Legal
Privacy Policy
Last updated September 2026
This policy explains what personal data ratepop (www.ratepop.co) processes, why, and what your rights are under the EU General Data Protection Regulation (GDPR) and Slovak Act No. 18/2018 Coll. on personal data protection.
1. Who is responsible (controller)
Email: hello@ratepop.co
For anything about your data, email us at hello@ratepop.co. We reply within 30 days at the latest.
2. What we process and why
- Account — email address, password (stored only as a one-way hash), login times, your settings (which optional e-mails you get) a random referral code and, if you signed up through someone's invite link, their code (referredBy — used once to credit their invite reward). Purpose: your account and login (magic link or password). Legal basis: contract (Art. 6(1)(b) GDPR).
- Your public creator listing — handle, platforms, follower and engagement numbers, niche, calculated rate, optional bio, photos, gallery, links to your posts and the optional tags you choose (gender, age range, look, vibe, location, audience). Purpose: showing you to brands on The Lineup, in the creator search below it and on your profile page. This information is public — your profile page stays reachable, and may be indexed by search engines, until you delete the listing. Free listings are on today's Lineup for 24 hours at a time and stay findable in the search after that. Also public on your profile: your rate history (date and rate from your own re-calculations of the listed handle) and, once you have at least 3 brand requests, your reply stats (share answered within 48 hours, median time to reply). Legal basis: contract. The tags are optional and you can clear them any time.
- Calculator look-ups of a handle — when anyone types an Instagram or YouTube handle into the calculator, we ask that platform's official API for the account's public numbers (followers, recent likes/comments or views, name and profile picture) and keep the answer, including a small copy of the profile picture, in a server cache for up to 24 hours so repeated look-ups don't hit the API again. Nothing is published or added to any listing unless the account owner creates one. This data does not come from you if you are the looked-up person (Art. 14 GDPR): the source is the platform's public profile. Legal basis: our legitimate interest in giving an accurate rate estimate (Art. 6(1)(f)); you can object any time by e-mail and we block look-ups of your handle.
- “Rates popped today” — when a calculation is revealed we add one to a daily total shown on the home page. To count each person once per handle and day we keep a keyed hash of (your e-mail or IP address + handle + day) for 2 days; the daily totals themselves contain no personal data. Legal basis: legitimate interest.
- Rate calculations and deals you report — numbers you enter and prices of deals you report or confirm. Purpose: your history and anonymous market statistics (min / median / max). Published market data contains only platform, niche, follower tier (e.g. “10k–100k”) and a rounded amount — never who reported it. Legal basis: contract and our legitimate interest in accurate market data (Art. 6(1)(f)).
- Payment screenshots (optional deal proof) — if you attach a screenshot to a reported deal, it is stored in a private folder that is not reachable from the web and never shown to brands or other users. First an automated check by Google Gemini (see section 4) looks at the image for signs of editing or generation; then a person from ratepop reviews it. The file is deleted right after the review — at the latest after 30 days — and a screenshot uploaded but never attached to a deal is deleted after 24 hours. Afterwards we keep only the outcome (verified / rejected / expired), technical flags (e.g. “edited with Photoshop”) and the AI verdict — not what it read off the image — plus an image fingerprint to recognise the same screenshot if it is uploaded again. With your tick, a verified deal can be shown on your profile as “Verified deal” with amount, format, platform and date (brand hidden). Legal basis: consent (Art. 6(1)(a)) — you can withdraw it by deleting the deal.
- Profile views and Insights — daily counts of profile views, media-kit opens, “Book” clicks, upvotes and brand requests per listing, without who viewed. Purpose: PRO Insights. Legal basis: legitimate interest.
- Brand views — when you are logged in with a brand account and open a creator’s card, we record your brand account, the creator and the day (once per day). The creator sees how many brands viewed them; creators on PRO see your company name and whether it is verified — never your e-mail. Purpose: show creators real interest in their card. Legal basis: legitimate interest. Kept 90 days; browse logged out if you prefer not to be counted.
- Pop streak — the dates you re-listed your card, to count your streak and grant PRO days. Kept with your account.
- Upvotes — stored as a keyed one-way hash of your account, or of a random device ID if you are logged out, so each account or browser counts once. Nobody can see who upvoted. Legal basis: legitimate interest.
- Sign in with Google, TikTok or LinkedIn (optional) — Google and LinkedIn give us your verified e-mail address, name, profile picture and account ID; we use them only to log you in or create your account. TikTok gives no e-mail, so a first TikTok sign-in asks for one and sends a confirm link. We never get your password for those services and never post anything for you. Legal basis: contract (your account).
- Connected accounts (optional) — if you sign in with or connect TikTok: user ID, username, display name, avatar, follower, like and video counts, the view counts of your last 20 public videos (to work out your average views), and access tokens that stay on our server and are used only to refresh those numbers daily. If you sign in with or connect LinkedIn: your LinkedIn member ID, name and profile picture, to show “LinkedIn connected” on your profile. Disconnect any time in the dashboard, or revoke access in TikTok/LinkedIn's own settings. Legal basis: consent.
- Brand accounts — company name, website, EU VAT number / company ID, country, contact person, a short description, the verification result, saved creators (shortlist), creator alerts and briefs you post. To verify a VAT number we send it to the European Commission's VIES service (returns whether it is valid and the registered name/address); the registered name is shown to creators you contact. Legal basis: contract and legitimate interest in preventing fake profiles.
- Brand requests and briefs — when a brand sends a request through “Book”: brand name, contact email, budget and message, shown to the creator it is for. When a creator applies to a brief: handle, price and message, shown to that brand. If a creator sends a counter-offer, replies to that e-mail go straight to the creator's address. Legal basis: steps prior to a contract / legitimate interest in connecting brands and creators.
- Payments — purchases (PRO, Top spots) are processed by Gumroad, which acts as the seller of record and handles card data. Gumroad sends us a notification of each sale; we store a record of it (e-mail, product, handle, price, order and subscription ID, and what we did with it), the link between a PRO subscription and your account, PRO paid for before your listing existed (so it starts once it does), and — if a purchase could not start (e.g. sold out) — a note for our refund. Before checkout you tick that the service should start right away; that choice and its time are e-mailed to you with the purchase confirmation. Legal basis: contract, and legal obligations for accounting (Art. 6(1)(c)).
- Emails — login and confirmation links, password resets, brand requests, counter-offers and deal updates, “did you close the deal?” reminders, rewards you earned (invites, pop streak, verified deals), brand verification, purchase notices (a spot or PRO that could not start), and — only if they apply to you — daily creator alerts (brands), a weekly progress e-mail on Mondays (free creators: streak, views, rank), a monthly Insights summary (PRO) and a reminder when a free listing leaves today's Lineup. The optional ones have an unsubscribe link and a switch in Dashboard → Settings. Legal basis: contract for the service e-mails; for the optional ones, our legitimate interest in telling existing users about their own listing (the “soft opt-in” of § 116(15) of Slovak Act 452/2021 and Art. 13(2) of the ePrivacy Directive) — you can turn them off any time, free of charge. We don't send third-party advertising and don't share your address. If an e-mail can't be delivered, the address, subject and error are kept in a log of the last 20 failures so we can fix delivery.
- Security logs — a keyed hash of your IP address to limit login and form abuse (rate limiting), kept for about one day. Our host may keep its own web-server logs for a short period. Legal basis: legitimate interest in security.
- ratepop's own social posts — if we post a weekly market update on ratepop's Instagram, it may show the handle and headline rate of the most-upvoted creator on The Lineup (public information from the listing). The image is published through Meta's Instagram API. Legal basis: legitimate interest; switch it off in Dashboard → Settings (“ratepop's weekly Instagram story”) or tell us and we leave you out.
- Reward abuse check — after you delete your account we keep only a one-way hash of your e-mail marking that the one-time “PRO for proven deals” reward was already granted, so it can't be claimed again by signing up anew. Legal basis: legitimate interest in preventing abuse.
We don't sell your data, we don't use advertising or tracking cookies and we don't build marketing profiles.
3. Cookies and browser storage
We don't use analytics or advertising cookies, so there is no cookie banner. Everything below is strictly necessary for a feature you use (Art. 5(3) ePrivacy Directive, § 109(8) of Slovak Act 452/2021) and never leaves your browser unless noted:
- rp_auth (local storage) — your login session, until you log out (the session itself expires after 30 days).
- rp_pending_pop, rp_confirm_pop, rp_just_popped — a calculation you haven't finished listing yet; removed when you list it.
- rp_theme, rp_cur — light/dark mode and USD/EUR.
- rp_ref — the invite code from a link you arrived with, sent once when you sign up; forgotten after 30 days.
- rp_votes, rp_dev — which cards you upvoted and a random device ID, so one browser upvotes once.
- rp_onb_done — you finished the dashboard tour.
- rp_seen_*, rp_calc_* (this tab only) — profiles you viewed and handles you calculated, so each counts once.
- rp_oauth_bind (cookie, 15 minutes, only on /api/) — ties a Google, TikTok or LinkedIn sign-in or connect you started to your browser, against login hijacking.
Fonts are hosted on our own server. Instagram, TikTok, YouTube or LinkedIn posts on profiles load only after you click them — then that platform's own privacy policy applies.
4. Who we share data with (processors and data sources)
- WebSupport s.r.o. (Slovakia) — hosting, database, backups and server email.
- Gumroad, Inc. (USA) — payments; seller of record for purchases.
- Resend (USA) or Brevo (France) — only if we use them to deliver emails.
- Google (Gemini API) (USA) — when a creator clicks “Write with AI” (handle, niche, platform numbers, calculated rate and chosen tags, to draft a bio); for the monthly re-read of public market reports; and to look at a payment screenshot a creator attached as deal proof (the image without its file metadata, plus the claimed brand, amount, format, platform and date — nothing about the account).
- Google (YouTube Data API) and Meta (Instagram Graph API) — when the calculator or the daily refresh reads the public follower and engagement numbers of a handle. Only the handle is sent. Meta also receives the weekly story image if we publish it on ratepop's Instagram.
- Google (sign-in), TikTok and LinkedIn — only if you sign in with or connect that account (see section 2).
- European Commission (VIES) — VAT number checks for brand accounts.
Transfers to the USA are covered by the EU–US Data Privacy Framework and/or the European Commission's standard contractual clauses.
5. How long we keep it
- Account, listings, deals, briefs and applications — until you delete your account (Dashboard → Settings → Account → Delete account) or delete the item yourself. Briefs close after 30 days.
- Brand requests — 12 months, then deleted automatically. If a brand deletes its account, its requests stay in the creator's inbox with the brand's email and message removed.
- Payment screenshots — until reviewed, at the latest 30 days (unattached uploads 24 hours). Insights counters and brand views — 90 days.
- Login links 20 minutes, password-reset links 30 minutes, account-connect links 15 minutes, company-email confirmation links 24 hours, e-mail confirmation links 7 days, Accept / Decline links in counter-offers 14 days, sessions 30 days.
- Security rate-limit data and handle look-ups — up to 24 hours. “Rates popped” de-duplication hashes — 2 days; daily totals 60 days.
- Weekly story images — about 8 weeks; the story history (date, market medians, featured handle) — the last 26 weeks.
- Notes about purchases that could not start — 12 months. E-mail failure log — the last 20 entries.
- Daily backups of the database — 14 days, so deleted data is fully gone after that.
- Anonymous market statistics — kept, as they can't identify you.
- Payment records — as long as accounting and tax law requires (10 years), also after you delete your account.
6. Your rights
You have the right to access your data, correct it, delete it, restrict or object to processing and to data portability. Creators and brands can download all their data (Dashboard → Settings → Account → Download my data, or the Account section of the brand dashboard) and delete their account themselves at any time. You can object to processing based on legitimate interest (e.g. calculator look-ups of your handle, the weekly story) at any time. For anything else, email hello@ratepop.co.
You can also complain to the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.
7. Age
ratepop is for people aged 18 and over. We don't knowingly process data of minors — if you believe a minor has created a listing, tell us and we remove it.
8. Changes
If we change this policy in a way that matters, we'll show a notice on the site or email you.
