Privacy Policy

Last updated: August 2026

1. Who we are

SMIPA Digital Marketing Ltd ("SMIPA", "we", "us", "our") operates SMIPA Creator Community, a hospitality creator partnership platform available at app.smipa.co.uk. We are registered in England and Wales under company number 15996371.

Registered address: 18 Maureen Grove, Newcastle, ST5 9NW, United Kingdom

We are the Data Controller for personal data processed through this platform, for all data protection matters, contact us at: admin@smipa.co.uk

2. What data we collect

We collect the following categories of personal data:

  • Account data: name, email address, password (stored as a bcrypt hash via Supabase Auth: never in plaintext), account type (venue, creator, or visual creator), account creation date
  • Profile data: display name, bio, city, profile photo, social media handles and URLs, portfolio content URLs, content niche and style tags, rates, availability status, whether you are willing to travel, the area you consider your primary audience location, and for visual creators: equipment details, insurance information, and editing style. Follower counts, engagement rates and audience demographics are not collected from you: they come only from a platform you have connected, as described in Section 4
  • Venue profile data: venue name, type, location, capacity, décor and content guidelines, preferred hashtags, brand colours, dos and don'ts, typical guest demographic, WiFi details, and accessibility information
  • Platform activity: campaign briefs posted, applications submitted, partnership records, contracts and amendments, ratings and reviews, notifications, messages, booking records, content submission URLs, and campaign outcomes
  • Payment data: we use Stripe to process all payments and do not store card numbers or full bank details. We store Stripe transaction IDs, payment status, payout amounts, Stripe Connect account IDs for creator and photographer payouts, and invoice references
  • Instagram and TikTok data (where connected): see Section 4 for full details
  • Google Calendar data (visual creators only): if you connect Google Calendar, we access your calendar free/busy information to display your availability to venues. We do not read, store, or share the content of your calendar events
  • Usage data: pages visited, features used, search queries, view counts, time spent on platform, and in-app interactions
  • Technical data: IP address, browser type and version, device type, operating system, and referring URLs (collected via Vercel hosting infrastructure)
  • Communications: support messages sent through the platform, feedback submitted, and email correspondence with our team

3. How we use your data

We use your personal data for the following purposes and legal bases under UK GDPR:

  • Providing the platform (contract performance): creating and managing your account, enabling you to post briefs, apply to partnerships, or list photography packages
  • Creator-venue matching (contract performance): using profile and brief data to suggest relevant creators and visual professionals for venue briefs. Where available and supported by the active matching configuration, Instagram API audience geography, age, engagement, and follower data may be used alongside other profile fields. Matching produces recommendations only. Venues make the final decisions on invitations and applications
  • Displaying creator data to venues (contract performance): creator profile information is displayed to venue partners when they browse creators or review applications. Audience and performance figures are shown to venues only where they come from a platform you have connected, and are always labelled with the platform they came from. We do not ask you for follower counts, engagement rates or audience demographics, and no figure you type is ever shown to a venue as a measured one
  • Payments (contract performance): processing venue payments and creator or photographer payouts via Stripe
  • Transactional communications (contract performance): sending booking confirmations, partnership updates, contract notifications, in-app notifications, and support replies via Resend
  • Verification (contract performance): confirming that a social account belongs to you, by connecting it through that platform's own login. An account is either connected or it is not: there are no verification levels, badges or tiers. Figures shown to venues come from the connected platform's API, so a venue can rely on them being the platform's own numbers
  • Safety and security (legitimate interests): verifying account authenticity, detecting and preventing fraud, enforcing our Terms of Service, and protecting the integrity of the platform
  • Legal compliance (legal obligation): meeting our obligations under UK law including HMRC tax and accounting requirements and UK GDPR
  • Platform improvement (legitimate interests): analysing aggregated and anonymised usage patterns to improve features, performance, and user experience. We do not use individual personal data for advertising purposes
  • Instagram, TikTok and Google Calendar integration (consent): where you have explicitly connected a third-party account using Instagram Login, TikTok Login Kit, or Google OAuth (Google Calendar). Instagram and TikTok API data is used for creator profile quality and verification, creator-venue matching, and Track & Measure campaign reporting. You may withdraw consent at any time, per account: see Sections 4 and 5

We do not use your personal data for targeted advertising, we do not sell your data to third parties, and we do not share your data with advertisers.

4. Connected social accounts (Instagram and TikTok)

You can connect Instagram, TikTok, both, or neither. Each connection is separate: you choose which to link, and disconnecting one does not affect the other.

Instagram

Connecting Instagram is optional. If you choose to connect your Instagram Business or Creator account to SMIPA Creator Community using Instagram Login, we access data via the Meta Instagram Graph API using these permissions:

  • instagram_business_basic: your Instagram username, display name, profile picture, numeric account ID, follower and media counts, and your published media: post captions, permalinks, thumbnails, media type, and like and comment counts. Where you choose to submit a story to a campaign, we also list your currently live stories so you can select one
  • Images are stored as our own copies. Instagram's image links expire after a few days, so we download and store a copy of your profile picture and of the thumbnails for your recent posts on our own servers rather than linking to Instagram. Without this, your profile would fill with broken images within a week. These copies are deleted when you disconnect Instagram, except for images attached to a completed campaign, which are kept as part of that campaign's record
  • instagram_business_manage_insights: where available from Instagram, account and audience insights including follower count, reach, views, profile views, accounts engaged, engagement rate, audience age distribution, gender split, top cities and countries, media-level insights on your posts, and story insights for stories you submit to a campaign

What venues see: venues only see Instagram API audience and performance data while you have an active Instagram connection. If you disconnect, those figures stop being shown rather than being replaced with anything you have typed.

How we use Instagram data:

  • To show images of your recent Instagram posts, and the Portfolio posts you choose, on your creator card when a venue browses creators — so a venue sees your actual work rather than a placeholder
  • To display Instagram API profile, performance, and audience information to venue partners browsing or reviewing your creator profile
  • Where available and supported by the active matching configuration, to suggest relevant campaign opportunities using Instagram API audience geography, age, engagement, and follower data together with brief and profile information. Matching produces recommendations only: venues decide which creators to invite, shortlist, or approve
  • Track & Measure campaign reporting: where you participate in a campaign on SMIPA Creator Community, Instagram API media and account insights may be used to populate campaign performance reports provided to the venue you are working with. This includes metrics such as reach, views, profile views, and engagement on content you have submitted for the campaign. You can view your own Instagram profile and post insights within the app at any time. Reporting is based solely on your own Instagram data. SMIPA does not access individual viewer identities and does not claim exact attribution of business outcomes to your content

What we do not do with your Instagram data:

  • We do not publish content to your Instagram account
  • We do not manage, read, or send messages on your behalf
  • We do not manage, read, or post comments on your behalf
  • We do not run ads using your Instagram account
  • We do not access, manage, or operate Instagram Shopping, product catalogues, or branded content tools
  • We do not act on your behalf on Instagram in any way beyond reading the data described above
  • We do not access your private messages or unpublished drafts
  • We only access your currently live stories when you choose to submit one to a campaign: we cannot retrieve stories after they expire, and we never browse your stories for any other purpose
  • We do not use Instagram data for advertising or marketing purposes
  • We do not sell or transfer Instagram data to any third party outside of SMIPA Creator Community
  • We do not use Instagram data beyond creator profile quality, creator-venue matching, and Track & Measure campaign reporting as described above

Token storage: we store a long-lived Instagram access token (valid for 60 days, refreshed automatically) in our secure database. This token is used solely to refresh your Instagram data. It is never exposed to venues or other users, and never transmitted to any third party.

Withdrawing consent: you can disconnect your Instagram account at any time in SMIPA Creator Community from Settings → Connected accounts → Instagram. On disconnection, we immediately delete your Instagram access token, Instagram snapshot data (audience, account insights, and media insights), and Instagram-derived profile fields stored from the API. Performance metrics already recorded for content you submitted to a completed campaign are retained as part of that campaign's performance record, shared with the venue you worked with, and follow the partnership retention period set out in Section 8. Your SMIPA Creator Community account and any non-Instagram profile information you entered separately remain unless you delete your account.

Data deletion via Meta: you may also request deletion of your Instagram data directly through Meta. When Meta sends us a data deletion request for your account, we promptly delete your Instagram profile, audience, and insights data and access token, on the same basis as disconnection above. Performance metrics already recorded for content submitted to a completed campaign are retained as part of that campaign's record as described above. Our data deletion status page is available at: app.smipa.co.uk/data-deletion

TikTok

Connecting TikTok is optional. If you choose to connect your TikTok account to SMIPA Creator Community using TikTok Login Kit, we access data via the TikTok Display API using these permissions:

  • user.info.basic: your TikTok account identifier (open ID), display name, and profile picture URL
  • user.info.profile: your TikTok username (handle), profile link, and whether your account is verified by TikTok
  • user.info.stats: your follower count, total likes across your account, and number of published videos
  • video.list: your public videos — video identifier, description or title, cover image, share link, duration, and the view, like, comment, and share counts TikTok reports for each one
  • Cover images are stored as our own copies. TikTok's cover image links expire within hours, so we download and store a copy of each cover on our own servers rather than linking to TikTok. These copies are deleted when you disconnect TikTok

What TikTok does not provide: TikTok's API does not report reach, impressions, saves, or audience demographics (age, gender, or location) at any permission level. We therefore hold no TikTok audience data, and these figures are shown as not reported rather than as zero anywhere they appear.

What venues see: your TikTok follower count and the per-video statistics above, only while you have an active TikTok connection. Any TikTok follower number you may have typed into your profile in the past is not shown to venues and is not used in matching: venue-facing figures come from the TikTok API or are not shown at all.

How we use TikTok data:

  • To display your TikTok profile and video performance to venue partners browsing or reviewing your creator profile, including your video cover images on your creator card when a venue browses creators
  • To suggest relevant campaign opportunities using your verified follower count and video engagement. Matching produces recommendations only: venues decide which creators to invite, shortlist, or approve
  • Track & Measure campaign reporting: where you take part in a campaign and submit a TikTok video, the statistics TikTok reports for that video may be used in the performance report provided to the venue you are working with. Reporting is based solely on your own TikTok data. SMIPA does not access individual viewer identities and does not claim exact attribution of business outcomes to your content

What we do not do with your TikTok data:

  • We do not publish, upload, or schedule content to your TikTok account
  • We do not read, send, or manage messages or comments on your behalf
  • We do not run ads using your TikTok account
  • We do not access private videos, drafts, or anything you have not published publicly
  • We do not use TikTok data for advertising or marketing purposes
  • We do not sell or transfer TikTok data to any third party outside of SMIPA Creator Community
  • We do not use TikTok data beyond creator profile quality, creator-venue matching, and Track & Measure campaign reporting as described above

Token storage: we store your TikTok access token (valid for 24 hours) and refresh token (valid for up to 365 days) encrypted at rest in our secure database. They are used solely to keep your TikTok data up to date, are never exposed to venues or other users, and are never transmitted to any third party.

Withdrawing consent: you can disconnect your TikTok account at any time from Settings → Connected accounts → TikTok. On disconnection we ask TikTok to revoke our access, and we immediately delete your stored TikTok tokens and the TikTok video statistics we hold. Performance metrics already recorded for content you submitted to a completed campaign are retained as part of that campaign's performance record, shared with the venue you worked with, and follow the partnership retention period set out in Section 8. Your SMIPA Creator Community account and any information you entered separately remain unless you delete your account.

Legal basis: consent (UK GDPR Article 6(1)(a)).

5. Google Calendar data (visual creators)

Visual creators may optionally connect their Google Calendar to display their availability to venues booking photography or videography services.

  • We access free/busy information only: we do not read the title, description, or attendees of your calendar events
  • When a booking is confirmed, we create a calendar event on your behalf to record the booking date
  • Google Calendar access tokens are stored securely in our database and used solely for availability display and booking event creation

You can disconnect Google Calendar at any time from your profile settings. On disconnection, your access token is immediately deleted and no further calendar access occurs.

Legal basis: consent (UK GDPR Article 6(1)(a)).

6. Who we share data with

We share data only with the following third-party processors who act on our instructions under Data Processing Agreements:

We also offer sign-in with Google. If you use this option, Google's privacy policy governs the data processed during authentication. We only receive your name and email address from Google to create your SMIPA account.

  • Supabase (Supabase Inc, USA): database hosting and authentication. Your data is stored in Supabase's EU (Ireland) region. Transfers to Supabase's US-based infrastructure are covered by Standard Contractual Clauses. supabase.com/privacy
  • Vercel (Vercel Inc, USA): application hosting and edge network. Transfers covered by Standard Contractual Clauses. vercel.com/legal/privacy-policy
  • Stripe (Stripe Inc, USA): payment processing and creator payouts. Stripe is an independent Data Controller for payment data processed under their own privacy policy. Transfers covered by Standard Contractual Clauses. stripe.com/gb/privacy
  • Resend (Resend Inc, USA): transactional email delivery. Email addresses and message content are processed to deliver notifications. Transfers covered by Standard Contractual Clauses. resend.com/legal/privacy-policy
  • Anthropic (Anthropic PBC, USA). AI processing for explaining why a creator and a brief were matched, and for drafting campaign brief and venue profile wording from details a venue provides. Data submitted for AI analysis is processed transiently and not used to train Anthropic models. Transfers covered by Standard Contractual Clauses. anthropic.com/legal/privacy
  • Meta Platforms (Meta Platforms Inc, USA) : where you connect your Instagram account, Meta processes your authentication and provides data to us via their Graph API. Meta is an independent Data Controller for your Instagram account data. facebook.com/privacy/policy
  • Google (Google LLC, USA): where visual creators connect Google Calendar. Google is an independent Data Controller for your Google account data. policies.google.com/privacy

Sharing within the platform: creator profile data is visible to venue users on SMIPA Creator Community as part of the platform's core function. Verified Instagram statistics and audience data are shown to venues only when you have connected Instagram. By creating a creator profile, you consent to this display.

We do not sell, rent, or otherwise transfer your personal data to any third party outside of the processors listed above.

7. International data transfers

SMIPA Creator Community is a UK-based platform. Several of our third-party processors are based in the United States, which means your data may be transferred outside the UK and European Economic Area. We ensure all such transfers are protected by appropriate safeguards under UK GDPR Article 46, specifically:

  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office and/or the European Commission, incorporated into our Data Processing Agreements with each processor
  • For processors covered by the UK Extension to the EU-US Data Privacy Framework where applicable

You may request a copy of the relevant transfer safeguards by emailing admin@smipa.co.uk.

8. Data retention

  • Account and profile data: retained while your account is active. When you delete your account your personal profile data is erased immediately. There is no grace period and no soft-delete of personal data. If you never took part in a campaign, the profile record itself is deleted outright. If you did, the record is kept only as an anonymised shell (shown as “Former creator” or “Former venue”) so the other party keeps their own campaign history; that shell holds no personal data and never appears in search, discovery or matching. Copies of deleted data may persist for a short period in the encrypted backups our database provider keeps for disaster recovery, and are removed as those backups age out; they are never used to restore a deleted account
  • Partnership and contract records: retained for up to 6 years from the end of the partnership for legal and accounting purposes
  • Payment records: retained for 7 years as required by HMRC under the Taxes Management Act 1970
  • Support messages: retained for 2 years from the date of the support interaction, then deleted automatically
  • Campaign messages: messages between a venue and a creator are part of the record of what was agreed, so they are retained for 6 years alongside the partnership, then deleted automatically. If one of you closes your account, the conversation stays in the other person's inbox with your name replaced by “Former creator” or “Former venue”: we do not delete their copy of a conversation you were both part of
  • Message requests: a creator's opening message to a venue — about a campaign, or sent directly to the venue. If it leads to a conversation or a partnership it becomes part of the campaign messages above (accepted conversations follow those rules even if no partnership ever forms); a request that is dismissed, expires, or is never answered is retained for 12 months, then deleted automatically
  • Instagram access tokens: deleted immediately on account disconnection or account deletion
  • Instagram profile and audience data: deleted immediately when you disconnect Instagram in SMIPA, or promptly upon receipt of a Meta data deletion request
  • Completed-campaign performance metrics: metrics recorded for content you submitted to a completed campaign form part of the partnership record and are retained accordingly (see "Partnership and contract records" above), as they are shared with the venue you worked with as the performance record of that campaign. They are not removed when you disconnect Instagram
  • Google Calendar access tokens: deleted immediately on disconnection
  • TikTok access and refresh tokens: deleted immediately on disconnection or account deletion, and we ask TikTok to revoke our access at the same time
  • TikTok video statistics: deleted immediately when you disconnect TikTok
  • Technical logs: retained for 90 days

9. Your rights under UK GDPR

As a data subject under UK GDPR and the Data Protection Act 2018, you have the following rights:

  • Right of access (Article 15): request a copy of the personal data we hold about you
  • Right to rectification (Article 16): request correction of inaccurate or incomplete data
  • Right to erasure (Article 17): request deletion of your data, subject to legal retention requirements. You can also delete your account directly from your settings. When you delete your account we erase or anonymise your personal data immediately; records of completed partnerships, contracts, and payments are retained in pseudonymised form for the periods in Section 8, as permitted by Article 17(3) where we have a legal obligation (HMRC) or need the record to establish or defend a legal claim. This works the same way in both directions: a creator who leaves appears to the venues they worked with as a former creator, and a venue that leaves appears to the creators it worked with as a former venue: so neither party can erase the other's record of work they completed and were paid for
  • Right to restrict processing (Article 18): request that we limit how we use your data in certain circumstances
  • Right to data portability (Article 20): receive your data in a structured, commonly used, machine-readable format where processing is based on consent or contract
  • Right to object (Article 21): object to processing based on legitimate interests, including profiling for matching purposes
  • Right to withdraw consent: where we process data on the basis of consent (Instagram, TikTok, or Google Calendar connection), you may withdraw consent at any time without affecting the lawfulness of prior processing. Withdraw by disconnecting the relevant account under Settings → Connected accounts in your dashboard
  • Rights relating to automated decision-making (Article 22): our platform uses automated matching algorithms to suggest creator-venue pairings. These are recommendations only. No automated decision produces a legally significant effect without human review. You have the right to request human review of any matching outcome that concerns you

To exercise any of these rights, email admin@smipa.co.uk with the subject line "Data Rights Request". We will respond within one calendar month as required by UK GDPR.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk . 0303 123 1113. Wycliffe House, Water Lane, Wilmslow, SK9 5AF

10. Cookies and local storage

We use the following cookies and browser storage on SMIPA Creator Community:

  • Authentication cookies: set by Supabase Auth to maintain your logged-in session. These are strictly necessary and cannot be disabled without preventing login
  • OAuth state cookies: short-lived cookies set during the Instagram, TikTok and Google Calendar connection flows to prevent cross-site request forgery. Deleted immediately after authentication completes
  • Local storage: your browser also stores a few preferences and drafts on your own device, which never leave it and are not personal data we hold: whether you have dismissed the cookie notice, your light or dark theme choice, progress through sign-up and onboarding so you can leave and come back, and unsaved drafts of a campaign you are writing. Clearing your browser storage removes them

We do not use advertising cookies, tracking cookies, or third-party analytics cookies. We do not use Google Analytics or similar tracking tools.

You can control cookies through your browser settings. Disabling authentication cookies will prevent you from logging in to the platform.

11. Data security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted data transmission via HTTPS/TLS for all connections
  • Passwords stored as secure hashes: never in plaintext
  • Row-level security (RLS) enforced across our database tables, ensuring users can only access their own data
  • API authentication via signed JWT tokens with short expiry windows
  • Sensitive API keys and tokens stored as server-side environment variables: never exposed to the client
  • Access controls limiting SMIPA staff access to personal data to what is strictly necessary
  • HMAC-SHA256 signature verification on all incoming Meta data deletion callbacks

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Article 33.

If you suspect a security issue, contact us immediately at admin@smipa.co.uk.

12. Children

SMIPA Creator Community is a professional platform intended for use by adults aged 18 and over only. We do not knowingly collect or process personal data from anyone under the age of 18. If you believe a child has provided personal data to us, please contact admin@smipa.co.uk and we will delete it promptly.

13. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify registered users of material changes by email at least 14 days before the change takes effect. The date at the top of this page shows when the policy was last updated. Continued use of SMIPA Creator Community after the effective date of a change constitutes acceptance of the updated policy.

14. Contact and data controller details

SMIPA Digital Marketing Ltd

Company number: 15996371

18 Maureen Grove, Newcastle, ST5 9NW, United Kingdom

admin@smipa.co.uk

app.smipa.co.uk

For Instagram data deletion requests: app.smipa.co.uk/data-deletion

For our Terms of Service: app.smipa.co.uk/terms

See also our Terms of Service and Data Deletion pages.