TrustaMarketerSign in

The paperwork

Privacy Policy

What we collect, why, who touches it, and your rights — written to be read. No tracking, no ad-tech, no selling data. The short version is that we hold what a marketplace of real money and real evidence has to hold, and nothing else.

Last updated: 13 July 2026

1.Who is responsible

TrustaMarketer is a pre-launch service. A UK limited company (intended name: TrustaMarketer Ltd) is being incorporated to operate it and will assume these terms; this page will be updated with the registered company details as soon as incorporation completes.

The operator of TrustaMarketer is the data controller for the personal data described here. For anything in this policy — questions, complaints, or exercising your rights — contact support@support.trustamarketer.com.

2.What we collect

  • Account: email address, name, and how you sign in. Google sign-in shares your name, email, and avatar from Google. Passkeys store only a public key — the biometric never leaves your device and we never see it.
  • Workspaces: team names, membership, and invitations you send.
  • Spaces: for social accounts — the handle you register and public platform data fetched during verification (bio, follower counts). For physical spaces — a public, approximate location (city or area) and a private, precise address. The precise address is never public: it is shared only with a brand whose campaign you have been accepted to (for example, to post materials). Verification photos you upload are kept as evidence of the verification decision.
  • Marketplace activity: campaigns, applications, messages between parties, proof of work (links, screenshots, photos, metrics), reviews, and print artwork.
  • Money: payments are processed by Stripe — we never hold full card numbers. We keep transaction records: amounts, fees, payment status, payout records, and the numbered receipts and statements the product issues. Payout onboarding data (identity, bank details) is collected and held by Stripe under its own terms.
  • Notifications: your email address and, if you enable them, push subscription endpoints and keys for the devices you enabled, plus your per-category preferences.
  • The record: an audit log of significant actions (who did what, when) — acceptance, publication, money movements, moderation decisions. This is load-bearing for dispute resolution and fraud prevention.
  • Technical: server logs including IP addresses, used for security and rate limiting. Cookies are strictly the essential ones: your session, security, and a small cookie remembering how you last signed in. There are no analytics or tracking cookies, which is why there is no cookie banner.

3.Why we process it (lawful bases)

  • Running the marketplace — accounts, campaigns, applications, messaging, payments, payouts, receipts: performance of our contract with you.
  • Trust and safety — verification, computed standing, fraud prevention, moderation, the audit log: our legitimate interest in a marketplace that both sides can rely on, balanced against your rights.
  • Financial records — kept as required by tax and accounting law: legal obligation.
  • Push notifications — sent only where you enabled them on a device: consent, withdrawable per device at any time in the dashboard.
  • Sensitive-category participation — your explicit opt-in is recorded with its timestamp when you apply to a labelled campaign.
  • Service email — transactional mail about your own activity (sign-in codes, acceptances, payouts): contract. We send no marketing email.

4.Automated decisions

One automation can accept on a human’s behalf: a brand may enable autopilot, which accepts applications that clear the brand’s own stated rules. It never rejects anyone— applications it doesn’t accept wait for a person. Adverse decisions (rejections, verification failures, moderation) are made by people, and reviewable ones come with the reason stated.

5.Who sees your data

Other users, as the marketplace requires: public campaign listings show what the brand chose to publish plus its computed track record; public team profiles show what you wrote, your logo, and computed history. Physical-space precise addresses are shared only after acceptance, as above. Messages are visible to the two parties of an application.

Service providers (processors), each doing one job:

  • Fly.io — application hosting (London region) and our database.
  • Cloudflare R2 — file storage (EU region) for uploads: photos, artwork, logos. Files are private; access is via short-lived signed URLs.
  • Resend — sending and receiving email (EU region).
  • Stripe — payments, payout accounts, and payment-method verification. Stripe may transfer data outside the UK/EEA under its own safeguards.
  • Google — optional Google sign-in; and the YouTube Data API for verifying YouTube channels (public channel data only — see section 6).
  • Browser push services (Apple, Google, Mozilla — chosen by your browser) — deliver push notifications you enabled; payloads are encrypted to your device.

We disclose data to authorities where the law requires it. We do not sell personal data, and nothing here is shared for advertising.

6.YouTube API Services

Verifying a YouTube space uses YouTube API Services to look up public channel data (handle, public subscriber count) at your request; the result is stored as verification evidence. By verifying a YouTube space you also agree to the YouTube Terms of Service; Google’s handling of data is described in the Google Privacy Policy.

7.Where data lives

Primary hosting and storage are in the UK and EU (London; EU regions for files and email). Where a processor transfers data outside the UK or EEA — principally Stripe — the transfer is covered by recognised safeguards (adequacy, the UK IDTA, or standard contractual clauses).

8.How long we keep it

  • Account and workspace data: while your account is active, then deleted or anonymised within a reasonable period.
  • Financial records (transactions, receipts, statements): the period tax and accounting law requires — in the UK, typically six years.
  • Evidence of transactions — proof of work, verification evidence, messages, the audit log: retained while relevant to potential disputes, chargebacks, or fraud, then removed.
  • Push subscriptions: until you disable them, the browser revokes them, or delivery permanently fails.

If you ask us to delete your data, we do — except what we must keep for the legal and dispute purposes above, which is retained only for those purposes and then removed.

9.Security

Everything moves over TLS. Sign-in supports passkeys and one-time codes rather than passwords. Tenancy is enforced at the data layer (a workspace cannot read another’s data), database roles are least-privilege, uploaded files are private behind signed URLs, and money and state changes are audit-logged.

10.Your rights

Under UK GDPR you can ask for access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing rests on consent (push notifications), you can withdraw it at any time. Write to support@support.trustamarketer.com — we respond within a month. You can also complain to the Information Commissioner’s Office (ico.org.uk), though we’d appreciate the chance to fix things first.

11.Age

TrustaMarketer is for adults. You must be 18 or over to use it.

12.Changes to this policy

When this policy changes materially we’ll notify you by email or in the product, and the date at the top always tells you when it last moved.