Privacy Policy
Last updated 26 August 2026
This explains what we collect, why we collect it, who else sees it, and what you can ask us to do with it. It is written to be read, not to be survived.
Who we are
Activated Creators Co., Ltd., Bangkok, Thailand operates activatedcreators.com and the Activated mobile app. We are the data controller for the information described here. Contact us at hello@activatedcreators.com.
What we collect
When you create an account
- Your name and email address.
- A password, stored only as a bcrypt hash. We never store, log, or have any way to read your actual password.
- If you sign in with Google or Apple instead, we receive your name and email address from them. We never receive your password.
Your profile, as you choose to fill it in
- Biography, city and country, nationality, languages, and whether you are currently available for work.
- Social handles and follower counts for Instagram, TikTok, YouTube and Facebook, plus any website you add.
- Rates and the services you offer, which you can mark public or private.
- Profile photo, cover photo and portfolio images that you upload.
Everything in this section is optional. A profile marked public is visible to anyone, including people who are not signed in — that is the point of a creator directory, and it is worth being deliberate about what you put there.
What you do on the platform
- Campaign applications and the deliverables you submit against them.
- Community posts, comments, and messages you exchange with brands.
- Event registrations and attendance check-ins.
- Service listings and bookings.
Payments
Payments are processed by Stripe. Card numbers never reach our servers — they go directly to Stripe. We store only the identifiers Stripe gives us: a customer reference, a subscription reference, and the status and dates of what you bought.
Notifications and devices
If you enable push notifications in the mobile app, we store the notification token your device issues, which platform it came from, and a random identifier we generate for that installation. A notification token identifies a device, not a person, and cannot be used to read anything from your phone.
Technical information
- Your IP address, used to rate-limit sign-in attempts and other abuse-prone actions. It is stored briefly and then discarded.
- Short-lived tokens for email verification and password resets, stored hashed so that reading our database does not let anyone use them.
Why we collect it
- To run your account — signing in, verifying your email, resetting your password.
- To make the marketplace work — showing your profile to brands, matching you to campaigns, taking event registrations.
- To tell you things that matter — campaign invites, application decisions, messages. By email, and by push notification if you have turned it on.
- To take and reconcile payments, and to meet the accounting obligations that come with them.
- To keep the platform safe — rate limiting, abuse reports, moderation.
Who else sees it
We do not sell your personal data, and we do not share it with advertisers. We use a small number of service providers to run the platform, and each sees only what it needs:
- MongoDB Atlas — stores the database.
- Vercel — hosts and serves the application.
- Stripe — processes payments.
- Cloudinary — stores and serves images you upload.
- Resend — delivers transactional email.
- Apple and Google — deliver push notifications to your device, and handle sign-in if you use those options.
Other users see what you make public: your profile if you publish it, your posts in communities you join, and your application to a campaign — which the brand running it can read. We may also disclose information where the law genuinely requires it.
Where it is held
We are based in Thailand, and our providers operate internationally, so your information may be processed outside your own country. We use established providers who contract to protect it in transit and at rest.
How long we keep it
- Account and profile data — until you delete your account.
- Push notification tokens — removed automatically once a device has not opened the app for around nine months, and immediately when you sign out.
- Verification and password-reset tokens — minutes to hours, then deleted automatically.
- Payment records — retained as long as tax and accounting rules require, even after account deletion.
Your rights
You can ask us to:
- Show you what we hold about you.
- Correct anything wrong — most of it you can edit yourself.
- Delete your account. You can do this yourself, without asking us, from your profile page. It removes your account, profile and content.
- Provide your data in a portable form.
- Stop sending you things. Push notifications have per-category controls on your notifications page and an off switch in your device settings.
If you are in Thailand, these rights sit under the Personal Data Protection Act. If you are in the UK or EU, under the GDPR. Either way, email us and we will act on it.
Children
Activated Creators is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has created an account, tell us and we will remove it.
Security
Passwords are hashed with bcrypt. Tokens are hashed before storage. Everything travels over HTTPS. No system is perfect, and we will not pretend otherwise — but if a breach affects you, we will tell you rather than hope you do not notice.
Changes
If we change this policy in a way that matters, we will update the date at the top and tell you in the app before it takes effect.
Questions about this page? Email hello@activatedcreators.com.