Skip to main content

GDPR & User Consent for FluentCommunity (Posts, Messages & Payments)

Hi,

We run a paid online community using FluentCommunity and FluentCRM, based in the Netherlands, but open to users worldwide. We received GDPR concerns from someone in Germany about whether users need to explicitly agree to:

  1. Posting in the community (e.g., who can see their posts).
  2. Sending private messages to other members.
  3. Adding external social media links to their profile.
  4. Accepting terms & conditions before payment (to prevent refund disputes).

Additionally, the platform collects first name, last name, and username as part of the user profile. Since these are personal data, do users need to explicitly consent to this upon registration, or is voluntary signup sufficient under GDPR?

Regarding the privacy policy, we have one on the website, but do users need to actively agree to it (e.g., via a checkbox), or is making it accessible enough?

Currently, we have a terms & conditions page, but users don’t explicitly agree before payment. Would adding a checkbox before purchase be the best approach? Also, is it necessary to have a separate consent for posting, messaging, and linking social profiles, or does joining the community already imply agreement?

Thanks for any insights! πŸš€

So when you are onboarding user, you should have a terms and condition page which user must need to check to create the account. It's a standard practice as this is how all social media sites work.

Sam Jansen

Shahjahan JewelΒ What needs to be in the terms and condition page related to the community?

Sam JansenΒ I am not a lawyer but you should state that when joining the site, these data will be available for other users for the community features.

Sam Jansen

Shahjahan JewelΒ Ok yeah. I though a Privacy Policy would be enough, but users have to agree to the terms and conditions when joining the community?

William Beem

I created a custom registration page for this issue. The default one didn't seem to allow more than one hyperlinks. Also, I wanted my registration to be paid, so that was my main driver for going custom.

It's not as pretty as the default page, but it functions.

Screenshot attached.

Sam Jansen

William BeemΒ Great! Can I see your agreements? I wonder what there needs to be in there

William Beem

Sam JansenΒ Sure. The site isn't ready, but you can visit the page to check out the agreements.

https://community.suburbiapress.com/register/

I use a service called Plainly Legal to generate these contracts and policies - plainlylegal.com. It's only for US law.

Sam Jansen

William BeemΒ Ok cool, looks good! What do you use btw for the magic login form?

William Beem

Sam JansenΒ I'm using Fluent Forms Pro. It integrates with Stripe and other payment gateways. I just put it on a regular WordPress page, added a headline & some text.

Sam Jansen

William BeemΒ I mean the magic login form. Is that fluentauth plugin?

William Beem

Sam JansenΒ Oh, sorry. That is the default login form with FluentCommunity. The image on the left is something I found on Canva.

If you go to Portal Settings > General, it's there on the bottom. Here's a screenshot of my settings.

Sam Jansen

William BeemΒ Login via Magic link is that fluent auth a free plugin? I dont use it yet

William Beem

Sam JansenΒ Oh, sorry for not picking up on that earlier. Yes, that is within FluentAuth in the settings. It's a free plugin.

I think I'll allow the Subscribers to use it. Just playing with things on this site right now.

Sam Jansen

William BeemΒ Thanks for info. I will try it out myself also.

Linda Rando

Just one consent is enough, and it has to be given during registration (and reconfirmed every time the privacy policy is updated).

Other than that, I’d recommend you consult a lawyer or at least take a GDPR course, because you seem to have some pretty basic doubts you really shouldn’t have πŸ˜…

Sam Jansen

Linda RandoΒ Ok yeah thanks. Normally for simple static websites there is not so much needed espesially when there is no tracking and login. So that is why I am asking some questions.

Linda Rando

Sam JansenΒ Exactly, I’m saying this for your own good, because it’s something very important and could have serious legal consequences, so it’s worth looking into it carefully :)

Mat β€Ž

Sam JansenΒ GDPR regulations require businesses to handle user data responsibly - particularly when using it for advertising, tracking, or lead generation.

You need explicit consent to collect or process personal data, including through tools like tracking pixels or cookies.

GDPR regulations apply wherever personal data is collected, processed, or stored - including social media/communities platforms.

You must respect EU Citizen and Resident Rights consent even if you have one user from the EU.

Social media marketers (if you use FluentCRM or any other tool for Marketing then read this twice) must ensure these rights are upheld when handling user information, including names, cookies, tracking pixels, and even data collected for advertising (including users profiling - The Right to Avoid Automated Decision-Making).

Explicit, opt-in consent is at the heart of GDPR compliance.

Internet users must actively agree to how their data is collected, stored, and used - consent cannot be implied through inactivity or pre-checked boxes.

Basic GDPR topics:

  • The Right to Information
  • The Right of Access
  • The Right to Rectification
  • The Right to Erasure (The "Right to Be Forgotten")
  • The Right to Restriction of Processing
  • The Right to Data Portability
  • The Right to Object
  • The Right to Avoid Automated Decision-Making

Read more here to get the idea.