1. Introduction and Scope
GETCOLLAB TECHNOLOGIES PRIVATE LIMITED ("GetCollab", "we", "us", or "our") operates the website getcollab.in and the GetCollab platform (the "Platform"), a marketplace that connects brands with creators for marketing campaigns, deals, and collaborations in India. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use the Platform as a Brand user (including organization admins and members), a Creator, or a visitor to our website.
This Policy is framed primarily under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and its rules, as applicable to us as a "Data Fiduciary" and to you as a "Data Principal". A short supplementary section for users in the European Economic Area ("EEA") and California is included in Section 15.
2. Key Terms
- Data Fiduciary: GetCollab, as the entity that determines the purpose and means of processing your personal data on the Platform.
- Data Principal: You, the individual to whom the personal data relates.
- Personal Data: Any data about an individual who is identifiable by or in relation to such data.
- Processing: Any operation performed on personal data, including collection, storage, use, sharing, and erasure.
- Consent Manager / Grievance Officer: See Section 10 for how to exercise your rights and raise grievances.
3. Personal Data We Collect
3.1 Account and Organization Data
- Account information: Name, email address, phone number, password, and account role (Brand or Creator)
- Organization data: For Brands, the organization name, business details, tax/GST information, billing address, and seat assignments (Admin and Member roles) for team members you invite to your organization
- Creator profile information: Profile picture, bio, category, languages, portfolio links, and connected social media handles
- Payment and payout information: Billing details and bank/UPI details required to fund escrow, receive payouts, or pay subscription fees, processed through our third-party payment processor (see Section 3.4)
- Communications: Messages exchanged on the Platform, deal briefs, contracts, support tickets, and feedback
3.2 Campaign, Deal, and Escrow Data
- Campaign details created by Brands, including briefs, budgets, and deliverable requirements
- Deal and workflow data, including proposals, bids, negotiation history, milestones, content submissions, and approvals exchanged between Brands and Creators
- Escrow and transaction data, including amounts funded, held, released, or refunded, platform fees charged, and related payment references
- Dispute-related evidence and communications submitted by either party
3.3 Information We Collect Automatically
- Usage data: Pages visited, features used, and actions taken on the Platform
- Device and log data: IP address, browser type, operating system, and device identifiers
- Cookies and analytics: Session data and product analytics collected with your consent as described in Section 12
3.4 Information from Third Parties and Processors
- Social media profile and engagement data from Instagram/Meta when you connect your account (see Section 5)
- Payment and settlement data from our payment processor, Razorpay, and other payment or banking partners we may use
- Product analytics data from PostHog, our analytics processor
4. Purpose of Processing and Consent
We process your personal data only for specified, lawful purposes, and rely on your consent or other lawful grounds recognized under the DPDP Act, including:
- Account and organization management: Creating and authenticating your account, managing organization seats and roles, and verifying identity
- Campaigns and deals: Enabling Brands to create campaigns, enabling Creators to discover and respond to them, and facilitating the deal workflow between the parties
- Escrow and payments: Processing payments, funding and releasing escrow, calculating and collecting platform fees, and processing subscription billing
- Support and safety: Responding to support requests, resolving disputes, and detecting fraud or abuse
- Analytics and improvement: Understanding usage patterns to improve the Platform, with your consent where required
- Legal compliance: Meeting obligations under tax, accounting, anti-fraud, and other applicable law
We collect and use personal data for these specified purposes only and do not use it for materially different purposes without seeking fresh consent, except where permitted by law. Where we rely on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal; withdrawing consent for certain processing (for example, escrow or payment processing) may mean we cannot continue providing the related service.
5. Instagram / Meta Data Usage
When you connect your Instagram account to GetCollab, we access and use certain data in compliance with Meta's Platform Policies:
- Profile data: Username, profile picture, biography, and follower count
- Public posts: Public content you have posted
- Insights data: Engagement metrics for your content (for creators)
Purpose: We use this data to:
- Display your profile on our marketplace for brand-creator discovery
- Provide analytics and performance insights relevant to campaigns and deals
- Verify account authenticity
- Enable collaboration features between Brands and Creators
We only use Instagram/Meta data as permitted by Meta's Platform Policies, request only the permissions necessary to provide our services, and do not retain this data longer than necessary for the purposes described above. You may disconnect your Instagram account at any time from your Account Settings; see Section 14.
6. How We Share Your Personal Data
We share personal data only as necessary for the purposes described in this Policy, including with:
- Other users on the Platform: Brands and Creators you interact with in connection with a campaign or deal see the profile, deal, and communication data necessary to complete that collaboration
- Payment processors: Razorpay and other payment or banking partners, to process payments, escrow funding/release, payouts, and subscription billing
- Analytics processors: PostHog, to help us understand product usage (see Section 8 on cross-border transfer)
- Service providers: Hosting, infrastructure, customer support, and communication tool providers that process data on our behalf under contractual confidentiality obligations
- Legal and regulatory authorities: Where required to comply with law, regulation, legal process, or governmental request
- Business transfers: In connection with a merger, acquisition, restructuring, or sale of assets, subject to equivalent protections
- With your consent: Any other sharing you explicitly authorize
We do not sell your personal data to third parties.
7. Organization Seats and Team Visibility
If you are added as an Admin or Member of a Brand organization, your name, email, role, and activity within that organization's campaigns and deals are visible to other members of the same organization, in particular its Admin(s). Organization Admins are responsible for managing seat access and removing members who should no longer have access.
8. Cross-Border Data Transfer
We primarily store and process personal data using service providers that may process data outside India. In particular, our analytics processor, PostHog, may process usage and analytics data on servers located in the United States. Where personal data is transferred outside India, we take steps to ensure the recipient provides a level of protection consistent with the DPDP Act and enters into appropriate contractual safeguards with us. We will notify you of any material change to our cross-border transfer practices through an update to this Policy.
9. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
- Account and profile data: Retained while your account is active and for a reasonable period after closure to handle support, legal, or safety needs
- On account deletion/erasure: We anonymize personal data that identifies you (such as your name, contact details, and profile information) so that it can no longer be linked back to you; we do not perform a hard, irreversible wipe of records that we are legally required to retain
- Financial, tax, and ledger records: Transaction, invoice, escrow, settlement, and GST/tax-related records are retained in anonymized or pseudonymized form for as long as required under applicable Indian tax, accounting, and company law. As general guidance only (and not legal advice), certain books of account and tax records are commonly required to be preserved for around eight years; the exact period depends on the specific record and law in force at the relevant time
- Dispute and fraud records: Retained for as long as necessary to resolve open disputes, investigate fraud, or comply with a legal hold
10. Your Rights as a Data Principal
Subject to applicable law, you have the right to:
- Access: Request a summary of the personal data we hold about you and the processing activities undertaken
- Correction: Request correction of inaccurate or misleading personal data, and completion of incomplete data
- Erasure: Request erasure of personal data that is no longer necessary for the purpose for which it was processed, subject to the retention obligations described in Section 9 (for example, we cannot erase financial or tax records we are legally required to retain, but we will anonymize the personal identifiers associated with them)
- Withdraw consent: Withdraw consent for processing that is based on consent, at any time
- Grievance redressal: Raise a grievance regarding the processing of your personal data, as described in Section 11
- Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity, in accordance with applicable rules
To exercise these rights, contact our Grievance Officer using the details in Section 11.
11. Grievance Officer and Grievance Redressal
In accordance with the DPDP Act, we have designated a Grievance Officer to address your questions, requests, and grievances regarding the processing of your personal data.
- Grievance Officer: Grievance Officer, GETCOLLAB TECHNOLOGIES PRIVATE LIMITED
- Email: privacy@getcollab.in
- Address: Manikonda, Hyderabad 500089, Telangana, India
We aim to acknowledge every request or grievance within 72 hours of receipt. We aim to resolve most requests and grievances within a reasonable period thereafter, and in any event within the timelines prescribed under the DPDP Act and its rules. If we require additional time or information to verify your identity or fulfil your request, we will let you know.
12. Cookies, Analytics, and Marketing Communications
12.1 Cookies and Analytics
We use cookies and similar technologies, and product analytics tools such as PostHog, to keep you signed in, remember your preferences, understand how the Platform is used, and improve our services. Where required, we will request your consent before setting non-essential cookies or activating analytics tracking, and you can manage your preferences through your browser settings or any in-product cookie controls we provide.
12.2 Marketing Communications
We send transactional and service communications (such as deal, escrow, and account notifications) as part of operating the Platform. We only send marketing or promotional communications if you have separately opted in to receive them, and you can opt out at any time using the unsubscribe link in those communications or through your account settings.
13. Children's Privacy and Age Restriction
The Platform is intended solely for individuals aged 18 years and above. We do not knowingly permit individuals under 18 to create accounts, and we do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from someone under 18, we will take steps to delete or anonymize that data.
14. Data Security
We implement reasonable technical and organizational measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Access controls and authentication measures, including organization seat-based access for Brands
- Regular security reviews and updates
- Incident response procedures
No method of storage or transmission over the internet is completely secure, and we cannot guarantee absolute security.
15. Supplementary Notice for EEA and California Users
If you access the Platform from the European Economic Area, our legal bases for processing under the General Data Protection Regulation include performance of a contract, our legitimate interests, your consent, and compliance with legal obligations. If you are a California resident, the California Consumer Privacy Act gives you rights to know, delete, and opt out of the sale of personal information; we do not sell personal information. Requests under GDPR or CCPA can be sent to the Grievance Officer contact in Section 11, and we will address them in accordance with the applicable law, in addition to your rights under the DPDP Act.
16. Third-Party Links
The Platform may contain links to third-party websites, including payment processor pages. We are not responsible for the privacy practices of those sites, and we encourage you to review their privacy policies.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by:
- Posting the updated policy on the Platform with a revised "Last updated" date
- Sending an email notification for material changes, where appropriate
Your continued use of the Platform after such changes constitutes acceptance of the updated policy.
18. Data Deletion Instructions
You may request erasure of your personal data at any time. Please see our Data Deletion Policy for the process, verification requirements, timelines, and the limits on erasure that apply to financial and legal records we must retain.
19. Contact Us
For general questions about this Privacy Policy, contact us: