Transparency
Data Safety
This page mirrors the disclosure we submit to Google Play's Data Safety form, so you can see exactly what data Creatora collects, why we collect it, who it's shared with, and how you can delete it. For full legal detail see our Privacy Policy.
At a glance
- Does Creatora collect or share user data? — Yes (only what's needed to run the marketplace)
- Is your data encrypted in transit? — Yes (HTTPS/TLS for all traffic)
- Can you request that your data be deleted? — Yes — full account at /account-deletion, or specific categories from your in-app Data Requests page.
- Is the app directed to children? — No (18+ only)
- Independently audited against a global security standard? — No
Personal info
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| Name | Yes | No | Required | Account management, App functionality |
| Email address | Yes | No | Required | Account management, App functionality, Communications |
| User IDs | Yes | No | Required | Account management, App functionality, Analytics, Fraud prevention |
| Phone number | Yes | No | Optional | Account management, Fraud prevention |
| Address | Yes | No | Optional | Compliance (GST invoicing), Payouts |
| Other info (KYC: PAN, GSTIN, ID doc) | Yes | Yes | Optional | Compliance with law, Fraud prevention (shared with KYC verification provider & payment gateway) |
Financial info
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| User payment info (bank/UPI for payouts) | Yes | Yes | Optional | App functionality (shared with payment gateway — Razorpay/Stripe). Full card/bank credentials are never seen by Creatora. |
| Purchase history (wallet deposits, deals, payouts) | Yes | No | Required | App functionality, Compliance (8-yr financial records) |
Messages
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| In-app messages (chat between brand & creator) | Yes | No | Required | App functionality |
Photos and videos
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| Photos (avatar, portfolio, campaign cover, submissions) | Yes | No | Optional | App functionality, Personalization |
| Videos (portfolio, submissions) | Yes | No | Optional | App functionality |
Files and docs
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| Files and docs (chat attachments, KYC docs) | Yes | Yes | Optional | App functionality; KYC docs shared with verification provider only |
App activity
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| App interactions (taps, page views, deal events) | Yes | No | Required | Analytics, App functionality |
| In-app search history | No | No | — | — |
| Other user-generated content (reviews, reports, campaigns) | Yes | No | Required | App functionality |
App info and performance
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| Crash logs | Yes | No | Required | Analytics, App functionality |
| Diagnostics | Yes | No | Required | Analytics, App functionality |
| Other app performance data | Yes | No | Required | Analytics |
Device or other IDs
| Data type | Collected | Shared | Optional? | Purposes |
|---|---|---|---|---|
| Device or other IDs (push token, session) | Yes | No | Required | App functionality (push notifications), Fraud prevention |
Explicitly NOT collected
Mark these No in Data Safety:
- Approximate or precise location
- Race or ethnicity, political/religious beliefs, sexual orientation
- Contacts, calendar, SMS, call logs, emails on device
- Health, fitness, web browsing history outside the app
- Audio recordings, music files, voice/sound recordings
- Installed apps inventory
- Credit/debit card numbers, bank credentials (handled solely by payment gateway)
Third parties data is shared with
- Supabase Inc. — backend host (database, auth, storage). Hosted on AWS
ap-south-1. Acts as a data processor, not a separate controller — Play treats this as "processing on our behalf", not "shared". - Google (Sign-In / OAuth) — receives auth request, returns name/email/picture. User-initiated.
- Firebase Cloud Messaging / APNs / Web Push — delivers push notifications (device token only).
- Razorpay / Stripe — payment gateway. Receives payment instrument data directly; Creatora never stores card/bank credentials.
- KYC verification provider — receives PAN/GSTIN/ID doc only when creator opts in for payouts.
Security practices to declare
- Data is encrypted in transit (TLS 1.2+).
- Users can request their data be deleted (full account at /account-deletion, or partial categories via in-app Data Requests).
- Follows Google Play's Families Policy: No (app is 18+).
- Committed to Play's Developer Distribution Agreement & Families Policy as applicable.
Questions about your data? Email privacy@creatora.in or visit our contact page.