DRAFT — pending legal review
This document has not yet been reviewed by counsel and may change before publication.
NicheCollab Privacy Policy
DRAFT — NOT REVIEWED BY COUNSEL Draft v0.1 · 2026-08-01 · Prepared from a code audit of the NicheCollab repository. Do not publish until reviewed by qualified privacy counsel and all
[BRACKETED]placeholders are resolved. Sections marked [FORWARD-LOOKING — FEATURE NOT YET LIVE] describe planned functionality that does not process any personal data today; they must be re-verified against the shipped implementation before those features launch.
Effective date: [EFFECTIVE DATE — set at publication] Who we are: NicheCollab, operated by [ENTITY NAME/JURISDICTION TBD] ("NicheCollab", "we", "us"). Contact: [email protected] Postal address: [ENTITY ADDRESS TBD]
This policy is written to satisfy the transparency requirements of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). The operator's place of establishment is not yet decided; the applicable-law analysis, EU/UK representative requirements (GDPR Art. 27), and supervisory-authority designation must be completed by counsel once the entity and hosting locations are fixed.
1. Summary (plain language)
- NicheCollab is a marketplace where sponsors (brands) and creators (influencers) find each other, negotiate offers, and run collaborations.
- We collect what you give us when you sign up and use the marketplace: your name, email, password (stored only as a cryptographic hash), your profile details, and the content of your offers, negotiations, and messages.
- We automatically record limited technical data for security: the IP address and browser information attached to your login sessions.
- We use one strictly necessary cookie to keep you signed in. We use no advertising, analytics, or tracking cookies.
- We do not sell or share your personal information for advertising, and we do not use it to train AI models.
- Planned features (payments via Stripe, transactional email, and creator directory profiles built from publicly available information) will process additional data. Those sections below are clearly marked as not yet live, and this policy will be updated when they launch.
2. Scope
This policy covers personal data processed through the NicheCollab web application and related support channels. It covers both account holders (sponsors and creators who sign up) and, once the relevant feature launches, individuals who do not have an account but appear in unclaimed creator profiles (see Section 6).
For data you provide about other people inside offers, negotiations, and messages, you are responsible for having the right to share it.
3. Personal data we collect today
3.1 Data you provide directly
| Category | Data | When |
|---|---|---|
| Account data | Name, email address, password (stored as a salted cryptographic hash — we never store or can read your plaintext password) | Sign-up |
| Creator profile | Display name, niche/category; and where you choose to add them: bio, avatar image URL, social platform handles and links, audience size, engagement rate, city and country | Onboarding and profile editing |
| Sponsor profile | Company name; and where you choose to add them: website, industry, logo URL | Onboarding and profile editing |
| Offer and negotiation content | Offer titles and descriptions, proposed budgets and currency, deliverables, timelines, and any message text you include with an offer, counter-offer, acceptance, or decline | Sending or responding to offers |
| Messages | Message text sent within a collaboration thread, and read timestamps (messaging is scoped to active collaborations) | Messaging (feature in development) |
3.2 Data collected automatically
| Category | Data | Purpose |
|---|---|---|
| Session security data | IP address, browser user-agent string, session creation/expiry timestamps, and a session token | Keeping you signed in; detecting account compromise and abuse |
| Negotiation audit log | An append-only record of every offer event (who acted, what changed, when) | Integrity of negotiations; dispute resolution; fraud prevention |
We do not collect device fingerprints, precise location, or behavioural analytics, and we do not run session-replay, advertising pixels, or third-party analytics scripts.
3.3 Cookies
We set a single strictly necessary authentication cookie (an HTTP-only session cookie) so you stay signed in. It is not used for advertising or analytics and is deleted or expires when your session ends. Because we use only strictly necessary cookies, no cookie-consent banner is presented. If we ever add non-essential cookies or similar technologies, we will update this policy and obtain any consent required before setting them.
3.4 Data we do not collect
We do not knowingly collect special-category data (GDPR Art. 9) or "sensitive personal information" as defined by the CCPA. We do not collect payment card details today (see Section 7 for planned payments — card details will be collected by Stripe, never stored by us).
4. Purposes and legal bases (GDPR / UK GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account; providing the marketplace (search, offers, negotiations, collaborations, messaging) | Account, profile, offer/negotiation, and message data | Contract performance — Art. 6(1)(b) |
| Keeping the service secure: session management, abuse and fraud detection, rate limiting | Session security data, negotiation audit log | Legitimate interests — Art. 6(1)(f) (security and integrity of the platform) |
| Maintaining a truthful record of negotiations and resolving disputes between users | Negotiation audit log, offer/negotiation content | Legitimate interests — Art. 6(1)(f); and contract performance |
| Complying with legal obligations (e.g. responding to lawful requests, tax and accounting once payments launch) | The minimum data required | Legal obligation — Art. 6(1)(c) |
| Service emails about your account and transactions (see Section 8) | Email address, name | Contract performance — Art. 6(1)(b) |
| Marketing communications | — | We do not send marketing communications today. If introduced, they will be consent-based (Art. 6(1)(a)) with a working unsubscribe. |
| Unclaimed creator directory profiles | See Section 6 | Legitimate interests — Art. 6(1)(f); analysis in Section 6 [needs counsel review] |
5. Who receives your data
Today, no third party receives your personal data in the ordinary operation of the service. The application currently runs without third-party analytics, advertising, error-tracking, email, or payment integrations that transmit personal data.
- Hosting: [HOSTING PROVIDER AND REGION TBD — must be completed before launch; this determines international-transfer disclosures.]
- Payment processing: Stripe — [FORWARD-LOOKING — FEATURE NOT YET LIVE], see Section 7.
- Email delivery: our self-managed mail infrastructure hosted at OVHcloud — we operate the mail server ourselves; no third-party email service provider processes your messages. OVHcloud provides the underlying server infrastructure. See Section 8.
- Other users: your profile is visible to other users of the marketplace (creator profiles are publicly viewable). The other party to an offer or collaboration sees your display name / company name and the negotiation content — by design, counterpart views do not expose your email address or internal account identifiers.
- Administrators: NicheCollab administrators can view marketplace content, including offers and collaboration messages, for trust-and-safety, moderation, and dispute-resolution purposes.
- Legal: we may disclose data where required by law or to protect rights, safety, or the integrity of the service.
We will maintain a current list of sub-processors at [SUB-PROCESSOR LIST URL TBD] once third-party processors are engaged.
6. Unclaimed creator profiles built from public information — [FORWARD-LOOKING — FEATURE NOT YET LIVE]
Status: the product design includes "unclaimed" creator profiles compiled from publicly available information about creators who have not signed up. No such profiles containing real people's data exist today — all current unclaimed profiles are synthetic demonstration data that do not correspond to real individuals. This section discloses the planned practice so the policy does not under-disclose when ingestion ships. It must be re-verified, and the assessment below completed and documented, before any real-person profile is published. [needs counsel review]
6.1 What these profiles will contain
Publicly available, professionally oriented information: display name or public handle, social platform handles and links, follower counts, engagement metrics, content niche, public bio text, public avatar image, and approximate location (city/country) where publicly stated. Sources: public creator pages on social platforms and other public sources; each profile records its data provenance. We will not ingest special-category data (e.g. health, religion, political opinions, sexual orientation), private or leaked data, or data about children.
6.2 Lawful basis: legitimate interests (GDPR Art. 6(1)(f)) — draft analysis
- Purpose test: NicheCollab and its sponsor users have a legitimate commercial interest in a discovery directory of professional creators open to sponsorship — comparable to established professional-directory and talent-discovery services. Creators may also benefit from sponsorship opportunities surfaced to them.
- Necessity test: the directory cannot serve its discovery function if limited to already-registered creators at launch; the data used is minimised to public, professional/commercial facts needed for sponsor search.
- Balancing test — safeguards in place or committed:
- only publicly available, professional-context information is used; no special-category data;
- every unclaimed profile is persistently and prominently labeled as built from public information, with an explicit statement that the person has not joined or endorsed NicheCollab;
- unclaimed profiles carry
noindexdirectives so search engines do not amplify them; - offers sent to unclaimed profiles are not delivered to the person; they are held privately and surface only if the person later claims the profile;
- a free, simple removal process is available without creating an account (see our Unclaimed Profile Removal Notice), and removal requests are honored as objections under GDPR Art. 21;
- claimed profiles always rank above unclaimed profiles in search.
- Transparency (Art. 14): because the data is not collected from the data subject, Art. 14 notice duties apply. The intended approach — public notice via this policy and the on-profile banner, plus direct notification where contact is practicable, or reliance on the Art. 14(5)(b) disproportionate-effort exemption with documented reasoning — is a legal judgment that must be made by counsel before ingestion launches, and a Legitimate Interests Assessment (LIA) and, if indicated, a DPIA must be completed and documented.
6.3 Your rights if a profile is about you
If an unclaimed profile describes you, you may — without creating an account — request its correction or removal, object to the processing, or exercise any of the rights in Section 12. See the Unclaimed Profile Removal Notice for the fastest route. If you request removal, we will keep a minimal suppression record (e.g. platform handle) solely to prevent your profile from being re-created by future ingestion; we consider this our legitimate interest in honoring your objection durably. [needs counsel review]
7. Payments via Stripe — [FORWARD-LOOKING — FEATURE NOT YET LIVE]
Status: the Stripe SDK is integrated but no payment flows exist and no payment data is collected or transmitted today.
When payments launch:
- Payment processing will be provided by Stripe, Inc. Sponsors' card or bank details will be collected directly by Stripe; NicheCollab will never store card numbers — we will store only payment references (e.g. a payment identifier) and transaction metadata (amounts, currency, status).
- Creators receiving payouts will onboard with Stripe (Stripe Connect), which will collect the identity, tax, and bank-account information Stripe requires for its own compliance obligations (e.g. "know your customer" and anti-money-laundering checks). For that data Stripe acts as an independent controller under its own privacy policy: https://stripe.com/privacy
- Sponsor funds for a collaboration are collected when the collaboration begins and held until the collaboration is completed, then released to the creator less platform fees. Payment records will be retained as required by tax and accounting law.
- A data processing agreement with Stripe and updated international-transfer disclosures will be put in place before launch. [operational prerequisite]
8. Transactional email — [FORWARD-LOOKING — FEATURE NOT YET LIVE]
Status: implemented, not yet in production — the service has not launched and processes no real user data. Email sending (address verification, password reset, and service notifications) exists in the codebase and operates through the infrastructure described below; this section must be re-verified at launch per the draft note above.
We send service messages through our self-managed mail infrastructure hosted at OVHcloud (a mail server we operate ourselves): email-address verification, security notices, and notifications about offers, collaborations, and messages. These are service communications necessary to operate your account, not marketing. No third-party email service provider processes your email address or message content; OVHcloud, as the underlying infrastructure host, processes data only on the servers it provides to us, under its data processing terms. [operational prerequisite]
9. International transfers
Today the service is not publicly deployed and no cross-border disclosures to third parties occur. Before launch, once hosting and processor locations are fixed, this section must disclose: the countries where data is stored and processed, and the transfer mechanism relied on for any transfer of EU/UK personal data to third countries (adequacy decision, Standard Contractual Clauses, UK IDTA/Addendum, or EU–US Data Privacy Framework certification of the recipient). [TBD — blocked on hosting/entity decisions; needs counsel review]
10. Retention
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account, then [RETENTION PERIOD TBD] after deletion |
| Session records (incl. IP address, user agent) | [RETENTION PERIOD TBD — recommend: deleted or anonymised within 90 days of session expiry] |
| Offers, negotiation audit log, collaborations, messages | Retained while relevant to the parties' business records; [RETENTION PERIOD TBD] — negotiation and collaboration records may be retained after account deletion to the extent needed for dispute resolution and the other party's records, with your identifiers removed where feasible |
| Payment records (once live) | As required by applicable tax and accounting law |
| Removal-request suppression records | Indefinitely, limited to the minimum needed to keep honoring the request |
Concrete periods are an open business decision and must be fixed before launch; the criteria above are the honest current state.
11. Security
Proportionate technical and organisational measures, honestly stated: passwords are stored only as salted cryptographic hashes; session cookies are HTTP-only; all authorisation checks are enforced server-side against the session (client-supplied identity is never trusted); negotiation history is an append-only audit log; counterpart views are designed not to expose email addresses or account identifiers; access to administrative functions is role-gated. In production the service will be served exclusively over TLS/HTTPS. No system is perfectly secure; we will notify affected users and regulators of personal-data breaches as required by law (GDPR Arts. 33–34 and applicable US state breach-notification statutes).
12. Your rights
12.1 EU/UK (GDPR / UK GDPR)
You have the right to access, rectify, and erase your personal data; to restrict or object to processing (including any processing based on legitimate interests, such as unclaimed profiles); to data portability; and to withdraw consent where processing is based on consent. To exercise these rights, email [email protected]. We will respond within one month (extendable by two months for complex requests, with notice). You also have the right to lodge a complaint with your supervisory authority ([LEAD SUPERVISORY AUTHORITY TBD — depends on establishment] or your local authority; in the UK, the Information Commissioner's Office).
12.2 California (CCPA/CPRA)
California residents have the right to know/access, delete, and correct personal information; the right to opt out of "sale" or "sharing" of personal information; the right to limit use of sensitive personal information; and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as defined by the CCPA, and we do not collect sensitive personal information, so no "Do Not Sell or Share" link is required at this time; if our practices change, we will provide the required links and honor opt-out preference signals such as Global Privacy Control. To exercise your rights, email [email protected]; we will verify your request and respond within 45 days (extendable once by 45 days with notice). You may use an authorised agent as permitted by law.
12.3 How requests work today
Self-service account deletion and data export are not yet built. Until they are, all requests are handled manually via [email protected]. Note for account deletion: negotiation records involving other users may be retained as described in Section 10, and a claimed creator profile is disassociated from your account on deletion — you may request that the profile itself also be deleted, which is the default for profiles you created. [The deletion workflow must be defined and tested before launch — see gap report.]
13. Children
NicheCollab is a business marketplace for users 18 or older. We do not knowingly collect personal data from anyone under 18, and unclaimed-profile ingestion will exclude accounts that identify their holder as under 18. If you believe a minor's data has been collected, contact [email protected] and we will delete it.
14. Automated decision-making and AI
We do not currently perform automated decision-making that produces legal or similarly significant effects (GDPR Art. 22), and no personal data is sent to AI providers. A planned search feature may rank creator–sponsor matches algorithmically (including AI-assisted relevance scoring); ranking does not produce legal effects, and this section will be updated with specifics before that feature launches. [FORWARD-LOOKING]
15. Changes to this policy
We will post changes here with an updated effective date and version history. For material changes we will give account holders reasonable advance notice (e.g. by email once transactional email exists, or by in-app notice).
16. Contact and complaints
Privacy contact: [email protected] · [ENTITY NAME/JURISDICTION TBD] · [ENTITY ADDRESS TBD] EU representative (if required under GDPR Art. 27): [TBD] · UK representative (if required): [TBD] You may complain to your data protection authority at any time (Section 12).
This document is a working draft produced by a privacy-engineering audit of the codebase. It is not legal advice and has not been reviewed by counsel. It must not be published in this form.