Privacy Policy
Last updated: April 2026
easyInfluencer is committed to protecting your privacy. This policy outlines how we collect, use, and safeguard your information.
Information We Collect
- Account information (name, email, profile details)
- Social media account data connected through OAuth (see below)
- Content created and submitted through collaborations
- Communication between businesses and creators on the platform
- Usage data and analytics (with your consent)
- Payment and billing information (processed by Stripe)
Social Media Data Collection
Data collected when you connect your social accounts
TikTok
When you connect your TikTok account, we request the following permissions:
- user.info.basic & user.info.profile — Your display name, avatar, and bio for your marketplace profile
- user.info.stats — Follower count, following count, and video count for tier classification
- video.list — Your recent videos for portfolio display to potential business partners
Data collected: display name, avatar URL, bio, follower/following counts, likes count, video count, verification status.
When you connect your Instagram account, we request the following permissions:
- instagram_business_basic — Your profile data, media list, and post insights for marketplace display and performance analytics
- instagram_business_content_publish — Ability to post collaboration deliverables on your behalf (only with your explicit consent per collaboration)
Data collected: username, display name, avatar, follower/media counts, account type, post metrics (reach, views, likes, comments, shares, saves), audience demographics (age, gender, country, city).
Token Storage
OAuth access tokens and refresh tokens are encrypted at rest using AES-256 encryption. You can disconnect any social account at any time from your dashboard settings, which immediately deletes the stored tokens.
How We Use Your Information
- To facilitate connections between creators and businesses
- To manage and display creator profiles to potential business partners
- To process and manage collaboration offers
- To classify creators into tiers based on audience size for appropriate matching
- To provide performance analytics to business partners (aggregate data only)
- To improve our platform and services
- To communicate important updates about the platform
Cookies and Tracking Technologies
We use cookies and similar technologies to operate our platform and, with your consent, to analyze site usage. Analytics tools (Vercel Analytics, Sentry) are only activated after you provide consent via our cookie banner.
For full details, see our Cookie Policy.
Content Ownership
As outlined in our Terms of Service, all content produced through collaborations facilitated by easyInfluencer becomes the property of easyInfluencer. We may use, redistribute, sublicense, or repurpose this content.
Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- OAuth tokens encrypted with AES-256 encryption at rest
- Encrypted JWT sessions with HttpOnly, SameSite cookies
- HTTPS enforced across all services
- Role-based access control for platform administration
- HMAC-signed OAuth state parameters to prevent CSRF attacks
Submitting a GDPR request
When you submit a data protection request through our /gdpr form, we collect and process the following data to handle your request:
- Name and email address — to contact you and verify the request.
- Request type and message— to understand what you're asking for.
- IP address and browser user-agent — for abuse mitigation, audit forensics, and to comply with our security obligations under NIS2.
Legal basis: compliance with our obligations under GDPR Article 12 (transparent information and communication regarding the exercise of data subject rights).
Retention: request records (including IP / user-agent) are retained for 24 months as audit evidence, then aggregated and anonymized.
Data Retention
- Account data — Retained while your account is active, deleted within 30 days of account deletion
- Social media tokens — Immediately deleted when you disconnect an account
- Social media metrics — Retained for 12 months, then aggregated and anonymized
- Collaboration content — Retained per our Terms of Service
- Analytics data — Retained for up to 26 months by analytics providers
Third-Party Services
We share data with the following third-party services to operate our platform:
- Vercel — Hosting and web analytics
- Sentry — Error tracking and session replay
- PostHog — Mobile app analytics
- Resend — Transactional email delivery
- Stripe — Payment processing
- TikTok API & Instagram API — Social media data synchronization
International Users & GDPR
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, correct, delete, and port your personal data.
For full details about your GDPR rights, see our GDPR & Data Protection page.
Children's Privacy
Our platform is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately so we can delete it.
Contact
For privacy-related inquiries, contact us at info@easyinfluencer.travel.