Privacy Policy
Last updated · August 2026
Your privacy is important to us. This Privacy Policy explains how Fanfare collects, uses, and protects personal information when you use our services.
Introduction
Welcome to Fanfare. This Privacy Policy describes how Fanfare Labs, Inc. (“Fanfare,” “we,” “us,” or “our”) collects, uses, and otherwise processes personal information about our customers, users, and visitors (“you” or “your”) through our websites, software, applications, APIs, and related services (collectively, our “Services”).
Fanfare is an AI-powered social intelligence platform for sports teams, leagues, and media organizations. Our Services include an AI copilot that answers questions about a Customer’s audience and content, automated reporting on social media performance, and audience understanding built from a Customer’s social media presence.
By accessing our Services, you consent to our collection, use, and disclosure of information about you as described in this Policy. If you do not agree, you are not authorized to use the Services.
Who We Are
Fanfare Labs, Inc. is a Delaware corporation headquartered in the United States. We provide audience intelligence software to sports organizations on a subscription basis. Our customers (“Customers”) are businesses — teams, leagues, and agencies — rather than individual consumers.
We handle personal information in two capacities. For our website visitors, prospective customers, and the individual users of a Customer account, we act as a controller and determine how that information is used. When we collect and analyze social media and audience data on a Customer’s behalf, that Customer is the controller and we act as a processor and service provider on its documented instructions, under a data processing agreement. This distinction matters most when you want to exercise your privacy rights, and is explained under Your Privacy Rights below.
Information We Collect
Information You Provide Directly to Us
- Contact and profile information: Your name, email address, and phone number when you request a demo, register for an account, or download content, along with the profile details you provide when setting up an account.
- Organization information: The team, league, or organization you work for, your role, and your business contact information.
- Athlete and creator data: Information about athletes and creators associated with your organization, including social media handles, follower counts, engagement metrics, and content performance data that you input or authorize us to collect.
- Sponsorship and deal information: Details about sponsorship agreements, contract terms, exclusivity provisions, and deal values that you input into the platform.
- Communication data: Records of communications with our support team, demo requests, and other correspondence.
Information We Collect Automatically
- Usage information: How you interact with our Services, which features you access, and what actions you take.
- Device information: Your hardware, software, operating system, and IP address.
- Location information: General geographic location derived from IP address. We do not collect precise geolocation.
- Cookies and similar technologies: Information collected via cookies, as described below.
Information We Receive from Social Media Platforms
Our Customers authorize us to connect to social media accounts, pages, and channels they own or control. Through those connections we receive profile information, account identifiers, follower counts, engagement and performance metrics, content and comments, and — where the account and the permissions granted allow it — direct messages. Authentication credentials are stored in encrypted form and used only to retrieve authorized data on the Customer’s behalf.
Instagram and Facebook. Data from connected Instagram and Facebook accounts is retrieved through the Instagram Platform APIs, including the Instagram API with Instagram Login and the Facebook Graph API. Its use is governed by Meta’s platform terms in addition to this Policy.
YouTube. Data from connected YouTube channels is retrieved through the YouTube API Services under read-only access, and includes channel information, video metadata, and performance and engagement metrics. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service. Google’s handling of your information is described in the Google Privacy Policy, and you may revoke our access to your Google account at any time through the Google security settings page.
Publicly available sources. At a Customer’s direction, we also collect publicly available information about accounts, creators, and sponsors that are not connected accounts — for example, public profile and post data from Instagram and TikTok. This collection does not involve access to private content, private messages, or account credentials.
Information About Social Media Audiences
In providing the Services to a Customer, we process information relating to individuals who follow, engage with, or message that Customer’s social media accounts. This may include social media identifiers and profile information, the content of posts and comments, direct messages made available through connected accounts, engagement and interaction data, transcripts of the Customer’s video content, and inferred audience characteristics and segments. We treat direct messages and inferred audience profiles as personal information, including where they are derived from publicly visible content. We process this information only as a processor, on the instructions of the Customer whose accounts it relates to.
Use of Your Information
- Provide and improve our Services: To create and maintain accounts, deliver audience intelligence features, generate reports, and improve our platform.
- AI-powered insights: To power our copilot, conflict checker, tagging, transcription, and analytics features.
- Communicate with you: To respond to inquiries, send product updates, and provide customer support.
- Ensure security: To monitor for suspicious activity, prevent fraud, and maintain platform integrity.
- Legal compliance: To meet our legal obligations and enforce our terms of service.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Disclosure of Your Information
We may share your information with:
- Our Customers: Information we process as a processor is made available to the Customer on whose behalf it was collected.
- Service providers and subprocessors: Third-party vendors that support our hosting, infrastructure, artificial intelligence, data collection, analytics, and business operations.
- Social media platforms: As necessary to authenticate and retrieve data from accounts a Customer has connected.
- Legal purposes: In response to legal demands or court orders, or to protect our rights and safety.
- Business transfers: In connection with a merger, acquisition, or sale of assets.
- With your consent: Where you have explicitly authorized sharing.
We contractually prohibit our service providers from using information for any purpose other than performing services for us, and we impose data protection obligations on our subprocessors that are no less protective than those we accept ourselves. Customers may request our current list of subprocessors, and receive advance notice of changes to it, as set out in their data processing agreement.
Cookies and Similar Technologies
Fanfare uses cookies and similar technologies to operate the Services, improve your experience, analyze usage patterns, and remember your preferences. You can manage cookie preferences through your browser settings.
Third-Party Websites and Links
Our Services may contain links to websites and services operated by others, including the social media platforms we connect to. This Policy does not apply to those websites and services, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policy of any third-party site you visit.
Children’s Privacy
Our Services are intended for business users and are not directed at children. We do not knowingly permit anyone under eighteen (18) to register for or use the platform, and our agreements prohibit Customers from providing us with information about individuals they know to be under sixteen (16). If we discover we have inadvertently collected such information, we will promptly delete it.
Data Security
We implement reasonable physical, administrative, and technical safeguards designed to protect information from unauthorized access, use, and disclosure, including encryption at rest (AES-256) and in transit (TLS 1.3), role-based access controls, logging and monitoring of production access, vulnerability management, and incident response procedures. All personnel with access to personal information are subject to confidentiality obligations.
Your data stays yours. We understand the sensitivity of sponsorship data, athlete contracts, and competitive intelligence. We maintain complete logical separation between Customer environments, so that your sponsorship terms, contract details, roster insights, and audience data are never disclosed to another Customer.
Retention of Your Information
We retain information for as long as necessary to provide our Services and fulfill the purposes described in this Policy. When we no longer need information, we securely delete or de-identify it.
On termination. For thirty (30) days after a Customer’s agreement ends, we make that Customer’s data available for export in a commonly used, machine-readable format. After that period we delete or return the data at the Customer’s election, other than copies residing in routine backups, which are deleted in the ordinary course.
Disconnecting an account. When a connected Instagram, Facebook, or YouTube account is disconnected, or deletion is requested, we delete the associated account identifier, access tokens, and cached data received from that platform’s API within thirty (30) days.
Your Privacy Rights
Depending on where you live, you may have the right to access your personal information, to correct or delete it, to restrict or object to certain processing, to receive it in a portable format, and to withdraw consent where processing is based on consent. Exercising these rights will not result in discriminatory treatment.
If you are a website visitor, a prospective customer, or a user of a Customer account, contact us at privacy@fanfaresocial.com and we will respond directly within the timeframes required by applicable law. We may need to verify your identity before acting on your request.
If your information reached us because you follow, engage with, or message one of our Customers’ social media accounts, that Customer is the controller of your information and your rights are exercised with that organization. If you contact us directly, we will, where legally permitted, promptly direct you to the relevant Customer and let them know of your request. We assist our Customers in responding to these requests.
California Residents
California residents have additional rights under the CCPA/CPRA, including the right to know what personal information we collect and how it is used, the right to delete and correct personal information, the right to opt out of its sale or sharing, and the right to non-discrimination when exercising privacy rights. Fanfare does not sell personal information and does not share it for cross-context behavioral advertising. Where we act as a service provider to a Customer, we do not retain, use, or disclose personal information for any purpose other than performing the Services, and we do not combine it with personal information obtained from other sources except as permitted for service providers under the CCPA. Residents of other states with comprehensive privacy laws have comparable rights. To make a request, contact us at privacy@fanfaresocial.com.
European Union, United Kingdom, and Canada
If you are located in the European Economic Area or the United Kingdom, you have rights under the EU and UK General Data Protection Regulation, including the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. If you are located in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act. Where we act as a processor for a Customer, please direct your request to that Customer, as described under Your Privacy Rights.
Where a legal basis is required for processing information we control, we rely on the performance of a contract with you or your organization, our legitimate interests in operating, securing, and marketing our business, your consent where we ask for it, and compliance with our legal obligations. Where we process information on behalf of a Customer, that Customer is responsible for establishing the legal basis for the processing it instructs.
International Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our servers are located. Where we transfer personal information subject to the EU or UK GDPR to a country that has not been recognized as providing an adequate level of protection, we rely on an approved transfer mechanism, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into our data processing agreement.
AI Use and Data Handling
We use artificial intelligence, including services provided by third-party AI vendors, to power our conflict checker, copilot, transcription, translation, and analytics features. Content is sent to these providers only as needed to generate a result for the Customer that requested it, and we do not permit them to use that content to train their models. Your proprietary data — contracts, deal terms, and exclusivity agreements — is processed within your isolated environment and is not used to train models for other customers.
We may create and use data derived from Customer data, social media data, or platform usage that has been aggregated or de-identified so that it does not identify, and is not reasonably capable of identifying, any Customer, any connected account, or any individual. We may use that aggregated data to develop, improve, train, benchmark, operate, analyze, and promote our products and services. We do not attempt to re-identify aggregated data, and we do not permit any third party to do so.
Updates to This Privacy Policy
We may update this Policy from time to time. When we make material changes, we will update the date at the top of this page and notify you through the Services or by other means. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
Contact Us
If you have any questions, complaints, or comments regarding this Privacy Policy or our practices, please contact us at:
Fanfare Labs, Inc.
privacy@fanfaresocial.com
Governing Law
This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of laws principles, consistent with our Terms and Conditions. Nothing in this Policy limits any right you may have under the mandatory privacy laws of your own jurisdiction.