Skip to content

Privacy notice

Your data, explained clearly.

This notice explains what personal data Collabory processes, why we process it, who receives it, and the choices and rights available to you.

Last updated: 16 July 2026

1. Who is responsible

Collabory
[Legal address required before production launch]
Organisation number: [Organisation number required before production launch]
Register: [Company register required before production launch]
VAT status: [VAT status required before production launch]
Email: contact.collabory@gmail.com

Collabory is the controller for account, product, support, safety, and website data described here. Creator and brand users remain responsible for personal data they independently place in campaign briefs, messages, agreements, and delivery records.

2. Data we process and why

DataPurposeLegal basis
Account identity, email, role, authentication and security eventsCreate and secure accounts, authenticate users, recover access, and prevent abuse.Performance of the service agreement; legitimate interests in service security; legal obligations where applicable.
Creator or brand profile fields, including profile image, handle, bio, platform and audience informationProvide profiles, creator discovery, and collaboration matching.Performance of the service agreement. You choose which optional profile details to provide.
Campaigns, applications, messages, deal terms, checklists, delivery links, feedback and activity recordsRun and document collaborations, deliver messages, resolve support or safety issues, and maintain an audit trail.Performance of the service agreement; legitimate interests in reliable records, safety, fraud prevention, and dispute handling.
Billing and payout identifiers and transaction statusProvide paid plans or payout connectivity when enabled, meet accounting duties, and handle billing support.Performance of a contract and legal obligations.
Contact-form details and correspondenceAnswer sales, support, privacy, press, partnership, payout, and safety requests.Steps requested before a contract or performance of a contract; legitimate interests in responding; legal obligations for rights requests.
IP-derived security signals, rate-limit counters, signed session state, and authenticated presenceProtect endpoints, keep sessions working, diagnose availability, and show authorized administrators an aggregated live-service view.Legitimate interests in security and reliable service operation.

3. What other users can see

  • Logged-in brands can see creator profile fields made available in creator discovery.
  • Relevant participants and authorized administrators can see collaboration messages, deal records, and delivery information.
  • Profile images currently use public storage URLs. Anyone who obtains the exact URL may be able to open that image, even though Collabory does not list private workspace content publicly.
  • Collabory does not sell personal data.

4. Service providers and recipients

Collabory uses providers only for defined service purposes. Current code supports Supabase for database, authentication and profile-image storage; Vercel for hosting and server functions; Resend for transactional and contact email; Google for optional sign-in and hosted fonts; and Gmail as the configured contact inbox. Stripe is used only when billing or payout connectivity is enabled. Upstash may be used for rate limiting when configured. Brands, creators, professional advisers, public authorities, or transaction counterparties receive data only where the service, law, safety, or a corporate transaction requires it.

Provider availability and deployment regions can change. You may request the current processor list through the contact form under Privacy.

5. International transfers

Some providers may process data outside Norway or the EEA. Before a restricted transfer, Collabory requires an applicable safeguard such as an adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary measures where required.

6. How long data is kept

  • Account and workspace data is kept while the account is active and afterwards only as needed to complete deletion, resolve disputes, protect the service, or meet legal duties.
  • Signed browser sessions expire after seven days; short-lived OAuth, recovery, and email-change state expires after ten minutes.
  • Rate-limit and security records are retained according to the relevant abuse-prevention window and operational need.
  • Authenticated live-presence rows fall out of the live summary after 90 seconds; database cleanup and provider backups follow operational retention schedules.
  • Billing and transaction records are retained for the period required by accounting, tax, and anti-fraud law.
  • Backups are overwritten on provider schedules. Data may remain in a backup until that backup expires, while access remains restricted.

7. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where consent is used. Collabory does not currently use optional analytics or marketing cookies and does not make solely automated decisions that produce legal or similarly significant effects.

Submit a request through the contact form with topic Privacy. We may need to verify identity. You may complain to Datatilsynet or another competent supervisory authority.

8. Security and changes

Collabory uses HTTPS, signed HTTP-only session cookies, role checks, rate limiting, restricted server credentials, database access controls, and audit records. No online service can promise absolute security. Material changes to this notice will be communicated in an appropriate way before they take effect.

Privacy contact

Use the Privacy contact route or email contact.collabory@gmail.com. Privacy notice version: 2026-07-16.