Legal

Privacy Policy

Effective Date: [COMPANY TO CONFIRM]Last Updated: July 19, 2026

This Privacy Policy explains how Be Belong Group Corp, a Delaware corporation headquartered in Miami, Florida ("Company," "we," "us," or "our"), collects, uses, discloses, and safeguards personal information in connection with the Launchpad brand-onboarding platform and the broader Be Belong ecosystem, which includes RentGain and CollegeGain (collectively, the "Services"). It also describes the rights and choices available to you.

This Policy should be read together with our Terms of Service and Cookies Policy, each of which is incorporated by reference.

1. Definitions

  • "Earners" — KYC-verified individual consumers (renters on RentGain; students on CollegeGain) who complete brand-funded activities to earn credits applied to rent or tuition.
  • "Brand Advertisers" or "Business Customers" — companies and their authorized representatives that sign up for Launchpad, fund campaigns, and access analytics.
  • "Institutional Partners" — landlords, buildings, property managers, and universities that onboard Earner populations.
  • "Personal Information" — information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable individual, as defined by applicable law (including "personal data" under GDPR/UK GDPR).
  • "Sensitive Personal Information" — as defined under the CPRA and other state laws, including government identifiers, precise geolocation, financial account information, and biometric identifiers.
  • "Process" — any operation performed on Personal Information, whether automated or not.

2. Scope of this Policy

In plain terms

This Policy covers everyone we interact with — brand advertisers using Launchpad, renters and students earning on RentGain and CollegeGain, and landlord and university partners. Some sections apply only to specific groups; we call that out where relevant.

This Policy applies to Personal Information we Process in connection with (i) the Launchpad platform used by Brand Advertisers, (ii) the RentGain and CollegeGain Earner-facing services, (iii) our websites, mobile applications, APIs, and related tools, and (iv) our sales, marketing, support, and other business operations. It does not apply to third-party websites, applications, or services that we do not own or control.

3. Information We Collect

In plain terms

We collect what we need to verify Earners, run brand campaigns, route rent and tuition credits, prevent fraud, and improve the platform.

3.1 Account and Registration Data

Name, email address, phone number, password, professional title, company name (for Brand Advertisers and Institutional Partners), and role-based permissions for authorized users.

3.2 KYC / Identity Verification Data (Earners)

To confirm eligibility to earn and receive rent or tuition credits, we (through vendors) collect: government-issued identification (e.g., driver's license, passport), a selfie or short video used for liveness detection and biometric comparison, date of birth, residential address, and, where applicable, tenancy or enrollment information. See Section 10 — Biometric Information Notice.

3.3 Financial and Wallet Data

Bank account or debit card details, ACH routing information, transaction history, credit and earnings balances, rent or tuition payment routing instructions, and virtual-card or wallet top-up data processed by our payment processing, card-issuing, and banking-as-a-service partners.

3.4 Behavioral, Device, and Engagement Data

App and website usage, session duration, features used, activity completion events, IP address, device identifiers, mobile advertising identifiers (IDFA/AAID where permitted), operating system and browser type, referring URLs, and approximate or precise location data used for building- or property-matching (with your consent where required).

3.5 Advertising and Matching Data

Interactions with brand campaigns (impressions, clicks, video completion, survey responses, cashback redemptions, gameplay, product-launch participation) and personalization signals used by our Smart Brand Matching Engine and AI Earnings Optimizer.

3.6 Brand Advertiser and Campaign Data

Company information, billing and payment method data, campaign creative and content, targeting parameters, budget and pacing preferences, campaign performance data, and communications with our team.

3.7 Institutional Partner Data

Property manager, landlord, and university contact and account data (typically B2B) and, where applicable, aggregated resident or student roster information supplied under a written data agreement.

3.8 Communications and Support Data

Emails, chat transcripts, call recordings (where notice and any required consent are provided), support tickets, and survey responses.

3.9 AI Inputs and Outputs

Content you submit to AI-enabled features (including the Launchpad voice-enabled onboarding flow, Smart Brand Matching Engine, Earnings Optimizer, predictive Financial Dashboard, and AI Shopping & Lifestyle Assistant), together with the outputs those features generate and metadata about how they were used.

4. Sources of Information

We collect Personal Information (i) directly from you, (ii) automatically through your use of the Services, (iii) from our Institutional Partners and Brand Advertisers, and (iv) from service providers such as identity-verification vendors, payment processors, card issuers, mobile measurement partners, advertising platforms, fraud-prevention providers, and enrichment or business-contact data providers.

5. How We Use Information

  • Provide, operate, secure, and improve the Services;
  • Verify Earner identity and eligibility (KYC/AML compliance);
  • Route and reconcile brand-funded credits, rent payments, and tuition payments;
  • Match Earners to relevant brand-funded activities via our Smart Brand Matching Engine;
  • Deliver campaigns, measure performance, prevent fraud and abuse, and enforce our Terms;
  • Personalize the Services and provide predictive insights (e.g., Earnings Optimizer);
  • Communicate about accounts, transactions, product updates, and (with permission where required) marketing;
  • Comply with legal, tax, regulatory, and audit obligations; and
  • Establish, exercise, or defend legal claims.

Where GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (delivering the Services you request); legal obligation (KYC/AML, tax, and financial reporting); legitimate interests (fraud prevention, security, product improvement, direct B2B marketing to Brand Advertisers), balanced against your rights; and consent (marketing to Earners where required, precise location, cookies where required, and biometric processing).

7. AI Features & Automated Decisions

In plain terms

We use AI to match Earners to activities and to help brands launch campaigns. It's a recommendation engine, not a legally binding decision-maker — you can always ask a human to review.

Our Services use machine learning and generative AI to power matching, ranking, predictive analytics, voice-enabled onboarding, and content assistance. These features may Process the categories described above to produce recommendations and outputs. They are not intended to make decisions producing legal or similarly significant effects about you without meaningful human involvement. If you believe an automated output has materially affected you, contact us at privacy@bebelong.group to request human review, an explanation, or correction. We do not knowingly use your inputs to train foundational third-party models beyond what is necessary to deliver the requested feature.

8. Data Ownership, Generated Outputs & Consumer Insights

In plain terms

Brands own what they upload. We own what our platform generates and what our consumer network produces. Nothing gets published or advertised externally without written permission — from us for consumer insights, or from the brand for brand assets. Unauthorized use in either direction can be pursued as a legal violation.

Advertiser-submitted assets. Brand Advertisers retain ownership of the logos, creative, offers, product content, first-party data, and other digital assets they upload ("Submitted Assets"). By providing Submitted Assets, the Advertiser grants us the operational rights described in the Terms of Service, Section 7 — a worldwide, royalty-free license to host, adapt, analyze, model, and use Submitted Assets solely to deliver, secure, improve, match, and measure Campaigns and to generate outputs for that Advertiser. We do not sell Submitted Assets, we do not license them to other advertisers for their own marketing, and we do not use an Advertiser's name, logo, or assets in public marketing without that Advertiser's prior written consent.

Generated Outputs. All content, briefs, question sets, targeting configurations, matching decisions, predictive scores, dashboards, benchmarks, models, embeddings, aggregates, and other materials that our Services (including AI features) create, derive, or synthesize — whether or not based on Submitted Assets — are the exclusive property of Be Belong Group Corp under Terms Section 8. Advertisers receive a limited internal-use license to Generated Outputs for their own Campaigns and may not resell them, share them with third parties as a standalone product, or use them to train competing models.

Consumer Insights. All Earner-level and audience-level data generated on or through our network — impressions, engagement, completions, survey responses, cashback redemptions, gameplay, product-review submissions, video reviews, sentiment, purchase-intent signals, verified-household attributes, cohort behavior, matching scores, and any aggregated or de-identified analytics derived therefrom ("Consumer Insights") — are collected, generated, and owned exclusively by Be Belong Group Corp. Consumer Insights are provided to Advertisers through the Services under a limited internal-use license only.

Explicit-consent gate for external use. Advertisers may not publish, syndicate, share externally, or use Consumer Insights in press, PR, social, paid media, sales collateral, investor materials, award submissions, or any other external channel without our prior express written consent, which we capture through the in-product consent flow described in Section 22 below and log against the associated Campaign. Consent to one specific use is not consent to any other use.

Enforcement. Unauthorized collection, retention, use, disclosure, publication, resale, scraping, re-identification, or model-training use of Submitted Assets, Generated Outputs, Consumer Insights, or Earner personal information — by any party — is a material breach of our Terms and may also violate federal and state privacy, consumer-protection, computer-fraud (including the CFAA), copyright, trademark, trade-secret, and unfair-competition laws. We reserve every remedy available at law and in equity, including immediate suspension, revocation of any license granted, required destruction of copies with written certification, injunctive relief, damages, disgorgement of profits, statutory damages where available, and reasonable attorneys' fees.

Reciprocal data-protection duties. Each party will use the other party's data only for the purposes expressly authorized, apply commercially reasonable safeguards, limit access to personnel with a need-to-know bound by written confidentiality obligations, and promptly notify the other of any confirmed unauthorized access, use, or disclosure.

9. How We Share Information

We share Personal Information with:

  • Service providers and processors that host, secure, analyze, and support the Services under contract;
  • Payment processing, card-issuing, and banking-as-a-service partners to move funds, top up wallets, and reconcile rent and tuition payments (see GLBA notice);
  • Identity-verification, KYC, and fraud-prevention vendors;
  • Analytics and mobile-measurement partners used to attribute installs, events, and campaign performance;
  • Brand Advertisers, in aggregated or de-identified form, and, where you have expressly opted in to a specific campaign, in the limited identified form required to deliver that campaign or fulfillment;
  • Institutional Partners for the limited purpose of routing credits to rent or tuition;
  • Affiliates within the Be Belong corporate family;
  • Professional advisors (auditors, lawyers, insurers, bankers);
  • Government, regulators, and law enforcement where required by law or to protect rights, safety, or the integrity of the Services; and
  • Successors in connection with a merger, acquisition, financing, or sale of assets, subject to customary confidentiality protections.

We do not sell Personal Information for monetary consideration. Certain sharing for cross-context behavioral advertising may qualify as a "sale" or "share" under some U.S. state laws; you may opt out as described in Section 14.

10. Financial Privacy Notice (Gramm-Leach-Bliley Act)

In plain terms

Because we help route rent, tuition, and wallet funds, we follow federal financial-privacy rules and give you the right to opt out of certain information-sharing with non-affiliated third parties.

Categories of nonpublic personal information ("NPI") we collect: information from applications and account activity (name, address, income or eligibility indicators), transaction information (payments, credits, balances), and information from consumer-reporting agencies or identity-verification vendors.

Categories of NPI we disclose: we disclose the NPI described above to affiliates and to non-affiliated third parties as permitted by law — for example, to process transactions, service accounts, respond to legal process, or with your consent.

Your right to opt out: where required, you may opt out of our sharing of NPI with non-affiliated third parties for their own marketing purposes by emailing privacy@bebelong.group. We do not share NPI with non-affiliated third parties for their own marketing purposes without your consent.

Safeguards: we maintain administrative, technical, and physical safeguards designed to comply with the GLBA Safeguards Rule and industry standards.

11. Biometric Information Notice

Our identity-verification workflow uses biometric identifiers or biometric information (for example, facial-geometry comparisons between your government ID and a live selfie) solely to confirm your identity, prevent fraud, and satisfy legal obligations. We (and our KYC vendors acting as our processors) obtain your written consent before collection, do not sell biometric identifiers, and retain biometric identifiers only for as long as reasonably necessary — and in any event no longer than three (3) years after your last interaction with us, or the shortest period required by applicable law (including Illinois BIPA, Texas CUBI, and Washington state biometric law), whichever is shorter. [COMPANY TO CONFIRM final retention window and vendor.]

12. Advertising, Analytics & Measurement

We participate in the digital advertising ecosystem in a limited, permission-based way. We honor the Digital Advertising Alliance (DAA) and Network Advertising Initiative (NAI) opt-outs and recognize the Global Privacy Control (GPC) signal as a valid opt-out of "sale" and "sharing" for browsers that transmit it. Where we participate in industry frameworks such as the IAB TCF / Global Privacy Platform, we surface a consent tool for users in applicable jurisdictions. Additional detail on trackers is set out in our Cookies Policy.

13. Cookies & Similar Technologies

We use cookies, SDKs, pixels, local storage, and mobile identifiers as described in our Cookies Policy, which includes categories, examples, durations, and instructions for managing your preferences.

14. Your U.S. State Privacy Rights

In plain terms

Depending on where you live, you may have rights to access, correct, delete, or port your data, and to opt out of certain sharing and profiling. We honor these rights for everyone we can, regardless of state.

13.1 California (CCPA/CPRA)

California residents have the right to (i) know the categories and specific pieces of Personal Information collected, sources, purposes, and recipients; (ii) delete Personal Information (subject to exceptions); (iii) correct inaccurate Personal Information; (iv) opt out of the "sale" or "sharing" of Personal Information; (v) limit the use and disclosure of Sensitive Personal Information; and (vi) not receive discriminatory treatment for exercising these rights. California residents may also request the "Shine the Light" disclosure once per year regarding certain third-party marketing sharing. You may designate an authorized agent to submit requests on your behalf.

13.2 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Florida (FDBR), Delaware (DPDPA), and other applicable states

Residents of these states generally have the right to access, correct (where provided), delete, and obtain a portable copy of their Personal Information, and to opt out of targeted advertising, "sale" of Personal Information, and certain profiling in furtherance of decisions producing legal or similarly significant effects. Rights and applicability thresholds vary by state, and coverage will be updated as additional state laws take effect. Florida residents should note that the Florida Digital Bill of Rights applies to certain large controllers meeting statutory thresholds; we honor equivalent rights on a voluntary basis where the FDBR does not otherwise apply. [COMPANY TO CONFIRM current FDBR applicability.]

13.3 Biometric Privacy States

Residents of Illinois, Texas, and Washington have additional rights and protections concerning biometric identifiers; see Section 11.

13.4 How to exercise your rights

Submit requests through privacy@bebelong.group or, where available, our rights-request portal at [privacy portal URL — COMPANY TO CONFIRM]. We will verify your identity using information reasonably necessary given the sensitivity of the request. You may appeal a denial by replying to our decision within sixty (60) days.

15. International Users & Data Transfers

The Services are operated from the United States. If you access them from outside the United States, your information will be transferred to, stored, and Processed in the U.S. and other jurisdictions with different data-protection laws. Where required, we implement Standard Contractual Clauses (or the UK IDTA/Addendum) and supplementary measures for transfers of personal data from the EEA, UK, and Switzerland. We do not currently believe we are required to appoint an EU/UK representative or Data Protection Officer, but we will do so if triggered under applicable law. [COMPANY TO CONFIRM DPO/representative status.] For Canadian residents, we handle personal information in accordance with PIPEDA principles.

16. Data Retention

We retain Personal Information only as long as necessary for the purposes described in this Policy, to comply with legal, tax, accounting, or reporting obligations, to resolve disputes, and to enforce our agreements. Financial and KYC records are typically retained for at least five (5) years after account closure to satisfy applicable law. [COMPANY TO CONFIRM detailed retention schedule.]

17. Data Security

We maintain administrative, technical, and physical safeguards designed to protect Personal Information, including encryption in transit and at rest, least-privilege access controls, secure development practices, vendor due diligence, logging, and incident-response procedures. No system is perfectly secure; we cannot guarantee absolute security, and you are responsible for keeping your credentials confidential.

18. Children & Minors (COPPA/FERPA)

The Services are not directed to children under 13, and we do not knowingly collect Personal Information from children under 13 in violation of COPPA. Launchpad is intended for adult business users. RentGain is intended for adults age 18 and over. CollegeGain is intended for verified students who are generally 18 or older; where a student user may be a minor, we require verifiable consent from a parent or guardian and limit collection accordingly. Where any data is sourced from a university system, we handle it consistent with our written agreement with the institution and applicable law, including FERPA, and we do not use education records for purposes beyond what the institution has authorized.

19. Email & SMS Communications

We send transactional and, with your permission where required, marketing communications by email, SMS, and push notification. Email marketing complies with the CAN-SPAM Act, and every marketing email includes an unsubscribe link. SMS communications comply with the Telephone Consumer Protection Act (TCPA); message and data rates may apply, and you can reply STOP to opt out and HELP for help. To the extent any identity-verification data could be construed as a consumer report under the Fair Credit Reporting Act (FCRA), we use it only for permissible purposes and in accordance with applicable notice and dispute procedures.

20. Accessibility

We are committed to making our Services accessible to people with disabilities in line with the Americans with Disabilities Act (Title III) and recognized web content accessibility guidelines. To request an accommodation or report a barrier, contact accessibility@bebelong.group.

21. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will notify you by email, an in-app banner, or another reasonable means before the changes take effect, and, where required, we will seek your renewed consent. The "Last Updated" date at the top reflects the most recent revision.

22. Advertiser Data Controls & Consent Flow

In plain terms

Brands can access, export, correct, or delete their data at any time from the in-app Data Controls page. Every request gets a receipt number and a defined retention window. External publication of consumer insights runs through the same in-app flow so every consent is logged against the campaign it belongs to.

Data-subject rights for Advertisers. Advertisers can submit access, export (portable JSON), correction, and deletion requests from the in-product Data Controls page. Each submission is timestamped and issued a unique confirmation receipt (e.g., BBG-XXXXXXXXXX) that is displayed on-screen and stored against the account. Standard response windows are: access and export within 30 days (downloads retained for 90 days); correction within 30 days with a 24-month audit log; deletion within 45 days, subject to legal retention (KYC/AML and financial: up to 7 years; security and audit logs: up to 24 months). We may extend by up to 60 days for complex requests and will notify you if we do.

Consumer-insight publication consent. The Data Controls page and the Insights workspace both surface a consent dialog that records, for a specific Campaign, (i) the scope (publication, advertising, or both), (ii) the approved channels, (iii) the exact data points and wording covered, (iv) the version of the consent clause, and (v) the timestamp and user agent. The Advertiser can revoke any recorded consent for future publications at any time. Consent records are retained for the life of the account plus seven (7) years to support audit and dispute resolution.

Data Processing Addendum. Where required by Applicable Data Protection Laws, our Data Processing Addendum governs controller/processor roles, subprocessors, and cross-border transfer safeguards (EU SCCs, UK IDTA, Swiss addendum, and Data Privacy Framework where applicable).

23. Contact Us & Exercise Your Rights

Be Belong Group Corp (a Delaware corporation)
Attn: Privacy Team
2980 NE 207th Street, Miami, FL 33180, USA
Email: info@bebelong.life