Privacy Policy

    Datenschutzerklärung · Last updated 15 July 2026

    1. Controller

    Controller within the meaning of Art. 4 (7) GDPR is:
    rawlenses media, proprietor Filip Nies
    Am Sonnenhang 20, 57223 Kreuztal, Germany
    VAT ID: DE362309606
    Email: hello@creatifs.com

    We have not appointed a statutory Data Protection Officer as the mandatory thresholds under § 38 BDSG are not met. Data-protection inquiries reach the controller directly at the address above.

    2. Categories of Data We Process

    • Account data: name, email, password hash, role, workspace membership.
    • Profile & business data: company name, VAT ID, address, IBAN, tax residency, company type.
    • Creator directory data: publicly available social handles, portfolio media, niches, and self-declared availability, collected from public sources or provided by the Creator during application.
    • Project data: briefs, quotes, contracts, signatures (with IP and user-agent), deliverables, messages.
    • Payment data: Stripe customer ID, subscription status, invoice metadata. Card details are handled by Stripe and never reach our servers.
    • Usage & log data: IP address, user-agent, timestamps, referrer, and technical error logs kept for security and abuse prevention.
    • Communications: emails you send us and email delivery events (opens, bounces) reported by our email provider.

    4. Recipients & Processors

    We share personal data only with carefully selected processors under written agreements pursuant to Art. 28 GDPR:

    • Supabase (via Lovable Cloud) — hosting, authentication, database, storage. Servers in the EU (Frankfurt).
    • Cloudflare, Inc. — CDN, DNS, DDoS protection, R2 object storage and Stream video hosting for files and media you upload. EU-US Data Privacy Framework certified.
    • Stripe Payments Europe, Ltd. (Ireland) — payment processing, Stripe Connect, Stripe Tax, subscription billing.
    • Resend — transactional and lifecycle email delivery.
    • Google Ireland Ltd. — OAuth sign-in (when you use "Continue with Google") and Google Maps / Places for location search and city autocomplete.
    • Sentry / logging providers — error monitoring, where enabled.
    • Meta Platforms Ireland — solely to fetch a Creator's own Instagram data via official APIs after that Creator has connected their account.

    Contract counterparties (Booker / Creator) receive the personal data necessary to perform the project (name, contact details, invoice data, signature). Access to project data on the Platform is enforced by row-level security.

    5. International Transfers

    Where processors act outside the EU/EEA (e.g. Cloudflare or Stripe US infrastructure), transfers rely on the EU-US Data Privacy Framework or on Standard Contractual Clauses (Art. 46 (2) (c) GDPR) with additional safeguards. Copies are available on request.

    6. Storage Periods

    • Account and profile data: for the duration of your account plus up to 30 days after deletion for backup rotation.
    • Invoices, contracts, signature audit trails, tax-relevant records: 10 years (§ 147 AO, § 257 HGB).
    • Server and security logs: up to 90 days, longer if required for incident investigation.
    • Marketing consent records: until consent is withdrawn plus 3 years to evidence lawful processing.

    7. Creator Directory (Art. 13 GDPR)

    The Creator network is invite-only and opt-in. A Creator is contacted with a personal invitation, connects their own Instagram account through Meta's official login dialog, and completes their profile themselves. Publication happens only after the Creator submits the profile and confirms publication — the legal basis is Art. 6 (1) (a) GDPR (consent).

    Before an invitation is accepted we hold nothing more than a public handle and the invitation status, in order to send and track that single invitation. Consent can be withdrawn at any time by disconnecting Instagram, deleting the profile in the account settings, or writing to hello@creatifs.com. Withdrawal immediately unpublishes the profile; remaining data is removed within 7 days of a verified request.

    8. Instagram Connection (Meta Platform Terms)

    Creators connect their Instagram account through the official Instagram API with Instagram Login (permission: instagram_business_basic). Consent is given inside Instagram's own login dialog and is the legal basis (Art. 6 (1) (a) GDPR).

    • We receive: account id, username, account type, media list (caption, media type, permalink, timestamp) and media links.
    • Instagram-sourced media stays on Meta's own content delivery network. To keep the site fast, image requests pass through our Cloudflare image proxy, which resizes them on the fly and holds them only in a temporary edge cache — we never store Instagram images or videos in our database or object storage, and cached copies expire automatically.
    • Separately, a Creator may upload their own files to their profile or workspace. Those uploads are stored by us (Cloudflare R2 / Stream) because the Creator chose to upload them; they are not Instagram data.
    • Access tokens are stored encrypted, refreshed automatically and used only to keep the connected portfolio current.
    • Disconnecting in Instagram (Settings → Apps and websites) triggers our deauthorize and data-deletion callbacks, which remove the connection, all Instagram-derived portfolio entries and unpublish the profile. You receive a confirmation code to check the status at creatifs.com/data-deletion.
    • We do not sell Instagram data, do not use it for advertising or profiling, and do not share it with third parties.

    10. Your Rights

    Under the GDPR you have the right to:

    • access your personal data (Art. 15);
    • rectification (Art. 16);
    • erasure ("right to be forgotten", Art. 17), subject to statutory retention;
    • restriction of processing (Art. 18);
    • data portability (Art. 20);
    • object to processing based on Art. 6 (1) (f) at any time (Art. 21);
    • withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7 (3));
    • lodge a complaint with a supervisory authority — for us the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf.

    Signed-in users can exercise the rights of access and portability directly in the app: open your account settings and choose Download my data to receive a machine-readable copy of everything we store about your account. The same screen lets you delete your account permanently.

    Requests: hello@creatifs.com. See also our Data Deletion instructions.

    11. Cookies & Similar Technologies

    Browsing créatifs works without consent. Strictly necessary cookies and local storage cover authentication, session security and remembering your cookie choice (§ 25 (2) TTDSG — no consent required). Fonts are served from our own servers, post thumbnails are proxied through our own image domain (img.creatifs.com), and the map basemap tiles set no cookies, so all of that is shown to everyone. Payment processing (Stripe) and file delivery are necessary for the performance of our contract.

    The only content that requires your consent is an embedded Instagram post: opening one loads a frame from instagram.com, which lets Meta set its own cookies and receive your IP address. We ask before that frame loads and you can always open the post on Instagram instead. Address autocomplete contacts Google Maps only once you start typing into an address field. We do not run advertising or cross-site tracking cookies; should that change, they would likewise load only after explicit consent. You can change your choice at any time by clearing site data in your browser.

    12. Automated Decision-Making

    We use algorithmic search and ranking to display Creators, but we do not carry out automated decision-making within the meaning of Art. 22 GDPR that produces legal effects for you.

    13. Security

    We apply appropriate technical and organisational measures under Art. 32 GDPR: TLS in transit, encryption at rest for storage buckets, row-level security in the database, principle of least privilege for staff access, and audited third-party processors. No system is fully secure — we cannot guarantee that unauthorised access will never occur, but we treat every incident with priority and notify affected users and authorities where legally required.

    14. Changes to this Notice

    We update this Privacy Policy when our processing changes. Material updates are announced by email or in-app notice. The current version is always available at creatifs.com/data-protection.