1. Scope
This Privacy Policy explains how VeroKit collects, uses, discloses, and protects personal information when you visit VeroKit, create an account, appear in a public creator profile, use a workspace, communicate with us, or participate in a transaction.
It applies to creators, brands, agencies, team members, clients, contacts, visitors, and other people whose information is processed through the Service.
2. Information we collect
Depending on how you use VeroKit, we may process:
- Account and profile information: name, email, company, role, phone, profile photo, logo, biography, location, website, preferences, and authentication identifiers;
- Creator and social information: public handles, platforms, content, audience and performance metrics, media-kit settings, rates, packages, and public profile information;
- Business and CRM information: clients, contacts, notes, activities, opportunities, campaigns, project terms, deadlines, tasks, costs, invoices, payment status, and reports;
- Transaction and support information: orders, agreements, approvals, files, messages, reviews, disputes, notifications, and support requests; and
- Technical information: IP address, device and browser information, session cookies, security logs, page interactions, referral information, and timestamps.
3. Where information comes from
We receive information directly from users, from public social and web sources, from transaction counterparties, from authorized service providers and integrations, and automatically when people use the Service.
A brand or agency may add a creator to its relationship workspace. A creator may add a brand contact or outside project to creator CRM. If another user adds your information, that user is responsible for having authority or another lawful basis to do so.
4. Sensitive information VeroKit does not request
VeroKit’s public-data workflow does not ask for or store creator social-media passwords and does not use them to post content. Complete payment-card and bank-account numbers are collected and handled by Stripe, not stored by VeroKit.
Do not place passwords, government identification, full financial-account details, health information, or other unnecessary sensitive data in CRM notes, briefs, messages, invoices, or uploads.
5. Public creator data
Creator profiles and insights may use information already public on social networks or the open web, as well as information provided by creators and data providers. Public availability does not remove privacy responsibilities. We use this information to create media kits, discovery results, analytics, rate-range estimates, campaign-fit signals, reporting, and marketplace context.
The first Brand or Agency search for a public creator may create one deduplicated, unclaimed profile and a prospect record. An unclaimed profile is non-bookable, does not publish creator-set pricing, and is marked not to be indexed by search engines. Ownership is granted only through a reviewed claim or a private invitation sent to a verified public business contact.
Creators may request correction, re-sync, review, removal, or ownership verification through the contact page or by emailing us. Some transaction, security, suppression, and legal records may need to be retained even if a public profile is removed.
6. How we use information
We use information to:
- provide, personalize, maintain, and improve the Service;
- authenticate users and protect accounts;
- create profiles, recommendations, CRM relationships, project briefs, creator matches, campaigns, agreements, invoices, analytics, and reports;
- deduplicate public creator searches and place potential invitation recipients into a reviewed outreach queue;
- process and reconcile transactions, transfers, refunds, and payout status;
- deliver operational messages and user-controlled communications;
- provide support, investigate disputes, prevent abuse, and enforce terms; and
- meet legal, tax, accounting, security, and compliance obligations.
7. Creator discovery invitations
A public search alone does not automatically send an email. When an authorized brand or agency identifies a creator as a potential project fit, VeroKit may prepare an invitation for administrator review. An invitation is sent only after the contact source and message are reviewed, uses a promotional email stream, identifies why the creator was contacted, and includes a one-click opt-out.
Suppression, bounce, complaint, cancellation, and unsubscribe records are used to prevent repeat contact. Campaign matching and rate ranges are estimates and are not promises of work, payment, or creator availability.
8. Legal bases
Where a legal basis is required, we process information to perform a contract, take requested pre-contract steps, pursue legitimate interests such as operating and securing the Service, comply with law, protect vital interests, or act with consent. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
9. Cookies and authentication
VeroKit uses essential cookies and similar technologies to keep users signed in, remember theme preferences, protect authentication flows, maintain security, and understand product use. Essential cookies are required for signed-in workspaces.
Google sign-in, when enabled and chosen by you, provides a verified account identifier, email address, and optional profile image. VeroKit does not receive your Google password.
10. Payments and financial services
Stripe processes checkout, connected-account onboarding, identity and business verification, payment methods, transfers, refunds, disputes, and payouts. Stripe may act as an independent controller of information it collects. VeroKit receives transaction identifiers, status, amount, currency, risk or eligibility signals, and limited account details needed to display and reconcile activity.
Invoice and expense information entered in VeroKit is stored as business workspace data. Users decide what client and tax information to include.
11. How information is disclosed
We may disclose information:
- to counterparties and authorized team members when needed for a profile, relationship, order, agreement, invoice, campaign, approval, or report;
- to service providers supporting hosting, databases, object storage, payments, email, authentication, address search, analytics, customer support, security, and public-data processing;
- in a business transaction such as financing, merger, acquisition, reorganization, or sale, subject to appropriate safeguards;
- when required by law or reasonably necessary to protect rights, safety, users, or the Service; and
- with your direction or consent.
VeroKit does not sell personal information for money. If our practices later fall within a broader statutory definition of “sale” or “sharing,” we will provide the required notice and choices.
12. Public and shared pages
Media kits, public campaign reports, invoice share links, public marketplace listings, and other intentionally shared pages may be accessible to anyone who has the URL or discovers the public page. Do not publish information you do not want recipients or the public to see.
Workspace owners control many sharing settings, but recipients can copy or redistribute information after receiving access.
13. International processing
VeroKit serves users internationally and uses providers that may process information in Canada, the United States, and other countries. Those countries may have privacy laws different from your location. Where required, we use contractual or other recognized safeguards for cross-border transfers.
14. Retention
We retain information for as long as reasonably necessary to provide the Service, maintain security, comply with legal and financial obligations, resolve disputes, enforce agreements, and preserve legitimate business records.
Retention varies by record. Active account and workspace data is generally retained while the account is open. Transaction, agreement, invoice, tax, payout, dispute, audit, and security records may be retained longer. Backups and suppression records may persist for a limited period after deletion.
15. Security
VeroKit uses measures designed to protect information, including encrypted transport, access controls, hashed passwords, signed webhooks, restricted administrator access, durable storage, and security logging. No online service can guarantee absolute security.
You are responsible for a strong unique password, protecting devices and accounts, limiting team permissions, and avoiding sensitive information in free-text fields.
16. Your privacy choices and rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain processing; withdraw consent; opt out of certain marketing; or appeal a decision. You may also have the right to complain to a privacy regulator.
Account settings provide some direct controls. Other requests can be sent to getverokit@verokit.com. We may verify identity and authority before completing a request. Some information cannot be deleted immediately where retention is required or permitted by law.
17. Canada, United States, and other regions
For Canadian users, VeroKit handles personal information in accordance with applicable federal and provincial privacy requirements. For residents of US states with comprehensive privacy laws, applicable access, correction, deletion, portability, and opt-out rights will be honored. Users in the European Economic Area, United Kingdom, and other regions may have additional rights under local law.
Mandatory rights are not limited by this Policy.
18. Children
VeroKit is a business service and is not directed to children under 13. Users must be old enough to form a binding agreement in their jurisdiction or use the Service through an authorized parent, guardian, or business representative where legally permitted. Contact us if you believe a child’s information was submitted improperly.
19. Changes and contact
We may update this Policy as the Service or legal requirements change. We will revise the effective date and provide additional notice when required.
Questions and privacy requests may be sent to getverokit@verokit.com.
Questions?
Contact VeroKit about these privacy practices or a rights request.
getverokit@verokit.com →