Skip to content

Privacy notice

Version 2026.10.04 · Effective 4 Oct 2026

Changes in this version: v0 for gateway review

Who is responsible

CreatorPodium is run by Shubhankar Kalra, an independent developer — an individual, not a registered company. Postal address: Ganga Utopia, Bavdhan, Pune, Maharashtra 411021. Support: support@creatorpodium.com. Grievance officer: Shubhankar Kalra, Founder & Grievance Officer, grievance@creatorpodium.com.

What we collect and why

The table lists each kind of data we hold, why we hold it and for how long. Each cell is quoted from the CreatorPodium specification.

Source: specs/operations.md §1.4

Field Purpose Retention
payer email (payer_contacts.email_ct) receipts, refunds, caps (via payer_key HMAC) 180 days after last payment, or erasure
payer phone, UPI VPA, card details — never stored (discarded from webhook payloads; Razorpay holds them)
reporter email (reports.reporter_email_ct) outcome email 180 days after resolution
report details (free text) moderation 180 days after resolution (DATA-032)
claimant email (claims.claimant_email_ct) claim codes, owner-control links while the listing is owner-confirmed; else 180 days after claim closure
privacy-request email request handling 1 year after completion (proof of compliance)
outbox recipient + payload (email_outbox.to_email_ct, payload_ct; may hold bearer links) sending one email 30 days after sent/dead
IP address rate limiting (binding, not stored), visitor hash input not stored; visitor hash salts deleted after 48 h
owner images (R2) display after moderation until owner removes, opt-out, or removal
privacy exports (R2 privacy-exports/<random>.json) access request answer 7 days
payment records (payments, ledger_entries, refunds) accounting, tax, disputes, ranking 8 years (CMP-023)

Legal basis, notices and processors

Source: specs/operations.md §7.4

Notices at each collection point (checkout email, report email, claim email, privacy form) link the privacy notice and state the specific purpose.

Legal basis: voluntary provision for a specified purpose (receipts, refunds, claims); withdrawal = erasure request.

Processors (disclosed in the privacy notice): Cloudflare (hosting, database, storage, analytics, bot checks, email routing), Razorpay (payments), Resend (email), Sentry (error tracking), Backblaze (encrypted backups). Telegram and UptimeRobot receive no personal data.

Payers must be 18+; a payer found to be under 18 is refunded and erased

Cross-border transfer: permitted except to countries the Government restricts

Your rights

Source: specs/product.md §4.11

Payers (and anyone whose email we hold) can request access, correction, erasure or raise a grievance

a verification link proves control of the email

erasure removes contact PII while keeping payment records without direct identifiers

Make a request with the privacy request form. Requests are answered within the time in this table:

Source: specs/operations.md §7.3

Case Clock
DPDP rights request ≤ 30 days (legal 90)

You may also complain to the Data Protection Board of India.

Source: specs/operations.md §7.1

Rule 3 notice (itemized data, purposes, withdrawal, rights, complaint to the Board)

Complaints

Write to grievance@creatorpodium.com or see Contact and grievance.

Changes to this notice

Each legal document shows its version, its effective date and a summary of changes.