LegalVersion 1.1
privacy
What we collect, why, who sees it, how long we keep it and the rights you have over it — written against the platform's own data inventory, including the gaps we disclose rather than paper over.
- Effective
- 21 September 2026
- Last updated
- 21 September 2026
- Version
- 1.1
- Applies to
- collabkrew.com, app.collabkrew.com and the CollabKrew mobile apps
Who we are, and what this policy covers
This policy explains what CollabKrew does with personal data. CollabKrew is a creator–brand collaboration platform operated from India. The data controller — whoever decides why and how your data is used — is CollabKrew, and you can reach us at any time at privacy@collabkrew.com.
CollabKrew is not yet incorporated. When a legal entity is formed it will become the named controller, this section will carry its registered name and office, and — because that is a material change — we will tell you before it takes effect. Until then, the commitments in this policy are made and kept by the people operating CollabKrew, and a change of legal form will not weaken them.
It covers:
- this website at collabkrew.com, including the waitlist form;
- the CollabKrew platform at app.collabkrew.com and our mobile apps, once you have an account;
- our emails and notifications to you.
It does not cover what a brand does with your data on its own systems after a deal, what a social platform does with your account, or what a website we link to does. Those are governed by their own policies.
Where brands are the controller, not us
For most things we are the controller. But where a brand or agency uploads personal data of its own into its workspace — a shortlist of creators it sourced elsewhere, a contact it invited, its own customer order references used for conversion tracking — that brand is the controller and we process it on their instructions under a Data Processing Addendum. If you want that data removed, ask the brand; tell us too and we will pass it on.
The short version
- Right now this website does one thing with personal data: it takes waitlist signups — your email, optionally your name, and whether you are a brand or a creator.
- We do not use advertising trackers, analytics SDKs, or third-party cookies. There are no cookies on this website at all.
- We never sell your personal data, and we never share it for cross-context behavioural advertising.
- On the platform we collect what running a paid marketplace actually requires: who you are, what you agreed, what you delivered, what it earned, and what tax was withheld.
- You can download everything we hold about you as one file, from your own settings, without asking us.
- You can delete your account yourself. We anonymise rather than obliterate, because tax records and contracts other people hold have to survive — and we list exactly what survives, with the reason.
- Automated checks can hold a payment for review. None of them can reject you on their own; a person decides, and you can appeal.
- Where you sign in with Google or link a YouTube channel, our use of that data follows the Google API Services User Data Policy, including its Limited Use requirements. We never sell it, never advertise against it, and never train a model on it. Section 10 says exactly what we receive and why.
What this website collects
collabkrew.com is a static site. It runs no analytics, sets no cookies, and stores nothing in your browser.
The waitlist form
- Email address
- Required. It is how we contact you when early access opens.
- Name
- Optional — your name, or your brand or company name. Leave it blank if you prefer.
- Role
- Whether you are joining as a brand or as a creator, so we invite you into the right side of the product.
- Timestamp
- When you signed up.
That is the whole record. We ask for nothing else, and the form has nowhere to put anything else.
Where it goes, and who sees it on the way
Your browser sends the signup directly to two Google services: a Firebase Realtime Database, and a Google Apps Script endpoint that appends a row to a Google Sheet we control. We use two so that a signup is not lost if one of them is down. Because your browser talks to Google directly, Google sees your IP address when you submit the form. The database is configured so that signups can be written but not read back by anyone without our credentials.
Other requests your browser makes on this page
- Firebase Hosting
- This site is hosted by Google. Their servers log the IP address, time, browser and pages requested, as any web server does.Google LLC / Google Ireland
- Unsplash
- The scrolling photo strip loads stock photography from images.unsplash.com, so Unsplash sees your IP address and browser when the page loads. The photos are illustrative stock images, not CollabKrew users.Unsplash Inc.
- Fonts
- None. The Inter typeface is downloaded when we build the site and served from our own domain, so your browser never contacts a font provider.
How long we keep a waitlist entry
Until launch plus 12 months, or until you ask us to remove it, whichever comes first. Unsubscribing from a waitlist email removes you. If you later create an account, the account record replaces the waitlist one.
What the platform collects
Once you have an account, we hold the following. This list is generated from the same inventory that drives your data export, so it is not a summary of what we think we hold — it is what we hold.
Who you are
- Account
- Name, email address, whether it is verified, profile image, whether you signed up as a brand, agency or creator, your interface language, locale and preferred display currency, and the date and time you confirmed you are 18 or over.
- Sign-in
- A hashed password, or — if you signed in with Google or Apple — that provider’s identifier for your account and the tokens it issues us. From Google we receive your Google account id, your email address and whether Google has already verified it, your name and your profile picture, and nothing else; section 10 sets out what each is for. We never see your password with those providers, and we never store your password in a readable form.
- Onboarding profile
- First and last name, country, state or region, city, profile photo. For brands: brand name, website, address, postal code, registered legal entity name, entity type, and the name and title of the person authorised to sign. For creators: legal full name and address. Plus what you told us about your interests, niches and how you plan to use the platform.
- Creator storefront
- Display name, headline, biography, niches, languages, country, and the packages and prices you publish. This is public — see section 19.
Your social accounts
- Linked accounts
- Which platform, the account id and handle there, your follower count, which permissions you granted, and encrypted access and refresh tokens. The tokens are stored sealed, and the database physically rejects a token that is not encrypted.
- Post metrics
- For each submitted post: views, likes, comments, whether it is public, and the caption where the platform exposes one — recorded as a series of timestamped snapshots that are only ever added to, never edited.
- Follower history
- Your follower count over time, with the handle it was recorded under, so a priced deal can cite the reach it was priced against and so a handle change does not silently rewrite the past.
What you did on the platform
- Campaigns and submissions
- Campaigns you joined, the frozen copy of the terms you accepted, the posts you submitted and their URLs, verification status and the reason for any rejection or flag.
- Orders and offers
- Deals, prices, deliverable specifications, delivery dates, renegotiated dates, tasks, revisions, approvals and reviews.
- Agreements
- The signed Creator–Brand Collaboration Agreement for each deal, the typed or drawn signature and the signer’s name, and — as evidence that the signature is real — the IP address and browser it was signed from.
- Licences
- Content you listed for licence and licences bought or sold, with the scope, duration and territory as agreed.
- Reputation
- Your Trust Score and its history, guild membership and leaderboard entries.
- Tracked links
- Which campaigns you were issued a tracked link or promo code for. The click record itself contains no IP address, no cookie and no device information — only that a click happened and when.
Money
- Ledger and wallet
- Every movement of money as double-entry records, per currency.
- Payouts
- Amount, currency, tax withheld, status, failure reason and settlement date.
- Payout methods
- The kind of method, a label, the last four digits, the currency, and a token from the payment provider. We never hold your full bank account number or card number — those live with the payment provider, not with us.
- Tax profile
- Your country and, for Indian creators, your PAN and the withholding rate applied. We need the PAN to make and file the deduction correctly.
- Identity verification
- Whether verification passed, a reference from the verification provider, and a one-way peppered hash of the identity the provider verified — which is what stops one person holding two accounts. We do not store your Aadhaar number, and we do not keep the underlying document identifiers.
- Referrals
- Your referral code, who you referred or were referred by, and what was earned.
- Invoices
- Tax invoices we raised for subscription charges, including a GSTIN where given.
What you said, and what we told you
- Messages
- Conversations with the other side of a deal, their content and attachments, and a flag recording whether a message appeared to contain off-platform contact details. See the Terms, section 23, for why we scan and why we only warn.
- Notifications
- In-app notifications and their read status, and — if you use the mobile app and allow it — a push token for each device, with the platform and when it was last seen.
- Disputes
- Disputes you raised or were party to, the reason, your explanation, and the evidence either side filed.
- Support
- What you write to us, and our replies.
Compliance and security records
- Policy acceptances
- Which version of the Terms or this Privacy Policy you accepted, when, and the IP address and browser you accepted from. This is evidence, not analytics — it exists so that “you agreed” can be substantiated rather than merely asserted.
- Consent register
- Every optional consent you granted or withdrew, with the date and the IP address and browser it was recorded from. Both the grant and the withdrawal, not just today’s setting.
- Sessions
- For each sign-in: an IP address, a browser or device string, and when the session expires.
- Server logs and traces
- Ordinary web-server and application logs. Values that look like passwords, tokens, secrets, authorisation headers or cookies are stripped before anything is written.
If you applied for brand access
A brand or agency access request holds your first and last name, work email, phone number, company, website, budget range, team size, industry and what you want to achieve — submitted before any account exists. Please read the disclosure in section 15 about how this particular record interacts with your self-service rights.
If you connect a store
A brand can connect a Shopify or WooCommerce store. We store the shop domain and encrypted API credentials, and we read order totals and order references to attribute revenue to campaigns. We do not ingest your customers’ names, addresses, emails or payment details.
What we deliberately do not collect
Saying what we do not do is as useful as saying what we do, so here it is explicitly:
- No third-party analytics SDK, no product-analytics vendor, no session replay, no heatmaps.
- No advertising or marketing cookies, no tracking pixels, no ad-network tags, no cross-site identifiers, and no fingerprinting.
- No Aadhaar number, and no copies of the identity documents the verification provider inspects — we receive a verdict and a reference, not the document.
- No card numbers, CVVs or full bank account numbers. Those go directly to a regulated payment provider and never reach our servers.
- No IP address, cookie or device identifier in the click-tracking record behind a campaign’s tracked links.
- No access to your camera or microphone from the mobile app — those permissions are blocked in the app itself, not merely unused.
- No reading, posting, editing or deleting on your social accounts. We ask for read-only permissions and nothing more.
- No Gmail, Drive, Calendar, Contacts, Photos or Google Workspace data. Those Google scopes are never requested, and no part of the product calls those APIs.
- No contact list, calendar, precise location or health data.
Why we use it, and our legal basis
Under India’s Digital Personal Data Protection Act, 2023 we rely on your consent, and on the “legitimate uses” the Act recognises, such as data you voluntarily give us for a purpose you asked for and processing required by law. Under the GDPR and UK GDPR, where they apply to you, our bases are set out below.
- Running your account
- Creating it, verifying your email, signing you in, keeping it secure, and supporting you.Basis: performance of a contract
- Running deals
- Matching brands and creators, generating and storing contracts, taking deliverables, handling approvals, revisions and disputes.Basis: performance of a contract
- Verifying views
- Reading metrics from the social platforms you linked, so earnings rest on a number both sides can see the provenance of.Basis: performance of a contract
- Moving money
- Holding escrow, settling earnings, paying out, taking subscription payments, raising invoices.Basis: performance of a contract; legal obligation
- Identity verification and tax
- KYC and KYB, PAN collection, tax withheld and remitted, invoices and statutory records.Basis: legal obligation
- Fraud prevention and platform safety
- Detecting artificially inflated metrics, coordinated accounts, and abuse; enforcing the Terms.Basis: legitimate interests — keeping a paid marketplace honest, which protects every user in it
- Advertising-disclosure and brand-safety checks
- Scanning captions against a campaign’s own banned-claims list and for disclosure markers.Basis: legitimate interests; legal obligation
- Security
- Logs, session records, rate limiting, audit trails, investigating incidents.Basis: legitimate interests; legal obligation
- Compliance evidence
- Policy acceptance records, the consent register, the 18+ attestation.Basis: legal obligation; legitimate interests
- Service messages
- Telling you a payout landed, a submission was approved, a dispute has a deadline, or the Terms have changed. These are part of the service and are not optional — being able to opt out of being told your money moved would be a worse outcome than any privacy gain.Basis: performance of a contract
- Marketing email
- Waitlist and product announcements.Basis: consent — withdrawable at any time
- Product analytics and personalisation
- Recorded as optional purposes in our consent register. Nothing is processed for them unless you opt in.Basis: consent
- Legal claims
- Establishing, exercising or defending legal claims, and responding to lawful requests.Basis: legal obligation; legitimate interests
Where we rely on legitimate interests, we have weighed them against your rights and interests, and you can object — see section 15.
Automated decisions and profiling
Some decisions on the platform start automatically. You are entitled to know which, what goes into them, and how to challenge them.
- Trust Score
- A 0–100 score computed from brand ratings, stalled deals, rejected submissions and open risk flags over a rolling 90-day window. Brands can gate campaigns on it, so it affects which opportunities are open to you. Every input and weight is published in the Terms, section 17.
- Fraud and risk holds
- Automated checks on view velocity against a post’s own history, on engagement relative to views, and on relationships between accounts. A finding pauses settlement and asks a person to look. It never rejects, and it never decides on its own to keep your money.
- Disclosure and brand-safety scan
- An automated read of a post’s caption against the campaign’s banned-claims list and for disclosure markers. Same outcome: a hold for human review, never an automatic rejection and never a takedown.
- Campaign eligibility
- Campaigns filter by Trust Score, follower count, account age and country. This is a filter set by the brand, applied mechanically.
- Auto-approval and auto-verification
- Scheduled jobs that approve an order a brand left unreviewed for 7 days, and that settle a verified submission once it has aged and its metrics are fresh. Both act in your favour.
None of these is a classifier, and none produces a number nobody can explain. Every rule is a threshold a person can read, argue with, and see quoted back in the reason we give you. That is deliberate: these decisions hold money, and a score of “0.83” is not something anyone can defend themselves against.
Your rights over them
You can ask for an explanation of a decision, ask for a person to review it, put your own case, and contest the outcome. For risk holds the appeal window is 7 days and is built into the product. For anything else, write to privacy@collabkrew.com.
Cookies and similar technologies
This website
No cookies. Nothing in local storage. Nothing in session storage. No consent banner, because there is nothing to consent to.
The platform
- Session cookie
- Keeps you signed in. It cannot be read by page JavaScript and it expires on its own.Strictly necessary
- CSRF cookie
- Stops another website submitting actions as you.Strictly necessary
- Local preferences
- Small values your browser keeps for you, such as your chosen language. They stay on your device.Strictly necessary / functional
That is the complete list. There are no advertising, analytics or third-party cookies, and nothing on the platform is shared with an ad network. The mobile app holds its session token in the operating system’s secure keystore rather than in a cookie.
Who we share it with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it in four circumstances, and no others.
1. With the other side of your deal
- A brand sees a creator’s public storefront, Trust Score, the linked account a submission came from, the submission and its verified metrics, the messages between them, and the contract — which names the creator as a contracting party, because that is what a contract is for.
- A creator sees the brand’s workspace name, its campaign terms, its brand assets, the messages between them, and the same contract.
- A brand does not see a creator’s PAN, tax profile, payout method, bank details, identity-verification data, home address, wallet balance or earnings from other brands.
- A creator does not see a brand’s billing details, plan, wallet balance or its other campaigns’ private data.
- Where a brand has added a creator to a private shortlist, that list is the brand’s own record — but if the creator asks us to erase their data, we redact them from it.
2. With service providers who process data for us
Each is bound by contract to process data only on our instructions, to keep it secure, and not to use it for their own purposes.
- Firebase Hosting for this website; Firebase Realtime Database and Apps Script / Sheets for waitlist signups.Hosting, waitlist storage
- Supabase
- The platform’s PostgreSQL database and its object storage for uploaded files.Database, file storage
- Cloud infrastructure provider
- The virtual machine the application and its background workers run on.Compute
- Email provider
- Sending verification, notification and transactional email over SMTP.Transactional email
- Stripe
- Payouts to creators outside India, and the account verification that comes with them.Payments
- Razorpay
- Payouts to creators in India.Payments
- Identity verification providers
- Verifying a creator’s identity and a business’s registration. In India this runs over government-backed rails (DigiLocker for people, EntityLocker for businesses) through a licensed intermediary; elsewhere through a global verification vendor.KYC / KYB
- Anthropic
- Drafting a campaign brief from a brand’s own description or product page, when a brand uses that feature. See section 10.AI drafting
- Apple
- Delivering push notifications to iOS devices, if you use the mobile app and enable them.Push (when enabled)
- Unsplash
- Serving the stock photography on this website’s scrolling strip. Your IP address is visible to them when the page loads.Images on this site only
- Shopify, WooCommerce
- Only where a brand connects its own store, and only to read order totals for attribution.Brand-initiated
- Professional advisers
- Lawyers, accountants, auditors and insurers, under a duty of confidence.As needed
We keep a current list of our processors and will provide it on request to a brand or agency that has signed our Data Processing Addendum.
3. With the social platforms you link
See section 10 — this runs mostly in the other direction.
4. Where the law or a transaction requires it
- To tax authorities, regulators, courts, and law enforcement acting under valid legal process. We check that a request is valid, we give only what is asked for, and we tell you unless we are legally barred from doing so.
- To enforce our Terms, to investigate fraud, or to protect the rights, property or safety of users or the public.
- To an acquirer, in a merger, acquisition, financing or sale of assets — on the same terms as this policy, and we will tell you.
AI features
A brand can ask us to draft a campaign brief from a short description or from a link to its own product page. When it does, we send that text — and, for a link, the text we fetched from that public page — to Anthropic’s API, which returns a draft.
- Only brand-authored campaign input and public product-page text is sent. No creator profile, no metrics, no messages, no financial data, no identity data.
- The output is a draft that fills a form. Nothing is published automatically; a person edits and publishes it.
- We record how many calls a workspace made and how many tokens they used, for billing and rate limiting. We do not keep the generated text as a profile of anyone.
- Your personal data is not used to train any model — not ours, and not a provider’s.
- No data obtained from Google APIs is ever sent to Anthropic or to any other AI provider, and none of it is used to develop, improve or train generalised or non-personalised AI or machine-learning models. See section 10.
Where your data is processed
We are based in India, and our providers operate globally, so your data may be processed outside the country you live in — including in the United States and the European Economic Area.
Where personal data protected by the GDPR or UK GDPR leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies, together with the additional safeguards those require. For transfers out of India we comply with the restrictions the Digital Personal Data Protection Act, 2023 and any notification made under it impose.
You can ask us for a copy of the transfer safeguards that apply to you: privacy@collabkrew.com.
How long we keep it
We would rather tell you what we actually do than describe a schedule we have not built.
- Waitlist entries
- Until launch plus 12 months, or until you ask us to remove you.
- Account and profile data
- For as long as your account is open. Deleting the account erases it — see section 14.
- Financial records
- Payouts, ledger entries, tax withheld and invoices: retained for the statutory period, currently 7 years, and they survive account deletion. Tax law requires it and a ledger with rows removed no longer balances.
- Contracts
- Signed agreements and the frozen terms of a deal are kept for the limitation period, because both parties hold them.
- Signature evidence
- The IP address and browser recorded beside a signature are automatically deleted 365 days after signing. The signature itself — name, time, basis — stays with the contract. This clock is fixed at the moment you sign, so shortening it later cannot retroactively extend anyone’s retention.
- Identity verification
- The verdict, the provider reference and the identity fingerprint are kept while the account is open and afterwards for the period our anti-money-laundering obligations require.
- Compliance records
- Policy acceptances, consent register entries and the 18+ attestation survive account deletion — they are the proof that a message we sent or a term we relied on had a basis.
- Short-lived tokens
- Email verification links, password reset codes and social-linking state tokens expire within minutes to hours and are then useless. Idempotency records are swept automatically.
- Session records
- Until the session expires or you sign out.
- Support correspondence
- 3 years from the last message, unless it relates to a dispute or a claim.
We do not currently run a general automated purge across every table. Beyond the specific clocks above — signature evidence, short-lived tokens, idempotency records — most operational records are retained for the life of the account and, where there is a legal or contractual reason, after it. Account deletion is what clears personal data today, and it is a self-service action you control.
We are saying this because storage limitation is a real principle and we would rather name the gap than write a retention schedule the system does not implement. Reducing this to a per-table schedule is on our roadmap, and it changes nothing about your right to have your data deleted now.
What deleting your account actually does
You delete your account yourself, from your settings. We show you anything that blocks it first, so you find out before you have committed — you cannot delete while you have a pending payout or unsettled escrow, or while you are the sole owner of a workspace that still holds funds or runs live campaigns.
Erased outright
Sessions and sign-in credentials, linked social accounts and their tokens, follower history, push tokens for your devices, onboarding answers, notifications, report subscriptions, your published packages, campaign match suggestions, your private notes, and your entry on any brand’s private shortlist.
Kept, with you removed from it
- Creator storefront
- Unpublished and emptied — the display name becomes “Deleted creator”, and the headline, bio, niches, country and languages are cleared. The row itself remains because orders and packages hang off it.
- Messages
- Your messages are replaced with “[deleted]”. The thread stays, because it is the other party’s record too.
- Payout methods
- The label is cleared and the method archived.
- Files
- Deleted, except files attached to a settled order, an approved submission or a licence someone bought. A brand that paid for content and is still running it as an advertisement holds a contract, and destroying that content would break it.
Kept in full, and why
- Payouts, the ledger, tax withheld
- Money that moved and tax that was filed. We are legally required to keep it, and it has to reconcile.
- Your tax profile, including PAN
- A filing that names a withholding cannot be made without it, and that obligation outlives the account. This is the clearest example there is of erasure yielding to a legal obligation.
- Signed agreements and the frozen terms of a deal
- A contract two parties hold. Erasing it would destroy the brand’s copy as well as yours.
- Orders, offers, submissions, approvals and the views a payment was calculated from
- The other party’s commercial record of a transaction they paid for.
- Disputes and the evidence filed in them
- A resolved dispute is both parties’ record of the outcome.
- Policy acceptances and the consent register
- Our proof that a message sent last March had consent behind it. Erasing it removes the defence, not the exposure.
- Identity-verification status and its audit trail
- Regulatory identity verification, retained by obligation and append-only by design.
- Licences and listings
- A licence a buyer paid for and still holds.
- Referrals and referral earnings
- Money credited to someone else, on a ledger that must balance.
In every retained record your user id is replaced by a tombstone and your email address is rewritten to a non-routable address that no mail can reach. The database enforces that — a “deleted” row whose email still works would not be a deleted row.
Backups are overwritten on their own cycle. A record erased from the live system may persist in a backup until that cycle completes, during which it is not used for anything except restoring the service.
Your rights, and how to use them
Do it yourself, without asking us
- Download everything
- Settings → Privacy → Download my data gives you a single JSON file containing every row we hold that is keyed to you, across every table and every workspace you have worked with. Credentials are deliberately excluded — session tokens, password hashes, OAuth tokens, push tokens and live tracked-link secrets — because handing you a working credential in a file that ends up in a downloads folder is how you lose it.
- Delete your account
- Settings → Privacy → Delete my account, after a check that shows you anything blocking it. Section 14 explains exactly what happens.
- Correct your details
- Edit them in your profile and settings.
- Manage consents
- Settings → Privacy, where each optional purpose can be granted or withdrawn.
- Unlink a social account
- Settings → Social accounts. It stops collection immediately.
Rights under India’s DPDP Act, 2023
You have the right to access a summary of your personal data and how it is processed, to correction and completion, to erasure, to grievance redressal through our Grievance Officer, and to nominate another person to exercise your rights if you die or become incapacitated. You also have duties under the Act — including not raising false or frivolous complaints and not impersonating another person.
Rights under the GDPR and UK GDPR
If you are in the EEA, the UK or Switzerland: access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interests, objection to direct marketing at any time, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see section 7. You can complain to your supervisory authority, and we would ask you to come to us first so we can put it right.
Rights under the CCPA and CPRA
If you are a California resident: the right to know what we collect, use, disclose and sell; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising any of them.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We collect the categories in section 4 for the business purposes in section 6, and we disclose them to the service providers in section 9.
Writing to us instead
Email privacy@collabkrew.com. We reply within 30 days and will tell you if we need longer and why. We may need to verify your identity before acting — usually by asking you to write from the address on the account. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you what it would cost before doing anything.
If you submitted a brand or agency access request before you had an account, that record holds your name, work email and phone number and is not linked to your user id. It is therefore not reached by the self-service export or by self-service deletion — those work by matching your user id, and nothing connects the two.
Email privacy@collabkrew.com and we will find and handle it by hand. We are fixing this so it is covered automatically; until then the honest thing is to tell you it is not.
Your choices about messages
Our consent register records every optional consent you grant or withdraw, with the date — both directions, not just today’s setting, so the history is available to you as well as to us.
- Marketing email
- Product and launch announcements. Opt in or out at any time; every marketing email also carries an unsubscribe link.Optional
- Product analytics
- Understanding how features are used. Nothing is processed for this unless you opt in.Optional
- Personalisation
- Tailoring campaign suggestions to you.Optional
- Service messages
- A payout landing, a submission approved, a dispute deadline, a change to these documents. Part of the service, not behind a toggle — see section 6.Not optional
- Push notifications
- Controlled by your device’s own permission settings, and by the notification settings in the app.Your device decides
Withdrawing a consent does not undo processing that already happened lawfully while it was in force.
How we protect it
- Everything travels over HTTPS, and data is encrypted at rest by our database and storage providers.
- Every tenant’s data is isolated at the database level, not merely by application code — the database itself refuses to return one workspace’s rows to another.
- Social access and refresh tokens, and store credentials, are stored encrypted. The database enforces this with a constraint that rejects any value that is not properly sealed — so a token written by a fix script at 3am fails loudly rather than sitting in plaintext.
- Identity verification is stored as a one-way peppered hash, never as a raw government identifier.
- Card and bank details never reach our servers; they go directly to a regulated payment provider.
- File uploads use short-lived signed URLs, so files are neither publicly listable nor permanently linkable.
- Administrative access is limited to a small allow-list of people, requires a verified email address and multi-factor authentication, and every administrative action is written to an append-only audit log.
- Passwords, tokens, secrets, authorisation headers and cookies are stripped from logs before anything is written.
- Requests are rate-limited, and the sign-up and access-request endpoints carry a tighter budget because they are on the public internet.
What we cannot promise
No system is perfectly secure. During the pre-launch period the platform is a tester environment with no backup guarantee and no uptime commitment — do not put anything in it that you could not afford to lose. If a breach occurs that is likely to result in a risk to you, we will notify you and the relevant regulators within the time the law requires.
Children
The platform is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we ask for a positive confirmation of age — recorded with its date and time — before you can join a campaign.
If you believe someone under 18 has given us personal data, write to privacy@collabkrew.com. We will close the account and delete the data. Under the DPDP Act we do not track children or direct advertising at them, and we could not — we run no advertising technology at all.
What is public
Some of what you give us is meant to be seen. It helps to be explicit about which parts:
- Your creator storefront
- Display name, headline, bio, niches, languages, country, packages and prices — but only once you publish it. Until then it is private, and unpublishing takes it out of discovery.
- Your Trust Score credential
- A short public page showing your score, so a brand can check it without signing in. It exists only for creators who have published a storefront.
- Your submitted posts
- Public by their nature — they live on YouTube, TikTok or Instagram under your own handle, and a campaign requires them to stay public to be measured.
Public pages can be indexed by search engines and cached by them. We cannot remove a copy someone else has made. Everything else — your legal name, address, identity verification, tax details, payout methods, wallet, messages and contracts — is private to you and to the specific counterparty a deal is with.
Changes to this policy, and how to reach us
Changes
We publish each version of this policy as a numbered record with its own date, and every previous version stays available so you can see what changed. If we make a material change we will tell you before it takes effect, and if you have an account you will be asked to acknowledge the new version the next time you sign in.
Contact
- Privacy and data rights
- privacy@collabkrew.com
- Data Protection Officer
- We have not appointed one. Our processing does not currently meet the thresholds that require a DPO under the GDPR or a Significant Data Fiduciary’s obligations under the DPDP Act, and we would rather say so than name a role nobody holds. Every question a DPO would answer goes to privacy@collabkrew.com, and a person reads it. If we appoint one, this row will name them.
- Grievance Officer (India)
- Grievances under the Information Technology Rules and the DPDP Act go to grievance@collabkrew.com. We acknowledge within 24 hours and aim to resolve within 15 days. The mailbox is monitored by the people operating CollabKrew; once a legal entity is formed, this row will name the individual designated to the role.
- EU / UK representative
- None appointed. We do not target the EEA or the UK, and we have no establishment there. If that changes we will appoint an Article 27 representative and name them here before we do.
- General support
- hello@collabkrew.com
- Post
- We have no postal address to publish yet, and an invented one would be worse than none. Email reaches us; a postal address will appear here with the registered office once the entity is formed.
If you are not satisfied
Come to us first — we would rather fix it than have you escalate. If we do not resolve it, you can complain to the Data Protection Board of India, to your supervisory authority in the EEA, to the Information Commissioner’s Office in the UK, or to the California Privacy Protection Agency, as applicable to you.
Google user data, and data from TikTok and Instagram
Verified views are the heart of the product, and they come from the official APIs of the platforms you post on. This section is the disclosure those platforms require. Google’s requirements are the strictest and the most specific, so Google is dealt with first and in full: what we ask for, what we receive, what we do with it, who else sees it, how it is protected, how long we keep it, and how you take it back.
The two places CollabKrew uses a Google account
Both are optional, both are started by you, and neither happens until you have been through Google’s own consent screen.
Those are the only Google scopes CollabKrew requests, anywhere in the product. We do not ask for Gmail, Drive, Calendar, Contacts, Photos, or any Google Workspace scope, and no part of the application is written to call those APIs.
What Google user data we receive, and what each item is for
The view, like and comment counts on a submitted video are read from the public YouTube Data API with our own API key, against a video that is already public — not with your token and not from your account. Your token is used for exactly two reads: confirming which channel is yours when you link, and re-reading that same channel’s handle and subscriber count afterwards. That separation is deliberate, and it is why verification of your submissions keeps working even after a token expires.
What we never ask Google for, and could not do if we wanted to
How Google user data is stored and protected
Who we share Google user data with
We do not sell Google user data. We have never sold it, we do not transfer it to data brokers or information resellers, and we do not share it for advertising of any kind. It leaves our systems in three circumstances only:
If CollabKrew were ever acquired, Google user data would transfer only on the terms of this policy, and we would tell you before it did.
How long we keep it, and how to take it back
You can also download everything we hold about you, Google-derived data included, as a single file from your settings — see section 15 — or write to privacy@collabkrew.com and ask us to delete it.
Limited Use
CollabKrew’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Stated as the specific commitments it consists of:
CollabKrew does not use data obtained through Google APIs — or through Google Workspace APIs — to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. No Google user data is sent to any third-party AI provider. The one AI feature in the product is described in section 11: it drafts a campaign brief from a brand’s own text, it is used by brands rather than creators, and nothing Google-derived is included in what is sent.
The automated checks described in section 7 — fraud, disclosure and brand-safety — are deterministic rules applied to a specific submission to decide whether a person should look at it. They train nothing, and no model is fitted on your data.
YouTube API Services
CollabKrew uses YouTube API Services. By linking a YouTube channel you also agree to the YouTube Terms of Service. Google’s own handling of your data is described in the Google Privacy Policy, and you can revoke CollabKrew’s access to your YouTube data at the Google security settings page.
TikTok and Instagram
The same shape applies to TikTok and to Instagram: read-only access, requested through their own authorisation flows, used only to prove which account is yours and to read statistics on the posts you submit, never used for advertising, never sold, and revocable at any time from CollabKrew or from your account settings on those platforms. From those APIs we receive your account id and handle, your follower count over time, and for each submitted post its id, view, like and comment counts, whether it is public, and its caption where the platform exposes one.
When you unlink
Unlinking any platform stops all further collection immediately and deletes the stored tokens. Metrics already recorded against a submission stay, because they are the basis on which a payment was calculated and a brand relies on them too.