unless Gummy has expressly enabled a compliant collection flow for that category and market. Questions about a Host’s independent practices should be directed to that Host. You may also contact Gummy if you need help identifying the relevant Host.
If you choose “Continue with Google,” Gummy uses Google OpenID Connect for authentication. For the current sign-in implementation, Gummy requests only the minimum scopes needed to create, link, and secure your account:
Depending on the information in your Google Account and the choices shown by Google, these scopes may provide your Google account identifier (the sub claim), email address, email-verification status, name, given and family name, profile image, and locale. Gummy also processes the ID token, authorization response, and limited technical metadata required to validate the sign-in and establish a secure Gummy session.
Gummy does not use Google Sign-In to access Gmail messages, Google Drive files, Google Calendar, Google Contacts, Google Photos, or your Google password. We do not take actions in your Google Account on your behalf.
We use Google user data only to:
We do not sell Google user data. We do not use or transfer it for targeted, personalized, or cross-context behavioural advertising, creditworthiness, lending, data-broker activities, surveillance, or training a general-purpose artificial intelligence model. We do not allow a person to read Google user data except when necessary to provide support you request, investigate security or abuse, comply with law, or use aggregated information for lawful internal operations.
Gummy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For sign-in-only access, Gummy stores the Google account identifier and the profile fields described above in your Gummy account record. Gummy does not ordinarily require or retain a long-lived Google refresh token for this feature. Authentication tokens that are temporarily processed are encrypted in transit, protected at rest where retained, and removed when no longer needed.
Google profile information may be shared with service providers that host or secure the Service and with other Gummy users only to the extent you make the corresponding Gummy profile field public. We do not disclose Google user data to advertisers or data brokers.
You can disconnect Google in Gummy under Settings → Account → Connected Accounts. You can also revoke Gummy’s access through your Google Account permissions page. Disconnecting Google stops future access from Google but does not by itself delete your Gummy account or information that you separately provided to Gummy. If Google is your only sign-in method, connect another sign-in method before disconnecting if you want to keep account access.
You may delete your Gummy account under Settings → Privacy & Safety → Delete Account or by emailing privacy@gummyfan.com. After the 30-day recovery period, we delete or de-identify Google-derived account data unless retention is required for security, fraud prevention, legal claims, financial records, or another legal obligation. We also revoke and delete any remaining Google access token when it is no longer needed, when you disconnect Google, or when your account is deleted.
If we later request additional Google scopes or use Google data for a materially different purpose, we will update this Policy and obtain any additional consent required before that new access or use begins.
Account and identity data: full name, display name, username, email address, telephone number, password hash, verification codes, profile photo, biography, preferred language, city, interests, and referral or invitation code.
Host onboarding and business data: club and business details, social-media links, identity or business verification status, tax information, payout account identifiers, and information needed to establish a Stripe connected account. Payment and identity-verification providers may collect some of this data directly.
Club, membership, and event data: clubs followed or joined; membership tier; subscription status; registrations, waitlists, confirmations, cancellations, refunds, check-ins, attendance, no-show status, ticket type, permitted non-sensitive event answers, and QR or booking identifiers.
Payment and transaction data: transaction amount, currency, payment status, refunds, chargebacks, payout status, limited card details such as brand and last four digits, and billing information. Full payment-card numbers are handled by our payment provider and are not stored by Gummy.
Content and communications: profile content, club and event descriptions, photos, videos, recaps, reviews, reactions, reports, appeals, group-chat and direct-message content, support requests, survey responses, and communications with Gummy or a Host.
Safety and compliance data: reports, evidence, blocked-user information, moderation decisions, account restrictions, suspected fraud, and information needed to resolve disputes or respond to law-enforcement requests.
Marketing preferences: newsletter choices, campaign responses, and opt-in or opt-out records.
Do not provide medical diagnoses, health records, reproductive or sexual-health information, biometric identifiers, precise personal location, government identifiers, account credentials, or other highly sensitive personal data through listings, registration questions, profiles, reviews, analytics fields, or chat. If you need an accessibility or dietary accommodation, use the limited contact method identified for that event and provide only what is necessary. Gummy will not use such an accommodation message for advertising, recommendations, or analytics. A Host must not require sensitive information unless Gummy has expressly enabled a separate lawful notice and consent flow.
Device and network data: IP address, device type, operating system, browser, app version, language, time zone, pseudonymous device or browser identifiers where permitted, and network or crash information. Gummy does not use advertising identifiers for cross-context behavioural advertising.
Usage data: pages and features viewed, searches, clicks, referral source, permitted UTM parameters, session times, sign-in activity, event and club interactions, conversion steps, and communications delivery or engagement. We configure analytics so that URLs, query strings, event properties, and user properties do not intentionally contain names, email addresses, message content, payment details, event answers, or sensitive information.
Approximate location: city or region inferred from IP address. Gummy does not collect device GPS or other precise personal location at launch. Event venue addresses describe the event, not a user's live location.
Cookie and similar-technology data: identifiers and preferences stored through cookies, SDKs, pixels, local storage, and similar technologies as described in Section 13.
Security and diagnostics data: login attempts, session identifiers, authentication events, device and IP risk signals, error messages, stack traces, app state immediately associated with an error, and records used to detect spam, fraud, abuse, unauthorized access, or technical failures. We configure diagnostic tools not to capture message bodies, form fields, payment details, or session replay.
Identity providers: Google, Apple, or another provider sends the account information you authorize.
Payment and verification providers: payment status, connected-account status, fraud signals, dispute data, and limited identity-verification results.
Hosts and users: registration or attendance information, invitations, photos, messages, reviews, reports, member notes, or other content involving you.
Connected services: data you choose to import or share when you connect a social-media, calendar, messaging, or other integration. We request separate authorization where required.
Public and professional sources: publicly available social profiles, business records, sanctions lists, or other information used for Host verification, fraud prevention, or compliance where lawful.
Under PIPEDA and other applicable Canadian privacy laws, we collect, use, and disclose personal information for purposes that a reasonable person would consider appropriate, with valid consent unless the law permits or requires processing without consent. The form of consent may vary with the sensitivity of the information and your reasonable expectations. Where another applicable law requires us to identify a specific legal basis, we rely on the bases below. The same processing purposes describe how we use personal information in Canada and other locations.
| Purpose | Typical data | Legal basis where required |
|---|---|---|
| Create, authenticate, and manage accounts, including Google Sign-In | Account, identity, authentication, device, and security data | Contract; legitimate interests in secure account administration |
| Provide clubs, events, memberships, bookings, waitlists, check-in, recaps, chat, and support | Profile, event, membership, content, communications, and transaction data | Contract; steps requested before a contract |
| Process payments, refunds, payouts, chargebacks, and taxes | Transaction, billing, Host business, and verification data | Contract; legal obligation; legitimate interests in payment administration and fraud prevention |
| Personalize discovery and recommendations | City, interests, memberships, activity, and usage data | Legitimate interests in making the Service relevant; consent where required for device data or cookies |
| Operate Host CRM and analytics | Attendance, purchase history, membership status, referral source, engagement, and Host notes | Contract; legitimate interests of Gummy and Hosts in running clubs and understanding performance, balanced against member privacy |
| Send service messages and event communications | Contact, booking, subscription, and communications data | Contract; legal obligation where applicable; legitimate interests for non-marketing service updates |
| Send marketing | Contact, preferences, campaign, cookie, and engagement data | Consent where required; otherwise legitimate interests subject to your right to object |
| Keep the Service safe, prevent fraud, enforce rules, and resolve disputes | Security, device, transaction, report, content, and moderation data | Legitimate interests; legal obligation; establishment, exercise, or defence of legal claims |
| Improve and develop the Service, including aggregate analytics | Usage, feedback, crash, support, and de-identified data | Legitimate interests in improving reliability and features; consent for non-essential cookies where required |
| Provide AI-assisted drafting or summaries selected by a Host | Host prompts, event details, operational statistics, and content selected for the feature | Contract; legitimate interests in providing requested productivity features; consent if required for optional sensitive inputs |
| Comply with law and protect rights | Identity, transaction, content, safety, and request records | Legal obligation; public interest where applicable; legitimate interests; legal claims |
Our legitimate interests include operating and improving a secure club and event platform, preventing misuse, supporting Hosts and attendees, measuring performance, and communicating about similar services. We assess whether those interests are overridden by your rights and expectations. You may object as described in Section 15.
If we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal. If data is needed to enter into or perform a contract, failing to provide it may prevent us from creating an account, processing a booking, making a payout, or providing the relevant feature. Unless expressly stated, providing data is not a statutory requirement.
Your display name, username, profile photo, biography, Host pages, public clubs, public events, reviews, and public recaps may be visible to anyone, including visitors who are not signed in. Search engines may index public webpages.
Certain information is shared only within a club, membership tier, event, or chat. A Host may see member and attendee information needed to run the club or event, such as booking status, attendance history, membership tier, transaction status, answers to registration questions, and engagement with that Host’s clubs. Hosts may create private operational notes that are not shown to other members.
Other attendees may see limited profile information in member lists, group chats, photos, or recaps. Do not post contact details or sensitive information in public or group areas unless you want others to see it. Users who receive information through the Service must not scrape, sell, or misuse it.
Gummy may use city, language, interests, followed Hosts, club memberships, event activity, searches, popularity, availability, and similar signals to order or recommend content. Hosts may receive aggregated or member-level operational insights, such as attendance, retention, or referral information.
We do not currently use solely automated processing to make decisions that produce legal effects or similarly significant effects on you. Fraud or safety systems may flag activity for restriction or review, but material enforcement decisions are subject to appropriate human review where required by law. You may contact us to request review of a decision.
Gummy may offer tools that help a Host draft an event description, caption, recap, or operational suggestion. The Host decides whether to use and publish generated content. We may send the prompt and selected event or operational data to an AI service provider acting under contract. Users and Hosts must not submit personal messages, event answers, payment information, or sensitive personal information to an AI-assisted feature, and Gummy does not use those categories for model prompts at launch.
We do not use Google user data to train a general-purpose AI model. We do not permit an AI provider to use personal data from Gummy for its own advertising. Before a feature uses personal content for model training or another materially different purpose, we will provide a separate notice and obtain consent where required.
We disclose personal data only as needed for the purposes in this Policy:
Hosts, clubs, and users: as described in Sections 3 and 7, to fulfil memberships, bookings, events, communications, and community features.
Identity and integration providers: Google, Apple, and other providers when you choose their sign-in or integration service.
Payment and verification providers: Stripe and its affiliates for payments, Stripe Connect Express Host accounts, payouts, identity verification, fraud prevention, and disputes. Stripe may act as our processor for some activities and as an independent controller for its own legal, identity-verification, and fraud-prevention obligations.
Communications providers that deliver verification codes, confirmations, reminders, notices, and support messages on our behalf.
Chat provider: Stream/GetStream for in-product group chat and direct messaging.
Product analytics provider: PostHog, using PostHog Cloud US, for consent-based product analytics on www.gummyfan.com. PostHog receives pseudonymous usage events only after analytics consent and is contractually restricted to providing the service to Gummy.
Error-monitoring provider: Sentry for application error, crash, and performance diagnosis on www.gummyfan.com. Sentry does not set a Gummy cookie for this purpose. Gummy does not use Sentry Session Replay and configures the SDK not to send default personally identifiable information or user-entered content.
Marketing-site analytics and security provider: Cloudflare, including Cloudflare Web Analytics on about.gummyfan.com. The analytics beacon is configured without cookies, local-storage identifiers, or fingerprinting. Cloudflare may separately process limited network and security data to deliver and protect the website.
Other contracted hosting, security, maps, customer-support, and storage providers, each limited to the services they provide to us.
Contracted AI service providers for an AI-assisted feature that a user or Host chooses to use.
Professional advisers and authorities: lawyers, accountants, auditors, insurers, regulators, courts, law enforcement, and public authorities where reasonably necessary or legally required.
Corporate transactions: an actual or proposed buyer, investor, lender, successor, or adviser in a merger, financing, reorganization, insolvency, or sale of assets, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. If that practice changes, we will update this Policy and provide any legally required opt-out or consent mechanism before it begins.
Service providers may process personal data only under our instructions and contracts, except where a provider acts as an independent controller for its own legal obligations, such as certain payment, identity, or fraud-prevention activities.
Ultron is established in Ontario, Canada. We and our service providers may process personal information in Canada, the United States, Singapore, and other countries in which an identified provider operates. In particular, consented product-analytics events from www.gummyfan.com are sent from Canada or the user's location to PostHog Cloud US through us.i.posthog.com and are stored in the United States. Sentry, Stripe, Stream/GetStream, Cloudflare, hosting, communications, and support providers may also process information outside your country as described in their service configuration and contracts. Those countries may have privacy laws different from the laws where you live, and information in another country may be accessible to courts, law enforcement, national-security authorities, or regulators under that country’s laws.
Ultron remains accountable under applicable Canadian privacy law for personal information transferred to a service provider for processing. Before a provider processes personal information, we require written data-protection terms appropriate to the service, restrict use and onward disclosure, review material subprocessors and regions, apply access and security controls, and provide for return or deletion. We also assess whether the destination and contract provide protection comparable to the protection required in Canada and, where applicable, Australia, New Zealand, Singapore, or Hong Kong. Contact privacy@gummyfan.com for information about the providers, processing locations, or safeguards relevant to your information.
We keep personal data only for as long as reasonably necessary for the purpose collected, including providing the Service, meeting legal or accounting obligations, resolving disputes, and enforcing agreements. Actual periods may vary where a longer or shorter period is required by law or a dispute, safety concern, or valid deletion request applies.
| Data | Typical retention approach |
|---|---|
| Account and profile | While the account is active; deleted or de-identified after the 30-day account-recovery period, subject to the exceptions below |
| Google account link and Google-derived profile fields | Until disconnected or the Gummy account is deleted; remaining tokens revoked and deleted when no longer needed |
| Event group chat | Removed from active use approximately two hours after the event ends under the current product design; limited backups or safety records may remain for up to 90 days or longer if needed for an investigation |
| Direct messages and other user content | While the account or relevant feature is active, then deleted or de-identified according to account deletion and backup cycles, unless preservation is required for safety, disputes, or law |
| Booking, payment, payout, tax, and accounting records | Generally six years after the relevant transaction or relationship, or longer if required by tax, anti-fraud, anti-money-laundering, or legal-claims rules |
| Security, fraud, moderation, and dispute records | For the investigation and a reasonable period afterward, generally up to six years for material matters; shorter for routine logs |
| PostHog product-analytics events | Up to 24 months, then deleted or irreversibly aggregated; browser identifiers may persist for up to 365 days unless consent is withdrawn or browser storage is cleared earlier |
| Sentry error and diagnostic events | Normally up to 90 days, and shorter where configured; selected security or incident evidence may be retained longer only when necessary |
| Other routine technical logs | Normally up to 12 months, then aggregated or deleted, unless needed for security, fraud, a dispute, or law |
| Marketing data | Until you opt out or the campaign purpose ends; a minimal suppression record may be kept so we honour your opt-out |
| Backups | Rotated and overwritten on a defined schedule, ordinarily within 90 days, unless isolated for security, disaster recovery, or legal preservation |
When deletion is not possible immediately because data is stored in a backup, we isolate it from ordinary use until the backup is overwritten. We may retain de-identified or aggregated information that can no longer reasonably identify you.
The two Gummy websites use different technologies. On about.gummyfan.com, Cloudflare Web Analytics measures aggregate page views, referral sources, and website performance through a JavaScript beacon that is configured without cookies, local-storage identifiers, or fingerprinting. Because this configuration does not store or access an identifier on your device and Cloudflare states that it does not collect or use visitors' personal data for Web Analytics, the beacon operates by default. If its configuration or legal characterization changes, we will update the notice and obtain consent where required.
On www.gummyfan.com, strictly necessary technologies support sign-in, security, fraud prevention, load balancing, payment, language, and features you request. The product application also offers optional PostHog analytics. PostHog does not load and analytics events are not sent until you choose "Accept All" or otherwise consent to analytics. PostHog may then use a cookie and related local storage with a name in the pattern ph_*_posthog to maintain a pseudonymous distinct identifier, device and session state, feature-flag state, and consented analytics configuration. Gummy records the choice in the strictly necessary gummy_cookie_consent_v1 cookie. You can reject analytics or later withdraw consent through Cookie Settings; withdrawal stops future analytics collection and causes Gummy to clear PostHog cookies and local-storage identifiers where technically possible.
Sentry error monitoring is packaged with the product application and may operate by default to diagnose failures and protect the Service. It does not set a Gummy cookie or local-storage identifier for this purpose, and Gummy does not enable Sentry Session Replay. We minimize diagnostic fields and do not intentionally send names, email addresses, chat content, form values, payment details, or event answers to Sentry.
Gummy does not use advertising cookies, advertising pixels, cross-context behavioural advertising, or session replay on either website. Google and Stripe may set their own necessary or security cookies when you interact with their sign-in, checkout, verification, or hosted pages. The Cookie and Similar Technologies Notice identifies the domains, providers, purposes, activation rules, and typical durations in more detail.
We may send essential account, payment, subscription, safety, and event messages regardless of marketing preference because they are needed to provide the Service or comply with law.
We send promotional email, SMS, or push notifications only as permitted by applicable law. You can unsubscribe using the message link, reply STOP where supported, or change notification settings. Opting out of marketing does not stop essential service communications. We do not use Google user data for personalized advertising.
Depending on where you live, you may have the right to:
You can edit many profile and preference fields in Settings. For another request, email privacy@gummyfan.com from the address linked to your account and state the right, account email or username, and information involved. You do not need to create a new account. We may request information reasonably necessary to verify your identity and authority. An authorized agent may act where local law permits, subject to proof of authorization and any permitted direct confirmation with you.
We respond within the period required by applicable law, provide required information in an accessible format, explain a lawful refusal, and identify any available appeal or complaint route. We do not charge unless law permits a reasonable fee for a manifestly unfounded, excessive, or repetitive request. Rights may be limited where an exemption applies, records must be retained, or fulfilling the request would adversely affect another person's rights. If applicable U.S. state law gives you a right to appeal a denial, reply to the decision or email privacy@gummyfan.com with "Privacy Appeal" in the subject line.
This subsection is designed to provide the category-based transparency required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA/CPRA"), the California Online Privacy Protection Act, and other U.S. privacy laws, whether or not a particular law's business-size or processing threshold currently applies to Gummy. The table describes the categories the Service is designed to collect and disclose for business purposes and, once collected, the categories processed during the 12 months preceding the date of this Policy. We use the categories for the purposes in Section 6 and retain them under Section 12.
| U.S. category and examples | Sources | Business-purpose disclosures |
|---|---|---|
| Identifiers and customer records: name, username, email, telephone number, account ID, IP address, device identifier, and limited billing details | You; identity providers; devices; Hosts | Hosting, identity, communications, security, support, analytics, payment providers; Hosts when needed for a booking or membership |
| Commercial information: memberships, bookings, transaction history, refunds, referral attribution, and Host payouts | You; Hosts; Stripe; Service activity | Stripe; Hosts; support, accounting, fraud, and hosting providers |
| Internet or electronic activity: pages and features used, searches, interactions, referral source, session state, sign-in events, and consented PostHog events | Your browser or device; Gummy systems | PostHog after consent; Sentry for minimized diagnostics; hosting and security providers |
| Approximate geolocation and event location: city or region inferred from IP and venue addresses | Your device; you or a Host | Hosting, security, maps, analytics after consent, Hosts, and attendees as needed for the event |
| Audio, electronic, visual, or similar information and user content: profile image, photos, videos, messages, reviews, reports, and support communications | You; Hosts; other users | Intended audiences; Stream/GetStream; hosting, moderation, support, security, and professional advisers |
| Professional or business information: Host business identity, role, public social links, verification status, and payout status | Host; public sources; Stripe | Stripe; verification, support, compliance, and professional advisers |
| Inferences: interests and recommendations based on city, followed Hosts, memberships, event activity, and popularity; fraud or safety flags | Service activity; information above | Hosting and internal service providers; a Host receives only permitted operational insights |
| Sensitive personal information: account credentials and payment-account access information handled for authentication, payment, security, or fraud prevention | You; Google or another identity provider; Stripe | Identity, payment, hosting, and security providers solely for permitted operational purposes |
Gummy does not sell personal information for money or other valuable consideration and does not share it for cross-context behavioural advertising. Gummy does not use or disclose sensitive personal information to infer characteristics or for a purpose that would trigger a right to limit under California law. We do not offer a financial incentive or price or service difference in exchange for personal information. Referral rewards compensate qualifying referrals or transactions and are not payment for the referred person's personal information.
Some browsers send a "Do Not Track" signal. Because there is no uniform technical standard for that signal, Gummy does not respond to it in a standardized manner. Gummy does not currently sell personal information or use it for targeted or cross-context behavioural advertising. Where a legally valid opt-out preference signal such as Global Privacy Control applies, we treat it as an opt-out of any covered sale or targeted-advertising practice; no such covered practice is active at launch. The optional PostHog choice remains governed by the affirmative consent shown in Cookie Settings.
If an applicable U.S. law grants the right, you may request confirmation, access, correction, deletion, portability, a list of relevant third parties, or information about processing; opt out of sale, targeted advertising, or qualifying significant profiling; limit a covered use of sensitive personal information; use an authorized agent; appeal a denial; and exercise a right without discrimination. Gummy does not currently use solely automated processing to make a decision that produces legal or similarly significant effects. Collection screens for account creation, Host onboarding, bookings, and payments must link to this Policy and identify the relevant categories and purposes before collection.
In Canada, you may request access and correction, withdraw consent subject to legal or contractual restrictions and reasonable notice, challenge our compliance, and complain to the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/en/report-a-concern/. For a request governed by PIPEDA, we normally respond within 30 calendar days, subject to a permitted extension, and provide access at minimal or no cost.
Where the Australian Privacy Act applies, you may request access or correction and complain to our Privacy Officer. If we do not resolve the complaint, you may contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints. Nothing in this Policy limits a mandatory Australian consumer guarantee.
In New Zealand, you may request access to or correction of your personal information and complain to the Office of the Privacy Commissioner at https://www.privacy.org.nz/your-rights/how-to-complain/. Ultron has appointed the Privacy Officer named in Section 2 to oversee New Zealand privacy compliance. We use contractual safeguards for disclosures to overseas providers as required by Information Privacy Principle 12.
In Singapore, you may request access or correction and withdraw consent subject to legal and operational limits. The Privacy Officer named in Section 2 is Gummy's public data-protection contact. You may contact the Personal Data Protection Commission at https://www.pdpc.gov.sg/complaints-and-reviews after giving us an opportunity to respond. We require overseas recipients to provide a standard of protection comparable to the Singapore PDPA where that law applies.
In Hong Kong, the notice shown at or before a collection point and this Policy explain the purposes of collection, whether requested fields are required or optional, the consequences of not providing required data, the classes of transferees, and how to request access or correction. We do not use personal data for direct marketing without the consent required by Hong Kong law. You may contact the Office of the Privacy Commissioner for Personal Data at https://www.pcpd.org.hk/ after contacting our Privacy Officer.
To delete your account:
Open Gummy Settings.
Select Privacy & Safety.
Select Delete Account and complete the confirmation and security-verification steps.
You may instead email privacy@gummyfan.com from the address linked to your account. Account deletion enters a 30-day recovery period. During that period, the account is disabled from ordinary use. After the period ends, we delete or de-identify personal data subject to legal, accounting, fraud, safety, dispute, and backup exceptions described in Section 12.
Deleting a Host account may require us first to address active events, member communications, refunds, chargebacks, payouts, tax records, and legal obligations. Public content already incorporated into another user’s legitimate event history may be retained in de-identified or archived form where lawful.
We use technical and organizational safeguards designed for the nature and risk of the data, including encrypted transport, access controls, authentication protections, logging, vendor controls, and incident procedures. Where retained, sensitive authentication secrets are protected at rest. No system is perfectly secure, and we cannot guarantee that unauthorized access or loss will never occur.
If a breach of security safeguards creates a real risk of significant harm or another legal notification obligation, we will notify the Office of the Privacy Commissioner of Canada, affected individuals, and any other required authority within the time required by applicable law. We maintain breach records as required.
The Service is for adults aged 18 or older, is not directed to children, and does not knowingly create accounts for anyone under 18. Hosts and users who enter contracts, receive payouts, or buy or sell services must meet the age-of-majority and capacity requirements in the Terms of Service. If you believe a child has provided personal data contrary to this section, contact privacy@gummyfan.com so we can investigate, close the account, and delete information as appropriate.
We may update this Policy to reflect changes in the Service, law, providers, or data practices. We will post the updated version at this URL and change the “Last updated” date. If a change materially affects your rights or how we use personal data, we will provide additional notice and obtain consent where required. We will not use previously collected Google user data for a materially new purpose without the notice and consent required by Google policy and applicable law.
Ultron Technology Limited
Ontario corporation number: 1000823664
25 Royal Troon Crescent
Markham, Ontario
Canada
Privacy Officer: Aosong Guo
Email: privacy@gummyfan.com
Home · Become a Host · Join Us · Terms of Service · Cookie Notice