Skip to content
Some services are unavailable right now.

Privacy

What data we ask for, what for, who can see it, how long it is kept and how you ask for it to be corrected or deleted.

Who is responsible for your data

FameLume, the service that operates the site famelume.com from the Argentine Republic, is responsible for the personal data described on this page. For any request about your data, the channel is the form on the contact page; the procedure and its time limits are further down, under “Your requests about your data”.

What data you give us

The minimum needed to deliver and to answer you afterwards. What the checkout asks for is not optional to complete a purchase, and we ask for nothing extra “just in case”.

  • Your email, which stays attached to the order.
  • The public link of the profile or post we deliver to.
  • Product, package, quantity, currency and price, and the version of the terms you accepted.
  • Your order events, timestamped, so the order can be audited.
  • What we observe about the public link we deliver to — whether it was reachable, its public title, the public count the platform shows on that same page (the likes on an Instagram post, for instance) and, on Kick, whether the channel was streaming — measured before the delivery starts and again when it finishes, together with what the provider reports about that delivery. It is timestamped and exists so a claim about what was delivered can be answered: it can never be edited, and it is deleted only when the retention period stated below runs out. We look at nothing private: it is the same public page you were already sharing.
  • If you write to us through the contact form: your email, the message and, if you fill them in, your name and your order number. We use them to answer you. Your IP address also counts the form’s submissions, as the attempt-counter section explains. Also, the anti-robot check on the contact form is Cloudflare Turnstile, it loads on the contact page alone and only if the operator has configured its keys: when it appears, Cloudflare receives your IP address and details of your browser to decide whether you are a person. From Cloudflare we receive the outcome of that check together with the time of the challenge and the domain it was solved on; we use only the yes or the no, and we do not store that response.
  • The order number, and the language and currency you buy in. The tracking link is generated once, when the order is created, and from then on we store the tracking link nowhere, only a fingerprint of it that cannot be reversed.

The data the attempt counter keeps

So that a brute-force attack costs something, the system counts attempts within a time window, and to count them it keeps what each attempt belongs to. None of it is asked of you separately: it comes from the request you were already making.

  • The IP address you connect from. It happens, for example, when you register, sign in, edit your profile, change your password, ask to recover access, ask for the verification link to be sent again, open a verification or recovery link, answer a second factor, write to support or use the contact form. The list is examples and does not claim to be exhaustive: any form the counter limits by address leaves it in that row, including while you are signed in.
  • The email address you type into the form, normalised, when you sign in or ask to recover access: without it there would be no per-account limit and an attack against one specific account would only have to change IP address.
  • Your account’s internal identifier, when you open or reply to a support ticket while signed in.

How we measure visits

To know which pages get read and whether they load quickly, visits to public pages are measured with Vercel Web Analytics and Speed Insights, with no cookies and without identifying you, and an order, account or checkout page is never reported. What is measured is aggregate: how many visits a page had, from which country and on what kind of device. It is not tied to your email, your account or your orders, and we do not use it for advertising. The detail of what Vercel receives is on the processors and providers page.

If you also open an account

Buying does not require an account: checkout works as a guest and the order is tracked with its link. If you decide to open one, the following is added.

  • Your email and, if you want one, a display name. The password itself is not stored: we store a cryptographic derivation from which the original cannot be recovered.
  • If you sign in with Google, the identifier Google gives us for your account, the address it asserts at that moment, whether Google vouches for it, the date of that response and the name it sends, if it sends one. We never receive your Google password. Note that signing in with Google is optional and is only available if the operator has configured Google credentials: see the processors and providers page.
  • Your open sessions, stored as a derivation of the cookie value rather than the value itself, with their creation and expiry dates.
  • The support tickets you open: their subject, their messages, their state, and the order of your own that you link them to.
  • Every link generated to verify your address — the first one when you register — or to recover access leaves a record: an irreversible fingerprint of the link instead of the link itself, which of the two it is for, your account, the address it was issued to, and when it expires. It works once: the verification one lasts 24 hours and the recovery one 15 minutes.
  • A timestamped record of the transactional emails the system prepared for you and of whether the mail server accepted them for delivery: emails go out from a mailbox on our famelume.com domain, through the mail server of the hosting we contract. Recording it is attempted and it can fail: if the database fails when the record is opened no mail goes out and no row is left, and if it fails when the record is closed the mail is left recorded without its outcome. See the processors and providers page.

If you sign in with Google

It is an alternative to a password, not a requirement: you can buy without an account and you can have an account without Google. Signing in with Google is optional and is only available if the operator has configured Google credentials. When you use it, your browser goes to Google, Google identifies you, and it returns a single-use code that our server exchanges. We never see your Google password.

  • What we ask Google for: the scopes “openid”, “email” and “profile”, and nothing else. They are read-only over your identity. We do not ask for permission to post on your behalf, nor access to your contacts, calendar, mail, files or any other Google API.
  • What we receive and store: the stable identifier Google assigns to your account for this application, your email address, whether Google vouches for it, and the name Google sends if it sends one, trimmed to 80 characters. We also store the date and time of that response, so that two Google responses about the same account can be ordered.
  • What we do NOT receive: your password, your profile picture or avatar, your separate family or given names, your contacts, or any other data from your Google account. We do not request offline access, so we neither receive nor store a refresh token.
  • The tokens: the access token Google returns is used once, on our server, to read those four values, and is stored in no database and no cookie.
  • What for: to authenticate you — to open your session — to link your FameLume account with your Google identity, and for the security of that link. If Google does not vouch for your address, we create and link nothing and the attempt is refused. We do not use this data for advertising or profiling, and we sell it to nobody.
  • How the link works: by the identifier Google gives, not by the email. One Google identity is linked to exactly one FameLume account and one account to exactly one Google identity. If your address already had a password account you never verified, linking Google to it removes that password and closes every open session.
  • Who it is shared with: only Google, and only during the flow. Your browser goes to accounts.google.com carrying the application identifier, the return address and the language of the screen; our server requests the token from oauth2.googleapis.com and reads your identity at openidconnect.googleapis.com. Google therefore knows you are signing in to this site. No other third party takes part.
  • While the flow lasts: a first-party cookie of ten minutes holds an anti-forgery value, a single-use verifier, your language and which page to return to. Page JavaScript cannot read it, and it is deleted as soon as you come back from Google, whether or not it worked. When it starts, your IP address is recorded by the attempt counter, as with any other access form.
  • How to revoke it: from your Google account settings you can remove FameLume’s access whenever you want. That stops future sign-ins with Google; on its own it does not delete the data already held in your FameLume account, and if your account was left without a password it can leave you unable to sign in until you recover access by email.
  • How to ask for deletion: this link’s data is deleted with your account. The procedure and its time limits are in the “Your requests about your data” section of this same page.

What we never ask for

Your password for any social network, nor an access token to your account, nor permission to post on your behalf. If a FameLume screen ever asks for that, it is not FameLume.

We also do not store your card details: payment happens at the payment provider, outside our screens.

Who can see your order

An order is looked up with a tracking link containing an opaque random identifier. There is no public listing and no order search, and those pages are neither indexed nor stored in shared caches. The email is shown masked even on your own order page, so sharing the link does not expose your full address.

If you opened an account, your orders and tickets are read with queries scoped to your account: asking for someone else’s order identifier does not return it.

A member of the internal team can see your order and your tickets in order to resolve them, with the address masked there too, signing in with a separate account and a mandatory second factor. What that person CHANGES is noted down with who did it and why — a best effort, not a promise: if the note fails, the change still stands, without its record. What they LOOK AT leaves no record, and we say that rather than claim everything is audited.

Basis and purpose of processing

We use the data to process payment, order delivery, show you the status, answer questions and limit access attempts. We do not use it for advertising or profiling, and we do not sell it.

The basis is twofold. We process purchase and account data because it is necessary to perform the contract you enter into with us when you buy, and you give it with your consent when you complete each form. We process the attempt-counter data for the security of the service and of your own account. Whatever the law obliges us to keep, we keep because of that obligation.

How long we keep it

Your account data is kept for as long as the account exists. Order and payment records — what was bought, how much was paid, what was delivered and what was returned — are kept for ten years from the purchase, to meet accounting and tax obligations and to be able to answer a complaint. When you ask for your account to be deleted, we delete or anonymise everything we are not obliged to keep.

The content of the messages you send through the contact form is not stored in our database: it travels through our domain’s mail server to our mailbox, and we keep them there for up to two years after the question is resolved.

The attempt-counter rows — IP address, form email address or account identifier, depending on the case — have a period decided by the code: they become eligible for deletion two hours after their window STARTS, not after it ends. The limiter itself deletes them while handling later requests, in bounded batches: no scheduled process does it, so with no traffic — or little — an expired row can sit there longer; what does not happen is that it gets renewed.

Who they are shared with

With the providers needed to charge, to deliver and — if the operator configures it — to identify you. The per-category detail, with its status, is on the processors and providers page, which includes the identity provider. We do not sell your data and we do not use the target profile to market to you.

International transfers

Your data is stored and processed in the United States: the site runs on Vercel and the database is on Neon, both on the east coast. The per-provider detail is on the processors and providers page.

That means your data leaves Argentina. By buying or by creating an account you consent to that transfer, which is necessary to provide the service to you. Those providers process the data on our behalf, under their data processing terms, and may not use it for purposes of their own.

Minors

The service is for people aged 18 or older. We do not knowingly sell to minors or process their data; if we learn that an account or an order belongs to a minor, we close it and delete its data, except for what the law obliges us to keep.

Your requests about your data

You can ask to access your data, to have it corrected or updated, or to have it deleted. Write to us from the form on the contact page, with the email of your account or your order, or open a support ticket from your account. To protect your data, we may ask you to confirm that the address is yours before we answer.

We answer an access request within ten calendar days, and we correct, update or delete within five business days of receiving the request. It is free. Deletion does not reach what the law obliges us to keep, which is listed under “How long we keep it”.

The Agencia de Acceso a la Información Pública, as the supervisory body of Argentine Law 25,326, has the power to hear complaints and claims from anyone whose rights are affected by a breach of the rules on personal data protection.