privacy policy

100%

PRIVACY POLICY

Creaxor · operated by Digissets Ventures Pvt Ltd

Effective 28 August 2026

IN SHORT

A summary of the sections below. The sections themselves set out the detail.

  • We collect what we need to run your account, take your payments and pay creators.
  • We never sell or rent your personal data, and we never share it so that someone else can market to you.
  • There is no identity check for supporters — we never ask for your Aadhaar or PAN. Creators are verified, because the law requires it before we send them money.
  • If you send an alert to a creator's stream, what you send is published to their audience, and may be read aloud by a speech service and stored as audio. Buying Tickets while a creator is live is published in the same way.
  • You can connect a YouTube or Kick account so that typing in a creator's chat works like pressing the button on our site. It is optional, we only ever read, and you can take the permission back at any time. Section 15 explains it.
  • Close your account whenever you like. You have 30 days to change your mind — sign back in and nothing is lost. After that we delete it, apart from records the law makes us keep.
  • Your data is stored in India. We never see or store your card number or your banking credentials.
  • If something goes wrong, raise a request through Support in the Platform. If we don't put it right, you can escalate to the Data Protection Board of India.


This Privacy Policy is the notice given by Digissets Ventures Pvt Ltd (the “Company”, “we”, “us”) under the Digital Personal Data Protection Act, 2023. It forms part of our User Agreement and explains what personal data we collect when you use Creaxor (the “Platform”), why, who we share it with, how long we keep it, and what you can do about it. Words with capital letters have the meanings given in the User Agreement.

1. Who we are, and the words we use

1.1  Digissets Ventures Pvt Ltd (CIN U66190TS2023PTC179513), Road No. 04, H.No. 14-196, Vivekananda Nagar, Dist. Medchal-Malkajgiri – 500055, Hyderabad, Telangana, India, is the Data Fiduciary in respect of your personal data. That means we decide why and how it is processed, and we are accountable for it.

1.2  You are the Data Principal — the person the data is about.

1.3  A Data Processor is a company that processes personal data on our behalf and on our instructions, such as our cloud host or our payment processor. Section 6 lists them.

1.4  This Policy applies to creaxor.com, our applications, our creator portal, and our overlays, widgets and related services.

2. The law this Policy is built on

2.1  The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. This is India's data protection law and the primary framework for this Policy.

2.2  The Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, under which we publish this Policy.

2.3  Laws that require us to collect and keep certain data regardless of your preference: the Prevention of Money Laundering Act and the KYC framework (creator verification), the Income-tax Act (tax deduction, payments and record-keeping), and the Goods and Services Tax law.

3. What personal data we collect

3.1  Everyone with an account: your full name, email address, mobile number and date of birth. Supporter accounts have no password — you sign in with a one-time code — so we hold no password for you. If you edit your profile you may also give us your legal name as it appears on your PAN, your address, and a profile photo.

3.2  When collection begins. We create a record holding your name and email address at the moment you first request an email verification code — before that code is verified, before you have agreed to anything, and whether or not you go on to create an account. If you abandon signup at that point, that record still exists.

3.3  Supporters: records of what you do on the Platform — Tickets you purchase, claim or spend; Collectibles you obtain; Challenges you back and any dispute you raise; alerts you send, including the display name and the message text; and the payment records for anything you buy. We do not verify a Supporter's identity and we do not collect a Supporter's Aadhaar or PAN.

3.4  Creators, in addition to 3.1: your legal name and date of birth; your address; identity verification data obtained through DigiLocker/Aadhaar-based verification and PAN verification (Individual Creators), or CIN, GST and director verification data (Company Creators), carried out through our verification partner; your bank account details (account holder name, account number, IFSC) so that we can pay you; your PAN and, where applicable, your GST registration number; and, for a Company Creator, your directors' details.

3.5  Content you give us: your streams, images, videos, audio, designs, text, the message text of any alert you send, the reason you give for a dispute, files you attach to a support request, and anything else you upload or publish.

3.6  What we do not collect: your card number, CVV, UPI PIN or net-banking credentials — these go directly to our payment processor and never reach us. We do not collect biometric data. We do not ask for your location. We do not knowingly collect data about anyone under 18. Our own application does not record your IP address or browser details; some of the third parties in Section 6 do, in the ordinary course of serving you.

3.7  How we hold this data. Identity and payment data is held with access limited to the staff who need it to verify a Creator and to make payments. Where we hold a password it is stored only as a one-way hash; Supporter accounts have no password. We can read the identity data we hold when we need to, and Section 11 explains the limits of what we can promise about security.

3.8  Files you upload. Please do not upload anything to the Platform that you would not be willing to have read by someone who obtained a link to it.

4. Why we process your data, and on what basis

4.1  We process your personal data to run Creaxor and to do the things you come to Creaxor for: creating and securing your account and signing you in; processing your payments and delivering what you pay for or take part in; showing a Creator who has supported them, where you have not chosen to stay anonymous; keeping the Platform safe and free of fraud and abuse; communicating with you about your account and your activity; responding to your questions and complaints; and understanding, in aggregate, how the Platform is used so that we can improve it.

4.2  For Creators we also process personal data to verify who you are before we pay you, to make those payments, to deduct or collect any tax the law requires, to issue invoices and statements, and to keep the financial and compliance records we are obliged to keep.

4.3  Alerts and speech. Where you send an alert to a Creator's live stream and that Creator has speech enabled, we transmit the display name and the message you typed to Microsoft's speech service so that it can be spoken aloud on the broadcast. We store the resulting audio file. We also keep the text of your message for a period so that we can prepare frequently requested phrases in advance.

4.4  We process most of this on the basis of your consent, or because you have given us the data voluntarily for a specific purpose you can see at the time. Some processing we carry out because the law requires it — in particular Creator identity verification, tax deduction and collection, financial record-keeping, and responding to lawful requests from authorities. Where the law requires it, that processing does not depend on your consent and continues for as long as the law says.

4.5  Where we use data only in aggregated, de-identified form, in a way that does not identify you, it is no longer personal data and we may use it to operate, analyse and improve the Platform.

4.6  We do not process your personal data for purposes incompatible with those described here without asking you first.

5. Consent, and how to withdraw it

5.1  Where we rely on your consent, that consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action.

5.2  We ask for your consent to this Policy and our User Agreement through the confirmation you give when you register.

5.3  You can withdraw your consent by closing your account (Section 8). When you do, we stop the processing that depended on it. Withdrawal does not make our earlier processing unlawful, and it is as straightforward to withdraw as it was to give.

5.4  Withdrawing consent means we can no longer provide the Platform to you.

5.5  Where the law requires us to hold data — for example creator verification records, or tax records — withdrawing consent does not remove that obligation, and we keep those records for as long as the law says.

6. Who we share your data with

6.1  We do not sell your personal data. We do not rent it. We do not share it with anyone so that they can market their own products to you. There is no exception to this, and nothing in this Policy should be read as creating one.

6.2  Data Processors. We use service providers who process personal data on our behalf, under contract, only on our instructions, and with no right to use it for their own purposes. The providers we currently use, and what each receives, are:

(a)  Razorpay — payment processing. Receives your name, email address and mobile number, and for Creators also PAN, GST number, bank account details and registered address. Because the payment sheet runs in your browser, Razorpay also sees your IP address and sets its own cookies.

(b)  Decentro Fintech — identity verification of Creators only. Receives Aadhaar (through DigiLocker), PAN, CIN, GSTIN and director identification numbers, and returns the verification data we store under clause 3.4.

(c)  Fast2SMS — SMS delivery. Receives your mobile number and the one-time code we are sending you.

(d)  Amazon Web Services — cloud hosting, file storage, database and outbound email, in the Mumbai region. Receives everything the Platform stores, and the recipient and body of every email we send you.

(e)  Microsoft Azure — cloud hosting, file storage, key management and, where a Creator has speech enabled, the speech service in clause 4.3, which receives the display name and message text of an alert.

(f)  Microsoft Clarity — a website analytics and session-recording service that runs on our pages and records how visitors interact with them. Section 14 explains this further.

(g)  Google — we load display fonts and a 3D-model viewer from Google's content delivery networks, which receive your IP address and browser details when a page loads.

(h)  unpkg — a content delivery network from which we load a 3D graphics library on the pages that show collectibles, and which receives your IP address.

(i)  api.postalpincode.in — a postal lookup service that receives the PIN code you type when you enter an address, so that we can fill in the town and state for you.

(j)  Google — where a Creator has connected a YouTube channel, we call the YouTube Data API to read that channel's live chat. Google receives the permission the Creator granted us and the identifier of the broadcast we are reading. We send Google no Supporter data, and nothing we hold about you is disclosed to Google by this. Section 15 explains what we read and how the permission is withdrawn.

(k)  Kick — where a Creator has connected a Kick channel, Kick sends us the messages posted in that channel's chat, and receives from us only the replies we post back into it. Section 15 explains this further.

6.3  We may add or change providers, and we will keep this list current.

6.4  Creators. When you support a Creator, that Creator sees the display name you used, the action, the number of Tickets, and any message you sent. If you send an alert anonymously, your name is replaced with “Anonymous” and you are left out of the public leaderboards. Anonymity is available on alerts only — when you buy Tickets, claim Tickets or back a Challenge, your name is shown. Creators do not see your email address, your mobile number, your postal address, your government identifiers or your payment details.

6.5  The public. If you send an alert, the display name and message are published to the Creator's live audience and to anyone who later watches a recording. If you buy Tickets, claim Tickets or back a Challenge while the Creator is broadcasting, that is published in the same way. If you are among a Creator's largest supporters, your name, rank and lifetime Ticket totals may be displayed on their broadcast. We cannot retrieve or delete anything once it has been broadcast.

6.6  Authorities. We will disclose personal data where the law requires it — to tax authorities, to law enforcement acting under lawful process, to a court, or to a regulator. We will not hand over your data to anyone simply because they ask.

6.7  Business transfer. If the Company is acquired or merges with another business, personal data may transfer as part of it. We will notify you, and the acquirer remains bound by this Policy until it lawfully replaces it.

7. Where your data is stored

7.1  Our infrastructure is hosted in Indian data centre regions, and your personal data is stored in India.

7.2  Some of our service providers process limited data outside India — in particular the speech service in clause 4.3, the analytics service in Section 14, the chat platforms in clause 6.2(j) and (k), and the content delivery networks in clause 6.2(g) and (h). Indian law permits such transfers except to countries the Central Government specifically restricts, and we will not transfer your data to any restricted country.

7.3  Payment data is handled by our payment provider in accordance with Reserve Bank of India requirements. We never see or store your card or banking credentials.

8. How long we keep your data

8.1  How long we keep something depends on what it is. Your account and everything in it is kept while the account is open, then for 30 days after you close it, then deleted. A small set of records the law requires us to keep outlives that, and clause 8.4 says which.

8.2  Closing your account, and the 30 days that follow. Closing hides your account straight away, but nothing is deleted for 30 days. Sign back in within that time and everything is restored exactly as you left it. If you do not, we then delete your account and your personal data — your name, your date of birth, your contact details, your profile photograph, your address, and any identity-verification records we hold. Any Tickets you still held can no longer be used. That deletion is permanent and cannot be reversed.

8.3  You do not have to spend your Tickets, settle anything, or ask our permission before closing your account. Restoring it inside the 30 days requires the one-time code we send to your registered mobile number.

8.4  Records we are required to keep. Payment, tax and financial records are retained for the periods the law requires and survive the deletion in clause 8.2 — your transactions remain in our books, but the name, the display name and any message attached to them are removed, so they are no longer linked to you by name. Creator identity, payment and tax records are likewise retained; Creator accounts are closed by writing to us and clause 8.2 does not apply to them.

8.5  Some things we keep for longer, and you should know which. Audio generated from an alert you sent is stored and served from an address that is not access-controlled, and we do not currently delete it. Support requests are kept even after the account they came from is closed, because a support request may need to be answered after someone has left. Records of transactions are never altered or removed, because our financial ledger is append-only.

9. Your rights

9.1  You have the right to obtain a summary of the personal data we hold about you and of how we are processing it, together with the identities of the Data Processors with whom we have shared it.

9.2  You have the right to have your personal data corrected, completed or updated if it is wrong or out of date. You can correct most of it yourself from your profile.

9.3  You have the right to have your personal data erased, unless we are required by law to keep it.

9.4  You have the right to nominate another person to exercise these rights on your behalf if you die or become unable to exercise them yourself.

9.5  You have the right to a readily available means of grievance redressal — see Section 13.

9.6  Exercising these rights costs you nothing, and we will not treat you differently for exercising them.

9.7  To exercise any of these rights, write to support@creaxor.com from the email address registered on your account, so that we can be satisfied the request comes from you. We will respond within 90 days at the outside, and in practice sooner.

9.8  If you are not satisfied with how we handle your request or your complaint, you may complain to the Data Protection Board of India. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal.

10. Children

10.1  Creaxor is for adults. You must be 18 or over to use it, in any capacity. We do not knowingly collect the personal data of anyone under 18.

10.2  We ask for your date of birth when you register and rely on what you tell us. We do not independently verify it.

10.3  We do not track children, monitor their behaviour, or direct advertising at them.

10.4  If we learn that we hold the personal data of someone under 18, we will erase it and close the account, and we will refund what they paid us. If you believe a child is using the Platform, raise a request through Support in the Platform and we will act.

11. How we protect your data

11.1  Data is encrypted in transit. Secrets are held in a managed vault. Passwords, where we hold them, are stored only as hashes. Aadhaar numbers and Supporter PAN numbers are encrypted at rest; clause 3.7 sets out precisely what is and is not encrypted, and you should read it rather than rely on this summary.

11.2  Administrative access is limited to a small number of staff accounts. Those accounts carry broad access to personal data, and we tell you that rather than imply otherwise.

11.3  We are honest with you about the limits of this: no system connected to the internet can be guaranteed secure. What we can promise is that we take reasonable security safeguards, that Section 12 sets out what we will do if there is a breach, and that we will not pretend otherwise.

11.4  Creators are given a private overlay address for their broadcasting software. Anyone who has that address can see the supporter information it displays, so Creators are asked to keep it private.

12. If there is a data breach

12.1  If a personal data breach occurs we will tell you, without delay, in plain language: what happened, what data was affected, what the likely consequences are, what we have done about it, what you can do to protect yourself, and who to contact. We will do that by email to the address on your account and through the notifications in the Platform.

12.2  We will intimate the Data Protection Board of India without delay on becoming aware of a breach, and will give the Board the detailed particulars the Rules require within 72 hours of becoming aware, or within any longer period the Board allows on request.

12.3  We keep a record of every breach we become aware of, and of the intimations we gave, for the period the law requires.

13. Complaints and grievance redressal

13.1  You can raise a complaint through Support in the Platform, which opens a ticket you can follow and reply to. You may also email support@creaxor.com. You do not need an account to raise a support request. Requests to exercise your rights under Section 9 should be made as described in clause 9.7, because we have to be satisfied that they come from you.

13.2  We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. Requests to exercise your rights under Section 9 are answered within 90 days at the outside.

13.3  If you remain dissatisfied, you may escalate to the Data Protection Board of India.

14. Cookies, analytics and similar technologies

14.1  The Creaxor site does not set any cookies of its own. We keep you signed in using your browser's local storage rather than a cookie.

14.2  We use Microsoft Clarity, a third-party analytics service, on every page of the site. Clarity records how visitors interact with our pages — including clicks, scrolling, mouse movement and snapshots of the page as you saw it — so that we can see where the Platform is confusing or broken. It sets its own cookies in your browser and is provided by Microsoft, who process the data on their own infrastructure.

14.3  Our payment provider also sets its own cookies when the payment sheet is open.

14.4  We do not use cookies to build an advertising profile of you, and we run no advertising, remarketing or cross-site tracking product.

14.5  We store the following in your browser's local storage, which is not a cookie but is personal data: your name, email address, mobile number, profile picture, user identifier and sign-in token.

15. Connected chat accounts

15.1  You can connect a YouTube or a Kick account to Creaxor, so that typing a command in a Creator's live chat does the same thing as pressing the button on our site. Connecting is optional, it is never done for you, and everything else on the Platform works whether you connect or not.

15.2  If you are a Creator, connecting lets us read your live chat. You are sent to the platform's own sign-in screen, and what comes back to us is a permission, not your password — we never see or store your YouTube or Kick password. On YouTube we ask only for read access. What we read is the identifier of the broadcast you are streaming and the messages posted in its live chat while it runs. We do not post, upload, edit, hide or delete anything on your channel, and we do not read your videos, your subscribers, your comments or your analytics. We hold no permission that would let us do any of those things.

15.3  If you are a Supporter, connecting proves that the chat account typing the commands is yours. You name the account on our site, we give you a short code, and you type that code once in the Creator's chat. We then keep the platform's own identifier for that account, and the name it displays under, so that we can recognise what you type later.

15.4  What we keep from a chat message. For each command we act on we record the platform it arrived from, the platform's identifier for the message, the identifier and display name of the account that sent it, the text of the command, and what we did about it. We keep this so that a command is never acted on twice, and so that we can answer a question about a spend afterwards. Where the account that sent a command is not connected to any Creaxor account, we do not keep its identifier or its name in readable form at all — we keep an irreversible fingerprint instead, and the readable values are recorded only if the sender turns out to be a Creaxor user.

15.5  YouTube. Our YouTube features use YouTube API Services. By using them you also agree to the YouTube Terms of Service, which you will find at https://www.youtube.com/t/terms . What Google itself does with your data is described in the Google Privacy Policy, at https://policies.google.com/privacy . Those two documents tell you what Google does; this Section tells you what we do.

15.6  Taking the permission back. A Creator can disconnect a channel at any time from the creator portal, and a Supporter can unlink an account at any time on our site or by typing the unlink command in chat. When a Creator disconnects a YouTube channel we also tell Google to cancel the permission, so that it ends on both sides rather than only on ours. You never have to rely on us for that: you can withdraw it yourself at any time from your Google account's security settings, at https://security.google.com/settings , and a Kick connection can be withdrawn from Kick's own settings in the same way. Once the permission is gone we can no longer read that chat.

15.7  How long we keep it. Anything we obtain through the YouTube API and hold in readable form — display names, the text of chat messages and the like — is kept for no more than 30 days and is then deleted automatically. The connection between your chat account and your Creaxor account lasts longer, because it is held as the platform's own identifier rather than as anything readable about you, and it is renewed each time you use it. Deleting your Creaxor account removes the connection with it, as clause 8.2 describes.

15.8  A command is a public act. Typing a command in a Creator's live chat puts it in front of that Creator's audience, and where the command sends an alert, clause 6.5 applies to it exactly as it would if you had sent the same alert from our site.

16. Messages we send you

16.1  We send you messages necessary to run your account: one-time sign-in codes by SMS, and by email your receipts, support-request updates, and notices about changes to our terms. These are not marketing, and you will continue to receive them for as long as you have an account.

16.2  We do not send marketing or promotional email, and we do not send promotional SMS. We have no mailing list and we do not run campaigns.

16.3  Because everything we send is necessary to the service, there is currently no way to switch these messages off other than by closing your account. If we ever begin sending marketing messages, we will ask for your consent first and give you a way to unsubscribe.

17. Changes to this Policy

17.1  If we change this Policy we will publish the new version here and, where the change is material, notify you directly. Continuing to use the Platform after a change takes effect means you accept it. If you do not, you may withdraw consent and close your account.

18. Contact

18.1  Questions about this Policy, or about your personal data: Support in the Platform, or support@creaxor.com.