Starlight Secure legal

Starlight Secure Privacy Policy

This Privacy Policy explains how Starlight Secure LLC collects, uses, discloses, protects, retains, and deletes personal data when you use the Starlight Secure compliance and workflow management platform.

Version 2026-08-09

1. Scope and Relationship to the Terms

1.1 This Privacy Policy applies to personal data processed by Starlight Secure LLC, a Colorado limited liability company, through the Starlight Secure software, features, tools, APIs, documentation, and services (collectively, the "Platform" and "Services").

1.2 This Privacy Policy is incorporated into the Starlight Secure Terms of Service. By creating an account, accessing, browsing, or otherwise using the Platform, You acknowledge the collection, use, and processing of Your data as described in this Privacy Policy and in accordance with applicable Data Protection Laws.

1.3 "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular identified or identifiable individual or household, as defined under applicable Data Protection Laws.

1.4 "Sensitive Personal Data" or "Sensitive Data" includes Personal Data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis (including STI Testing Records), sex life or sexual orientation, citizenship or citizenship status, genetic or biometric data used to uniquely identify an individual, and Personal Data collected from a known child, as defined under applicable Data Protection Laws.

1.5 "Biometric Data" means information generated from the automated measurement or analysis of an individual's unique biological or physical characteristics, including facial recognition templates, fingerprint mapping, or voiceprints, used for Identity Verification on the Platform. "STI Testing Records" means information, results, reports, or documentation related to sexually transmitted infection tests that are uploaded to, stored by, or retrieved through the Platform.

2. Personal Data We Process

2.1 Account information may include registration details, login credentials, contact information, subscription information, associated permissions, and information used to manage Your account.

2.2 User Content may include identification documents, contracts, STI Testing Records, photographs, Biometric Data, production schedules, communications, and other text, images, video, audio, documents, or data You submit, upload, transmit, or otherwise make available through the Platform.

2.3 Starlight Secure may process Sensitive Personal Data, including Biometric Data and STI Testing Records, when You choose or are required to use identity, age-verification, health-record, compliance, or related Platform workflows.

2.4 Starlight Secure maintains Audit Logs containing electronic records of user actions, system events, data access, and changes made within the Platform for compliance, security, and auditing purposes. We also retain records associated with electronically executed agreements as described in Section 8.

2.5 When You enable a Third-Party Integration, the Platform may transmit, retrieve, process, store, or display User Content, Personal Data, and other information from or through that service, including sensitive health or biometric data where applicable.

3. Processing Roles and Uses

3.1 For purposes of the CPA, Starlight Secure acts as a processor and the User acts as the controller of Personal Data. Each party will comply with its respective obligations under the CPA and other applicable Data Protection Laws.

3.2 Starlight Secure processes Personal Data, including Sensitive Personal Data, on documented instructions from the User to provide the Platform and Services and as described in the Terms and this Privacy Policy, unless otherwise required by applicable Law.

3.3 We use Personal Data to create and manage accounts, provide compliance and workflow features, perform identity and age verification, prevent fraud, maintain security, support electronic agreements and records, provide enabled communications and integrations, respond to support requests, and comply with applicable Law.

3.4 The User represents that they have obtained the explicit consents and authorizations required under the CPA to collect, use, and share Personal Data, including Sensitive Personal Data, with Starlight Secure and connected Third-Party Services.

3.5 By uploading, storing, or retrieving STI Testing Records, You explicitly consent to the collection, processing, and disclosure of such sensitive health data in accordance with the CPA and other applicable Data Protection Laws. You represent that You have obtained all necessary consents from any individual whose records are made available through Your account.

3.6 To the extent Starlight Secure processes Personal Data subject to the CPA on a User's behalf, Starlight Secure will: (a) ensure authorized persons are subject to a duty of confidentiality; (b) implement and maintain reasonable administrative, technical, and physical security measures appropriate to the risk; (c) assist the User in responding to consumer-rights requests and meeting obligations regarding data security and data-protection assessments; (d) notify the User without undue delay upon detecting a security breach involving Personal Data; (e) at the User's choice, delete or return Personal Data upon termination unless retention is required by Law; and (f) make available information necessary to demonstrate compliance and cooperate with reasonable audits and inspections.

3.7 To the extent Starlight Secure processes de-identified data, it will take reasonable measures to ensure the data cannot be associated with an individual, maintain and use the data in de-identified form, and contractually obligate recipients of the data to comply with the same provisions in accordance with the CPA.

4. When We Share Personal Data

4.1 The Platform may integrate with or enable access to third-party services, applications, or APIs, including identity verification providers, payment processors, healthcare electronic medical record systems, cloud storage providers, communications providers, and artificial intelligence services. By enabling or using a Third-Party Integration, You authorize and consent to the transmission, retrieval, processing, storage, and display of Your User Content, Personal Data, and other information by and through that service.

4.2 Users authorize Starlight Secure to engage subprocessors to process Personal Data. Starlight Secure will enter into written agreements with such subprocessors that impose data protection obligations no less restrictive than those in the Terms and remains liable for its subprocessors' compliance as provided by the Terms.

4.3 Starlight Secure may disclose Confidential Information and Personal Data to its representatives who have a need to know and are bound by appropriate confidentiality obligations. We may also disclose information to the extent required by applicable Law or a valid subpoena, court order, warrant, regulatory demand, or other lawful request. Where legally permitted, Starlight Secure may use reasonable efforts to notify the affected User before disclosure.

4.4 Starlight Secure may preserve records relevant to an active investigation, suspected prohibited conduct, legal hold, or lawful request, including after account termination or a deletion request. Information may be disclosed without notice when notice is prohibited by Law, would compromise an investigation, or when disclosure is necessary to address an emergency involving imminent danger of death, serious physical injury, child exploitation, human trafficking, or other severe illegal activity.

4.5 Third-Party Services have their own privacy practices, and Your use of a Third-Party Service is governed by Your agreement with that provider.

5. Mobile Information and SMS Communications

Mobile information will not be sold or shared with third parties for promotional or marketing purposes. SMS opt-in data and consent will not be shared with third parties for purposes unrelated to providing the SMS messaging service.

We may share information necessary to provide SMS communications with service providers that facilitate the delivery of those communications, including messaging platform providers, telecommunications carriers, and other vendors involved in delivering text messages.

Users may opt out of SMS communications at any time by replying STOP. Users may reply HELP for assistance.

6. Biometric Data Privacy and Consent

6.1 Starlight Secure collects, processes, and stores Biometric Data, including facial templates and liveness detection data, solely for Identity Verification, age verification, fraud prevention, and compliance with applicable Law, including 18 U.S.C. § 2257 and the CPA. Starlight Secure does not sell, lease, trade, or otherwise profit from Your Biometric Data.

6.2 By submitting Biometric Data through the Verification Process, You provide Your explicit, freely given, and informed consent to its collection, processing, storage, and disclosure as described in this Section. You may withdraw Your consent at any time by terminating Your account; however, withdrawal does not affect the lawfulness of processing carried out before withdrawal and may prevent Your access to the Platform.

6.3 Biometric Data will be retained only for as long as necessary to fulfill the purposes in Section 6.1 or as required by Law. Unless a longer retention period is legally mandated, Starlight Secure will permanently destroy or irreversibly de-identify Your Biometric Data within three (3) years of the termination of Your account or Your last successful Identity Verification using secure methods designed to render the data unreadable and non-reconstructable.

6.4 Starlight Secure may disclose Your Biometric Data to authorized third-party identity verification providers, such as Veriff, solely to perform the Verification Process. Starlight Secure contractually requires such providers to maintain strict confidentiality, implement equivalent security safeguards, and comply with applicable Data Protection Laws.

6.5 Starlight Secure implements and maintains reasonable administrative, technical, and physical security measures designed to protect Biometric Data from unauthorized access, disclosure, alteration, or destruction, including encryption in transit and at rest.

6.6 In accordance with the CPA, You may have the right to request access to, correction of, or deletion of Your Biometric Data, subject to legal exceptions. You may exercise these rights as described in Section 10.

7. Health Information and Healthcare Integrations

7.1 As of the effective date of this Privacy Policy, Starlight Secure does not operate as a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). Starlight Secure's status as a business associate under HIPAA depends on the nature of the services and integrations used by a User.

7.2 Where a User enables a Third-Party Integration involving the creation, receipt, transmission, or maintenance of protected health information (PHI), including integrations with healthcare providers, clinical laboratories, electronic medical record systems, or laboratory test ordering services, Starlight Secure and the User will enter into a Business Associate Agreement to the extent required by applicable Law before transmitting PHI through the Platform.

7.3 In the absence of an executed Business Associate Agreement, the User must not transmit PHI through the Platform and is responsible for ensuring compliance with HIPAA, the CPA, and other applicable Data Protection Laws in connection with healthcare-data integrations.

8. Data Retention and Deletion

8.1 Starlight Secure retains User Content, including Personal Data, Biometric Data, STI Testing Records, 2257-compliant documentation, Audit Logs, and electronically executed agreements, while Your account is active and for any additional period necessary to comply with applicable Law, resolve disputes, prevent fraud, and maintain security.

8.2 The specific retention periods established in the Terms are: (a) 2257-compliant documentation is retained for the full period required under 18 U.S.C. § 2257, 28 C.F.R. Part 75, and other applicable Law; (b) Biometric Data is retained and destroyed in accordance with Section 6; (c) STI Testing Records are retained for the duration of Your account plus three (3) years, unless a longer period is required by applicable Law; (d) Audit Logs are retained for a minimum of three (3) years after the recorded event; and (e) electronically executed agreements are retained for the duration of Your account plus seven (7) years to comply with applicable statutes of limitations.

8.3 Upon termination of Your account, Starlight Secure will, within a commercially reasonable period not to exceed sixty (60) days, delete or irreversibly de-identify Your User Content and Personal Data, subject to the exceptions in Section 8.5. Archival copies in backup systems will be securely destroyed according to standard backup rotation and destruction procedures.

8.4 You may request deletion of Your Personal Data under the CPA and other applicable Data Protection Laws. After identity verification, Starlight Secure will process requests within applicable statutory timeframes, subject to Section 8.5, and will provide written confirmation of deletion upon request.

8.5 Notwithstanding a deletion request or account termination, Starlight Secure may retain copies of User Content and Personal Data as necessary to: (a) comply with applicable federal, state, or local Law, including 18 U.S.C. § 2257; (b) respond to a valid lawful request or legal hold; (c) resolve ongoing or potential disputes, claims, or investigations; (d) enforce the Terms or investigate suspected prohibited conduct; or (e) maintain standard archival or backup systems, provided the data remains subject to applicable confidentiality and security obligations.

8.6 At the end of the applicable retention period, Starlight Secure will securely destroy or irreversibly de-identify User Content using industry-standard methods designed to render the data unreadable and non-reconstructable. Starlight Secure may retain, use, or disclose de-identified or aggregated data as permitted under the CPA and the Terms after deletion of Your Personal Data.

9. Confidentiality and Security

9.1 Starlight Secure will hold User Confidential Information in strict confidence, use it to provide the Platform and fulfill its obligations, and protect it with at least a reasonable degree of care. We will not disclose Confidential Information to a third party except as permitted by the Terms and this Privacy Policy.

9.2 Starlight Secure maintains reasonable administrative, technical, and physical safeguards, including encryption in transit and at rest, access controls, and regular testing, to protect the Platform, User Content, Personal Data, and Confidential Information.

9.3 In the event of a confirmed security breach compromising User Content or Personal Data, Starlight Secure will notify affected Users without undue delay and cooperate in mitigation in accordance with applicable Law, including the CPA and Colo. Rev. Stat. § 6-1-716.

9.4 You are responsible for maintaining the confidentiality of Your account credentials, implementing reasonable security measures for systems You use to access the Platform, and promptly notifying Starlight Secure of unauthorized account access or a security breach.

9.5 Upon account termination or a valid written request, Starlight Secure will return, destroy, or retain Confidential Information in accordance with Section 8 and applicable Law. Retained archival or backup copies remain subject to applicable confidentiality and security obligations.

10. Privacy Rights and Requests

10.1 Depending on applicable Law and subject to legal exceptions, You may have the right to request access to, correction of, deletion of, or a copy of Your Personal Data, including Biometric Data.

10.2 Registered Users can submit available export, correction, and deletion requests through the Data Collection settings. We may need to verify Your identity before processing a request.

10.3 You may also contact Starlight Secure about this Privacy Policy or a privacy request at support@starlight-secure.com.

11. Changes to This Privacy Policy

11.1 Starlight Secure may update this Privacy Policy from time to time. For material changes to data privacy or biometric-data provisions, Starlight Secure will provide notice through the email address associated with Your account or by posting a prominent notice on the Platform as provided by the Terms. Changes required by applicable Law or needed to address security or fraud risks may take effect upon notice.

11.2 The version date displayed at the top of this page identifies the current Privacy Policy.