Skip to content

Last updated 24 September 2026

Privacy

1 Who is responsible for your information

CreatorCall is operated by TERCZA Limited, registered in England and Wales with company number 16716012 and registered office at 3 Cumming Street, London, England, N1 9HW. We are the controller where we decide why and how personal information is used to operate CreatorCall, including our accounts, creator discovery and outreach, billing, service security and product improvement.

Contact support@creatorcall.io for questions, rights requests or a data-protection complaint. You can also write to the registered office, marked “CreatorCall privacy”.

This notice applies to website visitors; brand and agency users; creators and their representatives, including people without a CreatorCall account; and people whose public social-media information is processed for campaign analysis. It also covers business contacts, support correspondents and people identified in uploaded campaign material.

Where a customer determines the purpose of processing and we act solely on its documented instructions, the customer is the controller and we act as its processor under a data processing agreement. The customer's own notice explains its use. We also have independent purposes described here. A brand receiving a creator shortlist or exporting campaign records is responsible for its own subsequent use. Stripe, social networks, identity providers and some signature services may act as separate controllers for parts of their services. Legal roles depend on the actual processing, not simply who owns an account.

2 Information we receive and where it comes from

Account and business information. We receive your name, business name, email address, account identifiers, profile and notification settings, subscription details and support correspondence from you or an authorised account administrator. If you use Google or Microsoft sign-in, we receive the account information authorised through that provider. Our authentication service handles credentials and session information.

Campaign information. Brands and agencies provide campaign names, briefs, product information, budgets, locations, channels, creator requirements, deliverables, usage rights, instructions, uploaded files, cover images and campaign history. These can identify employees, client contacts, creators and other people mentioned or depicted in the material.

Creator discovery and qualification information. We obtain professional profiles, handles, names, contact details, biographies, niches, locations, channel information, follower and engagement metrics, thumbnails and examples of work from public social networks, collection services and third-party creator-data providers.These can contain information about creators who have never used CreatorCall or contacted us. We may also receive creator details from a brand, agency, representative, prior business correspondence or the creator. The source and available information vary by platform and campaign. We do not treat inclusion in a purchased list as consent to our marketing or permission for every onward disclosure. Contact support@creatorcall.io for information about the source of your personal data.

Our team stores source spreadsheets locally on its computers. Information imported into CreatorCall is also processed through the platform and relevant providers described in section 7. Local storage of a source file does not mean all subsequent processing stays on that computer or in the UK. Local copies, exports and related backups remain subject to applicable retention limits and rights requests; retaining a separate spreadsheet is not a reason to ignore a correction, objection or valid erasure request.

Creator replies and evidence. A creator or representative may send interest or refusal, rates, availability, commission preferences, portfolio material, analytics screenshots and other qualification evidence. We process the correspondence, delivery metadata, attachments and, where needed to operate the email service, the underlying email message. We record objections so that we do not contact people contrary to their preferences.

Campaign communications and work. We process messages between brands and creators, attachments, contracts, legal names and addresses, signature and envelope records, invoices, submitted draft content, links, review comments, decisions, file hashes, previews and approval history. Creators may participate by email and secure links without creating an account.

Payments. Stripe processes subscription and service-credit card payments, creator bank payments, connected-account onboarding and payouts. Creator payments use Stripe's hosted Checkout with Pay by Bank for GBP and EUR and ACH Direct Debit for USD. We receive payment, customer and connected-account references, amounts, currencies, service fees, status, relevant billing or verification information, and refund or dispute records. Card entry, bank-payment authorisation and payout onboarding are handled through Stripe. We do not ask you to send complete card details or bank credentials in chat. Stripe's collection process does not mean that we receive no financial metadata.

Campaign performance and public engagement. We may obtain public post URLs, author handles, captions or excerpts, publication dates, thumbnails, views and other metrics, baseline posts, public comments and replies, and limited information from sampled public audience profiles. Where returned by a provider, full captions or transcripts may be processed transiently for campaign checks; stored excerpts and derived findings have separate retention. We derive campaign measurements and estimates such as comment sentiment, topics, intent, repeated engagement and audience summaries. Per-person audience analysis can include estimated country or region, language and interests, explicit-pronoun gender information, and profile or activity quality signals. These are estimates and may be wrong. This can involve information about commenters who have never visited CreatorCall. Brands or creators may also provide private insight screenshots, exports or typed metrics that they are authorised to share.

AI interactions. We process your Juno questions, relevant previous turns, responses, saved conversation titles and status, generated draft references, and information retrieved from your account to answer the question. We also process technical records of AI use, model routing, cost, errors and provenance. Account context can contain creator names, briefs, correspondence, contract status and campaign metrics.

Website and service use. Necessary service operations can process network and device information, session identifiers, authentication events, errors, timestamps, browser details, security signals and audit references. CreatorCall also uses PostHog for product usage analytics, but only after you allow it: we ask before anything runs, once in each browser you use without signing in and once per account when you are signed in, and nothing is collected until you choose. If you allow it, it processes page and interaction events, device and browser information and identifiers. Session replay is switched off in our configuration. Section 6 describes this in more detail. If you allow advertising measurement, a Google Ads tag on our public marketing pages processes the page address, ad-click details, device and browser information and cookies, as section 6 also explains. Identifiers and hashed identifiers can still be personal information.

Information required by law. If applicable tax or platform-reporting rules require it, we may request verified legal identity, address, date of birth, tax residence, tax identification or registration numbers and relevant transaction information. We will explain the purpose at collection. This is not a statement that every such field is already collected from every creator.

Please provide only information needed for the task and ensure you are entitled to share it. Do not upload passwords, unrestricted identity documents, special-category information or information about children unless an expressly supported and lawful process requires it. A brand's instruction cannot waive another person's privacy rights.

3 Why we use information and our legal grounds

We use the grounds below under UK GDPR and, where applicable, EU GDPR. We select and document the ground for each processing activity. Accepting our Terms is not consent to every use.

Providing the service to an individual customer. Where you personally enter a contract with us, we use information necessary to create and operate the account, fulfil orders, respond to your requests and administer payment on the basis of that contract or steps you request before it. We do not use this ground merely because your employer or client has a contract with us.

Serving a business through its representatives. We process work contact details, account permissions, campaign instructions and relevant correspondence in our legitimate interests and those of the customer in obtaining and supplying a functioning business service. We limit access and use to the work involved.

Creator sourcing and qualification. Subject to our documented necessity and balancing assessment, we use relevant professional information to identify suitable creators, verify campaign interest and evidence, prepare a shortlist and keep accurate sourcing records in our and customers' legitimate interests in arranging genuine commercial collaborations. This does not automatically authorise marketing by email. Where a creator requests a service or enters a contract with us, processing necessary for that request or contract may use the contract ground instead.

Outreach and marketing. We use consent where electronic marketing law requires it. Where lawful without consent, we rely on a documented legitimate interest in relevant business communication and provide an objection route. We do not assume that a public email address or the word “business” means a sole trader has agreed to marketing. A soft opt-in is used only where its actual conditions are met. Consent to CreatorCall product updates is separate from necessary campaign correspondence and from analytics choices.

Campaign operation and analysis. We use relevant messages, evidence, creator submissions, public post and engagement information and derived reports to support campaign decisions and measure results. For independently determined activity we rely on assessed legitimate interests in providing accurate campaign services, with minimisation and objection safeguards. Where we act only for a customer's instructions, the customer's lawful basis and our processor agreement govern that processing. Public availability alone is not our legal basis.

AI assistance. Providing a requested assistant or document feature uses the same relevant contract, business-service or instructed-processing ground as the underlying task. We limit the account context to information relevant to the request. Using an AI provider is not a separate lawful basis and does not permit unrelated reuse.

Billing, accounting and compliance. We process financial records to perform applicable contracts and meet specific accounting, tax, court, regulatory and other legal obligations. Fraud investigation and the establishment, exercise or defence of legal claims may also rely on legitimate interests, with limited access and retention.

Security and support. We use proportionate authentication, rate-limiting, diagnostic and audit information in our legitimate interests in preventing abuse, protecting accounts, fixing failures and handling complaints. Where a specific law requires processing, we use the legal-obligation ground. This does not justify recording every page interaction as necessary security monitoring.

Product analytics. Optional usage analytics is distinct from necessary security and authentication. Accepting the Terms or reading this notice is not analytics consent. We rely on your consent: product analytics runs only after you allow it, and you can withdraw that choice at any time from Privacy choices at the foot of the website and the app. Section 6 explains what runs and how to change your choice.

Advertising measurement. We rely on your consent here too, and it is a separate choice from product analytics: the Google Ads tag runs only after you allow advertising measurement, and you can withdraw that choice at any time from Privacy choices at the foot of the website and the app. Section 6 explains what runs.

When using legitimate interests, we assess the purpose, whether the information is necessary and the likely effect on the people concerned. You may object for reasons relating to your situation. Objections to direct marketing are honoured without requiring such reasons. We provide the applicable explanation without disclosing another person's confidential information.

If required account or payment information is not provided, we may be unable to supply that feature. Declining optional promotional messages does not prevent ordinary use. We will identify mandatory legal information and the consequences of withholding it when it is requested.

4 Creators and public social media information

You can appear in our professional sourcing records without having a CreatorCall login. We use the sources described above to assess relevance, contact eligibility and suitability for a genuine campaign. Where required, we provide this notice within the applicable period after obtaining the information, and no later than the first communication or disclosure if earlier. We identify the available source information as required by law, including when responding to a request.

If you express interest and qualify, relevant information can be shared with the requesting brand or its authorised agency, including professional profile details, the quoted rate, evidence relevant to the brief and contact information. A response is not agreement to unlimited unrelated marketing or public publication of private evidence. The outreach should make clear which brand and campaign the disclosure concerns.

You can ask us not to contact you or not to include you in future sourcing by using the opt-out in an email or contacting support@creatorcall.io. We keep a minimal suppression record to honour the objection. We do not require a CreatorCall account to exercise these rights. A campaign-specific chat stop can affect that communication route; you can also request a broader objection to future outreach.

We may analyse public comments or sampled profiles to understand campaign engagement. Where a public commenter cannot practicably receive an individual notice, we assess and document whether the law permits an exception, provide accessible information and safeguards, and limit collection. We do not treat public posting as consent or claim that every commenter has received this notice individually.

We do not intentionally infer an individual's health, ethnicity, religion, political views, sexual orientation or other special-category characteristics for creator selection or audience targeting under this policy. Any new processing that does so requires its own lawful condition, impact assessment and prior notice. Ordinary photographs are not automatically biometric identification data, but may still identify people or reveal sensitive information.

5 AI providers and automated assessments

CreatorCall uses AI providers including Anthropic, Google and OpenAI for supported assistance, extraction, classification, drafting and matching functions. Which provider receives a request depends on the feature and approved configuration. OpenAI processes the campaign planner's interview turns and Juno's conversations on the free and Lite plans, with the account context those conversations retrieve, which includes the names, quoted rates and profile text of creators delivered to that account when a conversation reads a Creator Call; Anthropic processes the planner's final recommendation and draft, the Campaign Brief, Juno's conversations on the Growth and Scale plans, and, when OpenAI cannot serve a request, a single retry of that request. Google processes the reference-search embedding behind Juno's retrieval, for every plan, so a Juno conversation can send a limited reference-search query to Google even when another provider answers it. It is not accurate to say every question is always sent to every provider.

Requests to OpenAI are sent with storage switched off, so OpenAI does not keep them to continue a conversation; under its API terms it may retain request data for up to 30 days to monitor for abuse, and it does not use API data to train its models. Anthropic and Google process requests under their API terms.

Information sent can include the prompt, relevant conversation turns and the account or creator information needed for the task. Some tools process supplied evidence or public captions and comments. We minimise unnecessary identifiers and do not intentionally include credentials. Provider processing can involve service delivery, safety monitoring and limited retention under the relevant agreement.

We use automated processing to assist with relevance, requirement checks, fit scores, response classification and campaign metrics. The principal inputs include the campaign criteria, professional profile facts, creator responses and relevant supplied or public evidence. Outputs can affect whether a person is considered, contacted, excluded or shortlisted, as well as which results a customer sees. A fit score is an estimate against the campaign, not a universal assessment of a person's quality.

You can contact support@creatorcall.io to correct information, contest an assessment and request human intervention where applicable law requires it. We provide the explanations and safeguards required for the particular decision.

6 Cookies product analytics advertising measurement and session replay

We use authentication sessions and other necessary technology to sign you in, protect the service and provide features you request. Third-party login, payments, signing and embedded content can involve the relevant providers' own technology and notices when you use those features. Necessary service technology is separate from optional product analytics.

Product analytics. PostHog analytics starts only after you allow it, and never on the creator submission, unsubscribe and chat-stop pages. Your choice is stored in your browser as a necessary preference so that we do not ask on every page, and while you are signed in it is also saved with your account, as described below; the analytics itself uses memory-based persistence for its identifiers, so no analytics cookie or local-storage entry is written for tracking. Privacy choices, at the foot of the website and the app, lets you allow, decline or withdraw at any time. Withdrawing stops collection in that browser immediately, and in your other browsers the next time you open the app there, signed in. An email-notification setting is not an analytics choice.

Session replay is switched off in our PostHog configuration. If we ever offer it, we will explain the feature and its safeguards and ask for a separate choice before any recording starts.

Your choices are stored in the browser you made them in. While you are signed in, they are also saved with your account, so we ask once per account rather than once per browser: when you open the app (the signed-in part of CreatorCall) on another browser or device, your latest saved choices apply there too, including a withdrawal. A refusal given while signed out is carried to your account the next time you open the app signed in; an acceptance given while signed out is never carried to your account, because we cannot tell who gave it: it stays in that browser, unless your account holds a refusal that may be newer, in which case the refusal applies. On a browser shared with someone else, a choice made under their account never counts for yours: your saved choices apply, or we ask. We do not ask on the sign-in and sign-up pages; if your account has no choice yet, we ask once you are in the app. A browser where you have not signed in, a private window or cleared site data asks afresh, and nothing is collected until you answer. The saved choices are part of your account and are deleted with it.

Before this notice took effect, analytics collection ran from 11 September 2026 without a choice. Team activity can still be personal information, and this notice does not retrospectively supply consent or another lawful basis for that earlier collection.

Advertising measurement. We advertise CreatorCall on Google Search. If you allow advertising measurement, a Google Ads tag runs on our public marketing pages (home, pricing, how it works, about and the blog) so that Google Ads can tell us whether our ads bring people to CreatorCall. It is a separate choice: allowing product analytics does not allow it. It never runs before you answer, and it is switched off as you leave a marketing page for any other part of the site, such as sign-in, sign-up, account, creator or payment pages, which then reload without it. Google sets cookies for it, including _gcl_ cookies on our domain that last up to 90 days, as well as its own cookies on Google domains. Ad personalisation is switched off, and we do not use it to build advertising audiences. The page address Google receives keeps only the parameters an ad click adds, and the page you came from is reduced to its website. Google receives this information and uses it under its own privacy policy and the terms that govern Google Ads. You can decline it in the same bar, or withdraw it from Privacy choices at the foot of the website and the app. Withdrawing stops it and clears the cookies and stored keys it set on our domain, reloading the page if it was running.

Referral links. If you follow a referral or partner link, the code is in the address of the page you land on and is filled in on the sign-up form. We remember that code in a first-party cookie for 60 days ONLY if you allow analytics in the cookie bar; if you decline, or have not answered, the code lasts for that visit alone and nothing is stored. The cookie holds the code and nothing else, and it is cleared once an account has used it.

Referral fraud checks. When a code is attached to an account we store a one-way scrambled form of the network address it came from, and the same for the account whose code it is, so that we can see when somebody refers themselves. The address itself is never stored, the scrambled form cannot be turned back into it, and both are deleted after 90 days. We use them for nothing else.

You can contact support@creatorcall.io about analytics information, objections or other rights.

7 Who can receive information

We disclose information only for the relevant purpose and subject to an appropriate legal basis and safeguards.

  • Brands, agencies and creators: campaign information needed for outreach, qualification, shortlisting, contracting, communications, draft review and payment. Access is limited to the relevant campaign and authorised participants.
  • Supabase and Vercel: database, authentication, file storage, hosting, delivery and operational infrastructure.
  • Mailgun: outreach, transactional notifications and campaign email relay, including delivery and failure handling.
  • Stripe: subscription payments, creator payment processing, connected-account onboarding, payouts, fraud checks and relevant financial administration.
  • DocuSign: document delivery, e-signatures, signature evidence and envelope status. New signature sends use CreatorCall's platform account; earlier envelopes continue to synchronise under their existing arrangement.
  • PostHog and Sentry: product usage analytics and error monitoring respectively. PostHog runs only after you allow it and session replay is switched off, as explained in section 6. Error monitoring is separate from the permanent platform audit trail.
  • Google Ads: advertising measurement on our public marketing pages, only if you allow it, as explained in section 6.
  • Cloudflare: the Turnstile security check on the sign-in, sign-up and password-reset forms. Your browser loads the check from Cloudflare, which receives your network address and browser and device information to tell people apart from automated abuse. It is a necessary security measure, separate from optional analytics.
  • Anthropic, Google and OpenAI: the AI and retrieval functions described in section 5.
  • Apify and approved collection providers: relevant public social-media discovery and campaign-performance data. Provider datasets and actor access are subject to the contracts and controls we approve.
  • Google, Microsoft and social platforms: information necessary for sign-in or an integration you choose, and the information those platforms independently process when you use their services.
  • Authorised staff, advisers and authorities: support, security, accounting, insurance, legal claims and disclosures required by law. We check the basis and scope of requests.
  • A business successor: where necessary for a genuine transaction involving the service, subject to confidentiality, due diligence limits and continued data protection.

We do not operate a public resale catalogue of creator personal data. Supplying a purchased shortlist to the requesting brand is nevertheless a disclosure of creator information. We do not describe the service as never sharing personal data. Any classification of a transfer as a “sale” or “sharing” under a particular US state law must be assessed under that law rather than inferred from the label used here.

The names above are the services CreatorCall is built on. We give the applicable notice of a material change to this processing and, where required, obtain consent.

8 International processing

Our suppliers and campaign participants can be outside the United Kingdom or European Economic Area. Our personnel with access are in the UK and source spreadsheets are held locally. Supplier infrastructure, remote support, backups and recipients of shortlists are not all in the UK. PostHog analytics is sent to PostHog's EU cloud, although the provider's personnel or sub-processors outside the UK and EEA may have access under its data processing agreement. Google Ads measurement is processed by Google, which can include processing in the United States. The AI providers named in section 5 process requests in the United States: OpenAI's API and Anthropic's API run there, and Google's embedding service can. Contact support@creatorcall.io to request information about the transfer mechanism and safeguards that apply to a particular transfer.

A restricted international transfer must have the route required by applicable UK or EU data-protection law. Depending on the specific recipient and arrangement, that can be an applicable adequacy decision or contractual safeguards such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses or EU Standard Contractual Clauses, with the required assessment and supplementary measures. A data privacy framework is relevant only where the actual recipient, service and territorial coverage qualify.

9 How long information is currently kept

Automatic retention controls exist for the classes shown with a default period below. The day counts are the defaults stamped when a record is created. Different records start their clocks at different times, changing a setting does not shorten dates already stamped on existing records, and the scheduled purge runs in batches, so a default period is the point after which deletion is due rather than proof that every copy has already gone.

InformationCurrent retention
Raw public comments and associated identitiesDefault 90 days from the relevant stored record's creation.
Per-comment analysis labelsDefault 90 days from their own creation.
Sampled public audience profiles and per-person audience labelsDefault 90 days.
Cross-post commenter pseudonymsDefault 400 days. Pseudonymous identifiers can still be personal information.
Raw creator baseline post recordsDefault 90 days. Derived creator-linked baseline statistics have no automatic expiry.
Stored campaign post media and supplied first-party insight recordsDefault 400 days for the registered record classes.
Uploaded creator draft media bytesDefault 180 days from the file record's creation, shortened to 30 days after an approval or rejection where that date is earlier. This media-byte purge does not remove the separate evidence records described below; account erasure has its own rules.
Unreferenced staged contract uploadsEligible for a separate sweep after 24 hours. This does not expire a recorded or signed contract.
Full public caption or transcript materialProcessed transiently and not stored as a transcript. Stored caption excerpts and derived findings follow their separate records.
Ordinary account and campaign working recordsNo automatic expiry. Individual product actions can remove particular records, and closing or archiving a campaign is not erasure. On valid account erasure, working content is deleted or scrubbed while necessary financial and relationship records remain, as described below.
Creator sourcing corpus, profiles, profile media and local source spreadsheetsNo automatic expiry for the sourcing corpus or profile media, including local source files.
Raw outreach and inbound email, underlying messages and qualification attachmentsNo automatic expiry.
Creator chat bodies, attachments and thread historyNo automatic expiry. Message content is deleted on a valid erasure request, with the bare thread record kept.
Juno conversation bodies and historyNo automatic expiry. Archiving a conversation hides it without deleting its underlying history. Deleted on a valid erasure request.
Recorded generated, uploaded and signed contracts, versions and envelope evidenceNo automatic expiry while the account exists. On account erasure, only final contracts signed by both parties are kept for six years from their first successful erasure archive. Unsigned drafts, uploads and earlier versions are deleted. Separate financial evidence remains subject to its applicable retention requirements.
Monitored post references, caption excerpts, metric history and creator-linked derived statisticsNo automatic expiry. Removing a post from monitoring stops collection while preserving its record and metric history. Analytics collected for a brand's campaigns are deleted on that brand's account erasure; the separate shared creator corpus is described below.
Draft first frames, hashes, submitted links and review metadataNo routine automatic expiry; the media-byte purge alone does not erase these records. Account erasure removes first-frame and media files and scrubs submitted links and review comments, while retaining necessary record identifiers, hashes and decision history.
Platform audit trailAppend-only and permanent. Actor, subject and brand references can identify people; some actor identifiers can be email addresses. This is not an anonymous record merely because it uses identifiers.
Outreach suppression informationNo routine expiry, to avoid renewed contact contrary to an objection. A durable suppression record is distinct from retaining an entire creator profile or message history.
Subscription, credit and creator-payment recordsKept for the statutory retention period that applies to business transaction records. They survive account erasure.
Product analytics, session replay and provider error logsHeld by the provider under its retention settings; CreatorCall applies no expiry of its own. Session replay is switched off.
Advertising measurementThe _gcl_ cookies on our domain last up to 90 days, and withdrawing clears them. Google keeps what it receives under its own retention settings; CreatorCall applies no expiry of its own.
Brand Terms acceptance record (who accepted which version of the Terms, when, and on which sign-in path)Kept while the account exists and explicitly deleted on account erasure. The audit log keeps the event, with identifiers and the version only.
Creator payment-terms acceptance evidenceRetained with the creator and financial history. A brand's account erasure does not delete the creator's separate acceptance record.
Rights-request records, provider copies and backupsRights-request records are kept while needed to evidence the request and its handling. Provider copies and backups follow the provider's rotation, as described below. Our own database backups are taken daily and kept for about a week.

“No automatic expiry” describes the present implementation; it is not an entitlement to retain personal information forever. We minimise records and honour valid rights requests. Genuinely anonymised statistics are different from statistics still linked to a creator, account or post. An unresolved dispute or legal hold can justify retaining particular evidence for an appropriate period, not keeping every record indefinitely.

Account erasure. Requests go to support@creatorcall.io and are handled by our team. Once we accept a valid account-erasure request, we freeze account access and stop new work. We then delete the login and company-profile content, Campaign Briefs and their versions, saved planner conversations, campaign analytics, ordinary uploaded files and notification history. We delete or scrub the brand's working campaign and Creator Call content, chat messages and ordinary attachments, and submitted-draft links and comments. Necessary stripped account, campaign, Creator Call and relationship records remain. Available credits are forfeited through the credit history; the wallet and financial records are retained rather than deleted.

The retained exceptions include payment, invoice and credit evidence, creator payment-terms acceptances, audit and webhook history, contact-suppression records, outreach history and the shared creator corpus with its supporting provider records. Bare chat and required submitted-draft records also remain. Retained history can contain personal information, including addresses, message content, attachment metadata, historical filenames and provider or AI outputs. Brand erasure does not remove every historical reference or erase shared creator data collected separately from that brand's campaign analytics. Only final contracts signed by both parties receive the six-year erasure archive described in the table. The availability of historical chat or audit records is not itself a legal basis for keeping unnecessary personal information indefinitely.

For account erasure, we request cancellation of the live Stripe subscription with immediate effect, rather than at the end of the billing period, without a prorated refund for the unused period. Cancellation and customer deletion are completed through recorded stages; unresolved payment or other work and provider failures can leave those stages pending. Accepting a request does not mean every deletion or provider action has finished. Content deletion also waits for outstanding work and previously issued upload access to end safely. Deleting the Stripe customer does not erase Stripe's historical charges, invoices or other financial records.

Copies held by providers, local spreadsheets, exports and recoverable backups are separate from the application records, and their deletion date cannot be inferred from an application purge setting. A valid deletion or restriction is applied across relevant copies as required by law, with any retained backup copy restricted and the deletion reapplied after restoration where necessary.

10 Your rights and choices

Depending on the applicable law and circumstances, you can ask to access and receive a copy of personal information, correct inaccurate information, erase information, restrict its use, object to processing or receive certain information in a portable form. You can withdraw consent and ask for the safeguards applicable to significant automated decisions. These rights are subject to specific conditions, not a blanket exception for business data.

For direct marketing, you can object at any time. We will stop that use and retain only what is needed to respect the objection. Notification preferences affect optional messages; essential service, billing, security or legal communications may still be sent where justified.

Contact support@creatorcall.io with enough information to locate the relevant account, email, profile, comment or campaign. We may need proportionate identity or authority verification. We will not require you to open an account or provide excessive identity documents simply to exercise a right. Authorised representatives can contact us on your behalf with appropriate authority.

We normally respond to rights requests without undue delay and within one month. Where applicable law permits an extension, clarification or another adjustment, we will explain the reason and timing. We ordinarily do not charge; any lawful refusal or exceptional fee will be explained with your complaint route. If we act as a processor, we will help route the request to the relevant customer and assist it as required.

Erasure is not absolute. For example, a necessary invoice or evidence needed for a legal claim may be retained while unrelated information is deleted. We will explain any relevant exception and the remaining period or criteria. A database dependency, an archive setting or the word “audit” is not itself a legal reason to refuse erasure.

How requests are handled. Export and deletion requests are made through support@creatorcall.io, from the Data and privacy settings of your account or directly, and are carried out by our team. Some database protections prevent retention-controlled records from being deleted before their scheduled date. These technical restrictions do not change your statutory rights, and where earlier erasure is legally required we carry it out.

11 Complaints and security

Please send a privacy complaint to support@creatorcall.io or our registered office. We acknowledge data-protection complaints within 30 days, investigate without undue delay, keep you informed and communicate the outcome. This is separate from the usual one-month timetable for a rights request.

You can complain to the Information Commissioner's Office in the UK. People protected by EU GDPR can also contact their competent supervisory authority, including where they live, work or believe an infringement occurred. These routes do not prevent other legal remedies.

We apply proportionate organisational and technical measures, including access restrictions, authentication, controlled service-provider access and incident handling. No system is perfectly secure. If a personal-data breach occurs, we assess it and notify the relevant authority and affected people where required by law. We do not claim that all correspondence is end-to-end encrypted, that all stored records are anonymous or that certification of a supplier certifies CreatorCall itself.

12 Children and updates

Customer accounts are intended for adults acting for business purposes. Creators are not universally required to be 18, so information processed through sourcing, correspondence, secure submission links and campaign records may concern children. We may also encounter children in public comments, audience samples and uploaded material. A business customer's adult status does not remove those children's privacy rights. A brand's responsibilities for an engagement do not remove CreatorCall's own responsibilities for the information we process.

Under-age participation remains subject to applicable law and the eligibility requirements of the relevant services and payment providers. We do not treat a public profile, a purchased list or a general acceptance of terms as blanket permission to profile or market to a child. Where applicable law requires parental authorisation, specific protections or understandable information for a child, those requirements apply to the relevant processing. A child or an appropriately authorised parent or guardian can contact support@creatorcall.io about the information, a decision or a concern. We consider the child's own rights and request only proportionate information to establish identity or authority when needed. This notice does not represent that every creator's age has been independently verified.

We update this notice when processing changes. The effective date identifies the version. For a material new purpose or optional technology, we provide additional information and obtain consent where required before the change. An update does not retrospectively validate earlier processing that lacked a lawful basis or adequate notice.

Send one Creator Call. Get your shortlist.