Legal

Privacy Policy

Effective date: 1 March 2026 · Last updated: 1 March 2026

Plain English summary: We collect only what we need to run Kollabs. We never sell your data. Your deal information is yours. You can delete everything at any time.

1. Who we are

Kollabs ("we", "us", "our") is a software product that helps Instagram creators manage brand collaborations, track payments, and send performance reports. You can reach us at [email protected] for any privacy-related questions.

2. What data we collect

We collect the following categories of personal data:

Account data: Your name, email address, and (if using email/password login) a hashed password. If you sign in with Google, we receive your name and email from Google — we never see your Google password.

Deal data: Brand names, deal amounts, due dates, deliverable types, payment amounts, and any notes you choose to enter. This is the core data you create inside Kollabs to manage your business.

Usage data: Log files, IP addresses, browser type, and pages visited. We use this to understand how the product is used and to debug issues.

Communication data: If you email us or use our contact form, we store your message to respond to you.

3. How we use your data

We use your data to:

— Provide the Kollabs service: displaying your deals, sending reminder emails, generating reports.

— Improve the product: analysing usage patterns (in aggregate, not individually) to prioritise features.

— Communicate with you: sending transactional emails (reminders, receipts), and responding to your support requests.

— Comply with legal obligations: maintaining records as required by Indian law.

We do not sell your personal data to third parties. We do not use your deal data to train AI models or share it with brands.

4. Sharing your data

We share data with a small number of trusted service providers who help us run the product:

— Our Database Provider: database hosting. Your deal data lives in their infrastructure. They are GDPR-compliant.

— Email: email delivery. Your email address is shared to send you reminders and transactional messages.

— Hosting: hosting providers for our frontend and backend. They process request logs.

— Google OAuth: if you use "Continue with Google", Google confirms your identity. We receive only your name and email.

— Razorpay: if you subscribe to a paid plan, payment processing is handled by Razorpay. We never see your full card number.

All providers are contractually required to keep your data confidential and use it only to provide their services to us.

5. Performance reports

When you create a performance report in Kollabs, it is assigned a unique, unguessable URL (e.g. kollabs.org/report/a3f7c2d1...). This URL is public — anyone who has the link can view the report. You control who you share the link with. We do not index report pages in search engines.

6. Data retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 90 days, except where we are required to retain it for legal or tax compliance purposes (typically 7 years for financial records under Indian law).

Deal data is soft-deleted first (recoverable for 30 days) and then permanently deleted.

7. Your rights

You have the right to:

— Correction: ask us to correct inaccurate data.

— Deletion: request deletion of your account and associated data.

— Portability: receive your deal data in a machine-readable format (CSV export).

— Objection: object to us processing your data for marketing purposes.

8. Cookies

We use a minimal number of cookies:

— Session cookies: to keep you logged in during a browser session.

— Preference cookies: to remember your settings (theme, language).

We do not use advertising cookies or third-party tracking cookies. We do not use Google Analytics.

9. Security

We take reasonable technical and organisational measures to protect your data:

— Passwords are hashed (cost factor 12) — we never store plaintext passwords.

— All data in transit is encrypted using TLS 1.2+.

— Our database is hosted in a private network with restricted access.

— JWT tokens expire after 7 days and are signed with a server-side secret.

No system is perfectly secure. If you discover a security vulnerability, please email [email protected]. We take reports seriously.

10. Changes to this policy

We may update this privacy policy from time to time. We will notify you of significant changes by email and by updating the "Effective date" at the top of this page. Continued use of Kollabs after a policy change constitutes your acceptance of the updated terms.

11. Contact us

For any questions about this privacy policy or your data, contact us at: