Privacy Policy

Your privacy
matters to us

We are committed to protecting your personal data and clearly explaining how we use it.

Effective: May 6, 2026 · Version 1.0 Personal data protection Law 1266/2008 · Law 1581/2012
This document explains what data we collect, how we use it, and what rights you have.

4U

PRIVACY POLICY AND PERSONAL DATA PROCESSING

Version 2.2 | Effective: September 2026


Applies to: Buyers • Insiders • Creators • Sellers

Domestic operations (Colombia) and international operations (Global Plan)



P0 •GOVERNING PRINCIPLES AND LEGAL BASES FOR PROCESSING

4U processes personal data in accordance with the principles of Colombian Law 1581 of 2012, Decree 1377 of 2013 (consolidated in Decree 1074 of 2015), the Florida Information Protection Act (FIPA), the California Consumer Privacy Act (CCPA/CPRA), the EU General Data Protection Regulation (GDPR) where applicable, and all other regulations applicable to the data subject's jurisdiction.

P0.1 Applicable principles

  1. Lawfulness: processing is strictly subject to applicable law.
  2. Purpose limitation: processing serves legitimate, specific, and informed purposes.
  3. Freely given consent: processing requires prior, express, and informed authorization, except where legal exceptions apply.
  4. Data accuracy: information must be truthful, complete, accurate, up-to-date, verifiable, and understandable.
  5. Transparency: data subjects may obtain information about the existence of data concerning them at any time.
  6. Restricted access and circulation: processing is limited to authorized personnel and within legal boundaries.
  7. Security: technical, human, and administrative measures are in place to protect personal data.
  8. Confidentiality: information remains protected even after the relationship ends.
  9. Data minimization and proportionality: only strictly necessary data is collected and processed.
  10. Accountability: 4U maintains documented measures to demonstrate compliance at all times.

P0.2 Legal bases for processing

Depending on the jurisdiction and specific purpose, processing is grounded in one or more of the following legal bases:

  1. Prior, express, and informed consent of the data subject (Article 9, Law 1581 of 2012 and equivalents).
  2. Performance of a contract or pre-contractual measures to which the data subject is party.
  3. Compliance with a legal obligation (KYC, AML/CFT, tax obligations, regulatory reporting).
  4. Legitimate interest of 4U or a third party, provided it does not override the rights and freedoms of the data subject. For each processing activity based on legitimate interest, 4U maintains a documented Legitimate Interest Assessment (LIA) available upon request from a competent authority.
  5. Protection of the vital interests of the data subject or another natural person.
  6. For EU users: the legal bases under Article 6 of the GDPR.

Commercial purposes, direct marketing, non-essential cookies, and processing of sensitive or biometric data always require explicit, specific, separate, and revocable authorization, obtained through a standalone granular consent flow independent from the general registration process.


P1 • DATA CONTROLLERS

The 4U platform is operated by two legal entities depending on the jurisdiction and type of user operation:



FINDIT SAS (Colombia)3SENSE TECHNOLOGY LLC (Florida, EE.UU.)
NIT / EINNIT 901.638.597-0EIN 36-4910894
AddressCll 2 S 20 211, Medellín, Colombia19391 SW 15 ST, 33029, Florida, EE.UU.
Data emaildatos@4u.socialprivacy@4u.social
Support emailsoporte@4u.socialsupport@4u.social
Applies toUsers domiciled in Colombia or transacting in COP.Users outside Colombia or transacting in USD under the Global Plan.
Legal frameworkLaw 1581 of 2012, Decree 1377 of 2013, Law 1266 of 2008.FIPA, CalOPPA, CCPA/CPRA (California), GDPR (EU users).
DPO / Data OfficerData Protection Officer designated. Contact: datos@4u.socialData Protection Officer designated. Contact: privacy@4u.social


Where this Policy refers to '4U' without specifying the entity, it shall be understood to refer to the responsible entity per the user's jurisdiction. Both entities operate in coordination under the same data protection standards described herein.

The databases of FINDIT SAS are registered or in the process of registration with the National Database Registry (RNBD) of the Colombian Superintendence of Industry and Commerce (SIC), pursuant to Circular 002 of 2015.


P2 •PERSONAL DATA COLLECTED BY ROLE

4U collects only the data necessary to operate the platform for each user role (data minimization principle):


Data collectedBuyer / InsiderCreatorSellerMain purpose
Full nameSí / YesSí / YesSí / YesIdentification, contracts, billing
Date of birthSí / YesSí / YesNoAge verification (18+)
Identity documentSí / YesSí / YesSí / YesKYC, fraud prevention and AML/CFT
Email addressSí / YesSí / YesSí / YesCommunications, support, notifications
Mobile phoneSí / YesSí / YesSí / YesVerification, support, notifications
Delivery addressSí / YesSí / YesSí / YesLogistics, delivery and KYC
Banking / payment dataGateway*Commission accountSettlement accountPayment processing and settlements
Transaction historySí / YesYes (commissions)Yes (sales)Commercial management, support, compliance
Published contentReviewsVideos, posts, reelsPhotos, pricesPlatform operation and marketing
Technical data (IP, device)Sí / YesSí / YesSí / YesSecurity, analytics, service improvement
Identity photo (sensitive/biometric data) **Sí / YesSí / YesSí / YesFraud prevention, KYC. Separate consent required.


* Full card details are processed directly by the payment gateway. 4U does not store full card numbers or security codes. Processing is conducted under PCI-DSS standards.

** Identity document photographs and any biometric verification data are classified as sensitive data (Article 5, Law 1581 of 2012; Article 9, GDPR). Their processing requires EXPLICIT, SEPARATE, and INFORMED authorization, obtained through an independent consent screen during the verification process.


P3 •PROCESSING PURPOSES BY ROLE

P3.1 Buyers and general users

Personal data is used to:

  1. Create and manage user accounts (basis: contract / consent).
  2. Process and track orders (basis: contract).
  3. Verify identity and prevent fraud (basis: legal obligation / legitimate interest / consent).
  4. Send order status notifications, updates, and support communications (basis: contract / legitimate interest).
  5. Send commercial and promotional communications (basis: express, revocable consent).
  6. Conduct statistical analysis and platform improvement using aggregated or pseudonymized data (basis: legitimate interest — LIA on file).
  7. Comply with legal obligations and report to authorities when required by law (basis: legal obligation).
  8. Handle requests, complaints, and claims — PQRS (basis: legal obligation / contract).

P3.2 Insiders (active membership users)

In addition to Buyer purposes:

  1. Manage Insider membership subscription and billing cycle (basis: contract).
  2. Enable priority access to private Drops, special pricing, and exclusive content (basis: contract).
  3. Personalize experience based on purchase history and preferences (basis: consent / legitimate interest — LIA on file).
  4. Notify renewals, price changes, or modifications to membership benefits (basis: contract / legitimate interest).

P3.3 Creators

In addition to Buyer purposes:

  1. Manage Creator onboarding and commercial agreements with Sellers (basis: contract).
  2. Calculate, settle, and transfer commissions for sales generated through their content (basis: contract / legal obligation).
  3. Publish content on the platform and, with separate specific authorization, in 4U marketing materials (basis: contract + marketing consent).
  4. Retain published Creator content for the duration of the contract and for a maximum of 90 calendar days following offboarding, after which it will be deleted or anonymized.
  5. Verify identity and compliance with Creator requirements (basis: legal obligation / consent).
  6. Comply with tax obligations arising from commission payments (basis: legal obligation).

P3.4 Sellers

In addition to Buyer purposes:

  1. Manage contractual onboarding and compliance with the Seller Agreement (basis: contract).
  2. Publish and promote products on the platform (basis: contract).
  3. Calculate, settle, and transfer sale proceeds net of commissions (basis: contract / legal obligation).
  4. Verify compliance with applicable legal and regulatory requirements (INVIMA, SIC, DIAN, or equivalents) (basis: legal obligation).
  5. Manage buyer claims related to their products (basis: contract / legal obligation).
  6. Comply with applicable tax and withholding obligations (basis: legal obligation).
  7. Prevent money laundering and terrorism financing (AML/CFT) in accordance with applicable regulations (basis: legal obligation).


P4 • DATA TRANSFERS AND DISCLOSURES

Personal data may be shared with the following third parties, solely for the purposes described in this Policy:

  1. Payment gateways: ePayco (COP), Stripe and PayPal (USD), under their own privacy policies and PCI-DSS standards.
  2. Carriers and logistics operators: buyer data necessary for delivery (name, delivery address, contact number).
  3. Technology service providers: cloud storage, data analytics, communication tools — under data processing agreements with confidentiality obligations and restricted access.
  4. Sellers: receive buyer name, delivery address, and phone number to process and fulfill the order. They do not receive full payment data.
  5. Creators: receive anonymized or aggregated data on content performance. They do not receive buyers' personal data without the data subject's express consent.
  6. Judicial, administrative, or regulatory authorities (SIC, DIAN, Fiscalía, IRS, or others): when required by law or pursuant to a court order.
  7. Shareholders and affiliated entities of the Operator: for internal administrative purposes, under the same protection standards.

4U does NOT sell personal data to third parties for their own commercial purposes under any circumstances.

P4.1 International data transfers

The transfer of data between FINDIT SAS (Colombia) and 3SENSE TECHNOLOGY LLC (Florida, USA) is carried out under the following safeguards:

  1. Colombia recognizes the United States as a country with adequate data protection (SIC External Circular 05 of 2017 and updates).
  2. Confidentiality contractual clauses and, where applicable, model contractual clauses pursuant to SIC External Circular 003 of 2025 are in place between the two entities.
  3. Compliance with the Florida Information Protection Act (FIPA) by 3SENSE TECHNOLOGY LLC.
  4. For EU users: transfers are conducted under GDPR-compatible mechanisms (Standard Contractual Clauses — SCCs). EU users may request a copy of applicable safeguards by writing to privacy@4u.social.
  5. For transfers to countries without recognized adequate protection: 4U will only proceed with the data subject's express authorization or an applicable exception under Article 26 of Law 1581 of 2012.


P5 • DATA RETENTION

  1. Active account data: retained for the duration of the contractual relationship with 4U.
  2. Transaction data: minimum 5 years from the transaction date (accounting and tax obligations).
  3. Identity document images and biometric data: deleted within 12 months of account deactivation, unless a longer retention period is required by law.
  4. Fraud prevention and AML/CFT data: up to 10 years as required by regulations.
  5. Minors' data: processed under legal guardian authorization and deleted upon account closure or guardian's request.
  6. Creator content: deleted or anonymized within 90 calendar days of the Creator's offboarding, except content tied to active transactions.
  7. Public content (reviews, posts): may remain anonymized after account closure to preserve commercial history integrity, unless the data subject requests deletion.

Upon expiry of each retention period, data will be securely and irreversibly deleted or anonymized.


P6 •COOKIES AND TRACKING TECHNOLOGIES

4U uses first-party and third-party cookies to improve user experience, analyze traffic, and — where expressly authorized by the user — personalize content and advertising.

NOTICE FOR EU USERS: In compliance with the GDPR and the ePrivacy Directive, only essential cookies are activated by default. Analytics, personalization, and advertising cookies require prior explicit consent, granted through the cookie preference panel before activation. Users may withdraw consent at any time without any impact on access to the service.

Third parties setting cookies on the platform:


Third partyCookie typePurposePrivacy policy
Google AnalyticsAnalyticsTraffic and user behavior measurementpolicies.google.com/privacy
Meta PixelAdvertisingRetargeting and conversion measurementfacebook.com/privacy/policy
StripeEssential / paymentSecure payment processingstripe.com/privacy
PayPalEssential / paymentSecure payment processingpaypal.com/privacy
ePaycoEssential / paymentCOP payment processingepayco.co/privacidad
Firebase / GoogleEssential / analyticsAuthentication, push notifications, app analyticspolicies.google.com/privacy


Users can manage preferences at Settings → Privacy → Cookies in the app. Global Privacy Control (GPC) signals will be honored as mandatory opt-out requests under CCPA/CPRA.


P7 • DATA SUBJECT RIGHTS

All data subjects have the following rights, exercisable at any time and free of charge:

  1. Access, update, and correct their personal data.
  2. Request proof of the authorization granted for processing of their data.
  3. Be informed about how their personal data is being used.
  4. Withdraw processing authorization and/or request deletion of their data, within legal limits.
  5. Access their personal data free of charge.
  6. Request data portability in a structured, commonly used, and machine-readable format (JSON or CSV) where recognized by applicable law (particularly GDPR).
  7. Object to processing based on legitimate interest, including profiling for marketing purposes.
  8. Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
  9. Request account deletion and deletion of associated data.
  10. File complaints with the SIC (Colombia) or the competent data protection authority in their country of residence.
  11. Not be discriminated against for exercising any of these rights.

P7.1 Additional rights for international users

California users (USA): under CCPA/CPRA, they have the right to know what data is collected, request its deletion, opt out of its sale or sharing (4U does not sell data), limit the use of sensitive personal information, and not be discriminated against. 4U honors GPC signals as a mandatory opt-out exercise. Contact: privacy@4u.social.

European Union users: under the GDPR, they have the rights of access, rectification, erasure ('right to be forgotten'), portability, objection, restriction of processing, and withdrawal of consent at any time. They may lodge complaints with the supervisory authority of their EU Member State. Contact: privacy@4u.social.


P8 • HOW TO EXERCISE YOUR RIGHTS

  1. Colombia (FINDIT SAS): datos@4u.social
  2. International / Global Plan (3SENSE TECHNOLOGY LLC): privacy@4u.social

The request must include: full name, identity document number or equivalent identifier, description of the right to be exercised, preferred contact method, and if acting as a representative, proof of such capacity.

Response deadlines:

  1. Inquiries: 10 business days (Colombia) / 30 calendar days (USA and international).
  2. Claims: 15 business days (Colombia) / 45 calendar days (USA and international).

Rights of minors must be exercised exclusively by their legal guardians.


P9 •INFORMATION SECURITY AND INCIDENT RESPONSE

4U implements technical, human, and administrative measures to protect personal data:

  1. Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
  2. Role-based access control: only authorized personnel may access sensitive data.
  3. Two-factor authentication for administrative access.
  4. Regular security audits and vulnerability/penetration testing.
  5. PCI-DSS compliance for payment processing.
  6. Data processing agreements with all vendors handling personal data.

Data breach response protocol:

  1. Immediate containment and scope assessment within 24 hours of detection.
  2. Notification to authorities: SIC (Colombia) within 15 business days; Florida Department of Legal Affairs (FIPA) within 30 days of determining a breach occurred. If the incident affects 500+ Florida residents, the Department of Legal Affairs is notified; if it affects 1,000+, consumer reporting agencies are also notified.
  3. Notification to affected data subjects: via email or in-app notification, within the applicable deadline per jurisdiction. The notification will include: estimated incident date, description of affected data, 4U contact details, and protective recommendations.
  4. Documentation of the incident in the Data Breach Register for accountability and audit purposes.


P10 •PROCESSING OF MINORS' DATA

4U is not designed for use by individuals under 18 years of age without supervision by a responsible adult. Minors under 18 who wish to register must do so with the express and verifiable authorization of their legal guardian, who assumes full responsibility for the use of the account.

4U does not knowingly collect personal data from children under 13. If an account created by a child under 13 without authorization is detected, the account will be suspended and all associated data will be immediately deleted.


P11 •CHANGES TO THIS PRIVACY POLICY

This Policy may be updated to reflect changes in platform operations, applicable legislation, or 4U's privacy practices. Material changes will be communicated via email and a prominent in-app notification at least 15 days in advance.

When changes affect purposes for which specific consent was previously obtained (sensitive data, marketing, non-essential cookies), 4U will request a new explicit authorization before applying the new purposes.

For California users, this Policy will be updated at least once every twelve (12) months, as required under CCPA/CPRA.


P12 •GOVERNING LAW, JURISDICTION, AND LIMITATION OF LIABILITY

This Policy is governed by the laws of the Republic of Colombia for users under the responsibility of FINDIT SAS, and by the laws of the State of Florida and the United States of America for users under the responsibility of 3SENSE TECHNOLOGY LLC, without prejudice to the mandatory data protection rules applicable to the data subject based on their place of residence (including GDPR for EU residents).

Limitation of liability: to the fullest extent permitted by applicable law, 4U shall not be liable for indirect, incidental, special, consequential, or punitive damages arising from data processing, except in cases of willful misconduct or gross negligence. For Colombian users, this limitation does not apply to the non-waivable rights recognized under Law 1480 of 2011 or Law 1581 of 2012.


P13 •CONTACT INFORMATION

Habeas Data / Data Protection Colombia: datos@4u.social (FINDIT SAS)

International Privacy: privacy@4u.social (3SENSE TECHNOLOGY LLC)

Support Colombia: soporte@4u.social

International Support: support@4u.social




ACCEPTANCE AND AUTHORIZATION

By registering on the 4U platform, the user grants their prior, express, and informed authorization for the processing of their personal data in accordance with this Policy, pursuant to Article 9 of Law 1581 of 2012 (Colombia) and the equivalent regulations applicable in their jurisdiction.

Where processing involves sensitive or biometric data, commercial marketing purposes, non-essential cookies, or international transfers requiring consent, 4U will request a specific, separate, documented, and revocable authorization through a standalone granular consent flow.

Version 2.2 |2026 | 4U — FINDIT SAS / 3SENSE TECHNOLOGY LLC