Product data notice

Privacy Policy

This notice maps the personal-data behavior currently visible in the Clipeo web and mobile product without claiming unverified company, retention, or regulatory facts.

Effective / last updated 2026-09-03Privacy-owner review required

1. Data the current product handles

  • Account data: sign-in email, authenticated user identifier, role, account status, and password credentials managed by Supabase Auth.
  • Creator and brand data: profile names, company names, profile images, biography, location/region, topics, social links, creator types, portfolio media, packages, pricing and onboarding/review state.
  • Marketplace activity: campaigns, applications, saves/signals, package orders, conversation messages, read state and associated timestamps.
  • Safety and consent records: reports, account blocks, and the accepted document type, version, source and time.

2. Why the product uses it

The application uses this data to authenticate accounts, display marketplace profiles and opportunities, save onboarding progress, support creator-brand workflows, deliver messages, maintain read state, enforce access and blocking rules, review reports, and record versioned legal acceptance.

3. Visibility

Profile and portfolio fields can be shown to marketplace participants according to listing and review state. Campaign and conversation data is limited by account role, ownership, participation, and database access rules. Blocking stops new messages but does not automatically erase existing conversation history.

4. Current infrastructure

The current application uses Supabase for authentication, database records and media storage, and Vercel for web delivery. A complete, approved processor/subprocessor list and cross-border transfer disclosure are still required before this shell can be treated as a final privacy policy.

5. Account controls

Users can edit supported profile data, change their password, sign out, review blocked accounts, and request permanent account deletion in the authenticated mobile app. The deletion endpoint verifies the current session and password and deletes only that authenticated Auth user; related application rows configured with database cascades are then removed.

See Delete account for steps and current boundaries.

6. Retention and requests

Exact retention periods, backup expiry, legal-hold exceptions, support identity-verification procedure, and response timelines are not established in this repository. They must be approved and published with a monitored contact route. Until then, use the in-app controls described on Support.