1. Introduction & Scope
CreatorOPS ("we," "us," or "our") operates a software-as-a-service platform for digital creators and media agencies to manage sponsor relationships, production workflows, and cross-platform analytics. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you access our website, application, or related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, do not use the Service.
2. Information We Collect
We collect the following categories of information:
Account and profile data
Name, email address, organization name, role, password hash, profile preferences, and workspace configuration settings you provide during registration or account management.
Billing and subscription data
Subscription tier, billing history, and payment method metadata. Full payment card numbers are processed by Stripe and are not stored on our servers.
Creator and business content
Sponsor deal records, deliverable schedules, invoice statuses, uploaded assets, approval comments, and production pipeline data you enter or sync into the Service.
Usage and technical data
IP address, browser type, device identifiers, operating system, access timestamps, pages viewed, feature usage events, error logs, and diagnostic data collected automatically when you interact with the Service.
Communications
Support tickets, email correspondence, feedback submissions, and in-app messages you send to us or other workspace members.
3. YouTube API Services
When you connect a YouTube channel, CreatorOPS accesses data through Google YouTube API Services subject to the YouTube Terms of Service and the Google Privacy Policy.
Data we may access includes:
- Channel metadata (name, subscriber count, branding)
- Video and playlist statistics (views, watch time, engagement metrics)
- Revenue and monetization summaries where authorized by your Google account
- OAuth tokens required to maintain the integration
We use this data solely to display normalized analytics in your CreatorOPS dashboard, track content performance against sponsor deliverables, and maintain the integration. We do not sell YouTube API data to third parties.
You may revoke CreatorOPS access at any time through your Google Account permissions page or by disconnecting the integration in your workspace settings. Upon revocation, we delete associated OAuth tokens within 30 days and cease fetching new data.
4. Twitch Integration
When you authorize Twitch, we receive OAuth access and refresh tokens scoped to the permissions you grant during the authorization flow. Typical scopes include channel information, stream statistics, follower counts, and clip/video metadata needed for analytics aggregation.
We use Twitch data to:
- Display live and VOD performance metrics in your unified dashboard
- Correlate stream activity with sponsor deliverable deadlines
- Generate cross-platform reports for your team or agency clients
Twitch tokens are encrypted at rest and transmitted over TLS. You may revoke access through your Twitch Connections settings or by disconnecting Twitch in CreatorOPS. Revoked tokens are invalidated immediately on our end.
5. TikTok & Other Platform APIs
TikTok and additional platform integrations (where available) follow the same principles: we access only the data scopes you authorize, normalize metrics into a consistent schema, and store the minimum data required to power dashboard features.
Normalized analytics may include:
- View counts, engagement rates, and audience retention summaries
- Content publish dates and platform-specific identifiers
- Growth trends aggregated across connected accounts
Raw API responses used for normalization are retained for up to 90 days for debugging and reconciliation, then deleted or aggregated into summary records.
6. How We Use Your Data
We use collected information to:
- Provide, operate, and maintain the Service
- Authenticate users and enforce workspace access controls
- Aggregate analytics across connected platforms into a single view
- Track sponsor deliverable status and invoicing workflows
- Process subscription payments and send billing notifications
- Respond to support requests and communicate product updates
- Detect, prevent, and address fraud, abuse, and security incidents
- Improve the Service through aggregated, de-identified usage analysis
We do not use your content or platform data to train third-party machine learning models without your explicit consent.
8. Payment Processing (Stripe)
Subscription payments are processed by Stripe, Inc. When you subscribe, you provide payment information directly to Stripe. CreatorOPS receives only:
- A Stripe customer identifier linked to your account
- Payment method type and last four digits of your card
- Subscription status, invoice amounts, and billing period dates
Stripe's handling of your payment data is governed by the Stripe Privacy Policy. We do not store full credit card numbers, CVV codes, or bank account numbers on our infrastructure.
9. Data Sharing & Subprocessors
We may share information with:
- Service providers — cloud hosting, email delivery, customer support tools, and analytics providers bound by data processing agreements
- Platform APIs — only as required to maintain integrations you authorize
- Legal authorities — when required by law, court order, or to protect rights, safety, and security
- Business transfers — in connection with a merger, acquisition, or sale of assets, with notice to affected users
We do not sell personal information. We do not share sponsor deal data or analytics with advertisers or data brokers.
10. Data Retention & Deletion
We retain account data for as long as your subscription is active. After account closure, we delete or anonymize personal data within 90 days, except where retention is required for legal, tax, or fraud-prevention obligations.
Platform OAuth tokens are deleted upon integration disconnect or account deletion. Aggregated analytics summaries may be retained in de-identified form for product improvement.
You may request deletion of your account and associated data by contacting privacy@creatorops.io.
11. Security Measures
We implement industry-standard safeguards including TLS encryption in transit, encryption at rest for sensitive fields, role-based access controls, multi-factor authentication options, and regular security assessments.
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at security@creatorops.io.
12. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data, subject to legal retention requirements
- Export your workspace data in a portable format
- Object to or restrict certain processing activities
- Withdraw consent for optional data processing
To exercise these rights, email privacy@creatorops.io. We respond within 30 days. EU/UK residents may lodge complaints with their local data protection authority.
13. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it promptly.
14. International Transfers
CreatorOPS is operated from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US or other countries where our subprocessors operate. We use standard contractual clauses and appropriate safeguards for cross-border transfers as required by applicable law.
15. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notice at least 14 days before taking effect. Continued use after the effective date constitutes acceptance of the revised policy.
16. Contact
For privacy-related inquiries:
- Email: privacy@creatorops.io
- Data protection requests: dpo@creatorops.io