← Back to Mysway

Privacy Policy

Last updated: 28 May 2026

1. Who we are

Mysway ("Mysway", "we", "us", "our") operates the creator marketing platform at mysway.co (the "Platform"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices and rights you have.

2. Information we collect

Account information. Name, email address, password (stored hashed), profile photo, role (Brand, Creator, admin), workspace, and contact details.

Connected social accounts. When you connect TikTok, Instagram, or YouTube, we receive your platform user ID, handle, display name, avatar, public follower/engagement metrics, video metadata (caption, thumbnail, view/like/comment/share counts), and OAuth access & refresh tokens. Tokens are stored encrypted and used only to read metrics and, where you opted in, publish content on your behalf.

Campaign & performance data. Campaigns you create or participate in, submitted content, performance snapshots, payouts, and messages exchanged inside the Platform.

Payment information. Wallet balances, top-up history, payout requests, and the last few digits / brand of cards. Full card numbers and bank details are handled directly by our payment processor, Stripe; Mysway does not store them.

Technical data. IP address, device and browser info, cookies, log files, and basic analytics about how you use the Platform.

3. How we use information

  • Operate the Platform, authenticate you, and maintain your account.
  • Match Brands with Creators and measure campaign performance.
  • Publish content to connected social accounts on your explicit instruction.
  • Process wallet top-ups, calculate payouts, and prevent fraud and abuse.
  • Send transactional emails (sign-in, receipts, payout notifications, support replies) and, where you opted in, product updates.
  • Comply with legal obligations, including tax and anti-money-laundering rules.
  • Improve the Platform via aggregated, de-identified analytics.

4. Legal bases (EEA / UK users)

We rely on (i) performance of a contract to run your account and execute campaigns; (ii) legitimate interests to secure, improve, and market the Platform; (iii) consent for optional cookies and marketing emails (which you can withdraw at any time); and (iv) legal obligation for tax and compliance records.

5. Sharing of information

We share personal data only as needed:

  • Other Platform users: Brands can see Creator handles, public metrics, and content submitted to their campaigns. Creators can see brand names and brief details for campaigns they engage with.
  • Service providers: Supabase (database & auth), Cloudflare (hosting & CDN), Stripe (payments), Resend / email providers (transactional email), Google / Apple (sign-in), TikTok, Meta, and Google (social APIs you connect).
  • Legal: When required by law, court order, or to protect rights, safety, and the integrity of the Platform.
  • Corporate transactions: If we merge, are acquired, or transfer assets, your data may transfer subject to this Policy.

We do not sell your personal information.

6. International transfers

Our infrastructure and service providers may process data in the United States and other countries. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

7. Data retention

We keep personal data while your account is active and as long as needed to provide the Platform, comply with our legal obligations, resolve disputes, and enforce our agreements. You can request deletion at any time (see Section 9); certain financial records are retained for legally-required periods.

8. Security

We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords, scoped database access via row-level security, and least-privilege service roles. No system is 100% secure; you are responsible for keeping your credentials safe.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. To exercise these rights, email privacy@mysway.co from the address on your account. You also have the right to lodge a complaint with your local data protection authority.

10. Cookies

We use essential cookies to authenticate sessions and remember preferences, and limited analytics cookies to understand aggregate usage. You can control cookies via your browser settings; disabling essential cookies may break sign-in.

11. Children

The Platform is not directed to children under 18 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Platform or by email. The "Last updated" date above reflects the latest revision.

13. Contact

Questions, requests, or complaints? Email privacy@mysway.co.