Privacy Policy
Last updated: June 2026
1. Who we are
SMIPA Digital Marketing Ltd ("SMIPA", "we", "us", "our") operates SMIPA Creator Community, a hospitality creator partnership platform available at app.smipa.co.uk. We are registered in England and Wales under company number 15996371.
Registered address: 18 Maureen Grove, Newcastle, ST5 9NW, United Kingdom
We are the Data Controller for personal data processed through this platform. For all data protection matters, contact us at: admin@smipa.co.uk
2. What data we collect
We collect the following categories of personal data:
- Account data: name, email address, password (stored as a bcrypt hash via Supabase Auth — never in plaintext), account type (venue, creator, or visual creator), account creation date
- Profile data: display name, bio, city, profile photo, social media handles and URLs, follower counts, engagement rates, audience demographics (self-reported or verified), portfolio content URLs, content niche and style tags, rates, availability status, and for visual creators: equipment details, insurance information, and editing style
- Venue profile data: venue name, type, location, capacity, décor and content guidelines, preferred hashtags, brand colours, dos and don'ts, typical guest demographic, WiFi details, and accessibility information
- Platform activity: campaign briefs posted, applications submitted, partnership records, contracts and amendments, ratings and reviews, notifications, messages, booking records, content submission URLs, and campaign outcomes
- Payment data: we use Stripe to process all payments and do not store card numbers or full bank details. We store Stripe transaction IDs, payment status, payout amounts, Stripe Connect account IDs for creator and photographer payouts, and invoice references
- Instagram data (where connected): see Section 4 for full details
- Google Calendar data (visual creators only): if you connect Google Calendar, we access your calendar free/busy information to display your availability to venues. We do not read, store, or share the content of your calendar events
- Audience insights screenshots (separate from Instagram API data): if you upload screenshots of your Instagram Insights for Silver verification, the images are stored in secure storage and processed using automated analysis (including AI) to extract audience statistics. Extracted figures are retained on your profile. Screenshot images are not automatically deleted when you disconnect Instagram
- Usage data: pages visited, features used, search queries, view counts, time spent on platform, and in-app interactions
- Technical data: IP address, browser type and version, device type, operating system, and referring URLs (collected via Vercel hosting infrastructure)
- Communications: support messages sent through the platform, feedback submitted, and email correspondence with our team
3. How we use your data
We use your personal data for the following purposes and legal bases under UK GDPR:
- Providing the platform (contract performance): creating and managing your account, enabling you to post briefs, apply to partnerships, or list photography packages
- Creator-venue matching (contract performance): using profile and brief data to suggest relevant creators and visual professionals for venue briefs. Where available and supported by the active matching configuration, Instagram API audience geography, age, engagement, and follower data may be used alongside other profile fields. Matching produces recommendations only — venues make the final decisions on invitations and applications
- Displaying creator data to venues (contract performance): creator profile information is displayed to venue partners when they browse creators or review applications. Instagram API audience and performance data is shown to venues only when you have connected your Instagram account. Self-reported or screenshot-based audience data is not shown to venues as Instagram API audience data
- Payments (contract performance): processing venue payments and creator or photographer payouts via Stripe
- Transactional communications (contract performance): sending booking confirmations, partnership updates, contract notifications, in-app notifications, and support replies via Resend
- Verification (contract performance): verifying audience data through Instagram API connection (Gold) or screenshot analysis (Silver) to help creators present trustworthy statistics on their profile. Screenshot verification is separate from Instagram API data and is not shown to venues as verified Instagram data
- Safety and security (legitimate interests): verifying account authenticity, detecting and preventing fraud, enforcing our Terms of Service, and protecting the integrity of the platform
- Legal compliance (legal obligation): meeting our obligations under UK law including HMRC tax and accounting requirements and UK GDPR
- Platform improvement (legitimate interests): analysing aggregated and anonymised usage patterns to improve features, performance, and user experience. We do not use individual personal data for advertising purposes
- Instagram and Google Calendar integration (consent): where you have explicitly connected a third-party account using Instagram Login (Instagram) or Google OAuth (Google Calendar). Instagram API data is used for creator profile quality and verification, creator-venue matching, and Track & Measure campaign reporting. You may withdraw consent at any time — see Sections 4 and 5
We do not use your personal data for targeted advertising, we do not sell your data to third parties, and we do not share your data with advertisers.
4. Instagram data
Connecting Instagram is optional. If you choose to connect your Instagram Business or Creator account to SMIPA Creator Community using Instagram Login, we access data via the Meta Instagram Graph API using these permissions:
- instagram_business_basic: your Instagram username, display name, profile picture URL, numeric account ID, follower and media counts, and your published media — post captions, permalinks, thumbnails, media type, and like and comment counts. Where you choose to submit a story to a campaign, we also list your currently live stories so you can select one
- instagram_business_manage_insights: where available from Instagram, account and audience insights including follower count, reach, views, profile views, accounts engaged, engagement rate, audience age distribution, gender split, top cities and countries, media-level insights on your posts, and story insights for stories you submit to a campaign
What venues see: venues only see Instagram API audience and performance data when you have an active Instagram connection. Self-reported or screenshot-based audience data is shown to you on your profile but is not shown to venues as Instagram API audience data.
How we use Instagram data:
- To display Instagram API profile, performance, and audience information to venue partners browsing or reviewing your creator profile
- Where available and supported by the active matching configuration, to suggest relevant campaign opportunities using Instagram API audience geography, age, engagement, and follower data together with brief and profile information. Matching produces recommendations only — venues decide which creators to invite, shortlist, or approve
- Track & Measure campaign reporting: where you participate in a campaign on SMIPA Creator Community, Instagram API media and account insights may be used to populate campaign performance reports provided to the venue you are working with. This includes metrics such as reach, views, profile views, and engagement on content you have submitted for the campaign. You can view your own Instagram profile and post insights within the app at any time. Reporting is based solely on your own Instagram data — SMIPA does not access individual viewer identities and does not claim exact attribution of business outcomes to your content
Screenshot verification is separate: Silver verification uses uploaded Instagram Insights screenshots and automated analysis (including AI). That data is stored separately from Instagram API data and is not shown to venues as Instagram API audience data.
What we do not do with your Instagram data:
- We do not publish content to your Instagram account
- We do not manage, read, or send messages on your behalf
- We do not manage, read, or post comments on your behalf
- We do not run ads using your Instagram account
- We do not access, manage, or operate Instagram Shopping, product catalogues, or branded content tools
- We do not act on your behalf on Instagram in any way beyond reading the data described above
- We do not access your private messages or unpublished drafts
- We only access your currently live stories when you choose to submit one to a campaign — we cannot retrieve stories after they expire, and we never browse your stories for any other purpose
- We do not use Instagram data for advertising or marketing purposes
- We do not sell or transfer Instagram data to any third party outside of SMIPA Creator Community
- We do not use Instagram data beyond creator profile quality, creator-venue matching, and Track & Measure campaign reporting as described above
Token storage: we store a long-lived Instagram access token (valid for 60 days, refreshed automatically) in our secure database. This token is used solely to refresh your Instagram data. It is never exposed to venues or other users, and never transmitted to any third party.
Withdrawing consent: you can disconnect your Instagram account at any time in SMIPA Creator Community from Settings → Connected accounts → Instagram. On disconnection, we immediately delete your Instagram access token, Instagram snapshot data (audience, account insights, and media insights), and Instagram-derived profile fields stored from the API. Performance metrics already recorded for content you submitted to a completed campaign are retained as part of that campaign's performance record, shared with the venue you worked with, and follow the partnership retention period set out in Section 8. Your SMIPA Creator Community account and any non-Instagram profile information you entered separately remain unless you delete your account. Screenshot-based verification data is not removed automatically when you disconnect Instagram.
Data deletion via Meta: you may also request deletion of your Instagram data directly through Meta. When Meta sends us a data deletion request for your account, we promptly delete your Instagram profile, audience, and insights data and access token, on the same basis as disconnection above. Performance metrics already recorded for content submitted to a completed campaign are retained as part of that campaign's record as described above. Our data deletion status page is available at: app.smipa.co.uk/data-deletion
Legal basis: consent (UK GDPR Article 6(1)(a)).
5. Google Calendar data (visual creators)
Visual creators may optionally connect their Google Calendar to display their availability to venues booking photography or videography services.
- We access free/busy information only — we do not read the title, description, or attendees of your calendar events
- When a booking is confirmed, we create a calendar event on your behalf to record the booking date
- Google Calendar access tokens are stored securely in our database and used solely for availability display and booking event creation
You can disconnect Google Calendar at any time from your profile settings. On disconnection, your access token is immediately deleted and no further calendar access occurs.
Legal basis: consent (UK GDPR Article 6(1)(a)).
6. Who we share data with
We share data only with the following third-party processors who act on our instructions under Data Processing Agreements:
We also offer sign-in with Google. If you use this option, Google's privacy policy governs the data processed during authentication. We only receive your name and email address from Google to create your SMIPA account.
- Supabase (Supabase Inc, USA) — database hosting and authentication. Your data is stored in Supabase's EU (Ireland) region. Transfers to Supabase's US-based infrastructure are covered by Standard Contractual Clauses. supabase.com/privacy
- Vercel (Vercel Inc, USA) — application hosting and edge network. Transfers covered by Standard Contractual Clauses. vercel.com/legal/privacy-policy
- Stripe (Stripe Inc, USA) — payment processing and creator payouts. Stripe is an independent Data Controller for payment data processed under their own privacy policy. Transfers covered by Standard Contractual Clauses. stripe.com/gb/privacy
- Resend (Resend Inc, USA) — transactional email delivery. Email addresses and message content are processed to deliver notifications. Transfers covered by Standard Contractual Clauses. resend.com/legal/privacy-policy
- Anthropic (Anthropic PBC, USA) — AI processing for creator-venue match analysis and audience insights extraction. Data submitted for AI analysis is processed transiently and not used to train Anthropic models. Transfers covered by Standard Contractual Clauses. anthropic.com/legal/privacy
- Meta Platforms (Meta Platforms Inc, USA) — where you connect your Instagram account, Meta processes your authentication and provides data to us via their Graph API. Meta is an independent Data Controller for your Instagram account data. facebook.com/privacy/policy
- Google (Google LLC, USA) — where visual creators connect Google Calendar. Google is an independent Data Controller for your Google account data. policies.google.com/privacy
Sharing within the platform: creator profile data is visible to venue users on SMIPA Creator Community as part of the platform's core function. Verified Instagram statistics and audience data are shown to venues only when you have connected Instagram. By creating a creator profile, you consent to this display.
We do not sell, rent, or otherwise transfer your personal data to any third party outside of the processors listed above.
7. International data transfers
SMIPA Creator Community is a UK-based platform. Several of our third-party processors are based in the United States, which means your data may be transferred outside the UK and European Economic Area. We ensure all such transfers are protected by appropriate safeguards under UK GDPR Article 46, specifically:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office and/or the European Commission, incorporated into our Data Processing Agreements with each processor
- For processors covered by the UK Extension to the EU-US Data Privacy Framework where applicable
You may request a copy of the relevant transfer safeguards by emailing admin@smipa.co.uk.
8. Data retention
- Account and profile data: retained while your account is active and for 30 days after a deletion request, after which all personal data is permanently deleted
- Partnership and contract records: retained for up to 6 years from the end of the partnership for legal and accounting purposes
- Payment records: retained for 7 years as required by HMRC under the Taxes Management Act 1970
- Support messages: retained for 2 years from the date of the support interaction
- Instagram access tokens: deleted immediately on account disconnection or account deletion
- Instagram profile and audience data: deleted immediately when you disconnect Instagram in SMIPA, or promptly upon receipt of a Meta data deletion request
- Completed-campaign performance metrics: metrics recorded for content you submitted to a completed campaign form part of the partnership record and are retained accordingly (see "Partnership and contract records" above), as they are shared with the venue you worked with as the performance record of that campaign. They are not removed when you disconnect Instagram
- Google Calendar access tokens: deleted immediately on disconnection
- Audience insights screenshots: retained in secure storage and on your profile until you remove them or delete your account. Extracted demographic figures are retained on your profile. Disconnecting Instagram does not automatically delete screenshot verification data
- Technical logs: retained for 90 days
9. Your rights under UK GDPR
As a data subject under UK GDPR and the Data Protection Act 2018, you have the following rights:
- Right of access (Article 15): request a copy of the personal data we hold about you
- Right to rectification (Article 16): request correction of inaccurate or incomplete data
- Right to erasure (Article 17): request deletion of your data, subject to legal retention requirements. You can also delete your account directly from your profile settings. When you delete your account we erase or anonymise your personal data; records of completed partnerships, contracts, and payments are retained in pseudonymised form for the periods in Section 8 (for legal, accounting, and HMRC purposes) and appear to the venue you worked with as a former creator
- Right to restrict processing (Article 18): request that we limit how we use your data in certain circumstances
- Right to data portability (Article 20): receive your data in a structured, commonly used, machine-readable format where processing is based on consent or contract
- Right to object (Article 21): object to processing based on legitimate interests, including profiling for matching purposes
- Right to withdraw consent: where we process data on the basis of consent (Instagram connection, Google Calendar connection), you may withdraw consent at any time without affecting the lawfulness of prior processing. Withdraw by disconnecting the relevant account under Settings → Connected accounts in your dashboard
- Rights relating to automated decision-making (Article 22): our platform uses automated matching algorithms to suggest creator-venue pairings. These are recommendations only — no automated decision produces a legally significant effect without human review. You have the right to request human review of any matching outcome that concerns you
To exercise any of these rights, email admin@smipa.co.uk with the subject line "Data Rights Request". We will respond within one calendar month as required by UK GDPR.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk — 0303 123 1113 — Wycliffe House, Water Lane, Wilmslow, SK9 5AF
10. Cookies and local storage
We use the following cookies and browser storage on SMIPA Creator Community:
- Authentication cookies: set by Supabase Auth to maintain your logged-in session. These are strictly necessary and cannot be disabled without preventing login
- OAuth state cookies: short-lived cookies set during Instagram and Google Calendar OAuth flows to prevent cross-site request forgery. Deleted immediately after authentication completes
We do not use advertising cookies, tracking cookies, or third-party analytics cookies. We do not use Google Analytics or similar tracking tools.
You can control cookies through your browser settings. Disabling authentication cookies will prevent you from logging in to the platform.
11. Data security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encrypted data transmission via HTTPS/TLS for all connections
- Passwords stored as secure hashes — never in plaintext
- Row-level security (RLS) enforced across our database tables, ensuring users can only access their own data
- API authentication via signed JWT tokens with short expiry windows
- Sensitive API keys and tokens stored as server-side environment variables — never exposed to the client
- Access controls limiting SMIPA staff access to personal data to what is strictly necessary
- HMAC-SHA256 signature verification on all incoming Meta data deletion callbacks
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Article 33.
If you suspect a security issue, contact us immediately at admin@smipa.co.uk.
12. Children
SMIPA Creator Community is a professional platform intended for use by adults aged 18 and over only. We do not knowingly collect or process personal data from anyone under the age of 18. If you believe a child has provided personal data to us, please contact admin@smipa.co.uk and we will delete it promptly.
13. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify registered users of material changes by email at least 14 days before the change takes effect. The date at the top of this page shows when the policy was last updated. Continued use of SMIPA Creator Community after the effective date of a change constitutes acceptance of the updated policy.
14. Contact and data controller details
SMIPA Digital Marketing Ltd
Company number: 15996371
18 Maureen Grove, Newcastle, ST5 9NW, United Kingdom
For Instagram data deletion requests: app.smipa.co.uk/data-deletion
For our Terms of Service: app.smipa.co.uk/terms
See also our Terms of Service and Data Deletion pages.