Trusty Creator / Information

Privacy Policy

What information the service uses, why it is needed, and how you can exercise your privacy rights.

Last updated

1. Who is responsible

Sergio Escosa Rodriguez

Operator of Trusty Creator, based in the Netherlands.

Business/contact address: to be confirmed before launch.

Business registration and VAT details: not yet provided.

Sergio Escosa Rodriguez is the controller of personal data used to operate Trusty Creator. Contact support@trustycreator.com about privacy or your data. This notice covers visitors, Creators, Brand representatives and people who contact us.

2. Information we handle

  • Accounts: email address, authentication information, account role, identifiers and timestamps. Supabase handles password authentication; your password is not displayed in your public profile.
  • Profiles and portfolios: name, avatar or logo, biography, location, categories, content types, rates, social handles, visibility choices, portfolio files and links, and company details you supply.
  • Projects: campaign briefs, applications, questions, messages, files, delivery and posting links, reviews, activity history, agreed amounts and deadlines.
  • Agreements: signer name, user and project identifiers, the agreement text and version, signing time and the IP address recorded when signing.
  • Payments: Stripe account and transaction identifiers, onboarding status, amounts, currency, transfers and refund status. Card entry and identity/bank information requested during Stripe onboarding are handled by Stripe; we do not store full card numbers or card security codes in our application database.
  • Optional verification: phone number and verification status if you use SMS verification; connected social account identifiers, handles, API responses, available metrics, encrypted access/refresh tokens and refresh timestamps if you connect a social account.
  • Technical and support data: requests, IP addresses, device/browser information, necessary cookies, error/security logs and communications sent to support. Hosting and delivery providers may keep operational logs.

3. Purposes and legal bases

  • Contract and pre-contract steps: create accounts, present profiles and briefs as requested, process applications, provide project messaging and delivery, manage payments, record agreements and send essential account/project notices. For employees representing a Brand, our legitimate interest in serving that organisation may apply instead.
  • Legitimate interests: secure the service, prevent abuse, resolve complaints, maintain proportionate evidence of transactions and claims, and help users assess collaborators through reviews and Trust Scores. We balance these interests against your rights; you may object.
  • Consent: optional social-account connections and phone verification. You can withdraw permission for future processing without affecting its lawfulness before withdrawal. A provider’s OAuth permission is also needed to access its data. Withdrawal does not prevent retention required on another lawful basis.
  • Legal obligations: comply with applicable accounting, tax, lawful disclosure and data-protection duties.

Account and transaction information needed to provide a requested service must be supplied for that service to work. Social connections, phone verification and portfolio details are optional, although leaving them out can affect displayed profile information or verification signals. Accepting platform terms is not blanket consent to unrelated uses of your data.

4. Who can see your information

Creator profiles, portfolios, reviews, Brand profiles and published campaign information may be visible to other users and, where public, visitors and search engines. Visibility settings affect profile discovery. Brands receiving your applications and parties to a project can see information needed for that collaboration.

Avatar and portfolio files use public file URLs. Making a profile private does not make a previously shared file URL private or remove copies from search engines and other people’s systems. Do not put confidential or sensitive information in those uploads. Project deliverables use restricted storage and temporary access links.

Project messages, agreement records and private transaction details are available to the relevant parties and to the operator where needed for support, delivery, administration or dispute handling. We do not sell personal data or use it for targeted advertising.

5. Service providers and other recipients

The service uses, or supports when the relevant feature is enabled, the following providers:

  • Supabase: authentication, database and file storage.
  • Vercel: website hosting, request processing, scheduled jobs and operational logs.
  • Stripe / Stripe Connect: payments, connected-account onboarding, transfers and refunds. Stripe also handles data for its own legal, fraud-prevention and payment purposes under its Privacy Policy.
  • Resend: delivery of transactional email. Authentication email is delivered through Supabase’s configured email service.
  • Twilio Verify: phone number and SMS verification requests when used.
  • Meta/Instagram, TikTok and Google/YouTube: optional account authorisation and API metrics, governed also by those platforms’ own terms and privacy notices.

Support emails are also handled by the operator’s mailbox provider, which is still being selected for this draft. Other recipients may include your project counterparties, professional advisers and authorities where necessary and lawful. Brands and Creators are responsible for their own independent use of personal data received during a collaboration.

6. Social accounts and verification

Connecting an account lets the service associate it with your profile and retrieve the available profile and statistical information permitted by the provider. Instagram requests account details and follower/media counts; TikTok requests profile details and follower, like and video counts; YouTube requests channel details and subscriber, video and view counts. Availability depends on provider permissions and account eligibility.

The current integrations read data; they do not post content or read private messages. Tokens allow later refreshes while the connection is active. You can disconnect in your social-account settings and revoke access directly with the provider. For Google, use Google account permissions; see also Google’s Privacy Policy and the YouTube Terms of Service.

Disconnecting stops the account being used for active refreshes and removes the associated handle from your profile. It does not currently erase the stored connection, tokens or metrics immediately. To request their deletion, contact privacy support. Revoking access with a provider does not by itself delete data already stored here.

Trust Scores are calculated from portfolio quantity/variety, delivery history, Brand ratings, profile completeness and social connections. The Verified badge depends on a connected social account and profile completeness. These automated signals can affect discovery and user decisions, but the platform does not automatically accept or reject a project application on that basis. You can ask for correction and human review.

7. Cookies and local storage

We use necessary authentication cookies to keep you signed in and maintain your session. When you connect a social account, short-lived security cookies check the authorisation response; the current connection cookies last up to ten minutes and are cleared as part of the callback flow.

The current application does not include advertising pixels or optional analytics trackers. Fonts are served with the application. Stripe-hosted payment pages and linked third-party services have their own cookie practices. Essential cookies support the service you request; disabling them can break login or account connection.

If we introduce non-essential tracking that requires consent, it must remain inactive until you choose it, with a way to withdraw that choice. The use of a Privacy Policy alone does not provide cookie consent.

8. How long information is kept

We retain account and profile information while you use the service. After a closure or deletion request, we assess which records can be deleted or anonymised and which remain necessary for an open project, payment, legal obligation or specific dispute. An account closure does not require us to keep every related file indefinitely.

Essential Dutch business and tax records are generally kept for seven years, with longer periods only where a specific rule requires them. This does not apply automatically to every message, portfolio file or social token. Agreement and dispute evidence is kept only while needed to establish, exercise or defend the relevant claims.

Support correspondence is kept while needed to resolve the request and any related complaint. Technical logs and backups follow the configured provider retention periods. Automatic deletion of all account data is not currently available; deletion and retention reviews are handled manually. The provider-specific log and backup periods still need confirmation before this draft is finalised. We will explain any retained categories and reasons when responding to a deletion request.

9. Security and international processing

The application uses authenticated access, database access rules, restricted project storage and encryption of stored social tokens. No internet service can guarantee absolute security. Please protect your account and avoid sending passwords, card details or unnecessary identity documents to support.

Our providers may process data outside the European Economic Area. Where such a transfer occurs, an appropriate GDPR transfer mechanism is required, such as an applicable adequacy decision or Standard Contractual Clauses with necessary supplementary safeguards. The selected regions, provider agreements and transfer arrangements are still being checked for this draft; we do not claim all data stays in the EU. Contact privacy support for information about the applicable safeguards or a copy where available.

10. Your choices and rights

Depending on the circumstances, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time. You may request human review of inaccurate scoring or verification information.

Send a request to support@trustycreator.com. We may request proportionate information to verify identity. We respond without undue delay, normally within one month; if a lawful extension is needed for complexity or number of requests, we explain it within that month. Requests are normally free.

See Your data rights for practical instructions. You may also complain to the Autoriteit Persoonsgegevens, another competent supervisory authority, or seek a judicial remedy. You do not have to contact us before exercising those rights.

11. Children and policy updates

The service is intended for users aged 18 or over. If you believe a child has provided personal data, contact us so we can investigate and handle it appropriately.

We will update this notice when our processing changes and communicate material changes where appropriate. The revision date appears above. A policy update does not itself authorise a new purpose that requires a different legal basis or consent.