Last Updated: August 2, 2026
This Privacy Policy explains how DOTVIDEO LLC, operating as Promote It ("Promote It," "we," "us," or "our"), collects, uses, discloses, and retains personal data when you use our websites, mobile applications, support channels, and related services (the "Service"). DOTVIDEO LLC is the controller unless another notice says otherwise.
This is a privacy notice, not a request for blanket consent. We identify our purposes and legal bases below and provide additional notice or choice when required. The Service is for people aged 18 or older.
We derive Program matches, eligibility, rewards, rankings, engagement summaries, fraud-risk and duplicate-content signals, and aggregated product statistics. We do not intentionally infer sensitive traits for advertising.
| Purpose | Typical data | Legal basis where required |
|---|---|---|
| Provide accounts and Service features | Account, organization, content, social, communication, and device data | Contract; requested pre-contract steps |
| Operate Programs and calculate rewards | Briefs, submissions, public metrics, reviews, eligibility, and cycle statements | Contract; legitimate interests in accurate administration |
| Process manual or authorized automatic funding, payouts, taxes, and compliance | Transaction, contact, destination, identity/status, tax, and fraud data | Contract; legal obligation; preventing loss |
| Secure, debug, and prevent abuse | IP/country, device fingerprint, logs, errors, request context, activity, and fraud signals | Legitimate interests; legal obligation; legal claims |
| Support and service communications | Contact, messages, account, transaction context, and feedback | Contract; legitimate interests in support and improvement |
| Analytics, feature flags, and improvement | Identifiers, events, device data, masked replay, and diagnostics | Consent on the web where required; legitimate interests in product improvement, security, and diagnostics where permitted; additional notice or choice where required |
| Law and agreement enforcement | Relevant account, content, transaction, communication, and audit records | Legal obligation; legitimate interests; legal claims |
Promotional messages are sent only where permitted and include an unsubscribe method. Security, payout, transaction, and policy notices are service communications. Where we rely on legitimate interests, we balance them against your rights; you may object under Section 8.
Promote It's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When a creator chooses to connect YouTube, we use read-only authorization to obtain the authenticated channel's identifier, handle, display name, avatar, and public channel statistics. We use this data to confirm control of the channel, display accurate creator profile information, and check that Program submissions correspond to the connected channel. We do not use Google API data for advertising, sell it, or permit it to be used to train generalized artificial-intelligence models. We disclose it only to service providers needed to operate these user-facing features, or as otherwise permitted by the Google policy and applicable law. Section 7 explains how to disconnect a social account and delete its stored OAuth credential.
On the browser Service, PostHog analytics, feature-flag persistence, and session replay are off until you affirmatively allow analytics. We strip URL query strings, disable IP capture in the web configuration, and mask text, inputs, images, attributes, and network details in replay. Use the persistent Privacy settings control to reject or change your choice. Supported Global Privacy Control or Do Not Track signals keep web analytics disabled.
The native apps use PostHog for product events, feature flags, diagnostics, and masked session replay. Native replay masks text inputs, images, and designated sensitive views. Analytics can use an account identifier after sign-in and a device/app identifier before sign-in. We provide additional notice or choice where required.
We do not currently use Google Analytics, Google Ads tags, Meta/Facebook Pixel, LinkedIn Insight Tag, or other cross-context behavioral-advertising pixels on the Service. We do not sell personal data or share it for cross-context behavioral advertising as defined by applicable U.S. state laws. Public creator information shown to brands as part of the Service is not an advertising-data sale. Before materially changing these practices, we will update this Policy and provide any required choice.
See our Cookie Policy for the browser-storage inventory.
We disclose only data reasonably needed for a stated purpose. Depending on context and jurisdiction, a recipient may act as our processor, service provider, or independent controller under its own policy.
| Recipient | Purpose | Data involved |
|---|---|---|
| Supabase; Vercel; Railway; Cloudflare/R2; Redis infrastructure | Authentication, databases, APIs, hosting, delivery, media storage, and rate limiting | Account, Service content, transactions, uploads, logs, IP address, and request counters |
| Whop; Talentir | Brand payments, creator payouts, verification, compliance, and transaction administration | Contact, amount, reference, saved-method status, automatic-funding settings/status, payment metadata, destination, identity/status, tax, and compliance data as required |
| PostHog; Sentry | PostHog web/native analytics, feature flags, and masked replay; separately configured redacted Sentry errors and performance | Identifiers, events, device/app data, masked replay, and redacted diagnostics |
| Postmark; Expo; Apple/Google notification services | Email, inbound support, manual-payout operations when enabled, app updates, and push notifications | Email, message/delivery metadata, push token, and device/app data; a restricted payout inbox also receives payout contact, history, and bank instructions only if the manual-payout flow is enabled |
| Google; Apple; TikTok; Meta/Instagram; YouTube; X | Sign-in, social connection, store/version checks, Places search, Translation, linked-site favicons, profiles/posts, and metrics | Connection identifiers/tokens, selected account or public data, app/store request data, search/place input, translation text, and a linked website domain |
| ElevenLabs; ScrapeCreators | Public-media transcription and retrieval of public social data | Public media URL/audio and transcript; social handle/post URL and associated public data |
| Vimeo; Loom; Google Drive; IndexNow; linked websites and media hosts | Resolve previews for linked media and submit public Service pages for search indexing | Linked-media or website URL/resource identifier, public preview or thumbnail metadata, public Service page URLs, and ordinary service or device/network request data when linked content is fetched or viewed |
| Unsplash and other static-media or linked-content hosts | Display non-user-specific marketing images and generic placeholders | IP address, browser/app and request metadata, and referrer where supplied by the device; Promote It does not intentionally append an account identifier |
| Restricted Telegram and Discord operational channels | Internal payout-status, feedback, and error alerts | Relevant contact, payout status/amount/reference, feedback, or redacted error/request context; Telegram payout alerts exclude bank-account instructions, address, phone, and payout history |
| Advisers, authorities, and transaction counterparties | Legal compliance, claims, audits, financing, merger, acquisition, or asset transfer | Data reasonably relevant to the request, claim, diligence, or transaction |
Creator profiles, selected social metrics, portfolios, submissions, and Program history may be visible to brands and authorized team members as part of the Service. Users may publish content on social networks. We may also disclose data at your direction; to comply with law; to protect rights, safety, and security; or in a corporate transaction subject to appropriate confidentiality protections.
We retain data only as reasonably necessary, considering account status, Program and payment lifecycle, contract obligations, fraud/security risk, dispute periods, provider retention, and legal, tax, accounting, or regulatory requirements. In general:
Deleted data can remain temporarily in backups, provider recovery systems, and security logs until overwritten through normal cycles. We may keep a minimal suppression or enforcement record so deletion, unsubscribe, fraud, or legal restrictions are not undone.
Disconnecting deletes the stored OAuth credential, stops future authorized collection, and requests token revocation where supported. Synced connection/profile data is removed from the active connection record. Public URLs, content, metrics, and audit records already used for an application, submission, Program, payment, fraud review, or claim may remain under the retention rules above.
Request deletion in account settings or at [email protected]. A brand with active Programs must first end or resolve them. An accepted in-app request schedules deletion 30 days later. During that grace period, most data remains so you can cancel and restore access; user-scoped push tokens are removed so push delivery to that account stops.
At finalization, we delete the authentication account, stored social credentials, bank instructions, integration keys, profile-media objects, device-event history, and other account-specific records no longer needed. A creator or brand profile solely owned by the deleting user is anonymized; if another active owner remains, the deleting user's membership is removed and the shared entity remains available to that owner. Program, submission, public-post, metric, transaction, audit, moderation, and dispute records may remain for the purposes above, with direct profile identifiers removed or restricted where reasonably possible. Automated deletion does not remove content published on a social network. You may make a more specific request, which we assess under applicable law.
Depending on where you live and subject to exceptions, you may have rights to:
EEA, UK, and Swiss users may have GDPR-style rights, including rights concerning certain automated decisions. Residents of U.S. states with applicable comprehensive privacy laws may have state-specific access, correction, deletion, portability, opt-out, appeal, or agent rights. Availability depends on whether the law applies to DOTVIDEO LLC and the processing involved.
Send requests to [email protected] or [email protected], identifying the account and right. We may verify identity and authority and may limit a request where permitted to protect others, complete a transaction, preserve security, or meet law. We respond within the applicable deadline—generally 30 days for GDPR requests and 45 days under many U.S. state laws—and notify you of an allowed extension or appeal route.
Unsubscribe from marketing through its email link. Change web PostHog analytics through the persistent Privacy settings control. Supported GPC signals keep optional web analytics disabled; because we do not currently sell or share data for cross-context ads, there is no separate advertising sale to opt out of.
Rules and calculations recommend Programs or creators, validate eligibility and metrics, flag abuse, calculate rewards and rankings, and perform time-based review. An unreviewed submission may auto-approve after 72 hours only when Program-status and brand-funding rules pass. A cycle statement may settle partially and retry when funding is insufficient. These processes can affect visibility, approval, reward calculation, or posting time.
Outputs may be corrected for source changes, duplicates, fraud, errors, or reversals. You may contest a result, provide context, and request human review through support. Where law restricts a solely automated decision with legal or similarly significant effects, we will provide required safeguards or avoid that processing.
DOTVIDEO LLC is in the United States, and providers operate in the United States and other countries. Where transfer law requires safeguards, the applicable transfer must rely on a permitted mechanism. Depending on the recipient and transfer, that may be an adequacy decision, an applicable Data Privacy Framework certification, standard contractual clauses, a data-processing agreement, or another lawful mechanism. Contact [email protected] for information about the mechanism applicable to a particular transfer, subject to confidentiality restrictions.
We use reasonable safeguards designed for the data and risk, including encrypted transport, managed access controls, credential and sensitive-field redaction, restricted administrative access, provider security controls, monitoring, and fraud prevention. The payment provider handles complete card data. No transmission or storage system is completely secure, so we cannot guarantee absolute security. Report suspected compromise promptly.
The Service is not directed to anyone under 18, and we do not knowingly collect children's personal data. Contact [email protected] if you believe a minor used the Service.
Links and integrations lead to third parties whose independent processing follows their own notices. This Policy does not cover data a social network, payment provider, or other third party collects from you for its own purposes.
We may update this Policy as the Service, providers, or law changes. We will post the new version and date. For a material change, we provide additional Service or email notice where appropriate and obtain consent before new processing when law requires it.
Contact us with privacy questions, requests, or complaints. EEA, UK, and Swiss users may also complain to the authority where they live or work. U.S. state residents may use appeal instructions included in our response.
DOTVIDEO LLC
5830 E 2ND ST, STE 7000 #26043
CASPER, WYOMING 82609
Phone: +1 321 237 7487
Support: [email protected]
Privacy: [email protected]
© 2026 DOTVIDEO LLC. All rights reserved.