Cookie & Tracking Policy
Version: Launch Suite vL1 (rev. 8.1) · Effective date: 29 September 2026
Document title: Cookie & Tracking Policy
Governing law: England & Wales (with local mandatory-rights savers — see Part 2) Availability: Steez's paid services are offered in the UK and US at launch (Terms of Service §2.1); this policy applies to all users wherever located, supplemented by the per-region rules in Part 2. Operator: Steelo Labs Ltd (England & Wales), company number 15553648, registered office Steelo Labs Ltd, 3 Harebell Close, Hamilton, Leicester, England, LE5 1UX Contact: privacy@steez.space
Related documents
This policy should be read alongside the following, all available at steez.space:
- Terms of Service
- Privacy Policy
- Acceptable Use & Community Guidelines
- Data Deletion Policy
- Creator Terms & Earnings Agreement
Part 1 — Introduction and scope
1.1 Who we are
- Steelo Labs Ltd ("Steelo", "we", "us", "our") is a company incorporated in England & Wales. We operate the Steez platform ("Steez", the "platform", the "service"), including:
- the website and web application at steez.space (and associated subdomains, including steelo.io); and
- the Steez mobile application for iOS and Android.
- Our registered office is Steelo Labs Ltd, 3 Harebell Close, Hamilton, Leicester, England, LE5 1UX, and our company number is 15553648.
- We are the data controller for the personal data processed through the cookies and tracking technologies described in this policy. For questions or to exercise your rights, contact us at privacy@steez.space. Our named privacy contact is reachable at that address; we have not appointed a formal Data Protection Officer at this time.
- EU/EEA users: Steez's paid services are not offered in the EU/EEA at launch (Terms of Service §2.1). If and when Steez is made available there, we will appoint a representative in the Union under Article 27 EU GDPR (a UK-established controller does not appoint an Article 27 representative for its own UK processing). The representative's identity and contact details will be published here once appointed; until then, any EU/EEA resident whose personal data we process can raise any data-protection matter with us directly at privacy@steez.space.
1.2 What this policy covers
- This policy explains:
- what cookies and similar storage or access technologies we use on steez.space and in the Steez app;
- why we use them;
- which ones require your consent (and where the consent rules differ by region);
- how you can control, withdraw, or adjust your choices at any time.
- "Cookie" in this policy means any technology that stores information on, or accesses information from, your device — including HTTP cookies, local storage, session storage, device identifiers, and mobile SDK tracking. In the UK these technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) as amended by the Data (Use and Access) Act 2025 (DUAA), which came into force on 5 February 2026. Equivalent rules apply in other regions — see Part 2.
- App SDKs: the Steez mobile app uses third-party software development kits (SDKs) that may access device information. These SDKs are subject to the same consent and exemption rules as web cookies and are disclosed in the tables in Parts 4 and 5 of this policy.
Part 2 — Legal framework and regional rules
What this section says: The same technologies are used everywhere, but the consent rules depend on where you are. We tell you the UK rule, the EU/EEA rule, and the position for the US and the rest of the world.
2.1 The consent rule (UK)
- Under PECR regulation 6 (as amended by DUAA), we must obtain your consent before storing or accessing information on your device unless one of the statutory exemptions in clause 12 applies. Consent must be:
- freely given — refusing must be as easy as accepting (you must be able to say "no" without losing access to the service);
- specific and informed — you must know what you are consenting to;
- unambiguous — a clear, affirmative action (no pre-ticked boxes); and
- withdrawable — you may change your mind at any time.
- Where we rely on consent, we collect it through the cookie consent manager on steez.space before the relevant non-essential technology is activated. If that manager is not live on a public web route, no non-essential web cookie or tracking technology requiring that consent is activated on that route. In the app, consent is collected through the in-app permissions and settings flows described in clauses 31–35.
2.2 Regional consent rules
What this section says: Steez's paid services are offered in the UK and US at launch. Wherever you access Steez from, local mandatory privacy and consent laws that you cannot waive apply to you in addition to, and prevail over, this policy where they give you stronger protection.
- The service's paid features are offered in the UK and US at launch (Terms of Service §2.1). We apply the following baseline approach and adapt it by region:
a. United Kingdom — PECR (as amended by DUAA) governs. We rely on the statutory exemptions in clause 12 where they apply and obtain consent for everything else (clause 8).
b. European Union / European Economic Area — the ePrivacy Directive (2002/58/EC) as implemented in each member state (the "PECR-equivalent" cookie/consent laws) governs, alongside the EU GDPR. Where local EU/EEA cookie law requires consent for storage or access that the UK DUAA exemptions would otherwise permit (including, depending on the member state, certain analytics), we will obtain consent in that region before setting or activating the technology. EU/EEA users also have the full rights described in Part 11 under the EU GDPR. Our content-moderation and notice-and-action obligations under the EU Digital Services Act are addressed in our Terms of Service and Acceptable Use & Community Guidelines, and we will appoint an EU legal representative for DSA purposes.
c. United States — where US state privacy laws (for example the California Consumer Privacy Act / California Privacy Rights Act and equivalent state statutes) apply, we honour the corresponding rights, including the right to opt out of any "sale" or "sharing" of personal information and of cross-context behavioural advertising. We do not currently use advertising or cross-context tracking technologies (see clause 14 and Parts 4–5); if that changes, US users will be offered the opt-out mechanisms those laws require before any such technology is activated.
d. Rest of world — local mandatory consumer and data-protection laws that cannot be excluded by agreement apply to you in addition to this policy and prevail over it to the extent they grant you stronger protection.
- Re-confirmation per jurisdiction: we do not rely on the DUAA first-party-statistics exemption for any SDK — first-party audience analytics is consent-gated and off by default (clause 12(d)). Crash diagnostics run as minimised fault-diagnostics under our legitimate interests and, where the configuration meets it, the PECR technical-fault exception (clause 12(e)); performance monitoring and video-quality telemetry are consent-gated (clause 12(d)). We obtain consent for audience analytics in every jurisdiction before activating it, and confirm the position for crash diagnostics in each non-UK jurisdiction before relying on any equivalent technical-fault basis.
2.3 Statutory exemptions we use (no consent required, UK baseline)
- The DUAA 2025 amended PECR to add exemptions for storage and access that is:
a. Strictly necessary for a service that the user has explicitly requested. We rely on this exemption for cookies and local storage that are essential to make the platform work — for example, keeping you logged in, processing a purchase, or preventing fraud. You cannot opt out of strictly necessary technologies without the service ceasing to function.
b. First-party statistics (first-party audience analytics only) — the DUAA added an exemption for analytics carried out solely by us to measure and understand audience and usage of our own service, where the resulting data is used only by us for that purpose and is not shared with any third party for that third party's own purposes. We do not currently rely on this exemption for any SDK. Firebase Analytics (audience analytics) is consent-gated: it is off by default and does not initialise until you opt in (clause 12(d) and Parts 4–5), and we do not rely on the first-party-statistics exemption for it. In any event the exemption would not extend to any use of analytics events linked to your Firebase UID to profile, segment, or target you (for example, segmentation for targeted push notifications under clause 27): that processing is consent-based.
Scope limit: We do not rely on the first-party-statistics exemption for Firebase Analytics (now consent-gated, clause 12(d)), Firebase Performance Monitor (performance telemetry) or Mux Data (video-quality telemetry). Firebase Crashlytics runs as minimised fault-diagnostics under our legitimate interests and, where its documented production configuration meets it, the PECR technical-fault detection exception (clause 12(e)); it is not used for advertising, audience measurement or product analytics. Performance Monitor and Mux Data are off by default and require your prior, affirmative opt-in consent — collected before the SDK initialises, everywhere, not only where local law requires it. No exemption here covers analytics used for advertising or cross-context profiling.
We do not rely on this exemption for any SDK; audience analytics is consent-gated and off by default (clause 12(d)). We provide clear information about the analytics in question and a free, easily accessible opt-out at any time. Opt-out controls for app analytics are provided in clause 29; disabling those controls does not affect strictly necessary technologies.
c. Appearance / functionality preferences — storing your display or language preferences so that the service looks and behaves the way you chose.
d. Technologies requiring your prior consent (no default-on, no legitimate-interests fallback) — first-party audience analytics (Firebase Analytics), performance monitoring (Performance Monitor), and video-quality telemetry (Mux Data) are not strictly necessary to deliver the service you requested. They therefore fall outside the clause 12(a)–(c) exemptions. We treat them as follows: each of these SDKs is off by default and is not initialised until you give prior, affirmative opt-in consent. On first launch of the Steez app, a non-dismissible consent screen asks you to choose, purpose by purpose, before any of these SDKs starts; the app does not proceed past that screen without your choice being recorded, and none of these SDKs runs until you opt in. You can grant or withdraw consent for each purpose at any time in Settings → Data & Privacy (clause 29). We do not rely on a separately stated legitimate-interests basis to run these SDKs without your consent.
e. Technical-fault detection (minimised crash diagnostics) — crash diagnostics (Firebase Crashlytics) run as minimised fault-diagnostics used solely to detect and remedy technical faults and protect security. Where the documented production configuration meets the PECR technical-fault detection exception, we rely on that exception for device storage/access, and on our legitimate interests under UK GDPR Article 6(1)(f) after a recorded balancing test (LIA), to run these diagnostics without prior consent. The configuration disables advertising IDs, Google Signals and analytics linking, minimises payload, and applies short retention; the data is not used for advertising, audience measurement, product analytics or model training. Identifiers are two-mode: if you have not opted in to crash diagnostics we attach only a pseudonymous, app-scoped installation identifier and never your account ID; if you have opted in, we may attach your account ID so a crash can be linked to your support request. If that configuration is not verified, crash diagnostics stay off until you consent. Crash diagnostics are on by default and you may object and switch them off at any time in Settings → Data & Privacy (clause 29) — an objection under Article 21, not a consent toggle. Why this is not simply switched off for everyone: a user who declines optional analytics and then hits a crash would otherwise suffer a fault we never see and never fix. Minimising what we collect is the price of running these diagnostics by default.
- For all other cookies and SDKs — including anything used for marketing, advertising, or cross-context tracking — we will always ask for your consent first, in every region where consent is required.
Part 3 — Cookie consent controls (steez.space web)
What this section says: When you first visit steez.space you will see a cookie banner where local law requires consent. You can accept, reject, or pick individual categories. You can change your mind any time.
3.1 How we obtain and record consent on the web
- Where consent is required for your region (clause 10) and a non-essential cookie or tracking technology is deployed on steez.space, the first time you visit the relevant page under that domain a cookie consent banner will appear before that technology is activated. The banner will:
- briefly explain the categories of cookies and their purposes;
- offer an "Accept all" button and an equally prominent "Reject all" button for non-essential cookies;
- offer a "Manage preferences" option to make granular choices by category;
- not set any non-essential cookie or activate any non-essential SDK until you make an affirmative choice.
- We do not rely on the first-party-statistics exemption, so first-party audience analytics is consent-gated and presented in the banner, off until you opt in, wherever a banner applies. Performance monitoring and video-quality telemetry are likewise not exempt (clause 12(d)) and are presented in the banner and off until you opt in wherever consent is required for them. Crash diagnostics run as minimised fault-diagnostics under our legitimate interests and the PECR technical-fault exception (clause 12(e)); you are given clear information and an objection route (clause 29). In EU/EEA member states whose law requires consent for analytics, the analytics category is also presented in the banner and is off until you opt in (clause 10(b)). The current public web app does not initialise non-essential analytics, diagnostics, performance, video-quality, marketing, advertising, or cross-context tracking technologies unless and until the required controls are live.
- Your choices are recorded in a first-party consent cookie (strictly necessary, because it prevents the banner from reappearing). That record is stored for up to 12 months, after which you will be asked to confirm your preferences again.
3.2 Granular categories on the web
- We organise web cookies into the following categories:
| Category | Consent required? | Examples |
|---|---|---|
| Strictly necessary | No (exempt) | Session authentication, Cloudflare security, CSRF protection, consent preference record |
| Audience analytics | Yes — consent (clause 12(d)); we do not rely on the first-party-statistics exemption. EU/EEA and outside UK/EU: consent per clauses 11 and 2 | Firebase Analytics web SDK (if deployed), Cloudflare Web Analytics |
| Performance monitoring | Yes (clause 12(d)) — runs only after prior opt-in consent, with no legitimate-interests fallback | Firebase Performance Monitor (if web SDK deployed) |
| Crash diagnostics | No prior consent where the minimised technical-fault configuration is verified (clause 12(e)) — legitimate interests + PECR technical-fault exception; otherwise off until consent; you may object | Error/crash diagnostics |
| Functionality / preferences | No (exempt) | UI theme/language preferences |
| Marketing & advertising | Yes, in every region | None currently — any future ad network will be listed here before deployment |
- We do not currently use any advertising cookies or cross-site tracking pixels on steez.space. If that changes, this policy will be updated and new consent (and, for US users, the applicable opt-out, clause 10(c)) will be sought before any such cookie is set.
3.3 Withdrawing or changing your web consent
- You may change your cookie preferences at any time by:
- clicking the "Cookie settings" link in the footer of any steez.space page where the consent manager is live; or
- clearing your browser cookies (this resets your preferences to "not yet chosen" and the consent banner will reappear where required).
- Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it.
- Most web browsers also let you block or delete cookies via their own settings. Blocking all cookies may mean some parts of steez.space do not function correctly.
Part 4 — Cookie inventory: steez.space (web)
What this section says: This table lists every cookie we currently set on steez.space, what it does, and how long it lasts.
- The following table describes the cookies currently set on steez.space:
4.1 Strictly necessary cookies
| Cookie name | Set by | Purpose | Duration | Consent? |
|---|---|---|---|---|
| `__cf_bm` | Cloudflare | Bot-management and DDoS protection — reads browser characteristics to distinguish humans from automated traffic. Strictly necessary for platform security. | Up to 30 minutes | No — strictly necessary |
| `_cfuvid` | Cloudflare | Cloudflare rate-limiting session cookie — ties together requests in a single session to enforce rate limits. Strictly necessary. | Session | No — strictly necessary |
| `cf_clearance` | Cloudflare | Cloudflare challenge clearance — set after a visitor passes a security challenge. Strictly necessary. | Up to 24 hours (per Cloudflare configuration) | No — strictly necessary |
| `__cflb` | Cloudflare | Cloudflare load-balancing — routes your session to the same back-end server. Strictly necessary. | Session | No — strictly necessary |
| `steez_session` or equivalent auth token | Steelo (first-party) | Maintains your authenticated session after sign-in. Without it you would be logged out on every page load. | Session / up to 30 days for "stay signed in" | No — strictly necessary |
| `cookie_consent_prefs` or equivalent | Steelo (first-party) | Stores your cookie consent choices so the banner is not shown on every visit. | 12 months | No — records your consent choice |
4.2 Audience analytics cookies (consent-gated)
| Cookie name | Set by | Purpose | Duration | Consent? |
|---|---|---|---|---|
| Firebase Analytics cookies (e.g. `_ga`-equivalent, Firebase measurement ID storage) | Google / Firebase (first-party configuration) | Counts page views, session duration, and in-app events (e.g. onboarding, checkout steps) to help us understand how the site is being used. Data is not shared with Google for its own advertising purposes (data-sharing off). | Up to 2 years (cookie lifetime; the analytics event data it enables is retained for up to 14 months — see Part 10) | Consent (clause 12(d)); off until you opt in. We do not rely on the first-party-statistics exemption. EU/EEA and outside UK/EU: consent per clauses 11 and 2 |
4.3 Marketing and advertising cookies
- We do not currently set any marketing or advertising cookies on steez.space. We will update this policy and obtain fresh consent (and offer US opt-outs, clause 10(c)) before any such cookie is deployed.
Part 5 — App SDK and local storage disclosure (Steez mobile app)
What this section says: Our app uses software SDKs that access your device. This section explains each one, what it does, and how you can control it.
- The Steez app (iOS and Android) uses the following SDKs that access or store information on your device. The UK consent and exemption rules (PECR as amended by DUAA) apply to these mobile-side technologies under regulation 6; equivalent regional rules apply per Part 2.
5.1 Strictly necessary SDKs
| SDK | Provider | Purpose | Data accessed | Consent? |
|---|---|---|---|---|
| Firebase Authentication | Google LLC (processor) | User identity and session management — stores a cryptographic authentication token on your device. Essential for login and account security. | Device-local auth token; your Firebase UID | No — strictly necessary |
| Firebase Cloud Messaging (FCM) | Google LLC (processor) | Delivers push notifications (e.g. new subscriber alerts, payout notifications). An FCM device token is generated and stored on your device and in our database. | FCM device token | No for delivery of notifications you have opted into; your consent to push notifications is collected via the OS permission prompt at app install or first use |
| Stripe iOS / Android SDK | Stripe Payments UK Ltd (UK) / Stripe Payments Europe Ltd (EEA) (processor) | Payment component included in the app's code. Released versions of the Steez app do not take payments (see clause 25), so it is not used to collect card details there; if it is ever used, card details are tokenised on-device and raw card data never reaches Steelo servers. | Payment card details (tokenised locally; raw data never sent to Steelo); device fingerprint used by Stripe's fraud system | No — strictly necessary for purchases |
- Payments: every purchase is made on Stripe's secure checkout page, reached from our website, whichever device you use; the Steez apps do not take payments. Stripe sets the cookies it needs to run that checkout securely and to prevent fraud, under its own cookie policy; they are strictly necessary for the payment you ask us to process and are never used for advertising or cross-context tracking.
Note — Stripe Connect independent-controller processing: For creators who onboard via Stripe Connect, Stripe acts as an independent data controller (not a processor under Steelo's instructions) for identity verification (KYC) data collected during account onboarding. Steelo does not have an Art. 28 data processing agreement governing that KYC processing, and this cookie/tracking policy does not cover it. Creators should refer to Stripe's Privacy Policy for how Stripe processes their identity data as controller.
5.2 Analytics, diagnostics, and performance SDKs
| SDK | Provider | Purpose | Data accessed | Duration | Basis / Consent? |
|---|---|---|---|---|---|
| Firebase Analytics | Google LLC (processor) | Collects first-party audience usage events (e.g. onboarding_started, first_portfolio_view, referral_redeemed — see app analytics service for full event list) to help us understand how the app is used and improve the product. With data-sharing off, Google does not use this data for its own purposes. | Firebase UID; device type/OS version; app version; event name + parameters; approximate country | Up to 14 months (Google's standard Analytics retention) | Consent (clause 12(d)). Off by default everywhere; the SDK does not initialise until you give prior opt-in consent at the first-run consent screen or in Settings → Data & Privacy (clause 29), withdrawable at any time. We do not rely on the DUAA first-party-statistics exemption, and we do not rely on legitimate interests to run this SDK without your consent. EU/EEA and outside UK/EU: consent per clauses 11 and 2 |
| Firebase Performance Monitor | Google LLC (processor) | Measures app startup times, network request latency, and screen rendering performance. Used to identify and fix technical issues. | Device hardware info; network type; app version; trace durations | 30 days rolling (Performance data auto-expires) | Not covered by the first-party-statistics exemption (clause 12(d)). Off by default everywhere; the SDK does not initialise until you give prior opt-in consent at the first-run consent screen or in Settings → Data & Privacy (clause 29), withdrawable at any time. We do not rely on legitimate interests to run this SDK without your consent. |
| Firebase Crashlytics | Google LLC (processor) | Captures crash reports and non-fatal errors as minimised fault-diagnostics. When your app crashes, a stack trace and device state snapshot are sent to help us diagnose and fix the bug. Also receives Mux environment key as a custom key for correlation purposes. | Crash stack trace; device model/OS version; app version/build; Mux environment key (as custom attribute) | 90 days (Crashlytics standard retention; short retention) | Legitimate interests (Art 6(1)(f)) + PECR technical-fault detection exception (clause 12(e)). Used solely to detect and remedy technical faults and protect security — not for advertising, audience measurement, product analytics or model training; advertising IDs, Google Signals and analytics linking are disabled and identifiers/payload minimised, supported by a recorded LIA. Where the documented production configuration meets the technical-fault exception it runs without prior consent; if that configuration is not verified, it stays off until you consent. You may object and switch it off in Settings → Data & Privacy (clause 29). |
| Firebase Remote Config | Google LLC (processor) | Allows us to push configuration values to the app (e.g. feature flags, minimum app version requirements) without requiring an app update. Accesses device type and Firebase UID to determine applicable configuration. | Firebase UID; device attributes (for configuration targeting) | Session / refreshed periodically | No — strictly necessary for app configuration. Justification: minimum-version enforcement (blocking incompatible app builds for security and service-continuity reasons) is a safety-critical function that the service cannot deliver without; this use case meets the PECR reg 6(3)(a) strictly-necessary test. Feature flags used solely for A/B testing or UX personalisation do not independently satisfy the strictly-necessary test — if Remote Config scope expands beyond minimum-version and safety-critical configuration, the basis should be reviewed and reclassified as appropriate (functionality/preferences or consent). |
| Mux Data SDK | Mux, Inc. (processor) | Measures video playback quality — buffering events, startup time, bitrate, and errors — to help us optimise video delivery. Receives your Firebase UID as a viewer identifier, plus device and connection metadata. | Firebase UID (as viewer_user_id); device name; device category; OS family/version; app version; connection type; subscription plan tier; view session ID | Per viewing session; Mux stores the pseudonymised view-level data for up to 100 days, then deletes it | Not covered by the first-party-statistics exemption (clause 12(d)). Mux Data is video-quality telemetry, not first-party audience analytics. Off by default everywhere; the SDK does not initialise, and no telemetry is sent, until you give prior opt-in consent at the first-run consent screen or in Settings → Data & Privacy (clause 29/31), withdrawable at any time. We do not rely on legitimate interests to run this SDK without your consent. |
5.3 Marketing and communications SDKs
- We do not currently use any advertising SDKs, ad-network SDKs, or cross-app tracking technologies in the Steez app. We will update this policy and seek consent (and offer US opt-outs, clause 10(c)) before any such technology is added.
- If you have given consent to receive marketing communications from us (collected by a separate consent mechanism at sign-up — see clause 38 below), we may use Firebase Analytics events to segment our user base for targeted push notifications. This processing uses only first-party data and Firebase UID — it does not involve third-party ad networks or cross-context behavioural advertising. This segmentation is profiling of an identified user and is therefore not covered by the first-party-statistics exemption (clause 12(b)): it relies on your separate marketing consent, and any storage of or access to information on your device for this purpose is consent-based. You can withdraw that consent at any time (clause 38), which stops the segmentation, without affecting the audience analytics you have separately consented to.
Part 6 — How to control and opt out
What this section says: You are in control. This section explains every way to change your tracking settings — on web and in the app.
6.1 Web controls
- Cookie banner: where a banner applies to your region and is live on the relevant web route, click "Cookie settings" in the steez.space footer to open the consent manager and change your choices for any category. Browser settings: all major browsers allow you to block, delete, or restrict cookies. Note that blocking strictly necessary cookies will prevent sign-in and checkout from working. Opt out of Firebase Analytics (web): where we rely on consent rather than the first-party-statistics exemption, you may withdraw consent via the cookie banner; you may also install the Google Analytics opt-out browser add-on for additional control.
6.2 App controls
- In-app settings — Data & Privacy: the Steez app provides a Settings → Data & Privacy screen with a separate on/off toggle for each of the following purposes. The consent-gated SDKs below are off by default and do not initialise until you give affirmative consent — first at the non-dismissible first-run consent screen (clause 12(d)), and thereafter adjustable at any time here. Crash diagnostics run under our legitimate interests and the PECR technical-fault exception (clause 12(e)) where the minimised configuration is verified; its toggle here lets you object and switch it off (and, where the configuration is not verified, it stays off until you consent). Each consent toggle reflects your actual consent state: on means consent is currently given and the SDK is active; off means consent is withdrawn (or was never given) and the SDK does not run.
- Audience analytics (Firebase Analytics — clause 12(d), Part 5.2) — consent-gated, off by default;
- Crash diagnostics (Firebase Crashlytics — clause 12(e), Part 5.2) — minimised fault-diagnostics under legitimate interests / technical-fault exception; objectable here;
- Performance monitoring (Firebase Performance Monitor — clause 12(d), Part 5.2) — consent-gated, off by default;
- Video analytics (Mux Data — clause 12(d), clause 31, Part 5.2) — consent-gated, off by default.
Push notification preferences (granular by notification type) are controlled separately in the app settings menu — see Part 7.
Turning any of these off means we cannot detect and fix crashes, performance problems, or video-quality issues affecting your device, and (for audience analytics) reduces our ability to understand product usage; it does not affect other app functions.
- OS-level permissions: you may control push notifications and (on iOS) app-tracking permissions through your device's operating system settings:
- iOS: Settings → Privacy & Security → Tracking (for cross-app tracking; currently not applicable — we do not use ATT) and Settings → Notifications → Steez
- Android: Settings → Apps → Steez → Notifications
- Mux Data SDK: Mux Data video-quality telemetry is off by default and is not relied on under the first-party-statistics exemption (clause 12(d)). The Mux Data SDK does not initialise, and no playback telemetry is sent, until you give consent at the first-run consent screen or switch on Video analytics in Settings → Data & Privacy (clause 29). If you do not consent, or you later withdraw consent, video playback itself is unaffected — you can still watch videos on Steez — but no Mux Data telemetry is collected for your account. If you have concerns about this data, contact us at privacy@steez.space.
- US users: in addition to the controls above, if a US state privacy law applies to you, you may exercise the rights described in clause 10(c), including opting out of any "sale" or "sharing" and of cross-context behavioural advertising, by contacting privacy@steez.space. As noted, we do not currently use any such technologies.
Part 7 — Push notification consent and marketing communications
What this section says: Push notifications and marketing emails are separate from cookie consent — we explain the rules for each here.
- Push notifications are governed by PECR regulation 22 (and equivalent regional rules) and the UK/EU GDPR in addition to the consent rules in Part 2. The following rules apply:
- Transactional push notifications (e.g. "your payout has been processed", "someone subscribed to your page", "a Steez you bought is now available") do not require separate marketing consent. They are sent under the contractual performance basis and are necessary to deliver the service you signed up for. You may still opt out via your device OS settings (see clause 30).
- Marketing push notifications (e.g. promotional offers, news about new features, re-engagement messages) require your prior consent. We collect this consent separately from cookie consent — via an in-app prompt or a checkbox at sign-up. Pre-ticked boxes are never used. If you do not consent to marketing communications, you will still receive transactional notifications.
- Withdrawing marketing consent: you may withdraw consent at any time via:
- in-app settings (notification preferences); or
- clicking "unsubscribe" in any marketing email; or
- contacting privacy@steez.space.
- Withdrawing consent does not affect any marketing communications sent before withdrawal.
- Soft opt-in (purchasers only): where you have made a purchase on Steez, we may contact you about similar products and services from Steelo Labs using the soft opt-in permitted by PECR regulation 22(3) (and equivalent regional rules), provided you were given a clear opportunity to opt out when we collected your contact details and in every subsequent message.
Part 8 — Third-party processors and international transfers
What this section says: Our tracking technologies send some data to US-based companies. We explain the legal safeguards here.
- The following third parties operate the cookies and SDKs described in this policy. Each is a data processor acting on our instructions under a data processing agreement (Art 28 UK/EU GDPR) except where noted:
| Provider | Entity | Country | Transfer mechanism | Data processing agreement |
|---|---|---|---|---|
| Google LLC / Firebase | Google LLC | USA | UK Extension to EU–US Data Privacy Framework (DPF); EU–US DPF for EU/EEA transfers — verify active status at dataprivacyframework.gov | Google Cloud DPA / Firebase Terms; SCCs / IDTA Addendum fallback |
| Cloudflare, Inc. | Cloudflare, Inc. | USA | UK Extension to EU–US DPF; EU–US DPF | Cloudflare DPA |
| Stripe | Stripe Payments UK Ltd (UK payments); Stripe Payments Europe Ltd (EEA payments); Stripe, Inc. (Connect KYC) | UK / Ireland / USA | UK Extension to EU–US DPF; EU–US DPF (Stripe, Inc.) | Stripe DTA with UK Addendum |
| Mux, Inc. | Mux, Inc. | USA | UK Extension to EU–US DPF; EU–US DPF | Mux DPA |
| Microsoft Corporation | Microsoft Ireland Operations Ltd (EU/UK contracting entity) | USA / Ireland | UK Extension to EU–US Data Privacy Framework (DPF); EU–US DPF | Microsoft Products and Services DPA |
- We verify DPF active status for all US processors at least annually. If a processor loses DPF certification, we will implement SCCs / IDTA / UK Addendum as a fallback before continued transfer. For EU/EEA users, transfers to the US rely on the EU–US DPF and/or EU Standard Contractual Clauses.
- All primary data (Firestore database, Firebase Auth, Cloud Functions) is processed in the europe-west1 (Belgium) Google Cloud region. Some Firebase services (Authentication, Analytics, logging, backups) are not necessarily confined to that region; the position is stated service-by-service in our internal processing matrix.
Part 9 — Data we collect through tracking technologies
- The tracking technologies described in this policy collect, or enable us to collect, the following categories of personal data:
| Data category | Source technology | Purpose | Lawful basis |
|---|---|---|---|
| Device identifiers (Firebase UID, FCM token) | Firebase Auth, FCM | Account management; push notifications | Contract performance |
| App usage events (screen views, feature interactions, onboarding steps) | Firebase Analytics | First-party audience analytics | Consent (Art 6(1)(a)) — clause 12(d); off by default and not initialised until you opt in. We do not rely on the DUAA first-party-statistics exemption (clause 12(b)) |
| Crash reports and error diagnostics (stack traces, device state) | Firebase Crashlytics | Detecting and remedying technical faults; security | No prior consent where the minimised technical-fault configuration is verified (clause 12(e)) — legitimate interests (Art 6(1)(f)) + the PECR technical-fault detection exception. On by default; you may object in Settings → Data & Privacy (clause 29). If that configuration is not verified, crash diagnostics stay off until you consent. Not the first-party-statistics exemption (clause 12(d)) |
| Performance telemetry (startup, latency, render times) | Firebase Performance Monitor | Technical issue detection | Consent (prior opt-in) — off by default; we do not rely on legitimate interests as a fallback. Not the first-party-statistics exemption (clause 12(d)) |
| Video playback telemetry (buffering, bitrate, playback errors) | Mux Data SDK | Video quality optimisation | Consent (prior opt-in) — off by default; we do not rely on legitimate interests as a fallback. Not the first-party-statistics exemption (clause 12(d)) |
| App configuration data | Firebase Remote Config | Feature management | Contract performance |
| Security and bot-mitigation data | Cloudflare | Platform security; DDoS protection | Legitimate interests |
| Session and authentication tokens | First-party cookies | Service delivery | Contract performance |
| Mosaic performance data (swipe/play/error counts, device model) | First-party Firestore analytics (_analytics/mosaic_perf/sessions) | Internal video-system diagnostics | Consent (Art 6(1)(a)) — off by default; gathered only after prior opt-in, retained for 90 days rolling, then deleted |
- For a full description of what personal data we collect and how we process it, including our retention schedule and your rights, see our Privacy Policy.
Part 10 — Retention
- Cookies and the data they generate are retained for the periods set out in the tables in Parts 4 and 5. As a general guide:
| Technology | Retention |
|---|---|
| Cloudflare security cookies | Session or up to 30 minutes |
| Authentication session tokens | Session / up to 30 days (if "stay signed in") |
| Consent preference record | 12 months |
| Firebase Analytics (audience analytics) | Up to 14 months (configurable in Firebase Console) |
| Firebase Performance | 30 days |
| Firebase Crashlytics | 90 days |
| Mux Data | Pseudonymised view-level data retained by Mux for up to 100 days, then deleted (Mux's standard Data retention period) |
| First-party mosaic telemetry (_analytics/mosaic_perf/sessions) | 90 days rolling — data older than 90 days is deleted. |
Part 11 — Your rights
- In addition to your control rights described in Part 6, you have the following rights under the UK GDPR (and, for EU/EEA users, the EU GDPR) in relation to personal data processed through the tracking technologies described in this policy:
- Access (Art 15): request a copy of the personal data we hold about you via tracking and analytics.
- Erasure (Art 17): request deletion of analytics and tracking data we hold about you, by contacting us at privacy@steez.space. Note that some data may be retained for longer under a legal obligation (see the Privacy Policy retention schedule).
- Restriction (Art 18): ask us to stop actively processing your data while a complaint is resolved.
- Object (Art 21): object to any processing we base on legitimate interests — including crash diagnostics, which run under our legitimate interests and the PECR technical-fault detection exception (clause 12(e)) rather than on your consent. Objection is the route for crash diagnostics: you can object and switch them off at any time in Settings → Data & Privacy (clause 29). Audience analytics, performance monitoring and video-quality telemetry run on your prior consent (clause 12(d)) — for those, the simpler route is withdrawing consent (below), which stops the processing without any balancing test.
- Withdraw consent (Art 7(3)): where processing is based on consent, withdraw it at any time — see Part 6.
- Portability (Art 20): where processing is by automated means on a consent or contract basis, you may request your data in a structured, machine-readable format by contacting us.
- EU/EEA users have these rights under the EU GDPR and may also lodge a complaint with their local supervisory authority. US users in states with applicable privacy laws have the rights described in clause 10(c). All users benefit from any local mandatory data-protection or consumer rights that cannot be excluded by agreement (clause 10(d)).
- To exercise any of these rights, contact us at privacy@steez.space or write to us at Steelo Labs Ltd, 3 Harebell Close, Hamilton, Leicester, England, LE5 1UX (company number 15553648). We will respond within one calendar month. We may ask you to verify your identity before processing a request.
- Since 19 June 2026, UK users also have the right to make a formal data protection complaint to us under DPA 2018 s.164A (inserted by DUAA 2025). We will acknowledge your complaint within 30 days and respond without undue delay.
- You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ICO):
- Online: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
EU/EEA users may complain to their national data protection authority.
Part 12 — Changes to this policy
- We will update this policy when we add new tracking technologies, change our consent approach, or when the law requires it (including changes required by a new jurisdiction as we add new markets).
- Material changes — for example, adding a new category of tracking technology or changing from an exemption to consent — will be notified to registered users by email and/or an in-app notification at least 14 days before they take effect. We will also update the version number and effective date in the header.
- For minor or clarificatory changes (for example, updating a cookie duration or correcting a name), we will update the policy without prior notice.
- The current version of this policy is always available at steez.space/cookies.
Part 13 — Contact us
- If you have any questions about this policy or the tracking technologies we use:
- Email: privacy@steez.space
- Post: Steelo Labs Ltd, 3 Harebell Close, Hamilton, Leicester, England, LE5 1UX (company number 15553648)
- In-app: use the Help & Support section of the Steez app settings
- EU/EEA — Article 27 representative: to be published once appointed