Privacy Policy

Last updated: August 18, 2026 · Compliant with: Colombia Law 1581/2012 · GDPR (EU) · CCPA (California)

Data Controller: HT Global Group LLC (operating as Mimame) · Wyoming, USA (EIN: [PENDING]) · privacy@mimame.me

1. Data we collect and why

Gifters (fans)

  • ·Email address — order confirmation and support. Legal basis: contract performance.
  • ·Name or nickname — gift dedication message. Legal basis: consent.
  • ·IP and device — fraud prevention. Legal basis: legitimate interest.
  • ·Payment data — processed directly by Stripe/Wompi. Mimame does not store card data.

Creators (beneficiaries)

  • ·Email and name — authentication and public profile. Legal basis: contract performance.
  • ·Bank account — payouts. Legal basis: contract performance.
  • ·Delivery address — receiving gifts. Legal basis: contract performance.
  • ·Profile photo and content — displayed publicly. Legal basis: consent.

2. Third-party transfers

We share data only with infrastructure providers necessary to operate: Stripe (USA) — payment processing; cloud database providers (USA) — secure data storage; transactional email providers (USA) — service communications; cloud web infrastructure providers (USA) — platform hosting. We do not sell or share data for advertising.

3. International transfers

Data processed outside Colombia and the EU is transferred under Standard Contractual Clauses (SCCs) pursuant to GDPR and Colombian Decree 1377/2013.

4. Retention

Transactions: 5 years (accounting obligation). Active account: during account lifetime. Closed account: deletion within 30 days except mandatory accounting records. Security logs (IP): 90 days.

5. Your rights (ARCO + GDPR)

You have the right to access, rectify, erase, port (GDPR), object to, and withdraw consent at any time. Exercise your rights by emailing privacy@mimame.me with subject "Data Rights Request". We respond within 10 business days. EU residents may also contact their national supervisory authority. Colombian residents may contact the SIC (Superintendencia de Industria y Comercio).

6. CCPA — California Resident Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.): (i) Right to know what personal information we collect, use, or disclose; (ii) Right to request deletion of your personal information; (iii) Right not to receive discriminatory treatment for exercising your privacy rights. Mimame does not sell personal data to third parties or use it for targeted advertising. To exercise your CCPA rights, email privacy@mimame.me with subject "CCPA Rights Request". We respond within 45 calendar days.

7. Security breach notification

In the event of a security breach affecting personal data: (i) We notify affected users within 72 hours of detection (GDPR Art. 33); (ii) Within 15 business days of detection, we notify Colombia's Superintendencia de Industria y Comercio (SIC) pursuant to Art. 17, Law 1581/2012 and SIC External Circular 002/2015. The SIC notification includes: breach description, categories of affected data, approximate number of affected individuals, technical remediation measures taken, and controller contact details.

8. Marketing communications

If you opted in to receive communications from Mimame at sign-up, we will send you platform updates, tips, and news. You may unsubscribe at any time by clicking "Unsubscribe" in any email or by emailing privacy@mimame.me. We will never share your email with third parties for advertising purposes.

9. Automatically collected data

When you use Mimame, we automatically collect: IP address and device/browser data (for security and fraud prevention), pages visited within the platform, and technical error logs. We do not collect behavioral analytics or use third-party tracking tools. We do not respond to Do Not Track (DNT) browser signals, as we do not engage in behavioral tracking.

10. Cookies

Mimame uses only essential session cookies for authentication. We do not use tracking cookies, advertising pixels, or third-party behavioral analytics. Since we do not use non-essential cookies, no additional consent is required.

11. Third-party links

Creator profiles may contain links to external social media or other third-party websites. Mimame is not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external sites you visit.

12. Technical security

TLS encryption in transit, bcrypt password hashing, Row-Level Security on database, least-privilege access, 2FA for administrators. Security breaches are handled pursuant to the procedure described in Section 7.

13. Minors

Mimame is not directed at users under 18. Report minor accounts to protection@mimame.me.

14. Contact

HT Global Group LLC (operating as Mimame) · Wyoming, USA · privacy@mimame.me · Response time: 10 business days.