1. Introduction
Phil Russell and Streamwalkers Corporation ("we," "us," or "our") respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Phil Russell Portfolio Platform ("Platform").
This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Data Controller
Phil Russell / Streamwalkers Corporation
San Antonio, Texas, United States
Data Protection Officer: privacy@streamwalkerscorp.com
3. Information We Collect
3.1. Information You Provide
- Account Information: Name, email address, password (hashed), phone number
- Profile Information: Display name, username, avatar, preferences
- Form Submissions: Contact forms, consultation requests, lead forms
- Business Data: Entity information, prospect data, property details you enter
- Communications: Messages, feedback, and support inquiries
3.2. Information Collected Automatically
- Usage Data: Pages visited, features used, timestamps, interaction patterns
- Device Information: Browser type, operating system, device type, screen resolution
- IP Address: Used for security, analytics, and approximate geolocation
- Cookies and Similar Technologies: See our Cookie Policy for details
3.3. AI Interaction Data
- Prompts and Queries: Text you submit to AI features (Deep Research, Writing Studio, AI Agents, Business Consultant)
- AI Outputs: Generated content, analysis results, and recommendations
- AI interaction data may be used to improve service quality but is not shared with third parties for their own purposes
4. How We Use Your Information
- To provide and maintain the Platform
- To authenticate users and manage accounts
- To process transactions via Stripe
- To generate AI-powered content and analysis
- To send service-related communications (with CAN-SPAM compliance)
- To monitor and analyze usage patterns for improvement
- To detect, prevent, and address security issues
- To comply with legal obligations
5. Legal Basis for Processing (GDPR)
- Consent: Cookie usage, marketing communications, AI data processing
- Contract Performance: Account creation, service delivery
- Legitimate Interest: Security, analytics, service improvement
- Legal Obligation: Tax compliance, fraud prevention
6. Third-Party Services and Data Sharing
We share data with the following categories of third-party service providers:
- Supabase — Database hosting, authentication, and file storage (SOC 2 Type II compliant)
- Stripe — Payment processing (PCI-DSS Level 1 compliant). We never store complete card numbers.
- Google AI (Gemini) — AI content generation. Prompts are sent to Google's API for processing.
- OpenAI — AI content generation. Prompts are sent to OpenAI's API for processing.
- Firecrawl — Web scraping for AI research features
- Twilio — SMS messaging services
- Resend — Transactional email delivery
We do not sell your personal information to third parties. We do not share your data with third parties for their own marketing purposes.
7. International Data Transfers
Your data may be transferred to and processed in the United States. Where required by GDPR, we use Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
8. Data Retention
We retain personal data for as long as your account is active or as needed to provide services. Upon account deletion, we will delete or anonymize your data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal disputes).
9. Your Rights
9.1. GDPR Rights (EU/EEA Users)
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request restricted processing of your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing
9.2. CCPA Rights (California Residents)
- Right to Know: Request information about data collection and sharing
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt out of the sale of personal information (we do not sell personal data)
- Right to Non-Discrimination: Equal service regardless of privacy choices
To exercise any of these rights, contact us at privacy@streamwalkerscorp.com. We will respond within 30 days (GDPR) or 45 days (CCPA).
10. Data Security
- Encryption at rest and in transit (TLS 1.3)
- Row-Level Security (RLS) policies on all database tables
- Role-based access controls (RBAC)
- Regular security audits and vulnerability assessments
- Secure authentication with hashed passwords
- Content Security Policy (CSP) headers
- Rate limiting on form submissions and API endpoints
11. Children's Privacy
The Platform is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has provided personal data, contact us for immediate removal.
12. Cookie Policy
We use cookies and similar technologies. For detailed information, please see our Cookie Policy.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notification. The "Effective Date" at the top indicates the latest revision.
14. Contact Us
Data Protection Officer
Phil Russell / Streamwalkers Corporation
Email: privacy@streamwalkerscorp.com
San Antonio, Texas, United States
For GDPR complaints, you also have the right to lodge a complaint with your local data protection supervisory authority.