Based Stream Tools logo

Based Stream Tools

Privacy Policy

Last updated: October 1, 2025

Who We Are

Based Stream Tools is operated by Actuator Digital Pty Ltd (ABN 44 617 792 293), registered in Queensland, Australia.

Contact: For privacy-related questions, contact us at basedstreamtools@gmail.com.

Roles & Responsibilities

Roles: For account, billing, and website analytics data, Actuator Digital Pty Ltd acts as a data controller. For streamer-provided content and personal data processed through overlays (e.g., chat messages, usernames, donation/subscription events) we act as a data processor on your behalf.

DPA: Where we act as a processor, the Data Processing Addendum (DPA) forms part of this Policy and our Terms. The DPA includes our security measures, subprocessors, and international transfer safeguards.

1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Username and display name
  • Profile picture (if provided)
  • Connected streaming platform accounts (Twitch, YouTube, etc.)
  • Payment information (processed securely by our payment providers)

Usage Information

We automatically collect information about how you use our Service:

  • Feature usage and preferences
  • Stream overlay configurations and customizations
  • Log data (IP address, browser type, device information)
  • Performance and analytics data
  • Error reports and crash data

Content and Communications

  • Content you create using our tools (overlays, graphics, configurations)
  • Support messages and feedback you send us
  • Beta feedback and feature requests

2. How We Use Your Information

Service Provision

  • Provide and maintain the Based Stream Tools service
  • Process your overlay and tool configurations
  • Connect with third-party streaming platforms
  • Handle billing and subscription management
  • Provide customer support

Improvements and Analytics

  • Analyze usage patterns to improve our Service
  • Develop new features based on user feedback
  • Monitor performance and fix bugs
  • Ensure security and prevent abuse

Communications

  • Send service-related notifications (account changes, billing, etc.)
  • Respond to support requests
  • Notify you about important updates or changes

Marketing consent: We send marketing communications only with your explicit consent (opt-in at sign-up). You can withdraw consent at any time via the unsubscribe link in emails or in account settings. Service (transactional) emails are not marketing.

3. Legal Bases for Processing (EU/UK)

We process personal data under the following legal bases:

  • Contract: to provide the Service (account creation, payment, overlays)
  • Legitimate Interests: to secure and improve the Service (analytics with safeguards; fraud prevention)
  • Consent: marketing emails and non-essential cookies
  • Legal obligation: tax and accounting compliance

4. Information Sharing

We do not sell your personal information. We may share information in these limited circumstances:

Service Providers

Vendors: We use vetted subprocessors to deliver the Service (e.g., cloud hosting, email delivery, analytics, payments). A current list and purposes are published at /legal/subprocessors and updated when changes occur.

  • Payment processors (Stripe, PayPal) for billing
  • Email service providers for communications
  • Analytics services (Google Analytics) for usage insights
  • Cloud hosting providers (AWS, etc.) for data storage

Third-Party Platforms

We share necessary data with streaming platforms (Twitch, YouTube) to provide our integration services, strictly according to their APIs and your permissions.

Legal Requirements

We may disclose information if required by law, court order, or to:

  • Protect our rights and property
  • Ensure user safety
  • Investigate fraud or abuse
  • Comply with legal obligations

4. Cookies and Tracking

We use cookies and similar technologies to:

  • Keep you logged in
  • Remember your preferences
  • Analyze website usage
  • Improve security

Types of cookies we use:

  • Essential: Required for the Service to function
  • Analytics: Help us understand usage patterns
  • Functional: Remember your settings and preferences

Cookie choices: We display a cookie prompt to obtain consent for non-essential cookies and respect Global Privacy Control (GPC) signals. See our Cookie Notice for categories, providers, and retention.

You can control cookies through your browser settings, but disabling essential cookies may affect Service functionality.

5. Data Security

We implement appropriate security measures to protect your information:

  • Encryption in transit and at rest
  • Secure hosting infrastructure
  • Access controls and authentication
  • Regular security audits
  • Employee training on data protection

Security: We apply layered safeguards including encryption in transit and at rest, access controls, and monitoring.

Incidents: If we become aware of a data incident affecting your personal data, we will notify you and, where required, regulators without undue delay, including details, impact, and remediation steps.

However, no internet transmission is 100% secure. We cannot guarantee absolute security but we continuously work to improve our protections.

6. Data Retention

Retention by Category:

  • Account profile & credentials: retained while the account is active; deleted within 30 days after account deletion
  • Billing records: retained 7 years (legal requirement)
  • Audit & security logs: 12 months (unless needed longer for investigations)
  • Overlay configurations/content: retained until you delete them or disconnect the integration

We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our Terms of Service.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

General Rights

  • Access: Request copies of your personal data
  • Correction: Update inaccurate information
  • Deletion: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Opt-out: Unsubscribe from marketing emails

Australian Privacy Rights

Under the Australian Privacy Principles, you have additional rights to access and correct your personal information. Contact us to exercise these rights.

EU/UK Rights (GDPR)

If you're in the EU/UK, you have additional rights under GDPR including:

  • Right to object to processing
  • Right to restrict processing
  • Right to withdraw consent
  • Right to lodge a complaint with supervisory authorities

Your rights & how to exercise them: To access, correct, delete, or export your data—or to object/restrict processing—contact basedstreamtools@gmail.com. We verify identity and respond within 30 days (may extend once by 60 days for complex requests).

8. International Data Transfers

Our Service is hosted and operated from Australia. If you're accessing from outside Australia, your information may be transferred to and processed in Australia and other countries where our service providers operate.

Transfers & safeguards: When transferring personal data outside your region, we use EU Standard Contractual Clauses (SCCs) and, where applicable, the UK IDTA/Addendum, plus organizational and technical measures.

9. Children's Privacy

Age limits: The Service is not for children under 13. Users 13–17 require parental consent; we may request reasonable proof. If we learn data was collected from a child under 13, we delete it.

If we learn we have collected information from a child under 13, we will delete it immediately. Contact us if you believe we have such information.

10. Third-Party Services

Third-party platforms: When you connect Twitch/YouTube/Discord/OBS, we only access the data necessary to provide the requested features and store it for the minimum time needed. Disconnecting a platform or deleting your account deletes or anonymizes related data within 30 days. We are not affiliated with or endorsed by these platforms.

These services have their own privacy policies that govern how they handle your information. We encourage you to review them:

  • Twitch Privacy Policy
  • YouTube Privacy Policy
  • Discord Privacy Policy
  • OBS Privacy Policy

11. California Privacy Rights (CPRA)

No "sale" or "sharing": We do not sell or share personal information for cross-context behavioral advertising. If this changes, we will provide a Do Not Sell or Share link and honor GPC signals.

12. Overlay Data We Handle

Overlay data we handle (examples):

  • Leaderboard/Goals: usernames, contribution counts, timestamps
  • AI Swear Jar: on-stream audio/chat text analyzed for flagged terms; thresholds configurable; no model training on your content unless you opt-in
  • Chat Overlay: messages and display names to render on-stream

Controls: You can disable overlays at any time. Retention: event logs max 30–90 days (configurable), then deleted or aggregated.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide 30 days' prior notice via email and/or prominent notice on our Service.

Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: basedstreamtools@gmail.com

Company: Actuator Digital Pty Ltd

ABN: 44 617 792 293

Jurisdiction: Queensland, Australia

We aim to respond to privacy inquiries within 3 business days.