This Privacy Policy describes how Reminiscent Road Media LLC collects, uses, and protects information from subscribers to Reminiscent Chronicles. Please read this policy carefully.
Section 1
Introduction & Identity of Data Controller
1.1 Who We Are. This Privacy Policy is published by Reminiscent Road Media LLC ("RRM," "we," "our," or "us"), a Texas limited liability company located in Houston, Texas. RRM operates Reminiscent Chronicles, a software-as-a-service application designed for creative businesses to manage their client relationships, gallery deliveries, contracts, invoices, questionnaires, and business analytics.
1.2 Scope of This Policy. This Privacy Policy applies to personal data and information that RRM collects from Platform subscribers and their Authorized Users — the businesses and individuals who subscribe to Reminiscent Chronicles. This policy does not govern the personal data of the subscribers' own clients, which is governed instead by our Data Processing Addendum (DPA).
1.3 Data Controller. RRM is the Data Controller for the personal data described in this Privacy Policy. You may contact us at any time regarding this policy at: info@reminiscentroadmedia.com.
Section 2
What We Collect
2.1 Account Information. When you register for the Platform, we collect information necessary to create and manage your account, including: your name or business name; email address; phone number; business address; and your selected subscription tier.
2.2 Billing Information. We collect information necessary to process your subscription payments, including: billing name and address; and payment card details. Payment card numbers and financial details are processed directly by Stripe, Inc. and are not stored by RRM on its own systems. We retain records of transaction amounts, dates, and Stripe transaction identifiers.
2.3 Business Data Uploaded to the Platform. In using the Platform's features, you may upload or create data relating to your own business operations, including: client contact records and communications; project information, media files, and gallery content; contracts, invoices, and financial documents; questionnaire responses; and other business-related information you choose to enter into the Platform.
2.4 Usage and Analytics Data. We automatically collect information about how you interact with the Platform, including: features accessed and frequency of use; session duration and timestamps; error logs and performance metrics; IP address and general geographic region; and browser type and device type (not fingerprinting data).
2.5 Cookies and Device Information. We use functional cookies and similar technologies to support your authenticated session and maintain your login state. We do not use advertising cookies or cross-site tracking technologies. Please see Section 9 for further details.
2.6 Communications. If you contact our support team or communicate with us via email, we retain records of those communications and any information you choose to share in them.
Section 3
How We Use Your Information
3.1 Providing the Service. We use your information primarily to provide, operate, maintain, and improve the Platform services you have subscribed to, including authenticating your identity, processing your instructions within the Platform, and delivering all features of your selected subscription tier.
3.2 Billing and Account Management. We use billing information to process subscription payments, send invoices and receipts, manage subscription renewals, and communicate about account status, payment issues, and changes to your plan.
3.3 Customer Support. We use information you provide and usage data to diagnose issues, respond to support requests, and provide technical assistance.
3.4 Platform Improvement. We use aggregated and anonymized usage analytics to understand how the Platform is used, identify bugs and performance issues, develop new features, and improve the overall user experience. This processing does not identify individual users.
3.5 Communications. We send transactional communications (subscription confirmations, invoices, payment receipts, service notices, security alerts) and, where you have not opted out, informational communications about Platform updates and new features. We do not engage in unsolicited marketing.
3.6 Legal Compliance and Safety. We use information as necessary to comply with applicable laws and regulations, respond to lawful requests from public authorities, enforce our agreements, protect the rights and safety of RRM and others, and prevent fraud and abuse.
Section 4
Legal Basis for Processing (GDPR)
For subscribers who are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases for processing personal data:
| Processing Activity |
Legal Basis |
| Account creation, authentication, and Platform provision |
Contract Performance (Art. 6(1)(b) GDPR) — necessary to perform the SaaS License Agreement |
| Billing and payment processing |
Contract Performance (Art. 6(1)(b) GDPR) |
| Customer support and technical assistance |
Legitimate Interests (Art. 6(1)(f) GDPR) — RRM's legitimate interest in providing quality service |
| Platform improvement using aggregate analytics |
Legitimate Interests (Art. 6(1)(f) GDPR) — RRM's legitimate interest in improving the Platform |
| Marketing communications about Platform features |
Consent (Art. 6(1)(a) GDPR) — you may withdraw consent at any time |
| Compliance with legal obligations (tax records, etc.) |
Legal Obligation (Art. 6(1)(c) GDPR) |
Section 5
Sharing Your Information
5.1 No Sale of Personal Data. RRM does not sell, rent, or trade your personal information to any third party for such party's own commercial purposes.
5.2 Service Providers (Sub-Processors). We share information with the following trusted service providers solely to enable the delivery of Platform services:
| Provider |
Purpose |
Data Shared |
| Google LLC (Firebase) |
Database, authentication, cloud infrastructure |
Account data, platform data, usage logs |
| Stripe, Inc. |
Payment processing |
Billing name, address, payment card data |
| Resend, Inc. |
Transactional email delivery |
Email address, message content |
5.3 Legal Requirements. We may disclose your information to law enforcement, courts, or other governmental bodies when we are legally required to do so, or when we believe disclosure is necessary to protect the rights, property, or safety of RRM, our subscribers, or the public.
5.4 Business Transfers. In the event of a merger, acquisition, or sale of all or substantially all of RRM's assets, your information may be transferred as part of that transaction. We will notify you by email prior to your information becoming subject to a different privacy policy.
Section 6
Data Retention
6.1 Active Subscriptions. We retain your personal data and business data for the full duration of your active subscription.
6.2 Post-Termination. Following termination or expiration of your subscription, we retain your data for a period of thirty (30) days to enable you to export your data. After this period, your data is deleted from production systems.
6.3 Billing and Financial Records. We retain billing records, invoices, and payment transaction history for a period of seven (7) years following the relevant transaction date, as required by applicable U.S. tax and accounting laws and regulations.
6.4 Legal Hold. We may retain specific data for longer periods if required by applicable law, court order, or governmental authority, or where the data is reasonably necessary for ongoing legal proceedings.
6.5 Support and Communications. Records of support communications are generally retained for twelve (12) months unless a longer retention period is required for legal or contractual reasons.
Section 7
Security
7.1 Security Measures. RRM takes the security of your data seriously. We implement industry-standard technical and organizational security measures appropriate to the nature of the data we process, including: AES-256 encryption of data at rest via Firebase/Google Cloud infrastructure; TLS 1.2+ encryption for all data in transit; role-based access controls limiting access to personal data; multi-factor authentication options for accounts; regular review of our security practices; and incident response procedures.
7.2 No Absolute Guarantee. While we employ robust security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your information and encourage you to use strong, unique passwords and enable available security features on your account.
7.3 Breach Notification. In the event of a data breach that is likely to result in a risk to your rights and freedoms, RRM will notify you without undue delay in accordance with applicable law and the terms of the Data Processing Addendum.
Section 8
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data in certain circumstances ("right to be forgotten").
Right to Portability
Receive your personal data in a structured, machine-readable format.
Right to Restriction
Request that we restrict processing of your data in certain circumstances.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
CCPA: Right to Know
Know what personal information we collect and how it is used and shared.
CCPA: Right to Delete
Request deletion of personal information, subject to exceptions.
CCPA: Right to Opt-Out
Opt-out of the sale or sharing of personal information. (RRM does not sell data.)
CCPA: Non-Discrimination
Exercise CCPA rights without receiving discriminatory treatment from RRM.
8.1 How to Exercise Rights. To exercise any of the above rights, submit a written request to info@reminiscentroadmedia.com with the subject line "Privacy Rights Request." We will respond to verified requests within thirty (30) days. We may ask you to verify your identity before processing your request.
8.2 Right to Lodge a Complaint. If you are located in the EEA or UK and believe we have processed your personal data in violation of applicable law, you have the right to lodge a complaint with your local data protection supervisory authority.
Section 9
Cookies
9.1 Cookies We Use. Reminiscent Chronicles uses only strictly necessary / functional cookies required to operate the Platform. These include: authentication session cookies that maintain your logged-in state; security cookies that help protect against cross-site request forgery; and user preference cookies that remember your display and language settings.
9.2 No Advertising Cookies. RRM does not use advertising cookies, cross-site tracking technologies, or any cookies designed to build profiles for targeted advertising. We do not allow third-party advertising networks to place cookies on our Platform.
9.3 Cookie Management. Because we only use strictly necessary cookies, cookie consent banners are not required for Platform operation. You may disable cookies in your browser settings; however, doing so will prevent you from logging in to or using the Platform.
Section 10
International Transfers
10.1 Data Location. RRM is based in the United States, and your personal data is primarily stored and processed in the United States via Firebase/Google Cloud infrastructure.
10.2 EEA and UK Subscribers. If you access the Platform from the European Economic Area or the United Kingdom, please be aware that your personal data may be transferred to, stored, and processed in the United States, which may not provide the same level of data protection as your country of residence. Where such transfers occur, RRM relies on the European Commission's Standard Contractual Clauses (or UK equivalent International Data Transfer Agreements) as the appropriate safeguard for such transfers, in conjunction with Google Cloud's compliance mechanisms.
10.3 Additional Safeguards. RRM implements supplementary technical and organizational measures (including encryption and access controls described in Section 7) to protect personal data transferred internationally.
Section 11
Children's Policy
11.1 Business Platform — Adults Only. Reminiscent Chronicles is a professional software service intended exclusively for use by business entities and adult individuals (aged 18 or older). We do not knowingly collect personal data from individuals under the age of 18.
11.2 Inadvertent Collection. If we become aware that we have inadvertently collected personal data from a person under the age of 18, we will take prompt steps to delete such information. If you believe we may have such information, please contact us immediately at info@reminiscentroadmedia.com.
Section 12
Changes to This Policy
12.1 Updates. RRM may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or for other operational reasons. We will provide notice of material changes at least thirty (30) days before such changes take effect by sending an email notification to your registered email address and/or by posting a prominent notice on the Platform.
12.2 Continued Use. Your continued use of the Platform after the effective date of a revised Privacy Policy constitutes your acknowledgment of the changes. If you do not accept the revised policy, you should discontinue use of the Platform and terminate your subscription.
12.3 Version History. We maintain a version history of this Privacy Policy. You may request a copy of a prior version by contacting us at info@reminiscentroadmedia.com.
Section 13
Contact Us