Data Privacy Guidelines

Privacy Policy

Effective Date: June 27, 2026  |  Last Updated: June 27, 2026

1. Introduction & Scope

Welcome to Promo ("we", "our", or "us"). Promo operates a modern creator marketing marketplace and dashboard infrastructure designed to connect brands and content creators.

This Privacy Policy serves as a legally binding document outlining our data processing standards. It explains what information we collect from you, how we process it, how we secure it, and your legal rights under regulations such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other global data privacy frameworks.

By downloading, installing, registering an account, or interacting with Promo's website, mobile application, database APIs, or customer support channels, you consent to the collection and use of your data as detailed in this policy. If you do not agree to these terms, you must immediately cease using the platform.

2. Information We Collect

We collect information directly from you, automatically via app interactions, and through third-party services you authorize to sync with Promo.

2.1 Information You Provide Directly

Account Registration Details:

  • Email address and display name.
  • Password (fully encrypted at rest and in transit — we do not store plain-text credentials).
  • Selected marketplace role (Brand Partner or Influencer Creator).

Profile Customization Information:

  • Company name and legal business entity name (for Brands).
  • Professional bio, category tag selections, website URLs, and avatar images.
  • Location in text format (city, region, country) or geographic coordinates if auto-detected.

Social Media Channels (Creators):

  • Handles/usernames for connected platforms (Instagram, YouTube, TikTok, Twitter/X, etc.).
  • Audience reach metric details (follower/subscriber counts synced via third-party APIs).

Campaign & Deliverable Creation:

  • Campaign briefs containing project titles, category requirements, budgets, deliverables, and images.
  • Creator portfolio links, uploaded work samples, pitch descriptions, and bid pricing quotes.
  • Direct chat histories (messages, uploaded media files, milestone checklists, and escrow agreement terms).

Verification Documents:

  • Government-issued ID documents or corporate tax filing certificates (exclusively when requesting a verified badge).

2.2 Information Collected Automatically

App Interaction Logs:

  • Details of buttons clicked, brief categories viewed, and applications processed.
  • Activity timestamps indicating registration date, login events, and last-active states.
  • Profile inspection records logging which brands or creators viewed your page.

Device Metadatas:

  • Operating system info (iOS, Android, Windows, Mac), device brand/model, and application version.
  • Firebase Cloud Messaging (FCM) device registration tokens for push sync.

Geolocational Geocoding:

  • GPS coordinates captured only when you actively trigger map geolocating or locate-me tools. We do not track location coordinates in the background.

Performance & Crash Analytics:

  • Sentry error stack traces, execution latency records, and navigation paths leading to system faults.

2.3 Information from Third-Party Services

Google Authentication: If you use Google Sign-In, Google shares your primary email address, profile name, and profile picture URL. We do not access your Google account credentials or search history.

Social Network Integrations: If you verify metrics via network APIs (YouTube, Instagram, TikTok), we receive engagement rates and follower metrics. You can revoke these access tokens directly in your social platform security settings at any time.

3. How We Use Your Information

We process your data to maintain the core functionality of Promo, ensure safety, and comply with law:

  • Core Service Provisioning: Hosting profiles, displaying campaign briefs, routing direct chat messages, and supporting map-based discovery pins.
  • Algorithmic Matching & Recommendations: Personalizing recommendation feeds for creators and sorting creator applicants for brand reviews based on tag matches, engagement sizes, and verified rating histories.
  • Real-Time Alerts: Delivering Firebase push notifications for chat replies, campaign updates, and payment milestones.
  • Security & Abuse Prevention: Implementing database Row-Level Security (RLS) policies, checking file uploads for malicious scripts, managing 7-day session inactivity timeouts, and preventing automated scraping of creator contacts.
  • Platform Optimization: Resolving application crashes and analyzing anonymized transaction metrics (such as average brief rates) to optimize performance.

4. How We Share Your Information

We do not sell your personal information. We share data only inside the Promo platform interface or with compliance-certified technical partners:

Service Provider Purpose Data Shared
Supabase Database, authentication, storage, real-time sync All application data elements
Firebase (Google) Push notifications (FCM) Device token, alert content
Sentry Crash and error logs Debugging variables, stack traces
Google Sign-In OAuth authentication Email and Google profile name
OpenStreetMap Nominatim Location Geocoding Text locations searched
Carto Map tile rendering None (map assets requests only)

5. Data Storage, Security & International Transfers

Your personal data, campaign briefs, metrics, and communications are stored securely within Supabase cloud infrastructure, built on top of enterprise-grade cloud environments.

  • Encryption Protocols: All data is encrypted in transit via Transport Layer Security (TLS 1.3) and at rest using Advanced Encryption Standard (AES-256). Cryptographic passwords are hashed utilizing SCRIPT/bcrypt key derivation functions.
  • Database Protection: We enforce strict database Row-Level Security (RLS) policies at the PostgreSQL database layer, preventing unauthorized cross-tenant data requests. Static file attachments are isolated in secure storage buckets using randomized UUID identifiers and audited MIME-type checking.
  • Access Control: Administrative access to database nodes is strictly restricted to certified security engineers and support staff on a documented, need-to-know basis using multi-factor authentication (MFA). Sessions automatically expire after 7 days of inactivity.
  • Cross-Border Transfers: As we leverage distributed cloud databases, your data may be transferred to and processed in servers situated outside your country of residence (such as AWS US/EU data centers). We utilize European Commission Standard Contractual Clauses (SCCs) and comply with global data security frameworks to safeguard international transfers.

6. Your Rights and Choices (GDPR, CCPA & Global Regulations)

Depending on your location, you possess comprehensive rights over your personal profile data under regional privacy acts (such as GDPR, CCPA, and COPPA):

  • Right of Access & Information: You can request a summary report detailing what data elements we hold about you, the categories of sources, and the processing purposes.
  • Right to Rectification: You can edit and update your display name, business tags, biographies, and linked social usernames directly in your profile settings panel.
  • Right to Portability: You have the right to request a copy of your platform profile details, transaction invoices, and campaign briefs in a structured, machine-readable CSV or JSON format.
  • Right to Object & Restrict: You can opt-out of automatic social channel metric syncs or object to platform-level analytics profiling by customizing your account configurations.
  • Right to Erasure (Right to be Forgotten): You can permanently purge your database records, chat logs, and files by submitting the form on our dedicated Account Deletion page. Submission immediately hides you from public search feeds, and physical erasure completes within 14 business days.
  • Consent Withdrawal: You can revoke device permissions (e.g. Location, Camera) at any time through system level settings.

7. Device Permissions We Request

To provide interactive capabilities, the Promo app requests system permissions. Denying optional permissions will not break core usage, but will restrict specific features:

Permission Why We Need It Impact if Denied Optional?
Internet Required for secure HTTPS API calls, Supabase database queries, and real-time messaging sync. The application cannot authenticate, fetch cards, or send messages. No
Camera To capture live profile images and take portfolio photo attachments. You cannot capture photos directly inside the app; you must choose files from the library instead. Yes
Photo Library To browse and select campaign brief image assets, billing attachments, or creator portfolio items. You will not be able to upload custom image assets to cards or message threads. Yes
Location To auto-detect geographic coordinates and center your profile pin on the discovery map layout. The app fallback to capital/country coordinates, and you cannot use the locate-me button. Yes
Notifications To send Firebase Cloud Messaging (FCM) alerts for direct message replies and campaign matches. You will not receive real-time push messages when the app is minimized. Yes
Microphone To capture voice note attachments in direct chat threads. You cannot record or transmit audio messages. Yes

8. Contact Us & Grievance Procedures

If you have any inquiries regarding data protection standards, CCPA data selling opt-outs, or GDPR rights processing, please contact our designated Privacy Compliance Group:

  • Email: mallipurapusiva@gmail.com
  • Mailing Address: Promo. Legal Compliance, Grievance and Privacy Division, Bangalore, India
  • Response Timeline: We review all inquiries immediately. Legitimate requests under GDPR or CCPA will receive a formal confirmation and response within 30 calendar days.
Specialised creator marketing

Scale your creator pipeline today.

Download our app
Promo.

We replace manual agency pipelines with clean, integrated digital infrastructure built to move as fast as your brand needs.

© 2026 Promo. All rights reserved.