Privacy Policy

Last Updated: August 2, 2026

1. Scope and Controller

This Privacy Policy explains how DOTVIDEO LLC, operating as Promote It ("Promote It," "we," "us," or "our"), collects, uses, discloses, and retains personal data when you use our websites, mobile applications, support channels, and related services (the "Service"). DOTVIDEO LLC is the controller unless another notice says otherwise.

This is a privacy notice, not a request for blanket consent. We identify our purposes and legal bases below and provide additional notice or choice when required. The Service is for people aged 18 or older.

2. Personal Data We Collect

2.1 Account and Organization Data

  • Name, username, email, photo, biography, language, country, account role, and referral source.
  • Invitation or referral identifiers, inviter/invitee relationship, attribution, exclusivity, status, and reward history.
  • Brand name, website, industry, logo, team membership, invitations, and permissions.
  • Authentication identifiers, login events, connected sign-in provider, and account status.

2.2 Creator, Social, and Public Data

  • Connected social handles and identifiers, profile details, verification status, follower and engagement counts.
  • Public post URLs, thumbnails, captions, media, timestamps, views, likes, comments, and shares.
  • OAuth access and refresh credentials, connection status, and account-ownership signals.
  • Public profiles, posts, media, and metrics obtained from social networks or public-data providers.

2.3 Programs, Content, and Communications

  • Program briefs, applications, submissions, files, scripts, transcripts, reviews, revisions, calculations, rankings, and history.
  • User messages, support requests, feedback, ratings, reports, and attachments.
  • Photos, video, audio, and documents selected or created through camera, microphone, photo-library, or file permissions.
  • Text you explicitly ask the app to read from or write to the clipboard by using a paste, copy, or share-fallback control; the app does not use these controls to continuously monitor the clipboard.
  • Text sent for translation and public-media audio sent for transcription when you use those features.

2.4 Payments, Payouts, Tax, and Compliance

  • Wallet balances, deposits, charges, withdrawals, fees, earnings, statements, invoices, refunds, chargebacks, and references.
  • Billing details, saved-payment-method reference/status, automatic-funding settings, charge attempts, and limited payment-method metadata. Whop, not Promote It, handles complete card details.
  • Payout contact and destination data, potentially including email, phone, social handle, bank or wallet destination, country, and provider status.
  • Identity, tax, sanctions-screening, and know-your-customer information requested by a provider. We generally receive a status and reference rather than its full verification file.

2.5 Device, Usage, Security, and Diagnostics

  • IP address; approximate country inferred from IP, delivery-network headers, or an offline lookup; device region; device/browser type; operating system; app version; locale; time zone; and user agent.
  • A fraud/security device fingerprint based where available on Apple's Identifier for Vendor (IDFV), Android ID, or otherwise a generated identifier stored by the app/browser. We may keep sign-in, signup, or app-session snapshots containing these signals; the routine signed-in refresh is currently limited to about once per 24 hours per account.
  • Pages, screens, events, navigation, timestamps, session activity, and feature-flag assignments.
  • Push tokens, notification status, app-installation signals, and privacy preferences.
  • Error messages, stack traces, routes, status codes, request context, crashes, performance, and fraud or security signals. Credentials and designated banking/contact fields are redacted from centralized monitoring.

2.6 Derived Data

We derive Program matches, eligibility, rewards, rankings, engagement summaries, fraud-risk and duplicate-content signals, and aggregated product statistics. We do not intentionally infer sensitive traits for advertising.

3. Sources of Data

  • You: registration, connected accounts, Programs, uploads, communications, funding, payouts, and support.
  • Your browser or device: cookies or local storage, app storage, logs, analytics, permissions, and security systems.
  • Other users: team invitations, reviews, messages, and reports.
  • Third parties: social and sign-in platforms, public webpages, social-data providers, payment and payout providers, app stores, and compliance services.

4. Purposes and Legal Bases

PurposeTypical dataLegal basis where required
Provide accounts and Service featuresAccount, organization, content, social, communication, and device dataContract; requested pre-contract steps
Operate Programs and calculate rewardsBriefs, submissions, public metrics, reviews, eligibility, and cycle statementsContract; legitimate interests in accurate administration
Process manual or authorized automatic funding, payouts, taxes, and complianceTransaction, contact, destination, identity/status, tax, and fraud dataContract; legal obligation; preventing loss
Secure, debug, and prevent abuseIP/country, device fingerprint, logs, errors, request context, activity, and fraud signalsLegitimate interests; legal obligation; legal claims
Support and service communicationsContact, messages, account, transaction context, and feedbackContract; legitimate interests in support and improvement
Analytics, feature flags, and improvementIdentifiers, events, device data, masked replay, and diagnosticsConsent on the web where required; legitimate interests in product improvement, security, and diagnostics where permitted; additional notice or choice where required
Law and agreement enforcementRelevant account, content, transaction, communication, and audit recordsLegal obligation; legitimate interests; legal claims

Promotional messages are sent only where permitted and include an unsubscribe method. Security, payout, transaction, and policy notices are service communications. Where we rely on legitimate interests, we balance them against your rights; you may object under Section 8.

4.1 Google API Services and YouTube Data

Promote It's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When a creator chooses to connect YouTube, we use read-only authorization to obtain the authenticated channel's identifier, handle, display name, avatar, and public channel statistics. We use this data to confirm control of the channel, display accurate creator profile information, and check that Program submissions correspond to the connected channel. We do not use Google API data for advertising, sell it, or permit it to be used to train generalized artificial-intelligence models. We disclose it only to service providers needed to operate these user-facing features, or as otherwise permitted by the Google policy and applicable law. Section 7 explains how to disconnect a social account and delete its stored OAuth credential.

5. Analytics, Replay, and Advertising

On the browser Service, PostHog analytics, feature-flag persistence, and session replay are off until you affirmatively allow analytics. We strip URL query strings, disable IP capture in the web configuration, and mask text, inputs, images, attributes, and network details in replay. Use the persistent Privacy settings control to reject or change your choice. Supported Global Privacy Control or Do Not Track signals keep web analytics disabled.

The native apps use PostHog for product events, feature flags, diagnostics, and masked session replay. Native replay masks text inputs, images, and designated sensitive views. Analytics can use an account identifier after sign-in and a device/app identifier before sign-in. We provide additional notice or choice where required.

We do not currently use Google Analytics, Google Ads tags, Meta/Facebook Pixel, LinkedIn Insight Tag, or other cross-context behavioral-advertising pixels on the Service. We do not sell personal data or share it for cross-context behavioral advertising as defined by applicable U.S. state laws. Public creator information shown to brands as part of the Service is not an advertising-data sale. Before materially changing these practices, we will update this Policy and provide any required choice.

See our Cookie Policy for the browser-storage inventory.

6. Disclosures and Recipients

We disclose only data reasonably needed for a stated purpose. Depending on context and jurisdiction, a recipient may act as our processor, service provider, or independent controller under its own policy.

RecipientPurposeData involved
Supabase; Vercel; Railway; Cloudflare/R2; Redis infrastructureAuthentication, databases, APIs, hosting, delivery, media storage, and rate limitingAccount, Service content, transactions, uploads, logs, IP address, and request counters
Whop; TalentirBrand payments, creator payouts, verification, compliance, and transaction administrationContact, amount, reference, saved-method status, automatic-funding settings/status, payment metadata, destination, identity/status, tax, and compliance data as required
PostHog; SentryPostHog web/native analytics, feature flags, and masked replay; separately configured redacted Sentry errors and performanceIdentifiers, events, device/app data, masked replay, and redacted diagnostics
Postmark; Expo; Apple/Google notification servicesEmail, inbound support, manual-payout operations when enabled, app updates, and push notificationsEmail, message/delivery metadata, push token, and device/app data; a restricted payout inbox also receives payout contact, history, and bank instructions only if the manual-payout flow is enabled
Google; Apple; TikTok; Meta/Instagram; YouTube; XSign-in, social connection, store/version checks, Places search, Translation, linked-site favicons, profiles/posts, and metricsConnection identifiers/tokens, selected account or public data, app/store request data, search/place input, translation text, and a linked website domain
ElevenLabs; ScrapeCreatorsPublic-media transcription and retrieval of public social dataPublic media URL/audio and transcript; social handle/post URL and associated public data
Vimeo; Loom; Google Drive; IndexNow; linked websites and media hostsResolve previews for linked media and submit public Service pages for search indexingLinked-media or website URL/resource identifier, public preview or thumbnail metadata, public Service page URLs, and ordinary service or device/network request data when linked content is fetched or viewed
Unsplash and other static-media or linked-content hostsDisplay non-user-specific marketing images and generic placeholdersIP address, browser/app and request metadata, and referrer where supplied by the device; Promote It does not intentionally append an account identifier
Restricted Telegram and Discord operational channelsInternal payout-status, feedback, and error alertsRelevant contact, payout status/amount/reference, feedback, or redacted error/request context; Telegram payout alerts exclude bank-account instructions, address, phone, and payout history
Advisers, authorities, and transaction counterpartiesLegal compliance, claims, audits, financing, merger, acquisition, or asset transferData reasonably relevant to the request, claim, diligence, or transaction

Creator profiles, selected social metrics, portfolios, submissions, and Program history may be visible to brands and authorized team members as part of the Service. Users may publish content on social networks. We may also disclose data at your direction; to comply with law; to protect rights, safety, and security; or in a corporate transaction subject to appropriate confidentiality protections.

7. Retention, Social Disconnection, and Deletion

7.1 Retention

We retain data only as reasonably necessary, considering account status, Program and payment lifecycle, contract obligations, fraud/security risk, dispute periods, provider retention, and legal, tax, accounting, or regulatory requirements. In general:

  • Account/profile data: while active and during the deletion grace period, then deleted or anonymized unless an exception applies.
  • Transactions, invoices, and tax records: for the required accounting or tax period, typically up to seven years depending on jurisdiction.
  • Program, submission, public-post, metric, communication, and moderation records: while needed to perform agreements, calculate or defend payments, address disputes, prevent fraud, enforce rights, and preserve platform integrity. They may remain after profile anonymization.
  • Social credentials: until disconnected, expired, or no longer needed. Program-related public-data snapshots may remain without the credential.
  • Security, analytics, support, and diagnostics: for a limited period based on operational, security, dispute, and improvement needs and provider configuration.

Deleted data can remain temporarily in backups, provider recovery systems, and security logs until overwritten through normal cycles. We may keep a minimal suppression or enforcement record so deletion, unsubscribe, fraud, or legal restrictions are not undone.

7.2 Disconnecting a Social Account

Disconnecting deletes the stored OAuth credential, stops future authorized collection, and requests token revocation where supported. Synced connection/profile data is removed from the active connection record. Public URLs, content, metrics, and audit records already used for an application, submission, Program, payment, fraud review, or claim may remain under the retention rules above.

7.3 Account Deletion

Request deletion in account settings or at [email protected]. A brand with active Programs must first end or resolve them. An accepted in-app request schedules deletion 30 days later. During that grace period, most data remains so you can cancel and restore access; user-scoped push tokens are removed so push delivery to that account stops.

At finalization, we delete the authentication account, stored social credentials, bank instructions, integration keys, profile-media objects, device-event history, and other account-specific records no longer needed. A creator or brand profile solely owned by the deleting user is anonymized; if another active owner remains, the deleting user's membership is removed and the shared entity remains available to that owner. Program, submission, public-post, metric, transaction, audit, moderation, and dispute records may remain for the purposes above, with direct profile identifiers removed or restricted where reasonably possible. Automated deletion does not remove content published on a social network. You may make a more specific request, which we assess under applicable law.

8. Your Rights and Choices

Depending on where you live and subject to exceptions, you may have rights to:

  • Know or access personal data and obtain a portable copy.
  • Correct, delete, or restrict personal data.
  • Object to legitimate-interest processing or direct marketing.
  • Withdraw consent without affecting earlier lawful processing.
  • Opt out of sale, sharing for cross-context behavioral advertising, or targeted advertising where applicable; we do not currently engage in these activities.
  • Appeal a denied request, use an authorized agent where allowed, and avoid discrimination for exercising a right.
  • Complain to a competent data-protection or privacy authority.

EEA, UK, and Swiss users may have GDPR-style rights, including rights concerning certain automated decisions. Residents of U.S. states with applicable comprehensive privacy laws may have state-specific access, correction, deletion, portability, opt-out, appeal, or agent rights. Availability depends on whether the law applies to DOTVIDEO LLC and the processing involved.

Send requests to [email protected] or [email protected], identifying the account and right. We may verify identity and authority and may limit a request where permitted to protect others, complete a transaction, preserve security, or meet law. We respond within the applicable deadline—generally 30 days for GDPR requests and 45 days under many U.S. state laws—and notify you of an allowed extension or appeal route.

Unsubscribe from marketing through its email link. Change web PostHog analytics through the persistent Privacy settings control. Supported GPC signals keep optional web analytics disabled; because we do not currently sell or share data for cross-context ads, there is no separate advertising sale to opt out of.

9. Automated Processing

Rules and calculations recommend Programs or creators, validate eligibility and metrics, flag abuse, calculate rewards and rankings, and perform time-based review. An unreviewed submission may auto-approve after 72 hours only when Program-status and brand-funding rules pass. A cycle statement may settle partially and retry when funding is insufficient. These processes can affect visibility, approval, reward calculation, or posting time.

Outputs may be corrected for source changes, duplicates, fraud, errors, or reversals. You may contest a result, provide context, and request human review through support. Where law restricts a solely automated decision with legal or similarly significant effects, we will provide required safeguards or avoid that processing.

10. International Transfers

DOTVIDEO LLC is in the United States, and providers operate in the United States and other countries. Where transfer law requires safeguards, the applicable transfer must rely on a permitted mechanism. Depending on the recipient and transfer, that may be an adequacy decision, an applicable Data Privacy Framework certification, standard contractual clauses, a data-processing agreement, or another lawful mechanism. Contact [email protected] for information about the mechanism applicable to a particular transfer, subject to confidentiality restrictions.

11. Security

We use reasonable safeguards designed for the data and risk, including encrypted transport, managed access controls, credential and sensitive-field redaction, restricted administrative access, provider security controls, monitoring, and fraud prevention. The payment provider handles complete card data. No transmission or storage system is completely secure, so we cannot guarantee absolute security. Report suspected compromise promptly.

12. Children and Third-Party Services

The Service is not directed to anyone under 18, and we do not knowingly collect children's personal data. Contact [email protected] if you believe a minor used the Service.

Links and integrations lead to third parties whose independent processing follows their own notices. This Policy does not cover data a social network, payment provider, or other third party collects from you for its own purposes.

13. Changes to This Policy

We may update this Policy as the Service, providers, or law changes. We will post the new version and date. For a material change, we provide additional Service or email notice where appropriate and obtain consent before new processing when law requires it.

14. Contact and Complaints

Contact us with privacy questions, requests, or complaints. EEA, UK, and Swiss users may also complain to the authority where they live or work. U.S. state residents may use appeal instructions included in our response.

DOTVIDEO LLC

5830 E 2ND ST, STE 7000 #26043

CASPER, WYOMING 82609

Phone: +1 321 237 7487

Support: [email protected]

Privacy: [email protected]

© 2026 DOTVIDEO LLC. All rights reserved.

Privacy Policy | Promote It