Privacy Policy
Date of Last Revision: July 13, 2026
Welcome to CreatorStore ("CreatorStore," "we," "us," or "our"). CreatorStore is a platform that enables content creators ("Creators") to monetize their digital goods, content, services, consultations, and subscriptions ("Creator Content"), and enables Creators' fans and followers ("Customers") to discover and purchase such Creator Content. Our platform includes our website at https://creatorstore.co/ and related services (collectively, the "Service").
This Privacy Policy explains the personal information we collect from Creators and Customers (collectively, "you") via our Service, how we use and share that information, and your choices and rights concerning our information practices.
CreatorStore Labs LLC is the controller of your personal information in accordance with data protection laws of the European Economic Area and the United Kingdom. If you have any questions or comments about this Policy, please contact us at [email protected].
PLATFORM NATURE — IMPORTANT NOTICE. CreatorStore is a technology platform, not a seller, publisher, retailer, or provider of Creator Content. We host storefronts and provide the tools that enable independent Creators to run their own businesses. Every Creator on the Service is an independent business. When you as a Customer interact with a Creator — browse their store, subscribe to their newsletter, book a session, or make a purchase — the Creator is a separate and independent controller of the personal information you share with them. The Creator may collect, use, retain, and process your personal information for their own purposes independently of us, including to fulfill your order, provide support, market their own products, and comply with their own legal obligations. Each Creator may also have their own Terms & Conditions and privacy notice that govern the purchase. CreatorStore is not responsible for the actions, decisions, or data-handling practices of Creators or other third parties. Please review Section 4 for important details.
1. Personal Information We Collect
Personal Information You Provide
Account and Profile Information: Your name, email address, phone number, address, profile photo, username, password, and any additional information you provide when creating an account or using the Service. When you contact us, we also collect the content of your communications.
Financial Information: Our payment processors Stripe, Inc. ("Stripe") and PayPal, Inc. ("PayPal") collect the financial information necessary to process payments. Your financial data is processed pursuant to Stripe's services agreement and privacy policy at https://stripe.com/privacy, and PayPal's privacy statement at https://www.paypal.com/legalhub/privacy-full.
Communication Information: Information you provide when you contact us or respond to questionnaires, surveys, or feedback requests. Providing this is optional.
Commercial Information: A history of the Creator Content you browse, make available, and/or purchase.
Other Information: Other information not specifically listed here, which we will use as described in this Policy or as disclosed at the time of collection.
Information Collected Automatically
Log Information: IP address, browser type and settings, date and time of your request, and how you interacted with the Service.
Cookies Information: See our Cookie Policy at https://creatorstore.co/cookies for details.
Device Information: Device name, operating system, and browser. May depend on device type and settings.
Usage Information: How you use the Service, including content viewed, features used, actions taken, and the time, frequency, and duration of activities.
Location Information: Approximate location data based on your IP address.
2. How We Use Personal Information
To Operate and Deliver the Service. We rely on performance of our contract with you and our legitimate business interests to: provide, operate, maintain, and secure the Service; provide support, assistance, and troubleshooting; send updates about administrative matters such as changes to our terms or policies; facilitate transactions between Customers and Creators.
To Improve, Personalize, and Protect the Service. Enrich your user experience and customize your relationship with us; protect the security of the Service; prevent and detect security threats, fraud, or other criminal or malicious activities.
Research and Development. It is in our legitimate business interest to develop, analyze, and improve the Service. We may create or use aggregated, de-identified, or anonymized data, which we may share with third parties for lawful business purposes.
To Comply with Legal Obligations and Defend Legal Claims: comply with applicable laws, lawful requests, and legal process; protect our, your, or others' rights, privacy, safety, or property; audit our compliance with legal and contractual requirements; enforce the terms that govern the Service; prevent, identify, investigate, and deter fraudulent, harmful, or illegal activity.
For Marketing. We may contact you about products or services we believe may interest you.
Direct marketing: We may send special offers by email. You may opt out at any time.
Legal basis for marketing. For users in the EEA and the UK, we rely on your consent for marketing communications; you may withdraw that consent at any time. For users elsewhere, we may rely on our legitimate business interests, subject to your right to opt out.
To Facilitate Corporate Transactions. We may use your personal information in connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider.
3. Sharing and Disclosure of Personal Information
We may share the categories of personal information described above with:
Creators (for Customer purchases): When you purchase Creator Content, we share your information with the relevant Creator. We do so because it is necessary to perform the purchase contract between you and the Creator. See Section 4.
Vendors and Service Providers: Hosting and cloud providers, IT services, email and marketing providers, payment processors (Stripe and PayPal), customer support, and web analytics. These parties process personal information solely to perform their duties to us, under contract.
Professional Advisors: Lawyers, accountants, auditors, where necessary.
Business Transfers: In a merger, acquisition, due diligence, reorganization, bankruptcy, sale of assets, or service transition.
Legal Requirements: Where required by law or where we believe in good faith disclosure is necessary to comply with law, protect rights or property, prevent fraud, protect personal safety, or protect against legal liability.
Aggregated/Statistical Information: De-identified information that does not identify you, shared for research, development, and marketing.
4. Personal Information You Make Available to Creators
This section is important. Please read carefully.
Our Service is a multi-party platform. When you, as a Customer, make purchases on a Creator's page, communicate with a Creator, or express interest in Creator Content, the Creator will receive your personal information, including your name, email address, billing information (as needed to fulfill the order), and any communications you send them.
The Creator is an independent controller of your personal information for purposes they determine independently of us, including: fulfilling your purchase and providing support; processing refunds, returns, and chargebacks (refunds are the sole responsibility of the Creator, not CreatorStore); marketing their own products or services to you; and complying with their own legal obligations.
Each Creator agrees to a data processing addendum with us governing how customer data is handled, and may have their own Terms & Conditions and privacy notice describing how they handle your data. Before completing a purchase, you will be asked to agree to the relevant Creator's Terms & Conditions in addition to this Privacy Policy.
CreatorStore is not responsible for the actions of Creators or other downstream recipients of your personal information. Please review the applicable policies of the Creator before making a purchase. If you have a dispute with a Creator about their handling of your personal information, please contact them directly. We may, but are not obligated to, assist.
5. Google API Services — User Data and Limited Use
CreatorStore uses Google API Services to provide scheduling and video conferencing features. This section discloses how we access, use, store, and share Google user data, in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
Google APIs we use:
Google Calendar API — to read your free/busy availability and create, update, or cancel calendar events for confirmed bookings.
Google Meet integration (via Calendar API) — to automatically attach a Google Meet video conference link to bookings.
What Google user data we access:
Your free/busy time slots (read-only); event creation, update, and cancellation — for confirmed customer bookings only. We do NOT access event titles, descriptions, attendee lists, or any other calendar content outside what we create through our Service.
How we use Google user data:
Only to provide and improve the scheduling and video call features visible in our app. Not for advertising. Not shared with third parties, except service providers under contract (e.g., hosting providers) and only as necessary to operate the Service.
How we store Google user data:
We store the minimum data necessary: OAuth tokens, event IDs we created, and references for booking management. Tokens are encrypted in transit and at rest. We do not duplicate or store the content of your Google Calendar beyond what's required for booking operations.
How users can revoke access:
Disconnect your Google account at any time from your account settings in CreatorStore. Upon disconnection, we delete the OAuth tokens immediately and stop accessing your Google data. You may also revoke access directly from your Google Account: https://myaccount.google.com/permissions.
Human review:
We do not allow humans to read or access your Google user data, except: (a) with your explicit consent for support purposes, (b) for security investigations (e.g., abuse), (c) to comply with applicable law, or (d) when data is aggregated and anonymized for internal operations.
Limited Use compliance:
CreatorStore's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Your Rights and Choices
Depending on where you are based, and subject to applicable law, you may have the right to: access; correct; erase; restrict processing; data portability; opt out of the sale or sharing of your personal information for interest-based advertising; opt out of profiling producing legal or similarly significant effects (note: we do not engage in such profiling); object to processing; and withdraw consent where we rely on it.
To exercise these rights, contact us at [email protected]. We may require you to verify your identity. You may use an authorized agent where your jurisdiction allows. You are entitled to exercise these rights free from discrimination. We may have valid legal reasons to refuse a request and will inform you if so.
Limits on Your Rights and Choices. Your choices may be limited where fulfilling a request would impair the rights of others, our ability to provide a requested service, or our ability to comply with legal obligations.
Opt Out of Direct Marketing. Follow the unsubscribe instructions in any marketing message. You will continue to receive non-marketing emails (service updates, account notifications).
Limit Online Tracking. Manage your preferences via Cookie Settings in our website footer; block or delete cookies in browser settings (instructions at https://www.allaboutcookies.org/); use privacy plug-ins or browsers such as Brave, Privacy Badger, Ghostery, or uBlock Origin; opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.
"Do Not Track" and Global Privacy Control. Because there is no industry standard for "Do Not Track" signals, we currently do not respond to them. Where required by applicable law, we honor Global Privacy Control (GPC) signals as an opt-out of the sale or sharing of personal information for advertising.
7. Data Retention
We keep personal information only for as long as necessary for the purposes described in this Policy, after which we delete or de-identify it. Our retention criteria include the duration of your account, the time needed to provide the Service, and applicable legal, tax, and accounting requirements. As general guidance:
Account and profile data: for the life of your account, then deleted or de-identified within a reasonable period after closure (typically up to 90 days), unless longer retention is required by law.
Transaction, billing, and tax records: retained for the period required by applicable tax and accounting law (commonly up to 7 years).
Support and communications: retained for as long as needed to handle your request and for a reasonable period afterward.
Marketing data and consents: until you withdraw consent or opt out, plus a record of the opt-out itself.
Logs and security data: retained for a limited period for security, fraud-prevention, and troubleshooting purposes.
Where data is no longer needed but cannot yet be deleted (for example, in backups), we isolate it and protect it from further processing until deletion is possible.
8. Children
Our Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided personal information, contact us at [email protected] and we will endeavor to delete it.
9. Links to Other Websites
The Service may contain links to other websites we do not control, including Creator-owned websites and social media services. Information you share with these third parties is governed by their policies, not this one. Please contact them directly for information on their practices.
10. Data Storage and International Users
Personal data of customers and creators located in the European Economic Area (EEA) and the United Kingdom is stored and processed on servers located within the EEA. We do not transfer this data outside the EEA/UK for storage.
Where limited processing by our service providers may involve access from outside the EEA/UK, we ensure appropriate safeguards are in place (such as European Commission Standard Contractual Clauses or an adequacy decision, including the EU-US Data Privacy Framework where applicable).
Personal data of users located outside the EEA/UK (including in the United States) may be stored and processed in the United States and other countries that provide our service infrastructure. Data protection laws in those countries may differ from the laws where you reside.
11. Security
You use the Service at your own risk. We implement commercially reasonable technical, administrative, and organizational measures to protect personal information. However, no internet or email transmission is ever fully secure or error-free. Please consider what information you share via the Service or email.
11A. Data Breach Notification
If we become aware of a Personal Data Breach as defined by the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, or comparable data protection laws — meaning a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information we hold — we will act as follows.
a. Notification to Supervisory Authorities. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority (for example, the UK Information Commissioner's Office, or the applicable Data Protection Authority in the EEA) without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware of it. Where we are unable to provide complete information within seventy-two (72) hours, we will provide the information in phases without further undue delay.
b. Notification to Affected Users. Where the breach is likely to result in a high risk to the rights and freedoms of affected users, we will communicate the breach to affected users without undue delay in clear and plain language, describing the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address the breach. Communication may be by email, in-Service notification, or, where individual notification would involve disproportionate effort, by public communication or equivalent effective measure.
c. Notifications Under U.S. State Laws. Where a breach affects U.S. residents whose personal information is subject to state data breach notification laws (including but not limited to California Civil Code §§ 1798.29 and 1798.82), we will provide notifications in accordance with the timing, content, and method requirements of those laws.
d. Notification to Creators (as Independent Controllers). Where the breach affects personal data that a Creator processes as an independent or joint controller, we will notify the affected Creator without undue delay so they may fulfill their own notification obligations. Creators are solely responsible for their own onward notifications to their Customers and to competent authorities.
e. Records. We maintain internal records of all Personal Data Breaches, including the facts of the breach, its effects, and the remedial action taken, in accordance with Article 33(5) GDPR.
f. Cooperation. Where a Creator suffers a Personal Data Breach affecting personal data processed on their behalf by CreatorStore, we will cooperate reasonably with the Creator's investigation and provide the assistance required by the Data Processing Addendum incorporated into the Creator agreement.
11B. U.S. State Privacy Rights (California, Virginia, Colorado, Connecticut, Utah, and Others)
This Section provides additional disclosures required by U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), the Utah Consumer Privacy Act ("UCPA"), and comparable state laws.
a. Categories of Personal Information We Collect. In the past twelve (12) months we have collected the categories of personal information described in Section 1, which correspond to the following statutory categories: identifiers (name, email, IP address, account identifiers); customer records (billing and address information); commercial information (transactions, product interactions); internet or other network activity (browsing, usage data); geolocation data (approximate, IP-based only); professional or employment information (where you provide it); inferences drawn from the above; and sensitive personal information limited to account credentials and government identifiers submitted for identity verification where required by law.
b. Purposes. We use these categories for the purposes described in Section 2 (operating the Service, security, marketing, legal compliance, and corporate transactions).
c. Categories Sold or Shared. We do not sell or share personal information in exchange for monetary or other valuable consideration, and we do not use it for targeted advertising as defined under the CCPA/CPRA, VCDPA, CPA, CTDPA, or UCPA. We do not knowingly sell or share personal information of consumers under sixteen (16) years of age.
d. Do Not Sell or Share My Personal Information; Opt Out of Targeted Advertising. California, Virginia, Colorado, Connecticut, and other state residents have the right to opt out of the sale or sharing of their personal information and targeted advertising. To exercise this right, use the "Do Not Sell or Share My Personal Information" link in our website footer, or email us at [email protected]. We honor Global Privacy Control ("GPC") signals as a valid opt-out mechanism where required by law.
e. Sensitive Personal Information. California residents may limit our use of "sensitive personal information" to purposes specified by law. We do not use sensitive personal information for purposes that would trigger this right.
f. Rights of Residents. Depending on the state where you reside, you may have the right to (i) know what personal information we hold about you; (ii) receive a copy in a portable format; (iii) correct inaccurate personal information; (iv) delete personal information (subject to permitted exceptions); (v) opt out of sale, sharing, or targeted advertising as described in (d); (vi) opt out of profiling that produces legal or similarly significant effects (we do not currently engage in such profiling); and (vii) not be discriminated against for exercising these rights. To exercise these rights, contact [email protected]. We may require you to verify your identity before responding.
g. Authorized Agents. You may use an authorized agent to submit privacy requests on your behalf in states that permit this, subject to identity verification of the agent and, in some cases, of you.
h. Appeals. Virginia, Colorado, and Connecticut residents may appeal any refusal to act on a privacy rights request by emailing [email protected] (Subject: "Privacy Rights Appeal"). We will respond to the appeal within the timeframe required by applicable law.
i. Retention. Our retention practices are described in Section 7.
j. Shine the Light (California). Under California Civil Code § 1798.83, California residents may request information about our disclosure of personal information to third parties for those third parties' direct marketing purposes during the immediately preceding calendar year. We do not disclose personal information to third parties for those third parties' own direct marketing purposes.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version and update the "Date of Last Revision." For material changes, we will provide additional notice (e.g., email or in-Service notification). By continuing to use the Service after an update, you consent to the revised Policy.
13. Contact Us
CreatorStore Labs LLC
30 N Gould St, STE R, Sheridan, WY 82801, USA
Email: [email protected]
If you wish to lodge a complaint, please contact us first. Depending on where you reside (e.g., the EEA or UK), you may also have the right to complain to a data protection regulator. If you are in the UK, your regulator is the Information Commissioner's Office (ICO).