privacy policy

100%

PRIVACY POLICY

Creaxor · operated by Digissets Ventures Pvt Ltd

Effective 7 September 2026 · Updated 3 October 2026 — clauses 8.7 and 15.6 updated: when we delist a Creator's account their page no longer opens, even from a direct link; for 30 days after the delist they can still sign in to the creator portal for their financial records; we keep when we delisted the account; and a delisted Creator's chat channel stays connected, but no command typed in it is acted on · Updated 28 September 2026 — clauses 5.2, 8.4 and 8.7 updated: a Creator leaves when we delist their account, which they can now ask for in the creator portal, even before accepting the documents clause 5.2 describes, as well as by writing to us; we record when they ask from the portal, and when they ask we contact them before we delist their account; delisting is permanent, and is not the same as taking a page off the listing; and when we delist an account we keep the reason we recorded and any notice we posted about it · Updated 27 September 2026 — clauses 3.4, 3.7, 4.4, 5.2, 5.3, 5.4, 5.5, 8.1, 8.2, 8.3, 8.4, 8.5, 8.7, 9.3, 15.7 and 17.1 updated: accepting our User Agreement and Creator Agreement is final, and you withdraw your consent to our processing your personal data by closing your account, after which that processing stops apart from what Section 8 keeps; a Creator can take their page off the listing without closing their account; the form for asking to become a Creator only shares contact details; 8.5 says why the records that outlive an account are kept, and for how long; the documents that carry a Creator's PAN are now stored where only the Platform can read them; and when a Creator leaves we keep their personal details together with the record of their activity on the Platform, for complaints, disputes, legal claims and lawful requests · Updated 26 September 2026 — clauses 5.2 and 8.5 updated: a Supporter's tick when they register is now recorded, with the versions agreed to and when, and that record outlives the account · Updated 25 September 2026 — clauses 3.6, 3.7, 5.2, 8.5, 9.3, 11.1, 14.5 and 17.1 updated: a Creator's PAN, and a Company Creator's authorised signatory's PAN, are encrypted at rest, though not where a PAN appears inside a GST registration number or in a document we store as a file, and those files are protected by an address nobody can guess rather than by access limits; we say how we ask for your consent, and a Creator now ticks a box in the creator portal for each of our Creator Agreement, this Policy, our User Agreement and our Refund Policy, without which their page cannot be put live, by them or by us; a Supporter is told about a change to this Policy on the site; our own application records your IP address in one place, when you set aside an amount for chat commands, and keeps that record; and 8.5 and 9.3 call what we keep after a chargeback what it is, a note about a payment method · Updated 24 September 2026 — clauses 3.1, 3.3, 3.4, 3.7, 4.2, 6.2(b), 8.4, 8.5, 9.7, 11.1, 16.1 and 17.1 updated: an Individual Creator verifies their PAN and is never asked for an Aadhaar; a Company Creator's authorised signatory verifies their Aadhaar through DigiLocker before the company's page can go live; we no longer accept a PAN from Supporters; and a Creator is told about a change to this Policy in their creator portal

IN SHORT

A summary of the sections below. The sections themselves set out the detail.

  • We collect what we need to run your account, take your payments and pay creators.
  • We never sell or rent your personal data, and we never share it so that someone else can market to you.
  • There is no identity check for supporters — we do not ask for your Aadhaar or PAN. Creators are verified, because the law requires it before we send them money. An individual creator verifies their PAN and is never asked for an Aadhaar; a company creator's authorised signatory also verifies their Aadhaar through DigiLocker before the company can go live.
  • If you send an alert to a creator's stream, what you send is published to their audience, and may be read aloud by a speech service and stored as audio. Buying Tickets while a creator is live is published in the same way.
  • You can connect a YouTube or Kick account so that typing in a creator's chat works like pressing the button on our site. It is optional, we only ever read, and you can take the permission back at any time. Section 15 explains it.
  • If you are a Supporter, close your account whenever you like. You have 30 days to change your mind — sign back in and nothing is lost. After that we delete it, apart from records the law makes us keep. A few other records outlive it too, and Section 8 lists them. If you are a Creator, you leave when we delist your account, which you can ask us to do from your creator portal or by writing to us, and we keep your personal details together with the record of what you did on the Platform; clause 8.7 says what, and why.
  • Your data is stored in India. We never see or store your card number or your banking credentials.
  • If something goes wrong, raise a request through Support in the Platform. If we don't put it right, you can escalate to the Data Protection Board of India.


This Privacy Policy is the notice given by Digissets Ventures Pvt Ltd (the “Company”, “we”, “us”) under the Digital Personal Data Protection Act, 2023. It forms part of our User Agreement and explains what personal data we collect when you use Creaxor (the “Platform”), why, who we share it with, how long we keep it, and what you can do about it. Words with capital letters have the meanings given in the User Agreement.

1. Who we are, and the words we use

1.1  Digissets Ventures Pvt Ltd (CIN U66190TS2023PTC179513), Road No. 04, H.No. 14-196, Vivekananda Nagar, Dist. Medchal-Malkajgiri – 500055, Hyderabad, Telangana, India, is the Data Fiduciary in respect of your personal data. That means we decide why and how it is processed, and we are accountable for it.

1.2  You are the Data Principal — the person the data is about.

1.3  A Data Processor is a company that processes personal data on our behalf and on our instructions, such as our cloud host or our payment processor. Section 6 lists them.

1.4  This Policy applies to creaxor.com, our applications, our creator portal, and our overlays, widgets and related services.

2. The law this Policy is built on

2.1  The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. This is India's data protection law and the primary framework for this Policy.

2.2  The Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, under which we publish this Policy.

2.3  Laws that require us to collect and keep certain data regardless of your preference: the Prevention of Money Laundering Act and the KYC framework (creator verification), the Income-tax Act (tax deduction, payments and record-keeping), and the Goods and Services Tax law.

3. What personal data we collect

3.1  Everyone with an account: your full name, email address, mobile number and date of birth. Supporter accounts have no password — you sign in with a one-time code — so we hold no password for you. If you edit your profile you may also give us your address and a profile photo, and a Supporter can show one of their Collectibles as their profile picture instead. A Creator also gives us the name printed on their PAN card, for the verification in clause 3.4.

3.2  When collection begins. We create a record holding your name and email address at the moment you first request an email verification code — before that code is verified, before you have agreed to anything, and whether or not you go on to create an account. If you abandon signup at that point, that record still exists.

3.3  Supporters: records of what you do on the Platform — Tickets you purchase, claim or spend; Collectibles you obtain; Challenges you back and any dispute you raise; alerts you send, including the display name and the message text; and the payment records for anything you buy. We do not verify a Supporter's identity and we do not collect a Supporter's Aadhaar or PAN. If you gave us a PAN, or your Aadhaar number for verification, before we stopped accepting them, we still hold what that check recorded. For a PAN: the number, encrypted, with a keyed fingerprint of the kind clause 3.7 describes; the name the PAN is registered to, which we also recorded as your legal name, and the title it is registered under; whether the PAN was valid and whether it was linked to an Aadhaar, as the check reported; and the date the PAN's record was last updated. For an Aadhaar: your Aadhaar number, encrypted as clause 3.7 describes, and any other details the verification returned, apart from the photograph, which we have removed. Nothing else, including that legal name, is encrypted in that way. We no longer use any of it, and nothing on the Platform depends on it. A payment you made while that name was recorded as your legal name may show it as the buyer's name, which the Creator you paid can see. We do not change the buyer's name on a payment after it is made, so that name stays on the payment while you have an account; when your account is deleted it is removed from the payment, as clause 8.4 describes. What the check recorded is deleted with your account under clause 8.2, apart from the bare record of the check that clause 8.5 describes, and you can ask us to erase it sooner under clause 9.3.

3.4  Creators, in addition to 3.1:

(a)  Every Creator: your legal name and date of birth; your address; your bank account details (account holder name, account number, IFSC) so that we can pay you; your PAN and, where applicable, your GST registration number; and a record of each payment you ask us for — the amount, the date, the last four digits of the account it was to be sent to with its IFSC, the transfer reference once we have paid it, and any tax deducted from it.

(b)  An Individual Creator: identity verification data, carried out through our verification partner — your PAN together with your name exactly as printed on the card, which we check against the name the PAN is registered to, and, if you are registered for GST, your GST registration. We do not ask an Individual Creator for an Aadhaar number, whether to become a Creator, to go live or to be paid. Where we already hold one from a verification carried out before 7 September 2026, clause 8.4 governs how long we keep it.

(c)  A Company Creator: your directors' details, and identity verification data, carried out through our verification partner — PAN, CIN, GST and director verification data, and the Aadhaar verification of your authorised signatory, the individual authorised to sign on the company's behalf. That Aadhaar verification must be completed before your page can go live. The signatory does it themselves, from the KYC page in your portal: they sign in to DigiLocker and agree there to share their Aadhaar details with us through our verification partner. The verification is made against the Aadhaar number we hold on file for your signatory: the one you gave us or, if you had not given us one, the one entered on that page when a verification is first started. We keep that number from when you give it to us or, if it comes from that page, from when a verification is first started, whether or not a verification is completed, and we record it again against each verification that is started. Once a verification is completed we also keep what DigiLocker returns: the signatory's name, date of birth, gender, address and care-of name, their Aadhaar number with all but the last four digits hidden, a reference number for the verification, and hashed forms of the email address and mobile number registered with their Aadhaar, together with the response in which those details reached us. We do not keep the photograph that DigiLocker also returns; we remove it from that response before we store it, and we have removed it from every such response we stored before we began doing so. We may also hold your signatory's PAN if you gave it to us. A verification counts only for the Company Creator it was made for, so a person who signs for more than one company verifies for each of them. If the Aadhaar number on file for your signatory is changed, a verification made against the earlier number no longer counts, and the signatory must verify again before your page can next go live. If you are an authorised signatory, this Policy applies to the data we hold about you just as it applies to a Creator's own.

(d)  Every Creator: a record of what happens on your page — the Tickets issued and claimed in connection with you and your claim code, the Alerts sent to you, your Challenges and what became of them, including any dispute, and the transactions between you and your Supporters.

3.5  Content you give us: your streams, images, videos, audio, designs, text, the message text of any alert you send, the reason you give for a dispute, files you attach to a support request, and anything else you upload or publish.

3.6  What we do not collect: your card number, CVV, UPI PIN or net-banking credentials — these go directly to our payment processor and never reach us. Clause 3.9 sets out what we do keep about the instrument you paid with. We do not collect biometric data. We do not ask for your location. We do not knowingly collect data about anyone under 18. Our own application records your IP address in one place only: when you set aside an amount on our site so that commands you type in a Creator's live chat can spend your Tickets (clause 6.11 of the User Agreement), we record the address that request came from, together with when you made it and the limits you set, because that record is our evidence of what you authorised if a chat spend is ever disputed; clause 8.5 says how long we keep it. Apart from that, our own application does not record your IP address, and it does not record your browser details; some of the third parties in Section 6 do, in the ordinary course of serving you.

3.7  How we hold this data. Identity and payment data is held with access limited to the staff who need it to verify a Creator and to make payments. Where we hold a password it is stored only as a one-way hash; Supporter accounts have no password. Every Aadhaar number we hold — an authorised signatory's under clause 3.4(c), and any we still hold from a verification carried out before 7 September 2026 — is encrypted at rest, and beside it we may also keep a keyed one-way fingerprint, so that we can recognise the same number if it is given to us again without decrypting it. Wherever the Platform shows an authorised signatory's Aadhaar number, in the Company Creator's portal or to our own staff, it shows only the last four digits. A Creator's PAN, including a PAN a GST check returns to us, and an authorised signatory's PAN are encrypted at rest in the same way, and beside the PAN a Creator gives us we also keep a keyed one-way fingerprint of the same kind, so that we can recognise the same PAN if it is given to us again without decrypting it; we keep no fingerprint of a signatory's PAN. A GST registration number contains the PAN it is registered under, and we hold a Creator's GST registration number, and the record of a GST check apart from the PAN it returns, without encrypting them. The other details DigiLocker returns under clause 3.4(c), and Creators' bank details, are protected by the access limits above but are not encrypted in that way. The documents that carry a Creator's PAN — the invoices and acknowledgements the creator portal prepares for a Creator to issue to us for their revenue share, and the tax deduction certificates we give them — are stored as files, and those files are not encrypted in that way either; they are stored where only the Platform can read them, and they are given only to the Creator they concern — in their creator portal or, as clause 9.5 of our Creator Agreement describes, by email once they no longer have access to it — and to our staff, within the access limits above. We can read the identity data we hold when we need to, and Section 11 explains the limits of what we can promise about security.

3.8  Files you upload. Please do not upload anything to the Platform that you would not be willing to have read by someone who obtained a link to it.

3.9  The instrument you pay with. When you make a payment we record which payment instrument paid for it, but only as a one-way hash of the kind clause 3.7 describes. The hash lets us recognise the same instrument if it is used again; it cannot be turned back into the instrument. We keep it so that if a payment method turns up again after a chargeback we can see that, and look at the payment before treating it as ordinary. We do not block payment methods; clause 4.7 says what we do instead, and why. That works for a UPI ID. For most cards it does not, because our payment provider gives us no reliable way to recognise the same card a second time, and clause 9.7 of the User Agreement says so. Beside the hash we keep, where the payment method has them, the last four digits, the card network and the issuing bank, so that you and we can tell one payment method from another. If you pay by UPI, the value we hash is your UPI ID — the handle you pay from, which often carries your name or your mobile number. We keep only the hash of it. We do not store the handle itself against your payment, and it is not shown to a Creator or to anyone else; if you send it to us yourself in a support request, clause 8.5 governs that request. Clause 4.7 explains what all of this means for you.

3.10  Chargebacks, and what we work out from them. If a chargeback or a payment dispute is raised against a payment you made, we keep a record of it: the payment it was raised against, the reason given, the stage it reached, the amount, and how it ended — whether we defended it successfully or not. We keep a record of every one, whichever way it goes. From those records, together with what you have bought from us and how long your account has been open, we work out a risk assessment: a number that says how closely a payment ought to be looked at. It is worked out afresh each time it is looked at and it is never stored. It decides nothing on its own — clause 4.7 says what it is used for and who decides.

4. Why we process your data, and on what basis

4.1  We process your personal data to run Creaxor and to do the things you come to Creaxor for: creating and securing your account and signing you in; processing your payments and delivering what you pay for or take part in; showing a Creator who has supported them, where you have not chosen to stay anonymous; keeping the Platform safe and free of fraud and abuse; communicating with you about your account and your activity; responding to your questions and complaints; and understanding, in aggregate, how the Platform is used so that we can improve it.

4.2  For Creators we also process personal data to verify who you are before we pay you — and, for a Company Creator, to verify the individual who signs for it before its page can go live — to make those payments, to deduct or collect any tax the law requires, to issue invoices and statements, and to keep the financial and compliance records we are obliged to keep.

4.3  Alerts and speech. Where you send an alert to a Creator's live stream and that Creator has speech enabled, we transmit the display name and the message you typed to Microsoft's speech service so that it can be spoken aloud on the broadcast. We store the resulting audio file. We also keep the text of your message for a period so that we can prepare frequently requested phrases in advance.

4.4  We process most of this on the basis of your consent, or because you have given us the data voluntarily for a specific purpose you can see at the time. Some processing we carry out because the law requires it — in particular Creator identity verification, tax deduction and collection, financial record-keeping, and responding to lawful requests from authorities. Where the law requires it, that processing does not depend on your consent and continues for as long as the law says. We also keep the records Section 8 describes, including after an account is closed or a Creator leaves, so that we can answer a complaint or a dispute, establish or defend a legal claim, or respond to a lawful request from an authority.

4.5  Where we use data only in aggregated, de-identified form, in a way that does not identify you, it is no longer personal data and we may use it to operate, analyse and improve the Platform.

4.6  We do not process your personal data for purposes incompatible with those described here without asking you first.

4.7  Chargebacks, and what can follow from one. We use the records in clauses 3.9 and 3.10 to answer your bank when a payment is disputed, to see whether the same instrument has been disputed before, and to decide whether we will take further payment from you. You should know what can follow from that. Where a chargeback is made against a payment to us and we do not succeed in defending it, we note the payment method it was made with, and a later payment from that method is looked at by a person before it is treated as ordinary. We do not block the payment method itself, and we will not, for two reasons we would rather tell you than leave you to discover: a payment method may belong to somebody other than the account holder, so blocking it would shut out a person who has no account with us and no way of hearing from us; and a new UPI ID takes a minute to make, so it would stop nobody who meant to come back. Clause 8.6 says how long we keep the note. We may also refuse further payment from your account, which means a purchase will not start. A person decides that, not a score. The assessment in clause 3.10 only decides whose case is looked at first; no account is refused automatically. If the payment was not yours to authorise — someone else used your card or got into your account — tell us, and we will leave that chargeback out of the assessment and clear any note we made because of it; clause 9.9 of the User Agreement sets out what happens then. This processing rests on your consent, as clause 4.4 describes, for the purpose in clause 4.1 of keeping the Platform safe and free of fraud and abuse.

5. Consent

5.1  Where we rely on your consent, that consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action.

5.2  How we ask for it. If you are a Supporter, we ask when you register: our registration form will not let you finish until you tick a box confirming that you have read and agree to our User Agreement and this Policy, both of which you can open from beside that box. When you finish registering, we record that you ticked it: which version of each of those two documents you agreed to, and when. We have no such record for an account registered before we began keeping one. If you are a Creator, you do not register — we open your account, as clause 1.1 of our Creator Agreement describes — and you are not shown that box. Instead, in your creator portal we show you our Creator Agreement, this Policy, our User Agreement and our Refund Policy, each with its own box to tick to confirm that you have read and agree to it; none of the boxes is ticked for you. We ask when you set up your portal, once you have filled in your profile, or, if your account was opened before we asked in this way, at your next visit to the portal. Your page cannot be put live, by you or by us, until you have ticked all four; a page that was already live when we started asking stays live. We ask again whenever we change the Creator Agreement in a way you must accept. Until you have accepted the version of the Creator Agreement currently in force and agreed to the other three, you cannot use your creator portal beyond those setup steps, apart from asking us to delist your account (clause 8.7). Each time, we record which document you agreed to, which version of it, and when. If you ask to become a Creator through the form on our site, you share your contact details with us so that we can contact you about listing with us; we do not use them for marketing. We do not ask anyone to accept a change to this Policy; Section 17 says how you are told about one.

5.3  Accepting our User Agreement — and, if you are a Creator, our Creator Agreement — is final: those agreements end only as their own terms say. Your consent to our processing your personal data is different: you can withdraw it only by closing your account (Section 8), apart from the permission to read a connected chat, which Section 15 says how to take back. When you do, we stop the processing that depended on it, apart from what Section 8 says we keep, for how long and why. Closing your account does not make our earlier processing unlawful. If you are a Creator and only want your page to stop being listed, you can take it off the listing yourself from your creator portal, as clause 1.5 of our Creator Agreement describes: it can then no longer be found by browsing or searching, though a direct link still opens it. That does not close your account or end our agreement, and our processing continues.

5.4  Closing your account means we can no longer provide the Platform to you.

5.5  Where the law requires us to hold data — for example creator verification records, or tax records — closing your account does not remove that obligation, and we keep those records for at least as long as the law says; clause 8.7 says what else we keep when a Creator leaves.

6. Who we share your data with

6.1  We do not sell your personal data. We do not rent it. We do not share it with anyone so that they can market their own products to you. There is no exception to this, and nothing in this Policy should be read as creating one.

6.2  Data Processors. We use service providers who process personal data on our behalf, under contract, only on our instructions, and with no right to use it for their own purposes. The providers we currently use, and what each receives, are:

(a)  Razorpay — payment processing. Receives your name, email address and mobile number, and for Creators also PAN, GST number, bank account details and registered address. Because the payment sheet runs in your browser, Razorpay also sees your IP address and sets its own cookies.

(b)  Decentro Fintech — identity verification of Creators only. Receives PAN and the name on the PAN card, CIN, GSTIN and director identification numbers, and returns the verification data we store under clause 3.4. For a Company Creator it also carries out the DigiLocker verification of the authorised signatory's Aadhaar: it receives the signatory's Aadhaar details from DigiLocker, with the consent the signatory gives there, and passes them to us. We no longer send it an Individual Creator's Aadhaar, because we no longer ask for one.

(c)  Fast2SMS — SMS delivery. Receives your mobile number and the one-time code we are sending you.

(d)  Amazon Web Services — cloud hosting, file storage, database and outbound email, in the Mumbai region. Receives everything the Platform stores, and the recipient and body of every email we send you.

(e)  Microsoft Azure — cloud hosting, file storage, key management and, where a Creator has speech enabled, the speech service in clause 4.3, which receives the display name and message text of an alert.

(f)  Microsoft Clarity — a website analytics and session-recording service that runs on our pages and records how visitors interact with them. Section 14 explains this further.

(g)  Google — we load display fonts and a 3D-model viewer from Google's content delivery networks, which receive your IP address and browser details when a page loads.

(h)  unpkg — a content delivery network from which we load a 3D graphics library on the pages that show collectibles, and which receives your IP address.

(i)  api.postalpincode.in — a postal lookup service that receives the PIN code you type when you enter an address, so that we can fill in the town and state for you.

(j)  Google — where a Creator has connected a YouTube channel, we call the YouTube Data API to read that channel's live chat. Google receives the permission the Creator granted us and the identifier of the broadcast we are reading. We send Google no Supporter data, and nothing we hold about you is disclosed to Google by this. Section 15 explains what we read and how the permission is withdrawn.

(k)  Kick — where a Creator has connected a Kick channel, Kick sends us the messages posted in that channel's chat, and receives from us only the replies we post back into it. Section 15 explains this further.

6.3  We may add or change providers, and we will keep this list current.

6.4  Creators. When you support a Creator, that Creator sees the display name you used, the action, the number of Tickets, and any message you sent. If you send an alert anonymously, your name is replaced with “Anonymous” and you are left out of the public leaderboards. Anonymity is available on alerts only — when you buy Tickets, claim Tickets or back a Challenge, your name is shown. Creators do not see your email address, your mobile number, your postal address, your government identifiers or your payment details.

6.5  The public. If you send an alert, the display name and message are published to the Creator's live audience and to anyone who later watches a recording. If you buy Tickets, claim Tickets or back a Challenge while the Creator is broadcasting, that is published in the same way. If you are among a Creator's largest supporters, your name, rank and lifetime Ticket totals may be displayed on their broadcast. We cannot retrieve or delete anything once it has been broadcast.

6.6  Authorities. We will disclose personal data where the law requires it — to tax authorities, to law enforcement acting under lawful process, to a court, or to a regulator. We will not hand over your data to anyone simply because they ask.

6.7  Business transfer. If the Company is acquired or merges with another business, personal data may transfer as part of it. We will notify you, and the acquirer remains bound by this Policy until it lawfully replaces it.

7. Where your data is stored

7.1  Our infrastructure is hosted in Indian data centre regions, and your personal data is stored in India.

7.2  Some of our service providers process limited data outside India — in particular the speech service in clause 4.3, the analytics service in Section 14, the chat platforms in clause 6.2(j) and (k), and the content delivery networks in clause 6.2(g) and (h). Indian law permits such transfers except to countries the Central Government specifically restricts, and we will not transfer your data to any restricted country.

7.3  Payment data is handled by our payment provider in accordance with Reserve Bank of India requirements. We never see or store your card or banking credentials.

8. How long we keep your data

8.1  How long we keep something depends on what it is. A Supporter account and everything in it is kept while the account is open, then for 30 days after you close it, then deleted. A small set of records the law requires us to keep outlives that, and clause 8.4 says which. A few other things outlive it as well, and clauses 8.5 and 8.6 say which. A Creator account is different, and clause 8.7 says what happens to it.

8.2  Closing a Supporter account, and the 30 days that follow. This clause applies to Supporter accounts. Closing hides your account straight away, but nothing is deleted for 30 days. Sign back in within that time and everything is restored exactly as you left it. If you do not, we then delete your account and your personal data — your name, your date of birth, your contact details, your profile photograph, your address, and any identity-verification records we hold. Any Tickets you still held can no longer be used. That deletion is permanent and cannot be reversed. Clauses 8.4, 8.5 and 8.6 set out the few records that outlive it.

8.3  If you are a Supporter, you do not have to spend your Tickets, settle anything, or ask our permission before closing your account. Restoring it inside the 30 days requires the one-time code we send to your registered mobile number.

8.4  Records we are required to keep. Payment, tax and financial records are retained for the periods the law requires and survive the deletion in clause 8.2 — your transactions remain in our books, but the name, the display name and any message attached to them are removed, so they are no longer linked to you by name. The hash of the payment instrument described in clause 3.9 stays with the transaction, because the record of what was paid and by what would otherwise be incomplete. It carries no name and cannot be read back to your UPI ID or your card, but if the same instrument pays us again we can match the two, and to that extent the record is not anonymous. Creator identity, payment and tax records are kept as well, for at least the periods the law requires, and they include everything we hold under clause 3.4(c) about a Company Creator's authorised signatory, including a verification that no longer counts because the number on file was changed, and any Aadhaar number or Aadhaar verification data we hold from an Individual Creator's verification before 7 September 2026. A Creator's name is not removed from their transactions; Creator accounts are closed by delisting them, which a Creator can ask us to do from their creator portal or by writing to us, and clause 8.7 says what delisting is and what we keep when a Creator leaves, and why.

8.5  Some things we keep for longer, and you should know which, and why: they record what happened on the Platform, between you and other people or between you and us, and we may need them to answer a complaint or a dispute, to establish or defend a legal claim, or to respond to a lawful request from an authority. Audio generated from an alert you sent — something said in public, on a Creator's stream — is stored and served from an address that is not access-controlled, and we do not currently delete it. Support requests are kept even after the account they came from is closed, because a support request may need to be answered after someone has left, and we do not currently delete them. Records of transactions are kept, because our financial ledger is append-only, but the name, the display name and any message on them are removed as clause 8.4 describes. If you gave us a PAN, or your Aadhaar number for verification, before we stopped accepting them from Supporters (clause 3.3), the deletion in clause 8.2 leaves a bare record that the check took place, so that we can show it was made, and we do not currently delete it: what kind of check it was, when it was made, its transaction references, for an Aadhaar the count of one-time codes requested for it, and, for a PAN, the statuses it reported and the date the PAN's record was last updated. Everything else the check recorded is deleted. If you set aside an amount for chat commands, the record of each time you did so, including the IP address it was done from (clause 3.6), also outlives the deletion in clause 8.2, because it is our evidence of what you authorised if a chat spend is disputed, and we do not currently delete it. The record that you ticked the box when you registered (clause 5.2) — which versions of our User Agreement and this Policy you agreed to, and when — also outlives the deletion in clause 8.2, so that we can show what you agreed to; it holds nothing else about you, and we do not currently delete it. The note we keep about a payment method after a chargeback also outlives the deletion in clause 8.2; clause 8.6 says for how long, and why.

8.6  The note we keep about a payment method, and why it outlives your account. Where a chargeback we did not succeed in defending was made against a payment, we keep a note of the payment method it came from for eighteen months from the day we make it, and it then expires by itself. It survives the deletion in clause 8.2 and the closing of your account — a record that closing an account would clear is not a record at all, and we would rather tell you that than promise you a deletion we do not carry out. What survives is the one-way hash of the payment method and the reason for the note. Your name, your contact details and the rest of your account are deleted as clause 8.2 says. The record of the chargeback itself sits with our payment records, and clause 8.4 governs how long those are kept. Eighteen months is not a round number we picked: a UPI ID that has been closed can be given to a different person after two years, so a note kept longer than that would in time be a note about somebody who had nothing to do with it. When the eighteen months are up we delete the note. We delete it sooner where the payment was not yours to authorise, as clause 9.9 of the User Agreement describes.

8.7  When a Creator leaves. Clauses 8.2 and 8.3 do not apply to a Creator account. A Creator leaves when we delist their account, whether they asked us to — from their creator portal or by writing to us — or we end the relationship, as Section 9 of our Creator Agreement describes. Asking does not delist the account by itself: we contact the Creator first, and then delist it. Delisting is permanent: the Creator's page comes off the listing and out of search, no longer opens, even from a direct link, and cannot be published again. For 30 days after the delist the Creator can still sign in to the creator portal, to see and download their financial records and to issue an invoice or acknowledgement for what we pay them, and for nothing else; after that they can no longer sign in. It is not the same as taking a page off the listing, which clause 5.3 describes and which a Creator can undo. When the account is delisted we do not delete the Creator's personal data or the record of what they did on the Platform, and we keep the two together, still linked to the Creator by name. A Creator deals with the public every day — through their page, on their streams and with their Supporters — and that record is what shows who did what, and when; we may need it to answer a complaint or a dispute, to establish or defend a legal claim, or to respond to a lawful request from an authority. What we keep is:

(a)  the Creator's personal details — everything clauses 3.1 and 3.4 describe, including, for a Company Creator, what clause 3.4(c) describes about its authorised signatory;

(b)  the record of the Creator's public-facing activity — their page, the Tickets issued and claimed in connection with them and their claim code, the Alerts sent to them and the audio made from them, their Challenges, what they delivered, the disputes raised and the statistics clause 4.4 of our Creator Agreement describes, and every transaction between them and their Supporters; and

(c)  what passed between the Creator and us — the payments they asked for and that we made, the invoices, acknowledgements and tax deduction certificates, the records clause 5.2 describes of which version of each document they agreed to and when, their support requests, when they asked us from their creator portal to delist their account, and, when we delisted it, when we did, the reason we recorded and any notice we posted about it.

We do not currently delete any of it, except where clause 10.4 applies. Two things in it are kept for less time: the record we keep of each chat command itself (clause 15.4), which we delete after 90 days; and a Supporter's name, display name and message, which are removed from the transactions and Alerts in (b) when that Supporter's account is deleted, as clause 8.4 describes. An Alert sent by a chat command is kept like any other Alert.

9. Your rights

9.1  You have the right to obtain a summary of the personal data we hold about you and of how we are processing it, together with the identities of the Data Processors with whom we have shared it.

9.2  You have the right to have your personal data corrected, completed or updated if it is wrong or out of date. You can correct most of it yourself from your profile.

9.3  You have the right to have your personal data erased, unless we are required by law to keep it. Clauses 8.5, 8.6 and 8.7 set out what we keep for longer than that and why. The note in clause 8.6 is not one we will remove on request, because a note you could ask us to remove would not be a record at all — but we do remove it where the payment was not yours to authorise, as clause 9.9 of the User Agreement describes.

9.4  You have the right to nominate another person to exercise these rights on your behalf if you die or become unable to exercise them yourself.

9.5  You have the right to a readily available means of grievance redressal — see Section 13.

9.6  Exercising these rights costs you nothing, and we will not treat you differently for exercising them.

9.7  To exercise any of these rights, write to support@creaxor.com from the email address registered on your account, so that we can be satisfied the request comes from you. If you are the authorised signatory of a Company Creator and have no account of your own, write to support@creaxor.com, tell us which Company Creator you sign for, and we will ask you for what we need to be satisfied the request comes from you. We will respond within 90 days at the outside, and in practice sooner.

9.8  If you are not satisfied with how we handle your request or your complaint, you may complain to the Data Protection Board of India. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal.

10. Children

10.1  Creaxor is for adults. You must be 18 or over to use it, in any capacity. We do not knowingly collect the personal data of anyone under 18.

10.2  We ask for your date of birth when you register and rely on what you tell us. We do not independently verify it.

10.3  We do not track children, monitor their behaviour, or direct advertising at them.

10.4  If we learn that we hold the personal data of someone under 18, we will erase it and close the account, and we will refund what they paid us. If you believe a child is using the Platform, raise a request through Support in the Platform and we will act.

11. How we protect your data

11.1  Data is encrypted in transit. Secrets are held in a managed vault. Passwords, where we hold them, are stored only as hashes. Aadhaar numbers, and the PANs we hold for Creators and their authorised signatories, are encrypted at rest, though not where a PAN appears inside a GST registration number or in a document we store as a file; a Creator's bank details are not encrypted in that way. Clauses 3.3 and 3.7 set out precisely what is and is not encrypted, and you should read them rather than rely on this summary.

11.2  Administrative access is limited to a small number of staff accounts. Those accounts carry broad access to personal data, and we tell you that rather than imply otherwise.

11.3  We are honest with you about the limits of this: no system connected to the internet can be guaranteed secure. What we can promise is that we take reasonable security safeguards, that Section 12 sets out what we will do if there is a breach, and that we will not pretend otherwise.

11.4  Creators are given a private overlay address for their broadcasting software. Anyone who has that address can see the supporter information it displays, so Creators are asked to keep it private.

12. If there is a data breach

12.1  If a personal data breach occurs we will tell you, without delay, in plain language: what happened, what data was affected, what the likely consequences are, what we have done about it, what you can do to protect yourself, and who to contact. We will do that by email to the address on your account and through the notifications in the Platform.

12.2  We will intimate the Data Protection Board of India without delay on becoming aware of a breach, and will give the Board the detailed particulars the Rules require within 72 hours of becoming aware, or within any longer period the Board allows on request.

12.3  We keep a record of every breach we become aware of, and of the intimations we gave, for the period the law requires.

13. Complaints and grievance redressal

13.1  You can raise a complaint through Support in the Platform, which opens a ticket you can follow and reply to. You may also email support@creaxor.com. You do not need an account to raise a support request. Requests to exercise your rights under Section 9 should be made as described in clause 9.7, because we have to be satisfied that they come from you.

13.2  We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. Requests to exercise your rights under Section 9 are answered within 90 days at the outside.

13.3  If you remain dissatisfied, you may escalate to the Data Protection Board of India.

14. Cookies, analytics and similar technologies

14.1  The Creaxor site does not set any cookies of its own. We keep you signed in using your browser's local storage rather than a cookie.

14.2  We use Microsoft Clarity, a third-party analytics service, on every page of the site. Clarity records how visitors interact with our pages — including clicks, scrolling, mouse movement and snapshots of the page as you saw it — so that we can see where the Platform is confusing or broken. It sets its own cookies in your browser and is provided by Microsoft, who process the data on their own infrastructure.

14.3  Our payment provider also sets its own cookies when the payment sheet is open.

14.4  We do not use cookies to build an advertising profile of you, and we run no advertising, remarketing or cross-site tracking product.

14.5  We store the following in your browser's local storage, which is not a cookie but is personal data: your name, email address, mobile number, profile picture, user identifier and sign-in token. The site and the creator portal also keep there, for each account that signs in on that browser, a note of which versions of this Policy, our User Agreement and our Refund Policy you have already been told about, so that we know which changes still to tell you about (Section 17, and clause 16.1 of our User Agreement).

15. Connected chat accounts

15.1  You can connect a YouTube or a Kick account to Creaxor, so that typing a command in a Creator's live chat does the same thing as pressing the button on our site. Connecting is optional, it is never done for you, and everything else on the Platform works whether you connect or not.

15.2  If you are a Creator, connecting lets us read your live chat. You are sent to the platform's own sign-in screen, and what comes back to us is a permission, not your password — we never see or store your YouTube or Kick password. On YouTube we ask only for read access. What we read is the identifier of the broadcast you are streaming and the messages posted in its live chat while it runs. We do not post, upload, edit, hide or delete anything on your channel, and we do not read your videos, your subscribers, your comments or your analytics. We hold no permission that would let us do any of those things.

15.3  If you are a Supporter, connecting proves that the chat account typing the commands is yours. You name the account on our site, we give you a short code, and you type that code once in the Creator's chat. We then keep the platform's own identifier for that account, and the name it displays under, so that we can recognise what you type later.

15.4  What we keep from a chat message. For each command we act on we record the platform it arrived from, the platform's identifier for the message, the identifier and display name of the account that sent it, the text of the command, and what we did about it. We keep this so that a command is never acted on twice, and so that we can answer a question about a spend afterwards. Where the account that sent a command is not connected to any Creaxor account, we do not keep its identifier or its name in readable form at all — we keep an irreversible fingerprint instead, and the readable values are recorded only if the sender turns out to be a Creaxor user.

15.5  YouTube. Our YouTube features use YouTube API Services. By using them you also agree to the YouTube Terms of Service, which you will find at https://www.youtube.com/t/terms . What Google itself does with your data is described in the Google Privacy Policy, at https://policies.google.com/privacy . Those two documents tell you what Google does; this Section tells you what we do.

15.6  Taking the permission back. A Creator can disconnect a channel at any time from the creator portal until we delist their account (clause 8.7). A delisted Creator's channel stays connected unless they disconnected it before, and the permission can still be withdrawn on Google's or Kick's side as below; we go on receiving that chat, but no command typed in it is acted on. A Supporter can unlink an account at any time on our site, or by typing the unlink command in the chat of a Creator who has switched that command on and is not delisted. When a Creator disconnects a YouTube channel we also tell Google to cancel the permission, so that it ends on both sides rather than only on ours. You never have to rely on us for that: you can withdraw it yourself at any time from your Google account's security settings, at https://security.google.com/settings , and a Kick connection can be withdrawn from Kick's own settings in the same way. Once the permission is gone we can no longer read that chat.

15.7  How long we keep it. Anything we obtain through the YouTube API and hold in readable form — display names, the text of chat messages and the like — is kept for no more than 30 days and is then deleted automatically. The connection between your chat account and your Creaxor account lasts longer, because it is held as the platform's own identifier rather than as anything readable about you, and it is renewed each time you use it. Deleting a Supporter account removes the connection with it, as clause 8.2 describes.

15.8  A command is a public act. Typing a command in a Creator's live chat puts it in front of that Creator's audience, and where the command sends an alert, clause 6.5 applies to it exactly as it would if you had sent the same alert from our site.

16. Messages we send you

16.1  We send you messages necessary to run your account: one-time codes — by SMS when you sign in, and by SMS or email when you register or activate your account, verify your email address or mobile number, or confirm a change to your account; emails about a support request you raise; if you are a Creator, emails about your application, your account and your tax deduction certificates; and, if you still hold a subscription taken out before we stopped offering them, emails about its renewal, its expiry and its automatic payments. These are not marketing, and you will continue to receive them for as long as you have an account. Your receipts and invoices are kept in your account for you to download.

16.2  We do not send marketing or promotional email, and we do not send promotional SMS. We have no mailing list and we do not run campaigns.

16.3  Because everything we send is necessary to the service, there is currently no way to switch these messages off other than by closing your account. If we ever begin sending marketing messages, we will ask for your consent first and give you a way to unsubscribe.

17. Changes to this Policy

17.1  If we change this Policy we will publish the new version here, with the date of the change and the clauses it changed at the top. If you are a Supporter, the next time you sign in to the Platform, or visit it while signed in, after a change, the site shows you a notice that this Policy has been updated, with a link to it, until you open the Policy from that notice or dismiss it. If you are a Creator, the next time you sign in to or visit your creator portal after a change, the portal shows you a notice that this Policy has been updated, with a link to it, until you open the Policy from that notice or dismiss it; and where a change asks something of you, you can do it in your portal at that visit — for example, a verification step on its KYC page. Continuing to use the Platform after a change takes effect means you accept it. If you do not, you may close your account (Section 8).

18. Contact

18.1  Questions about this Policy, or about your personal data: Support in the Platform, or support@creaxor.com.