Legal
Privacy Policy
Effective April 22, 2026
1. Who we are
StackPass is a product of Prosimian Labs LLC, a Delaware limited liability company. For the purposes of GDPR and similar laws, Prosimian Labs LLC is the “data controller” for information collected through the StackPass website and dashboard.
You can contact us anytime at hello@getstackpass.com for general questions or privacy@getstackpass.com for privacy-specific requests.
2. What we collect
We collect information in three categories, depending on how you interact with StackPass.
2.1 From creators (our customers)
- Account information: your name, email address, and any profile information you provide through Clerk (our authentication provider) when you sign up.
- Billing information: your payment method, billing address, and subscription status. Payment card numbers are handled by Stripe and are never stored on our servers.
- Stripe Connect data:when you authorize StackPass via Stripe Connect, we receive an access token that lets us read your connected Stripe account's customers and subscriptions. We read customer email addresses, subscription statuses, product and price identifiers, and cancellation timestamps. We do not receive full card numbers, CVVs, or other sensitive payment data.
- Discord data: the Discord server (guild) ID, server name, and role IDs you map through StackPass. The bot we install on your server has the minimum permissions needed to read roles and assign the role you configured.
- Product telemetry: the pages you visit in the StackPass dashboard, the actions you take, and diagnostic information (browser, OS, IP address) we use to debug issues.
2.2 From subscribers (your end-users)
When one of your paying subscribers clicks your StackPass invite link and authorizes Discord, we collect:
- Their Discord user ID and username.
- Their Discord-verified email address (so we can match them to a Stripe customer on your connected account).
- Their Stripe customer ID and subscription status, which we store so we know when to grant or revoke their Discord role.
We don't collect their card details, Substack reading history, or anything else outside what Discord and Stripe expose for this specific purpose.
2.3 From visitors to getstackpass.com
- Analytics: if you accept cookies, we use Google Analytics 4 to understand aggregate page views. IP addresses are anonymized. We do not combine analytics data with your account.
- Server logs: standard HTTP request logs (timestamp, IP, URL, user agent) kept for up to 30 days for security and debugging.
3. How we use your information
- Provide the service. Syncing roles, processing payments, detecting cancellations.
- Communicate with you.Account-related transactional emails (trial ending, payment receipts, limit warnings). You can't opt out of these while you have an active account.
- Improve the product. Aggregate usage patterns help us decide what to build next.
- Comply with the law. Tax, accounting, and occasional lawful-request compliance.
We never use your data or your subscribers' data to train AI models. We never sell your data. If this ever changes, we'll email you and give you a chance to opt out first.
4. Sub-processors
We rely on a small number of vetted services to operate StackPass. Each has signed data-processing terms with us, handles their own compliance, and is listed here so you know exactly where your data lives.
| Vendor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting, serverless functions, CDN | United States (with global edge) |
| Neon | PostgreSQL database | United States |
| Clerk | Authentication and session management | United States |
| Stripe | Payments, billing, Stripe Connect for reading creators' subscriber data | United States (global) |
| Discord | OAuth, bot API for role management | United States |
| Resend | Transactional email delivery | United States |
| Google Analytics (optional) | Aggregate site analytics (only with your consent) | United States |
If we add a new sub-processor, we'll update this list and notify current customers by email before they start processing personal data.
5. How long we keep data
- Account data: for as long as your account is active, plus 90 days after cancellation so we can reverse accidental deletions. After 90 days, we permanently delete your account record and anonymize any diagnostic logs.
- Subscriber records: deleted immediately when you remove a subscriber, when a subscriber cancels, or when you cancel your StackPass account (whichever comes first).
- Billing records: retained for 7 years to comply with U.S. tax law.
- Server logs: 30 days.
6. Your rights
Regardless of where you live, you can email privacy@getstackpass.com to:
- Access a copy of all the data we hold about you.
- Correct or update any of it.
- Delete your account and all associated personal data.
- Export your data in a portable format.
- Object to or restrict a specific kind of processing.
- Withdraw any consent you previously gave.
We'll respond within 30 days. We don't charge a fee unless requests are repetitive or excessive, and we'll tell you if that's the case before we do anything.
California residents
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), you additionally have the right to know the categories of personal information we've collected, the categories of sources, our purposes, and any third parties we've shared it with. StackPass does not sell or share personal information as defined by the CCPA/CPRA. If you'd like a formal confirmation, email the address above.
EU / UK residents
Our legal basis for processing your data is a combination of contract performance (to provide the service you signed up for), legitimate interests (to operate and improve the service), and consent (for optional analytics). You have the right to lodge a complaint with your local data protection authority if you believe we've mishandled your data.
7. Security
We use industry-standard protections: TLS 1.3 in transit, AES-256 encryption for OAuth access tokens at rest, short-lived session cookies, principle-of-least-privilege on the Discord bot permissions, and regular audits of our sub-processor list.
No system is perfect. If we ever discover a breach affecting your personal data, we'll notify you and the relevant authorities as required by applicable law — typically within 72 hours of confirming the incident.
8. Children
StackPass is not intended for anyone under 16. We don't knowingly collect data from children. If you believe a child has provided us information, email privacy@getstackpass.com and we'll delete it.
9. Changes to this policy
We'll update this page from time to time. Material changes will be announced via email to active creators at least 30 days before they take effect.
10. Contact
Prosimian Labs LLC
Attn: Privacy
30 N Gould St, Ste N
Sheridan, WY 82801
United States
Email: privacy@getstackpass.com