Pactly

Privacy Policy

Last updated: August 5, 2026 — Version 2.2

1. Introduction

Pactly, Inc., a Delaware corporation, with registered offices at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States ("Pactly") is committed to protecting its users' privacy. This Policy describes how we collect, use, store, and protect your personal information when you use our Platform.

By using Pactly, you accept the practices described in this Policy.

2. Data we collect

2.1 Data you provide directly

Creator account:

  • Full name and handle.
  • Email and password (hashed).
  • Bio and avatar.
  • Declared and verified social networks.
  • Location (city, country).
  • Stripe account information (managed by Stripe, not stored by Pactly).

Buyer account:

  • Full name.
  • Email (authentication primarily via magic link; Creators use email and password).
  • Brand name and website.
  • Billing data (managed by Stripe, not stored by Pactly).

Guest purchase (no account):

  • Email and name for identification.
  • JWT tracking token sent to email.
  • Payment data (managed by Stripe).

Generated content:

  • Briefs, messages, publication evidence.
  • Publication screenshots and content URLs.
  • Reports about other users.
  • Support tickets.

2.2 Automatically collected data

  • IP address: retained only in hashed form (consent and visit records). During anti-bot verification it is transmitted in the clear to our security provider (Section 5.1) without Pactly storing it.
  • User agent (browser, operating system).
  • Preferred language.
  • Visited pages, performed actions, and referring URL (referer) on visits to profiles and services.
  • Date and time of sessions and of each Order's events (including which user or process originated each event).

2.3 Third-party data

  • Payment data processed by Stripe. Pactly does not store card numbers; it does temporarily retain the technical payment events Stripe sends us (amounts, transaction identifiers, payer email), which are automatically purged after 90 days (Section 8).

2.4 Derived and inferred data we generate about you

  • Internal trust and performance scores: for Creators, the Pactly Score (CRS) and its inputs (completed orders, dispute rate, acceptance rate) together with financial aggregates (totals earned, balances); for Buyers, a trust score based on their payment history, chargebacks, and reports. Part of this data is displayed publicly: the Creator's Pactly Score on their profile, and the Buyer's payment history (paid orders and abandonments) in their requests to Creators. See Section 5.2.
  • Results of the AI-assisted analysis of the screenshots you submit (account verification and publication validation): analysis confidence, detected elements and, in verifications, the audience size visible in the screenshot.
  • Internal security and risk records associated with your account or orders (anti-fraud events).
  • Relationships within the Platform: blocks between users, reports, and private notes a Buyer keeps about Creators they work with.

3. How we use your data

We use your data for the following purposes, each with its legal basis (GDPR Art. 6):

  • Process Orders, payments, and payouts — performance of the contract.
  • Verify the publication of content within the scope of validation — performance of the contract.
  • Send transactional notifications (confirmations, status alerts) — performance of the contract.
  • Calculate internal trust and performance scores (the Creator's Pactly Score, the Buyer's trust score) and apply the operational limits derived from them — legitimate interest in marketplace security (Section 5.2).
  • Make the automated decisions described in Section 5.2 — performance of the contract and legitimate interest, as applicable.
  • Prevent fraud and ensure Platform security (including risk records) — legitimate interest.
  • Comply with legal and tax obligations — legal obligation.
  • Improve the Platform via aggregate analysis (not individually identifiable) — legitimate interest; cookie-based analytics requires your consent.
  • Send promotional communications — only with explicit consent.

4. Cookies and similar technologies

4.1 Essential cookies and storage (always active)

No consent required. Necessary for basic functionality.

  • sb-[project]-auth-token (Supabase) — User session (includes session renewal). Duration: session managed by the authentication provider.
  • locale (Pactly) — Preferred language. Duration: 1 year.
  • activeRole (Pactly) — Active role when the account has both roles. Duration: 7 days.
  • referral_code (Pactly) — Referral tracking. Duration: 30 days.
  • invited_by (Pactly) — Buyer→creator invitation. Duration: 30 days.
  • cookie_consent (Pactly) — Your cookie preferences, stored in the browser's local storage (localStorage), with a logical validity of 6 months. In addition, each consent decision is recorded on our servers as proof of compliance (date, decision, notice version, hashed IP, and user agent).

4.2 Analytics and monitoring (require consent in the browser)

Help us understand aggregate Platform usage. Do not identify users personally.

  • _ga, _ga_* (Google Analytics) — Aggregate usage metrics, with anonymized IP. Duration: 2 years. Only loaded after your consent.
  • Sentry (error monitoring) — In the browser it only activates after your consent and does not use its own cookies; it records technical error reports. On our servers, error monitoring runs continuously based on legitimate interest in service stability. No user sessions are recorded.

4.3 Marketing cookies

Pactly currently does NOT use marketing cookies or pixels (no Meta Pixel or Google Ads installed). If they are added in the future, they will only be activated with your explicit consent and this section will be updated before they go live.

4.4 Consent management

The user can change their preferences at any time from the "Cookies" link in the footer or from Settings → Privacy and Cookies (in authenticated accounts). Optional technologies are not loaded until explicit consent is granted.

5. Sharing data with third parties

We do NOT sell personal data to third parties. We share data only with the following service providers necessary to operate the Platform.

5.1 Essential subprocessors

  • Stripe, Inc. (United States) — payment processing. Data: email, name, banking data (managed by Stripe).
  • Supabase, Inc. (United States, us-east-2 / AWS Ohio region) — database, authentication, and file storage. Data: all account data and the files you upload or generate (account verification screenshots, publication evidence, avatars, and brand material).
  • Resend (United States) — transactional emails. Data: email, name, notification content (including single-use access links).
  • Vercel, Inc. (United States / global) — hosting and application execution. Data: IPs, access logs, and technical application logs, which may include email addresses in operational events.
  • Upstash (United States) — usage limits (rate limiting) and cache. Data: temporary rate-limiting keys that include emails, IPs, and user identifiers, and short-lived cache (24 hours) of AI analysis results indexed by image fingerprint.
  • Sentry (United States) — error and performance monitoring. Data: user agents, URLs, and technical error traces. No user sessions are recorded.
  • Cloudflare, Inc. (United States) — anti-bot verification (Turnstile) on sign-in, registration, access links, and sensitive forms, including the privacy rights form. Data: IP address and technical browser signals, processed in transit to resolve the challenge; Pactly does not store them.
  • Anthropic PBC (United States) — AI-assisted verification of submitted media (Claude Vision API). Data: account verification screenshots and Order publication evidence screenshots, declared handle, verification code and, in publication validation, the declared URL and the Brief requirements (including reference images provided by the Buyer). Images are processed in transit and not retained by Anthropic beyond the time required to return the analysis result. Subject to Anthropic's Privacy Policy and Commercial Terms.

5.2 Automated decision-making and profiling (GDPR Article 22)

Pactly uses automated systems in the following processes. In all of them you have the right to obtain human intervention, express your point of view, and contest the decision by writing to privacy@pactly.io:

  • Social account verification: the analysis of your screenshot can automatically approve (high confidence), refer to human review (medium confidence), or reject with the option to retry (low confidence). Every rejection or referral is reviewed by an administrator.
  • Order publication validation: the automated analysis can approve the publication (which starts the payment cycle to the Creator), request a correction, or refer the case to human review. Final rejections and ambiguous signals always go through an administrator before any adverse economic effect.
  • Automated delivery checks (N0): deterministic checks (platform, deadline, publishing account, evidence present) that can return a delivery for correction.
  • Pactly Score (CRS) and Creator limits: a daily process recalculates your score and tier from your history (orders, disputes, acceptance), which determines your per-Order and monthly amount limits. You can request a review of your score.
  • Buyer trust score: your payment history may trigger additional security checks (3D Secure) at checkout, and part of that history (paid orders and abandonments) is visible to the Creators who receive your requests.
  • Report-based moderation: the accumulation of reports from distinct users can temporarily suspend (3 reporters in 30 days) or close (5 reporters) an account automatically. Any automatic suspension or closure can be appealed by writing to support@pactly.io and is reversible by an administrator.

5.3 Marketing subprocessors

Pactly currently does NOT use marketing subprocessors (no Meta pixel or Google Ads). If they are added in the future, they will only be activated with the user's prior consent and this Policy will be updated before they go live.

5.4 Data shared with Stripe

We share with Stripe the data necessary to process transactions and comply with financial regulations: full name, email address, IP address, transaction data (amounts, dates, service description), and for Creators receiving payments, identity verification and bank account data. Stripe processes this data in accordance with its Privacy Policy.

5.5 Legal disclosure

We may share data when legally required by:

  • Judicial or administrative authorities (with valid order).
  • Compliance with tax or regulatory obligations.
  • Protection of Pactly's or its users' rights, safety, or property.

6. International data transfers

Pactly, Inc. is incorporated in the United States. By using our services, your personal data may be transferred and processed in the United States — our database and file infrastructure is hosted in the us-east-2 region (AWS, Ohio) — where data protection laws different from those in your country of residence may apply.

For users in the European Economic Area (EEA) and United Kingdom: data transfer is carried out in accordance with the Standard Contractual Clauses (SCCs) approved by the European Commission and adequacy decisions when applicable.

For Brazilian users: data processing is carried out in accordance with the Lei Geral de Proteção de Dados (LGPD). You have the rights provided for in articles 17 and 18 of the LGPD.

For Mexican users: data processing is carried out in accordance with the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).

By registering with Pactly, you consent to the transfer and processing of your data in the United States under the safeguards described herein.

7. Data security

We implement technical and organizational measures to protect your data:

  • Encryption in transit (TLS 1.3).
  • Encryption at rest (database).
  • Row Level Security (RLS) in the database.
  • Authentication with secure hashing.
  • Rate limiting on critical endpoints.
  • Active security monitoring.
  • Restricted access to sensitive data (principle of least privilege).
  • Payment data processed exclusively by Stripe (PCI DSS Level 1 certification).

If a security breach affects your personal data and poses a high risk to your rights and freedoms, we will notify you without undue delay (within 72 hours where technically feasible), in accordance with GDPR Article 34. The notification will include the nature of the breach, the likely consequences, and the measures taken to mitigate them. We will also notify the competent supervisory authorities within 72 hours under GDPR Article 33.

8. Data retention

We retain your data as follows:

  • Active account: while you use Pactly.
  • Order, payment, and financial records: retained while legal and tax obligations exist (minimum 7 years after account closure).
  • Technical payment events (Stripe webhooks): automatic purge 90 days after processing.
  • Consent records: retained as proof of regulatory compliance.
  • All other data (disputes, support tickets, visit records, security events): retained while the account exists. Pactly is implementing automatic purges by category with these target periods: disputes, 5 years after resolution; tickets, 2 years after closure; visit records, 12 months. While those purges are being completed, we handle deletion requests individually (Section 9).
  • Cookies and browser technologies: per Section 4.
  • Marketing communications: until consent is withdrawn.

9. Your rights

You have the right to:

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate data. Most information can be edited from Settings.
  • Erasure: request the deletion of your data (right to be forgotten). We carry it out through a verified manual process, within legal timeframes and subject to the retention exceptions in Section 8.
  • Portability: receive a copy of your data in a structured, commonly used format. We prepare it manually for each request.
  • Objection: object to processing based on legitimate interest.
  • Restriction: limit the use of data in specific cases.
  • Withdrawal of consent: revoke previously granted consent.
  • Non-discrimination: not be penalized for exercising your rights.

9.1 How to exercise your rights

We will respond within a maximum of 30 days. Note: completed transaction data is retained for legal and tax obligations for the period required by law.

10. California residents (CCPA)

California residents (U.S.) have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect and how we use it.
  • Right to delete personal information we hold about you (subject to legal exceptions).
  • Right to correct inaccurate information.
  • Right to opt out of sale or sharing of personal information.

We do not sell your personal information, nor do we share it for behavioral advertising. Pactly currently does not use third-party advertising pixels (Section 4.3). If that changes, this section will be updated and the opt-out will be available before activation.

The "Do Not Sell My Info" link in the footer opens the cookie preference center, where you can manage any optional technology; you can also write to privacy@pactly.io.

We will not apply discriminatory treatment for exercising these rights.

11. Minors

Pactly is not directed at individuals under 18. We do not knowingly collect data from minors. If we detect a minor's account, we will proceed to close it immediately and delete their data through the process in Section 9, subject to any applicable legal retention exceptions.

If you are a parent or guardian and believe your child has provided us with data, contact us at privacy@pactly.io.

12. Links to external sites

Pactly contains links to third-party sites (social networks, payment processors, legal pages of providers). We are not responsible for the privacy practices of those sites. We recommend reviewing their policies.

13. Changes to this Policy

We may update this Policy occasionally. Substantial changes will be notified at least 30 days in advance through at least one of the following channels: email to the registered address or a prominent notice on the Platform.

The last updated date and document version appear at the top of this page.

14. Contact

For questions about this Privacy Policy, exercising your rights, or reporting a concern:

For EU residents: direct your data protection inquiries to dpo@pactly.io, indicating your country of residence.

Back to homeBack to top
·····