Privacy Policy

Privacy Policy

Last updated

The Founders Inc.
In effect from

U.S. State Privacy Rights (see Annex A) · European, Swiss, and UK Privacy Rights (see Annex B) · Canada Privacy Rights (see Annex C)

1. Scope and Controller

The Founders Inc. ("The Founders," "we," "us," or "our") operates Arumy (the "Service"), a creator marketing platform through which creators join brand campaigns, publish content on their own channels, and receive rewards based on the sales that content generates.

This Privacy Policy applies to personal information that we process as a controller — meaning we determine the purposes and means of the processing — in connection with (i) the Arumy creator web application, (ii) the parts of our internal systems that hold creator records, and (iii) your other communications and dealings with us in relation to the Service.

For purposes of this Privacy Policy, "personal information" means any information that, alone or in combination with other information, identifies or can be linked to a particular individual, and that is subject to a data protection law. It does not include anonymized or de-identified data that is not attributable to a particular individual and not otherwise subject to a data protection law.

Our address and contact details are in Section 16.

What this policy does not cover. The social platforms on which you publish (Instagram, TikTok, YouTube) and the storefronts through which your audience purchases are governed by their own privacy policies, not by this one.

2. Purposes of Processing

We process personal information in order to operate the Service, to perform our contract with you, to comply with our legal obligations, and to protect our legitimate interests. We process it for the following purposes, and for no others.

PurposeDescription
Account creation and sign-in Creating your account, authenticating you through your Google account, and maintaining your session.
Account review and approval Reviewing new accounts and verifying that a connected channel belongs to you, in order to prevent impersonation.
Campaign matching and invitation Identifying creators whose profile and channels fit a campaign brief, and inviting them.
Campaign operation Running the campaigns you join, issuing tracking links or codes, and receiving the content you register.
Product sample fulfillment Sending you a campaign's product sample at the address you provide.
Reward calculation and payment Calculating rewards from aggregate campaign figures, paying them, and keeping the accounting record.
Customer support Responding to your inquiries, requests, and complaints.
Security and fraud prevention Protecting accounts, detecting and preventing unauthorized access and abuse, and investigating incidents.
Dispute resolution Establishing, exercising, or defending legal claims, including disputes about a reward.
Legal compliance Complying with tax, accounting, and other legal obligations, and with lawful requests from authorities.
Business transfer Transferring records where our business, or part of it, is sold or reorganized.

We do not use your personal information for advertising targeting, we do not sell it, and we do not use it to make automated decisions producing legal or similarly significant effects. Whether you are invited to a campaign is a decision made by our team.

3. Categories of Personal Information We Process

We collect the minimum information necessary for the purposes set out in Section 2. If you do not provide it, we may not be able to provide the Service or complete a transaction you requested.

CategoryItemsPurpose
Google account identity Google account identifier, email address, display name, a copy of your profile picture, account language Sign-in without a password; identifying you
Sign-in records Sign-in time, sign-in count, the IP address of your most recent and previous sign-in, the first part of your browser user-agent string, device language Account security; answering "did someone else sign in as me?"
Creator profile Name, email address, country, languages you create in, ambassador status, and the notes our team keeps while working with you Campaign matching and campaign operation
Shipping address Recipient name, telephone number, postal address Sending you a campaign's product sample
Verified channels Platform, channel or account identifier, handle, display name, profile URL, a copy of the avatar, verification time Proving a channel is yours, so rewards go to the right person
Campaign records Campaign applications and their status, participation records, the tracking link or code issued to you, and the content you register to a campaign Running campaigns; calculating rewards; resolving disputes
Reward payment details Account holder name, bank or remittance details for the country you are paid in Paying a reward you earned, and the accounting record of it
Support communications The content of your inquiries and our replies, and the contact details you use to reach us Responding to your inquiries, requests, and complaints; keeping a record of what was agreed
Session cookie A signed session identifier (see Section 12) Keeping you signed in
Technical records Server logs, which may contain IP addresses, online identifiers, and other information generated by your use of the Service Operating and securing the Service

Reward payment details. We ask for these only when there is a reward to pay, we use them for nothing but paying you and keeping the accounting record, and you give them to us directly. If we are ever required to collect more than the above before paying you — a tax form, for example — we will tell you at the point we ask.

4. Sources of Information

  • Direct collection. Information you give us yourself — your shipping address, the content you register to a campaign, and anything you tell us in support inquiries.
  • Google, when you sign in. For sign-in we ask Google only for the email and profile scopes, and we request online access only. We never receive or store a Google refresh token, and the sign-in grant gives us no ability to call Google on your behalf or read anything else in your Google account after you have signed in. Your account is created the first time you sign in; there is no separate sign-up form. Connecting a YouTube channel is a separate authorization that you initiate, and is described below.
  • The platform you choose to connect. When you connect an Instagram, TikTok, or YouTube channel, we send you to that platform to sign in, and the platform tells us who you are. We read that answer once and store only what identifies the channel.
  • Automated collection. Sign-in records and server logs generated by your use of the Service.
  • Our own records. Parts of your profile may have been created by our team before you ever signed in — for example if we had already worked with you.

Channel verification is read-only, and we do not store the access token. The token is used for a single identity read and then discarded, so we cannot read your channel again afterwards. We cannot post, comment, message, delete, or change anything on your channel, and we do not ask for permission to.

The authorization you grant our app at the platform does persist at the platform itself, even though we hold no token from it — which is why you can revoke it there at any time, and why Instagram is able to notify us when you do. Revoking it has the effects described in Section 5 and Section 11.

PlatformPermission we requestWhat we read
Instagram instagram_business_basic Account ID, username, name, profile picture
TikTok user.info.basic, user.info.profile Username, display name, avatar, profile link
YouTube youtube.readonly Channel ID, channel title, channel thumbnail

Google user data — Limited Use. Arumy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account information only to sign you in and identify you, and YouTube channel information only to confirm that a channel you connect is yours. We do not transfer it to third parties except as needed to provide the Service, for security, or to comply with law; we do not use it for advertising; and we do not allow humans to read it except with your permission, for security purposes, to comply with law, or where the data has been aggregated and de-identified. Our use of YouTube data is also subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke our access at any time at myaccount.google.com/permissions.

5. Retention and Destruction

We retain personal information only for as long as necessary for the purposes for which it was collected, and destroy it without delay once that purpose has been achieved — except where a law requires or permits us to retain it, in which case we keep it only for that purpose and use it for nothing else.

RecordRetention period
Account, creator profile, shipping addresses, verified channels While your account is active; deleted or anonymized within 30 days of account closure, except for the records listed below (see Deleting your data)
Channel verification record and stored avatar copy Deleted as soon as we learn you have revoked our access — either because the platform tells us, or because you do (see below). We delete the stored avatar file itself, not only our reference to it
Support communications 3 years from the date the inquiry is closed — our own policy, so that we can resolve a dispute that surfaces later
Sign-in records For the life of the account
Access logs to the systems that hold personal information 1 year
Other technical records (server logs) 1 year
Session cookie 30 days from sign-in, or until you sign out
Campaign participation, settlement, and reward payment records 5 years, counted from the end of the tax year in which the reward was paid, so that we can meet the tax and accounting record-keeping rules that apply to us. Closing your account does not shorten this

What stays when you disconnect a channel. Where the platform tells us you have revoked our access — or, for the platforms that send no such notice, where you tell us yourself — we remove the record that you verified the channel and the avatar copy we stored. Revoking does not remove the channel record itself, the public handle, or the campaign records a reward was calculated against. Those are not held on the basis of the permission you revoked: the handle is information you publish publicly, and the campaign records are the basis on which a reward was worked out and paid.

How this differs by platform. Instagram notifies us when you revoke our access, so we act on it without you asking us twice. TikTok and YouTube provide no such notification, so for those platforms you need to tell us — email privacy@thefounders.kr and we will delete the same records. Deleting your data sets out the full procedure.

Two further things we want to be explicit about. First, we do not delete campaign participation records, because a reward was calculated and paid against them and both sides need to be able to check that later; a withdrawn or rejected application is recorded as a status, not removed. Second, the identifiers we issue for creators, channels, and participations are retired rather than reused — a deleted record's identifier is never given to somebody else.

Method of destruction. Personal information stored in electronic form is deleted using a method that makes it unrecoverable; personal information recorded on paper, if any, is shredded or incinerated.

6. Provision of Personal Information to Third Parties

A third party here means a recipient who uses your information for its own purposes rather than on our instructions. There are only two.

RecipientContactInformation providedPurpose Retention by recipient
Professional advisers, auditors, and authorities aws.amazon.com/privacy Only what the particular matter or lawful demand requires Complying with law; establishing, exercising, or defending legal claims For as long as the matter, or the law, requires
A buyer or successor googlekrsupport@google.com The records that form part of the business being transferred Sale or reorganization of our business or part of it Under that party's own privacy policy, which we will tell you about before the transfer takes effect

Joining a campaign does not send your information to an outside company. We run the campaigns on the Service for our own brands, so there is no separate brand for us to hand your details to.

Beyond the two recipients above and the service providers in Section 7, who act on our instructions rather than their own, we do not disclose your personal information to anyone.

If our business or part of it is sold or reorganized, we will tell you before your personal information becomes subject to a different privacy policy.

7. Entrustment of Processing (Service Providers)

We entrust the processing of personal information to the following service providers. They act only on our instructions and under a data processing agreement that requires them to protect it.

Service providerEntrusted workPersonal information involved Held by them for
Amazon Web Services, Inc. Hosting, database, and file storage Everything we hold about you, as set out in Section 3 As long as we hold it — the periods in Section 5
Google LLC Sign-in (OAuth) Your Google account identity As long as your account exists

We handle campaigns, samples, and rewards ourselves. We run the campaigns on the Service for our own brands, so joining one does not hand your information to an outside company. We pay rewards ourselves. We do not currently entrust delivery to a carrier, and no product sample has been dispatched through one to date; when we begin using a carrier, we will name it here, and in Section 8, before your address is passed to it.

Our internal team chat. We send operational notifications to a team chat tool, which like the providers above is based outside Korea. Those messages carry record identifiers only — never your name, email address, handle, or address — so we have not listed it as a recipient of your personal information. Anyone reading them would need our own systems to work out who a record belongs to.

When we change a service provider or the work we entrust to it, we will update this Policy.

8. Cross-Border Transfer of Personal Information

The Arumy application, its database, and its file storage run on Amazon Web Services in Oregon, United States, and that is where the records described in this Policy are held. Our operations team, which supports campaigns and can view your profile in our internal admin tool, works from our offices in Seoul, Republic of Korea.

Your personal information may therefore be accessed from, and stored in, countries other than the one you live in.

Transfers for hosting and sign-in. We transfer personal information out of the Republic of Korea to our hosting and sign-in providers, listed in Section 7, because operating and storing your records outside Korea is necessary to perform our contract with you. We do so on the basis of Article 28-8(1)3(a) of the Personal Information Protection Act, by disclosing the following here.

Information reaches Amazon Web Services continuously from the moment we collect it; your Google account identity is exchanged with Google each time you sign in. Both are transmitted over an encrypted network connection.

RecipientCountryItems transferredTheir purpose How long they keep itContact
Amazon Web Services, Inc. United States (Oregon) Everything we hold about you, as set out in Section 3 Hosting, database, and file storage As long as we hold it — the periods in Section 5 aws.amazon.com/privacy
Google LLC United States Your Google account identity Signing you in As long as your account exists googlekrsupport@google.com

How to refuse, and what happens if you do. You may refuse by not signing up, or — if you already have an account — by closing it or emailing privacy@thefounders.kr. If you refuse, we cannot provide the Service, because it runs entirely on infrastructure located outside the Republic of Korea.

Transfers to the two third parties in Section 6. Where you are in the Republic of Korea and a professional adviser, auditor, or authority, or a buyer or successor, is outside it, we disclose only where the law requires or permits it, and — in the case of a business transfer — we tell you before your personal information becomes subject to a different privacy policy. We make no other cross-border provision of your personal information to a third party, so there is nothing else here for you to consent to or refuse.

If you are in the EEA, Switzerland, or the UK. The Republic of Korea, where we are established, benefits from adequacy decisions adopted by the European Commission and by the United Kingdom, so your personal data can reach us without any additional transfer safeguard. Your records are then held on Amazon Web Services in the United States; for that onward transfer, and for transfers from Switzerland, we rely on the European Commission's standard contractual clauses with the UK and Swiss addenda where they apply, which form part of our agreements with our service providers. If you would like a copy of the safeguards that apply to a particular transfer, contact us in accordance with Section 16.

9. Sensitive Information

We do not collect or process sensitive information — including information revealing race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data processed for the purpose of uniquely identifying an individual, health data, sex life or sexual orientation, or criminal records — through the Service, and we do not ask you for it.

10. Pseudonymized Information

We do not process pseudonymized information for statistical, scientific research, or public-interest archiving purposes.

Where we use campaign figures to calculate rewards, we use aggregate totals for a campaign and a tracking link — not personal information about you or about anyone who purchased something. We do not receive, and do not want, the identity of any shopper.

11. Your Rights and How to Exercise Them

You, or your legal representative, may ask us to:

  • Access — give you a copy of the personal information we hold about you, in a portable form;
  • Correct — correct anything that is inaccurate or out of date;
  • Delete — delete your account and the information we are not required to keep;
  • Restrict or suspend processing — stop or restrict a particular use, for example by disconnecting a channel you verified or removing part of your profile;
  • Withdraw consent — withdraw a consent you gave, at any time, without affecting what we did while it was in force;
  • Object — object to a use we base on our legitimate interests.

You can manage your own shipping addresses in your profile, and can disconnect a channel and revoke our access at the platform yourself without contacting us.

How to submit a request. Email privacy@thefounders.kr from the address on your account, or contact us as set out in Section 16.

Verification. We will ask you to confirm your identity before we act — usually by asking you to sign in — because acting on a request from the wrong person is the one mistake we cannot undo. We may require written documentation that a third party is authorized to act as your agent.

Response time. We respond as quickly as we can, and in any event within the shorter of 45 days and any statutory deadline that applies to you. The deadlines that apply in particular jurisdictions are set out in Annexes A, B, and C, and apply where they are shorter than 45 days. If you are in the Republic of Korea, we work to a 10-day clock: we will let you access your personal information within 10 days of your request, and will tell you the outcome of a correction, deletion, or suspension-of-processing request within 10 days, as the Personal Information Protection Act and its Enforcement Decree require. If we decline, we will tell you why and how to object, within the same 10 days. Where we need longer than the applicable period and the law permits an extension, we will tell you before the original period expires, and why.

Limits. None of these rights is absolute. We may decline a request to the extent a law requires or permits us to retain the information, or where fulfilling it would prejudice the rights of another person.

Deleting your account. Deleting your data sets out exactly what a deletion request removes, what we keep and why, and how long it takes, including how the process differs between Instagram, TikTok, and YouTube.

12. Cookies and Automated Collection Devices

We set one cookie: a signed session cookie that keeps you signed in. It expires 30 days after you sign in, and signing out discards it.

There are no analytics cookies, no advertising cookies, and no third-party trackers on the creator application — we do not run any analytics or advertising script on it.

How to refuse. You can refuse or delete cookies through your browser settings (Chrome: Settings → Privacy and security → Cookies and other site data; Safari: Settings → Privacy). If you refuse the session cookie, you will not be able to stay signed in, and the Service will not work.

13. Targeted Advertising and Behavioral Data

We do not collect, use, or provide behavioral information (information about your online activities collected over time and across websites or services) for targeted or interest-based advertising, and we do not run advertising or analytics scripts on the Service.

14. Security Measures

We take the following technical and administrative measures to protect your personal information.

Authentication.

  • We store no passwords. Sign-in is delegated to Google, so there is no password of ours to leak.
  • We store no platform access tokens for your connected channels.

Encryption.

  • All traffic between you and the Service is encrypted in transit.
  • The account number you give us for a reward payout is encrypted when stored, using a secure algorithm.

Access control.

  • Our internal admin tool runs on a separate, non-public host and is reachable only by staff signed in with a company Google Workspace account that belongs to the authorized access group. Removing someone from that group revokes their access.
  • Staff accounts that can reach the admin tool require multi-factor authentication.
  • Account numbers are masked where they appear in the admin tool.

No system is perfectly secure. If a breach affects you, we will notify you and the relevant authority as required by law.

15. Children

The Service is intended for creators aged 18 or over. It is not directed at, nor intended for use by, children, and we do not knowingly collect personal information from anyone under 18.

If you believe that a person under 18 has an account, tell us at privacy@thefounders.kr and we will delete it.

16. Privacy Officer and Contact

If you have questions about this Privacy Policy or our handling of your personal information, would like more information, or would like to exercise a privacy right, please contact us.

ChannelContact
Privacy questions and rights requests privacy@thefounders.kr
Address The Founders Inc., 8F, 10F, Parnas Tower, 521, Teheran-ro, Gangnam-gu, Seoul, Republic of Korea
PositionNameE-mail Address
CPO privacy@thefounders.kr

17. Remedies for Infringement of Rights

If you believe we have handled your personal information improperly, tell us first and we will try to fix it. You may also contact the authority where you live.

  • United States — your state Attorney General (see Annex A for the list).
  • European Economic Area / Switzerland / United Kingdom — your data protection supervisory authority (see Annex B).
  • Canada — the Office of the Privacy Commissioner of Canada, priv.gc.ca.
  • Republic of Korea
    • Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr)
    • Personal Information Infringement Report Center (118, privacy.kisa.or.kr)
    • Supreme Prosecutors' Office Cybercrime Investigation Division (1301, spo.go.kr)
    • National Police Agency Cyber Bureau (182, ecrm.police.go.kr)

We will not discriminate against you for exercising a privacy right or filing a complaint.

18. Changes to the Policy

We will update this Privacy Policy when what we do changes, and will change the "Last Updated" and "In effect from" dates at the top. If you would like to see a previous version, ask us in accordance with Section 16 and we will send it to you.

If a change materially affects your rights — a new purpose, a new category of recipient, or a longer retention period — we will notify you in the Service or by email at least 7 days before it takes effect, and where the law requires consent we will ask for it rather than assume it.

Annex A — U.S. State Privacy Rights

A-1. California Privacy Rights

Pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA"), California residents are entitled to the following privacy rights.

  • Right to Know (Specific Pieces of Personal Information). You have the right to know the specific pieces of your personal information that we have collected about you.
  • Right to Know (Categories of Personal Information). You have the right to know (i) the categories of personal information we have collected from you — Section 3; (ii) the categories of sources from which it was collected — Section 4; (iii) the categories of your personal information we have sold or disclosed for a business purpose — Sections 6 and 7; (iv) the categories of third parties to whom it was sold or disclosed for a business purpose — Sections 6 and 7; and (v) the business or commercial purpose for collecting or selling it — Section 2.
  • Right to Delete. You have the right to request that we delete the personal information we have collected and retain about you.
  • Right to Correct. You have the right to request that we correct inaccurate personal information about you.
  • Right to Limit Use of Sensitive Personal Information. You have the right to limit our use and disclosure of sensitive personal information.
  • Nondiscrimination. You have the right not to be subject to discrimination for asserting your rights under the CCPA.

Submit a Privacy Request. To submit a privacy request, you (or your authorized agent) may contact us in accordance with Section 16. An authorized agent must be a natural person, or a business entity registered with the California Secretary of State to conduct business in California.

Privacy Request Verification Process. If you (or your authorized agent) make a request, we will ascertain your identity to the degree of certainty required or permitted by law before addressing it. We will, to the extent required or permitted by law, require you to verify your request via email and match at least two pieces of personal information with data we have previously collected from you before granting access to, deleting, or correcting specific pieces or categories of personal information. We may require written documentation demonstrating that a third party is authorized to act as your agent, unless you have provided that agent with power of attorney pursuant to California Probate Code §§ 4000 to 4465.

Response time. We will confirm receipt of your request within 10 business days and tell you how we intend to handle it. We will then respond within 45 days of receiving a verifiable request. If we need more time, we will notify you of the extension and the reason for it within that 45-day period; the maximum response time is 90 days.

Opt-Out Rights / Do Not Sell My Personal Information. California residents have the right to opt out of the "sale" of their personal information. We do not sell your personal information to third parties for monetary or other valuable consideration, and therefore we do not provide an opt-out request process for the sale of personal information (because we do not undertake such activities).

Opt-Out Rights / Do Not Share My Personal Information. California residents have the right to opt out of the "sharing" of their personal information for cross-context behavioral advertising. We do not share your personal information for cross-context behavioral advertising, we run no analytics or advertising script on the Service, and therefore we do not provide an opt-out request process (because we do not undertake such activities). This is why you will not find a "Do Not Sell or Share My Personal Information" control on the Service.

Opt-Out Rights / Automated Decisionmaking Technology ("ADMT"). California residents have the right to opt out of ADMT used to make significant decisions concerning consumers. We do not use ADMT to make significant decisions concerning consumers, and therefore we do not provide an opt-out request process (because we do not undertake such activities).

Limit Use of Sensitive Personal Information. We do not collect sensitive personal information as the CCPA defines it. The bank or remittance details you give us so that we can pay a reward are not accompanied by any security code, password, or credential that would allow access to the account, and we use them only to pay you and to keep the accounting record. We therefore do not provide a process to limit the use or disclosure of sensitive personal information.

Children. The Service is not directed at, and may not be used by, anyone under 18. We do not knowingly sell or share the personal information of minors under 16 years of age.

Notice of financial incentive. Rewards paid to creators are consideration for services performed under a campaign, not a financial incentive offered in exchange for personal information.

For more information about the CCPA, see oag.ca.gov/privacy/ccpa.

A-2. Other U.S. States (General)

Pursuant to certain other U.S. state privacy laws, you may have the following privacy rights:

  • To confirm whether we process your personal information and to access it;
  • To correct inaccuracies in your personal information;
  • To delete personal information you provided or that we obtained about you;
  • To obtain a copy of your personal information in a portable and readily usable format;
  • To obtain a list of the specific third parties, or the categories of third parties, to which we have disclosed your personal information;
  • To opt out of the sale of personal information, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects;
  • Not to be discriminated against for exercising any of these rights.

Submit a Privacy Request. Contact us in accordance with Section 16.

Response time. We will respond within 45 days of receiving a request. Where the law permits, we may extend that period once by a further 45 days, in which case we will notify you of the extension and the reason for it within the original 45-day period.

Privacy Requests Appeals Process. If you would like to appeal a decision we have made regarding your privacy request, email us in accordance with Section 16 with the subject line "ATTN: Privacy Appeals," describing the nature of your request and the reason for requesting an appellate review. We will respond to an appeal within 45 days of receipt, and will tell you in writing the reasons for our decision.

Opt-Out Rights. We do not sell personal information, do not use it for targeted advertising, and do not engage in profiling in furtherance of decisions producing legal or similarly significant effects. We therefore do not provide opt-out request processes for these activities (because we do not undertake them). Nevada residents may nonetheless submit a request directing us not to sell personal information we maintain about them; if you would like to exercise this right, contact us in accordance with Section 16.

Global Privacy Control. Some browsers and browser extensions send a Global Privacy Control ("GPC") signal, which is a request to opt out of the sale or sharing of personal information. Where we detect a GPC signal, we treat it as a valid opt-out request and make reasonable efforts to honor it as applicable law requires. In practice there is nothing for it to switch off, because we neither sell nor share your personal information.

Do-Not-Track Signals. Separately, some browsers transmit "do-not-track" signals. These are not standardized, and browsers differ in how they implement and activate them, so unless the law requires otherwise we do not take action in response to them. A do-not-track signal is not the same as a GPC signal.

Complaints. You may lodge a complaint with your state Attorney General: Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Virginia.

Annex B — European, Swiss, and UK Privacy Rights

If you are in the European Economic Area, Switzerland, or the United Kingdom, you are entitled to the following privacy rights. Where you are in the United Kingdom, the same rights reach you through the UK GDPR and the Data Protection Act 2018.

  • Access Rights. To obtain confirmation of whether we process your personal data and a copy of it.
  • Rectification. To have inaccurate or incomplete personal data corrected.
  • Erasure. To have your personal data erased where it is no longer necessary, where you withdraw consent and there is no other legal basis, or where it has been unlawfully processed.
  • Restriction of Processing. To restrict processing in defined circumstances, for example while the accuracy of the data is being verified.
  • Data Portability. To receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to Object. To object to processing based on our legitimate interests.
  • Automated Decision Making. Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
  • Withdrawing Consent. To withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

Legal Basis for Processing.

PurposePersonal dataLegal basis
Creating your account and signing you in Google account identity, session Contractual Obligations
Reviewing and approving new accounts Creator profile, verified channels Contractual Obligations; Legitimate interest — preventing impersonation
Matching you to campaigns and inviting you Creator profile, verified channels Legitimate interest — operating a creator marketing platform
Running a campaign you joined and getting its sample to you Creator profile, shipping address Contractual Obligations
Calculating what you earned Campaign records, registered content Contractual Obligations
Paying rewards and keeping accounting records Identity, campaign records, payment details Contractual Obligations; Legitimate interest — keeping accurate accounting records and meeting the tax and accounting rules that apply to us
Responding to your support inquiries Support communications, identity Contractual Obligations; Legitimate interest — running a service people can get help with
Security, fraud prevention, dispute resolution Sign-in records, campaign history Legitimate interest — keeping the Service and the people who use it safe
Complying with legal obligations and responding to lawful requests Whatever the obligation or request covers Legal Compliance where an EU or Member State law applies; otherwise Legitimate interest — meeting the legal obligations that bind us
Transferring records if our business is sold or reorganized Whatever forms part of the business transferred Legitimate interest — reorganizing or disposing of a business

Submit a Privacy Request. Contact us in accordance with Section 16.

Response time. We will respond without undue delay and in any event within one month of receipt. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests; we will inform you of any such extension, and the reasons for it, within one month of receipt.

International transfers. See Section 8.

Complaints. You have the right to lodge a complaint with your supervisory authority — the EDPB member list for the EEA, the Swiss FDPIC, or the UK ICO. We would, however, appreciate the opportunity to address your concerns first, so please feel free to contact us regarding any complaint you may have. We will not discriminate against individuals for exercising their privacy rights or filing a complaint.

Annex C — Canada Privacy Rights

If you are located in Canada, we process your personal information in accordance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and other applicable Canadian provincial privacy laws. You have the right to access the personal information we hold about you and to request its correction. We may charge you a fee to access your personal information, provided we advise you of any such fee in advance. There are limits on the right of access — for example, where the information contains references to other individuals or is subject to legal privilege. You may also ask to be removed from our electronic mailing lists at any time. To exercise any of these rights, contact us in accordance with Section 16.

Response time. We will respond no later than 30 days after receiving your request. Where PIPEDA permits, we may extend that period by a further 30 days, in which case we will notify you of the extension and the reason for it within the original 30 days.

You may also file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.