collabkrewJoin the waitlist

LegalVersion 1.1

privacy

What we collect, why, who sees it, how long we keep it and the rights you have over it — written against the platform's own data inventory, including the gaps we disclose rather than paper over.

Effective
21 September 2026
Last updated
21 September 2026
Version
1.1
Applies to
collabkrew.com, app.collabkrew.com and the CollabKrew mobile apps

Contents

  1. Who we are, and what this policy covers
  2. The short version
  3. What this website collects
  4. What the platform collects
  5. What we deliberately do not collect
  6. Why we use it, and our legal basis
  7. Automated decisions and profiling
  8. Cookies and similar technologies
  9. Who we share it with
  10. Google user data, and data from TikTok and Instagram
  11. AI features
  12. Where your data is processed
  13. How long we keep it
  14. What deleting your account actually does
  15. Your rights, and how to use them
  16. Your choices about messages
  17. How we protect it
  18. Children
  19. What is public
  20. Changes to this policy, and how to reach us
01

Who we are, and what this policy covers

This policy explains what CollabKrew does with personal data. CollabKrew is a creator–brand collaboration platform operated from India. The data controller — whoever decides why and how your data is used — is CollabKrew, and you can reach us at any time at privacy@collabkrew.com.

CollabKrew is not yet incorporated. When a legal entity is formed it will become the named controller, this section will carry its registered name and office, and — because that is a material change — we will tell you before it takes effect. Until then, the commitments in this policy are made and kept by the people operating CollabKrew, and a change of legal form will not weaken them.

It covers:

  • this website at collabkrew.com, including the waitlist form;
  • the CollabKrew platform at app.collabkrew.com and our mobile apps, once you have an account;
  • our emails and notifications to you.

It does not cover what a brand does with your data on its own systems after a deal, what a social platform does with your account, or what a website we link to does. Those are governed by their own policies.

Where brands are the controller, not us

For most things we are the controller. But where a brand or agency uploads personal data of its own into its workspace — a shortlist of creators it sourced elsewhere, a contact it invited, its own customer order references used for conversion tracking — that brand is the controller and we process it on their instructions under a Data Processing Addendum. If you want that data removed, ask the brand; tell us too and we will pass it on.

02

The short version

  • Right now this website does one thing with personal data: it takes waitlist signups — your email, optionally your name, and whether you are a brand or a creator.
  • We do not use advertising trackers, analytics SDKs, or third-party cookies. There are no cookies on this website at all.
  • We never sell your personal data, and we never share it for cross-context behavioural advertising.
  • On the platform we collect what running a paid marketplace actually requires: who you are, what you agreed, what you delivered, what it earned, and what tax was withheld.
  • You can download everything we hold about you as one file, from your own settings, without asking us.
  • You can delete your account yourself. We anonymise rather than obliterate, because tax records and contracts other people hold have to survive — and we list exactly what survives, with the reason.
  • Automated checks can hold a payment for review. None of them can reject you on their own; a person decides, and you can appeal.
  • Where you sign in with Google or link a YouTube channel, our use of that data follows the Google API Services User Data Policy, including its Limited Use requirements. We never sell it, never advertise against it, and never train a model on it. Section 10 says exactly what we receive and why.
03

What this website collects

collabkrew.com is a static site. It runs no analytics, sets no cookies, and stores nothing in your browser.

The waitlist form

Email address
Required. It is how we contact you when early access opens.
Name
Optional — your name, or your brand or company name. Leave it blank if you prefer.
Role
Whether you are joining as a brand or as a creator, so we invite you into the right side of the product.
Timestamp
When you signed up.

That is the whole record. We ask for nothing else, and the form has nowhere to put anything else.

Where it goes, and who sees it on the way

Your browser sends the signup directly to two Google services: a Firebase Realtime Database, and a Google Apps Script endpoint that appends a row to a Google Sheet we control. We use two so that a signup is not lost if one of them is down. Because your browser talks to Google directly, Google sees your IP address when you submit the form. The database is configured so that signups can be written but not read back by anyone without our credentials.

Other requests your browser makes on this page

Firebase Hosting
This site is hosted by Google. Their servers log the IP address, time, browser and pages requested, as any web server does.Google LLC / Google Ireland
Unsplash
The scrolling photo strip loads stock photography from images.unsplash.com, so Unsplash sees your IP address and browser when the page loads. The photos are illustrative stock images, not CollabKrew users.Unsplash Inc.
Fonts
None. The Inter typeface is downloaded when we build the site and served from our own domain, so your browser never contacts a font provider.

How long we keep a waitlist entry

Until launch plus 12 months, or until you ask us to remove it, whichever comes first. Unsubscribing from a waitlist email removes you. If you later create an account, the account record replaces the waitlist one.

04

What the platform collects

Once you have an account, we hold the following. This list is generated from the same inventory that drives your data export, so it is not a summary of what we think we hold — it is what we hold.

Who you are

Account
Name, email address, whether it is verified, profile image, whether you signed up as a brand, agency or creator, your interface language, locale and preferred display currency, and the date and time you confirmed you are 18 or over.
Sign-in
A hashed password, or — if you signed in with Google or Apple — that provider’s identifier for your account and the tokens it issues us. From Google we receive your Google account id, your email address and whether Google has already verified it, your name and your profile picture, and nothing else; section 10 sets out what each is for. We never see your password with those providers, and we never store your password in a readable form.
Onboarding profile
First and last name, country, state or region, city, profile photo. For brands: brand name, website, address, postal code, registered legal entity name, entity type, and the name and title of the person authorised to sign. For creators: legal full name and address. Plus what you told us about your interests, niches and how you plan to use the platform.
Creator storefront
Display name, headline, biography, niches, languages, country, and the packages and prices you publish. This is public — see section 19.

Your social accounts

Linked accounts
Which platform, the account id and handle there, your follower count, which permissions you granted, and encrypted access and refresh tokens. The tokens are stored sealed, and the database physically rejects a token that is not encrypted.
Post metrics
For each submitted post: views, likes, comments, whether it is public, and the caption where the platform exposes one — recorded as a series of timestamped snapshots that are only ever added to, never edited.
Follower history
Your follower count over time, with the handle it was recorded under, so a priced deal can cite the reach it was priced against and so a handle change does not silently rewrite the past.

What you did on the platform

Campaigns and submissions
Campaigns you joined, the frozen copy of the terms you accepted, the posts you submitted and their URLs, verification status and the reason for any rejection or flag.
Orders and offers
Deals, prices, deliverable specifications, delivery dates, renegotiated dates, tasks, revisions, approvals and reviews.
Agreements
The signed Creator–Brand Collaboration Agreement for each deal, the typed or drawn signature and the signer’s name, and — as evidence that the signature is real — the IP address and browser it was signed from.
Licences
Content you listed for licence and licences bought or sold, with the scope, duration and territory as agreed.
Reputation
Your Trust Score and its history, guild membership and leaderboard entries.
Tracked links
Which campaigns you were issued a tracked link or promo code for. The click record itself contains no IP address, no cookie and no device information — only that a click happened and when.

Money

Ledger and wallet
Every movement of money as double-entry records, per currency.
Payouts
Amount, currency, tax withheld, status, failure reason and settlement date.
Payout methods
The kind of method, a label, the last four digits, the currency, and a token from the payment provider. We never hold your full bank account number or card number — those live with the payment provider, not with us.
Tax profile
Your country and, for Indian creators, your PAN and the withholding rate applied. We need the PAN to make and file the deduction correctly.
Identity verification
Whether verification passed, a reference from the verification provider, and a one-way peppered hash of the identity the provider verified — which is what stops one person holding two accounts. We do not store your Aadhaar number, and we do not keep the underlying document identifiers.
Referrals
Your referral code, who you referred or were referred by, and what was earned.
Invoices
Tax invoices we raised for subscription charges, including a GSTIN where given.

What you said, and what we told you

Messages
Conversations with the other side of a deal, their content and attachments, and a flag recording whether a message appeared to contain off-platform contact details. See the Terms, section 23, for why we scan and why we only warn.
Notifications
In-app notifications and their read status, and — if you use the mobile app and allow it — a push token for each device, with the platform and when it was last seen.
Disputes
Disputes you raised or were party to, the reason, your explanation, and the evidence either side filed.
Support
What you write to us, and our replies.

Compliance and security records

Policy acceptances
Which version of the Terms or this Privacy Policy you accepted, when, and the IP address and browser you accepted from. This is evidence, not analytics — it exists so that “you agreed” can be substantiated rather than merely asserted.
Consent register
Every optional consent you granted or withdrew, with the date and the IP address and browser it was recorded from. Both the grant and the withdrawal, not just today’s setting.
Sessions
For each sign-in: an IP address, a browser or device string, and when the session expires.
Server logs and traces
Ordinary web-server and application logs. Values that look like passwords, tokens, secrets, authorisation headers or cookies are stripped before anything is written.

If you applied for brand access

A brand or agency access request holds your first and last name, work email, phone number, company, website, budget range, team size, industry and what you want to achieve — submitted before any account exists. Please read the disclosure in section 15 about how this particular record interacts with your self-service rights.

If you connect a store

A brand can connect a Shopify or WooCommerce store. We store the shop domain and encrypted API credentials, and we read order totals and order references to attribute revenue to campaigns. We do not ingest your customers’ names, addresses, emails or payment details.

05

What we deliberately do not collect

Saying what we do not do is as useful as saying what we do, so here it is explicitly:

  • No third-party analytics SDK, no product-analytics vendor, no session replay, no heatmaps.
  • No advertising or marketing cookies, no tracking pixels, no ad-network tags, no cross-site identifiers, and no fingerprinting.
  • No Aadhaar number, and no copies of the identity documents the verification provider inspects — we receive a verdict and a reference, not the document.
  • No card numbers, CVVs or full bank account numbers. Those go directly to a regulated payment provider and never reach our servers.
  • No IP address, cookie or device identifier in the click-tracking record behind a campaign’s tracked links.
  • No access to your camera or microphone from the mobile app — those permissions are blocked in the app itself, not merely unused.
  • No reading, posting, editing or deleting on your social accounts. We ask for read-only permissions and nothing more.
  • No Gmail, Drive, Calendar, Contacts, Photos or Google Workspace data. Those Google scopes are never requested, and no part of the product calls those APIs.
  • No contact list, calendar, precise location or health data.
06

Why we use it, and our legal basis

Under India’s Digital Personal Data Protection Act, 2023 we rely on your consent, and on the “legitimate uses” the Act recognises, such as data you voluntarily give us for a purpose you asked for and processing required by law. Under the GDPR and UK GDPR, where they apply to you, our bases are set out below.

Running your account
Creating it, verifying your email, signing you in, keeping it secure, and supporting you.Basis: performance of a contract
Running deals
Matching brands and creators, generating and storing contracts, taking deliverables, handling approvals, revisions and disputes.Basis: performance of a contract
Verifying views
Reading metrics from the social platforms you linked, so earnings rest on a number both sides can see the provenance of.Basis: performance of a contract
Moving money
Holding escrow, settling earnings, paying out, taking subscription payments, raising invoices.Basis: performance of a contract; legal obligation
Identity verification and tax
KYC and KYB, PAN collection, tax withheld and remitted, invoices and statutory records.Basis: legal obligation
Fraud prevention and platform safety
Detecting artificially inflated metrics, coordinated accounts, and abuse; enforcing the Terms.Basis: legitimate interests — keeping a paid marketplace honest, which protects every user in it
Advertising-disclosure and brand-safety checks
Scanning captions against a campaign’s own banned-claims list and for disclosure markers.Basis: legitimate interests; legal obligation
Security
Logs, session records, rate limiting, audit trails, investigating incidents.Basis: legitimate interests; legal obligation
Compliance evidence
Policy acceptance records, the consent register, the 18+ attestation.Basis: legal obligation; legitimate interests
Service messages
Telling you a payout landed, a submission was approved, a dispute has a deadline, or the Terms have changed. These are part of the service and are not optional — being able to opt out of being told your money moved would be a worse outcome than any privacy gain.Basis: performance of a contract
Marketing email
Waitlist and product announcements.Basis: consent — withdrawable at any time
Product analytics and personalisation
Recorded as optional purposes in our consent register. Nothing is processed for them unless you opt in.Basis: consent
Legal claims
Establishing, exercising or defending legal claims, and responding to lawful requests.Basis: legal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights and interests, and you can object — see section 15.

07

Automated decisions and profiling

Some decisions on the platform start automatically. You are entitled to know which, what goes into them, and how to challenge them.

Trust Score
A 0–100 score computed from brand ratings, stalled deals, rejected submissions and open risk flags over a rolling 90-day window. Brands can gate campaigns on it, so it affects which opportunities are open to you. Every input and weight is published in the Terms, section 17.
Fraud and risk holds
Automated checks on view velocity against a post’s own history, on engagement relative to views, and on relationships between accounts. A finding pauses settlement and asks a person to look. It never rejects, and it never decides on its own to keep your money.
Disclosure and brand-safety scan
An automated read of a post’s caption against the campaign’s banned-claims list and for disclosure markers. Same outcome: a hold for human review, never an automatic rejection and never a takedown.
Campaign eligibility
Campaigns filter by Trust Score, follower count, account age and country. This is a filter set by the brand, applied mechanically.
Auto-approval and auto-verification
Scheduled jobs that approve an order a brand left unreviewed for 7 days, and that settle a verified submission once it has aged and its metrics are fresh. Both act in your favour.
The principle we built to

None of these is a classifier, and none produces a number nobody can explain. Every rule is a threshold a person can read, argue with, and see quoted back in the reason we give you. That is deliberate: these decisions hold money, and a score of “0.83” is not something anyone can defend themselves against.

Your rights over them

You can ask for an explanation of a decision, ask for a person to review it, put your own case, and contest the outcome. For risk holds the appeal window is 7 days and is built into the product. For anything else, write to privacy@collabkrew.com.

08

Cookies and similar technologies

This website

No cookies. Nothing in local storage. Nothing in session storage. No consent banner, because there is nothing to consent to.

The platform

Session cookie
Keeps you signed in. It cannot be read by page JavaScript and it expires on its own.Strictly necessary
CSRF cookie
Stops another website submitting actions as you.Strictly necessary
Local preferences
Small values your browser keeps for you, such as your chosen language. They stay on your device.Strictly necessary / functional

That is the complete list. There are no advertising, analytics or third-party cookies, and nothing on the platform is shared with an ad network. The mobile app holds its session token in the operating system’s secure keystore rather than in a cookie.

09

Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it in four circumstances, and no others.

1. With the other side of your deal

  • A brand sees a creator’s public storefront, Trust Score, the linked account a submission came from, the submission and its verified metrics, the messages between them, and the contract — which names the creator as a contracting party, because that is what a contract is for.
  • A creator sees the brand’s workspace name, its campaign terms, its brand assets, the messages between them, and the same contract.
  • A brand does not see a creator’s PAN, tax profile, payout method, bank details, identity-verification data, home address, wallet balance or earnings from other brands.
  • A creator does not see a brand’s billing details, plan, wallet balance or its other campaigns’ private data.
  • Where a brand has added a creator to a private shortlist, that list is the brand’s own record — but if the creator asks us to erase their data, we redact them from it.

2. With service providers who process data for us

Each is bound by contract to process data only on our instructions, to keep it secure, and not to use it for their own purposes.

Google
Firebase Hosting for this website; Firebase Realtime Database and Apps Script / Sheets for waitlist signups.Hosting, waitlist storage
Supabase
The platform’s PostgreSQL database and its object storage for uploaded files.Database, file storage
Cloud infrastructure provider
The virtual machine the application and its background workers run on.Compute
Email provider
Sending verification, notification and transactional email over SMTP.Transactional email
Stripe
Payouts to creators outside India, and the account verification that comes with them.Payments
Razorpay
Payouts to creators in India.Payments
Identity verification providers
Verifying a creator’s identity and a business’s registration. In India this runs over government-backed rails (DigiLocker for people, EntityLocker for businesses) through a licensed intermediary; elsewhere through a global verification vendor.KYC / KYB
Anthropic
Drafting a campaign brief from a brand’s own description or product page, when a brand uses that feature. See section 10.AI drafting
Apple
Delivering push notifications to iOS devices, if you use the mobile app and enable them.Push (when enabled)
Unsplash
Serving the stock photography on this website’s scrolling strip. Your IP address is visible to them when the page loads.Images on this site only
Shopify, WooCommerce
Only where a brand connects its own store, and only to read order totals for attribution.Brand-initiated
Professional advisers
Lawyers, accountants, auditors and insurers, under a duty of confidence.As needed

We keep a current list of our processors and will provide it on request to a brand or agency that has signed our Data Processing Addendum.

3. With the social platforms you link

See section 10 — this runs mostly in the other direction.

4. Where the law or a transaction requires it

  • To tax authorities, regulators, courts, and law enforcement acting under valid legal process. We check that a request is valid, we give only what is asked for, and we tell you unless we are legally barred from doing so.
  • To enforce our Terms, to investigate fraud, or to protect the rights, property or safety of users or the public.
  • To an acquirer, in a merger, acquisition, financing or sale of assets — on the same terms as this policy, and we will tell you.
10

Google user data, and data from TikTok and Instagram

Verified views are the heart of the product, and they come from the official APIs of the platforms you post on. This section is the disclosure those platforms require. Google’s requirements are the strictest and the most specific, so Google is dealt with first and in full: what we ask for, what we receive, what we do with it, who else sees it, how it is protected, how long we keep it, and how you take it back.

The two places CollabKrew uses a Google account

Both are optional, both are started by you, and neither happens until you have been through Google’s own consent screen.

Signing in with Google
An alternative to a password. You are sent to Google’s sign-in screen, Google tells us that the sign-in succeeded and who it was, and we create or open the matching CollabKrew account. You can use an email address and password instead and never involve Google at all.Scopes: openid, email, profile
Linking a YouTube channel
Only for creators, and only if you want to submit YouTube videos to a campaign. It proves which channel is yours, so that nobody can submit someone else’s video and be paid for its views.Scope: https://www.googleapis.com/auth/youtube.readonly

Those are the only Google scopes CollabKrew requests, anywhere in the product. We do not ask for Gmail, Drive, Calendar, Contacts, Photos, or any Google Workspace scope, and no part of the application is written to call those APIs.

What Google user data we receive, and what each item is for

Your Google account identifier
A stable id for your Google account. It is what links your next sign-in to the same CollabKrew account rather than creating a second one.Sign-in
Email address, and whether Google has verified it
It becomes the email address on your CollabKrew account, and it is how we send you service messages such as a payout landing or a deadline falling due. Google having already verified it means we do not have to make you verify it again.Sign-in
Name and profile picture
Used to pre-fill your name and avatar so you do not have to type them. You can change or clear both in your settings afterwards.Sign-in
Your YouTube channel id and handle
Recorded against your account as the channel you own. Every video you later submit is checked against it — if the video's channel is not this channel, the submission is refused. This single check is the reason the YouTube scope is requested at all.youtube.readonly
Your subscriber count
Read when you link and re-read periodically, and stored as a dated series. Brands set follower thresholds on campaigns, and a deal priced against reach has to be able to cite the reach it was priced against.youtube.readonly
Your channel’s thumbnail image URL
Shown as the avatar beside the linked channel in your own settings, so you can see which channel is connected.youtube.readonly
OAuth access and refresh tokens
Google’s credentials for the read-only permission you granted. They are what lets us re-read your subscriber count later without asking you to sign in again. They are stored encrypted — see below — and are never shown to you, to a brand, or to anyone else.youtube.readonly
What the YouTube scope is not used for

The view, like and comment counts on a submitted video are read from the public YouTube Data API with our own API key, against a video that is already public — not with your token and not from your account. Your token is used for exactly two reads: confirming which channel is yours when you link, and re-reading that same channel’s handle and subscriber count afterwards. That separation is deliberate, and it is why verification of your submissions keeps working even after a token expires.

What we never ask Google for, and could not do if we wanted to

  • We cannot upload, edit, delete or schedule a video, change a title, description or thumbnail, or alter anything at all on your channel. The youtube.readonly scope grants no write of any kind.
  • We cannot post, reply to or moderate comments, and we cannot message anyone as you.
  • We cannot read your private or unlisted videos' performance on your behalf as an ongoing feed — we read the channel that is yours, and public statistics for the specific videos you choose to submit.
  • We do not read your Gmail, your Drive, your Calendar, your Contacts or your Photos. Those scopes are not requested, not granted, and not called.
  • We do not use Google user data to build an advertising profile, and we run no advertising product.

How Google user data is stored and protected

  • In transit it travels over TLS, to us and to Google.
  • OAuth access and refresh tokens are encrypted with authenticated encryption before they are written, and the database physically rejects a token column that is not sealed — an unencrypted token cannot be stored even by mistake.
  • Encryption keys live in the server's environment, not in the database, so a copy of the database on its own does not yield a usable token.
  • The rest — channel id, handle, subscriber history, email, name — sits in our managed PostgreSQL database, encrypted at rest by the provider, reachable only by the application and by named administrators.
  • Access to production data is limited to the people who operate the service, and application logs strip anything that looks like a token, password, secret, authorisation header or cookie before it is written.

Who we share Google user data with

We do not sell Google user data. We have never sold it, we do not transfer it to data brokers or information resellers, and we do not share it for advertising of any kind. It leaves our systems in three circumstances only:

  1. To the brand whose campaign you submitted to — and only the channel handle the submission came from, the submitted video and its verified public metrics. Never your email address from Google, never your tokens, and never your channel data outside the context of a deal you entered into.
  2. To the infrastructure providers that run the service — the database and hosting listed in section 9 — which store it on our instructions under contract, and are not permitted to use it for their own purposes.
  3. Where the law requires it — valid legal process, or to investigate fraud and protect users, on the same terms as the rest of section 9.

If CollabKrew were ever acquired, Google user data would transfer only on the terms of this policy, and we would tell you before it did.

How long we keep it, and how to take it back

Revoke at Google
Remove CollabKrew’s access at any time from myaccount.google.com/permissions. Our access ends the moment you do, with no action needed from us.
Unlink in CollabKrew
Settings → Linked accounts → Unlink. This stops all further collection immediately and deletes the stored access and refresh tokens.
Delete your account
Deleting your CollabKrew account erases the linked account record, its tokens and your follower history outright. Section 14 sets out exactly what a deletion erases and what it cannot.
Tokens
Kept only while the link is live. Deleted on unlink, on account deletion, and when a revoked grant is detected on refresh.
Channel id, handle and subscriber history
Kept while the account is linked. Metrics already recorded against a submission stay after unlinking, because they are the basis on which a payment was calculated and the brand relies on them too — see the end of this section.
Email and name from Google sign-in
Held for as long as your account is open, as your account's own email and name, and erased or anonymised on account deletion per section 14.

You can also download everything we hold about you, Google-derived data included, as a single file from your settings — see section 15 — or write to privacy@collabkrew.com and ask us to delete it.

Limited Use

CollabKrew’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Stated as the specific commitments it consists of:

  • We use Google user data only to provide and improve the user-facing features described in this section — proving channel ownership, verifying submissions, and reporting a campaign's results to its two parties. We do not use it for any other purpose.
  • We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.
  • We do not use Google user data for serving advertising of any kind — not targeted, not personalised, not retargeted, and not for building audiences or profiles for advertisers.
  • We do not sell Google user data, and we do not transfer it to data brokers, information resellers, or anyone assembling a database from it.
  • We do not use Google user data for creditworthiness, lending, insurance, employment or any similar eligibility decision.
  • We do not allow humans to read Google user data, unless you have given specific consent for specific data, it is necessary for security purposes such as investigating abuse, it is required by law, or the data has been aggregated and anonymised for internal operations.
AI and machine learning, stated explicitly

CollabKrew does not use data obtained through Google APIs — or through Google Workspace APIs — to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. No Google user data is sent to any third-party AI provider. The one AI feature in the product is described in section 11: it drafts a campaign brief from a brand’s own text, it is used by brands rather than creators, and nothing Google-derived is included in what is sent.

The automated checks described in section 7 — fraud, disclosure and brand-safety — are deterministic rules applied to a specific submission to decide whether a person should look at it. They train nothing, and no model is fitted on your data.

YouTube API Services

CollabKrew uses YouTube API Services. By linking a YouTube channel you also agree to the YouTube Terms of Service. Google’s own handling of your data is described in the Google Privacy Policy, and you can revoke CollabKrew’s access to your YouTube data at the Google security settings page.

TikTok and Instagram

The same shape applies to TikTok and to Instagram: read-only access, requested through their own authorisation flows, used only to prove which account is yours and to read statistics on the posts you submit, never used for advertising, never sold, and revocable at any time from CollabKrew or from your account settings on those platforms. From those APIs we receive your account id and handle, your follower count over time, and for each submitted post its id, view, like and comment counts, whether it is public, and its caption where the platform exposes one.

When you unlink

Unlinking any platform stops all further collection immediately and deletes the stored tokens. Metrics already recorded against a submission stay, because they are the basis on which a payment was calculated and a brand relies on them too.

11

AI features

A brand can ask us to draft a campaign brief from a short description or from a link to its own product page. When it does, we send that text — and, for a link, the text we fetched from that public page — to Anthropic’s API, which returns a draft.

  • Only brand-authored campaign input and public product-page text is sent. No creator profile, no metrics, no messages, no financial data, no identity data.
  • The output is a draft that fills a form. Nothing is published automatically; a person edits and publishes it.
  • We record how many calls a workspace made and how many tokens they used, for billing and rate limiting. We do not keep the generated text as a profile of anyone.
  • Your personal data is not used to train any model — not ours, and not a provider’s.
  • No data obtained from Google APIs is ever sent to Anthropic or to any other AI provider, and none of it is used to develop, improve or train generalised or non-personalised AI or machine-learning models. See section 10.
12

Where your data is processed

We are based in India, and our providers operate globally, so your data may be processed outside the country you live in — including in the United States and the European Economic Area.

Where personal data protected by the GDPR or UK GDPR leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies, together with the additional safeguards those require. For transfers out of India we comply with the restrictions the Digital Personal Data Protection Act, 2023 and any notification made under it impose.

You can ask us for a copy of the transfer safeguards that apply to you: privacy@collabkrew.com.

13

How long we keep it

We would rather tell you what we actually do than describe a schedule we have not built.

Waitlist entries
Until launch plus 12 months, or until you ask us to remove you.
Account and profile data
For as long as your account is open. Deleting the account erases it — see section 14.
Financial records
Payouts, ledger entries, tax withheld and invoices: retained for the statutory period, currently 7 years, and they survive account deletion. Tax law requires it and a ledger with rows removed no longer balances.
Contracts
Signed agreements and the frozen terms of a deal are kept for the limitation period, because both parties hold them.
Signature evidence
The IP address and browser recorded beside a signature are automatically deleted 365 days after signing. The signature itself — name, time, basis — stays with the contract. This clock is fixed at the moment you sign, so shortening it later cannot retroactively extend anyone’s retention.
Identity verification
The verdict, the provider reference and the identity fingerprint are kept while the account is open and afterwards for the period our anti-money-laundering obligations require.
Compliance records
Policy acceptances, consent register entries and the 18+ attestation survive account deletion — they are the proof that a message we sent or a term we relied on had a basis.
Short-lived tokens
Email verification links, password reset codes and social-linking state tokens expire within minutes to hours and are then useless. Idempotency records are swept automatically.
Session records
Until the session expires or you sign out.
Support correspondence
3 years from the last message, unless it relates to a dispute or a claim.
Stated plainly, because you should know it

We do not currently run a general automated purge across every table. Beyond the specific clocks above — signature evidence, short-lived tokens, idempotency records — most operational records are retained for the life of the account and, where there is a legal or contractual reason, after it. Account deletion is what clears personal data today, and it is a self-service action you control.

We are saying this because storage limitation is a real principle and we would rather name the gap than write a retention schedule the system does not implement. Reducing this to a per-table schedule is on our roadmap, and it changes nothing about your right to have your data deleted now.

14

What deleting your account actually does

You delete your account yourself, from your settings. We show you anything that blocks it first, so you find out before you have committed — you cannot delete while you have a pending payout or unsettled escrow, or while you are the sole owner of a workspace that still holds funds or runs live campaigns.

Erased outright

Sessions and sign-in credentials, linked social accounts and their tokens, follower history, push tokens for your devices, onboarding answers, notifications, report subscriptions, your published packages, campaign match suggestions, your private notes, and your entry on any brand’s private shortlist.

Kept, with you removed from it

Creator storefront
Unpublished and emptied — the display name becomes “Deleted creator”, and the headline, bio, niches, country and languages are cleared. The row itself remains because orders and packages hang off it.
Messages
Your messages are replaced with “[deleted]”. The thread stays, because it is the other party’s record too.
Payout methods
The label is cleared and the method archived.
Files
Deleted, except files attached to a settled order, an approved submission or a licence someone bought. A brand that paid for content and is still running it as an advertisement holds a contract, and destroying that content would break it.

Kept in full, and why

Payouts, the ledger, tax withheld
Money that moved and tax that was filed. We are legally required to keep it, and it has to reconcile.
Your tax profile, including PAN
A filing that names a withholding cannot be made without it, and that obligation outlives the account. This is the clearest example there is of erasure yielding to a legal obligation.
Signed agreements and the frozen terms of a deal
A contract two parties hold. Erasing it would destroy the brand’s copy as well as yours.
Orders, offers, submissions, approvals and the views a payment was calculated from
The other party’s commercial record of a transaction they paid for.
Disputes and the evidence filed in them
A resolved dispute is both parties’ record of the outcome.
Policy acceptances and the consent register
Our proof that a message sent last March had consent behind it. Erasing it removes the defence, not the exposure.
Identity-verification status and its audit trail
Regulatory identity verification, retained by obligation and append-only by design.
Licences and listings
A licence a buyer paid for and still holds.
Referrals and referral earnings
Money credited to someone else, on a ledger that must balance.

In every retained record your user id is replaced by a tombstone and your email address is rewritten to a non-routable address that no mail can reach. The database enforces that — a “deleted” row whose email still works would not be a deleted row.

Backups are overwritten on their own cycle. A record erased from the live system may persist in a backup until that cycle completes, during which it is not used for anything except restoring the service.

15

Your rights, and how to use them

Do it yourself, without asking us

Download everything
Settings → Privacy → Download my data gives you a single JSON file containing every row we hold that is keyed to you, across every table and every workspace you have worked with. Credentials are deliberately excluded — session tokens, password hashes, OAuth tokens, push tokens and live tracked-link secrets — because handing you a working credential in a file that ends up in a downloads folder is how you lose it.
Delete your account
Settings → Privacy → Delete my account, after a check that shows you anything blocking it. Section 14 explains exactly what happens.
Correct your details
Edit them in your profile and settings.
Manage consents
Settings → Privacy, where each optional purpose can be granted or withdrawn.
Unlink a social account
Settings → Social accounts. It stops collection immediately.

Rights under India’s DPDP Act, 2023

You have the right to access a summary of your personal data and how it is processed, to correction and completion, to erasure, to grievance redressal through our Grievance Officer, and to nominate another person to exercise your rights if you die or become incapacitated. You also have duties under the Act — including not raising false or frivolous complaints and not impersonating another person.

Rights under the GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland: access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interests, objection to direct marketing at any time, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see section 7. You can complain to your supervisory authority, and we would ask you to come to us first so we can put it right.

Rights under the CCPA and CPRA

If you are a California resident: the right to know what we collect, use, disclose and sell; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising any of them.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We collect the categories in section 4 for the business purposes in section 6, and we disclose them to the service providers in section 9.

Writing to us instead

Email privacy@collabkrew.com. We reply within 30 days and will tell you if we need longer and why. We may need to verify your identity before acting — usually by asking you to write from the address on the account. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you what it would cost before doing anything.

A gap we are disclosing rather than hiding

If you submitted a brand or agency access request before you had an account, that record holds your name, work email and phone number and is not linked to your user id. It is therefore not reached by the self-service export or by self-service deletion — those work by matching your user id, and nothing connects the two.

Email privacy@collabkrew.com and we will find and handle it by hand. We are fixing this so it is covered automatically; until then the honest thing is to tell you it is not.

16

Your choices about messages

Our consent register records every optional consent you grant or withdraw, with the date — both directions, not just today’s setting, so the history is available to you as well as to us.

Marketing email
Product and launch announcements. Opt in or out at any time; every marketing email also carries an unsubscribe link.Optional
Product analytics
Understanding how features are used. Nothing is processed for this unless you opt in.Optional
Personalisation
Tailoring campaign suggestions to you.Optional
Service messages
A payout landing, a submission approved, a dispute deadline, a change to these documents. Part of the service, not behind a toggle — see section 6.Not optional
Push notifications
Controlled by your device’s own permission settings, and by the notification settings in the app.Your device decides

Withdrawing a consent does not undo processing that already happened lawfully while it was in force.

17

How we protect it

  • Everything travels over HTTPS, and data is encrypted at rest by our database and storage providers.
  • Every tenant’s data is isolated at the database level, not merely by application code — the database itself refuses to return one workspace’s rows to another.
  • Social access and refresh tokens, and store credentials, are stored encrypted. The database enforces this with a constraint that rejects any value that is not properly sealed — so a token written by a fix script at 3am fails loudly rather than sitting in plaintext.
  • Identity verification is stored as a one-way peppered hash, never as a raw government identifier.
  • Card and bank details never reach our servers; they go directly to a regulated payment provider.
  • File uploads use short-lived signed URLs, so files are neither publicly listable nor permanently linkable.
  • Administrative access is limited to a small allow-list of people, requires a verified email address and multi-factor authentication, and every administrative action is written to an append-only audit log.
  • Passwords, tokens, secrets, authorisation headers and cookies are stripped from logs before anything is written.
  • Requests are rate-limited, and the sign-up and access-request endpoints carry a tighter budget because they are on the public internet.

What we cannot promise

No system is perfectly secure. During the pre-launch period the platform is a tester environment with no backup guarantee and no uptime commitment — do not put anything in it that you could not afford to lose. If a breach occurs that is likely to result in a risk to you, we will notify you and the relevant regulators within the time the law requires.

18

Children

The platform is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we ask for a positive confirmation of age — recorded with its date and time — before you can join a campaign.

If you believe someone under 18 has given us personal data, write to privacy@collabkrew.com. We will close the account and delete the data. Under the DPDP Act we do not track children or direct advertising at them, and we could not — we run no advertising technology at all.

19

What is public

Some of what you give us is meant to be seen. It helps to be explicit about which parts:

Your creator storefront
Display name, headline, bio, niches, languages, country, packages and prices — but only once you publish it. Until then it is private, and unpublishing takes it out of discovery.
Your Trust Score credential
A short public page showing your score, so a brand can check it without signing in. It exists only for creators who have published a storefront.
Your submitted posts
Public by their nature — they live on YouTube, TikTok or Instagram under your own handle, and a campaign requires them to stay public to be measured.

Public pages can be indexed by search engines and cached by them. We cannot remove a copy someone else has made. Everything else — your legal name, address, identity verification, tax details, payout methods, wallet, messages and contracts — is private to you and to the specific counterparty a deal is with.

20

Changes to this policy, and how to reach us

Changes

We publish each version of this policy as a numbered record with its own date, and every previous version stays available so you can see what changed. If we make a material change we will tell you before it takes effect, and if you have an account you will be asked to acknowledge the new version the next time you sign in.

Contact

Privacy and data rights
privacy@collabkrew.com
Data Protection Officer
We have not appointed one. Our processing does not currently meet the thresholds that require a DPO under the GDPR or a Significant Data Fiduciary’s obligations under the DPDP Act, and we would rather say so than name a role nobody holds. Every question a DPO would answer goes to privacy@collabkrew.com, and a person reads it. If we appoint one, this row will name them.
Grievance Officer (India)
Grievances under the Information Technology Rules and the DPDP Act go to grievance@collabkrew.com. We acknowledge within 24 hours and aim to resolve within 15 days. The mailbox is monitored by the people operating CollabKrew; once a legal entity is formed, this row will name the individual designated to the role.
EU / UK representative
None appointed. We do not target the EEA or the UK, and we have no establishment there. If that changes we will appoint an Article 27 representative and name them here before we do.
General support
hello@collabkrew.com
Post
We have no postal address to publish yet, and an invented one would be worse than none. Email reaches us; a postal address will appear here with the registered office once the entity is formed.

If you are not satisfied

Come to us first — we would rather fix it than have you escalate. If we do not resolve it, you can complain to the Data Protection Board of India, to your supervisory authority in the EEA, to the Information Commissioner’s Office in the UK, or to the California Privacy Protection Agency, as applicable to you.

collabkrew

HomeTermsPrivacyhello@collabkrew.com
© 2026 CollabKrew. All rights reserved.Creators × Brands — one krew.