Privacy policy

1. Who we are and who this covers

The Voice Store (“the Platform”) hosts storefronts for voice actors. This policy explains what we collect from actors (the merchants who run storefronts), customers (people who buy from a storefront) and visitors, and what we do with it. For customer data, the actor whose storefront you use is the controller of the commercial relationship and the Platform processes data on the actor’s behalf, except for the Platform’s own records (payments, licence receipts, security logs) where the Platform is the controller. [Counsel to confirm the controller/processor split for the operating jurisdiction.]

2. What we collect

Actors

  • Account: name, legal name, email, password hash, country, time zone, two-factor settings.
  • Storefront content: display name, bio, avatar, samples, portfolio, credentials, pricing, licence terms, custom domains.
  • Voice verification: the video you record, the audio extracted from it, the transcript and a similarity score. A hash of the verification media, the script and the outcome are kept as a permanent consent record.
  • Billing: Stripe customer and Connect account identifiers, plan history, ledger entries, payouts, usage invoices. Card numbers never reach us.
  • Usage: sign-ins, dashboard actions, API key use, webhook deliveries, audit log entries.

Customers

  • Email, and optionally name and company, per storefront. The same person on two storefronts is two separate records.
  • Orders, carts, credit balance and bundles, Stripe customer identifier for that storefront.
  • For AI generations: the script, the chosen voice and sample, the declared use, the generated audio, and the licence receipt.
  • For projects: briefs, reference files, delivered files, messages with the actor.
  • For live sessions: booking times and connection details.

Visitors

  • Server logs: IP address, user agent, pages requested, timestamps.
  • Demo usage: a per-visitor counter, the demo script and the generated audio, kept briefly for rate limiting and abuse review.
  • Storefront analytics for the actor, on plans that include them: page views and referrers, aggregated.

3. Why we use it

  • To run your storefront or fulfil your order (performance of a contract).
  • To process payments and payouts, keep books and pay tax (legal obligation).
  • To prove that a voice belongs to the actor who sells it and that each generation was licensed (legitimate interest and legal obligation: these records protect the actor’s likeness and both parties in a dispute).
  • To prevent fraud, refund abuse and misuse of voices, including rate limiting and script screening (legitimate interest).
  • To send transactional email: sign-in links, receipts, order updates, verification and password reset (contract). We do not send marketing email without consent.

4. Voice audio and AI processing

Synthetic voice generation runs on inference infrastructure the Platform operates (a dedicated GPU endpoint that is shared between storefronts). Voice samples, verification recordings and generated audio are never sent to third-party model APIs. Script text is screened before generation; screening may use a hosted language model that receives the text of the script only, never audio. Verification transcripts are produced with a speech-to-text model on the same infrastructure.

No voice data is used to train models that are offered to anyone other than the actor who owns the voice.

5. Who we share it with

  • Stripe for payments, payouts and plan billing. Stripe’s own privacy policy applies to card data.
  • The actor whose storefront you buy from sees your email, name, company, orders, scripts and files, and the licence receipts of your generations.
  • The customer of a generation receives the licence receipt naming the actor’s storefront and voice, but not the actor’s email.
  • Infrastructure providers: hosting, database, private file storage and the email delivery service, each under a data processing agreement. [Counsel to list them.]
  • Authorities where the law requires.

We do not sell personal data.

6. Cookies

We set only functional cookies: a session cookie for signed-in actors on the dashboard, and a separate per-storefront session cookie for customers. No advertising or cross-site tracking cookies are set by the Platform. Actors on plans with analytics see aggregated counts, not individual visitors.

7. Security

Media is stored privately and served only through signed, expiring links. Passwords are hashed. Email addresses in permanent evidence records are replaced by a keyed hash. Access to production data is limited to staff with a need to act, and staff actions on accounts are logged.

8. Retention and deletion

  • Storefront content, voices, samples and voice models: deleted within 30 days of the actor closing their storefront.
  • Generated audio: kept while the customer’s account exists or for the download period shown at delivery, then deleted.
  • Demo audio and scripts: deleted within 7 days.
  • Verification video and audio: kept while the voice is on sale; after deletion only the hash, transcript outcome and consent record remain.
  • Orders, ledger entries, payouts and invoices: kept for the period tax and accounting law requires (typically 7 to 10 years).
  • Licence receipts and consent records: kept indefinitely in hashed form; they outlive account deletion because they evidence a licence that continues to exist.
  • Server logs and rate-limit counters: 30 days or less.

Actors delete their account from the dashboard. Customers request deletion from the storefront’s account page or by writing to the actor or to us; we remove personal data that is not required to be kept and mark evidence records as belonging to a deleted account.

9. Your rights

Depending on where you live you may have the right to access, correct, export or delete your data, to object to or restrict processing, and to complain to a supervisory authority. Write to the contact address on the Platform site; we answer within the period the law sets. For customer data on a storefront we may forward your request to the actor or ask them to confirm it.

10. International transfers

Our infrastructure runs in [Counsel to set regions]. Where data leaves the region you live in, transfers rely on standard contractual clauses or an equivalent mechanism with the provider.

11. Children

The Platform is for adults. We do not knowingly collect data from anyone under 18; storefronts may not be opened by minors.

12. Changes and contact

We may update this policy; material changes are notified by email to actors and shown on storefronts, and the version string above changes. [Counsel to set the operating entity’s legal name, address and privacy contact.]