Fabric

Privacy Policy

Last updated September 23, 2026

1. INTRODUCTION & SCOPE

1.1. Who We Are. This Privacy Policy is published by Fabric Global, PBC, a Delaware Public Benefit Corporation ("Fabric," "we," "us," or "our"). Fabric operates a platform and suite of products and services that enable brands, organizations, sports leagues, host committees, and other partners to build and manage consumer engagement Moments, programs, activations, rewards initiatives, and related experiences.

1.2. What This Policy Covers. This Privacy Policy describes how Fabric collects, uses, stores, shares, and protects personal information in connection with all websites, applications, platforms, programs, and other products and services owned or operated by Fabric, including any current or future products or services made available by Fabric (collectively, the "Service"). This Policy applies to all users of the Service, including individuals who access the Service as participants in a Program or Activation operated by Fabric on behalf of a Client or Partner.

1.3. What This Policy Does Not Cover. This Policy does not apply to:

(a) the privacy practices of any Client, Partner, sponsor, brand, sports league, or other third party, even where such third party operates a program or activation through or in connection with the Service. Each such third party's collection and use of your personal information is governed by that party's own privacy policy, which you are encouraged to review before participating in any program or activation they operate;

(b) any third-party websites, applications, or services linked to or accessible from the Service, regardless of whether such links or integrations are provided by Fabric, a Client, or a Partner; or

(c) personal information collected from individuals in their capacity as employees, contractors, or other personnel of Fabric, Clients, or Partners in a business-to-business context, which is governed by separate agreements and policies.

1.4. Relationship to Terms of Service. This Privacy Policy is incorporated by reference into Fabric's Terms of Service, available at https://fabric.space/terms (the "Terms"). Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the Terms. In the event of any conflict between this Privacy Policy and the Terms with respect to the collection, use, or handling of personal information, this Privacy Policy shall control.

1.5. Programs and Activations. Where Fabric operates a Program or Activation on behalf of a Client or Partner, Fabric may act as a data processor on behalf of that Client or Partner with respect to certain personal information collected in connection with that Program or Activation. In such cases, the Client or Partner acts as the data controller and their privacy policy governs their independent use of your personal information. This Privacy Policy governs Fabric's own collection and use of your personal information in connection with the operation of the Service, regardless of the Program or Activation context.

1.6. Acceptance. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the collection, use, and sharing of your personal information as described in this Privacy Policy. If you do not agree to this Privacy Policy, you may not access or use the Service.

1.7. Updated. This Privacy Policy was last updated on September 23, 2026. We encourage you to review this Policy periodically to stay informed about how we collect, use, and protect your information. The most current version of this Policy will always be available at https://fabric.space/privacy.

2. INFORMATION WE COLLECT

.

2.1. Overview. Fabric collects personal information in three primary ways: information you provide directly to us, information we collect automatically when you use the Service, and information we receive from third parties including Clients, Partners, and advertising partners. The specific information we collect depends on how you interact with the Service and which Programs or Activations you participate in.

2.2. Information You Provide Directly.

2.2.1. Account Registration. When you create an Account, we collect information such as your name, email address, phone number, username, password, and any other information you choose to provide during the registration process.

2.2.2. Profile Information. You may choose to provide additional information to complete or enhance your profile, such as a profile photo, date of birth, gender, language preference, and general location information.

2.2.3. Program and Activation Participation. When you enroll in or participate in a Program or Activation, we collect information necessary to administer that Program or Activation, which may include your name, email address, phone number, mailing address, date of birth, eligibility information, and any other information required by the applicable Program Terms or Partner terms. Specific information collected in connection with a Program or Activation will be described in the applicable Program Terms or privacy notice.

2.2.4. Communications. When you contact us for support, submit feedback, report a problem, or otherwise communicate with us, we collect the content of your communications and any information you choose to include, such as your name, email address, and a description of your inquiry.

2.2.5. User Content. When you submit, post, upload, or otherwise make available User Content through the Service, we collect and store that content, together with associated metadata such as the date, time, and location of submission where applicable.

2.2.6. Surveys and Promotions. If you participate in any survey, contest, sweepstakes, or promotional activity offered through the Service or in connection with a Program or Activation, we collect the information you provide in connection with your participation.

2.2.7. Prize Redemption and Fulfillment. When you redeem points, rewards, or prizes through a Program or Activation, we may collect additional information necessary to fulfill your redemption, including your mailing address, email address, and, where required by law, tax identification information.

2.3. Information Collected Automatically.

2.3.1. Device Information. When you access the Service, we automatically collect information about the device you use, including your device type, operating system and version, unique device identifiers, mobile network information, and browser type and version.

2.3.2. Log Data. Our servers automatically record certain information when you access the Service, including your IP address, the date and time of your request, the pages or features you accessed, the referring URL, and the duration of your session.

2.3.3. Location Information. With your permission where required by applicable law, we collect precise or approximate location information from your device, including GPS coordinates, Wi-Fi access point data, and cell tower information. We use location information to enable location-based features of the Service, including check-in functionality within Programs and Activations. You may be able to disable location collection through your device settings, but doing so may limit the availability or functionality of certain features of the Service.

2.3.4. Usage and Behavioral Data. We collect information about how you interact with the Service, including the features you use, the content you view, the actions you take, the time and frequency of your activity, and the sequence of your interactions. This information is used to understand how users engage with the Service and to improve the user experience.

2.3.5. Cookies and Tracking Technologies. We use cookies, web beacons, pixel tags, software development kits ("SDKs"), and similar tracking technologies to collect information about your use of the Service. For a detailed description of the tracking technologies we use and your choices with respect to those technologies, please see Section 5 of this Privacy Policy.

2.4. Information Collected Through Programs and Activations.

2.4.1. Check-In and Engagement Data. Programs and Activations may involve check-in features that collect your location at the time of check-in, the name and address of the venue or business where you checked in, the date and time of check-in, and any associated engagement activity such as points earned or rewards triggered.

2.4.2. Program Activity Data. We collect information about your participation in Programs and Activations, including points balances, redemption history, reward status, eligibility determinations, and any communications exchanged in connection with your participation.

2.4.3. Third-Party Authentication Data. Where a Program or Activation requires you to authenticate through a third-party OAuth or single sign-on flow, we may receive certain profile information from the third-party authentication provider, such as your name, email address, profile photo, and account identifier, as permitted by your settings with that provider and as described in Section 2.5(b) below.

2.5. Information Received from Third Parties.

2.5.1. Clients and Partners. Clients and Partners may provide us with information about you in connection with a Program or Activation they operate through the Service, including eligibility information, enrollment data, and other information necessary to administer the Program or Activation on their behalf.

2.5.2. Third-Party Authentication Providers. If you choose to log in to the Service or an Activation using a third-party authentication service such as Google, Apple, or a Partner's single sign-on system, we receive information from that provider as described in Section 2.4(c) above. The information we receive depends on the permissions you grant and the settings of your account with that provider.

2.5.3. Advertising and Analytics Partners. We may receive information about you from advertising partners, data analytics providers, and similar third parties, including information about your interactions with advertisements served on third-party platforms, demographic and interest information used to improve the relevance of content and advertising, and information used to measure the effectiveness of advertising campaigns.

2.5.4. Publicly Available Sources. We may supplement the information we collect with information obtained from publicly available sources, such as public social media profiles, public records, and other publicly accessible databases, to the extent permitted by applicable law.

2.6. Sensitive Information. Fabric does not intentionally collect sensitive categories of personal information, including without limitation Social Security numbers, financial account numbers, payment card information, health or medical information, biometric data, or information about racial or ethnic origin, religious beliefs, sexual orientation, or political opinions, except where: (a) you voluntarily provide such information; (b) collection is required by applicable law or regulation; or (c) collection is necessary to fulfill a specific Program or Activation requirement disclosed to you at the time of collection. If you believe you have inadvertently submitted sensitive information to Fabric, please contact us at privacy@fabric.space to request deletion.

2.7. Consequences of Not Providing Information. Providing personal information to Fabric is voluntary in most cases. However, certain information is required to create an Account, access specific features of the Service, or participate in a Program or Activation. If you choose not to provide required information, you may not be able to access certain features of the Service or participate in certain Programs or Activations. We will endeavor to identify which information is required and which is optional at the time of collection.

3. How We Use Your Information

.

3.1. Overview. Fabric uses the personal information we collect for the purposes described in this Section. Where required by applicable law, we will only use your personal information where we have a valid legal basis for doing so, as described in Section 10 of this Privacy Policy and in the GDPR-specific provisions of Fabric's Terms of Service. We do not use your personal information for purposes that are incompatible with the purposes for which it was collected without your consent or as otherwise permitted by applicable law.

3.2. Service Operation and Delivery. We use your personal information to:

(a) create, maintain, and manage your Account, including verifying your identity and eligibility to use the Service;

(b) provide, operate, and deliver the features, functions, and content of the Service, including processing your requests and transactions;

(c) authenticate your identity when you log in to the Service, including through third-party OAuth or single sign-on flows;

(d) communicate with you about your Account, including sending transactional messages such as account confirmations, password resets, security alerts, and administrative notices;

(e) respond to your inquiries, support requests, and other communications;

(f) enforce these Terms, applicable Program Terms, and Partner terms, and investigate and address violations thereof; and

(g) protect the security and integrity of the Service, including detecting, preventing, and responding to fraud, abuse, unauthorized access, and other harmful or illegal activity.

3.3. Programs and Activations. We use your personal information to:

(a) enroll you in and administer any Program or Activation in which you participate, including processing check-ins, calculating and crediting points or rewards, tracking eligibility, and managing redemptions;

(b) communicate with you about your participation in a Program or Activation, including sending program updates, points statements, reward notifications, expiration notices, and other program-related communications;

(c) fulfill prizes, rewards, and other incentives earned through your participation in a Program or Activation, including sharing your information with third-party fulfillment vendors, shipping carriers, and ticketing platforms as necessary to complete fulfillment;

(d) make eligibility determinations required by applicable Program Terms or Partner terms, including verifying your age, location, or other qualifying criteria; and

(e) share your Program or Activation data with the applicable Client or Partner to the extent necessary for the administration of that Program or Activation and as described in Section 4 of this Privacy Policy.

3.4. Communications and Marketing. We use your personal information to:

(a) send you promotional communications about the Service, new features, Programs, Activations, and other offerings from Fabric that we believe may be of interest to you, where you have consented to receive such communications or where we have a legitimate interest in doing so and applicable law permits;

(b) send you communications on behalf of Clients or Partners in connection with Programs or Activations in which you participate, including co-branded marketing messages, partner offers, and program-specific promotions, to the extent permitted by applicable Program Terms and your communication preferences;

(c) personalize the content and communications you receive from us based on your activity on the Service, your participation in Programs and Activations, and your inferred interests and preferences; and

(d) measure the effectiveness of our communications, including tracking open rates, click-through rates, and other engagement metrics.

You may opt out of receiving promotional communications from Fabric at any time by following the unsubscribe instructions included in any such communication or by updating your Account preferences. Opting out of promotional communications does not affect your receipt of transactional or administrative communications related to your Account or any Program or Activation in which you participate.

3.5. Analytics and Service Improvement. We use your personal information to:

(a) analyze usage patterns, trends, and user behavior in connection with the Service to understand how users engage with our products and to identify opportunities for improvement;

(b) conduct research and development to improve existing features and develop new features, products, and services;

(c) generate aggregated, de-identified, or anonymized data that does not identify you individually, which we may use for any purpose, including sharing with Clients, Partners, and third parties for analytics, research, and reporting purposes;

(d) monitor and evaluate the performance, reliability, and availability of the Service; and

(e) train and improve any machine learning, artificial intelligence, or algorithmic systems used in connection with the Service, using de-identified or aggregated data where practicable.

3.6. Advertising. We use your personal information to:

(a) deliver advertisements and sponsored content through the Service that may be relevant to your interests, based on information we collect about your activity on the Service and information we receive from advertising partners and third-party data providers;

(b) share your personal information with advertising partners to enable the delivery of targeted or behavioral advertising on the Service and on third-party platforms, as further described in Section 6 of this Privacy Policy;

(c) measure the performance and effectiveness of advertising campaigns, including tracking impressions, clicks, conversions, and other engagement metrics; and

(d) build and refine audience segments and interest profiles based on your activity on the Service and information received from third parties, which may be used to inform advertising targeting on the Service and elsewhere.

For information about your choices with respect to advertising data sharing, including your right to opt out of the sale or sharing of your personal information for advertising purposes under the California Consumer Privacy Act, please see Section 6 of this Privacy Policy.

3.7. Legal Compliance and Safety. We use your personal information to:

(a) comply with applicable laws, regulations, legal process, and governmental requests, including responding to subpoenas, court orders, and other legal demands;

(b) establish, exercise, or defend legal claims, including in connection with any dispute resolution proceedings under Fabric's Terms of Service;

(c) enforce our rights under these Terms and applicable agreements;

(d) investigate and respond to complaints, reports of prohibited conduct, and DMCA notices submitted in connection with the Service;

(e) protect the rights, property, safety, and security of Fabric, its Clients, Partners, users, and the public; and

(f) fulfill any reporting or disclosure obligations imposed on Fabric as a Delaware Public Benefit Corporation or otherwise by applicable law.

3.8. Business Transfers. In connection with any merger, acquisition, reorganization, sale of assets, financing, or similar transaction involving Fabric, we may use your personal information to evaluate, negotiate, and complete such transaction, and your personal information may be transferred to the successor entity as part of that transaction, subject to the terms of this Privacy Policy and applicable law. We will notify you of any such transfer and any material changes to this Privacy Policy that result from such transaction in accordance with Section 13.

3.9. With Your Consent. In addition to the uses described above, we may use your personal information for any other purpose with your prior consent. Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw your consent, please contact us at privacy@fabric.space or update your Account preferences.

3.10. Aggregated and De-Identified Data. Fabric may create aggregated, de-identified, or anonymized data from personal information we collect by removing information that makes the data personally identifiable. We may use and share such aggregated, de-identified, or anonymized data for any lawful business purpose, including analytics, research, product development, and reporting to Clients and Partners, without restriction. Once data has been de-identified in accordance with applicable law, it is no longer considered personal information and is not subject to this Privacy Policy.

4. HOW WE SHARE YOUR INFORMATION

4.1. Overview. Fabric does not sell your personal information to third parties for their own independent marketing or commercial purposes, except as described in Section 6 of this Privacy Policy with respect to advertising partners. We share your personal information only as described in this Section, as disclosed to you at the time of collection, or with your consent. We require all third parties with whom we share your personal information to maintain appropriate confidentiality and security obligations consistent with this Privacy Policy and applicable law.

4.2. Clients and Partners. We share your personal information with Clients and Partners in the following circumstances:

4.2.1. Program and Activation Administration. Where you participate in a Program or Activation operated by Fabric on behalf of a Client or Partner, we share your personal information with that Client or Partner to the extent necessary to administer the Program or Activation, including your enrollment status, participation history, points balance, redemption activity, eligibility determinations, and contact information required for prize fulfillment or program communications. The Client or Partner's use of your personal information is governed by their own privacy policy, which you are encouraged to review before participating.

4.2.2. Co-Branded Programs. Where a Program or Activation is co-branded between Fabric and one or more Clients or Partners, your personal information may be shared with all co-branding parties to the extent necessary to operate the co-branded program, as disclosed in the applicable Program Terms or privacy notice.

4.2.3. Sponsor and Brand Partners. Where a Moment, Program or Activation involves sponsors or brand partners, we may share aggregated, de-identified, or anonymized data about program participation and engagement with such sponsors or brand partners for reporting and analytics purposes. We will not share your individually identifiable personal information with sponsors or brand partners without your consent, except as necessary for prize fulfillment or as described in the applicable Program Terms.

4.2.4. Reporting and Analytics. We may share aggregated, de-identified, or anonymized reports and analytics with Clients and Partners regarding the performance of Programs and Activations, user engagement, and other metrics relevant to the administration of their programs. Such reports do not identify you individually.

4.2.5. Consumer-Directed Disclosures to Sponsors. Where you affirmatively opt in to receive communications directly from a Sponsor in connection with a Sponsored Moment, Fabric discloses to that Sponsor the minimum contact information necessary to fulfill your request. This disclosure is made at your direction for a purpose you selected and does not constitute a "sale" or "sharing" of your personal information under the CCPA. Fabric requires Sponsors to refrain from selling, sharing, or otherwise using this information beyond the purpose for which you provided it.

4.3. Advertising Partners. We share certain personal information with advertising partners to enable the delivery of targeted and behavioral advertising on the Service and on third-party platforms, to measure the effectiveness of advertising campaigns, and to build and refine audience segments. The categories of personal information we share with advertising partners may include device identifiers, IP addresses, behavioral and usage data, location information, and inferred interest and demographic information. For a full description of our advertising data sharing practices and your rights and choices with respect thereto, including your right to opt out under the California Consumer Privacy Act, please see Section 6 of this Privacy Policy.

4.4. Service Providers and Vendors. We share your personal information with third-party service providers and vendors that perform services on our behalf in connection with the operation of the Service, including without limitation:

(a) cloud hosting, storage, and infrastructure providers;

(b) email, SMS, and push notification delivery providers;

(c) customer support and help desk platforms;

(d) payment processors and financial services providers;

(e) identity verification and authentication providers;

(f) analytics and performance monitoring providers;

(g) fraud detection and security providers;

(h) prize fulfillment, shipping, and logistics vendors;

(i) ticketing and event access platforms; and

(j) legal, accounting, and professional services firms.

Service providers and vendors are authorized to use your personal information only as necessary to perform the services they provide to Fabric and are prohibited from using your personal information for their own independent purposes. We require all service providers and vendors to maintain appropriate technical and organizational security measures consistent with this Privacy Policy and applicable law.

4.5. Legal and Regulatory Disclosures. We may disclose your personal information to governmental authorities, law enforcement agencies, regulators, courts, or other third parties where we believe in good faith that such disclosure is necessary or appropriate to:

(a) comply with applicable law, regulation, legal process, or governmental request, including a subpoena, court order, search warrant, or regulatory inquiry;

(b) enforce these Terms, applicable Program Terms, or other agreements;

(c) detect, prevent, or address fraud, security incidents, technical issues, or illegal activity;

(d) protect the rights, property, or safety of Fabric, its Clients, Partners, users, employees, or the public; or

(e) respond to an emergency that we believe in good faith requires disclosure to prevent harm.

Where permitted by applicable law, we will endeavor to provide you with notice of any such disclosure request before complying, so that you may seek appropriate legal protection.

4.6. Business Transfers. In connection with any merger, acquisition, reorganization, divestiture, sale of all or substantially all of Fabric's assets, financing, or similar corporate transaction, your personal information may be disclosed to prospective purchasers, investors, or transaction counterparties under appropriate confidentiality obligations, and may be transferred to the successor or acquiring entity as part of the completion of such transaction. In the event of any such transfer, we will notify you in accordance with Section 13 of this Privacy Policy and will require the successor entity to honor the commitments made in this Privacy Policy with respect to your personal information, or to provide you with notice and an opportunity to opt out before your personal information is used in a manner materially inconsistent with this Privacy Policy.

4.7. Professional Advisors. We may share your personal information with our legal counsel, auditors, accountants, insurers, and other professional advisors where necessary in connection with the provision of professional services to Fabric, subject to applicable professional confidentiality obligations.

4.8. With Your Consent. In addition to the sharing described above, we may share your personal information with third parties for any other purpose with your prior consent. Where we rely on your consent as the basis for sharing, you may withdraw your consent at any time by contacting us at privacy@fabric.space or updating your Account preferences. Withdrawal of consent does not affect the lawfulness of any sharing that occurred prior to withdrawal.

4.9. Onward Transfer Obligations. Where Fabric transfers your personal information to a third party acting as a data processor on Fabric's behalf, Fabric remains responsible for ensuring that such third party processes your personal information in a manner consistent with this Privacy Policy and applicable law. Where a third party to whom we have transferred your personal information processes it in a manner that violates this Privacy Policy, Fabric will take reasonable steps to remediate such processing upon becoming aware of it, except where the processing was caused by your own act or omission.

4.10. No Unauthorized Sale. Except as described in Section 6 with respect to advertising partners, Fabric does not sell, rent, lease, or otherwise transfer your personal information to third parties for their own independent marketing, advertising, or commercial purposes without your consent. If Fabric's data sharing practices change in a manner that constitutes a new category of sale or sharing under applicable law, we will update this Privacy Policy and provide you with notice and, where required by law, an opportunity to opt out before such sharing commences.

5. COOKIES AND TRACKING TECHNOLOGIES

5.1. Overview. Fabric and our third-party partners use cookies, web beacons, pixel tags, software development kits ("SDKs"), local storage objects, and other similar tracking technologies (collectively, "Tracking Technologies") to collect information about your use of the Service, recognize you across devices and sessions, personalize your experience, deliver and measure advertising, and analyze the performance of the Service. This Section explains what Tracking Technologies we use, why we use them, and what choices you have with respect to their use.

5.2. What Are Tracking Technologies.

5.2.1. Cookies. Cookies are small text files placed on your device by a website or application when you visit or use it. Cookies allow the website or application to recognize your device across sessions and to store information about your preferences and activity. Cookies may be set by Fabric ("first-party cookies") or by third parties whose content or services are embedded in the Service ("third-party cookies"). Cookies may be "session cookies," which expire when you close your browser or application, or "persistent cookies," which remain on your device for a defined period or until you delete them.

5.2.2. Web Beacons and Pixel Tags. Web beacons and pixel tags are small, transparent image files embedded in web pages, emails, or other content that allow us or our partners to track whether content has been accessed or viewed, and to collect information such as your IP address, browser type, and the time and date of access.

5.2.3. Software Development Kits (SDKs). SDKs are blocks of code embedded in our mobile applications that allow third-party partners to collect information about how you use the App, including usage analytics, crash reporting, advertising measurement, and other performance data.

5.2.4. Local Storage Objects. Local storage objects, including HTML5 local storage and IndexedDB, are similar to cookies but can store larger amounts of data on your device and are not automatically transmitted to our servers with each request. We may use local storage objects to store your preferences and application state information.

5.2.5. Device Fingerprinting. We or our third-party partners may use device fingerprinting techniques that collect information about your device's characteristics — such as your browser type and version, operating system, installed plugins, screen resolution, and time zone — to generate a unique identifier that allows us to recognize your device across sessions and platforms, even when cookies are not available.

5.3. Categories of Tracking Technologies We Use.

5.3.1. Strictly Necessary. These Tracking Technologies are essential to the operation of the Service and cannot be disabled without impairing core functionality. They include technologies that enable you to log in to your Account, maintain your session, remember your security preferences, and complete transactions. Because these technologies are strictly necessary for the Service to function, they do not require your consent under most applicable laws.

5.3.2. Functional. These Tracking Technologies enable the Service to remember your preferences and settings — such as your language preference, region, and display settings — to provide a more personalized experience. Disabling functional Tracking Technologies may affect the personalization and convenience features of the Service but will not prevent you from accessing core functionality.

5.3.3. Analytics and Performance. These Tracking Technologies collect information about how you use the Service, including which pages you visit, how long you spend on each page, what links you click, and any errors you encounter. This information is used to understand how users engage with the Service and to improve its performance, reliability, and content. Analytics data is generally aggregated and does not identify you individually, though some analytics tools may associate usage data with your Account or device.

5.3.4. Advertising and Targeting. These Tracking Technologies are used to deliver advertisements that are relevant to your interests, to limit the number of times you see an advertisement, to measure the effectiveness of advertising campaigns, and to build audience profiles for advertising targeting purposes. Advertising Tracking Technologies may be set by Fabric or by our advertising partners and may track your activity across the Service and third-party websites and applications over time. For information about your choices with respect to advertising Tracking Technologies, including your right to opt out of the sale or sharing of personal information collected through such technologies, please see Section 6 of this Privacy Policy.

5.3.5. Social Media and Integration. Where the Service includes social media sharing buttons, embedded social media content, or other third-party integrations, those third parties may set their own Tracking Technologies on your device when you interact with such features. Fabric does not control the Tracking Technologies set by third parties, and their use is governed by those third parties' own privacy policies.

5.4. Third-Party Tracking. Certain Tracking Technologies on the Service are set and operated by third parties, including advertising networks, analytics providers, and social media platforms. These third parties may collect information about your online activity across multiple websites and applications over time, and may combine that information with data they have collected from other sources. Fabric does not control the tracking practices of third parties and is not responsible for their use of your information. We encourage you to review the privacy policies of any third-party partners whose Tracking Technologies are used in connection with the Service. A list of our primary third-party tracking partners and links to their privacy policies and opt-out mechanisms is available at https://fabric.space/partners.

5.5. Your Choices Regarding Tracking Technologies.

5.5.1. Browser Controls. Most web browsers allow you to control cookies through their settings, including the ability to block, delete, or receive notifications about cookies. Instructions for managing cookies in common browsers are available at the browser developer's support pages. Please note that blocking or deleting cookies may affect the functionality of the Service, including your ability to log in to your Account and access certain features.

5.5.2. Mobile Device Controls. Most mobile operating systems provide controls that allow you to limit or reset advertising identifiers associated with your device, or to opt out of interest-based advertising. These controls are typically available in your device's privacy or advertising settings.

5.5.3. Do Not Track. Some browsers offer a "Do Not Track" ("DNT") signal that you can enable to request that websites not track your activity. The Service does not currently respond to DNT signals because there is no industry-wide standard for how DNT signals should be interpreted or honored. We will continue to monitor developments in this area and update our practices accordingly.

5.5.4. Global Privacy Control. To the extent required by applicable law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CPRA"), Fabric will honor Global Privacy Control ("GPC") signals received from your browser or device as a valid opt-out of the sale or sharing of your personal information for advertising purposes. If your browser or device transmits a GPC signal when you access the Service, Fabric will treat that signal as a request to opt out of advertising data sharing in accordance with Section 6 of this Privacy Policy.

5.5.5. Cookie Preference Center. Where required by applicable law or made available as a convenience, Fabric may provide a cookie preference center or consent management tool through the Service that allows you to review and adjust your preferences for non-essential Tracking Technologies. Your preferences will be stored and applied to your use of the Service on the device and browser on which they are set. You may need to reset your preferences if you clear your cookies, use a different browser, or access the Service from a different device.

5.5.6. Opt-Out of Advertising Tracking. You may opt out of interest-based advertising delivered through certain advertising networks by visiting the Network Advertising Initiative opt-out page at www.networkadvertising.org/choices or the Digital Advertising Alliance opt-out page at www.aboutads.info/choices. Please note that opting out through these tools does not prevent you from seeing advertisements; it means that the advertisements you see may be less relevant to your interests. These opt-out mechanisms are device- and browser-specific and must be reset if you clear your cookies or use a different browser or device.

5.6. Consequences of Disabling Tracking Technologies. Disabling or blocking certain Tracking Technologies may affect your ability to use the Service, including without limitation your ability to log in to your Account, participate in Programs or Activations, access personalized content, and complete certain transactions. Fabric is not responsible for any degradation in the functionality or availability of the Service resulting from your choice to disable or block Tracking Technologies.

5.7. Updates to Tracking Practices. Fabric may add, modify, or discontinue the use of specific Tracking Technologies from time to time as the Service evolves and as our partners and tools change. Material changes to our tracking practices will be reflected in updates to this Privacy Policy in accordance with Section 13. We encourage you to review this Section periodically to stay informed about the Tracking Technologies we use and your available choices.

6. ADVERTISING AND DO NOT SELL / DO NOT SHARE

6.1. Overview. Fabric engages in advertising activities that may involve the sharing of your personal information with advertising partners for the purpose of delivering targeted and behavioral advertising on the Service and on third-party platforms. This Section describes our advertising practices in detail and explains the rights you have with respect to the use of your personal information for advertising purposes, including your right under the California Consumer Privacy Act to opt out of the sale or sharing of your personal information.

6.2. How We Use Your Information for Advertising.

6.2.1. On-Service Advertising. Fabric may display advertisements within the Service, including advertisements delivered by third-party advertising networks and demand-side platforms. These advertisements may be targeted based on information we collect about your activity on the Service, your participation in Programs and Activations, your inferred interests and demographics, and information we receive from advertising partners and third-party data providers.

6.2.2. Off-Service Advertising. Fabric may share your personal information with advertising partners to enable the delivery of advertisements about the Service, Programs, Activations, and our Clients' and Partners' products and services on third-party websites, applications, and platforms. This may include retargeting campaigns that deliver advertisements to you on third-party platforms based on your prior activity on the Service.

6.2.3. Audience Building. Fabric and our advertising partners may use your personal information to build audience segments and interest profiles that are used to target advertising to you and to other users with similar characteristics. This may include the use of hashed email addresses, device identifiers, and other persistent identifiers to match your information with data held by advertising partners and third-party data providers.

6.2.4. Measurement and Attribution. Fabric and our advertising partners collect information about your interactions with advertisements, including impressions, clicks, conversions, and other engagement metrics, to measure the effectiveness of advertising campaigns and to optimize future advertising delivery.

6.2.5. Data Clean Rooms. Fabric may participate in data clean room arrangements with Clients, Partners, and advertising partners in which aggregated or pseudonymized data is analyzed in a secure environment to generate insights about audience behavior and campaign performance without directly exposing individually identifiable personal information.

6.3. Categories of Personal Information Shared for Advertising. The categories of personal information we may share with advertising partners for advertising purposes include:

(a) device identifiers, including advertising IDs such as Apple's IDFA and Google's GAID;

(b) IP addresses and approximate location information derived therefrom;

(c) behavioral and usage data, including pages visited, content viewed, features used, and actions taken on the Service;

(d) hashed email addresses and hashed phone numbers used for identity matching and audience building;

(e) inferred interest, demographic, and behavioral segments derived from your activity on the Service and information received from third parties; and

(f) Program and Activation engagement data, including participation history and redemption activity, to the extent used to inform advertising targeting or measurement.

6.4. Sale and Sharing of Personal Information Under California Law. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), grants California residents specific rights with respect to the sale and sharing of their personal information. For purposes of the CCPA:

6.4.1. Sale. A "sale" of personal information includes the disclosure of personal information to a third party for monetary or other valuable consideration. Fabric may share certain categories of personal information with advertising partners in exchange for advertising services, data enrichment, or other valuable consideration, which may constitute a "sale" of personal information under the CCPA.

6.4.2. Sharing. "Sharing" of personal information includes the disclosure of personal information to a third party for cross-context behavioral advertising purposes, regardless of whether monetary consideration is exchanged. Fabric shares certain categories of personal information with advertising partners for cross-context behavioral advertising purposes, which constitutes "sharing" of personal information under the CCPA.

6.4.3. Categories Sold or Shared. The categories of personal information that Fabric sells or shares with advertising partners for advertising purposes are described in Section 6.3 above. Fabric does not sell or share sensitive personal information, as defined under the CCPA, for advertising purposes.

6.4.4. Parties to Whom Personal Information Is Sold or Shared. Fabric sells or shares personal information with advertising networks, demand-side platforms, data management platforms, identity resolution providers, and measurement and attribution partners. Fabric does not sell to or share data with third parties unless the user has explicitly opted into receiving communications from a specific sponsor or brand partner. Fabric does not sell bulk data, analytics or enrichment information to third parties without the user’s explicit opt-in consent. Opting in is not required to participate in a Moment, Activation or Program. Anonymized analytics data may be shared with sponsors or brand partners to demonstrate engagement, however this data does not include personal identifiable information including, but not limited to: device fingerprints, names, locations, email addresses, or phone numbers.

6.5. Your Right to Opt Out — California Residents. If you are a California resident, you have the right to opt out of the sale and sharing of your personal information for advertising purposes at any time, without any penalty or adverse effect on your access to the Service. To exercise your right to opt out, you may:

6.5.1. Do Not Sell or Share My Personal Information. Click the "Do Not Sell or Share My Personal Information" link available at https://fabric.space/opt-out and in the footer of our website. Completing this process will apply your opt-out preference to the personal information associated with your Account and, to the extent technically feasible, to device-level data collected from the device on which you submit your request.

6.5.2. Global Privacy Control. If your browser or device transmits a Global Privacy Control ("GPC") signal when you access the Service, Fabric will treat that signal as a valid opt-out of the sale and sharing of your personal information for advertising purposes, in accordance with applicable California law. You do not need to submit a separate opt-out request if you have enabled GPC on your browser or device.

6.5.3. Account Settings. You may also opt out of advertising data sharing by updating your advertising preferences in your Account settings.

Upon receipt of a valid opt-out request, Fabric will process your request within fifteen (15) business days and will direct our advertising partners to cease the sale or sharing of your personal information as required by applicable law. Please note that certain advertising partners may require additional time to process opt-out requests, and you may continue to see targeted advertisements for a period following submission of your opt-out request while your preference is being propagated.

6.6. Effect of Opt-Out. If you opt out of the sale or sharing of your personal information for advertising purposes:

(a) Fabric will cease sharing your personal information with advertising partners for targeted or behavioral advertising purposes, to the extent technically feasible;

(b) you may continue to see contextual advertisements on the Service that are based on the content of the page or feature you are viewing rather than on your personal information or behavioral profile;

(c) your opt-out preference will not affect Fabric's ability to share your personal information with Clients, Partners, and service providers for purposes other than advertising, as described in Section 4 of this Privacy Policy;

(d) your opt-out preference will not affect Fabric's ability to use your personal information for the operation and delivery of the Service, Program and Activation administration, legal compliance, and other non-advertising purposes described in Section 3; and

(e) your opt-out preference will be stored and honored for a period of at least twelve (12) months before Fabric may request that you reconsider your preference, in accordance with CCPA requirements.

6.7. Authorized Agents. California residents may designate an authorized agent to submit an opt-out request on their behalf. To submit an opt-out request through an authorized agent, the agent must provide written proof of authorization to act on your behalf, and Fabric may require you to verify your identity directly before processing the request. Authorized agent requests should be submitted to privacy@fabric.space.

6.8. Non-Discrimination. Fabric will not discriminate against you for exercising your right to opt out of the sale or sharing of your personal information or any other right afforded to you under applicable privacy law. We will not deny you access to the Service, charge you different prices, provide you with a diminished level of service, or suggest that you will receive any such treatment as a result of exercising your privacy rights.

6.9. Sensitive Personal Information. Fabric does not use or disclose sensitive personal information, as defined under the CCPA, for the purpose of targeted advertising or for any purpose other than those permitted under applicable law without your explicit consent. If you believe Fabric has used your sensitive personal information for an unauthorized purpose, please contact us at privacy@fabric.space.

6.10. Other US State Residents. Residents of certain US states other than California may have similar rights with respect to the use of their personal information for advertising purposes under applicable state privacy laws, including without limitation the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), and similar legislation. For a description of your rights under applicable state privacy laws and how to exercise them, please see Section 10 of this Privacy Policy.

6.11. GDPR and International Users. If you are located in the EEA, UK, or Switzerland, Fabric's use of your personal information for behavioral or targeted advertising is subject to the requirements of the GDPR and applicable national implementing legislation, including the requirement to obtain your explicit consent before processing your personal information for behavioral advertising purposes. Where we rely on your consent for advertising processing, you may withdraw that consent at any time by contacting us at privacy@fabric.space or updating your Account preferences. Withdrawal of consent does not affect the lawfulness of advertising processing carried out prior to withdrawal.

7. DATA RETENTION

7.1. General Approach. Fabric retains personal information for as long as necessary to fulfill the purposes for which it was collected, to operate and improve the Service, to comply with applicable legal obligations, to resolve disputes, and to enforce our agreements. We do not retain personal information for longer than is necessary for these purposes, taking into account the nature and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the information, and applicable legal requirements.

7.2. Retention by Category. The following describes our general retention practices for different categories of personal information. Specific retention periods may vary depending on the nature of your relationship with Fabric, your participation in Programs or Activations, and applicable legal requirements:

7.2.1. Account Information. We retain your Account information, including your name, email address, phone number, username, and profile information, for as long as your Account remains active. Following the closure or termination of your Account, we retain your Account information for a period of three (3) years to enable account recovery, to resolve any outstanding disputes or claims, and to comply with applicable legal obligations. Following the expiration of this retention period, your Account information will be deleted or de-identified in accordance with Section 7.5.

7.2.2. Program and Moments Data. We retain data relating to your participation in Programs and Activations, including enrollment records, check-in history, points balances, redemption records, and prize fulfillment information, for a period of five (5) years following the conclusion of the applicable Program or Activation, or following the closure or termination of your Account, whichever is later. This retention period reflects the potential for disputes arising from Program participation and the need to maintain records for Client and Partner reporting and audit purposes.

7.2.3. User Content. We retain User Content you submit through the Service for as long as your Account remains active and for a period of three (3) years following the closure or termination of your Account, unless you request earlier deletion in accordance with Section 7.4 or applicable law requires a different retention period. Where User Content has been shared with or made available to other users, Clients, or Partners, copies of that content may persist in those parties' systems beyond the retention period applicable to Fabric's own systems.

7.2.4. Communications and Support Records. We retain records of communications between you and Fabric, including support tickets, feedback submissions, and dispute-related correspondence, for a period of three (3) years following the resolution of the relevant inquiry or dispute, or for such longer period as may be required by applicable law or necessary in connection with ongoing legal proceedings.

7.2.5. Automatically Collected Data. We retain automatically collected data, including log data, device information, IP addresses, and behavioral and usage data, for a period of twenty-four (24) months from the date of collection, following which such data will be deleted or de-identified. Where automatically collected data is associated with your Account, it may be retained for the duration of your Account and for a period of twenty-four (24) months following Account closure.

7.2.6. Advertising and Tracking Data. We retain advertising identifiers, audience segment data, and other information collected through Tracking Technologies for advertising purposes for a period of thirteen (13) months from the date of collection, consistent with industry standards and applicable regulatory guidance. Where you have exercised your right to opt out of the sale or sharing of your personal information under Section 6, we will retain a record of your opt-out preference for a minimum of five (5) years to ensure your preference is honored.

7.2.7. Financial and Transaction Records. Where Fabric collects financial or transaction information in connection with a Program or Activation, including prize redemption records and tax-related information, we retain such information for a period of seven (7) years following the relevant transaction, consistent with applicable tax, accounting, and financial recordkeeping requirements.

7.2.8. Legal Hold. Notwithstanding the retention periods described above, we may retain personal information for longer periods where necessary in connection with actual or reasonably anticipated litigation, regulatory investigation, audit, or other legal proceeding (a "Legal Hold"). Personal information subject to a Legal Hold will be retained until the Legal Hold is lifted and will then be retained or deleted in accordance with the applicable retention period described in this Section.

7.3. Retention Following Opt-Out. Where you have exercised your right to opt out of the sale or sharing of your personal information for advertising purposes under Section 6, Fabric will retain a record of your opt-out preference for a minimum of five (5) years. Retention of this record does not constitute processing of your personal information for advertising purposes and is necessary to ensure that your preference is honored and to demonstrate compliance with applicable law.

7.4. Deletion Requests. You may request deletion of your personal information in accordance with your rights under applicable law, as described in Section 10 of this Privacy Policy. Upon receipt of a verified deletion request, Fabric will delete or de-identify your personal information within the timeframes required by applicable law, subject to the following exceptions:

(a) information that Fabric is required to retain under applicable law, regulation, or legal process;

(b) information necessary to complete a transaction you have initiated or to fulfill an obligation arising from a Program or Activation in which you participated;

(c) information necessary to detect, prevent, or investigate security incidents, fraud, or illegal activity;

(d) information necessary to exercise or defend legal claims; and

(e) information that has been de-identified or aggregated in a manner that no longer identifies you individually, which Fabric may retain and use without restriction.

Where Fabric is unable to fulfill a deletion request due to one of the exceptions above, we will inform you of the basis for our inability to delete and will restrict further use of the relevant information to the purpose that prevents its deletion.

7.5. Deletion and De-Identification. Upon expiration of the applicable retention period or upon fulfillment of a verified deletion request, Fabric will either:

(a) permanently delete your personal information from its active systems and, to the extent technically feasible, from its backup systems within a reasonable period following deletion from active systems; or

(b) de-identify your personal information in a manner such that it can no longer reasonably be used to identify you, in which case the de-identified information is no longer subject to this Privacy Policy and may be retained and used by Fabric for any lawful purpose.

The method of disposal — deletion or de-identification — will be determined by Fabric based on technical feasibility, the nature of the information, and applicable legal requirements

7.6. Third-Party Retention. Where Fabric has shared your personal information with Clients, Partners, service providers, or advertising partners, those parties may retain your personal information in accordance with their own retention policies, which may differ from Fabric's. Fabric is not responsible for the retention practices of third parties, and requests for deletion of personal information held by third parties should be directed to those parties directly. Where Fabric has shared your personal information with a service provider acting on Fabric's behalf, Fabric will make reasonable efforts to instruct that service provider to delete your personal information in accordance with a verified deletion request, subject to the service provider's own legal obligations.

7.7. Backup Systems. Personal information deleted from Fabric's active systems may persist in encrypted backup or archival systems for a period of up to ninety (90) days following deletion from active systems, after which it will be deleted from backup systems as part of Fabric's regular backup rotation cycle. During this period, personal information retained in backup systems will not be accessed or used for any purpose other than disaster recovery and will be subject to appropriate security controls.

7.8. Retention Schedules. Fabric maintains internal data retention schedules that govern the retention and disposal of personal information across its systems and services. These schedules are reviewed and updated periodically to reflect changes in applicable law, regulatory guidance, and Fabric's business operations. The retention periods described in this Section represent Fabric's standard practices and may be adjusted from time to time in accordance with this review process, subject to the notice requirements of Section 13.

8. DATA SECURITY

.

8.1. Our Commitment to Security. Fabric takes the security of your personal information seriously and implements reasonable and appropriate technical, administrative, and physical safeguards designed to protect your personal information against unauthorized access, use, disclosure, alteration, loss, and destruction. Our security program is designed to be proportionate to the nature and sensitivity of the personal information we collect and the risks associated with its processing.

8.2. Technical Safeguards. Fabric's technical security measures include without limitation:

8.2.1. Encryption. Personal information transmitted between your device and Fabric's systems is protected using industry-standard Transport Layer Security ("TLS") encryption. Personal information stored in Fabric's systems is encrypted at rest using industry-standard encryption protocols, including AES-256 or equivalent standards.

8.2.2. Access Controls. Access to personal information within Fabric's systems is restricted to authorized personnel who require access to perform their job functions. Access controls are enforced through role-based access management, multi-factor authentication, and the principle of least privilege.

8.2.3. Network Security. Fabric employs firewalls, intrusion detection and prevention systems, and other network security measures designed to prevent unauthorized access to its systems and infrastructure.

8.2.4. Vulnerability Management. Fabric conducts regular vulnerability assessments and penetration testing of its systems and infrastructure to identify and remediate security vulnerabilities. Critical vulnerabilities are prioritized for remediation in accordance with Fabric's internal security policies.

8.2.5. Logging and Monitoring. Fabric maintains security logs and monitoring systems designed to detect and alert on suspicious or unauthorized activity within its systems. Security events are reviewed and investigated by Fabric's security personnel in accordance with Fabric's incident response procedures.

8.2.6. Secure Development. Fabric follows secure software development practices, including code review, security testing, and vulnerability scanning, in connection with the development and deployment of features and updates to the Service.

8.3. Administrative Safeguards. Fabric's administrative security measures include without limitation:

8.3.1. Security Policies. Fabric maintains written information security policies and procedures that govern the collection, use, storage, and disposal of personal information and the security of Fabric's systems and infrastructure.

8.3.2. Employee Training. Fabric personnel who have access to personal information receive training on Fabric's security policies and data handling practices, including training on the recognition and reporting of security incidents and phishing attempts.

8.3.3. Vendor Management. Fabric evaluates the security practices of third-party service providers and vendors that process personal information on Fabric's behalf and requires such parties to maintain appropriate security measures consistent with this Privacy Policy and applicable law. Fabric includes data processing and security obligations in its agreements with service providers and vendors.

8.3.4. Incident Response. Fabric maintains an incident response plan that governs Fabric's response to security incidents, including procedures for containment, investigation, remediation, notification, and post-incident review. Fabric's incident response plan is reviewed and tested periodically.

8.3.5. Background Checks. To the extent permitted by applicable law, Fabric conducts background checks on personnel who will have access to sensitive personal information as part of its hiring process.

8.4. Physical Safeguards. Fabric's physical security measures include without limitation:

8.4.1. Facility Security. Fabric's offices and facilities are secured against unauthorized physical access through access control systems, visitor management procedures, and other physical security measures appropriate to the nature of the operations conducted at each facility.

8.4.2. Cloud Infrastructure. Fabric's primary data processing and storage infrastructure is hosted by third-party cloud service providers that maintain their own physical security programs, including SOC 2 Type II or equivalent certifications. Fabric evaluates its cloud service providers' security certifications and practices as part of its vendor management program.

8.4.3. Device Security. Fabric maintains policies governing the security of devices used by personnel to access personal information, including requirements for device encryption, screen lock, remote wipe capability, and the use of approved security software.

8.5. Security of Third-Party Services. Fabric's security measures apply to personal information processed within Fabric's own systems and infrastructure. Where personal information is processed by third-party service providers, Clients, Partners, or advertising partners, the security of that information is governed by those parties' own security programs. Fabric is not responsible for the security practices of third parties and encourages you to review the security and privacy policies of any third party with whom you share personal information directly.

8.6. Your Role in Security. The security of your personal information also depends on the steps you take to protect your Account and your device. You are responsible for:

(a) maintaining the confidentiality of your Account credentials and not sharing your username or password with any third party;

(b) using a strong, unique password for your Account and updating it periodically;

(c) enabling multi-factor authentication on your Account where available;

(d) keeping your device's operating system, browser, and applications up to date with the latest security patches;

(e) logging out of your Account when using shared or public devices; and

(f) notifying Fabric immediately at support@sparkfabric.com if you suspect any unauthorized access to or use of your Account.

Fabric is not liable for any loss or damage arising from your failure to comply with these responsibilities.

8.7. Data Breach Notification. In the event of a security incident that compromises the confidentiality, integrity, or availability of your personal information in a manner that creates a risk of harm to you, Fabric will notify you and applicable regulatory authorities in accordance with applicable data breach notification laws, including without limitation the California Consumer Privacy Act, applicable US state breach notification statutes, and, where applicable, the GDPR's seventy-two (72) hour notification requirement to supervisory authorities under Article 33. Breach notifications will be provided to the email address associated with your Account and will describe the nature of the incident, the categories of personal information affected, the steps Fabric has taken to address the incident, and the steps you can take to protect yourself.

8.8. No Absolute Security. Notwithstanding the security measures described in this Section, no method of transmission over the internet and no method of electronic storage is completely secure. Fabric cannot guarantee the absolute security of your personal information and cannot ensure or warrant that your personal information will never be accessed, disclosed, altered, or destroyed by unauthorized parties. By using the Service, you acknowledge and accept this inherent risk. In the event you become aware of any security vulnerability or incident affecting the Service, please notify Fabric immediately at security@fabric.space.

8.9. International Data Security. Where personal information is transferred internationally as described in Section 11 of this Privacy Policy, Fabric implements appropriate safeguards to ensure that your personal information receives a level of protection consistent with the requirements of applicable data protection law, including the GDPR's requirements for international data transfers. These safeguards include the use of Standard Contractual Clauses approved by the European Commission and, where applicable, supplementary technical measures such as encryption and pseudonymization.

8.10. Security Certifications and Audits. Fabric periodically engages third-party auditors to assess the effectiveness of its security program and its compliance with applicable security standards. Information about Fabric's current security certifications and audit status is available upon written request to security@fabric.space.

9. CHILDREN’S PRIVACY

9.1. Age Requirement. The Service is not directed to, and is not intended for use by, individuals under the age of sixteen (16). Fabric's Terms of Service prohibit use of the Service by individuals under the age of sixteen (16), and by accessing or using the Service, you represent and warrant that you are at least sixteen (16) years of age. The age restriction applicable to the Service is higher than the minimum age threshold established by the Children's Online Privacy Protection Act ("COPPA"), which applies to the online collection of personal information from children under the age of thirteen (13). Fabric has adopted a sixteen (16) year age floor in recognition of the stricter age thresholds applicable under the General Data Protection Regulation ("GDPR") and as a general matter of policy reflecting Fabric's commitment to the protection of minors.

9.2. No Collection of Personal Information from Children Under 13. Fabric does not knowingly collect, use, store, or disclose personal information from children under the age of thirteen (13). The Service is not directed at children under the age of thirteen (13), and no aspect of the Service is designed or intended to attract children under the age of thirteen (13). Fabric does not knowingly allow children under the age of thirteen (13) to create Accounts, participate in Programs or Activations, or otherwise use the Service.

9.3. No Collection of Personal Information from Minors Under 16. In addition to the protections described in Section 9.2, Fabric does not knowingly collect, use, store, or disclose personal information from individuals between the ages of thirteen (13) and fifteen (15) inclusive. The age floor established in Fabric's Terms of Service applies to all aspects of the Service, including participation in any Program or Activation, and Fabric does not knowingly permit individuals under the age of sixteen (16) to access or use the Service in any capacity.

9.4. Age Verification. Fabric relies on users to accurately represent their age when creating an Account or accessing the Service. While Fabric does not currently employ formal age verification technology at the point of Account creation, Fabric reserves the right to implement age verification measures at any time, including in connection with specific Programs or Activations that may be subject to age-related eligibility requirements. Where a Program or Activation requires participants to be of a specific age, the applicable Program Terms will describe the age verification procedures applicable to that Program or Activation.

9.5. Discovery of Underage Users. If Fabric discovers or is notified that it has collected personal information from an individual under the age of sixteen (16), including from a child under the age of thirteen (13) in violation of COPPA, Fabric will take the following steps promptly upon such discovery:

(a) suspend or terminate the Account associated with the underage user;

(b) delete or de-identify the personal information collected from the underage user from Fabric's active systems, including Account information, usage data, Program and Activation data, and any User Content submitted by the underage user, subject to any applicable legal hold obligations;

(c) notify the applicable Client or Partner if the underage user's personal information was shared with a Client or Partner in connection with a Program or Activation, and request that the Client or Partner delete the underage user's personal information from their systems;

(d) notify advertising partners and service providers with whom the underage user's personal information was shared, and request that such parties delete the underage user's personal information from their systems; and

(e) where required by applicable law, including COPPA and applicable state children's privacy laws, notify the relevant regulatory authority of the inadvertent collection of personal information from an underage user.

9.6. Reporting Underage Users. If you believe that Fabric has inadvertently collected personal information from an individual under the age of sixteen (16), or if you are a parent or legal guardian and believe that your child under the age of thirteen (13) has provided personal information to Fabric without your consent, please contact us immediately at privacy@fabric.space with the subject line "Minor — Privacy Concern." Please include in your report the username or email address associated with the Account in question and a description of the nature of your concern. Fabric will investigate all reports submitted under this Section and will take appropriate action in accordance with Section 9.5 and applicable law.

9.7. Parental Rights Under COPPA. To the extent that Fabric has inadvertently collected personal information from a child under the age of thirteen (13) in violation of COPPA, parents and legal guardians have the following rights with respect to that information:

(a) the right to review the personal information collected from their child;

(b) the right to request deletion of the personal information collected from their child; and

(c) the right to refuse to permit any further collection or use of their child's personal information.

To exercise any of these rights, parents or legal guardians should contact Fabric at privacy@fabric.space with the subject line "COPPA — Parental Rights Request." Fabric will respond to verified parental rights requests within the timeframes required by applicable law and will take appropriate action to fulfill such requests subject to any applicable legal obligations.

9.8. Programs and Activations Directed at Families. Certain Programs or Activations operated through the Service may be designed for family participation or may involve prizes or experiences that are of interest to families with children. Where a Program or Activation is designed for or marketed to families, the applicable Program Terms will include age-appropriate participation requirements, and participation by minors will be subject to parental or guardian consent requirements as specified in those Program Terms. Fabric does not collect personal information directly from minors in connection with family-oriented Programs or Activations without verifiable parental consent where required by applicable law.

9.9. COPPA Safe Harbor. Fabric is not currently a member of any FTC-approved COPPA safe harbor program. Fabric complies with COPPA through the measures described in this Section and through its general policy of not directing the Service at children under the age of thirteen (13). Fabric monitors developments in children's privacy law and reserves the right to seek membership in an FTC-approved COPPA safe harbor program in the future.

9.10. State Children's Privacy Laws. In addition to COPPA, certain US states have enacted or are in the process of enacting children's privacy laws that may impose additional obligations on operators of online services with respect to the collection and use of personal information from minors. These laws include without limitation the California Age-Appropriate Design Code Act ("CAADCA"), the Children and Teens' Online Privacy Protection Act ("CTOPPA" or "COPPA 2.0" if enacted), and similar state legislation. Fabric monitors developments in state children's privacy law and will update its practices and this Privacy Policy as necessary to comply with applicable requirements as they come into effect.

10. YOUR PRIVACY RIGHTS

10.1. Overview. Depending on where you are located, you may have certain rights with respect to your personal information under applicable privacy law. This Section describes the privacy rights available to residents of California, the European Economic Area, the United Kingdom, Switzerland, and other US states with comprehensive privacy legislation, and explains how you can exercise those rights. Fabric is committed to honoring your privacy rights in a timely and transparent manner and will not discriminate against you for exercising any right described in this Section.

10.2. California Residents (CCPA / CPRA)

10.2.1. Scope. This Section 10.2 applies to residents of the State of California. The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"), grants California residents specific rights with respect to their personal information. These rights are in addition to any rights described elsewhere in this Privacy Policy.

10.2.2. Your Rights Under the CCPA. As a California resident, you have the following rights with respect to your personal information:

10.2.2.1. Right to Know. You have the right to request that Fabric disclose to you: (i) the categories of personal information Fabric has collected about you; (ii) the categories of sources from which that personal information was collected; (iii) the business or commercial purposes for which Fabric collected, sold, or shared that personal information; (iv) the categories of third parties to whom Fabric disclosed, sold, or shared that personal information; and (v) the specific pieces of personal information Fabric has collected about you.

10.2.2.2. Right to Delete. You have the right to request that Fabric delete personal information that Fabric has collected from you, subject to certain exceptions described in Section 7.4 of this Privacy Policy.

10.2.2.3. Right to Correct. You have the right to request that Fabric correct inaccurate personal information that Fabric maintains about you.

10.2.2.4. Right to Opt Out of Sale or Sharing. You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising purposes at any time, as described in Section 6 of this Privacy Policy.

10.2.2.5. Right to Limit Use of Sensitive Personal Information. You have the right to direct Fabric to limit its use and disclosure of sensitive personal information, as defined under the CCPA, to purposes that are necessary to perform the Service or as otherwise permitted under applicable law. Fabric does not currently use sensitive personal information for purposes beyond those permitted under the CCPA without your consent.

10.2.2.6. Right to Non-Discrimination. You have the right not to receive discriminatory treatment for exercising any of your CCPA rights. Fabric will not deny you access to the Service, charge you different prices, provide you with a diminished level of service quality, or suggest that you will receive any such treatment as a result of exercising your CCPA rights.

10.2.2.7. Right to Notice. You have the right to receive notice of Fabric's privacy practices at or before the time personal information is collected, including notice of the categories of personal information collected and the purposes for which it is used.

10.2.3. Categories of Personal Information Collected. In the preceding twelve (12) months, Fabric has collected the following categories of personal information as defined under the CCPA:

(a) Identifiers, including name, email address, phone number, IP address, device identifiers, and Account username;

(b) Personal information described in California Civil Code § 1798.80(e), including name, address, and telephone number;

(c) Commercial information, including Program and Activation participation history, points balances, and redemption records;

(d) Internet or other electronic network activity information, including browsing and usage data, interaction data, and log data;

(e) Geolocation data, including precise and approximate location information collected through the Service;

(f) Inferences drawn from personal information to create a profile reflecting preferences, characteristics, behavior, and interests; and

(g) Sensitive personal information, including precise geolocation data, to the extent collected through the Service with your permission.

10.2.4. Categories of Personal Information Sold or Shared. In the preceding twelve (12) months, Fabric has sold or shared the following categories of personal information with advertising partners for cross-context behavioral advertising purposes: device identifiers, IP addresses, behavioral and usage data, approximate location data, and inferred interest and demographic information, as further described in Section 6 of this Privacy Policy.

10.2.5. Retention. Fabric retains each category of personal information described in Section 10.2.3 for the periods described in Section 7 of this Privacy Policy.

10.2.6. Submitting a CCPA Request. To exercise your rights under Section 10.2.2, you or your authorized agent may submit a verifiable consumer request by emailing Fabric at privacy@fabric.space with the subject line "CCPA Rights Request".

10.2.7. Verification. To protect your personal information and prevent unauthorized access, Fabric will verify your identity before processing any CCPA rights request. The verification process may require you to provide information that Fabric can match against information it already holds about you, such as your name, email address, and Account information. For requests to access specific pieces of personal information, Fabric may require a higher level of verification. Fabric will not use information provided for verification purposes for any purpose other than verification.

10.2.8. Response Timeframes. Fabric will respond to verifiable CCPA rights requests within forty-five (45) days of receipt. If Fabric requires additional time to respond, Fabric will notify you within the initial forty-five (45) day period and may extend the response period by an additional forty-five (45) days, for a maximum total response period of ninety (90) days. Fabric will provide its response free of charge, except that Fabric may charge a reasonable fee for requests that are manifestly unfounded, excessive, or repetitive.

10.2.9. Authorized Agents. California residents may designate an authorized agent to submit CCPA rights requests on their behalf. To submit a request through an authorized agent, the agent must provide written proof of authorization signed by you, and Fabric may require you to verify your identity directly before processing the request. Authorized agent requests should be submitted to privacy@fabric.space.

10.2.10. Financial Incentives. Fabric does not currently offer any financial incentives or price differences in connection with the collection, retention, or sale of personal information. If Fabric introduces any such program in the future, Fabric will provide you with notice and an opportunity to opt in before your personal information is used in connection with any financial incentive program.

10.3. EEA, UK, and Swiss Residents (GDPR)

10.3.1. Scope. This Section 10.3 applies to individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland (collectively, "Covered Jurisdictions"). Your rights under this Section are in addition to those described in Section 11 of Fabric's Terms of Service, which addresses GDPR compliance in the context of your use of the Service.

10.3.2. Your Rights Under the GDPR. As a resident of a Covered Jurisdiction, you have the following rights with respect to your personal information, subject to applicable exceptions and limitations under the GDPR and applicable national implementing legislation:

10.3.2.1. Right of Access (Article 15). You have the right to obtain confirmation of whether Fabric processes your personal information and, if so, to receive a copy of that information together with information about the purposes of processing, the categories of data concerned, the recipients or categories of recipients, the retention period, and your other rights under the GDPR.

10.3.2.2. Right to Rectification (Article 16). You have the right to request correction of inaccurate personal information Fabric holds about you and to have incomplete personal information completed.

10.3.2.3. Right to Erasure (Article 17). You have the right to request deletion of your personal information where: (i) the personal information is no longer necessary for the purposes for which it was collected; (ii) you withdraw consent and no other legal basis for processing applies; (iii) you object to processing and there are no overriding legitimate grounds; (iv) the personal information has been unlawfully processed; or (v) deletion is required to comply with a legal obligation.

10.3.2.4. Right to Restriction of Processing (Article 18). You have the right to request that Fabric restrict processing of your personal information in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you oppose deletion, or where Fabric no longer needs the data but you require it for the establishment, exercise, or defense of legal claims.

10.3.2.5. Right to Data Portability (Article 20). Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit that information to another controller.

10.3.2.6. Right to Object (Article 21). You have the right to object at any time to processing of your personal information carried out on the basis of legitimate interests, including profiling, on grounds relating to your particular situation. You also have the right to object at any time to processing of your personal information for direct marketing purposes, including profiling to the extent it relates to direct marketing.

10.3.2.7. Right to Withdraw Consent (Article 7(3)). Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

10.3.2.8. Rights Related to Automated Decision-Making (Article 22). You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects concerning you, except where such processing is necessary for the performance of a contract, authorized by applicable law, or based on your explicit consent.

10.3.3. Legal Bases for Processing. Fabric processes your personal information on the legal bases described in Section 11.3 of Fabric's Terms of Service. Where you wish to understand the specific legal basis applicable to a particular processing activity, you may contact Fabric at privacy@fabric.space.

10.3.4. Submitting a GDPR Request. To exercise any of the rights described in Section 10.3.2, please contact Fabric's privacy team at privacy@fabric.space with the subject line "GDPR Rights Request." Your request should describe the right you wish to exercise and provide sufficient information to verify your identity and locate your personal information in Fabric's systems. Fabric will respond to GDPR rights requests within one (1) month of receipt and may extend this period by an additional two (2) months for complex or numerous requests, with notice to you within the initial one-month period.

10.3.5. Complaints to Supervisory Authorities. If you are located in a Covered Jurisdiction and believe that Fabric has processed your personal information in violation of applicable data protection law, you have the right to lodge a complaint with the supervisory authority in your jurisdiction. A list of EEA supervisory authorities is available at https://edpb.europa.eu. The UK supervisory authority is the Information Commissioner's Office, available at https://ico.org.uk. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner, available at https://www.edoeb.admin.ch. Fabric encourages you to contact Fabric directly at privacy@fabric.space before filing a complaint so that Fabric may have an opportunity to address your concerns.

10.3.6. EU Representative. To the extent required by Article 27 of the GDPR, Fabric will appoint an EU representative to act on Fabric's behalf with respect to Fabric's obligations under the GDPR. Information about Fabric's EU representative will be made available at https://fabric.space/GDPR and upon request to privacy@fabric.space.

10.4. Other US State Residents.

10.4.1. Scope. This Section 10.4 applies to residents of US states that have enacted comprehensive privacy legislation granting consumers rights with respect to their personal information, including without limitation:

(a) Virginia — Virginia Consumer Data Protection Act ("VCDPA");

(b) Colorado — Colorado Privacy Act ("CPA");

(c) Connecticut — Connecticut Data Privacy Act ("CTDPA");

(d) Utah — Utah Consumer Privacy Act ("UCPA");

(e) Texas — Texas Data Privacy and Security Act ("TDPSA");

(f) Oregon — Oregon Consumer Privacy Act ("OCPA"); and

(g) such other states as may enact comprehensive privacy legislation from time to time.

10.4.2. Your Rights. Depending on your state of residence and subject to applicable exceptions and limitations, you may have some or all of the following rights with respect to your personal information:

10.4.2.1. Right to Know / Access. The right to confirm whether Fabric processes your personal information and, in certain states, to access a copy of that personal information.

10.4.2.2. Right to Delete. The right to request deletion of personal information you have provided to Fabric or that Fabric has collected about you, subject to applicable exceptions.

10.4.2.3. Right to Correct. The right to request correction of inaccurate personal information Fabric maintains about you.

10.4.2.4. Right to Opt Out. The right to opt out of: (i) the processing of your personal information for targeted advertising purposes; (ii) the sale of your personal information; and (iii) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning you.

10.4.2.5. Right to Data Portability. The right, in certain states, to obtain a copy of your personal information in a portable and, to the extent technically feasible, readily usable format.

10.4.2.6. Right to Non-Discrimination. The right not to receive discriminatory treatment for exercising any of your privacy rights under applicable state law.

10.4.3. Sensitive Data. Certain state privacy laws require that controllers obtain your consent before processing sensitive personal information, as defined under applicable state law. To the extent Fabric processes sensitive personal information subject to such requirements, Fabric will obtain your consent before doing so, as further described in Section 2.6 of this Privacy Policy.

10.4.4. Submitting a State Privacy Rights Request. To exercise any of the rights described in Section 10.4.2, please contact Fabric at privacy@fabric.space with the subject line "State Privacy Rights Request — [Your State]." Fabric will respond to verified requests within the timeframes required by applicable state law, which vary by jurisdiction but are generally between forty-five (45) and sixty (60) days from receipt, with the possibility of one extension of equal length for complex requests.

10.4.5. Appeals. If Fabric declines to act on your privacy rights request, you have the right, in certain states, to appeal Fabric's decision. To submit an appeal, please contact Fabric at privacy@fabric.space with the subject line "Privacy Rights Appeal — [Your State]" within thirty (30) days of receiving Fabric's decision. Fabric will respond to appeals within the timeframes required by applicable state law. If your appeal is denied, you may have the right to submit a complaint to your state's attorney general or other applicable regulatory authority, and Fabric will provide you with information about how to do so at the time of its appeal response.

10.5. How to Submit a Privacy Rights Request.

10.5.1. General Submission Methods. Regardless of your jurisdiction, you may submit a privacy rights request to Fabric by any of the following methods:

(a) Email. Send your request to privacy@fabric.space with the appropriate subject line as described in the applicable subsection above;

(b) Mail. Send a written request to:

Fabric Global, PBC

Attn: Privacy Team

3501 Ocean View Blvd.

Glendale, CA 91208

10.5.2. Information to Include. To enable Fabric to process your request efficiently, please include the following information in your submission:

(a) your full name and the email address associated with your Account;

(b) your state or country of residence;

(c) a description of the right you wish to exercise and, where applicable, the specific personal information to which your request relates;

(d) if you are an authorized agent submitting a request on behalf of another individual, proof of your authorization to act on that individual's behalf; and

(e) any additional information that may help Fabric locate your personal information in its systems.

10.5.3. Verification. Fabric will verify your identity before processing any privacy rights request. The verification process is designed to protect your personal information and prevent unauthorized access. Fabric will not use information provided for verification purposes for any purpose other than verifying your identity and processing your request. Fabric reserves the right to decline requests that cannot be verified or that are manifestly unfounded, excessive, or repetitive, and will inform you of the reason for any such declination.

10.5.4. No Fee for Requests. Fabric will not charge a fee for processing your privacy rights request unless the request is manifestly unfounded, excessive, or repetitive. In such cases, Fabric may charge a reasonable administrative fee or decline to act on the request. Fabric will notify you before charging any fee.

10.5.5. Limitations. Fabric's ability to fulfill your privacy rights request may be limited by applicable law, legal obligations, and the exceptions described in this Privacy Policy. Where Fabric is unable to fulfill all or part of your request, Fabric will inform you of the reason for the limitation and, where applicable, the steps you can take to seek further recourse.

11. INTERNATIONAL DATA TRANSFERS

11.1. Overview. Fabric is headquartered in the United States, and the Service is operated from the United States. When you access or use the Service from outside the United States, your personal information is transferred to, stored in, and processed in the United States. The United States has not been deemed by the European Commission to provide an adequate level of data protection for purposes of the GDPR, and the level of data protection in the United States may differ from the level of protection afforded in your country of residence. By using the Service, you acknowledge that your personal information will be transferred to and processed in the United States as described in this Privacy Policy.

11.2. Transfers from the EEA, UK, and Switzerland. Where Fabric transfers personal information from the EEA, UK, or Switzerland to the United States or to any other country that has not been deemed to provide an adequate level of data protection under applicable law, Fabric will implement appropriate safeguards to ensure that your personal information receives a level of protection consistent with the requirements of the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection ("FADP"), as applicable. These safeguards may include one or more of the following transfer mechanisms:

11.2.1. Standard Contractual Clauses. Fabric relies primarily on the Standard Contractual Clauses ("SCCs") approved by the European Commission under Commission Implementing Decision (EU) 2021/914 of June 4, 2021 for transfers of personal information from the EEA to third countries. For transfers from the UK, Fabric uses the International Data Transfer Agreement ("IDTA") or the UK Addendum to the EU SCCs approved by the UK Information Commissioner's Office. For transfers from Switzerland, Fabric uses transfer mechanisms recognized under the FADP as amended.

11.2.2. Adequacy Decisions. Where the European Commission, the UK Secretary of State, or the Swiss Federal Council has issued an adequacy decision recognizing that a recipient country provides an adequate level of data protection, Fabric may transfer personal information to that country on the basis of such adequacy decision without implementing additional safeguards.

11.2.3. Binding Corporate Rules. To the extent Fabric implements binding corporate rules approved by a competent supervisory authority in the future, such rules may serve as a transfer mechanism for intra-group transfers of personal information.

11.2.4. Derogations. In the absence of an adequacy decision or appropriate safeguards, Fabric may transfer personal information on the basis of derogations permitted under Article 49 of the GDPR, including where the transfer is necessary for the performance of a contract with you, for the establishment, exercise, or defense of legal claims, or where you have explicitly consented to the transfer after being informed of the possible risks.

11.3. Supplementary Measures. In light of the Court of Justice of the European Union's judgment in Case C-311/18 (Schrems II) and subsequent guidance from the European Data Protection Board, Fabric conducts transfer impact assessments ("TIAs") for transfers of personal information from Covered Jurisdictions to the United States and other third countries, as applicable. Where a TIA identifies risks to the rights and freedoms of data subjects that are not adequately addressed by the applicable transfer mechanism alone, Fabric implements supplementary technical and organizational measures to address those risks, which may include:

(a) end-to-end encryption of personal information in transit and at rest, with encryption keys held by Fabric rather than by the recipient;

(b) pseudonymization of personal information prior to transfer, where technically feasible and consistent with the purpose of the transfer;

(c) contractual restrictions on the recipient's ability to access or use personal information beyond the purposes of the transfer; and

(d) technical measures to prevent access to personal information by public authorities in the recipient country beyond what is permitted under applicable law.

11.4. Sub-Processors and Onward Transfers. Where Fabric engages sub-processors or other third parties that process personal information on Fabric's behalf and are located outside the EEA, UK, or Switzerland, Fabric ensures that such onward transfers are subject to appropriate safeguards consistent with this Section. Fabric includes data transfer obligations in its agreements with sub-processors and requires sub-processors to implement transfer mechanisms equivalent to those described in Section 11.2. A list of Fabric's primary sub-processors and their locations is available upon request to privacy@fabric.space.

11.5. Transfers in Connection with Programs and Activations. Where you participate in a Program or Activation operated by or on behalf of a Client or Partner, your personal information may be transferred to and processed by that Client or Partner in a country outside the EEA, UK, or Switzerland. Fabric will ensure that any such transfer carried out by Fabric on behalf of a Client or Partner is subject to appropriate transfer mechanisms as described in this Section. However, where a Client or Partner independently transfers your personal information as a data controller, that transfer is governed by the Client's or Partner's own privacy policy and data transfer practices, for which Fabric is not responsible.

11.6. Transfers to Advertising Partners. Where Fabric shares personal information with advertising partners located outside the EEA, UK, or Switzerland, Fabric will implement appropriate transfer mechanisms as described in Section 11.2. Advertising partners that receive personal information from Fabric in connection with cross-context behavioral advertising are required to implement equivalent transfer mechanisms and to process personal information in accordance with applicable data protection law. Where you have exercised your right to opt out of the sale or sharing of your personal information under Section 6, Fabric will not transfer your personal information to advertising partners for advertising purposes, regardless of the transfer mechanism in place.

11.7. Access to Your Transfer Safeguards. You have the right to request a copy of the transfer safeguards Fabric has implemented in connection with transfers of your personal information from a Covered Jurisdiction, including a copy of the applicable Standard Contractual Clauses or other transfer mechanism. To request this information, please contact Fabric at privacy@fabric.space with the subject line "Data Transfer Safeguards Request." Fabric will provide the requested information within the timeframes required by applicable law, subject to any confidentiality obligations applicable to the transfer safeguards.

11.8. Changes to Transfer Mechanisms. The legal landscape governing international data transfers is subject to ongoing development, including through judicial decisions, regulatory guidance, and legislative change. Fabric monitors developments in international data transfer law and will update its transfer mechanisms and this Section as necessary to ensure that transfers of personal information from Covered Jurisdictions remain lawful. Material changes to Fabric's international data transfer practices will be reflected in updates to this Privacy Policy in accordance with Section 13.

11.9. US Data Protection Framework. To the extent that Fabric participates in any data transfer framework recognized by the European Commission, the UK Secretary of State, or the Swiss Federal Council as providing an adequate level of protection for transfers of personal information to the United States — including without limitation the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, or any successor framework — Fabric will update this Section to reflect its participation in such framework and the rights available to individuals thereunder. Information about Fabric's participation in any such framework will be available at https://fabric.space/security and upon request to privacy@fabric.space.

11.10. Transfers Outside Covered Jurisdictions. Where personal information is transferred internationally in connection with your use of the Service and you are not located in a Covered Jurisdiction, such transfers are carried out in accordance with Fabric's general security and data handling practices as described in Sections 7 and 8 of this Privacy Policy and applicable law. Fabric does not transfer personal information internationally in a manner that is inconsistent with the purposes described in this Privacy Policy or with applicable law.

12. THIRD-PARTY SERVICES AND LINKS

.

12.1. Overview. The Service may contain links to, integrations with, or references to websites, applications, platforms, and other services operated by third parties, including without limitation Clients, Partners, sponsors, social media platforms, advertising networks, payment processors, identity verification providers, and other organizations (collectively, "Third-Party Services"). This Section describes Fabric's relationship to Third-Party Services and your rights and responsibilities when interacting with them.

12.2. No Responsibility for Third-Party Privacy Practices. Fabric does not control the privacy practices, data collection activities, or security measures of any Third-Party Service, and this Privacy Policy does not apply to any Third-Party Service. When you access or use a Third-Party Service, your personal information is governed solely by that third party's own privacy policy, terms of service, and other applicable agreements, and not by this Privacy Policy. Fabric is not responsible for the content, privacy practices, data handling, security, or accuracy of any Third-Party Service, and Fabric's inclusion of a link to or integration with a Third-Party Service does not constitute an endorsement, sponsorship, or recommendation of that Third-Party Service or its privacy practices.

12.3. Links to Third-Party Websites. The Service may contain hyperlinks to third-party websites. When you click on a link to a third-party website, you will leave the Service and be directed to that third-party website. Fabric has no control over and assumes no responsibility for the content, privacy policies, data collection practices, or security of any third-party website you visit through a link on the Service. We encourage you to review the privacy policy of every website you visit before providing any personal information.

12.4. Third-Party Integrations. The Service may offer integrations with third-party platforms and services, including without limitation social media platforms, ticketing systems, mapping services, payment processors, and identity verification providers. When you use a third-party integration within the Service:

(a) you may be redirected to or interact with the third party's interface within or alongside the Service;

(b) the third party may collect personal information directly from you in accordance with its own privacy policy;

(c) Fabric may receive certain information from the third party as a result of the integration, as described in Section 2.5 of this Privacy Policy; and

(d) your use of the integration is subject to both this Privacy Policy with respect to Fabric's data practices and the third party's own privacy policy with respect to that third party's data practices.

12.5. Social Media Features. The Service may include social media features, such as sharing buttons, embedded feeds, and social login functionality, provided by third-party social media platforms including without limitation Meta, X, Instagram, LinkedIn, and YouTube. These features may collect your IP address, record which pages of the Service you visit, and set cookies or other tracking technologies to enable the feature to function properly. Social media features are governed by the privacy policy of the social media platform that provides them, and Fabric has no control over and assumes no responsibility for the data practices of any social media platform.

12.6. OAuth and Single Sign-On. Where you choose to log in to the Service or an Activation using a third-party OAuth or single sign-on service, as described in Sections 2.4(c) and 2.5(b) of this Privacy Policy, the third-party authentication provider will collect and process your authentication credentials and may collect additional information about your use of the Service through its authentication SDK or API. The collection and use of your personal information by any third-party authentication provider is governed by that provider's own privacy policy. Fabric encourages you to review the privacy policies and permission settings of any authentication provider before using third-party login functionality.

12.7. Advertising Networks. The Service may display advertisements served by third-party advertising networks, as described in Section 6 of this Privacy Policy. Advertising networks may use cookies, pixel tags, and other tracking technologies to collect information about your activity on the Service and on other websites and applications for the purpose of delivering targeted advertisements. The collection and use of your personal information by advertising networks is governed by those networks' own privacy policies. For information about your choices with respect to interest-based advertising delivered by advertising networks, please see Sections 5.5 and 6.5 of this Privacy Policy.

12.8. Client and Partner Services. Where you participate in a Program or Activation operated by or on behalf of a Client or Partner, you may interact with services, platforms, or systems operated directly by that Client or Partner, including without limitation loyalty platforms, ticketing systems, event management tools, and prize fulfillment portals. Fabric is not responsible for the privacy practices of Clients or Partners with respect to personal information they collect directly from you through their own systems or platforms. You are encouraged to review the applicable Client's or Partner's privacy policy before providing personal information directly to that Client or Partner.

12.9. Payment Processors. Where the Service facilitates any financial transaction, payment processing is handled by third-party payment processors. Fabric does not collect or store your full payment card information. Payment information you provide in connection with a transaction is transmitted directly to and processed by the applicable payment processor in accordance with that processor's privacy policy and security practices. Fabric may receive limited transaction information from payment processors, such as a transaction confirmation number or a truncated card number, as necessary to record and administer the transaction.

12.10. Map and Location Services. The Service may incorporate mapping or location services provided by third parties, including without limitation Google Maps. Your use of any third-party mapping or location service within the Service is subject to that third party's terms of service and privacy policy. Fabric encourages you to review the privacy policies of any mapping or location service provider before enabling location features of the Service.

12.11. Analytics Providers. The Service uses third-party analytics providers to help Fabric understand how users interact with the Service, as described in Section 5.3(c) of this Privacy Policy. Analytics providers may collect information about your use of the Service through cookies, SDKs, and other tracking technologies, and may combine that information with data they collect from other sources. The collection and use of your personal information by analytics providers is governed by those providers' own privacy policies. A list of Fabric's primary analytics providers and links to their privacy policies is available at https://fabric.space/analytics-providers.

12.12. Your Responsibility When Using Third-Party Services. When you choose to interact with any Third-Party Service in connection with your use of the Service, you do so at your own risk. Fabric strongly encourages you to:

(a) review the privacy policy and terms of service of any Third-Party Service before providing personal information or enabling integrations;

(b) review and manage the permissions you grant to Third-Party Services with respect to access to your Account, device, or personal information;

(c) be cautious about the personal information you share with Third-Party Services, particularly where those services may share your information with additional third parties; and

(d) contact the relevant Third-Party Service directly if you have questions or concerns about their privacy practices or wish to exercise any rights with respect to personal information they hold about you.

12.13. Removal of Third-Party Links and Integrations. Fabric reserves the right to add, modify, or remove links to and integrations with Third-Party Services at any time, without notice and without liability. The removal of a link to or integration with a Third-Party Service does not affect any personal information that was collected or shared in connection with that integration prior to its removal.

13. CHANGES TO THIS PRIVACY POLICY

13.1. Right to Modify. Fabric reserves the right to modify, amend, update, or replace this Privacy Policy at any time and for any reason, in its sole discretion, to reflect changes in applicable law, regulatory guidance, Fabric's data practices, the Service, or Fabric's business operations. All modifications to this Privacy Policy will be reflected in an updated version of this Privacy Policy posted to the Service, and the "Last Updated" date at the top of this Privacy Policy will be revised accordingly.

13.2. Categories of Changes. Changes to this Privacy Policy may include without limitation:

(a) updates to reflect new or amended privacy laws or regulatory guidance applicable to Fabric's data practices, including changes to CCPA, GDPR, COPPA, or applicable state privacy legislation;

(b) additions or modifications to the categories of personal information Fabric collects, the purposes for which Fabric uses personal information, or the third parties with whom Fabric shares personal information;

(c) changes to Fabric's data retention periods, security practices, or international data transfer mechanisms;

(d) additions of new features, products, Programs, or Activations that involve new data collection or processing activities;

(e) changes to the rights available to users under applicable privacy law and the procedures for exercising those rights;

(f) updates to Fabric's advertising data sharing practices or opt-out mechanisms; and

(g) corrections of typographical errors, clarifications of existing provisions, and updates to contact information or URLs.

13.3. Material vs. Non-Material Changes.

13.3.1. Material Changes. A change to this Privacy Policy is material if it: (i) introduces a new category of personal information that Fabric will collect; (ii) introduces a new purpose for which Fabric will use personal information that is materially different from the purposes described in this Privacy Policy at the time of your last acceptance; (iii) introduces a new category of third party with whom Fabric will share personal information in a manner that could affect your rights or expectations; (iv) materially changes Fabric's advertising data sharing practices or your opt-out rights under Section 6; (v) materially changes your rights under Section 10 or the procedures for exercising those rights; or (vi) materially changes Fabric's international data transfer practices in a manner that could affect the level of protection afforded to your personal information.

13.3.2. Non-Material Changes. Changes that do not meet the threshold described in Section 13.3(a) — including without limitation clarifications of existing provisions, corrections of typographical errors, updates to contact information or URLs, additions of new features consistent with existing data practices, and updates to reflect changes in applicable law that do not alter your substantive rights — are non-material changes and do not require advance notice.

13.4. Notice of Material Changes. Where Fabric determines that a change to this Privacy Policy constitutes a material change, Fabric will provide you with advance notice of such change by one or more of the following methods prior to the effective date of the change:

(a) posting a prominent notice on the Service or within your Account dashboard describing the nature of the change and its effective date;

(b) sending a notification to the email address associated with your Account describing the nature of the change and its effective date; or

(c) displaying an in-app or in-platform alert requiring your acknowledgment of the change before continued use of the Service.

13.5. Effective Date of Changes.

13.5.1. Non-Material Changes. Non-material changes to this Privacy Policy become effective upon posting of the updated Privacy Policy to the Service.

13.5.2. Material Changes — New Users. For individuals who create an Account or first access the Service after the effective date of a material change, the updated Privacy Policy applies from the date of first access.

13.5.3. Material Changes — Existing Users. For existing users, material changes become effective thirty (30) days after notice is provided in accordance with Section 13.4, unless a shorter effective date is required by applicable law or necessary to address an urgent security, legal, or operational issue. Where a material change requires your consent under applicable law — including where Fabric introduces a new use of sensitive personal information or a new basis for processing personal information of EEA, UK, or Swiss residents — the change will not apply to your personal information until you provide the required consent.

13.6. Continued Use as Acceptance. Your continued access to or use of the Service following the effective date of any modification to this Privacy Policy constitutes your acceptance of the modified Privacy Policy and your agreement to be bound by its terms. If you do not agree to the modified Privacy Policy, you must discontinue your use of the Service and may close your Account in accordance with Section 3.5 of Fabric's Terms of Service prior to the effective date of the modification.

13.7. Consent-Based Changes. Where a proposed change to this Privacy Policy would involve using your personal information in a manner that requires your consent under applicable law — including without limitation the introduction of a new purpose for processing personal information of EEA, UK, or Swiss residents that is not compatible with the original purpose of collection — Fabric will seek your explicit consent to the new processing activity before applying the change to your personal information. Your decision not to consent will not affect your ability to continue using the Service for purposes that do not involve the new processing activity, though certain features or programs that rely on the new processing activity may not be available to you.

13.8. Prior Versions. Fabric will maintain an archive of prior versions of this Privacy Policy and will make prior versions available upon reasonable written request to privacy@fabric.space. The availability of prior versions is intended to assist users in understanding how Fabric's data practices have evolved over time and to support the resolution of any disputes about the Privacy Policy in effect at a particular point in time.

13.9. Regulatory Changes. Where changes to applicable privacy law require modifications to this Privacy Policy or to Fabric's data practices, Fabric will implement such changes as required by law and will update this Privacy Policy accordingly. Where a regulatory change grants you new rights or imposes new obligations on Fabric with respect to your personal information, those rights and obligations apply from the effective date of the applicable law regardless of whether this Privacy Policy has been updated to reflect them, and Fabric will endeavor to update this Privacy Policy promptly to reflect any such regulatory changes.

13.10. Changes Affecting Programs and Activations. Where a change to this Privacy Policy affects the collection, use, or sharing of personal information in connection with a specific Program or Activation, Fabric will provide notice of such change through the communication channels associated with that Program or Activation, in addition to the general notice methods described in Section 13.4. Where a Program or Activation is operated on behalf of a Client or Partner, Fabric will coordinate with the applicable Client or Partner regarding notice of any changes that affect data practices associated with that Program or Activation.

14. CONTACT INFORMATION

14.1. Overview. Fabric maintains separate contact channels for different categories of privacy-related inquiries to ensure that your communications are routed to the appropriate team and handled within the timeframes required by applicable law. Please use the contact information most appropriate to the nature of your inquiry, as described in this Section.

14.2. General Privacy Inquiries. For general questions or concerns about this Privacy Policy or Fabric's data practices, please contact Fabric's privacy team at:

Fabric Global, PBC

Attn: Privacy Team

3501 Ocean View Blvd.

Glendale, CA 91208

Email: privacy@fabric.space

Subject Line: Privacy Inquiry

Fabric will endeavor to respond to general privacy inquiries within thirty (30) days of receipt. General inquiries that do not relate to the exercise of a specific privacy right will be addressed as promptly as practicable, taking into account the nature and complexity of the inquiry.

14.3. Privacy Rights Requests. For requests to exercise your privacy rights under applicable law, including requests submitted under the CCPA, GDPR, or applicable state privacy legislation as described in Section 10 of this Privacy Policy, please contact Fabric at:

Email: privacy@fabric.space

Subject Line: [Applicable Rights Request Type — e.g., "CCPA Rights Request," "GDPR Rights Request," "State Privacy Rights Request — [Your State]"]

Online Form: https://fabric.space/support

Mail:

Fabric Global, PBC

Attn: Privacy Team — Rights Request

3501 Ocean View Blvd.

Glendale, CA 91208

Fabric will acknowledge receipt of your privacy rights request within ten (10) business days and will respond to verified requests within the timeframes required by applicable law, as described in Section 10 of this Privacy Policy. For information about the verification process applicable to privacy rights requests, please see Section 10.3.3.

14.4. California-Specific Contact. In addition to the general privacy rights contact information described in Section 14.3, California residents may exercise their rights under the CCPA, including their right to opt out of the sale or sharing of their personal information, through the following California-specific channels:

14.4.1. Do Not Sell or Share My Personal Information. To opt out of the sale or sharing of your personal information for advertising purposes, click the "Do Not Sell or Share My Personal Information" link available in the footer of Fabric's website and within the App's settings menu, or visit https://fabric.space/opt-out.

14.4.2. Authorized Agent Submissions. California residents submitting CCPA rights requests through an authorized agent should direct their agent to contact Fabric at privacy@fabric.space with the subject line "CCPA Authorized Agent Request" and to include written proof of authorization as described in Section 10.2.9 of this Privacy Policy.

14.5. Data Protection Officer. To the extent required by the GDPR or applicable national implementing legislation, Fabric will designate a Data Protection Officer ("DPO") responsible for overseeing Fabric's compliance with applicable data protection law. Where a DPO has been designated, contact information for the DPO will be made available at https://fabric.space/gdpr and upon request to privacy@fabric.space. Until a DPO is formally designated, privacy inquiries from individuals in Covered Jurisdictions should be directed to privacy@fabric.space with the subject line "GDPR Inquiry."

14.6. EU Representative. As described in Section 10.3.6 of this Privacy Policy, Fabric will appoint an EU representative to act on Fabric's behalf with respect to Fabric's GDPR obligations, to the extent required by Article 27 of the GDPR. Once appointed, contact information for Fabric's EU representative will be made available at https://fabric.space/gdpr and upon request to privacy@fabric.space. The EU representative may be contacted by individuals in EEA member states and by supervisory authorities in addition to or instead of contacting Fabric directly.

14.7. UK Representative. To the extent required by the UK GDPR and the Data Protection Act 2018, Fabric will appoint a UK representative to act on Fabric's behalf with respect to Fabric's UK data protection obligations. Once appointed, contact information for Fabric's UK representative will be made available at https://fabric.space/gdpr and upon request to privacy@fabric.space. The UK representative may be contacted by individuals in the United Kingdom and by the Information Commissioner's Office in addition to or instead of contacting Fabric directly.

14.8. Security Inquiries and Vulnerability Reporting. For inquiries regarding Fabric's data security practices, to report a suspected security vulnerability or data breach, or to request information about Fabric's security certifications and audit status, please contact Fabric's security team at:

Email: security@fabric.space

Subject Line: Security Inquiry / Vulnerability Report

Attn: Security Team

3501 Ocean View Blvd.

Glendale, CA 91208

If you believe you have discovered a security vulnerability in the Service, please contact security@fabric.space promptly and provide a detailed description of the vulnerability, the steps required to reproduce it, and any other information that may assist Fabric in assessing and remediating the issue. Fabric is committed to working with security researchers in good faith and will not take legal action against individuals who report security vulnerabilities in accordance with this responsible disclosure process.

14.9. COPPA and Children's Privacy. For inquiries related to the collection of personal information from children, including reports of suspected underage users and parental rights requests under COPPA as described in Section 9 of this Privacy Policy, please contact Fabric at:

Email: privacy@fabric.space

Subject Line: Minor — Privacy Concern / COPPA — Parental Rights Request

Attn: Privacy Team — Children's Privacy

3501 Ocean View Blvd.

Glendale, CA 91208

Fabric treats all COPPA-related inquiries and parental rights requests as urgent and will prioritize their review and resolution above general privacy inquiries.

14.10. Supervisory Authorities. If you are located in the EEA, UK, or Switzerland and wish to lodge a complaint with a supervisory authority regarding Fabric's data practices, you may contact the relevant supervisory authority for your jurisdiction as described in Section 10.3.5 of this Privacy Policy. Fabric encourages you to contact Fabric directly at privacy@fabric.space before filing a supervisory authority complaint so that Fabric has an opportunity to address your concerns informally. The relevant supervisory authority contact information is as follows:

14.10.1. EEA Member States. A list of EEA supervisory authorities and their contact information is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

14.10.2. United Kingdom. The Information Commissioner's Office ("ICO") is the UK supervisory authority. The ICO can be contacted at https://ico.org.uk/make-a-complaint or by telephone at 0303 123 1113.

14.10.3. Switzerland. The Federal Data Protection and Information Commissioner ("FDPIC") is the Swiss supervisory authority. The FDPIC can be contacted at https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html.

14.11. Program and Activation-Specific Inquiries. For privacy inquiries specific to a particular Program or Activation in which you participate, including inquiries about data practices of the applicable Client or Partner, please refer to the privacy notice or contact information provided in the applicable Program Terms. Where you are unable to locate Program-specific contact information, you may contact Fabric at privacy@fabric.space with the subject line "Program Privacy Inquiry — [Program Name]" and Fabric will endeavor to direct your inquiry to the appropriate party.

14.12. Updates to Contact Information. Fabric may update the contact information set forth in this Section from time to time as Fabric's operations and organizational structure evolve. The most current contact information will always be available on the Service at https://fabric.space/privacy. Fabric encourages you to check this Section periodically to ensure that any privacy-related communications you direct to Fabric reach the correct recipient. In the event of any discrepancy between contact information set forth in this Privacy Policy and contact information published on the Service, the information published on the Service shall control.

© 2026 Fabric Global PBC

  • Investors
  • Terms
  • Privacy