Privacy Policy
Version 2.0 · Last updated: August 25, 2026
1. Who we are
Rovalty (Upstal, "Rovalty", "we") operates rovalty.com and the Rovalty app for commerce platforms: a service that connects e-commerce merchants ("Merchants") with content creators ("Creators") for user-generated-content and clipping campaigns, tracks published videos, and administers performance-based creator earnings, and issues the weekly payment statements merchants settle directly with creators. Privacy contact: upstalproject@gmail.com.
2. Data we collect
From Merchants
- Store information via the commerce platform's API (Shopify): store name, contact email, domains, plan type, and — solely for sample orders our app itself creates — order and fulfillment status. We request only the API scopes the service needs.
- Billing metadata (plan, subscription status). Recurring charges are processed by Shopify. We never handle payments between merchants and creators, so we store no card numbers and no bank credentials of our own.
From Creators
- Account data: name, email, password (stored only as a salted argon2id hash).
- Social account data, only after you explicitly link an account via each platform's official OAuth flow: account/channel identifiers and public video statistics (views, likes, comments, shares) for videos you submit to campaigns. We use official APIs only — YouTube Data API, TikTok Display API, Instagram API — and never scrape.
- Payment details you register (PayPal address, bank, Wise or Payoneer reference) so that the merchant who owes you can pay you directly. These are encrypted at rest and disclosed only to a merchant with a statement owing to you — Rovalty never uses them to move money. Also your shipping address for product samples.
- Content you upload (e.g. raw video files for placement campaigns).
From everyone
- Technical logs (IP address, user agent) for security, fraud prevention, and debugging.
3. YouTube, TikTok, and Instagram API data
Rovalty uses YouTube API Services. By linking a YouTube channel you also agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy. You can revoke Rovalty's access at any time via Google security settings. Data obtained from platform APIs is used solely to verify content ownership and to retrieve view metrics to calculate what merchants owe creators, is never sold, and is never used for advertising. Disconnecting a social account stops all further data retrieval for it. Meta platform data deletion requests are honored via our data-deletion endpoint and upstalproject@gmail.com.
4. How we use data
- Operating campaigns: matching Creators to Merchant programs, verifying video ownership, tracking performance.
- Calculating and disbursing earnings; maintaining an auditable payment ledger.
- Fraud prevention and program integrity (e.g. anomalous view-pattern detection).
- Transactional email (submission decisions, payment statements and reminders) — we do not send third-party marketing.
- Legal compliance, including tax reporting where applicable.
5. Sharing
- Between the parties we connect: Merchants see the profiles, submissions, and performance statistics of Creators in their program; Creators see campaign and brand details Merchants publish.
- Service providers acting on our instructions: Shopify (platform integration), Google (email delivery), and our hosting infrastructure. There is no payment processor, because Rovalty never receives or transmits funds.
- Authorities where legally required. We do not sell personal data.
6. Retention
- Account data: while the account exists, then deleted or anonymized within 90 days of deletion.
- Social tokens: encrypted at rest (AES-256-GCM) and deleted immediately on unlink or account deletion.
- Raw uploaded video files: until 12 months after the campaign ends.
- Payment ledger records: retained as required for accounting and tax law (typically 7 years).
7. Your rights
Depending on your jurisdiction (including GDPR and CCPA rights), you may request access, correction, deletion, portability, or restriction of your personal data via upstalproject@gmail.com. Merchant store data deletion additionally follows the commerce platform's mandated redaction webhooks automatically. EU/UK users may lodge complaints with their supervisory authority.
8. Security & transfers
All traffic is TLS-encrypted; access tokens and personal identifiers are encrypted at rest; access to production data is restricted and audited. Data is processed in the European Union (Germany); where data crosses borders we rely on standard contractual clauses or equivalent safeguards.
9. Age limits & changes
The service is not directed at anyone under 18; Creators must be at least 18. We will announce material changes to this policy by email or in-product notice at least 14 days before they take effect.