Privacy Policy - #club

Version 1.2

In plain language

What we collect: your name, contact details, social handles, connected platform analytics, PAN and bank details (only if you receive money), and technical device data.

Why: to run the Platform, match you to deals, verify your performance, release escrow, and comply with tax law.

Who sees it: brands see only aggregate, non-identifying data about you until you accept a deal. Full analytics unlock only after acceptance. Our service providers see data only to the extent needed to run the Platform.

What we don't do: we don't sell your data. We don't use your likeness in our advertising unless you separately opt in. We don't process under-18s.

Your rights: access, correction, erasure, grievance, and nomination. Contact our Grievance Officer at support@hashtagclub.co.

One thing to know: where a deal uses metric-gated release, an automated system decides whether your payout is released. You can always ask for a human to review it - see Clause 12.

This summary is for convenience. Where it differs from the clauses below, the clauses govern.

1. Introduction and scope

1.1 This Privacy Policy describes how Hashtag Club ("#club", "we", "us", "our") collects, uses, discloses, retains and protects personal data when you access or use the Platform.

1.2 For the purposes of the Digital Personal Data Protection Act, 2023, #club is the Data Fiduciary in respect of personal data it processes, and you are the Data Principal.

1.3 This Policy forms part of the Agreement as defined in the Terms of Service and is incorporated into it by reference. Capitalised terms not defined here have the meanings given in the Terms.

1.4 This Policy applies to all Users - Creators, Brands, and visitors to the Platform - and to personal data processed in connection with the Services, the Referral Program, and #club's own marketing content.

1.5 Consent notice. By using the Platform you confirm that you have been informed, in clear and plain language, of the personal data collected (itemised in Schedule A); the purposes of processing (Clause 5); the manner in which you may exercise your rights (Clause 13); the manner in which you may complain (Clause 14); and the identity and contact details of the Data Fiduciary and its Grievance Officer (Clauses 1.6 and 14).

1.6 Data Fiduciary and Grievance Officer. Hashtag Club, Villa 83, Vishal Sanjivini, 168, Ecity and Fab City Road, Tukkuguda, Hyderabad 501359. Grievance Officer and Data Protection Contact: Manish Maryada, support@hashtagclub.co. We acknowledge within 48 hours and resolve within 15 days.

2. Legal bases for processing

2.1 We process personal data on the following bases:

  • Consent - the primary basis for most processing, given freely, specifically, informedly and unambiguously, by a clear affirmative action, and withdrawable at any time under Clause 13.5.
  • Legitimate use - processing necessary to perform the Agreement with you, to administer escrow, to verify Content and metrics, and to respond to a request you have made.
  • Compliance with law - processing required by the Income Tax Act, 2025, the Information Technology Act, 2000 and Rules, the Prevention of Money Laundering Act, 2002, the Consumer Protection Act, 2019, and directions of any competent authority, court, or the Data Protection Board of India.
  • Vital interests and public interest - in limited circumstances as permitted by law.

2.2 Where we rely on consent, we record the fact, time, scope and manner of consent, and can produce that record on request.

2.3 Granularity. Consent is obtained separately for each distinct purpose. Bundled, blanket or pre-ticked consent is not used. In particular, consent to the Model Release and Content Consent for #club's own marketing is obtained entirely separately from consent to this Policy - see Clause 11.

3. What we collect

3.1 The personal data we collect is itemised in Schedule A, which forms part of this Policy.

3.2 In summary, we collect identity and contact data (name, email, mobile number, city, date of birth, optional gender, profile photograph); account and credentials data; social and audience data obtained only through official platform APIs after your own authorised account connection; deal and transaction data; financial data (PAN, bank account details, UPI identifier, payment and escrow references, subscription records, referral balances, tax deduction records); business data for Brands (legal entity name, GSTIN, CIN, registered address, beneficial ownership, category, authorised signatory, and FIU-IND registration number where applicable); technical data; communications data; and, where you separately opt in, marketing participation data.

3.3 We do not collect Aadhaar. We collect PAN and bank details only. PAN is collected because we are required to deduct tax at source in respect of monetary rewards.

3.4 We do not knowingly collect data from anyone under 18. See Clause 10.

3.5 Sensitive data. We treat financial data, PAN, precise audience analytics, and any data revealing religious or political opinion as requiring heightened care, and apply the safeguards in Clause 8. We do not seek data revealing caste, religion, ethnicity, health, biometrics or sexual orientation, and you must not provide it.

4. Cookies, device data and tracking

4.1 We use cookies and similar technologies for the following purposes:

CategoryPurposeEssential?
Strictly necessaryAuthentication, session integrity, security, load balancingYes - cannot be disabled
FunctionalRemembering preferences, language, UI stateYes
AnalyticsUnderstanding usage to improve the PlatformConsent-based
Advertising and measurementMeasuring campaign effectiveness, remarketingConsent-based

4.2 Non-essential cookies and tracking are deployed only with your consent, obtained through a cookie preference interface on first visit, which is not pre-ticked and which permits you to accept only essential cookies without losing access to the Platform.

4.3 You may change cookie preferences at any time, and may block cookies through your browser settings. Some features may not function if you do.

4.4 We do not sell cookies data and do not build advertising profiles of Users for third-party sale.

4.5 Do Not Track. We do not currently respond to Do Not Track signals.

Note(legal): the cookie preference interface described in 4.2 is not built yet, and no analytics or advertising cookies are deployed today - so nothing non-essential is set without consent, because nothing non-essential is set at all. This clause must be revisited on the same day any analytics or pixel tag is added.

5. Purposes of processing

5.1 We process personal data for the following specific, itemised purposes, and for no others:

#PurposeBasis
P1Create and administer your accountLegitimate use
P2Verify eligibility, identity and audience authenticityLegitimate use
P3Match creators to suitable deals and brands to suitable creatorsConsent
P4Display aggregate, non-identifying creator profiles to brands pre-dealLegitimate use
P5Administer reservation, content submission and verificationLegitimate use
P6Ingest and measure performance metrics via official platform APIsConsent
P7Determine escrow release under the applicable Release ModeLegitimate use
P8Administer adjudication, manual intervention and disputesLegitimate use
P9Detect inauthentic audience and enforce platform integrityLegitimate use
P10Process payments, refunds, payouts and escrow instructionsCompliance with law
P11Comply with tax obligations, including TDS and issuing Form 16ACompliance with law
P12Administer the Referral ProgramConsent
P13Provide customer support and grievance redressalLegitimate use
P14Ensure platform security, prevent fraud, maintain audit recordsLegitimate use
P15Comply with legal and regulatory obligations and lawful requestsCompliance with law
P16Send transactional notifications relating to a deal you are party toLegitimate use
P17Send marketing communications about #clubConsent - separately obtained
P18Use your name, image, voice and likeness in #club's own marketingConsent - Model Release
P19Improve the Platform, and conduct aggregated analytics and researchConsent

5.2 Purpose limitation. Personal data collected for one purpose is not used for another without fresh, separate consent, except where required by law.

5.3 In particular, analytics data ingested under P6 is used only for P3, P4, P7, P8 and P9. It is not used to build advertising profiles, is not sold, and is not used for any purpose unrelated to deal facilitation and verification. This is a condition of our use of third-party platform APIs and we treat it as binding.

5.4 Data minimisation. We collect only data adequate, relevant and necessary for the stated purposes.

6. Social platform analytics - official API ingestion

6.1 Analytics data is obtained only through official platform APIs - the Instagram Graph API, Instagram Login for Business, the YouTube Data API and YouTube Analytics API, or their equivalents - and only after you have initiated and authorised the account connection through that platform's own consent flow. The permissions we request from Meta, the data each returns, and why we need it, are these. We request nothing beyond them.

PermissionWhat it lets us readWhy we need it
public_profileThe basic public profile returned when you log in - an app-specific user ID, your name, and your profile picture URLTo create and link your #club login session, to know the same person has returned, and to render your own profile back to you
instagram_business_basicYour Instagram business profile - username, account type, profile picture, follower count - and your media, with caption, permalink, media type, timestamp, and like and comment countsTo confirm you are who your profile says you are, that the account is a professional account, that your audience meets the threshold in the deal brief, and that the content you submitted was actually posted to your own account
instagram_business_manage_insightsInsights for your account and for individual media - reach, impressions, views, plays, saves, shares, profile visits, and follower movement over the measurement windowTo measure whether a metric-gated deal achieved the committed number, and to detect inauthentic-audience patterns such as a follower spike with no corresponding reach

We do not request permission to read or moderate your comments, to access your direct messages, to publish on your behalf, or to read your friends list, your posts on Facebook, or anything on Facebook other than the basic public profile above. The user ID returned under public_profile is app-specific: it is not your Facebook ID and it cannot be used by anyone else to look you up on Facebook.

6.2 You control the connection. You may disconnect at any time, either through your social platform's app and website permissions or through the Platform. On disconnection we stop ingesting new data, and Clause 9 governs deletion of data already collected. See Data Deletion Request.

6.3 We do not scrape. #club does not scrape, crawl, harvest or collect data from any third-party platform by means other than its official API, and does not access any account using credentials other than tokens you have authorised.

6.4 Meta Platform Terms - Limited Use. In respect of data obtained from Meta products we comply with the Meta Platform Terms and Developer Policies, including the Limited Use requirements. Specifically: we use the data only to provide the Services to you and to the Brand party to your deal; we do not sell Meta-originated data; we do not transfer it to any third party except to a service provider processing it on our behalf under a written contract, to the Brand party to your deal, or where required by law; we do not use it for advertising, marketing or any purpose other than as permitted; we do not use it to inform, establish or influence creditworthiness, eligibility for credit, insurance, employment, housing or any similar determination; we do not measure or build audiences for advertising purposes other than as expressly permitted; and we maintain a working data deletion mechanism at hashtagclub.co/data-deletion and implement Meta's user data deletion callback.

6.5 API access tiers. Access to certain advanced permissions requires Meta App Review and Business Verification. Where a permission is not yet granted, we will tell you which features are unavailable rather than substituting a non-compliant data source. We connect Instagram accounts through the Instagram API with Instagram Login, not through a linked Facebook Page.

6.6 Reliance and accuracy. Third-party analytics are the platform's data, not ours. We do not warrant that they are complete, accurate or current.

7. Disclosure of personal data

7.1 Two-stage visibility to Brands. Before you accept a deal, a Brand sees only aggregate, non-identifying data: follower band, engagement-rate band, content category, broad geography and content style. A Brand does not see your handle, your name, your detailed audience demographics, or your per-post performance. After you accept a deal, the Brand party to that deal sees full handle-level analytics for the connected accounts, including audience demographics, per-post performance, reach and impressions, and verification of the committed metrics.

7.2 That second-stage disclosure is limited to the specific Brand party to the deal, the specific accounts connected for that deal, the period necessary for verification and the measurement window, and the purposes of verification, adjudication and deal administration only.

7.3 Brands are independent Data Fiduciaries. Once data is disclosed to a Brand under the second stage, the Brand processes it as an independent Data Fiduciary for its own purposes and is separately responsible under the DPDP Act. #club does not control, and is not responsible for, a Brand's subsequent processing. The Brand's use is contractually limited by Clauses 11 and 22 of the Terms of Service.

7.4 Visibility to other Users. Your public profile, portfolio and published Content are visible to other Users in accordance with your privacy settings. You control these settings and should review them.

7.5 Service providers and processors. We share personal data with the processors listed in Schedule B, solely to the extent necessary for them to perform their function, and under written contracts imposing confidentiality, security and DPDP-compliant obligations.

7.6 Escrow and payment partners. We share financial data with the Escrow Partner and payment partners to hold, administer and disburse Deal Value, to process subscription payments, and to make referral payouts. The Escrow Partner is an independent regulated entity and processes that data as a fiduciary in its own right.

7.7 No sale of data. We do not sell, rent, trade or barter personal data. We do not share personal data with data brokers or advertising networks for their own independent purposes.

7.8 Disclosures required by law. We may disclose personal data to comply with any law, regulation, subpoena, court order, or direction of the Government, the Data Protection Board of India, the Central Consumer Protection Authority, the Advertising Standards Council of India, FIU-IND, the Income Tax Department, or any other competent authority; within the timelines prescribed by the IT Rules, 2021; to third-party platforms, where required by their terms or a lawful process; to enforce the Agreement or to protect the rights, safety or property of #club, its Users or the public; to professional advisers under confidentiality obligations; and in connection with a merger, reorganisation, incorporation of #club as a company, sale of assets or change of control, provided the acquirer agrees to be bound by this Policy or issues a fresh consent notice.

7.9 We will notify you of a disclosure required by law unless prohibited from doing so.

7.10 Aggregate and de-identified data. We may use and disclose aggregated or de-identified data that does not identify you, including platform-level statistics, category benchmarks and market reports. Where re-identification is reasonably possible, the data is not treated as de-identified.

8. Security safeguards

8.1 We implement reasonable technical and organisational safeguards to protect personal data against unauthorised access, disclosure, alteration, destruction or loss, including: encryption in transit (TLS 1.2 or higher); encryption at rest (AES-256 or equivalent), with separate encryption or tokenisation for PAN and bank account details; role-based access control on least privilege, with access to financial data restricted to named personnel on a need-to-know basis; multi-factor authentication for all personnel with access to production systems; audit logging of access to personal data, with alerting on anomalous access; firewalls, intrusion detection, dependency scanning and periodic vulnerability assessment; encrypted, geographically separated backups with tested restoration; confidentiality obligations and data-protection training for personnel; contractual security obligations on all processors; and periodic review of these safeguards.

8.2 No system is secure. While we take these measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials.

8.3 Breach notification. In the event of a personal data breach we will notify the Data Protection Board of India in the prescribed form and within the prescribed timeline, and in any event without undue delay; notify each affected Data Principal in clear and plain language, describing the breach, the data concerned, the likely consequences, the measures taken and the remedial steps available to them; and take all reasonable steps to contain and remediate the breach.

9. Retention and deletion

9.1 Retention schedule.

Data categoryRetention periodReason
PAN and tax deduction records8 years from the relevant financial yearIncome Tax Act, 2025
Escrow and payment transaction records8 yearsIncome Tax Act; partner requirements
GST invoices and tax records6 years, or longer if requiredCGST Act, 2017
Deal records, content, verification and determinations3 years from completion or terminationLimitation and dispute defence
Dispute and grievance records3 years from resolutionDispute defence
Account and identity data (active)Duration of the account plus 3 yearsContract performance
Account and identity data (after closure)3 years from closure, then deleted or anonymisedLimitation period
Social analytics ingested via APIDuration of the connection, plus each deal's measurement window, plus 3 yearsMeta Platform Terms; dispute defence
Technical and log data12 monthsSecurity
Marketing consent recordsDuration of consent plus 3 yearsProof of consent
Inauthentic-audience findings and blacklist recordsIndefinitelyPlatform integrity

9.2 Deletion on erasure request. On a valid erasure request under Clause 13.4 we delete or anonymise the relevant personal data without undue delay and within 30 days, except where retention is required or permitted by law. Where an exception applies we will tell you what we retained and why.

9.3 Third-party deletion. We will instruct each processor to delete the relevant data and will confirm deletion where the processor provides a mechanism. We cannot delete data that a Brand holds as an independent fiduciary under Clause 7.3, or data already published on a third-party platform.

9.4 Meta deletion requirement. We maintain a data deletion request mechanism at hashtagclub.co/data-deletion and implement Meta's user data deletion callback, satisfying the deletion requirements of the Meta Platform Terms.

10. Children

10.1 The Platform is not for anyone under 18. We do not knowingly collect, process or store personal data of any individual under 18, and we do not offer services directed at children.

10.2 Because we exclude under-18 Users entirely, the specific obligations applicable to processing children's personal data - verifiable parental consent, prohibitions on behavioural monitoring and targeted advertising toward children - do not arise in respect of Users.

10.3 Children appearing in Content. Where a minor appears in Content created by an adult Creator or in a Brand's campaign, that Content may contain the minor's image and likeness, which is personal data. Responsibility for obtaining documented verifiable parental consent, and for compliance with the NCPCR Guidelines and all applicable child-protection law, rests with the Creator, who warrants under Clause 13.1 of the Terms that they hold it, and with the Brand, who indemnifies #club under Clause 22.1. #club does not verify parental consent and does not accept responsibility for it.

10.4 Pet accounts. Accounts representing animals are operated by adults. Data collected is the adult operator's data. No animal is a Data Principal.

10.5 If we learn that we have collected personal data of a person under 18, we will delete it promptly and terminate the account. If you believe we hold such data, contact the Grievance Officer.

11. #club's own marketing content - separate consent

11.1 #club produces its own marketing content, including influencer game-show formats, interviews, features and user-generated content campaigns.

11.2 Participation is governed by a separate Model Release and Content Consent. That consent is presented separately from this Policy and from the Terms, and is never pre-ticked; is not bundled with signup, subscription, account connection or deal acceptance; itemises each specific purpose separately - filming, use of name, image, voice, likeness, performance, editing, distribution across #club channels, and paid advertising use - so that each may be given or withheld independently; states the duration and territory of the licence; may be declined with no adverse consequence of any kind; and may be withdrawn prospectively by notice to the Grievance Officer.

11.3 Effect of withdrawal. Withdrawal stops future use of your name, image, voice and likeness in new #club marketing. It does not require removal of content already published or already in circulation, nor of content in respect of which third parties have acquired rights. We will tell you specifically what we can and cannot withdraw, and we will remove content under our control within 30 days.

11.4 Without the Model Release, we do not use your name, image, voice or likeness in #club advertising. The licence in Clause 11.8 of the Terms expressly does not extend to advertising use of your likeness absent that separate consent.

11.5 Non-User participants. Where a participant is not a registered User, a written appearance agreement is signed before filming, and this Clause applies in equivalent fashion.

12. Automated decision-making

12.1 Where a deal uses metric-gated release, an automated system determines whether your payout is released. This is automated processing with a significant financial effect on you, so we set out exactly how it works and what you can do about it.

12.2 How it works. #club's systems ingest performance metrics through official platform APIs and compare them mechanically against the committed metrics and the Acceptance Checklist recorded in the deal brief. Where the criteria are met, release is instructed automatically. Where they are not, the make-good ladder in Clause 8.5 of the Terms applies.

12.3 What it does not do. The system does not profile your personality, does not assess your creditworthiness or eligibility for credit, does not make employment-related determinations, and does not decide whether you may use the Platform.

12.4 Transparency. The criteria applied to any deal are the criteria you accepted in the deal brief before reserving. There are no undisclosed or hidden criteria. You can see the Acceptance Checklist, the committed metrics, the measurement window and the elected Release Mode at all times.

12.5 Your right to an explanation. You may request, in writing, an explanation of any automated determination made about you, and we will provide the measured values, the criteria applied, the measurement window, and the outcome, within 30 Business Days.

12.6 Your right to human review. You may request human review of any automated determination within forty-eight (48) hours of being notified of it. Human review is conducted under Tier 3 of the adjudication ladder in Clause 10 of the Terms, and results in a written determination with reasons. Human review is not a token step - a human reviewer may reach a different conclusion from the automated system, and may override it.

12.7 Safeguards. We maintain documented and version-controlled criteria; audit logging of every determination; retention of determination records under Clause 9.1; periodic accuracy testing of the measurement pipeline; and an escalation path where API data is unavailable, inconsistent or demonstrably unreliable.

13. Your rights as a Data Principal

13.1 You have the following rights, exercisable free of charge, by contacting the Grievance Officer or through hashtagclub.co/data-deletion. We respond within 30 days, extendable where the request is complex, and we will tell you if we extend.

13.2 Right to information and access. You may request a summary of the personal data we process about you; the identities of all Data Fiduciaries and Data Processors with whom we have shared it, together with the categories shared; the purposes of processing; and a copy of the personal data itself, in a structured, commonly used and machine-readable format.

13.3 Right to correction, completion and updating. You may request correction of inaccurate or misleading data, completion of incomplete data, and updating of out-of-date data. We will notify the relevant counterparties - including any Brand who received the incorrect data - where doing so is practicable and appropriate.

13.4 Right to erasure. You may request erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to Clause 9.2 and to retention required or permitted by law.

13.5 Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time, and withdrawal must be as easy as giving consent. We stop the processing that depended on that consent, prospectively; withdrawal does not affect the lawfulness of processing before it; where the consent was necessary to perform the Agreement - for example analytics ingestion required to verify a metric-gated deal - withdrawal may make it impossible to complete in-flight deals, and we will tell you that before it takes effect; and withdrawal does not affect data we are required to retain by law.

13.6 Right to grievance redressal. You have the right to readily available grievance redressal in respect of any act or omission by us relating to your personal data. See Clause 14.

13.7 Right to nominate. You may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity. Nominations may be made or changed through the Grievance Officer.

13.8 Exercising rights. Write to the Grievance Officer with your registered email address, the right you wish to exercise, and sufficient detail. We may require identity verification before disclosing data. We will not charge for a request unless it is manifestly unfounded or excessive, in which case we will tell you before proceeding.

13.9 No adverse consequence. You will not be disadvantaged, deprioritised, de-ranked or charged differently for exercising any right under this Clause.

14. Grievance redressal and complaints

14.1 First, contact us. Write to the Grievance Officer at support@hashtagclub.co with your registered email address, the nature of the complaint, supporting material, and the relief sought.

14.2 Our service levels. We acknowledge within forty-eight (48) hours of receipt, and resolve within fifteen (15) days of receipt, or tell you why we need longer and when we expect to conclude.

14.3 Escalation within #club. If the Grievance Officer's response is unsatisfactory you may escalate to support@hashtagclub.co, and we will respond within 15 days.

14.4 Then, the Data Protection Board of India. If you remain dissatisfied, you have the right to approach the Data Protection Board of India, the regulator constituted under the DPDP Act, through the channels it publishes.

14.5 Other complaints. Complaints relating to advertising standards may be made to the Advertising Standards Council of India; consumer complaints to the Central Consumer Protection Authority or the relevant Consumer Commission; intermediary-related complaints under the IT Rules, 2021.

14.6 Lawful requests. We act on lawful requests from Government, courts, the Data Protection Board and other competent authorities within the timelines prescribed by law.

15. Cross-border transfer

15.1 #club operates a mixed hosting environment. Our primary application database, authentication and file storage are hosted on Supabase in the Seoul region (ap-northeast-2), outside India. Payment and OTP processing are performed in India. Other processors and their locations are listed in Schedule B.

15.2 We may transfer personal data outside India unless the Central Government has, by notification, restricted transfer to that country or territory. We monitor such notifications and will suspend transfers to a restricted jurisdiction.

15.3 Where we transfer personal data outside India we do so under written contracts imposing confidentiality, security and DPDP-compliant obligations, and we rely on our processors' own compliance frameworks. We remain responsible as Data Fiduciary for data transferred on our instructions.

15.4 The specific hosting locations and transfer destinations are recorded in Schedule B. You may request a current copy from the Grievance Officer.

16. Marketing communications

16.1 Transactional communications relating to a deal you are party to, your account, your escrow, verification, or a grievance you have raised are sent as necessary to perform the Agreement. You cannot opt out of these while your account is active.

16.2 Marketing communications about #club, new features, category reports and Referral Program promotions are sent only with your separate consent, obtained at signup or thereafter through your preferences.

16.3 You may withdraw marketing consent at any time through your communication preferences, by clicking unsubscribe in any marketing email, by replying STOP to any marketing SMS, or by contacting the Grievance Officer.

16.4 We process withdrawal within 5 to 7 Business Days. Transactional messages continue.

16.5 TRAI compliance. We respect the Telecom Commercial Communications Customer Preference Regulations. We do not send promotional SMS or make promotional voice calls to numbers registered on the Do-Not-Disturb registry, and we send promotional communications only within permitted hours and categories.

16.6 WhatsApp. Where we communicate via WhatsApp we do so in compliance with the WhatsApp Business and Commerce Policies, including their requirements on user opt-in, message categories and prohibited content. Your opt-in to WhatsApp is recorded separately and may be withdrawn separately.

17. Third-party links and platforms

17.1 The Platform contains links to third-party websites, social platforms, Brand websites and payment interfaces. This Policy does not apply to them. Review their privacy policies before providing data.

17.2 Third-party platforms - Instagram, YouTube and others - process your data under their own policies when you connect an account or publish Content. We are not responsible for their processing.

17.3 Brands receiving data under Clause 7.3 are independent Data Fiduciaries responsible for their own processing.

18. Referral program data

18.1 To administer the Referral Program we process the referrer's and referee's identity and contact data, the referral relationship and chain, the referral event, reward status, withdrawal requests, and - for cash withdrawal - PAN and bank details.

18.2 Referrer-invited third parties. Where you invite a person who is not yet a User, we use the contact details you provide solely to send that invitation, and we do not add them to any marketing list without their own consent. You represent that you have that person's permission to share their contact details with us.

18.3 Cash referral rewards are subject to tax deduction at source. We process PAN and reward amounts for that statutory purpose and to issue Form 16A.

18.4 Further detail is in the Referral Program Policy.

19. Data accuracy

19.1 We take reasonable steps to ensure personal data is accurate, complete and, where necessary, kept up to date - by collecting data directly from you wherever practicable, ingesting analytics from official platform APIs rather than from self-report, providing self-service editing of profile data, and correcting data on request under Clause 13.3.

19.2 You are responsible for keeping your account data - particularly bank and PAN details - accurate and current. Clause 4.1 of the Terms applies to failures caused by stale data.

20. Changes to this policy

20.1 We may update this Policy to reflect changes in law, our processing, our stack or our Services.

20.2 For material changes we will give not less than fifteen (15) days' notice by email and in-app notification, and we will update the version above.

20.3 Where a change materially expands the purposes of processing or the categories of data collected, we will seek fresh consent rather than rely on continued use.

20.4 Continued use of the Platform after the effective date of a non-material change constitutes acceptance.

20.5 Previous versions are archived and available on request to the Grievance Officer.

21. Contact

Data Fiduciary: Hashtag Club.

Grievance Officer and Data Protection Contact: Manish Maryada, support@hashtagclub.co. We acknowledge within 48 hours and resolve within 15 days.

Data deletion requests and exercising your rights: hashtagclub.co/data-deletion.

Schedule A - Itemised data inventory

Every item of personal data we hold, its source, the purposes from Clause 5.1 it serves, and how long we keep it.

#Data itemSourcePurposesRetention
A1Full nameYouP1, P2, P10, P11, P12Account + 3 years
A2Email addressYouP1, P13, P16, P17Account + 3 years
A3Mobile numberYouP1, P13, P16, P17Account + 3 years
A4Date of birthYouP1, P2Account + 3 years
A5City and stateYouP3, P4Account + 3 years
A6Gender (optional)YouP3Account + 3 years
A7Profile photographYouP1, P4Account + 3 years
A8Username and hashed passwordYouP1, P14Account + 3 years
A9Social handles and URLsYouP2, P3, P4, P6Connection + 3 years
A10Follower and subscriber countsOfficial APIP2, P3, P4, P7, P9Connection + window + 3 years
A11Engagement rate, reach, impressionsOfficial APIP3, P4, P7, P9As A10
A12Audience demographicsOfficial APIP4, P7As A10
A13Per-post performance dataOfficial APIP5, P6, P7, P8As A10
A14Content submitted under a dealYouP5, P8Deal + 3 years
A15Checklist outcomes and determinations#club systemsP5, P7, P8Deal + 3 years
A16Dispute records and submissionsYou / #clubP8, P13Resolution + 3 years
A17PANYouP10, P11, P128 years
A18Bank account name, number, IFSCYouP10, P128 years
A19UPI identifierYouP10, P128 years
A20Escrow and payment referencesEscrow PartnerP7, P108 years
A21Subscription payment recordsPayment partnerP10, P118 years
A22Referral chain, status and balances#club systemsP12Account + 3 years
A23TDS records and Form 16A data#club systemsP118 years
A24Brand entity name, GSTIN, CIN, addressBrandP1, P2, P11Account + 8 years
A25Brand beneficial ownershipBrandP2, P14Account + 3 years
A26FIU-IND registration numberBrandP2, P15Account + 8 years
A27IP addressAutomaticP9, P14, P1912 months
A28Device identifiers, type, OS, browserAutomaticP14, P1912 months
A29Approximate location from IPAutomaticP3, P1412 months
A30Referring URL, pages viewed, clickstreamAutomaticP1912 months
A31Session duration, time zone, languageAutomaticP1912 months
A32Crash and diagnostic logsAutomaticP1412 months
A33Support messages and call recordingsYou / #clubP13Resolution + 3 years
A34Marketing consent records#club systemsP17Consent + 3 years
A35Cookie preferences#club systemsP19Consent duration
A36Name, image, voice, likeness in #club marketingYouP18 onlyPer Model Release
A37Inauthentic-audience findings and blacklist ids#club systemsP9, P14Indefinite
A38Audit logs of access to personal dataAutomaticP1424 months

Not collected: Aadhaar number or copy; biometric data; caste, religion or ethnicity; health data; sexual orientation; precise geolocation; contacts from your device; SMS content; call logs.

Schedule B - Processors and recipients

The third parties that process personal data on our behalf or receive it from us, what each does, which Schedule A items it touches, and where it holds them.

#ProcessorFunctionDataLocation
B1SupabasePrimary database, authentication, file storage, server functionsAllSeoul, South Korea (ap-northeast-2)
B2VercelWeb application hosting and deliveryA27-A32Global edge network
B3RazorpayPayment processing, disbursement, subscription billingA17-A21India
B4MSG91One-time password delivery by SMSA3India
B5SentryError and crash reportingA27, A28, A32United States
B6DigiLocker (Government of India)KYC document verificationA17India
B7Meta Platforms (Instagram)Official API source - we receive from, not send toA9-A13Per Meta
B8Google (YouTube)Official API source - we receive from, not send toA9-A13Per Google
B9Regulators and competent authoritiesLegal complianceAs requiredIndia
Note(legal): this schedule is rebuilt from the processors the codebase actually integrates with. The written contracts, DPDP-compliant terms and hosting commitments referred to in Clauses 7.5 and 15.3 must be confirmed against each vendor's current agreement before this page is relied on in a regulatory filing. Adding any new vendor that touches personal data means adding a row here in the same change.

Related documents