Privacy Policy

Last updated: 1 June 2026 · Effective date: at launch

1. Who we are

This Privacy Policy explains how LocalModels collects, uses, shares, and protects your personal data when you use the LocalModels platform at localmodels.com and related services (the "Platform").

The data controller is Commercial Media LLC, a limited liability company registered in Delaware, United States, with its address at 8 The Green, STE A, Dover, Delaware 19901, United States ("LocalModels", "we", "us" or "our"). You can contact us about privacy matters at [email protected].

We are committed to protecting your personal data and to handling it in line with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data we collect

We collect the following categories of personal data:

  • Account data: name, email address, password, account type (Brand or Talent), and profile details you provide.
  • Profile and Content data: photos, videos, descriptions, categories, location or city, rates, availability, and other material you add to your profile or upload to the Platform.
  • Verification data: information used to confirm identity and age, including government-issued identification, date of birth, and a facial image (selfie) used for liveness and identity matching. See Section 3 for how we handle biometric data. We also collect social media account handles and follower counts where you choose to connect or provide them.
  • Booking and transaction data: details of bookings, messages exchanged on the Platform, quotes, and records of payments and payouts.
  • Payment data: payments are handled by our payment processor, Stripe. We do not store full card numbers. We receive limited information such as transaction status and the last digits of a card or bank account where needed to operate the Platform.
  • Usage and device data: IP address, browser type, device information, pages viewed, and similar technical data collected automatically, including through cookies.
  • Communications: messages you send to us, including support requests and waitlist sign-ups.

3. Identity and age verification (biometric data)

To keep the marketplace trustworthy and to comply with our obligation to allow only adults (18+), Talent must complete identity and age verification. This verification is carried out by our identity verification provider, Veriff OU, a company established in Estonia, acting as our processor under Article 28 GDPR.

As part of verification we collect a facial image (selfie) and an image of a government-issued identity document, and the provider performs a biometric comparison between them to confirm that the document belongs to the person presenting it (a liveness and face-match check). The facial image and the biometric processing involved are special category (biometric) data under Article 9 GDPR.

Legal basis. We process this biometric data only with your explicit consent, which you give at the start of the verification flow. You can withdraw consent at any time, but without completing identity and age verification you will not be able to take bookings or perform paid offline work on the Platform.

Storage and retention. Verification selfies and documents are stored in encrypted, access-restricted private storage, separate from your public profile, and are accessible only to authorised staff for fraud-prevention and dispute purposes. We retain this verification data for up to twelve (12) months after your account is deleted or becomes inactive, after which it is securely deleted, unless a longer period is required to resolve an open dispute or to comply with a legal obligation. We do not use your biometric data for any purpose other than identity and age verification and fraud prevention, and we do not sell it or use it to build a facial-recognition database.

If you delete your account, your verification selfies and documents are deleted from our systems as part of the deletion process described in Section 8, subject only to the limited retention above where a dispute or legal obligation requires it.

4. How and why we use data

We use personal data to:

  • create and manage your account and provide the Platform;
  • enable discovery, communication, and bookings between Brands and Talent;
  • verify identity and age and help keep the marketplace trustworthy;
  • process payments, payouts, fees, and subscriptions through our payment processor;
  • provide customer support and respond to your requests;
  • send service messages and, where permitted, marketing communications you can opt out of;
  • analyze and improve the Platform and develop new features;
  • detect, prevent, and address fraud, abuse, and security issues;
  • comply with legal obligations and enforce our Terms.

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract: to provide the Platform, manage your account, and facilitate bookings and payments.
  • Legitimate interests: to operate, secure, and improve the Platform, prevent fraud, and promote our services, where these interests are not overridden by your rights.
  • Consent: for biometric identity verification (Section 3), for certain marketing, for non-essential cookies, and where you choose to connect social media accounts. You can withdraw consent at any time.
  • Legal obligation: to comply with applicable laws, including tax, accounting, and anti-fraud requirements.

6. Sharing with third parties

We do not sell your personal data. We share data only as needed to run the Platform, including with:

  • Payment processor: Stripe, Inc., to process payments, payouts, and subscriptions.
  • Identity verification provider: Veriff OU (Estonia), to verify identity and age for Talent, including the biometric processing described in Section 3.
  • Hosting and infrastructure providers: that store and serve the Platform and its data, including encrypted private storage for verification and escrow data.
  • Other Users: your public profile information is visible to Brands and Talent on the Platform as needed to enable bookings. Messages and booking details are shared with the other party to a booking. Your verification documents and selfie are never shared with other Users.
  • Professional advisers and authorities: where required by law, to enforce our Terms, or to protect our rights, Users, or the public.
  • Successors: if we are involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

All providers that process data on our behalf are bound by appropriate data protection terms.

7. International transfers

We are based in the United States and our service providers may be located in various countries. This means your personal data may be transferred to and processed outside the European Economic Area (EEA), including in the United States. Our identity verification provider is established in the EEA (Estonia).

Where we transfer personal data out of the EEA, we put in place appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to ensure your data receives an adequate level of protection. You can ask us for more information about these safeguards using the contact details below.

8. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy, including to provide the Platform, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements.

When you delete your account, we delete your profile, listings, messages, bookmarks, and verification data (including selfies and identity documents, removed from storage), subject to the limited retention described in Section 3 and to anonymised financial records we are required to keep for accounting and tax purposes. When data is no longer needed, we delete or anonymize it.

9. Your rights

If the GDPR applies to you, you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request erasure of your data ("right to be forgotten"), subject to legal retention needs. You can delete your account and associated data directly from your account settings (Settings, Privacy, Delete account), which removes your profile and verification data as described in Section 8;
  • request restriction of, or object to, certain processing;
  • receive your data in a portable, machine-readable format. You can download a copy of your data at any time from your account settings (Settings, Privacy, Download my data), in JSON and PDF;
  • withdraw consent at any time, without affecting processing already carried out. Withdrawing consent to biometric verification is described in Section 3;
  • lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on a request.

If you are in California or another US state with privacy rights, you may have similar rights to access, delete, and opt out of the "sale" or "sharing" of personal information. We do not sell personal information. Contact us using the details below to exercise these rights.

10. Children's privacy

The Platform is intended only for users aged 18 and over. We do not knowingly collect personal data from anyone under 18, and our identity and age verification is designed to prevent minors from using the Platform. If a verification check indicates a person is under 18, the account is blocked and no profile, badge, or points are granted. If you believe a minor has provided us with personal data, please contact us and we will take steps to delete it.

11. Cookies and similar technologies

We use cookies and similar technologies to operate the Platform, remember your preferences, and understand how the Platform is used. Cookies are small files placed on your device.

When you first visit the Platform you will be asked to accept or reject non-essential cookies. You can change your choice at any time through your browser settings or our cookie controls. Blocking some cookies may affect how the Platform works.

12. Data security

We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. Sensitive data such as verification selfies, identity documents, and escrow records is held in encrypted, access-restricted private storage, separate from public profile data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly to any incident.

13. Changes to this Policy

We may update this Privacy Policy from time to time. If we make a material change, we will give reasonable notice, for example by email or through the Platform. The "last updated" date at the top shows when the Policy was last revised.

14. Contact

For any privacy question or to exercise your rights, contact us at [email protected], or by post at:

Commercial Media LLC
8 The Green, STE A
Dover, Delaware 19901
United States