Privacy Policy
1. Who we are
The controller of your personal data within the meaning of Art. 4(7) GDPR is DCSOLUTIONS Dominik Ciślak, with its registered office at Zygmuntowska 24/24, 31-314 Kraków, NIP: 8681948654, REGON: 521751639 (“Vereel”, “we”, “us”).
Vereel operates a marketplace that connects content creators with brands (the “Platform”).
You can reach us about anything in this policy through our contact form, or in writing at our registered address.
We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR. Privacy enquiries reach us through the contact form above.
2. Who this policy covers
This policy applies to:
- Creators who register to offer collaborations.
- Brands who register to publish offers and engage creators.
- Visitors who browse the Platform without an account, and anyone who writes to us through the contact form.
Where something applies to only one of these, we say so.
3. What data we process
We process the categories below. Which apply to you depends on whether you are a creator, a brand, or a visitor.
- Account and identity: your email address and a password stored only as a cryptographic hash — we never hold the password itself — together with your role, display name, interface language, preferred currency, account status, and the date of any deletion request.
- Creator profile: display name, biography, content categories, the languages you work in, which platforms you are on and your follower and post counts for each, the compensation types you accept, and your subscription tier.
- Creator settlement data: your invoicing identity — legal or personal name, VAT identification number, address, country, invoicing email and any notes — the invoice you upload to be paid against, and a shipping address with a phone number for the courier where a collaboration involves goods being sent to you. An invoice states the account it is to be paid into, so we hold your bank account details as part of that document: we do not ask you to type bank details into Vereel, and keep no separate record of them.
- Brand profile and billing: brand name, logo, website, description, whether you act as an agency, and your invoicing identity including a contact phone number.
- Collaborations and communication: the offers you publish or apply to, applications, the status and history of each collaboration, the messages and attachments you exchange with the other party, draft content submitted for approval, and links to published posts.
- Terms acceptance records: each time you accept the Platform Terms or the Cooperation Terms, we record which document you accepted, its version, the language you read it in and a fingerprint of that exact text, the role you acted in, where on the Platform you accepted it, the offer concerned when you accepted Cooperation Terms for an application or a campaign kickoff, and the time. We do not record your IP address or browser for this.
- Correspondence with us: support conversations, and messages sent through the contact form. For contact-form messages we also store the IP address and browser user-agent they were sent from, so that abuse of the form is traceable. We use it for nothing else.
- Payments: the value of a collaboration, the platform fee applied, payment and refund records, the exchange rate where currencies differ, and the invoices and accounting documents we are required to issue and keep. Card payments are processed by Stripe — we never see or store your full card number.
- Instagram connection data, only if you connect an account: profile figures, insights, audience demographics, recent media and captions, a history of your follower and post counts, and an access token. Section 7 sets this out in full.
- Technical and security data: IP address, device and browser type, pages and features used, cookie identifiers where you have consented, error reports and application logs, rate-limiting counters keyed to your IP address, email delivery records, and an audit log of significant administrative changes recording who made the change and the values before and after it.
4. Where the data comes from
Most of it comes directly from you — when you register, complete your profile, run a collaboration, or write to us. Some is generated by us as you use the Platform: logs, delivery records, audit entries, and the content profile described in section 9.
Some comes from third parties, and Art. 14 GDPR requires that we name them:
- Google — your email address, name, profile picture and Google account identifier, if you sign in with Google.
- Meta (Instagram) — your Instagram account identifier and username, if you sign in with Instagram.
- Meta (Instagram) — the connection data in section 7, if you connect an Instagram account.
- Stripe — the outcome of a payment, and a payment reference.
5. Signing in with Google
When you choose “Continue with Google”, Google tells us your email address, name, profile picture and Google account identifier. That is all we request and all we receive.
We do not request, and cannot access, your Gmail, Drive, Contacts, Calendar or any other Google service. The basis is Art. 6(1)(b) GDPR — you are asking us to create or open your account.
Your use of Google remains governed by Google’s own privacy policy.
6. Signing in with Instagram
When you sign in with Instagram, we ask Meta for the minimum permission Instagram offers (instagram_business_basic) and use it for one purpose: to learn your Instagram account identifier and username, so we know which Vereel account is yours.
Three things follow from this, and they are why signing in is described separately from connecting:
- The access token from a sign-in is discarded immediately. We do not keep it and cannot use it later.
- We collect no statistics. Signing in does not give us your reach, profile views, audience demographics or media. Those require the separate, explicit connection described in section 7.
- Instagram gives us no email address, and no permission exists that would. Your account is therefore created against a non-deliverable placeholder address that can never receive mail, and we hold no contact address for you until you choose to add one in your settings.
If you later delete your Vereel account, signing in again with the same Instagram account will not restore it.
7. Connecting an Instagram account
This is separate from signing in and entirely optional. It exists so brands can see verified statistics rather than numbers you typed yourself.
When you connect, you grant Meta permissions (instagram_business_basic and instagram_business_manage_insights), and we retrieve and store:
- Profile: username, Instagram account id, account type, follower count, media count and profile picture.
- Insights: reach, profile views, engaged accounts and total interactions.
- Audience demographics: aggregated age, gender and location breakdowns of your followers, which Instagram provides only for accounts above its own follower threshold.
- Media: your recent posts — captions, thumbnails, permalinks, media type, likes, comments, views and per-post insight metrics.
- A history of your follower and post counts, recorded over time so trends can be shown.
- An access token issued by Meta, stored with its expiry and the permissions you granted, so statistics can be refreshed without asking you to sign in again.
We use this to display your creator statistics to brands on the Platform, and to generate the content profile in section 9. Nothing else. We do not post on your behalf, send messages as you, read your direct messages, or access anything the permissions above do not cover. This data is stored on Supabase infrastructure in the EU (Frankfurt).
8. Stopping the Instagram connection
There are three ways to stop it, and they do not all do the same thing.
- Disconnect in your Vereel settings. We delete everything obtained through the connection: profile figures, insights, audience demographics, cached posts and captions, the history of your follower and post counts, the content profile in section 9, and the stored access token. Nothing from the connection is kept.
- Send a data deletion request through Instagram. The same — everything listed above is deleted.
- Remove Vereel in Instagram (Settings → Website permissions → Apps and websites). This revokes our access. We immediately delete the access token and your insight figures — reach, profile views, engaged accounts, interactions and audience demographics — and stop refreshing anything. We keep the public part of your profile: your handle, display name, profile picture, follower and post counts, engagement averages, your cached recent posts and their captions, the history of those counts, and the content profile generated from them. This is so your Vereel profile does not silently lose its Instagram section when you were only revoking access. To remove those as well, disconnect in your Vereel settings, send a deletion request through Instagram, or ask us through our contact form.
Your use of Instagram remains governed by Meta’s own terms and privacy policy. Vereel is not affiliated with, endorsed by, or sponsored by Meta Platforms.
9. AI analysis of your content
If you have connected an Instagram account, we submit up to 25 of your most recent post captions to Google’s Gemini API for analysis.
What comes back and is stored: a short summary of your content, a list of topics you post about, and a list of brands your captions appear to reference, each with the caption it was drawn from. Brands viewing your creator profile can read it — it is part of how you are presented to them.
The basis is Art. 6(1)(f) GDPR: our legitimate interest, and yours, in presenting your account to brands in a usable form. You can object at any time (section 16), and disconnecting your Instagram account stops it and deletes the result.
One thing worth stating plainly. Topics are inferred from text you wrote. If your posts discuss your faith, your health, your politics, or anything else the GDPR treats as a special category of data, an inferred topic may reflect that. We do not seek such categories, do not ask for them, and do not use them to match you with offers. If an inferred topic is wrong, or you would rather it were not there, tell us and we will remove it.
This analysis makes no decision about you — see section 17.
10. Why we process your data, and on what basis
We process your data for these purposes, on these legal bases:
- Creating and operating your account, matching creators and brands, and running collaborations and the messaging between them — Art. 6(1)(b) GDPR, performance of a contract.
- Keeping a record of which terms you accepted and when (the terms acceptance records in section 3), as evidence of what was agreed — Art. 6(1)(b) GDPR, performance of the contract those terms form, and Art. 6(1)(f) GDPR, our legitimate interest in establishing, exercising or defending legal claims arising from it.
- Taking payment, paying creators, and issuing and keeping accounting documents — Art. 6(1)(b) and (c) GDPR, contract and legal obligations under tax and accounting law.
- Displaying verified statistics from a connected Instagram account — Art. 6(1)(a) GDPR, the consent you give by connecting the account.
- Generating the AI content profile (section 9) — Art. 6(1)(f) GDPR, legitimate interest in presenting creators usefully to brands.
- Keeping the Platform secure — rate limiting, abuse prevention, error monitoring and audit logging — Art. 6(1)(f) GDPR, legitimate interest in a service that works and is not abused.
- Answering enquiries, support requests and complaints — Art. 6(1)(b) and (f) GDPR.
- Product analytics and session recording — Art. 6(1)(a) GDPR, the consent you give through the cookie banner (section 15).
- Marketing messages such as a newsletter — Art. 6(1)(a) GDPR, consent, withdrawable at any time.
- Handling your GDPR requests, and being able to show we handled them — Art. 6(1)(c) GDPR, legal obligation.
- Establishing, exercising or defending legal claims — Art. 6(1)(f) GDPR, legitimate interest.
11. Who we share it with
We do not sell your personal data. We share it in four situations.
With other users of the Platform, to the extent a collaboration requires it: a brand you apply to sees your profile, your statistics and your content profile; the party you are working with sees your messages to them; and where a collaboration is paid, each side receives the invoicing details needed to issue and settle documents.
With service providers who process data on our instructions, under data processing agreements:
- Supabase — database, authentication and file storage.
- Vercel — application hosting.
- Stripe — card payments and settlement.
- Resend — sending and tracking our email.
- Sentry — error monitoring.
- PostHog — product analytics and session recording, consent-gated and hosted in the EU (Frankfurt).
- Google — AI analysis of creator content, as described in section 9.
- Cloudflare — anti-abuse verification on our sign-in, sign-up, password-reset and contact forms.
- Upstash — rate-limiting counters, to stop automated abuse of our API.
- Meta (Instagram) — the integration you have connected, to the extent you have connected it.
With our own staff, who may access your account data to provide support or investigate a problem. Administrators can in limited circumstances view the Platform as your account in order to reproduce a fault. Every such access is recorded in an audit log, with who did it and when. And with authorities entitled to it — law enforcement, courts, tax authorities — on a justified request and only to the extent required.
12. Transfers outside the European Economic Area
Your data is held inside the European Economic Area. Our database and files are hosted in the European Union (Frankfurt), our product analytics are hosted in the EU (Frankfurt), and our rate-limiting counters are held in the EEA.
Several of the providers in section 11 are established outside the EEA, or may access data from outside it, including in the United States. Where that happens we rely on the safeguards Chapter V GDPR requires: the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), or an adequacy decision where one covers the provider, such as the EU–U.S. Data Privacy Framework.
You can ask us for a copy of the safeguards that apply through our contact form.
13. What deleting your account does
We erase or anonymise the personal data in your account: your name, biography, profile picture, contact address, invoicing identity and shipping address, including its phone number. Connected social accounts are deleted outright, which takes the Instagram data in section 7 and the content profile in section 9 with them. Your profile stops being visible to anyone on the Platform.
A short list is deliberately kept, and you should know what is on it:
- Payment history, invoices and accounting documents — tax and accounting law requires it, as a rule for 5 years from the end of the year in which the tax obligation arose. Art. 17(3)(b) GDPR recognises this limit on the right to erasure.
- Your Instagram account identifier, if you signed in with Instagram — so that a deleted account cannot be re-opened by simply signing in again. It is what makes the deletion stick.
- Messages exchanged in a collaboration — they are equally the other party’s record of an agreement they were part of, and we cannot erase one side of a conversation without destroying theirs.
- Your terms acceptance records — they are the evidence of which terms you agreed to and when, for any claim arising from those agreements. They stay linked to the retained, anonymised account.
- Support and contact-form correspondence — to deal with any complaint or claim arising from it, and to show how we dealt with it.
- Our administrative audit log — Art. 5(2) GDPR requires us to be able to demonstrate that we handled your data properly, including that we deleted it.
Within those categories we reduce what identifies you wherever doing so does not defeat the purpose the record is kept for.
14. How long we keep it
Outside account deletion, we keep data no longer than the purpose requires:
- Account and profile data — while your account exists; erased or anonymised on deletion, subject to section 13.
- Accounting documents and payment records — as a rule 5 years from the end of the year in which the tax obligation arose.
- Settlement data (invoicing identity, shipping address and its phone number) — while your account exists, except where it forms part of an accounting document.
- Collaboration records — while your account exists, then for the period in which a claim arising from the collaboration could be brought.
- Terms acceptance records — while your account exists, then for the period in which a claim arising from the accepted terms could be brought. They are not erased when you delete your account (section 13).
- Instagram connection data, including the access token — until you disconnect the account or delete your Vereel account, whichever comes first. See section 8.
- The AI content profile — regenerated as your content changes; deleted when you disconnect Instagram or delete your account.
- Data we hold on the basis of consent — until you withdraw consent.
- Product analytics events — no longer than 14 months.
- Session recordings — no longer than 30 days.
- Technical and security logs — typically up to 12 months.
- Contact-form messages, with their IP address and user-agent — as long as needed to deal with the matter, and then for the period in which a related claim could be brought.
- The administrative audit log — for as long as we need it to demonstrate accountability under Art. 5(2) GDPR.
15. Cookies and similar technologies
We use strictly necessary cookies to make the Platform work, principally to keep you signed in. These cannot be switched off without breaking the service, and they do not require your consent.
With your consent we use cookies and similar technologies for product analytics and session recording. These run only if you accept all cookies. If you accept only the strictly necessary ones, no analytics tool is loaded and no analytics data is sent.
Our analytics provider is configured to discard visitor IP addresses, and does not automatically capture everything on the page.
You can change your mind at any time. Use “Cookie settings” in the footer of any public page, or “Privacy & cookies” in your account settings. Withdrawing consent is as easy as giving it, as Art. 7(3) GDPR requires. You can also manage cookies in your browser, though restricting the strictly necessary ones will stop parts of the Platform working.
16. Your rights
In connection with the processing of your data, you have the right to:
- Access your data and receive a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase your data — the “right to be forgotten”. Deleting your account erases or anonymises what we hold about you, apart from the short list in section 13, each item of which Art. 17(3) GDPR permits.
- Restrict how we process it.
- Port it, in a structured, commonly used, machine-readable format.
- Object to processing we base on legitimate interest, including the AI content profile in section 9.
- Withdraw consent at any time, without affecting the lawfulness of what we did before you withdrew it.
To exercise any of these, use our contact form, or write to us at our registered address. We respond without undue delay and within one month of receiving your request, as Art. 12(3) GDPR requires; if a request is complex we may extend that by two further months, and we will tell you if we do. Some rights you can exercise yourself, immediately, in your account settings — editing your profile, disconnecting Instagram, changing your cookie choice, or requesting deletion of your account.
17. Automated decision-making and profiling
We profile in two limited ways: matching offers to creators using categories, reach and activity, and generating the content profile described in section 9.
No decision that produces legal effects for you, or similarly significantly affects you, is made automatically. Whether a collaboration happens is decided by a brand and a creator, not by our system. Art. 22 GDPR is therefore not engaged.
You can still object to the profiling itself under Art. 21 GDPR — see section 16.
18. Complaints
If you believe we are processing your data in breach of the GDPR, you can lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. You may also complain to the authority in your own country of residence.
We would rather hear from you first, through our contact form — but this right does not depend on that.
19. Is providing data mandatory?
Providing data is voluntary, but some of it is necessary. Without the data needed to create an account and run a collaboration we cannot provide the service, and without invoicing and settlement data we cannot pay you or issue the documents the law requires.
Connecting Instagram, accepting analytics cookies and subscribing to marketing are all genuinely optional, and refusing them costs you nothing but the feature itself.
20. Security
We apply technical and organisational measures appropriate to the risk: data travels over encrypted connections (HTTPS/TLS), passwords are stored only as hashes, access to production data is limited to authorised people and recorded, our database enforces row-level access rules so one user’s data is not reachable by another, and our API is rate limited against automated abuse.
No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you as Art. 34 GDPR requires.
21. Children
The Platform is intended for people aged 16 or over. We do not knowingly collect the data of anyone younger without the consent of a parent or guardian. If you believe a child’s data has reached us, contact us and we will delete it without delay.
22. Changes to this policy
We may update this policy. If a change is material we will tell you by email or by a prominent notice on the Platform, with reasonable advance notice. The current version always lives on this page, with the date it was last updated at the top.
Contact — Personal Data
For anything relating to your personal data — questions, requests or complaints — use our contact form, or write to us at the controller’s registered address.