Privacy Policy

Last updated: 22nd July, 2026

This Privacy Policy explains how WUMP! (“WUMP”, “we”, “us”, “our”) collects, uses, and protects personal data when you use our website at wump.io and our related tools and services (the “Service”).

WUMP is a platform for creators to grow and manage their audience. We take a privacy-first approach: creators own the audience data they collect through WUMP, and we process personal data only as described below.

1. How to contact us

For any privacy question, or to exercise your data rights, contact us at: [email protected].

2. The two roles WUMP plays

WUMP processes personal data in two distinct capacities. This matters because your rights and our responsibilities differ between them.

a) When we act as a “controller” for data about our own account holders (creators) and website visitors. We decide how and why this data is processed. This covers account registration, billing, support, and general use of wump.io.

b) When we act as a “processor” for the audience data a creator collects through their own gates, submission boxes, and forms (for example, the email addresses fans submit to unlock a download). Here, the creator is the controller of that data – they decide why it’s collected and how it’s used, and WUMP processes it on their behalf under our Terms. If you are a fan who submitted your email to a creator’s gate and you want your data removed, you can contact us at [email protected] and we will act on it, and/or contact the creator directly.

3. Personal data we collect

From creators (account holders):

  • Account details: name, email address, password (stored hashed, never in plain text).
  • Billing information, if you purchase a paid plan. [Payments are handled by Stripe]
  • Content you upload, such as cover images and links.
  • Social media account URLs and OAuth authorisations you connect (e.g. SoundCloud, Spotify) to enable follow/engagement features.
  • Your connected email-marketing provider credentials/tokens, if you enable an integration (e.g. Brevo, MailerLite, Kit, EmailOctopus).

From fans/visitors (audience data – WUMP as processor for the creator):

  • Email addresses submitted to a creator’s download gate or submission box.
  • Submission details where applicable (e.g. a URL, title, and optional message).
  • Verification data used to confirm an email is genuine.

Collected automatically:

  • Basic usage and analytics data, including visit counts to gates and submission pages.
  • Cookies and similar technologies.

4. How and why we use personal data (and our legal basis)

Under UK GDPR we must have a lawful basis for each purpose. We rely on the following:

  • To provide the Service (create and run your account, render gates, process submissions) – legal basis: performance of a contract.
  • To verify email addresses submitted through gates/forms, using a third-party verification provider, so creators collect genuine addresses – legal basis: legitimate interests (ensuring data quality and reducing abuse), and/or performance of the creator’s contract where WUMP is processor.
  • To send transactional emails, such as one-time verification codes – legal basis: performance of a contract/legitimate interests.
  • To process payments for paid plans – legal basis: performance of a contract.
  • To sync collected emails to a creator’s chosen email provider, where the creator has enabled that integration – legal basis: the creator’s instruction as controller.
  • To maintain security, prevent fraud and abuse, and keep the Service reliable – legal basis: legitimate interests.
  • For analytics to understand and improve the Service – legal basis: consent (where required for non-essential cookies) and/or legitimate interests.

We do not sell personal data, and we do not use fans’ email addresses for our own marketing. Audience data belongs to the creator who collected it.

5. One-time passcodes and verification

Some gates and forms ask a fan to verify their email with a short one-time code. We send this code by email to confirm the address is real and belongs to the person using it. These codes are time-limited and are not used for any other purpose.

6. Third parties and sub-processors

We use trusted third-party services to run the Service. Each processes personal data only as needed for its function. Current providers include:

  • Stripe – payment processing.
  • Postmark (ActiveCampaign) – sending transactional email (e.g. verification codes).
  • Cloudflare – content delivery and security.
  • Google (Analytics) – website analytics.
  • Email marketing providers you choose to connect – Brevo, MailerLite, Kit, EmailOctopus – used only when a creator enables that integration, to sync that creator’s own collected emails.
  • SoundCloud, Spotify and similar platforms – where a fan authorises a follow/engagement action, the relevant OAuth data is used only to perform that action.

7. International data transfers

Some of our providers process data outside the United Kingdom (for example, in the United States). Where data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum, EU Standard Contractual Clauses, or a provider’s certification under an approved framework.

8. How long we keep data

  • Account data: for as long as your account is active, and for a reasonable period afterwards as needed for legal, accounting, or security purposes.
  • Verification records: short-lived; verified-email records used to skip repeat verification expire automatically.
  • Audience data collected by a creator: retained while the creator’s account is active or until the creator deletes it. Creators can remove collected emails at any time.
  • When data is no longer needed, we delete or anonymise it.

9. Cookies

We use cookies and similar technologies to keep you logged in, secure the Service, and, with your consent where required – to measure usage via analytics.

10. Your rights

Under UK GDPR you have the right to: access your data; correct inaccurate data; erase your data; restrict or object to processing; data portability; and to withdraw consent where we rely on it. You also have the right to lodge a complaint with the UK’s Information Commissioner’s Office (ICO) at ico.org.uk.

To exercise any of these rights, email [email protected]. If your request concerns data a creator collected about you (where WUMP is a processor), we may need to refer you to, or coordinate with, that creator.

11. Security

We protect personal data with appropriate technical and organisational measures, including encryption in transit (HTTPS), hashed password storage, access controls, and a security/firewall layer in front of the Service. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.

12. Children

The Service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact [email protected] and we will delete it.

13. Changes to this policy

We may update this policy from time to time. We’ll post the updated version here and change the “Last updated” date above. Significant changes will be communicated where appropriate.

14. Contact

Questions about this policy or your data: [email protected].