WeMatch System Policy (Data Validation)
Contents
- 1. Introduction
- 2. Data controller
- 3. What WeMatch is
- 4. Who can use WeMatch — age restriction
- 5. Data sources and collection
- 6. How validation works
- 7. How information is shared
- 8. Data retention and deletion
- 9. Security and sensitive data
- 10. Your rights and controls
- 11. Transparency and appeals
- 12. Limits of liability
- 13. Compliance and international transfers
- 14. Security incident notification
- 15. Changes to this Policy
- 16. Contact
1. Introduction
WeMatch is the proprietary achievement validation and reputation system of Wemany Inc. ("WEMANY", "we"). It lets a community member prove, with real and verifiable data, that they meet the requirements defined by that community's creator (for example, a number of sales, hours of activity or completed modules), and thereby earn roles, badges and a Mission Score.
This Policy explains what WeMatch does, what data it uses, where it comes from, how long it is kept, who can see it and what rights you have over it. It forms part of our Privacy Policy and should be read together with it, with our Terms of Service and with the Community Creator Terms.
Principles governing WeMatch:
- Access to data only with your explicit consent.
- Minimization: we access the least amount of data possible to validate.
- Time limitation: we do not keep raw data indefinitely.
- Purpose limitation: we use the data only for the purposes described here.
- User control: you can connect, disconnect and delete at any time.
- Verification, not surveillance: we validate that a requirement is met, we do not monitor your life.
2. Data controller
With respect to the WeMatch system, the Mission Score and the public reputation profile, the data controller is:
Wemany Inc. 8 The Green, Suite R, Dover, DE 19901, United States EIN: 38-4357462 Privacy contact: privacy@wemany.com
WEMANY decides the purposes and means of the validation system, so it acts as controller of the data it processes for WeMatch and the Mission Score.
Data that a community creator manages within their own community for their own purposes (for example, their member list or gamification settings) is governed by the controller/processor relationship described in the Community Creator Terms and their Data Processing Addendum, where the creator acts as controller and WEMANY as processor under their instructions.
3. What WeMatch is
3.1 Overview
WeMatch is a validation and analytics system that:
- Verifies whether a member meets the requirements ("milestones") a creator defines for a role.
- Reads metrics from external accounts the member connects voluntarily.
- Assigns roles, badges and the "Verified by WEMANY" badge when the requirement is met.
- Feeds the Mission Score, a 0-to-100 score updated daily with the member's real activity.
- Gives creators aggregated metrics for their community's gamification.
3.2 What the "Verified by WEMANY" badge certifies — and what it does NOT certify
This is important and we define it precisely to avoid misunderstandings:
The "Verified by WEMANY" badge certifies that a data source connected by the member reported, at a given moment, a metric that met the threshold defined by the community creator.
The badge is NOT, and does not imply:
- an audit, accounting review or professional opinion on the member's finances or activity;
- a guarantee that the metric remains true after the validation date;
- a validation of the truthfulness of the data reported by the source platform;
- a recommendation, endorsement or backing by WEMANY of the member, their products, services or results.
WeMatch reflects what an external source reported at a point in time. The accuracy of that data depends on the source, not on WEMANY.
4. Who can use WeMatch — age restriction
Access to WeMatch, to connecting external accounts and to the Mission Score based on external data is reserved for people over 18, or over 16 with the verifiable consent of a parent or legal guardian.
Minor members can take part in communities (post, comment, access age-appropriate content), but:
- They may not connect any external account of any kind (including gaming platforms, social networks, commerce or financial services).
- They do not take part in WeMatch and do not receive a Mission Score based on external data.
- They do not have a public reputation profile based on external data.
This restriction protects minors and allows us to comply with child protection legislation, including the Children's Online Privacy Protection Act (COPPA) in the United States and equivalent rules in the European Union and the countries where we operate. If we detect that a minor has connected an external account by circumventing this restriction, we will delete the associated data and deactivate the connection.
5. Data sources and collection
5.1 External accounts connected by the member
When you decide to connect an external account, you do so through an authorization process (for example OAuth) in which the source platform itself tells you which permissions you grant. We only access accounts and data that are public or for which you have given us express authorization through that process.
The categories of sources WeMatch can read include, depending on the connectors available at any given time:
- Commerce and business: e-commerce and sales platforms (for example, sales or order metrics).
- Creation and audience: video, streaming and social media platforms (for example, public activity metrics, streaming hours or posts).
- Financial and trading data: payment and trading platforms (for example, reported volumes or results). This data is treated as a sensitive category and receives the additional safeguards described in Section 9.
- Video games and gaming platforms: public or authorized gaming activity statistics.
- WEMANY native data: your activity within the platform (participation, content, completed modules, event attendance).
Public connector list. WEMANY maintains an up-to-date list of the available connectors and the data each one reads. We only enable connectors whose use is allowed by the source platform's terms and for which the member grants authorization. We do not access data through unauthorized means or contrary to the source platforms' terms.
5.2 Activity data on WEMANY
For the Mission Score and native gamification, WeMatch uses your activity within the platform: participation patterns, content creation and interaction, completed modules and courses, event attendance and membership history.
6. How validation works
6.1 Consent process
- Explicit consent: before connecting an account, you are clearly told which data will be read and for what.
- Granular control: you choose which accounts to connect and, when the source platform allows it, which data to share.
- Purpose limitation: the data is used only to validate the milestones defined by the creator and for your Mission Score.
- Revocation: you can disconnect an account at any time, which stops the reading of new data and triggers the deletion described in Section 8.
6.2 How roles and badges are granted
The creator defines a milestone (for example, "sales threshold X on platform Y"). When a source connected by the member reports a metric that meets that threshold, WeMatch automatically assigns the corresponding role or badge. The assignment reflects what the source reported at the time of validation.
6.3 Accuracy and fairness
- Where possible, we cross-check data from several sources to detect inconsistencies or possible fraud.
- We apply human oversight to sensitive validations.
- There is an appeals process (Section 11) so you can dispute a validation you consider incorrect.
7. How information is shared
7.1 Public reputation profile (opt-in)
Your Mission Score, your badges and your verified achievements may be shown on a public profile, but only if you expressly turn it on. This feature is voluntary, optional and revocable:
- It is off by default for data coming from external accounts.
- You control, granularly, which elements are visible and to whom.
- You can turn it off at any time; when you do, the information stops being shown publicly.
- Any achievement shown is presented with its context: the source that reported it and the validation date, under the framing of Section 3.2.
7.2 Community creators
Creators can access:
- Aggregated and anonymous analytics: validation trends and distributions of their community, health and authenticity metrics, without identifying underlying personal data.
- Individual member data, only with the member's consent: badge and achievement status, credentials relevant to the community's purpose, and gamification progress.
Creators cannot:
- access the underlying raw data used to validate (for example, actual sales figures or external account data);
- track a member across different communities without their consent;
- use validation data to discriminate unlawfully;
- share a member's validation data with third parties without authorization.
Creators' obligations regarding this data are detailed in the Community Creator Terms and their Data Processing Addendum.
7.3 Service providers
We share data with the providers strictly necessary to operate the system, including our cloud infrastructure provider (data is hosted on Amazon Web Services) and our payment providers. These providers act as processors, only process data according to our instructions and are subject to confidentiality and security obligations.
7.4 Legal requirements
We may disclose information when required by a competent authority through a valid order, or when necessary to protect the rights, safety or integrity of the platform and its users.
8. Data retention and deletion
This section precisely defines our retention policy, because it is central to your privacy.
8.1 Raw data from external accounts
The raw data we read from your external accounts (for example, detailed metrics reported by the source) is kept for a maximum of 90 days on a rolling window. We keep this window because the Mission Score is recalculated daily and needs recent data to reflect your real activity. After 90 days, the raw data is deleted.
8.2 Validation result (achievement)
The validation result — that is, the fact that you met a threshold on a given date, together with the source and the date — is kept permanently for as long as the badge or achievement remains visible on your account or profile. We keep the result, not the underlying raw data. If you delete the achievement, close your account or withdraw display consent, the result is deleted in accordance with Section 8.4.
8.3 Aggregated and anonymous data
Aggregated and anonymized analytics, which do not allow a person to be identified, may be kept for service improvement purposes.
8.4 Deletion at the user's request and automatic deletion
- On request: when you disconnect an account, we stop reading new data and delete the associated raw data within the 90-day window or earlier if you ask; when you close your account, we delete the associated WeMatch data, including validation results.
- Automatic: expired access tokens are deleted shortly after expiry; temporary processing data is deleted when validation is completed.
9. Security and sensitive data
9.1 Security measures
- Encryption of data in transit and at rest.
- Secure API connections with rate limits.
- Strengthened authentication and role-based permissions for internal access.
- Audit logs of data access.
- Periodic security assessments.
9.2 Financial and trading data (sensitive category)
When a connector reads financial or trading data (for example, payment, commerce or trading platforms), we apply additional safeguards:
- we preferably store the validation result and not the raw financial figures beyond the 90-day window;
- we restrict internal access to this data;
- we do not share raw financial figures with creators or third parties.
9.3 Privacy by design
We apply data minimization, pseudonymization where possible and anonymization techniques for aggregated analytics. No system is completely secure, so we cannot guarantee absolute security, but we work to protect your data in line with industry best practices.
10. Your rights and controls
You have the right to:
- Selective connection: choose which accounts to connect and, when the source allows it, which data to share.
- Real-time control: connect or disconnect accounts at any time.
- Transparency: see which validations apply to your account and which sources contributed.
- Rectification: request correction of an inaccurate validation result.
- Appeal: challenge a validation decision (Section 11).
- Deletion: request deletion of your data and validation results.
- Visibility: control who sees your badges and your Mission Score.
- Marketing objection: prevent the use of validation data for marketing purposes.
Depending on where you live, you also have specific rights:
- EU/EEA/UK residents (GDPR): the legal basis for processing connected accounts is your consent, which you can withdraw at any time; you have the right of access, rectification, erasure, portability, restriction and objection, and to lodge a complaint with your supervisory authority.
- California residents (CCPA/CPRA): the right to know, delete, correct, opt out of the sale or sharing of data, and limit the use of sensitive personal information, without discrimination for exercising your rights.
- Colombia residents (Law 1581 of 2012 — Habeas Data): the right to know, update, rectify and delete your data, revoke authorization and file inquiries and complaints.
To exercise any of these rights, write to privacy@wemany.com. We will respond within the deadlines required by applicable law.
11. Transparency and appeals
- Validation status: you can see what has been validated on your account.
- Sources: we tell you which connected accounts contributed to a validation.
- History: we keep a record of changes to your validations.
- Appeal: if you believe a validation is incorrect, you can appeal by writing to appeals@wemany.com. Appeals are reviewed by staff other than those who made the initial decision, within a reasonable time.
12. Limits of liability
WeMatch is a verification tool that reflects what an external source reported at a given time. To the maximum extent permitted by law:
- WEMANY does not guarantee the truthfulness or accuracy of the data reported by source platforms; it validates that a threshold was met with the available information, without auditing its content.
- WEMANY is not responsible for the use third parties make of a badge, role, achievement or Mission Score, nor for improper or fraudulent use of the verification system by any person, including the verified member or those who interact with them.
- A badge or Mission Score does not constitute advice, a recommendation, an endorsement or a guarantee by WEMANY regarding the member, their products, services or results.
- Members and third parties are solely responsible for the decisions they make on the basis of the reputation information displayed.
These limits apply together with those in the Terms of Service and do not affect rights the law grants on a mandatory basis.
13. Compliance and international transfers
- Legal basis (GDPR): consent for connected accounts; legitimate interest and performance of the contract for the native activity needed to provide the service.
- Third parties / APIs: we respect the terms of service, usage limits and policies of each connected platform, including their data retention and refresh rules. When a platform requires data to be deleted or refreshed within set periods, we adjust our retention to those rules.
- International transfers: data is hosted and processed in the United States (Amazon Web Services) and other countries. For transfers from the EU/EEA/UK we apply appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission.
- Minors: we apply the restrictions of Section 4 in accordance with COPPA and equivalent rules.
14. Security incident notification
We have security monitoring, incident classification and containment, and impact analysis. In the event of a security breach affecting your data:
- we will notify the competent authorities within the deadlines required by law;
- we will notify you when there is a high risk to your rights, with an explanation of the scope and recommendations;
- we will notify creators where appropriate.
15. Changes to this Policy
We may update this Policy to reflect changes in WeMatch, new data sources, legal requirements or privacy improvements. We will notify significant changes through in-platform notification, email and by updating the effective date. When a change is material and the law requires it, we will give you the opportunity to review and consent to it.
16. Contact
- WeMatch support: wematch@wemany.com
- Privacy team: privacy@wemany.com
- Appeals and disputes: appeals@wemany.com
- Technical support: support@wemany.com
Wemany Inc. — 8 The Green, Suite R, Dover, DE 19901, United States
© 2026 Wemany Inc. All rights reserved.