Privacy Policy
Last updated: 15 September 2026
This policy covers The Creator Collab, an invite-only pilot for content creators: the waitlist on this site, the pilot app (where creators manage outreach and message brands), the contact form on a creator's public media kit, and the optional social-platform connections a creator can set up in the app. It explains what we collect, why, and what your rights are.
1. Who we are
The data controller is Spijker Dienstverlening (trading as The Creator Collab), a business registered in the Netherlands with the Dutch Chamber of Commerce (KVK) under number 96035250, located at Sibeliusstraat 12, Leiden, the Netherlands.
For anything privacy-related, email hello@thecreatorcollab.com. We have not appointed a data protection officer, as our processing does not require one.
2. What we collect
Only what you enter in the two waitlist forms:
- Creator waitlist: email address, biggest platform, follower range, and — optionally — your handle and content niche.
- Brand waitlist: company, business type, and email address.
- Media-kit contact form & in-app messages: if you contact a creator through their public media kit or message them in the app, we process your name, company, email address and the content of your messages, so the conversation can be delivered and continued.
We also see cookieless, aggregated visit statistics for this site (for example how many people viewed a page). These cannot identify you.
Atlas — places a creator saves. A creator can build a travel log: the places they stayed, with coordinates and dates, and per place their tips (a hotel, a restaurant, an activity) with an optional note, price, photos, video and booking link. Coordinates come from a place the creator picks from a search list, or from the photos they import. This is location data about the creator, entered by the creator.
We do not collect payment details, location data about visitors, or any cross-site tracking data.
3. Connected social platforms
In the app, a creator can optionally connect a social account so their media kit fills itself. Today that is YouTube (via Google sign-in), Instagram (via Instagram Login) and TikTok. Connecting is never required — every number can also be entered by hand, and each connection stands on its own: connecting one says nothing about the others.
Read-only, always. All three connections are read-only by design. We cannot post, comment, message, advertise, or change or delete anything on your account. We never see or store your password on any platform: you authorise access on the platform's own screen, and you can withdraw it there or with us.
How we store it. Data from a connected account is stored in our database (Supabase, EU) in records only you can read. The sign-in tokens are stored with additional access controls that make them unreadable from the app itself; only our server-side functions can use them, solely to fetch the data described below.
Thumbnails. The image addresses these platforms hand us expire after a while, so when a video or post enters your media kit we save a copy of its thumbnail in our own media storage to keep the tile working. Those copies count as platform data: they go when the rest goes.
Publishing is manual. Nothing from a connected account appears on your public media kit until you press publish yourself.
How long we keep it. We keep data from a connected account for as long as that connection is active. When you disconnect, we revoke and delete the tokens immediately. Statistics already saved to your profile stay until you edit or delete them, and anything you previously published stays on your media kit until you change it — disconnecting stops future updates, it does not silently rewrite your page. Deleting your account, or asking us to erase your data (section 3d), removes all of it.
What we never do with it. We do not sell, rent or license it. We do not share it with advertisers, and we do not use it for advertising or targeting. We do not use it to train, fine-tune or improve AI models, and the AI providers we use for drafting text are contractually prohibited from doing so. We do not use it to build profiles or databases about anyone beyond the media kit you build yourself, and we never use it to approach brands.
Legal basis: Article 6(1)(b) GDPR — performing the service you asked for. You start each connection yourself and can end it at any time. Audience statistics, where a platform provides them at all, are aggregated percentages about your viewers as a group; we receive no data that identifies an individual viewer.
3a. YouTube & Google user data
What we access. When you connect YouTube, you grant us read-only access. We retrieve your channel name and ID, subscriber count, view and video counts, a list of your uploads (titles, thumbnails, view counts, publish dates) and, from YouTube Analytics, 30-day totals (views, watch time, likes, comments, shares, subscribers gained) and aggregated audience statistics (age groups, gender split, top countries).
Disconnecting. You can disconnect at any time in the app: we then revoke our access with Google and delete the stored tokens. You can also revoke access yourself at myaccount.google.com/permissions.
Platform terms. The YouTube connection uses YouTube API Services. By connecting, you also agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy. Our use of data received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
3b. Instagram
What we access. When you connect Instagram, you grant us read-only access through the Instagram API with Instagram Login, and we receive from Meta:
- Profile: your Instagram user ID, username, account type, name, biography, profile picture, website, follower count and media count.
- Posts: your media objects — media ID and type, caption, permalink, thumbnail and timestamp.
- Account insights: reach, views, profile views and accounts engaged.
- Media insights, per post: reach, views, likes, comments, saves and shares.
- Audience demographics: aggregated top countries, cities, age ranges and gender split — only if your account is a professional (business or creator) account with enough followers for Meta to release them. Below that threshold Meta returns nothing and your kit shows nothing.
We do not receive your password, your email address or your direct messages from Meta.
Disconnecting. You can disconnect at any time in the app: we then invalidate and delete the stored tokens and stop fetching. You can also revoke our access from Instagram itself, under Settings, then Website permissions, then Apps and websites (instagram.com/accounts/manage_access). If you remove it there, Meta notifies us and we treat it the same way: tokens deleted, updates stopped. Your handle and account ID stay with the disconnected record, so that a later deletion request can still be matched to you; a deletion request removes those too.
Platform terms. By connecting, you also agree to the Instagram Terms of Use; Meta's handling of your data is described in the Meta Privacy Policy.
3c. TikTok
What we access. When you connect TikTok, you grant us read-only access and we receive:
- Basic profile: your open ID, display name and avatar.
- Profile details: your profile link, bio description and whether your account is verified.
- Account statistics: follower count, following count, total likes and video count.
- Videos: a list of your public videos with title or description, cover image, publish date, and per video the view, like, comment and share counts.
No audience data. TikTok does not offer audience demographics through its API, so we never receive the age, gender or country of your TikTok audience — not in aggregate, and not per viewer. Where your kit shows audience data, it comes from another connection or from what you entered yourself.
We do not receive your password, your email address or your direct messages from TikTok. Only your public videos are returned, even with your permission.
Disconnecting. You can disconnect at any time in the app: we then revoke the tokens with TikTok and delete them. You can also revoke our access in the TikTok app under Settings and privacy, then Security and permissions, then Manage app permissions.
Platform terms. By connecting, you also agree to the TikTok Terms of Service; TikTok's handling of your data is described in the TikTok Privacy Policy.
3d. Asking us to delete your data
Three routes, all of which reach us. You do not have to give a reason, and you do not need an account with us.
- In the app. Disconnect a single platform in Settings, or delete your account entirely. Deleting your account removes your profile and statistics, your media kit (the public page goes offline immediately), your messages, your trips, and the tokens of every connected platform.
- Through your Facebook or Instagram settings. Remove The Creator Collab under Apps and websites and ask there for your data to be deleted. That request reaches us automatically: we delete the tokens, the connection, the statistics we fetched and the images we copied from it. You are given a confirmation code and a link where you can check the status without logging in — which matters precisely because removing the app there also removes your way in.
- Email us. hello@thecreatorcollab.com, from any address, naming the account concerned. Use this if you cannot log in, if you never had an account with us, or if you want figures you already published removed as well.
The deletion log. We record every deletion request we receive: the confirmation code, which platform it concerned, that platform's account ID, and what we did. That record is what makes the status link work, and it is how we can show a regulator that a request was honoured. We keep it for twelve months and it is never readable from the app.
What stays. Data we are legally required to keep — invoices, for the seven years Dutch tax law prescribes — and aggregated statistics that can no longer be traced back to you. Anything others copied or archived from a media kit while it was public is outside our control. If we cannot honour a request in full, we tell you which part we kept and why.
We complete deletion requests within one month, as Article 12(3) GDPR requires, and in practice much sooner. This is your right to erasure under Article 17 GDPR; the same address serves the other rights in section 8.
4. Why we collect it & legal basis
- Managing the waitlist and sending pilot invites. Legal basis: Article 6(1)(b) GDPR — taking steps prior to a contract at your request.
- Selecting the pilot group based on platform, follower range and niche, so the first cohort is a workable mix. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in running a small, balanced pilot. Platform and follower range are required to join; your handle and niche are optional — leaving those empty still keeps you on the waitlist.
Invite emails are the service you signed up for, not marketing. We only send a newsletter or other marketing if you separately opt in (Article 6(1)(a) GDPR — consent), and you can withdraw that consent at any time.
- Running the pilot app and delivering messages. When you contact a creator or exchange messages, we deliver and — because people use the app occasionally rather than all day — email you a notification that a new message or inquiry is waiting (never the message content). Legal basis: Article 6(1)(b) GDPR (performing the service) and 6(1)(f) GDPR — our legitimate interest in reliably delivering conversations.
- Fetching statistics from a connected social account (section 3). This only happens after you connect the account yourself, and only to fill your own profile and media kit. Legal basis: Article 6(1)(b) GDPR — performing the service you asked for. Audience statistics are aggregated percentages about your viewers as a group; we receive no data that identifies an individual viewer.
5. Who we share it with
We do not sell your data and we do not share it with advertisers. We use these service providers (processors):
- Supabase — database where waitlist entries, accounts and messages are stored, hosted in the EU.
- Vercel — website and app hosting, and cookieless analytics.
- Resend (EU region) — delivers our transactional email: invites, password resets, and new-message/new-inquiry notifications.
- Hostinger — hosts our hello@thecreatorcollab.com mailbox, which receives the emails you send us (including removal and rights requests).
A data processing agreement is in place with each processor.
5b. Public Atlas pages
A creator can publish a trip. It then gets a public page at /a/<handle>,
or an unlisted page at a link containing a random token. The page shows their name, handle
and avatar, a world map of the places, and per place their tips: title, note, price, photos
or video, a booking link where there is one, and the required disclosure whenever a
partnership or a commission sits behind it. Nothing appears that the creator did not enter,
and any tip can be kept off the page individually.
Who can see it. Anyone, without an account. Search engines can index a public page, and others can copy or archive it. A trip with future dates also shows where the creator will be, and when. A creator who does not want that keeps the trip as a draft, or publishes it after the trip.
Undoing it. Setting a trip back to draft, or deleting it, takes the page offline immediately. What others saved or archived in the meantime is outside our control.
Photos. A photo is stored as the camera wrote it, including the data inside the file — capture time, often the exact GPS location, and the camera model. Anyone who downloads the file can read that. Uploaded files also live at their own unguessable address as soon as they are uploaded, including while the trip is still a draft. If people are recognisable in a photo, it is for the creator to judge whether they may publish it; if you are in one and want it removed, email us.
Legal basis: Article 6(1)(b) GDPR — publishing is the service the creator asks for and switches on themselves.
5c. Parties your browser contacts directly
Some parties receive nothing from us, but are contacted by your browser because we placed their content on the page. They see your IP address, and handle it under their own terms. We have no data processing agreement with them.
- OpenFreeMap (Hyperknot Software Kft., Hungary, delivered over Cloudflare) — the map imagery on Atlas pages. They see your IP address, which part of the map you are looking at, and the page you came from. No cookie is set and there is no tracking. Their policy states they do not log IP addresses by default. If the map fails, the page falls back to a simple map with no third party involved; the list of places stays either way. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in showing a working map.
- Counting on Atlas pages — public Atlas pages keep day-level counters: how often a page or trip was viewed and how often a booking link was clicked. Counters only — no IP address, no device details, no visitor identifier, no cookie. A creator can share the counters of one collaboration with the brand that paid for it through the platform; the brand then sees those aggregate numbers for that campaign, never anything about individual visitors.
- Komoot GmbH (Germany), through its Photon place search — used in three moments. When a creator types a place name, and when they import photos: photos are read on the creator's own device and are not uploaded for this; to find a place name we send one coordinate per group of photos, rounded to roughly 100 metres. And when a visitor searches the public Atlas for a place we have no entry for, we send that search text so the map can travel there anyway. In all three cases we send the text or coordinate and nothing else — no photo, no filename, no account detail, no visitor identifier, and no cookie.
5d. Media-kit signals
When a creator messages a brand through the app, the link to their media kit carries a marker unique to that recipient. If the link is opened, or a reply comes in through the contact form on that kit, we record that it happened and when — nothing more. No IP address, no browser details, no fingerprint, no cookie. Several opens within the same hour count as one. This lets the creator see whether their proposal was read. Legal basis: Article 6(1)(f) GDPR — following up on a proposal they sent themselves. If you are a recipient and would rather this were not recorded, email us.
6. International transfers
Waitlist data is stored in the EU, in Frankfurt, Germany (eu-central-1). Vercel is a US-based company; where data leaves the EU, it does so under Vercel's EU-U.S. Data Privacy Framework certification and/or Standard Contractual Clauses.
Map imagery and place-name lookups stay within the EU (Hungary and Germany respectively). Our typeface is served from our own servers, so no request goes to Google for it.
7. How long we keep it
We keep your waitlist entry until you accept an invite or ask to be removed — whichever comes first. If neither happens, we delete all waitlist data no later than 12 months after the waitlist closes.
Sign-in tokens for a connected social account are kept until you disconnect, and are deleted immediately when you do. Statistics fetched from a connection stay on your profile until you edit or delete them. Deleting your account removes both at once.
8. Your rights (GDPR)
You can ask us at any time to:
- access the data we hold about you;
- correct it (rectification);
- delete it (erasure);
- restrict how we use it;
- receive it in a portable format;
- object to processing based on legitimate interest (such as pilot-group selection);
- withdraw any consent you gave, such as a newsletter opt-in.
Email us at hello@thecreatorcollab.com — we respond within one month.
You also have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or to your local EU supervisory authority.
9. Your rights — California & other regions
We do not sell or share your personal information with anyone, for any purpose, and we do not use it for targeted advertising.
Wherever you live, you have the same rights to know, access, delete and correct your data. Use the same address: hello@thecreatorcollab.com.
10. Cookies & analytics
This site does not use cookies or similar storage on your device. We measure visits with Vercel Web Analytics, a cookieless service: it counts page views using an anonymised, aggregated method, never stores anything in your browser, and cannot identify you. Because there is nothing to consent to, you won't see a cookie banner here. If we ever introduce cookies, we will ask for your consent first and update this policy.
11. Security
All traffic to and from this site is encrypted (TLS/HTTPS). Waitlist entries are stored with Supabase behind access controls, including row level security, and only the business owner has access to them.
12. Children
The Creator Collab is aimed at professional content creators and is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has joined the waitlist, email us and we will delete the entry.
13. Changes to this policy
The date at the top shows when this policy was last changed. If we make a material change, we email everyone on the waitlist before it takes effect.
14. Contact
hello@thecreatorcollab.com
Sibeliusstraat 12, Leiden, the Netherlands