We don't sell your information and we don't run ads. Here's exactly what we collect, why, and how long we keep it.
Version 1.6 Thankly LLC getthankly.com
This Privacy Policy explains what information Thankly LLC collects, how we use it, and the choices you have. By using the Platform, you agree to this policy.
Stripe Identity may use facial recognition technology to compare a selfie against your government-issued ID during verification. This constitutes collection of a biometric identifier.
Retention policy for all users:
State-specific protections:
Certain data we collect qualifies as Sensitive Personal Information (SPI) under the CPRA, including government-issued identification numbers. Thankly only collects and uses SPI to perform services specifically permitted under the CPRA (payment processing, identity verification, fraud prevention). Because our use is strictly limited to these permitted purposes, Thankly is not required to offer a “Limit the Use of My Sensitive Personal Information” opt-out link, and no such link is provided.
Thankly utilizes SMS messaging exclusively for account authentication and security-related notifications, such as one-time passwords (OTP). We collect your mobile number when you provide it during registration and consent to receive these messages. We do not use your phone number for marketing or promotional purposes.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of data sharing described in this policy exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties. We may share your mobile number only with trusted service providers (such as Twilio, our SMS delivery provider) who assist us in operating the verification messaging program, and only to deliver those messages on our behalf.
Message frequency: messages are sent only during account signup and authentication. Message and data rates may apply depending on your mobile carrier plan. Reply STOP to opt out, HELP for help, or contact hello@getthankly.com for assistance.
SMS messages are sent from our registered number +1 (407) 759-7255 via Twilio, our A2P 10DLC registered SMS provider, under the “Two-Factor Authentication” use case, covering all OTP and verification messages sent during account signup and authentication.
Right to know, delete, correct, and opt out of sale or sharing of personal data. We do not sell personal data. Contact hello@getthankly.com to exercise rights. No discrimination for exercising CCPA/CPRA rights.
Rights to access, correct, delete, portability, and opt out of targeted advertising. Contact hello@getthankly.com.
Written biometric consent obtained in-app before any collection. Written retention and destruction schedule available on request. Contact hello@getthankly.com.
The Platform is not directed to users under 18. Accounts belonging to minors will be deleted immediately upon discovery.
Contact hello@getthankly.com. We respond within 30 days.
We retain account data for the account lifetime plus 3 years. Transaction records are retained 7 years. Identity verification records are retained 5 years post-closure. Biometric data is deleted on verification or within 3 years maximum.
| Data type | Retention period | Legal basis |
|---|---|---|
| Account & registration data | Account lifetime + 3 years | Legal compliance |
| Transaction records | 7 years | IRS / financial regulations |
| Identity verification records | 5 years post-closure | AML / KYC requirements |
| Biometric data (if collected) | Deleted on verification or 3 years max | BIPA / state biometric laws |
| Earnings reports | Available while account is active | User service |
| Support communications | 3 years | Dispute resolution |
| Analytics / usage data | 2 years | Service improvement |
| Marketing consent records | 3 years post opt-out | Consent documentation |
We retain this data to provide and improve services, comply with financial and tax regulations, resolve disputes, enforce agreements, and support workers’ earnings documentation needs.
Apple App Store guidelines require an in-app account deletion option. Thankly’s deletion button initiates a two-phase process.
A written confirmation email is sent specifying what was deleted immediately and what is being archived, and for how long.
To request deletion outside the app, email hello@getthankly.com. The same two-phase process applies. We respond within 30 days.
Stripe retains payment and identity data under its own legally mandated schedules. Requests regarding Stripe-held data must be directed to Stripe.
We use TLS encryption in transit, access controls, and PCI DSS Level 1 payment handling via Stripe. We will notify you of breaches as required by applicable law.
Material changes are communicated 14 days in advance by email or in-app notice. Continued use constitutes acceptance.
hello@getthankly.com · Thankly LLC, Florida, United States