Skip to content

Legal

Privacy Policy

Last updated: September 25, 2026

ViewStage LLC ("ViewStage," "we," "us") is the controller of the personal data described here. This policy explains what we collect from creators, brands, and visitors, how we use and share it, and the choices and rights you have. Questions: [email protected].

1. Data we collect

  • Account information — name, email, password, role, and billing details when you sign up.
  • Connected-platform data — when you connect a YouTube or TikTok account, we read the profile, analytics, video, and audience data listed under "Linked accounts" below to build your match profile. If you set up a deal video to publish through ViewStage, we post it to that account after the brand approves it. We store OAuth access tokens encrypted and delete them when you disconnect the account.
  • Public profile research — when you give us a creator handle at signup (or, if you skipped it, when you connect your first account), we read that account's public profile page and ask Google's Gemini, with Google Search, to draft your creator profile fields, such as niche, bio, audience, content formats and style, languages, and country. You can edit the draft in Settings → Profile. For a brand, we read the website you give us to draft the brand profile the same way.
  • Video submissions — content you upload for AI review and brand review, with related metadata and comments.
  • AI-derived signals — transcripts, frame analysis, brand-mention extraction, and scores produced from your submissions by our AI pipeline.
  • Payment & payout information — brands pay through Stripe, which collects and stores their card or other payment details. We keep Stripe's references to them and your transaction history. Creators set up payouts in Trolley's form, which opens inside ViewStage. You enter your bank or other payout details, identity information, and tax form there, and no ViewStage form asks for them. To open your Trolley recipient profile we send Trolley your email address and ViewStage user ID. For each payout we send the amount, the currency, and our reference numbers for the payout and the deal. We keep your Trolley recipient ID, the type of payout method you chose, whether your setup is complete, and the amount and status of each payout. Trolley tells us when your profile, payout method, tax form or a payment changes. From each notice we keep only its type and the Trolley ID numbers in it, then read the current status from Trolley. If you set up a Stripe payout account before we moved payouts to Trolley, Stripe holds those details instead.
  • UGC Marketplace data — if you use the UGC Marketplace: view counts for posts you are paid on, read from the connected account that hosts the post (used to compute view-based pay), and, for brands, subscription and billing data for your plan.
  • Usage data — log data, IP address, device information, and diagnostics, including recordings of page interactions in the web app with all text, form input, and media masked. Our error monitor keeps a recording when an error occurs and for a small sample of other sessions.

YouTube API Services. ViewStage uses YouTube API Services. By connecting your YouTube account you agree to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy. ViewStage's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google or YouTube user data to develop, improve, or train generalized AI or machine-learning models, and we do not use it for advertising. You can revoke ViewStage's access at any time by disconnecting in the app or via your Google security settings.

Linked accounts

For each account you can link to ViewStage, the tables below list the access we request, what we store, how long we keep it, and how to revoke our access. We generate the scope lists from the same code that builds each authorization request.

YouTubeLinked from Settings → Connections, or "Continue with YouTube" at signup
Access we request
  • https://www.googleapis.com/auth/youtube.readonlySee your YouTube channel: its details, videos, playlists, live streams, comments, and the subscribers who show their subscriptions publicly.
  • https://www.googleapis.com/auth/yt-analytics.readonlySee YouTube Analytics reports for your channel: views, watch time, audience and traffic sources.
  • https://www.googleapis.com/auth/youtube.uploadUpload videos to your channel. We use it only to publish a deal video you set up to publish through ViewStage, after the brand approves it.
  • openidConfirm which Google account you used.
  • emailSee the email address on your Google account.
  • profileSee the name and profile picture on your Google account.
What we store
  • Channel profile: channel ID, name, handle, avatar, and the permissions you granted.
  • If you signed up with "Continue with YouTube": your Google account ID, linked to your ViewStage login, and the email address and name on your Google account. This is how you sign in, so it stays when you disconnect the channel, and we delete it with your ViewStage account.
  • Encrypted access and refresh tokens.
  • Channel statistics and daily analytics: subscribers, views and watch time.
  • Your videos: titles, descriptions, publish dates and lengths, with per-video views, likes, comments, audience retention and traffic sources.
  • Audience reports as percentages and totals: age, gender, country, city, device and traffic source, plus your channel's recent activity feed.
  • Your playlists and their statistics.
  • Public comments on your 10 most-viewed videos, with each commenter's public name and channel ID.
  • Your live broadcasts and Super Chats, with each supporter's public name, amount and message.
  • A sample of your subscribers who show their subscriptions publicly: channel name, channel ID and picture.
  • Estimated revenue, membership levels and channel members, only for a connection that granted Google's revenue or membership permission before we stopped asking for it.
  • A record of each video we published to your channel for you.
  • Figures we work out from the data above to match you with campaigns: your largest follower or subscriber count, 90-day views, average engagement rate, the age, gender and country make-up of your audience, and your match score for each campaign. When we delete an account's data, we recompute them from the accounts you still have connected. Records of match lists we already showed keep the scores you had then.
How long we keep itWe refresh or delete data fetched from the YouTube API within 30 days of fetching it. Your connection record and tokens stay while the channel is connected.
How to revoke
  • Disconnect the account in Settings → Connections. Within minutes, and always within 7 days, we delete its tokens and everything above except your sign-in link, and recompute your matching figures without it.
  • Or remove ViewStage in your Google Account. That ends our access at once. Within 7 days after you remove us, we delete its tokens and everything above except your sign-in link, and recompute your matching figures without it. If you reconnect the account before then, we keep it. Google Account permissions
TikTokLinked from Settings → Connections, or "Continue with TikTok" at signup
Access we request
  • user.info.basicSee your TikTok user ID, display name and avatar.
  • user.info.profileSee your TikTok bio, profile link and verified status.
  • user.info.statsSee your follower, following, like and video counts.
  • video.listSee your public TikTok videos and their view, like, comment and share counts.
  • video.publishPost a video to your TikTok account. We use it only to publish a deal video you set up to publish through ViewStage, after the brand approves it.
What we store
  • Account profile: TikTok user IDs, display name, avatar, bio, profile link, verified status, and the permissions you granted.
  • If you signed up with "Continue with TikTok": your TikTok user ID, linked to your ViewStage login, and your TikTok display name as your account name. This is how you sign in, so it stays when you disconnect the account, and we delete it with your ViewStage account.
  • Encrypted access and refresh tokens.
  • Follower, following, like and video counts over time.
  • Your public videos: captions, lengths, cover images and embed links, with view, like, comment and share counts and the hashtags in each caption.
  • A record of each video we published to your account for you.
  • Figures we work out from the data above to match you with campaigns: your largest follower or subscriber count, 90-day views, average engagement rate, the age, gender and country make-up of your audience, and your match score for each campaign. When we delete an account's data, we recompute them from the accounts you still have connected. Records of match lists we already showed keep the scores you had then.
How long we keep itKept while the account is connected. Account statistics older than 730 days are deleted.
How to revoke
  • Disconnect the account in Settings → Connections. Within minutes, and always within 7 days, we delete its tokens and everything above except your sign-in link, and recompute your matching figures without it.
  • Or remove ViewStage from the apps connected to your account in TikTok's settings. That ends our access at once. Within 7 days after you remove us, we delete its tokens and everything above except your sign-in link, and recompute your matching figures without it. If you reconnect the account before then, we keep it.
Sign in with GoogleLinked from the "Sign in with Google" button at login
Access we request
  • openidConfirm which Google account you used.
  • emailSee the email address on your Google account.
  • profileSee the name and profile picture on your Google account.
What we store
  • Your Google account ID, linked to your ViewStage login, plus the email address and name on your account. We store no Google token.
How long we keep itKept as part of your login while you have a ViewStage account.
How to revoke
  • Remove ViewStage in your Google Account to withdraw the permission you gave. We hold no Google token, so this changes nothing we store, and if you use Sign in with Google again, Google asks you to allow it again. The link between your Google account ID and your login stays until you delete your ViewStage account; our Data Deletion page explains how. Google Account permissions
DiscordLinked from Settings → Integrations, or the /link command in the ViewStage Discord server
Access we request
  • identifySee your Discord user ID, username, display name and avatar. It does not include your email, your servers or your messages.
What we store
  • Your Discord user ID, username and display name, linked to your ViewStage account. We store no Discord token.
  • A record of each notification we send you by Discord direct message.
  • Support tickets you open in the ViewStage Discord server, with the messages in them.
How long we keep itThe link stays until you unlink. Notification and ticket records stay with your account's support history until you ask us to delete them.
How to revoke
  • Run /unlink in the ViewStage Discord server. That deletes the link and stops Discord notifications.

We do not offer connections to X (Twitter), Twitch, Instagram, Facebook or Snapchat, and we do not ask for access to your accounts on them. We will add a platform to this section before we offer it.

2. How we use your data

  • Operate and maintain the marketplace and review pipeline.
  • Match brands and creators and compute match scores.
  • Run the automated AI review of submissions.
  • Facilitate payments and payouts and meet tax obligations.
  • Measure views on connected accounts to compute view-based pay, and operate brand subscriptions, on the UGC Marketplace.
  • Communicate about deals, support, and platform updates.
  • Detect and prevent fraud, abuse, and safety issues.

3. AI & automated processing

Submissions are processed by automated AI systems (such as Whisper, Gemini, and Qwen) to transcribe, analyze, and score them against the brand's brief. UGC Marketplace submissions go through the same automated review pipeline, calibrated for the listing's content format (such as short-form UGC or paid-ad usage). Some submissions are approved or declined automatically based on these outputs; others are routed to a brand for a human decision, with the review's findings attached. A deal can also settle without anyone deciding: if a submission passes the automated review and the brand records no decision before its review window closes, the submission is deemed approved and the creator is paid (Section 9 of the Terms). Where a submission is decided solely by automated means, you can ask us to have a person review that decision. You can contact us at [email protected] with questions about this processing.

4. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (operating the Service for you); our legitimate interests (improving and securing the Service, preventing fraud); compliance with legal obligations (e.g., tax); and your consent where required, which you may withdraw at any time.

5. How we share data

  • With brands — when you apply to or are matched with a campaign, your profile, match score, and relevant analytics are shared, and your video submissions are shared with that brand for review. On the UGC Marketplace, a deliverable you submit is shared with the hiring brand, and on approval and payment its ownership transfers to that brand under the UGC Marketplace Terms.
  • Service providers (subprocessors) — we use third parties (hosting, GPU inference, AI, payments, email, error monitoring) to run ViewStage. They process personal data to provide their service to us, and we are putting a data-processing agreement in place with each of them. Stripe and Trolley also use some of your data under their own privacy policies, as described under payment processors below. The current list is on our Subprocessors page.
  • Payment processors — Stripe processes brand payments and UGC subscription billing, and runs its own fraud and identity checks under the Stripe Privacy Policy. Trolley processes creator payouts, including recipient screening and tax forms, under its own privacy policy for your country. Stripe also pays creators who set up a Stripe payout account before we moved payouts to Trolley.
  • Legal & safety — where required by law, legal process, or to protect rights and safety (including reporting apparent child sexual abuse material to NCMEC as required by law).
  • Business transfers — in connection with a merger, acquisition, or sale of assets.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) signal.

6. Cookies

We keep cookies to a minimum — a strictly-necessary session cookie and a first-party attribution cookie that honors GPC/Do Not Track — and we use no third-party advertising cookies. See our Cookie Policy for details.

7. Data retention

We keep personal data only as long as needed for the purposes above or as required by law. Connected-platform access tokens and synced platform data are deleted when you disconnect an account, and the "Linked accounts" tables in Section 1 give the retention for each platform while it stays connected. When you delete your account, we delete your personal data, except limited records we must keep (such as transaction and tax records) for the period the law requires.

A ViewStage login can hold separate workspaces (for example, a sponsorship workspace and a UGC workspace); each workspace's business data is kept separate. If you ask us to delete one workspace, we delete that workspace's data while your other workspaces keep working, and records shared across your workspaces (such as payout identity and connected accounts) are kept while any remaining workspace still relies on them. Transaction and tax records are retained for the period the law requires in every case.

When you delete your account, a few records stay and we strip your details from them. Payment, payout and tax records stay for the period the law requires. We keep the record that you accepted our Terms and this policy, with the version and date, and remove the IP address and browser details. Brands you worked with keep their record that a deal happened, including review verdicts, ratings and how any dispute ended; we remove your name and the messages, notes and reasons you wrote on it. If a safety report or a legal request requires us to preserve content or account details, we keep them until that obligation ends and delete them then.

8. Security

We use technical and organizational safeguards including encryption in transit and at rest, encryption of sensitive credentials, strict access controls, and tenant isolation. No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.

9. Your rights & choices

Depending on where you live, you may have the right to access, correct, delete, export (port), restrict, or object to processing of your personal data, and to opt out of marketing. Under U.S. state privacy laws (such as the CCPA/CPRA) you may request to know, delete, or correct your data, and opt out of any sale or sharing (we do neither) — and we will not discriminate against you for exercising these rights.

To exercise your rights, see our Data Deletion page or email [email protected]. We verify requests before acting on them.

10. International transfers

ViewStage operates primarily in the United States, and some of our subprocessors are based in, or process data in, the U.S. and other countries outside the EEA and UK (see our Subprocessors page). If you are in the EEA or UK, transfers of your data outside the EEA and UK are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism.

We are appointing a representative in the EEA and the UK under Article 27 of the GDPR and the UK GDPR, and we will list their contact details here. Until then, if you are in the EEA or the UK, send any privacy request or question to [email protected] and we will handle it ourselves.

11. Children's privacy

The Service is for adults — you must be at least 18 to use it. We do not knowingly collect personal data from anyone under 18; if we learn we have, we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the updated policy with a new "Last updated" date and, for material changes, take reasonable steps to notify you.

13. Contact

ViewStage LLC · [email protected]
2986 Lehman Avenue #405
West Valley City, UT 84119, United States