Privacy Policy
1. Who we are
getseedsy is a platform that brands use to send free products to social media creators and to manage the content those creators post in return. It is operated by Cloud Nest Technology (Proprietor: Pavittar Singh), a sole proprietorship registered in India.
In this policy, “we”, “us” and “our” mean Cloud Nest Technology. This policy is published under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and the rules made under them.
2. Who this policy covers
getseedsy handles data about two quite different groups of people, and the difference matters for everything below:
- Brand users — the businesses and their team members who sign up for getseedsy and use it to run campaigns.
- Creators — the people brands invite to receive products. A creator usually does not sign up with us; their details are most often added by a brand.
This policy also covers visitors to getseedsy.com, from whom we collect nothing beyond what any web server records.
3. Our role for creator data
For brand users’ own account data, we decide how it is used, and we are the Data Fiduciary.
For creator data, the brand that added the creator is the Data Fiduciary and we act as its Data Processor: we process that data on the brand’s instructions, to provide the service to that brand. Each brand’s creator records are kept separately, so the same person can appear independently in several brands’ accounts. Brands are responsible for having a lawful basis for the creator data they add, and for honouring requests that creators make of them.
4. What we collect
About brand users
- Name, email address and a securely hashed password
- Business details the brand provides, such as legal name, GSTIN, PAN and registered address, which are used to issue tax invoices
- Subscription and payment records. Card and bank details are entered directly with our payment providers and never reach us.
- Credentials the brand chooses to connect, such as a Shopify store, a WhatsApp Business account or an Instagram account. Access tokens are stored encrypted.
- Records of activity in the account, kept for security and to show an activity history
About creators
A brand may hold some or all of the following. Most records begin as just a name and a handle.
- Name, and social handles on Instagram, TikTok and YouTube
- Email address and phone number, where the brand has them
- Shipping address — collected on the gift checkout page when a creator accepts a gift, because a courier cannot deliver without it
- Publicly available audience information, such as follower counts, top audience cities and the largest audience age bracket
- Tags, notes and custom fields the brand adds
- Campaign history: gifts offered and accepted, orders, deliveries, and content posted
- Messages exchanged with the brand by email and WhatsApp, including their content
- Whether consent to be contacted was recorded, when, and by whom
5. How we use it
- To let a brand invite a creator to a campaign and send them a product
- To pass a creator’s shipping address to the brand and its delivery partner so the product can be delivered
- To track deliveries and to show a brand the content a creator posted
- To keep the message thread between a brand and a creator in one place
- To keep a suppression list, so that anyone who unsubscribes, or whose address bounces, is not contacted again
- To bill brands, issue GST tax invoices, and meet our legal and tax obligations
- To keep the service secure, prevent abuse, and fix problems
We do not sell personal data, we do not use creator data to advertise to creators, and we do not use personal data to train machine-learning models.
6. WhatsApp and Instagram
Brands can message creators through the WhatsApp Business Platform, provided by Meta. When they do, the creator’s phone number and the message content pass through Meta to be delivered, and replies are received back into the brand’s inbox.
WhatsApp messages are only sent to creators for whom an opt-in has been recorded. The platform enforces this before any message is sent; a creator without a recorded opt-in is contacted by email instead, or not at all.
If a brand connects an Instagram business account, we use it to read publicly available information about creators and the content posted for a campaign. If a creator connects their own Instagram account, we store the access token encrypted, and it can be revoked at any time from the creator’s Instagram settings.
7. Automated reply suggestions
When a creator replies to a brand, the message may be sent to an AI service to suggest how to categorise it and a possible response. Before the text is sent, we remove the private gift-checkout links and the reply addresses we use to route messages, since those act as access keys. The rest of the message is sent as written. The suggestion is shown to the brand only; nothing is ever sent to a creator automatically, and the brand decides whether and how to reply.
8. Who we share it with
We share personal data only as needed to provide the service:
- With the brand a creator is working with, and the people that brand has invited to its account
- With the delivery partners a brand uses, who receive the shipping address
- With the service providers that run parts of the platform on our behalf:
- Amazon Web Services — email delivery and file storage
- Meta Platforms — WhatsApp message delivery and Instagram data
- Postmark — receiving email replies
- Anthropic — the reply suggestions described above
- Razorpay and Stripe — brand subscription payments. No creator data is shared with them.
- Shopify, WooCommerce and Shiprocket — where a brand connects them, to place and track orders
- Cloud hosting and database providers that store and run the application
We may also disclose data where the law requires it, for example in response to a lawful request from a government authority, or to protect the rights and safety of our users.
9. Where data is processed
Our email and file-storage services run in Amazon Web Services’ Mumbai region. Some of the other providers listed above process data outside India. Where that happens, we rely on those providers’ contractual and security commitments, and we transfer data only as permitted under the Digital Personal Data Protection Act, 2023.
10. How long we keep it
- Brand account data is kept while the account is active, and deleted after a brand asks us to close the account, subject to the exceptions below.
- Creator data is kept for as long as the brand that holds it keeps it, or until the creator asks for it to be deleted.
- Tax invoices and billing records are kept for as long as Indian tax law requires.
- The suppression list — a record that someone asked not to be contacted — is kept indefinitely, because forgetting it would mean contacting that person again.
11. Security
Connection tokens and credentials are stored encrypted. Passwords are stored only as secure hashes. Sessions use secure, HTTP-only cookies, and each brand’s data is kept separate from every other brand’s, enforced in the database itself rather than by application code alone. No system is perfectly secure, but we take reasonable measures to protect personal data, and we will notify affected people and the authorities of a personal data breach as the law requires.
12. Your rights
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access — ask for a summary of the personal data held about you and how it is used
- Correction — ask for inaccurate or incomplete data to be corrected
- Erasure — ask for your data to be deleted, as described below
- Withdraw consent — at any time. Every marketing email carries a one-click unsubscribe, which takes effect immediately.
- Grievance redressal — raise a complaint with our Grievance Officer
- Nominate someone to exercise these rights on your behalf
If you are a creator, the brand that holds your data is responsible for acting on these requests, but you are welcome to write to us and we will pass the request on and help make sure it is dealt with.
13. Deleting your data
To ask for your data to be deleted, email getseedsy@gmail.com with the subject “Data deletion request”.
- If you are a brand user, send it from the email address on your account and tell us whether you want your whole account closed.
- If you are a creator, tell us the brand that contacted you and your social handle, so we can find the right record — creator records are kept separately for each brand.
- If you connected an Instagram account, you can also remove getseedsy’s access yourself at any time from your Instagram settings under apps and websites.
We will confirm when we receive your request and act on it within 30 days. Deletion removes your personal details across your profile, campaign records and message history. We keep a minimal record that the deletion took place, so your details are not added and contacted again by mistake, and we keep any records we are legally required to retain, such as tax invoices.
14. Children
getseedsy is not intended for anyone under 18. Brands must not add creators under 18 to the platform. If we learn that we hold data about a child, we will delete it.
15. Cookies
This website does not use tracking or advertising cookies. The getseedsy dashboard uses essential cookies only, to keep you signed in; they cannot be switched off without breaking sign-in, and they are not used to track you across other websites.
16. Changes to this policy
We may update this policy as the service changes. We will change the “last updated” date above, and where a change materially affects how we use your data, we will tell brand users by email or in the dashboard before it takes effect.
17. Grievance Officer and contact
If you have a question or a complaint about how your personal data is handled, contact our Grievance Officer:
Pavittar Singh, Grievance Officer
Cloud Nest Technology (Proprietor: Pavittar Singh)
getseedsy@gmail.com
We will acknowledge your complaint and aim to resolve it promptly. If you are not satisfied with our response, you may approach the Data Protection Board of India.
See also our Terms & Conditions.