Reel Neet
Privacy Policy
Reel Neet Accounts — `accounts.reelneetsolutions.com`
Last updated: 29 September 2026 Effective: 29 September 2026
---
1. Introduction
This Privacy Policy explains what personal information Michael Wesley Schiff (an individual trading as a sole proprietor under the name Reel Neet Solutions) ("we", "us", "our") collects through Reel Neet Accounts at `accounts.reelneetsolutions.com` (the "Service"), why we collect it, who we share it with, and what rights you have.
The Service is the one invite-only sign-in for Reel Neet's apps: the Worth Saying commentator platform, the company wiki and the hub, and, as they join, the crew portal and the live scoring office (each an "App"). This policy covers what the Service itself holds: your account, your sign-in and your access. Each App has its own privacy policy for what that App holds and does, such as Worth Saying's notes, seats and booth.
It covers three groups of people, and they are treated differently:
- Members, and people invited to become one — the people an admin invites
into an App, who choose a password and sign in. Sections 2 to 10. Where those sections say "you", they mean you in this role.
- Guest commentators — people invited onto one show in Worth Saying, who
enter by a personal link, without a password, until the show ends. Section 3.8 says what we hold. Where Sections 2 to 10 describe a member's account and sessions, they apply to a guest commentator too, except where Section 3.8 says otherwise.
- Call-in guests — people invited into one show's booth waiting room in
Worth Saying. The Service keeps their invite and hands them into the waiting room, but they have no account, no session and no cookie. Section 3.9 says what we hold.
Read this alongside our Terms of Service.
2. Summary — the short version
- We collect very little: your name, your email address, a hashed
password, the state of your account, which Apps you may use and in what role, and two signed session cookies.
- There is no public sign-up. Everything we hold about you starts with an
admin inviting you by name and email address.
- **When you visit an App, the App is told who you are, but not your email
address**: only an internal account number, your name, and your role there. Section 5 has the detail.
- We use **no advertising, no tracking pixels, no third-party fonts and no
third-party CAPTCHA**. There are no third-party analytics or trackers in this Service at all. Your use of the Service is not measured by anybody but us.
- Account email is sent through Resend, an email delivery service acting
for us. Open and click tracking is off. Section 3.10 lists every email we send.
- We do not sell or share your personal information, and never have.
- We collect no payment information, because the Service is not sold.
- Your IP address is used only to throttle sign-in, password-reset and
invite-link attempts, is kept for five minutes, and only as a keyed hash, and is never stored as written.
- You can change your name, email address and password, sign out everywhere,
and delete your account yourself.
3. Information we collect
3.1 Account information
| Data | Why | How obtained | |---|---|---| | Account id | An internal identifier that stands for you in the Service and in every App, so that what you do in an App stays yours when your email address changes. It is never shown to anyone and never reused | Created automatically when you are invited | | Name | How you are named to the people you work with, and in the emails we send you | Given by the admin who invited you, and changeable on your account page | | Email address | What you sign in with, and where we send the emails in Section 3.10 | Given by the admin who invited you, and changeable on your account page | | Password (hashed) | To authenticate you | Chosen by you when you accept your invite, and changeable on your account page | | When your account was created, and when you accepted the Terms | Account administration, and a record that you agreed to the Terms | Recorded automatically | | Account state: invited, member or suspended, and whether you are an admin of the Service | So that only members who are not suspended can sign in, and only admins can invite, grant, suspend and delete | Recorded automatically, and changed by an admin | | Whether you have asked not to be recorded in the usage record | So that Section 3.7's opt-out is kept on your account | Set when you ask | | Session records (your account id, when each session started and when it expires) | So signing out ends that session, and so we can end every session you hold if a device is lost or access ends | Recorded automatically each time you sign in | | One-time links: invite, password reset and email change | To prove that an email address is yours before it is used | Created when you are invited, ask for a reset, or change your email |
Accepting an invite. An admin, or an app admin for their own App, invites you by giving us your name, your email address, and the App and role you are to have. Until you accept, your account is invited: it cannot sign in, and it is not listed to any App. You accept by following the link we email you, choosing a password and agreeing to the Terms; you are then a member, and signed in. If you already have an account, a new App is simply added to it, and we tell you by email.
We never store your password. It is hashed with scrypt (a deliberately slow, memory-hard algorithm) using a random 16-byte salt unique to your account. We cannot read, recover or tell you your password. If you forget it, you can ask for a password-reset link by email; a reset signs out every device.
Passwords must be at least 8 characters. There are no other composition rules. A password that appears on a list of commonly used passwords is refused; that list is bundled with the Service and checked on our own server, so your password is never sent to any outside service to be checked.
There is no two-factor sign-in. An email address and password are the whole of what signs you in. We have chosen to keep sign-in simple for now; a strong password that you use nowhere else is therefore your main protection.
One-time links are stored only as a hash, work once, and expire: an invite link after 7 days, a password-reset link after 1 hour, and an email-change link after 24 hours. Changing your email address requires your current password, the new address only takes effect once you follow the link sent to it, and your old address is told of the change.
3.2 Your access to each App
| Data | Why | How obtained | |---|---|---| | For each App you may use: the App, your role in it (`user` or `admin`), and for the crew portal the business your role covers | So that each App lets you in, in the right role, and no App you have not been given lets you in | Set by the admin who invited you, and changed by an admin | | When that access ends, if it has an end date | So that access given for a limited time ends by itself | Set by an admin | | Who gave you that access, and when | A record of who let whom into which App | Recorded automatically |
A member with no access to any App can still sign in, but can enter nothing.
3.3 Cookies
The Service sets two cookies, both for the same signed-in session. They are strictly necessary for the Service to function — without them you cannot stay signed in.
| Cookie | Sent to | Contents | Duration | Flags | |---|---|---|---|---| | `rns_session` | Every `reelneetsolutions.com` address, so that one sign-in works for every App | A random session identifier and an expiry timestamp — cryptographically signed (HMAC-SHA256) so it cannot be altered or forged. It does not contain your email address | 30 days | `HttpOnly`, `Secure`, `SameSite=Lax` | | `__Host-rns_acct` | `accounts.reelneetsolutions.com` only | A second signed reference to the same session, which the Service requires before it changes anything: your account, your password, or anyone's access | 30 days | `HttpOnly`, `Secure`, `SameSite=Strict` |
The first cookie reaches every Reel Neet address because that is what lets you sign in once. It can only be used to ask the Service "who is this, and may they enter this App?" — it is not, on its own, enough to change your account; that takes the second cookie, which never leaves the accounts address.
The 30-day life is deliberate: it means a commentator or operator is not signed out on the morning of a competition, on venue wifi, minutes before going on air.
A guest commentator is given the same cookies when they open their invite link, on each device they open it on. Their session ends when their show ends (Section 3.8), even if that is sooner than 30 days. A call-in guest is never given a cookie.
`HttpOnly` means page scripts cannot read them. `Secure` means they are only ever sent over HTTPS. They are first-party cookies, they are not used for tracking or advertising, and they are not shared with anyone.
We use no other cookies. There are no analytics cookies, no advertising cookies, and no third-party cookies, so there is nothing to consent to or opt out of beyond signing out.
3.4 IP address — form protection only
When you submit the sign-in or password-reset form, change your password, or open an invite or call-in link, your IP address is used to rate-limit attempts (a limit per account and a looser limit per address, because a commentary booth or a production truck shares one venue connection).
So that a restart of the Service does not reset these limits, each attempt is recorded in the Service's own database for a rolling five-minute window. Your IP address is not stored as written: it is recorded only as a keyed hash, which cannot be turned back into the address without the Service's secret key. The record is deleted when the window passes, and a successful sign-in clears your account's attempts. It is not used to identify, locate, profile or track you.
3.5 Server logs
The Service itself keeps no access log, so no link you follow lands in a log. Our reverse proxy may generate operational logs in the ordinary course of serving requests, which may include IP address, timestamp, requested path, response status, and user agent. These are used only to operate and secure the Service and to diagnose faults, and are not shared with any advertising or analytics provider.
When an admin invites, grants, suspends or deletes, the Service writes one line to its log naming the admin's account id, what was done, and the other person's account id — never a name or an email address.
3.6 Stored on your device
Apart from the cookies in Section 3.3, the Service stores nothing in your browser.
3.7 Worth Saying's feedback and usage record
Two small functions of the Worth Saying App are, for now, answered by this Service, because they need to know who is signed in. Worth Saying's own privacy policy describes them in full; in short:
- Bug reports and feature requests. When you send one from inside Worth
Saying, its text, your account email and the screen you were on are filed as an issue on GitHub (Section 6).
- Usage record. When it is switched on, we keep a first-party record of how
Worth Saying's pages are used — the date and time, your account id (not your email or name), the page without its query string, the names of the controls used, a coarse device class and a rounded screen width, and any error the application hit — so that we can fix what breaks and remove what nobody uses. It is written only for requests to Worth Saying, never for this Service or any other App. It never contains your IP address, your user agent string or anything you type. It stays on our own server and is not backed up. If you would prefer not to be recorded, write to privacy@reelneetsolutions.com and we will switch it off for your account; that choice is kept on your account, so it stays in force if you change your email address.
3.8 Guest commentators
A guest commentator does not choose a password. A Worth Saying admin invites them onto one show by giving us their name and email address, and we email them a personal invite link. The link works on any device, from the moment it is sent until midnight at the venue at the end of the show's last day, or sooner if it is revoked. Reissuing an invite ends the old link and emails a new one. In this section "you" means a guest commentator.
| Data | Why | How obtained | |---|---|---| | Your name | So the people you are working with know who you are, and so the invite email can greet you | Given by the admin who invited you | | Your email address | Where we send your invite link. It is kept with the invite, not as a sign-in address | Given by the admin who invited you | | The show, and when your access ends | So the link lets you into that show and nowhere else, and stops at the end | Set by the admin who invited you | | The invite link (hashed) | To let you in without a password | Created when the invite is sent or reissued. We keep only a hash of it | | The invite's status: active, revoked or expired, who sent it, and when | So a revoked or expired link stops working, and so admins can see and manage invites | Recorded automatically | | Account id, and when you agreed to the Terms | As for a member (Section 3.1) | Recorded when you are invited, and when you agree on the invite page | | Session records | As for a member (Section 3.1). Revoking your invite, or the end of your show, ends every session it opened | Recorded each time you open your link on a device |
A guest commentator can enter Worth Saying only, never any other App. A guest has no account page and cannot sign in with a password.
3.9 Call-in guests
A call-in guest has no account, no session and no cookie. A Worth Saying admin invites them into one show's booth by giving us their name and email address, and we email them a personal link. We hold:
| Data | Why | |---|---| | Your name and email address | To send your link, and so your name labels your place in the waiting room | | The show, and when the invite ends | So the link works for that show only, until the end | | The invite link (hashed) | To let you into the waiting room. We keep only a hash of it | | The waiting room's address and password | To hand you into it once you have agreed to the terms on the call-in page | | The invite's status, who sent it, and when you agreed | So a revoked or expired link stops working, and a record that you agreed |
When you agree on the call-in page, the Service sends your browser to the waiting room at VDO.Ninja with your name as your label (Section 6). What happens in the waiting room and the booth is described in Worth Saying's privacy policy.
3.10 Email we send
We send email only to run your account. We send no newsletters, no marketing and no reminders. Every email is sent through Resend (Section 6), from a `reelneetsolutions.com` address.
| Email | Sent to | When | |---|---|---| | You're invited | The person invited, at the address the admin gave | When an admin invites a new person into an App, and again with a new link if the invite is reissued | | You have access to a new App | You | When an admin gives an existing member access to another App | | Reset your password | You | When a reset is asked for with your address | | Confirm your new email address | Your new address | When you change your email address | | Your email address was changed | Your old address (without saying the new one) | When the change takes effect | | You're invited as a guest commentator | The guest, at the address the admin gave | When the invite is sent, and again with a new link if it is reissued | | You're invited as a call-in guest | The guest, at the address the admin gave | When the invite is sent, and again with a new link if it is reissued |
A request for a password reset for an address that has no account, or for an account that is not a member, is answered exactly as any other and sends nothing.
3.11 What we do not collect
We do not collect: payment or financial information; government identification; date of birth; precise location or GPS; contacts; photographs of you; biometric data; device fingerprints; advertising or cross-site behavioural profiles; health information; or any special category / sensitive personal information as those terms are used under GDPR or U.S. state privacy laws.
The emails we send carry no open or click tracking: no tracking pixel, and no link rewritten to pass through a tracking address. This is switched off at Resend and stays off. If that ever changes, this policy will change first.
We do not track you across other websites, and the Service sends no "do not sell or share" signal-relevant data to anyone because there is no such sharing.
4. How we use information
We use the limited information above only to:
| Purpose | Data used | Legal basis (GDPR, where applicable) | |---|---|---| | Invite a person into an App, email them their link, and let them accept | Name, email, the App and role, the invite link (hashed), IP address (transient) | Legitimate interests (giving the people Reel Neet works with access to the tools for that work); steps taken at your request before entering into a contract | | Authenticate you and keep you signed in | Email, password hash, account state, session cookies | Performance of a contract; legitimate interests | | Tell each App who you are and what role you hold there (Section 5) | Account id, name, member or guest, role, crew scope | Performance of a contract; legitimate interests (controlling access to confidential material) | | Reset a forgotten password, or change your email address | Email, password-reset or email-change link, IP address (transient) | Performance of a contract; legitimate interests (security) | | Issue, change, suspend and withdraw access | Account id, name, email, account state, access to each App, session records | Legitimate interests (controlling access to confidential material) | | Invite a guest commentator or a call-in guest onto a show, email them their link, let them in, and revoke or reissue the invite | The guest's name and email address as given by the admin, the show, the invite link (hashed), the invite's status and end; IP address (transient) | Legitimate interests (bringing a guest the show has chosen into its commentary, and controlling access to confidential material); performance of a contract once the guest has agreed to the terms | | Protect the forms from brute-force attacks | IP address (transient) | Legitimate interests (security) | | Operate, secure and debug the Service, and keep a record of admin actions | Server logs, the admin log line (ids only) | Legitimate interests (security and service integrity) | | Understand which parts of Worth Saying are used, so we can improve them and remove what is not | Usage record (Section 3.7) | Consent, which you may withdraw at any time by writing to us | | Receive and act on a bug report or feature request you send from Worth Saying | The text you write, your account email, and the screen you were on | Performance of a contract; legitimate interests | | Contact you about your access, or a material change to our terms | Email | Legitimate interests; legal obligation where applicable |
The information about an invited person comes first from the admin who invited them, not from that person.
We do not use your information for marketing, advertising, automated decision-making, or model training. Every invitation and every grant of access is decided by a person, an admin.
5. What each App is told about you
When you open an App, the App asks the Service whether to let you in. If you have access, the Service answers with exactly five things:
| Told to the App | Example | |---|---| | Your account id | an internal identifier (Section 3.1) | | Your name | `Pat Doe` | | Whether you are a member or a guest commentator | `member` | | Your role in that App | `user` or `admin` | | For the crew portal, the business your role covers | `reelneet`, or blank |
Your email address is never sent to an App this way, and an App you have no access to is told nothing: it only learns that someone without access tried to enter.
One exception, for Worth Saying. So that Worth Saying's admins can manage commentators and guest invites, Worth Saying's own server may ask the Service for the list of people who have access to Worth Saying: each person's account id, email address, name, whether they are an admin, whether they are a member or a guest, and their access. It is never given a password hash or a session, and it is never told about people who have no access to Worth Saying. This request travels only inside our own server, never over the internet.
6. Who we share information with
We do not sell your personal information. We do not share it for advertising or cross-context behavioural advertising. We do not disclose it to data brokers. We have not done so in the preceding twelve months.
We share information only in these circumstances:
| Recipient | What they receive | Role | |---|---|---| | Hostinger, our hosting provider (virtual private server) | Everything stored on the server, incidentally, as the operator of the infrastructure | Processor | | The Apps you have access to | The five things in Section 5; and, for Worth Saying, the list described there | Within Reel Neet | | Admins and app admins | Admins see every member and invited person: name, email address, account state, and access to each App. An app admin sees only the people with access to their own App. Guest commentators are never listed among members | Within the Service | | Resend (Plus Five Five, Inc., USA), which sends the Service's email | For each email in Section 3.10: the recipient's email address and name, the subject, the full message including any invite, password-reset or email-change link in it, the record of whether it was delivered, and the log of our request to send it. Resend keeps this for 30 days, and in its backups for 7 days more; if we stop using Resend, what remains is deleted within 90 days. An address that bounces or complains may stay on its list of addresses not to send to. It is stored in the United States and delivered through Amazon Web Services' email service. Resend uses sub-processors, listed at resend.com/legal/subprocessors, and gives at least 14 days' notice before it adds or replaces one. Open and click tracking is off (see 3.11) | Processor | | GitHub (GitHub, Inc.), where our source code and issue tracker live | Two things. When you send a bug report or feature request from Worth Saying: the text you wrote, your account email, and the screen you were on. And our encrypted backup (Section 9) of the Service's database — accounts, access, invites, call-in invites, session records and the record of deleted accounts. It is encrypted before it is stored; GitHub does not hold the key that opens it, so it cannot read what it stores. Nothing else reaches them — the usage record in Section 3.7 never leaves our own server | Processor | | Cloudflare (Cloudflare, Inc.) | Nothing about you. Cloudflare answers the domain-name lookups for `reelneetsolutions.com` and nothing more: your traffic to the Service does not pass through Cloudflare, and it receives nothing about your account | Service provider | | VDO.Ninja (peer-to-peer call service) | Only for a call-in guest, once they agree on the call-in page: their name, as the label on their place in the waiting room. The Service sends VDO.Ninja nothing else | Service provider | | Legal or regulatory recipients | Only where compelled by valid legal process, or where necessary to establish, exercise or defend legal claims, or to protect the safety of any person | As required | | A successor | In connection with a merger, acquisition or sale of assets, subject to this policy | Controller |
6.1 A note on fonts and outside content
Every page of the Service is served from `accounts.reelneetsolutions.com` alone: no script, stylesheet, typeface or image is loaded from anywhere else, so your browser makes no request to Google, Meta, a font service or any other third party when you use the Service. The only links that leave it are the ones on your "my apps" page, to the Apps you have access to.
There are three places where information about you reaches a third party from our server, and it is never your browser that sends it: when we send you an email, our own server passes it to Resend; if you choose to file a bug report or feature request from Worth Saying, our own server passes it to GitHub; and our backup is encrypted and stored with GitHub, which cannot read it. All three are described in the table above. Nothing else does — in particular the usage record in Section 3.7 is written to our own disk, goes nowhere, and is not in the backup.
7. International transfers
The Service is operated from the United States and runs on a virtual private server supplied by Hostinger. If you access the Service from outside the country in which that server sits, your information will be transferred across borders.
Where personal information of individuals in the European Economic Area or the United Kingdom is transferred to the United States, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses where applicable, and we minimise what is transferred — for members and invited guests, that is a name, an email address and the emails in Section 3.10. Those emails are stored by Resend in the United States; that transfer relies on the Standard Contractual Clauses (Module Two, controller to processor) built into Resend's data processing agreement, with the UK Addendum for the United Kingdom, and on Resend's certification under the EU-U.S. Data Privacy Framework and its UK Extension. You may ask us at privacy@reelneetsolutions.com where the Service is currently hosted.
8. Data retention
| Data | Retained | |---|---| | Account record (account id, name, email, password hash, dates, account state) | For as long as your account exists. When the account is deleted, see *Deleting an account* below | | An invite to become a member that is never accepted | The link stops working after 7 days. The invited account (name, email and the access offered) cannot sign in, and stays until an admin withdraws the invite or deletes it; withdrawing deletes an invited account that never accepted | | Access to each App (the App, role, scope, end date, who gave it and when) | For as long as your account exists, including after an end date passes, as a record of who had access to what. Removed when an admin removes it, or when the account is deleted | | One-time links (invite, password reset, email change) | Until used or expired — 7 days, 1 hour and 24 hours respectively — and kept only as a hash. A newer link replaces an older one | | Session cookies and session records | 30 days from sign-in — for a guest commentator, no later than the end of their show — or until you sign out, sign out everywhere, reset or change your password, change your email, are suspended, or we revoke it or the invite that created it; the record is deleted then, or when the next session is opened, or when the account is deleted | | Sign-in rate-limit data (IP address as a keyed hash) | Five minutes | | Server logs | For a short operational period, then rotated and discarded in the ordinary course | | Admin log lines (account ids only) | As part of the server logs | | Guest commentator invites (name, email address, show, status, end, who sent it, when the guest agreed; the link kept only as a hash) | The link works until midnight at the venue at the end of the show's last day, or until it is revoked or reissued. The invite record is then kept as a production record of who was invited onto which show | | A guest commentator's account (account id, name) | Kept after the show ends, so that what they wrote in Worth Saying stays credited to them; it can no longer be used. When it is deleted, see *Deleting an account* below | | Call-in guest invites (name, email address, show, status, end, who sent it, when the guest agreed; the link kept only as a hash) | The link works until the invite's end, or until it is revoked or reissued. The invite record is then kept as a production record of who was invited onto which show | | The record that an account was deleted (its account id, and the account id of whoever deleted it) | Kept, so that every App can show that account's past work as belonging to a former member rather than to anyone else | | Usage record (Section 3.7) | Through the competition season it was recorded in, and deleted after 90 days | | Resend's copy of each email (Section 6) | 30 days, plus 7 days in Resend's backups | | Encrypted backups (Section 9) of the Service's database | Kept in our private source repository as a history of past backups, so that the Service can be recovered. A record removed from the server remains, encrypted, in backups taken before its removal; only we hold the key, and a backup is opened only to recover the Service |
Deleting an account. You can delete your account yourself from your account page, with your password; an admin can delete it; or you can write to us and we will. The last admin cannot delete their own account until someone else is an admin. Deletion removes your name, your email address, your password and your access to every App, cancels any one-time link, and ends every session you hold. We keep only your account id and who deleted it, so that the Apps can show what you did there as done by a former member — in Worth Saying, your notes stay, credited to "a former commentator" rather than to you. That id is never shown and never given to anyone outside Reel Neet. What each App itself keeps is set out in that App's own privacy policy. A guest commentator has no account page: to have their account or an invite deleted, a guest writes to us, and the same rules apply.
Suspension. An admin may suspend an account. A suspended account is kept whole — including your name and your access to each App — but cannot sign in, and every session and one-time link it held ends at once, until an admin lifts the suspension.
9. Security
Security is the reason this Service is built the way it is. Measures include:
- Invite-only. There is no sign-up form, so nobody can create an account
without an admin.
- Passwords hashed with scrypt, memory-hard, with a unique random salt per
account, and compared in constant time.
- A password floor of 8 characters, with commonly used passwords refused
against a list held on our own server — nothing about your password is sent out to be checked.
- No two-factor sign-in. We say so plainly: the Service does not offer a
second factor, for anyone.
- Signed sessions — the session cookies are HMAC-SHA256 signed and verified
in constant time; they cannot be forged or tampered with.
- Server-side sessions — every session is also a record on our server, so
signing out ends it for good, even for a copy of the cookie. Sign out everywhere ends every session you hold, and resetting or changing your password, or changing your email, ends every other one.
- Two cookies, not one — the cookie every Reel Neet address receives can
only ask who you are; changing anything takes the second, which only the accounts address ever receives (Section 3.3).
- Access checked on every request — a change to your access, a suspension or
a revoked invite takes effect on your next click, not your next sign-in.
- One-time and invite links are made from at least 128 random bits, stored
only as a hash, and expire (Sections 3.1 and 3.8).
- Forms refuse submissions from other sites, including other Reel Neet
addresses, so no other website can sign you in, change your account, or change anyone's access.
- Rate limiting on sign-in, password reset, password change, email change
and opening an invite or call-in link, per account and per address.
- No account enumeration — a wrong email and a wrong password produce the
same message in the same time, and asking for a reset always answers "check your email", so no form can be used to discover who has an account.
- Open-redirect protection — after signing in, the Service will only send
you on to one of Reel Neet's own addresses, so it cannot be used to build a convincing phishing link.
- Fails closed — the Service refuses to start without its secret key and
its settings, rather than starting in a weaker state.
- No access log, and invite pages send no referring address, so links do
not leak into logs or to other sites.
- Least privilege — the Service's internal interface is reachable only
inside our own server, never from the internet, and requires a secret token. Cryptography is standard-library only, so there is no third-party crypto dependency to be compromised.
- Encrypted off-server backups — the Service's database is backed up and
encrypted to a public key before it is stored. The key that opens a backup is held only by us, and is on neither the server nor the system that makes the backups. The usage record is never backed up.
- Transport security — HTTPS throughout, with certificates renewed
automatically.
- Not indexed — the sign-in pages are served `noindex, nofollow`, so the
Service does not appear in search results.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.
10. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information;
- port your information to another provider;
- object to or restrict processing;
- withdraw consent, where we rely on it; and
- not be discriminated against for exercising these rights.
Given how little we hold, most requests can be answered simply: for almost every member, the complete record is an account id, a name, an email address, a password hash, a few dates, the state of the account, its access to each App, and its open sessions. You can change your name, email address and password, and delete your account, yourself on your account page.
For an invited guest the record is smaller still: the invite (a name, an email address, a show, a status and an end), and, for a guest commentator, an account id and sessions. A guest has no account page, so a guest exercises every right by writing to us. For what an App holds about you, see that App's own privacy policy; the same address below reaches us for every App.
To exercise any right, write to privacy@reelneetsolutions.com. We will respond within the time required by applicable law (generally 30 days under GDPR, 45 days under California law, extendable where permitted). We may need to verify your identity, which we normally do by corresponding with the email address on the account.
10.1 If you are in the European Economic Area or the United Kingdom
You may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
10.2 If you are a California resident
Under the CCPA/CPRA, in the preceding twelve months we have collected the category of identifiers (name, email address, IP address) and internet or network activity, including interaction history with our own applications (server logs, and the usage record described in Section 3.7) for the business purposes described in Section 4.
We have not sold or shared personal information, and do not do so. We do not use or disclose sensitive personal information for purposes requiring a right-to-limit disclosure. You have the rights described in Section 10, and we will not discriminate against you for exercising them. You may use an authorised agent, with proof of authorisation.
10.3 Other U.S. states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others) have broadly equivalent rights of access, correction, deletion, portability and appeal. Write to privacy@reelneetsolutions.com. If we decline a request you may appeal by replying to our decision; we will respond to an appeal within the period your state's law requires.
11. Children's privacy
The Service is a professional tool for the people Reel Neet works with. It is not directed to children, and we do not knowingly invite, or knowingly collect personal information from, anyone under 18. If we learn that we have collected personal information from a child under 13 (or the applicable age in your jurisdiction), we will delete it promptly. Contact privacy@reelneetsolutions.com if you believe this has occurred.
12. Changes to this policy
We may update this Privacy Policy. The "Last updated" date at the top always reflects the current version. If a change is material, we will make reasonable efforts to notify account holders by email or by a notice within the Service before it takes effect.
13. Contact
For any privacy question, request or complaint:
Michael Wesley Schiff, trading as Reel Neet Solutions Privacy: privacy@reelneetsolutions.com General: mschiff05@gmail.com
We handle privacy requests by email. If you require a postal address, ask and we will provide one.
We are the controller of the personal information described in this policy.