1. Controller, data protection officer and supervisory authority
The controller for the processing described in this policy is JLRS AB, Swedish organisation number 559484-0323, c/o Mailboxes ETC, Riddargatan 3, 114 11 Stockholm ("Collabify", "we", "us").
How to reach us
- Controller
- JLRS AB, org. no. 559484-0323, c/o Mailboxes ETC, Riddargatan 3, 114 11 Stockholm
- Data protection officer (privacy requests, access, erasure)
- privacy@collabify.se
- General contact and support
- support@collabify.se
- Supervisory authority
- The Swedish Authority for Privacy Protection (IMY), Sweden
We have appointed a data protection officer who is accountable for our record of processing activities, our data protection impact assessment, the retention schedule and the handling of your rights. Write to privacy@collabify.se and your request goes straight to the officer. We acknowledge within 72 hours and answer within one month.
You always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), which is our supervisory authority, or with the supervisory authority in the EU/EEA country where you live or work. You do not have to contact us first, though we would welcome the chance to put things right.
1.1 When someone else is responsible
- Business customers. When a business receives a creator's profile, application or campaign content, that business becomes an independent controller of what it receives and of how it is used in its own operations. It is bound by our Terms of Service and by its own GDPR obligations.
- Collabify as a processor. For data we process solely on a business customer's instructions — for example applications and campaign material inside that business's own workspace — we act as a processor under a data processing agreement.
- Connected platforms. TikTok, Shopify, WooCommerce and any other service you choose to connect are independent controllers of your accounts with them and process your data under their own privacy policies.
- A merchant's customers. If you bought something from an online store that uses Collabify, the store (the merchant) is the controller of your purchase; see the Shopify section below.
2. What personal data we process
Which categories apply depends on whether you use Collabify as a business or as a creator, and on which features you use.
2.1 Data you give us
- Account data — name, email address, password (held by our authentication provider, never stored by us in clear text), two-factor settings and your role (business or creator).
- Business data — company name, organisation number, contact and billing details, brand names, logos, product catalogue, campaign briefs and budgets, and the people authorised to act for the business.
- Creator profile — display name, profile picture, biography, niches, location, links to your social accounts and the TikTok handle you enter.
- Campaign content — the videos, captions, hashtags and other material you upload, the business's review decisions and the messages exchanged inside a campaign.
- Delivery details — name and shipping address when a campaign involves a physical product being sent to you.
- Identity and signing data — see the BankID and personal identity number section below.
- Payment and payout data — invoices, payment history and customer references at our payment provider (businesses), and payout records and tax details at our payout partner (creators). Card and bank account details are entered directly with the payment or payout provider and are not stored in full by us.
- Support and consent records — support tickets, your acceptance of the terms and this policy, your cookie choices, your messaging preferences and every publish approval you give.
2.2 Data from services you connect
When you connect an account with another service (TikTok for creators; Shopify or WooCommerce for businesses) we receive the data described in the TikTok and other-integrations sections. A connection is never established automatically — it always starts with you approving it on that service's own consent screen.
2.3 Data collected automatically
- Usage data — which views and features are used and when, recorded in our own systems to operate, debug and improve the Service.
- Technical data — IP address, device and browser type, operating system, app version, and crash and error reports. Personal data is redacted at the application boundary before error reports leave our systems.
- Web performance and visit metrics — the page or route visited and anonymous performance metrics, through our hosting provider's built-in measurement.
- Push token — if you turn on push notifications in the app we store the device's push token so the notification can be delivered. A token unseen for about six months is purged as a dead device.
- Cookies — the website today sets strictly necessary cookies only; there are no analytics or marketing cookies to consent to. The app uses no cookies and no advertising identifiers. See the Cookie Policy.
We use no third-party advertising or tracking SDKs in the app, and we build no profiles for advertising purposes.
3. Purposes and legal bases (Article 6)
Every processing activity below rests on one of the legal bases in Article 6 GDPR. Where the basis is legitimate interests we have carried out a balancing test, and you have the right to object — see the section on your rights.
| Purpose | Personal data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account, authentication and account security | Account, profile and business data, session data | Contract, Art. 6(1)(b) |
| Show creator profiles to businesses and match creators with campaigns | Creator profile, TikTok profile and public statistics | Contract, Art. 6(1)(b) |
| Run campaigns: briefs, applications, offers, submitted content, review and messaging | Campaign content, participation records, messages | Contract, Art. 6(1)(b) |
| Publish an approved video to your TikTok account and read its results | Video, caption, post settings, publish approval, TikTok tokens and statistics | Contract, Art. 6(1)(b) — the publish approval itself is your explicit approval of that exact post |
| Verify identity and age and sign contracts using BankID | Name, personal identity number, derived date of birth, signature evidence | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c); personal identity number under ch. 3 s. 10 of the Swedish Data Protection Act (2018:218) |
| Obtain and check a guardian's consent for creators under 18 | Guardian's name, contact details and signature evidence, hashed personal identity number | Legal obligation, Art. 6(1)(c), and contract, Art. 6(1)(b) |
| Take payment from businesses, pay creators, invoicing, accounting and tax reporting | Payment, payout and invoice records, tax identifiers | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) (Swedish Accounting Act, tax legislation) |
| Calculate and settle campaign results and prize pools | Snapshots of video statistics, participation records | Contract, Art. 6(1)(b) — see the prize pool rules |
| Deliver product samples in physical-product campaigns | Creator's name and shipping address | Contract, Art. 6(1)(b) |
| Prevent fraud, abuse and fake engagement, and protect the Service | Usage and technical data, statistics, security logs | Legitimate interests, Art. 6(1)(f) — a safe and honest marketplace |
| Operate, debug and improve the Service | Usage data, error reports with personal data redacted | Legitimate interests, Art. 6(1)(f) |
| Send necessary service messages and notifications | Email address, push token, notification preferences | Contract, Art. 6(1)(b) |
| Send newsletters and marketing | Email address, your preferences | Consent, Art. 6(1)(a) — withdrawable at any time |
| Non-essential cookies and consent-based measurement | See the Cookie Policy | Consent, Art. 6(1)(a) |
| Comply with law, respond to authorities and handle legal claims | Whatever the individual case requires | Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f) |
3.1 Automated decision-making and AI
Collabify ranks and suggests creators for a campaign using a scoring model that weighs niche, audience size and past performance, and can suggest a publishing time. The suggestions are shown to a person who makes the decision. We take no decision that produces legal effects concerning you or similarly significantly affects you based solely on automated processing within the meaning of Article 22.
Businesses can use AI assistance to draft campaign briefs, and a submitted campaign video can be checked by an AI model against the campaign brief as an advisory checklist for the reviewer. In those cases the brief, the draft or the video is sent to the AI provider listed in the sub-processor register, under terms that prohibit using the content for model training. It is always the business's reviewer — never the model — that approves or rejects content.
4. BankID, personal identity numbers and age data
We use BankID to sign campaign contracts and to authorise payouts. The signing itself is performed by the BankID provider; we never see your security code and we never store your BankID credentials. From a completed signature we receive your name, your Swedish personal identity number (personnummer) and signature evidence.
Of that, we keep the following and nothing more:
- The signature evidence — the provider's completion envelope is stored encrypted alongside the signed contract. It is the proof that you signed, and it is what makes the contract hold up in a dispute or an audit.
- A derived date of birth — the minimum sufficient fact for every age rule (data minimisation, Art. 5(1)(c)). The identity number itself is not stored for that purpose.
- A keyed hash (HMAC) of the identity number — not the number, and not reversible without a separate secret. It exists for one purpose: to prove, at guardian-consent time, that the person signing is a different person from the creator who is a minor.
- Tax identifiers held by our payout partner — where the law requires us to report earnings to the Swedish Tax Agency, the identity number, tax withholding and income statements are handled by the payout partner as a sub-processor.
A Swedish personal identity number is not a special category of personal data under Article 9, but its processing is specifically regulated in Sweden: under ch. 3 s. 10 of the Swedish Data Protection Act (2018:218) it may be processed without consent only where clearly justified by the purpose, the importance of secure identification or another substantial reason. We process it solely for secure identification at contract signing, for age verification, and for the accounting and tax obligations that follow from payouts.
We never ask for special categories of personal data under Article 9 — data revealing health, ethnic origin, political opinions, religion, trade union membership, sex life, or biometric data for identification — and we never run face or voice recognition on your content. Please do not put more personal information into a campaign video than the campaign actually requires.
5. TikTok (Login Kit and Content Posting API)
Creators may connect their TikTok account to Collabify. The connection uses TikTok's official developer platform: TikTok Login Kit to link the account and the TikTok Content Posting API to publish campaign videos and read their results. Connecting is optional, but it is required to take part in TikTok campaigns because that is where the campaign video is published.
5.1 What we access, and why
When you connect, TikTok shows you the permissions ("scopes") we request and you decide on TikTok's own screen. We request these 5 permissions and no others:
| TikTok permission | Data we receive | What we use it for |
|---|---|---|
user.info.basic | Your TikTok open id, display name and profile picture | Link your TikTok account to your Collabify profile and show which account a post will be published to |
user.info.profile | Username, biography, profile link and whether the account is verified | Show your creator profile to businesses in the marketplace and pre-fill your Collabify profile |
user.info.stats | Follower, following, likes and video counts | Show your audience size on your profile and to businesses reviewing your application |
video.list | The list of your public videos and their view, like, comment and share counts | Show your ten most recent public videos and their figures on your Collabify profile and, as a snapshot taken when you apply, to the business reviewing that application; and read the performance of the videos you publish through Collabify so campaign results, prize-pool shares and payouts can be calculated |
video.publish | Permission to publish a video to your account | Publish a campaign video to your TikTok account on your behalf, only after you have approved that exact post |
If a campaign publishes through the TikTok inbox — the only way to attach a native commercial sound in TikTok's own editor — we additionally request the video.upload permission for that connection. It is not part of the standard set above and is never requested unnecessarily.
We also receive an access token and a refresh token that let our servers call TikTok on your behalf. The tokens are encrypted at rest, are used only by our servers, and are never shown to businesses or other users.
5.2 How publishing on your behalf works
Collabify never posts anything to TikTok automatically. Publishing always follows the same steps:
- You upload your campaign video in the Collabify app and the business approves it.
- You open the publish screen in the app. It fetches your current TikTok account information live from TikTok and shows the account (nickname and username) the video will be published to, a preview of the video, the final caption (which you can edit, apart from the paid-partnership disclosure and the campaign's required hashtags), who can see the video (you must choose — nothing is preselected), the commercial content disclosure (every Collabify post is labelled as a paid partnership), whether comments, duets and stitches are allowed (all off unless you turn them on), whether the video is AI-generated, and the exact date and time of publication.
- You confirm by pressing "Publicera" (Publish). In doing so you also accept TikTok's Branded Content Policy and Music Usage Confirmation, which are linked on that screen. We record your approval together with a fingerprint of the video, caption and settings you approved.
- At the time you chose, our servers check your TikTok account information again. If anything you approved is no longer permitted by TikTok (for example a privacy setting or an interaction you enabled), nothing is published and you are asked to review the post again. Otherwise we send exactly the approved video, caption and settings to TikTok's Content Posting API.
- You can cancel or change a scheduled post in the app at any time before it is published. After publication the post lives on your TikTok account and is under your control like any other post.
We do not add watermarks, logos or promotional text to your video, and we do not alter your video before sending it to TikTok.
5.3 What we share with TikTok, and where TikTok data is shown
When you publish, we send TikTok the video file, the caption and the settings you approved. When we read your profile or video statistics, we send TikTok your access token and the ids of the videos concerned. TikTok processes this as an independent controller under its own Privacy Policy and Terms of Service. TikTok's European operation is established in the United Kingdom and Ireland — see the section on international transfers.
- Your TikTok display name, username, profile picture, follower count and biography are shown on your Collabify creator profile, which businesses can see when recruiting for campaigns.
- Your TikTok statistics (followers, likes, video count, and average views and engagement across your ten most recent public videos) and those ten videos are shown on your own profile in the app and, as a snapshot taken at the moment you apply, to the business reviewing that application. We refresh them when you connect, when you apply, daily while your account is connected, and when you press "Uppdatera statistik". Collabify never shows businesses self-reported figures: a creator is either verified through TikTok or shown as unverified.
- The performance of a campaign video (views, likes, comments, shares) is shown to you and to the business running that campaign and is used to calculate campaign results, prize-pool shares and payouts. We store periodic snapshots of those numbers for the duration of the campaign and its settlement.
- We do not share your TikTok data with anyone else, and we never sell it.
5.4 Disconnecting and deleting TikTok data
You can disconnect TikTok at any time in the app (Profile → TikTok → Disconnect). When you do, we revoke our authorisation at TikTok and then delete your TikTok connection with us, including the access and refresh tokens. You can also remove Collabify from your TikTok account under Manage app permissions in TikTok's settings; we detect the revocation and treat the account as disconnected.
Disconnecting does not delete videos already published to your TikTok account — those are yours and you manage them on TikTok. Records of a campaign you took part in (which post was published, when, with which caption and settings, and how it performed) are kept for as long as the retention section says, because they document a paid collaboration and a payout. Deleting your Collabify account disconnects TikTok automatically.
6. Shopify, WooCommerce and other connections
The connections below are engaged only when a business chooses to connect its store.
6.1 Shopify and WooCommerce
When a business connects a Shopify or WooCommerce store we process the store domain, store name and store admin email address to link the store to the business's Collabify account and authenticate API calls, plus a mirror of product titles, images, prices and variants so campaigns can reference real products.
For discount codes minted for a campaign we process the code, the redemption count and the redemption timestamps, so that both the business and the creator can follow how the code performs. For orders attributed to a campaign code we process the order id, order totals, currency and the redeemed code, for commission settlement and fraud prevention. We receive this through Shopify's orders/* webhooks — we never query Shopify's Customer API for it. The buyer's email address is stored encrypted (AES-256-GCM with a keyed hash for lookup) and is automatically redacted by a weekly job after 18 months; the order record itself is kept as an accounting artefact.
Product samples in physical-product campaigns. When a creator accepts an offer for a physical product we create a zero-value order in the business's own Shopify store, carrying the creator's name and shipping address, so the business can send the sample. As soon as that order exists in the store, the business is an independent controller of it, exactly as for any other order in that store, and the creator's address is then also covered by the store's own privacy policy.
Uninstalling. When a store uninstalls the app its access token is wiped immediately and the connection itself is deleted 48 hours later, via Shopify's mandatory shop/redact webhook. The 48-hour window covers an accidental uninstall without leaving an unused token in place for longer than necessary.
If you are a customer of a merchant that uses Collabify, you exercise your rights through the merchant's and Shopify's own process, because the merchant — not Collabify — is the controller of your purchase. Shopify relays the request to every app installed on the store, including Collabify, through the mandatory customers/data_request and customers/redact webhooks. We act on them automatically, without you needing to contact Collabify directly.
6.2 Other social platforms
Collabify publishes to TikTok only. If we open a connection to another platform we will update this policy and the sub-processor register before it can be used, and you will approve the permissions yourself on that platform's own consent screen.
8. Transfers outside the EU/EEA
We prefer providers inside the EU/EEA, but some sub-processors process data in the United States or the United Kingdom. Where that happens we rely on the European Commission's Standard Contractual Clauses (SCC), and for the United Kingdom on the UK International Data Transfer Addendum (IDTA), together with supplementary measures such as encryption in transit and at rest and strict access control.
The mechanism that applies to each individual provider is stated in the sub-processor register. You can request a copy of the transfer documentation we rely on by writing to privacy@collabify.se.
9. How long we keep data
We keep personal data only as long as the purpose requires, then delete or anonymise it. The periods below follow our retention schedule, which is machine-readable and drives the automated purge jobs — so this is the period the system actually applies, not a statement of intent.
| Data | Kept for | Why |
|---|---|---|
| Account and profile data | Until you request deletion; the deletion runs after a 14-day cancellation window | Needed to provide the Service (Art. 6(1)(b)) |
| TikTok access and refresh tokens | Deleted immediately when you disconnect TikTok or delete your account | No longer required |
| Cached TikTok portfolio and statistics | At most 30 days | No longer required; re-fetched when needed |
| Messages inside a campaign | 2 years from each message, assessed case by case when one party requests erasure | One party's erasure must not wipe out the other party's record |
| Consent records (terms, cookies, messaging, notification settings) | 3 years after they stop applying | Evidence that consent was given and withdrawn (Art. 7(1)) |
| Publishing approvals for a TikTok post | Assessed case by case; the final term is not yet decided and the record is held for at most 10 years | The record is the evidence that you approved exactly that post — it is read during TikTok's review and in a payout dispute |
| Access and erasure request records | 3 years | Evidence that your request was handled correctly |
| Payments, payouts, invoices, commission records and order records | 7 years | Swedish Accounting Act (1999:1078) ch. 7 s. 2 and tax legislation |
| Signed contracts, contract documents and guardian consents | 10 years | Evidence of the contractual relationship and of the payout authorisation |
| Buyer email on a Shopify order attributed to a campaign code | 18 months, encrypted, then redacted | Commission settlement and fraud prevention (Art. 6(1)(f) and 6(1)(b)) |
| Security, fraud and administrator logs | Up to 7 years | Audit, dispute handling and protection of the Service (Art. 6(1)(f)) |
| A device's push token | Purged when the device has not been seen for about 6 months | No longer required |
9.1 Exceptions to the right to erasure
Article 17(3)(b) GDPR carves out the right to erasure where processing is necessary to comply with a legal obligation. In Sweden that is primarily the Accounting Act and tax legislation. When you request erasure we therefore go through each data category and do one of the following:
- Delete the record where no legal obligation prevents it.
- Keep the record but minimise the personal data in it where it is an accounting or tax artefact: the amounts, dates and audit chain remain, while identifying fields are nulled or pseudonymised. Once the statutory period expires the record is deleted outright.
- Keep the record as evidence where the record itself is the proof of a compliance event — a consent granted or withdrawn, or the erasure request itself. Deleting it would defeat its only purpose.
- Assess the record case by case where erasure would touch someone else's data, for example in a conversation between two parties.
You are always told which categories were kept and on what basis. A small number of tables do not yet have a final retention decision; for those we apply a case-by-case assessment rather than automatic deletion or indefinite retention, and the decision is recorded in the retention schedule once it is made.
10. Your rights
Under the GDPR you have the right to:
- Access the personal data we process about you and receive a copy of it (Art. 15).
- Have inaccurate data rectified or completed (Art. 16). Most of your profile you can change yourself in the app.
- Have data erased (Art. 17), subject to the exceptions described above.
- Request restriction of processing (Art. 18).
- Receive your data in a machine-readable format and transfer it to someone else (Art. 20).
- Object to processing we base on legitimate interests, including profiling (Art. 21).
- Withdraw consent at any time, with effect for the future — this covers newsletters, non-essential cookies and a scheduled TikTok post that has not yet been published (Art. 7(3)).
- Complain to a supervisory authority, primarily IMY (Art. 77).
10.1 How to do it in practice
- Delete your account. The app has "Radera konto" (Delete account) under Settings. A request stays cancellable for 14 days; after that the deletion runs automatically, your connections to TikTok and other services are revoked, and your data is deleted or minimised according to the exceptions above. If the app shows that self-service deletion is not yet switched on for your account, we carry out the deletion on request to privacy@collabify.se within the same timeframe. Some live commitments — an active campaign or an unpaid payout — must be closed first, and the app tells you exactly what is blocking and where to resolve it.
- Access and portability. A self-service data export exists in the platform (
/api/dsar/export) but is being rolled out in stages. Until it is switched on for your account, request your copy by writing to privacy@collabify.se and we will deliver it in a machine-readable format. - Other rights. Write to privacy@collabify.se. Telling us which right you want to exercise saves us both a round of questions.
- Complaints. You can go to IMY without contacting us first.
We acknowledge your request within 72 hours and answer within one month of receiving it. Where a request is complex that period can be extended by two months, and we will tell you within the first month if it is (Art. 12(3)). We may need to verify your identity before disclosing data — we will not ask for more information than that requires.
11. Security
We protect personal data with technical and organisational measures proportionate to the risk: encryption in transit (TLS) and at rest, field-level encryption of TikTok tokens, BankID envelopes and other secrets, access limited to the staff who need it, sign-in through a dedicated identity provider supporting multi-factor authentication, logging of administrative access, redaction of personal data before error reports leave our systems, and regular security reviews.
No system is completely secure. If we discover a personal data breach that is likely to result in a risk we notify IMY within 72 hours, and we inform you where the breach is likely to result in a high risk to your rights and freedoms (Art. 33–34).
13. Age requirements and minors
Business accounts may only be created by adults authorised to represent the business.
Creators must be at least 13 years old. A creator under 18 can take part in campaigns only with the consent of their guardian, which is given with BankID and kept as evidence; we use the keyed hash to check that the person signing is a different person from the creator. Certain campaign categories — including alcohol, gambling and other age-restricted marketing — are never offered to minors. For creators under 16 the earnings are administered by the guardian, as the Swedish Children and Parents Code requires.
A guardian can withdraw consent at any time; the contact detail we keep exists precisely to make that possible. If we learn that we hold data about a child in breach of these rules, we delete it.
14. Changes to this policy
We update this policy when the Service or the law changes. The version and date at the top of the page always show which text applies. For material changes we tell you in the app or by email before they take effect, and where the change requires it we ask you to accept the new version. Earlier versions are archived and available on request.
15. Contact
Contact details
- Controller
- JLRS AB, org. no. 559484-0323, c/o Mailboxes ETC, Riddargatan 3, 114 11 Stockholm
- Data protection officer
- privacy@collabify.se
- Support
- support@collabify.se
- Supervisory authority
- The Swedish Authority for Privacy Protection (IMY)
If you have questions about this policy or about how we process your data, write to privacy@collabify.se. For anything that is not a data protection matter, reach us at support@collabify.se.
