Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how OnlyVega — the talent "hire network" and agency workspace, together the "Service" — collects, uses, shares, and protects personal data, and the rights you have over it. It describes what the Service actually does: we collect only what the Service needs to operate, we do not sell your data, and we run no advertising or third-party analytics.
Note: this document is a plain-language template prepared for the operator of the Service. It is not legal advice. Before relying on it, the operator should have it reviewed by a qualified lawyer for the relevant jurisdictions.
Who We Are
OnlyVega is a business-to-business software platform for creator-economy management agencies. It provides a public profile and "hire network" for industry workers, and a private workspace where an agency manages its team, creators, sales, payouts, and analytics. OnlyVega manages agencies' own business records only — it does not host adult content, and it does not connect to, log into, or access any OnlyFans, Fansly, or similar creator account.
The Service is operated by OnlyVega and is reachable at support@onlyvega.com (in this policy, "OnlyVega", "we", "us", or "our"). We are the controller responsible for the personal data described here. For any privacy question, or to exercise your rights, contact us at support@onlyvega.com.
What Data We Collect
We collect the following categories of personal data:
- Account and profile — the email address you sign in with, your password (kept only as a bcrypt hash, never in plain text), and the profile details you choose to add: display name, headline, bio, country, timezone, languages, skills, a Telegram handle, an accent colour, and an optional profile photo you upload. Your account also records its type (individual talent or agency) and its status.
- Privacy preferences — your leaderboard-visibility and work-history-visibility settings, and your "open to work" availability flag.
- Employment and work history — the trust record at the heart of the network: the companies you have worked with, job titles, start and end dates, how an engagement ended (currently working, resigned, terminated, or mutual agreement), whether a record is verified or confirmed, and any dispute you raise, including your dispute note and the company's reply. These records may be created by you or by an agency you work with.
- Agency and team membership — if you belong to an agency workspace: your role (owner, manager, team lead, chatter, or HR), your commission percentage, your supervisor link, and your membership status; and, for a company, its name, description, website, Telegram, size, and subscription plan.
- Jobs and applications — job posts an agency publishes, and the applications you submit, including a free-text cover note and the application's status.
- Creator management data — for agency workspaces, the business metadata of the creators an agency manages: a stage name, a platform tag (for example OnlyFans, Fansly, or other), and revenue-split settings. This is relationship and accounting metadata only — the Service does not connect to any creator-platform account and hosts no adult content.
- Financial records — for agency workspaces, the operating records your team enters: sales (the amount a fan paid, the revenue split, and who logged it), payouts (amount, period, and method, typically a USDT crypto transfer), refunds, and agency expenses. These feed the split, payout, and analytics calculations.
- Billing and subscription — when an agency subscribes, we record the plan, term, amount, the payment provider used, an invoice or order reference, the payment status, the pay currency, and the crypto transaction hash of a completed payment. We never receive or store card or bank-account numbers — payment itself happens on the provider's own hosted crypto checkout.
- Contests and achievements — agency-run contests (metric, period, and winner) and a permanent per-user achievement record (title, type, period, company, and award date) that stays on your profile.
- Recruiting and HR — if an agency uses the recruiting tools, the details of prospective hires it enters: name, contact (email or handle), source, target role, funnel stage, notes, interview schedules and outcomes, and onboarding checklist items.
- Audit and governance — an append-only log of money-affecting actions (such as approving a sale or activating a plan), recording who acted, what they did, the target, the amount, and the time.
- Technical, session, and security data — to keep the Service secure we log sign-in and sign-up attempts with the email entered, the IP address, whether the attempt succeeded, and the time (used to rate-limit abuse), and we keep short-lived, single-use password-reset tokens. A session cookie keeps you signed in.
- Identity verification (optional) — only if you choose to apply for the verified badge: photographs of a government-issued identity document (passport, national ID card, or driver's licence) and a selfie holding that document together with a short handwritten code we generate, plus the document type, the IP address the submission came from, and the review outcome. This is special-category-adjacent identity data and we treat it accordingly: the images are encrypted at rest, are readable only by our review team through an access-logged internal viewer, are never shown to agencies or on your profile, and are deleted automatically once the retention window passes — the verified badge itself remains. Providing these documents is entirely optional; the rest of the Service works without them.
A profile or record marked "verified" can mean two different things: an employment record confirmed by the agency within the Service, or — where the blue check and the "Government ID verified" label appear — an identity our team checked against a government-issued document. Agencies see only the fact of verification, never your documents.
How and Why We Use Your Data
We use personal data for the purposes below. For each, we note the legal basis we rely on under the GDPR (and equivalent laws):
- Run your account and provide the Service — display profiles and records to the right people, calculate revenue splits and payouts, and process job posts and applications. Legal basis: performance of our contract with you (or with your agency).
- Maintain the employment trust record — keep work history and achievements available, subject to your visibility settings, so the network stays reliable. Legal basis: our legitimate interest in a trustworthy professional network, and the contract for members who rely on it.
- Operate agency finances — record and calculate sales, payouts, refunds, and expenses, and maintain the audit log. Legal basis: our contract, our legitimate interest in accurate operations, and, for accounting records, our legal obligations.
- Process subscription payments — take and confirm crypto payments through our payment providers. Legal basis: performance of our contract.
- Keep the Service secure — authenticate logins, rate-limit sign-in and sign-up, detect and prevent abuse and fraud, and maintain the audit trail. Legal basis: our legitimate interest in security, and our legal obligations.
- Communicate with you — send account and security messages such as password resets, and respond to your support requests. Legal basis: our contract and our legitimate interest in supporting users.
- Optional features you switch on — where a feature is genuinely optional (for example, adding a Telegram handle or a profile photo), the legal basis is your consent, which you can withdraw by removing the information.
Who We Share Data With
We do not sell your personal data and we do not share it for advertising. We share it only with the providers that make the Service work, and only as far as needed:
- Payment providers — Cryptomus and NOWPayments process agency subscription payments. When you pay, we send the plan amount and an order reference to the provider and you complete payment on the provider's hosted page; the provider handles the crypto transaction and the related payment and currency data, and confirms the result back to us.
- Hosting — our hosting provider (Hostinger) runs the servers and the database that store the data, acting as our processor under our instructions.
- Google Fonts — our pages load fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When your browser fetches them, Google receives your IP address and browser user-agent.
- Cloudflare (icons) — we load icon styles from Cloudflare's cdnjs. When your browser fetches them, Cloudflare receives your IP address and browser user-agent.
- Transactional email — password-reset and similar account emails are sent from our own server's mail system; we do not use a third-party email marketing service.
- Legal and safety — we may disclose data where the law requires it, or to protect our rights, our users, or the security of the Service.
The Service uses no push-notification service, no Google Analytics, no tag managers, no advertising pixels, and no cross-site tracking. A Telegram handle you enter is a contact detail, not an integration.
International Data Transfers
Our providers and the content-delivery networks above may process data on servers located outside your country, including outside the EEA. Where personal data is transferred internationally, we rely on appropriate safeguards for such transfers (for example, the European Commission's Standard Contractual Clauses, where applicable). Contact us for more detail.
Cookies and Local Storage
- Session cookie — we set one session cookie (by default named PHPSESSID) to keep you signed in. It is strictly necessary, is marked HttpOnly and SameSite=Lax, and is sent only over HTTPS when the Service is served securely.
- Appearance preferences — your browser stores two settings in local storage: your light/dark theme and your accent colour. They stay in your browser, are never sent to our servers, and are not used to track you.
- No trackers — we set no advertising, analytics, or cross-site tracking cookies, and we use no tracking pixels or tag managers.
How Long We Keep Data
We keep personal data for as long as your account exists and as long as we need it for the purposes above. Some data is kept longer by design:
- Accounts — accounts persist until removed. Rather than deleting an account, we may set it to a banned or inactive status where needed for safety or to enforce our terms.
- Employment history — this is a long-lived trust record. It stays on the network (subject to your history-visibility setting) even after you leave an agency, and an agency can always see the records of its own former workers.
- Achievements — once awarded, an achievement remains on your profile permanently, even after a leaderboard resets or you leave an agency.
- Audit log — the audit log is append-only and retained so that every money-affecting action stays traceable to an actor.
- Financial records — sales, payouts, refunds, expenses, and billing are kept as the agency's operating and accounting record.
- Security data — password-reset tokens expire quickly and are single-use; sign-in attempt logs are kept for abuse prevention.
The public Service does not yet offer self-service data export or account deletion. To request access to, a copy of, correction of, or deletion of your personal data, email us at support@onlyvega.com from your account address and we will action it in line with your rights and our legal obligations. Note that where an agency has recorded data about its own operations, it may need to retain those records.
Your Rights
Depending on where you live (including under the GDPR in the EEA and UK), you have some or all of these rights over your personal data:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — ask us to correct data that is inaccurate or incomplete.
- Erasure — ask us to delete your data, subject to records we are required or entitled to keep.
- Restriction and objection — ask us to pause certain processing, or object to processing based on our legitimate interests.
- Portability — ask to receive certain data in a portable, machine-readable format.
- Withdraw consent — for anything based on your consent, withdraw it at any time.
- Complain — lodge a complaint with your local data-protection supervisory authority.
You already control much of your data directly in the Service: you can edit your profile (headline, bio, country, timezone, languages, skills, Telegram, and "open to work"), choose whether you appear on the leaderboard and whether outsiders can see your work history, upload or remove your profile photo, dispute an employment record you disagree with, reset your password by email, and switch theme and language.
For anything not available in the Service — including a full data export or account deletion — email support@onlyvega.com from your account address; we will respond within a reasonable time and within any period the law requires.
How We Protect Data
We take reasonable technical and organizational measures to protect personal data, including: passwords stored only as bcrypt hashes (never in plain text); session cookies marked HttpOnly and SameSite=Lax, and Secure over HTTPS; CSRF protection on form submissions; role- and capability-based access control, so workspace data is visible only to authorized members; an append-only audit log of money-affecting actions; and security headers, including a Content-Security-Policy, on responses. We never store card or bank-account numbers. No system is completely secure, but we design for security by default and review our practices.
Children
OnlyVega is a business tool for adults. You must be at least 18 to use the Service, and it is not directed to children. We do not knowingly collect personal data from anyone under 18; if you believe a minor has provided us data, contact us and we will remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on this page with a new "last updated" date and, where appropriate, notify you through the Service or by email.
Contact
Questions about this policy or your personal data, or to exercise your rights, contact OnlyVega at support@onlyvega.com.
See also our Terms of Service.