NicheCollab Privacy Policy
Version 0.2 · 2 August 2026. NicheCollab is in early access and under active development — see Terms of Service Section 2. Prepared from a code audit of the NicheCollab repository, re-verified against the shipped code on 2026-08-02. Sections marked "feature not yet live" describe planned functionality that does not process any personal data today; they will be re-verified against the shipped implementation before those features launch.
Who we are: NicheCollab ("we", "us"). Contact: [email protected]
This policy is written to satisfy the transparency requirements of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). The operator's place of establishment is not yet decided; the applicable-law analysis, EU/UK representative requirements (GDPR Art. 27), and supervisory-authority designation must be completed by counsel once the entity is fixed. Hosting and traffic-routing locations are known and disclosed in Section 9.
1. Summary (plain language)
- NicheCollab is a marketplace where sponsors (brands) and creators (influencers) find each other, negotiate offers, and run collaborations.
- We collect what you give us when you sign up and use the marketplace: your name, email, password (stored only as a cryptographic hash), your profile details, and the content of your offers, negotiations, and messages.
- We automatically record limited technical data for security: the IP address and browser information attached to your login sessions.
- We use one strictly necessary cookie to keep you signed in. We use no advertising, analytics, or tracking cookies.
- We do not sell or share your personal information for advertising, and we do not use it to train AI models.
- Parts of the service process further data when you use them: payments via Stripe (Section 7) and service email (Section 8). Creator directory profiles built from publicly available information (Section 6) are not yet live — that section is marked accordingly and will be re-verified before it launches.
2. Scope
This policy covers personal data processed through the NicheCollab web application and related support channels. It covers account holders (sponsors and creators who sign up), anyone who contacts us without an account — for example by submitting the removal or correction request form (Sections 3.1 and 6.3) — and, once the relevant feature launches, individuals who do not have an account but appear in unclaimed creator profiles (see Section 6).
For data you provide about other people inside offers, negotiations, and messages, you are responsible for having the right to share it.
3. Personal data we collect today
3.1 Data you provide directly
| Category | Data | When |
|---|---|---|
| Account data | Name, email address, password (stored as a salted cryptographic hash — we never store or can read your plaintext password) | Sign-up |
| Creator profile | Display name, niche/category; and where you choose to add them: bio, avatar image URL, social platform handles and links, audience size, engagement rate, city and country | Onboarding and profile editing |
| Sponsor profile | Company name; and where you choose to add them: website, industry, logo URL | Onboarding and profile editing |
| Offer and negotiation content | Offer titles and descriptions, proposed budgets and currency, deliverables, timelines, and any message text you include with an offer, counter-offer, acceptance, or decline | Sending or responding to offers |
| Messages | Message text sent within a collaboration thread, and read timestamps (messaging is scoped to active collaborations) | Messaging (feature in development) |
| Removal or correction requests | The email address you give us so we can send the confirmation link, what you are asking for (removal or correction) and anything you write to explain it, whether you are the person the profile is about or acting for them, and the profile the request concerns | Submitting the request form or emailing [email protected] — no account needed (Section 6.3) |
3.2 Data collected automatically
| Category | Data | Purpose |
|---|---|---|
| Session security data | IP address, browser user-agent string, session creation/expiry timestamps, and a session token | Keeping you signed in; detecting account compromise and abuse |
| Negotiation audit log | An append-only record of every offer event (who acted, what changed, when) | Integrity of negotiations; dispute resolution; fraud prevention |
We do not collect device fingerprints, precise location, or behavioural analytics, and we do not run session-replay, advertising pixels, or third-party analytics scripts.
3.3 Cookies
We set a single strictly necessary authentication cookie (an HTTP-only session cookie) so you stay signed in. It is not used for advertising or analytics and is deleted or expires when your session ends. Because we use only strictly necessary cookies, no cookie-consent banner is presented. If we ever add non-essential cookies or similar technologies, we will update this policy and obtain any consent required before setting them.
3.4 Data we do not collect
We do not knowingly collect special-category data (GDPR Art. 9) or "sensitive personal information" as defined by the CCPA. We never collect payment card details: where a payment is made, card details go directly to Stripe and never reach us (Section 7).
4. Purposes and legal bases (GDPR / UK GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account; providing the marketplace (search, offers, negotiations, collaborations, messaging) | Account, profile, offer/negotiation, and message data | Contract performance — Art. 6(1)(b) |
| Keeping the service secure: session management, abuse and fraud detection, rate limiting | Session security data, negotiation audit log | Legitimate interests — Art. 6(1)(f) (security and integrity of the platform) |
| Maintaining a truthful record of negotiations and resolving disputes between users | Negotiation audit log, offer/negotiation content | Legitimate interests — Art. 6(1)(f); and contract performance |
| Complying with legal obligations (e.g. responding to lawful requests, tax and accounting once payments launch) | The minimum data required | Legal obligation — Art. 6(1)(c) |
| Service emails about your account and transactions (see Section 8) | Email address, name | Contract performance — Art. 6(1)(b) |
| Marketing communications | — | We do not send marketing communications today. If introduced, they will be consent-based (Art. 6(1)(a)) with a working unsubscribe. |
| Receiving, checking and acting on removal and correction requests, and keeping a record of how each one was handled | Removal/correction request data (Section 3.1) | Legal obligation — Art. 6(1)(c) (responding to data-subject requests); legitimate interests — Art. 6(1)(f) (accountability, and detecting abusive or fraudulent requests) |
| Unclaimed creator directory profiles | See Section 6 | Legitimate interests — Art. 6(1)(f); analysis in Section 6 |
5. Who receives your data
No third-party analytics, advertising, error-tracking or session-replay service receives your personal data — we run none of them. Personal data leaves our own infrastructure only where a section below says so.
- Hosting: OVHcloud — the application, its database, and our mail server all run on a single server we rent from OVHcloud in Montréal, Québec, Canada. See Section 9.
- DNS and content delivery: Cloudflare, Inc. (United States) — all traffic to nichecollab.com is routed through Cloudflare, which provides our DNS and acts as a reverse proxy in front of our server. Because it terminates the encrypted connection, Cloudflare processes connection data — your IP address, the pages you request, your browser information, and the content of your requests — in order to route traffic and protect the service from attack and abuse. See Section 9.
- Payment processing: Stripe, Inc. — when a sponsor funds a collaboration or a creator sets up payouts; see Section 7.
- Email delivery: our self-managed mail infrastructure hosted at OVHcloud — we operate the mail server ourselves; no third-party email service provider processes your messages. OVHcloud provides the underlying server infrastructure. See Section 8.
- Other users: your profile is visible to other users of the marketplace (creator profiles are publicly viewable). The other party to an offer or collaboration sees your display name / company name and the negotiation content — by design, counterpart views do not expose your email address or internal account identifiers.
- Administrators: NicheCollab administrators can view marketplace content, including offers and collaboration messages, for trust-and-safety, moderation, and dispute-resolution purposes.
- Legal: we may disclose data where required by law or to protect rights, safety, or the integrity of the service.
A data processing agreement is not yet in place with any of these providers; putting those agreements in place is a pre-launch task (see Sections 7 and 9). We will publish a current list of sub-processors as they are engaged.
6. Unclaimed creator profiles built from public information (feature not yet live)
Status: the product design includes "unclaimed" creator profiles compiled from publicly available information about creators who have not signed up. No such profiles containing real people's data exist today — all current unclaimed profiles are synthetic demonstration data that do not correspond to real individuals. This section discloses the planned practice so the policy does not under-disclose when ingestion ships. It must be re-verified, and the assessment below completed and documented, before any real-person profile is published.
6.1 What these profiles will contain
Publicly available, professionally oriented information: display name or public handle, social platform handles and links, follower counts, engagement metrics, content niche, public bio text, public avatar image, and approximate location (city/country) where publicly stated. Sources: public creator pages on social platforms and other public sources; each profile records its data provenance. We will not ingest special-category data (e.g. health, religion, political opinions, sexual orientation), private or leaked data, or data about children.
6.2 Lawful basis: legitimate interests (GDPR Art. 6(1)(f)) — draft analysis
- Purpose test: NicheCollab and its sponsor users have a legitimate commercial interest in a discovery directory of professional creators open to sponsorship — comparable to established professional-directory and talent-discovery services. Creators may also benefit from sponsorship opportunities surfaced to them.
- Necessity test: the directory cannot serve its discovery function if limited to already-registered creators at launch; the data used is minimised to public, professional/commercial facts needed for sponsor search.
- Balancing test — safeguards in place or committed:
- only publicly available, professional-context information is used; no special-category data;
- every unclaimed profile is persistently and prominently labeled as built from public information, with an explicit statement that the person has not joined or endorsed NicheCollab;
- unclaimed profiles carry
noindexdirectives so search engines do not amplify them; - offers sent to unclaimed profiles are not delivered to the person; they are held privately and surface only if the person later claims the profile;
- a free, simple removal process is available without creating an account (see our Unclaimed Profile Removal Notice), and removal requests are honored as objections under GDPR Art. 21;
- claimed profiles always rank above unclaimed profiles in search.
- Transparency (Art. 14): because the data is not collected from the data subject, Art. 14 notice duties apply. The intended approach — public notice via this policy and the on-profile banner, plus direct notification where contact is practicable, or reliance on the Art. 14(5)(b) disproportionate-effort exemption with documented reasoning — is a legal judgment that must be made by counsel before ingestion launches, and a Legitimate Interests Assessment (LIA) and, if indicated, a DPIA must be completed and documented.
6.3 Your rights if a profile is about you
If an unclaimed profile describes you, you may — without creating an account — request its correction or removal, object to the processing, or exercise any of the rights in Section 12. The fastest route is the request form on every unclaimed profile page and on the Unclaimed Profile Removal Notice page; emailing [email protected] works too. If you request removal, we will keep a minimal suppression record — the profile's page name on NicheCollab, plus keyed, non-readable codes derived from that name and from the profile's platform handles — solely to prevent your profile from being re-created by future ingestion; we consider this our legitimate interest in honoring your objection durably. You can decline the suppression record (see the Removal Notice) — but the profile could then reappear.
7. Payments via Stripe
Status: the payment flows described here are built into the service (Stripe Checkout when a sponsor funds a collaboration; Stripe Connect for creator payouts). The service is in a pre-launch period with no real users, so no real payment has been processed yet. The data processing agreement with Stripe and the transfer disclosures in Section 9 must be completed before the first real payment.
- Payment processing is provided by Stripe, Inc. Sponsors' card or bank details are collected directly by Stripe; NicheCollab never stores card numbers — we store only payment references (e.g. a payment identifier) and transaction metadata (amounts, currency, status).
- Creators receiving payouts onboard with Stripe (Stripe Connect), which collects the identity, tax, and bank-account information Stripe requires for its own compliance obligations (e.g. "know your customer" and anti-money-laundering checks). For that data Stripe acts as an independent controller under its own privacy policy: https://stripe.com/privacy
- Sponsor funds for a collaboration are collected when the collaboration begins and held until the collaboration is completed, then released to the creator less platform fees. Payment records are retained as required by tax and accounting law.
- A data processing agreement with Stripe and updated international-transfer disclosures will be put in place before the first real payment.
8. Transactional email
Status: email sending is live (address verification, password reset, service notifications, and the removal/correction request emails described in Section 6.3). The service is in a pre-launch period and processes no real user data.
We send service messages through our self-managed mail infrastructure hosted at OVHcloud (a mail server we operate ourselves): email-address verification, security notices, notifications about offers, collaborations, and messages, and the confirmation, acknowledgment and outcome emails for removal and correction requests. These are service communications necessary to operate your account or to handle your request, not marketing. No third-party email service provider processes your email address or message content; OVHcloud, as the underlying infrastructure host, processes data only on the servers it provides to us, under its data processing terms.
9. Where your data is stored, and international transfers
Where the service runs. NicheCollab's application, its database, and the mail server that sends our service emails all run on a single dedicated server we rent from OVHcloud in Montréal, Québec, Canada. Account, profile, offer, negotiation, message, session and email-log data is stored there.
Traffic routing. Traffic to nichecollab.com is routed through Cloudflare, Inc. (United States), which provides our DNS and acts as a reverse proxy in front of that server, processing connection data as described in Section 5. Cloudflare operates a global network, so this data may be handled at locations outside Canada.
If you are in the EEA or the UK. Your personal data is processed in Canada. The European Commission has decided that Canada offers an adequate level of protection for personal data transferred to recipients subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and the UK maintains equivalent adequacy regulations for Canada. Whether that adequacy covers this particular deployment, and which mechanism applies to data reaching the United States through Cloudflare (and through Stripe once payments are connected), is part of a transfer analysis we have not yet completed. We will state the mechanism relied on for each provider here — and put the corresponding data processing agreements in place — before the service opens to real users. Until then the service is in a pre-launch period with no real users and synthetic demonstration data.
Changes. If we move hosting or add a provider in another country, we will update this section, and where the change is material we will notify account holders as described in Section 15.
10. Retention
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account; after account deletion, only as long as needed for the purposes described in this policy |
| Session records (incl. IP address, user agent) | Deleted or anonymised within 90 days of session expiry |
| Offers, negotiation audit log, collaborations, messages | Retained while relevant to the parties' business records; negotiation and collaboration records may be retained after account deletion to the extent needed for dispute resolution and the other party's records, with your identifiers removed where feasible |
| Payment records (once live) | As required by applicable tax and accounting law |
| Creator profiles removed after a removal request | Removed from public view immediately when the removal is executed; residual profile data permanently deleted within 30 days of removal, retained in that window solely to detect and reverse fraudulent or mistaken removals. If a payment connected to the profile has not finished settling when deletion is due, deletion waits until that payment completes and then happens on the next sweep — the profile stays out of public view throughout |
| Removal/correction request records | Unconfirmed requests are deleted once the confirmation link expires, 72 hours after submission; resolved requests are kept for 24 months after resolution for accountability, then minimised (free-text content removed; the requester's email address replaced with a keyed hash). The minimised remainder — request and profile identifiers, timestamps and what was decided — is kept for as long as the related suppression record |
| Transactional email log | Deleted within 90 days of sending |
| Removal-request suppression records | Indefinitely, limited to the minimum needed to keep honoring the request |
| Administrative action records (audit log) | Kept indefinitely for accountability: who did what and why, and the identifiers of what it was done to — for a removed profile, its page name and display name, and any payment references needed to keep the money trail reconstructable |
Retention periods above are enforced by an automated sweep that runs once a day, so a record is deleted on the first sweep after its period ends (the 30-day profile deletion above is swept early enough to always land inside 30 days). Except where a period is stated above, concrete periods are an open business decision and must be fixed before launch; the criteria above are the honest current state.
11. Security
Proportionate technical and organisational measures, honestly stated: passwords are stored only as salted cryptographic hashes; session cookies are HTTP-only; all authorisation checks are enforced server-side against the session (client-supplied identity is never trusted); negotiation history is an append-only audit log; counterpart views are designed not to expose email addresses or account identifiers; access to administrative functions is role-gated. In production the service will be served exclusively over TLS/HTTPS. No system is perfectly secure; we will notify affected users and regulators of personal-data breaches as required by law (GDPR Arts. 33–34 and applicable US state breach-notification statutes).
12. Your rights
12.1 EU/UK (GDPR / UK GDPR)
You have the right to access, rectify, and erase your personal data; to restrict or object to processing (including any processing based on legitimate interests, such as unclaimed profiles); to data portability; and to withdraw consent where processing is based on consent. To exercise these rights, email [email protected]; for removal or correction of an unclaimed profile you can also use the request form described in Section 6.3. We will respond within one month (extendable by two months for complex requests, with notice). You also have the right to lodge a complaint with your local supervisory authority; in the UK, the Information Commissioner's Office.
12.2 California (CCPA/CPRA)
California residents have the right to know/access, delete, and correct personal information; the right to opt out of "sale" or "sharing" of personal information; the right to limit use of sensitive personal information; and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as defined by the CCPA, and we do not collect sensitive personal information, so no "Do Not Sell or Share" link is required at this time; if our practices change, we will provide the required links and honor opt-out preference signals such as Global Privacy Control. To exercise your rights, email [email protected]; we take reasonable steps to confirm a request comes from you — for an unclaimed profile that means clicking the confirmation link we email you (Section 6.3), and we ask for more only where something gives us genuine doubt — and respond within 45 days (extendable once by 45 days with notice). You may use an authorised agent as permitted by law.
12.3 How requests work today
Removal of a creator profile is self-serve. Submit the request form (on the profile page or the Unclaimed Profile Removal Notice page) or email [email protected], then confirm your email address from the link we send. Removal requests for unclaimed profiles are normally executed automatically once confirmed; if the profile has been claimed by an account holder, we notify the holder first, who has 14 days to confirm or contest before the removal is executed (details in the Removal Notice).
Everything else is handled manually. Correction requests ride the same form and confirmation link, but a person checks each one against the public source and applies any change — never automatically. Self-service account deletion and data export are not yet built; account deletion, access, and portability requests are handled manually via [email protected]. Note for account deletion: negotiation records involving other users may be retained as described in Section 10, and a claimed creator profile is disassociated from your account on deletion — you may request that the profile itself also be deleted, which is the default for profiles you created.
13. Children
NicheCollab is a business marketplace for users 18 or older. We do not knowingly collect personal data from anyone under 18, and unclaimed-profile ingestion will exclude accounts that identify their holder as under 18. If you believe a minor's data has been collected, contact [email protected] and we will delete it.
14. Automated decision-making and AI
Removal requests for creator profiles may be executed automatically once the requester confirms their email address (Section 6.3). Where the profile has been claimed by an account holder, the holder is notified first and can contest within 14 days — contesting always brings the request to a human for review. Beyond that, we do not perform automated decision-making that produces legal or similarly significant effects (GDPR Art. 22), and no personal data is sent to AI providers. A planned search feature may rank creator–sponsor matches algorithmically (including AI-assisted relevance scoring); ranking does not produce legal effects, and this section will be updated with specifics before that feature launches.
15. Changes to this policy
We will post changes here with an updated effective date and version history. For material changes we will give account holders reasonable advance notice (e.g. by email once transactional email exists, or by in-app notice).
16. Contact and complaints
Privacy contact: [email protected] You may complain to your data protection authority at any time (Section 12).
Early-access version. We update this policy as NicheCollab develops — see Terms of Service Section 2.