Privacy Policy
What we collect, why, and what you can ask us to do about it
Last updated: 26 August 2026
1. What we collect
Given by you when you sign up and use the Platform:
- Name, email address, and optionally a phone number and city.
- A password, which we store only as a one-way hash. If you sign in with Google we never see a password at all — Google tells us your name, email and profile picture, and nothing else.
- Clippers: the social handles you link, the verification code we issue for each, your content niche, and your payout details — UPI ID, or bank name, account number and IFSC code.
- Brands: company name, industry, website, GST number, and the account details used for any refund.
Created as you use the Platform:
- Campaigns you join, clips you submit (the public URL and the platform), their review status and any rejection reason.
- View counts read for your clips, the earnings calculated from them, your wallet balance and every transaction on it.
- Withdrawal and refund requests, and their outcomes.
- Messages you send us through the in-app conversation, and notifications we send you.
Collected automatically, and deliberately kept thin:
- A session cookie so you stay signed in. See our Cookie Policy.
- When you request an email verification code, a one-way hash of your IP address — not the address itself. It exists to stop one machine requesting thousands of codes, it cannot be turned back into an IP, and it is deleted with the code record.
- Ordinary server logs kept by our hosting provider for security and debugging.
We do not collect your card details — those go straight to Razorpay and never reach our servers. We do not run advertising or cross-site tracking pixels, and we do not buy personal data from anyone.
2. Why we use it, and on what basis
Under the DPDP Act we process your data for the specific purposes below, on your consent given when you create an account and when you supply each piece of data, or because it is a legitimate use permitted by the Act — such as complying with a legal obligation.
- To run your account: authenticate you, keep you signed in, show you your own data.
- To verify you control a social account: read the public bio of the profile you linked, to find the code we issued.
- To count views and calculate earnings: query the publishing platform for the view count of the clip URL you submitted.
- To pay you: process withdrawals to the UPI ID or bank account you gave us.
- To collect campaign payments: create and settle orders through Razorpay.
- To communicate: verification codes, password resets, submission outcomes, payout confirmations and other service messages. These are part of the service, not marketing.
- To keep the marketplace honest: detect artificial views, duplicate accounts and fraud, and enforce our Terms of Service.
- To meet legal obligations: tax, accounting, and responding to lawful requests.
We do not use your data to train machine-learning models, and we do not sell it. If we ever want to use it for a purpose not listed here, we will ask you first.
3. Who we share it with
Only the processors we need to operate, and only the data each one needs. Every one of them is bound to use it for us and not for their own purposes.
- Razorpay — payment collection and settlement. Receives the payer's name, email, phone and the amount.
- Resend — sending transactional email. Receives your email address and the message.
- Google — sign-in (if you use it), and the YouTube Data API for reading the public view count and channel details of clips and channels you link.
- Cloudinary — hosting the images you or brands upload.
- Neon — the managed PostgreSQL database that stores the Platform's data.
- Vercel — hosting and serving the application.
Between users: a brand whose campaign you join sees your name, your linked handle, the clips you submitted to that campaign and their view counts. It does not see your email, phone, payout details or your earnings on any other campaign.
We will disclose data to a law-enforcement or government authority where we are legally required to, and to a professional adviser or acquirer in connection with a reorganisation or sale — in which case this policy continues to apply until you are told otherwise.
Some of these providers operate servers outside India. Where data is transferred outside India, we do so as permitted under section 16 of the DPDP Act.
4. How long we keep it
- Account data — while your account is open, and for as long afterwards as we need it for tax, accounting and dispute records.
- Financial records — transactions, withdrawals, payments and refunds are kept for the period Indian tax and company law requires, which is longer than your account may exist. We cannot delete these on request while that obligation runs.
- Verification codes and email codes — deleted or expired shortly after use. The hashed IP attached to an email code goes with it.
- Everything else — deleted or anonymised when the purpose it was collected for has been served.
5. Your rights
Under the DPDP Act you may:
- Access a summary of the personal data we hold about you and what we do with it.
- Correct or complete anything inaccurate. Most of it you can edit yourself from your profile.
- Erase data we no longer need for the purpose it was collected for or for a legal obligation. Closing your account starts this; the financial records in clause 4 are the exception.
- Withdraw consent at any time, as easily as you gave it. Withdrawing consent for data the Platform needs in order to function means closing your account.
- Nominate someone to exercise these rights on your behalf if you die or become incapable of exercising them.
- Complain — to us first, and to the Data Protection Board of India if we do not resolve it.
Write to support@indclipping.com from your registered email address and we will respond within few hours. We may ask you to confirm who you are before acting on a request — that check protects you, not us.
6. How we protect it
- Everything travels over HTTPS. Passwords are stored only as one-way hashes.
- Password-reset and email-verification codes are stored hashed, expire quickly, and are single-use.
- Access to production data is limited to the people who need it to run the Platform.
- Card details are never stored by us — Razorpay handles them.
No system is perfect. If a breach affects your personal data we will notify you and the Data Protection Board as the DPDP Act requires.
7. Children
The Platform is not for anyone under 18. We do not knowingly collect data from children, and we do not carry out behavioural advertising or tracking directed at them. If you believe a child has given us data, tell us and we will delete it.
8. Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how we use data you have already given us, we will notify account holders by email before it takes effect and, where the DPDP Act requires it, ask for fresh consent.