Legal documentation

Privacy Policy

Effective Date: August 23, 2026 · Version 5.0

This Privacy Policy describes the data handling and privacy safeguards governing CollabBase accounts, connected platforms, campaign operations, and creator information.

Section 1.0

Scope and Acceptance

This Privacy Policy governs the collection, processing, storage, and disclosure of personal data and workspace information by CollabBase ('Company', 'we', 'us', or 'our') through our web application, discovery services, and associated APIs (collectively, the 'Service'). By registering for, accessing, or using the Service, you ('User', 'Customer', or 'Workspace Administrator') acknowledge that you have read and understood the data practices described here.

Section 2.0

Information Collected

We process account, authentication, billing, search, campaign, sender-identity, compliance, messaging, and security information. When a person connects an account, we may receive encrypted OAuth credentials and the account identifiers, profile fields, statistics, recent content, messages, or commerce data that person authorizes the provider to disclose. Our creator catalog can also include public profile information, public content and business contact pages, customer-supplied corrections, and licensed provider data.

Section 3.0

Connected Google and YouTube Data

A workspace may connect Google to send creator-partnership email from its own account. If the workspace separately enables Gmail inbox synchronization, CollabBase reads only Gmail conversation threads created by CollabBase outreach and stores bounded, sanitized plain-text message content and minimum headers so authorized workspace members can view replies, reply, stop follow-ups, and update campaign workflow. CollabBase does not import unrelated mailbox threads, attachments, or raw HTML. A creator may separately connect YouTube so CollabBase can verify the linked channel and display authorized profile, channel, audience, analytics, and recent-content information. CollabBase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, used to determine creditworthiness, or used to train a generalized artificial-intelligence model.

Section 4.0

Instagram and TikTok Connections

A creator may connect Instagram or TikTok to verify control of at least one professional profile and allow CollabBase to display the profile, statistics, insights, and recent content that the provider authorizes. A brand may separately connect an eligible Instagram professional account or TikTok Business account for read-only inbound conversation synchronization. This lets CollabBase import replies to the brand's creator-outreach conversations into the central inbox and update campaign workflow. The optional browser helper does not silently send social messages. It may open a social profile, fill a proposed message, and observe the user's own explicit Send action. Official provider APIs and webhooks, rather than inbox-preview inference, are used for reply import when a connected account and provider access support it.

Section 5.0

Chrome Helper and Stripe Affiliate Data

The optional CollabBase Chrome helper operates only on the listed CollabBase, Instagram, and TikTok pages needed for assisted outreach. It stores bounded task state, does not collect general browsing history, and does not click Send. A workspace may connect Stripe to create and measure creator-linked promotion codes and affiliate performance. CollabBase stores the connected account identifier, encrypted authorization material, promotion-code attribution, and bounded sales and revenue statistics required for that feature.

Section 6.0

Purpose of Data Processing and Automated Assistance

We use data to provide discovery and campaign tools, facilitate user-authorized outreach and conversations, enforce search limits and sender health, detect replies, opt-out requests, and delivery failures, classify reply intent for campaign workflow automation, verify connected creator profiles, measure campaign or affiliate performance, secure the Service, bill customers, and respond to privacy requests. Reply classification uses a contracted paid AI processing service with bounded sanitized text. Message bodies and prompts are excluded from application logs and are not used by CollabBase to train a general-purpose model. Classification can suggest or apply workflow states such as replied, negotiating, or awaiting content; authorized users can review and correct those states. A batch requires deliberate user authorization before its individual messages are delivered durably and at paced intervals. CollabBase does not start an outreach campaign without that authorization.

Section 7.0

Data Security and Retention Safeguards

We use administrative and technical safeguards designed to protect data integrity and confidentiality. Data in transit is protected with modern TLS. Sensitive credentials, OAuth tokens, and synchronized inbox message content are encrypted at the application layer before storage. Access is limited by authenticated workspace and creator authorization. Gmail synchronization excludes unrelated threads, attachments, raw HTML, and oversized content. Automated classification receives only the newest authored text after quoted history and signatures are removed. Message bodies, OAuth tokens, and AI prompts are excluded from operational logs. Provider data is retained only while needed for the connected feature, the published retention period, or a documented security, legal, accounting, or suppression obligation. Revocation, disconnection, verified deletion, and provider-specific lifecycle rules may require earlier deletion or revalidation. Backup copies age out under the backup-retention schedule and are not restored into active use after a verified deletion.

Section 8.0

Third-Party Data Disclosures

We do not sell Google user data or customer workspace search history. Creator discovery and contact-unlock features may make public or licensed creator information available to customers, which some jurisdictions may classify as sale, sharing, licensing, or data brokering. We disclose only the data necessary to providers that support hosting, database, analytics, authentication, mail, platform connections, AI-assisted classification, billing, and security under contractual controls, and when law requires it.

Section 9.0

Data Subject Rights (GDPR & CCPA)

Depending on location, people may request access, correction, deletion, portability, restriction, or an opt-out from sale or sharing. Use the public Creator Privacy & Data Rights form or contact the privacy office. We verify identity before disclosing or changing data. A connected user can disconnect a provider account in CollabBase and can also revoke access in that provider's account settings. An ordinary reply asking one business not to contact you creates a non-expiring preference scoped to that business; it does not prevent unrelated businesses from independently contacting you. A verified request directed to CollabBase can create a catalog-wide restriction or deletion obligation. We retain the minimum request and suppression evidence needed to prove and honor the request.