clipbeep Privacy Policy

Version 1.0 draft. 30 August 2026. Pending legal review. The wording may still change on legal review; the commitments about your money will not get worse retroactively.

1. Who we are

In plain words: we are an EU company, we are the controller of the data described here, and you can reach a human at hello@clipbeep.com.

1.1 clipbeep is operated by Everlancer OÜ, a European Union company registered in Estonia (registry code 17590253, Narva mnt 5, 10117 Tallinn) ("clipbeep", "we", "us"). We are the data controller for the processing described in this policy, unless a section says otherwise.

1.2 Contact us about anything in this policy at hello@clipbeep.com. We answer privacy requests within one month, and we will tell you if we need to extend that under Article 12(3) GDPR.

1.3 We have not appointed a Data Protection Officer. We will appoint one if our processing reaches the threshold in Article 37 GDPR, and we will name them here when we do.

2. Who this policy covers

In plain words: four different groups of people, with genuinely different data.

2.1 Clippers. Creators with a clipbeep account who join campaigns, post clips, and get paid.

2.2 Brands. Companies that fund campaigns, and the individual people at those companies who use the cockpit. A company is not a person, so this policy applies to the humans behind the account, not to the company itself.

2.3 Waitlist visitors. People who ask for early access from our website but do not yet have an account.

2.4 People who click a tracked link. Viewers who tap a clipper's link and land on a brand's product page. We deliberately hold very little about you, and section 6 says exactly what.

3. What we collect from clippers, and why

In plain words: enough to run your account, pay you, verify results, stop fraud, and meet tax law. Not more.

What Why Legal basis
Email, password credentials, account settings Create and secure your account Contract, Art. 6(1)(b)
Display name, avatar, bio, country Your profile and campaign eligibility Contract, Art. 6(1)(b)
Social handles and links to the posts you submit Attributing results to you and verifying posts Contract, Art. 6(1)(b)
Public post metrics we fetch from platform APIs (views, publish date) Paying view-based rates on verified numbers only Contract, Art. 6(1)(b)
Tracked links you mint, clicks on them, sales attributed to them Working out what you earned Contract, Art. 6(1)(b)
Ledger: accruals, platform fee, payouts, reversals, holds Paying you, and keeping the books Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) for the accounting record
Payout account identifiers held by our payout partner Sending you money Contract, Art. 6(1)(b)
Legal name, date of birth, address, tax residence, tax identification number EU platform tax reporting, see section 11 Legal obligation, Art. 6(1)(c)
Fraud signals: device and network patterns, click patterns, duplicate detection, refund and chargeback rates Keeping the marketplace honest and paying the right people Legitimate interests, Art. 6(1)(f)
Support messages and dispute correspondence Answering you and keeping a record of what was decided Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)
Your handle shown next to amounts on the public ledger Public transparency, see section 7 Consent, Art. 6(1)(a), and only if you switch it on

3.2 Our legitimate interests, where cited above, are running an honest marketplace, preventing fraud against brands and against other clippers, securing the service, and defending legal claims. You can object to processing based on legitimate interests under section 16.

4. What we collect from brands

In plain words: company details for the contract and the invoice, and the details of the people who log in.

4.1 Company name, registration number, VAT number, billing address, and the details on your deposits and invoices. Company data is not personal data, but the natural person behind a sole trader is covered here too.

4.2 For each user of the cockpit: name, work email, role, and login and security data. Legal basis: contract, Article 6(1)(b), and our legitimate interest in securing the account.

4.3 Campaign configuration, spend, and results. Where these contain personal data they are covered by section 3 and section 7.

4.4 Correspondence, onboarding calls, and the anti-money-laundering and sanctions screening we and our payment partners run. Legal basis: legal obligation, Article 6(1)(c), and legitimate interests.

5. What we collect from waitlist visitors

In plain words: your email, which side you are on, what you build, and where. That is the whole list.

5.1 We collect: email address, whether you are a clipper or a brand, your product segment (app, game, music, info product, DTC), and your country.

5.2 We use it to: confirm your request, contact you about early access, and size demand by segment.

5.3 Legal basis: your request to take steps before entering a contract, Article 6(1)(b), and our legitimate interest in measuring demand, Article 6(1)(f). Where we send you general marketing rather than a response to your request, we rely on consent, Article 6(1)(a), and every such email has a one-click unsubscribe.

5.4 If you never take up early access, we delete your waitlist record after 24 months, or sooner if you ask.

6. What we collect about people who click a tracked link

In plain words: we do not store your IP address. We store a daily one-way hash and the country your request came from.

6.1 When someone taps a clipbeep tracked link, we record: the campaign, the clipper's post link, a timestamp, the country supplied by our content delivery network, and a value we call fp_hash.

6.2 fp_hash is a SHA-256 hash of the IP address, the browser user agent string, and the calendar date, computed at the moment of the request. The raw IP address is not written to our database. Because the date is part of the input, the hash changes every day and cannot be used to follow a person over time.

6.3 We use this to count clicks once, to attribute a sale to the right clipper, and to detect click farms and duplicate traffic. Legal basis: legitimate interests, Article 6(1)(f), in measuring a transaction we are contractually required to measure and in preventing fraud.

6.4 We do not set cookies on the redirect, do not read anything from your device, and do not build an advertising profile. The redirect only sends you to the brand's page. What the brand's own site then does is covered by the brand's privacy policy, not ours.

6.5 We treat fp_hash as pseudonymised personal data, not as anonymous data, because it is derived from personal data. We hold click records for 24 months, then delete or aggregate them.

7. The public ledger

In plain words: campaign totals and brand money are public. Your handle next to your earnings is public only if you turn it on, and one click turns it off again, including for the past.

7.1 Public transparency is the point of clipbeep, and we built it so that it does not require publishing anyone's income.

7.2 Published by default:

(a) campaign-level and platform-level aggregates, for example "this campaign paid out $33,880 across 41 clippers";

(b) a brand's money movement: deposits, spend, platform fee, refunds. Brands are companies, and this is company financial activity;

(c) campaign rates, caps, attribution windows, and non-monetary metrics.

Legal basis: legitimate interests, Article 6(1)(f), in a transparent marketplace. Aggregates are published at a level that does not identify an individual clipper.

7.3 Published only with your separate consent: your handle, or anything else that identifies you, shown next to an amount you earned.

(a) This is controlled by a separate toggle in your profile. It is not ticked by default, it is not part of accepting the Terms of Service, and joining a campaign does not switch it on.

(b) Nothing about your access, your rates, or your standing changes if you leave it off.

(c) Legal basis: consent, Article 6(1)(a).

7.4 Withdrawing consent. One click, in your profile, at any time. We apply it within 24 hours, and it hides past entries as well as future ones. There are two levels of control: a per-entry setting, and a master switch that hides your handle everywhere at once.

7.5 Withdrawing consent does not make earlier publication unlawful, and it does not delete the financial record behind the entry. See sections 12 and 13.

7.6 We do not publish a clipper's balance, payout history, tax data, email, or country.

8. Cookies and analytics

In plain words: a session cookie so you stay logged in, and privacy-friendly analytics that do not identify you.

8.1 Strictly necessary cookies: your login session and security tokens. These are required for the service to work and do not need consent.

8.2 Analytics: we use Vercel Web Analytics, which is cookieless and does not build a cross-site profile of visitors. It gives us page counts and referrers.

8.3 We do not run advertising trackers, do not sell data to data brokers, and do not embed third-party ad pixels on our own site.

8.4 If we ever add analytics or marketing tools that require consent, we will ask for it with a banner that makes declining as easy as accepting, and this section will be updated first.

9. Who we share data with

In plain words: the vendors that make the product work, the brand whose campaign you joined, and authorities when the law requires it. Nobody else.

9.1 Service providers (processors) acting on our instructions:

Provider What they process Where
Vercel Inc. Hosting, content delivery, web analytics EU and US
Supabase Database, authentication EU (Frankfurt region)
Payoneer Clipper payouts, identity verification, sanctions screening Global
Solidgate Brand card payments EU
Resend Transactional email EU and US
Social platform APIs (YouTube, and others as we integrate them) Fetching public metrics for posts you submitted Global

Each of these is bound by a data processing agreement under Article 28 GDPR.

9.2 Brands. A brand whose campaign you joined sees your handle, the posts you submitted to that campaign, the links you minted, and the results attributed to them. Section 10 explains our respective roles.

9.3 Authorities. Tax authorities under section 11, and courts, regulators, or law enforcement where we are legally required to respond. We push back on requests that are overbroad, and we tell you unless we are prohibited from doing so.

9.4 A successor. If our business is sold or merged, data moves with it, and we will tell you before it does.

9.5 We do not sell personal data. There is no version of this business where we do.

10. Roles between clipbeep and brands

In plain words: we each answer for the data we hold. A brand does not get to reuse your data for anything beyond the campaign.

10.1 clipbeep is the controller of the data described in sections 3 to 8.

10.2 When a brand receives clipper data from us, the brand acts as an independent controller for its own purposes. We are not joint controllers, and neither of us processes on the other's instructions.

10.3 Our Terms of Service for Brands contractually restrict what a brand may do with clipper data: use it only for running and evaluating the campaign it came from, never sell it, never add it to a marketing list, never use it to train a model, never combine it with other sources to build a profile, and never attempt to re-identify individual earnings from aggregates.

10.4 Where a brand sends us its own customers' data (for example in a sale postback), we act as the brand's processor for that narrow flow, under a data processing agreement.

10.5 A brand's own use of your data is governed by the brand's privacy policy. If a brand misuses data it received through clipbeep, tell us at hello@clipbeep.com and we will act on it under our Terms of Service for Brands.

11. Tax reporting (DAC7)

In plain words: EU law makes us collect and report what clippers earn. This is a legal obligation, not something you can opt out of, and it is not based on consent.

11.1 As a platform operator that intermediates services for consideration, we are required to collect, verify, and report seller information under EU Council Directive 2021/514 ("DAC7") and the Estonian rules implementing it.

11.2 We report, annually, to the Estonian Tax and Customs Board: your identifying and tax details from section 3, the total amounts paid to you, and the number of transactions. That authority may share the report with the tax authority of the country where you are resident.

11.3 Legal basis: legal obligation, Article 6(1)(c). We cannot delete this data on request while the obligation and its retention period run.

11.4 We may suspend payouts, but not accruals, until the required information is provided.

12. How long we keep things

In plain words: accounting records for seven years because Estonian law says so. Everything else for as long as it is useful, then gone.

Data Kept for
Accounting and transaction records: accruals, payouts, invoices, deposits, platform fee 7 years from the end of the financial year, under the Estonian Accounting Act
Tax identification data collected for DAC7 The period required by the DAC7 rules, at least as long as the report it supports
Account profile and campaign participation While your account is open, then 12 months, unless a longer accounting period above applies
Click records and fp_hash 24 months, then deleted or aggregated
Fraud investigation records and decisions 3 years from the decision, to defend claims and to spot repeat patterns
Support and dispute correspondence 3 years from the last message
Waitlist records 24 months, or until you ask us to delete them
Public ledger entries you consented to publish Hidden within 24 hours of withdrawal; the underlying accounting record stays for its own period
Backups Rolling, overwritten within 90 days

13. Deletion, and why the ledger stays

In plain words: we will erase you from the product. We cannot erase the accounting record, and we will tell you honestly which is which.

13.1 Ask us to delete your account and we will: close it, remove your profile, your avatar, your bio, your social handles, and your support history from the live product; and hide any public ledger entries carrying your handle within 24 hours.

13.2 What survives, and why:

(a) the financial record of what was earned, paid, reversed, and charged as fee. We are required to keep it under the Estonian Accounting Act and tax law. Article 17(3)(b) GDPR provides the exception to erasure for a legal obligation;

(b) DAC7 records, for the same reason;

(c) fraud records, where we need them to establish, exercise, or defend legal claims, Article 17(3)(e) GDPR;

(d) an entry on a suppression list so we do not email you again by accident.

13.3 What survives is a financial record, not a public profile. After deletion, the surviving record is not shown publicly, is not linked to your handle in the product, and is used only for accounting, tax, and the defence of claims.

13.4 A negative balance or an open dispute pauses deletion of the records it relates to until it is resolved.

14. Where your data goes

In plain words: mostly the EU. Where a vendor is outside it, there is a legal transfer mechanism, and we will name it.

14.1 Our database sits in the EU. Some providers in section 9 process data in the United States or globally.

14.2 For those transfers we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on Standard Contractual Clauses together with a transfer impact assessment.

14.3 Ask us at hello@clipbeep.com and we will tell you which mechanism covers which provider.

15. Automated processing, and where a human steps in

In plain words: software flags suspicious activity. A person decides before anything is restricted, and you can always ask for that person.

15.1 We use automated signals to detect fraud: duplicate clicks, implausible traffic patterns, device and network repetition, refund and chargeback rates, and view velocity.

15.2 A flag from those signals is not a decision. Before we restrict an account, void an accrual for fraud, or place a hold, a person at clipbeep reviews the case and signs off, and you get a written statement of reasons under the Terms of Service.

15.3 You can ask for human review, put your side of it, and contest the outcome, at hello@clipbeep.com. Section 15 of the clipper terms and section 14 of the brand terms set the timescales.

15.4 We do not use your data for automated profiling for advertising, and we do not sell scores about you.

16. Your rights

In plain words: access, correct, delete, port, object, complain. No fee, no hoops.

16.1 You can ask us to:

(a) give you a copy of the personal data we hold about you (Article 15);

(b) correct anything wrong (Article 16);

(c) delete your data, subject to section 13 (Article 17);

(d) restrict processing while a dispute about accuracy or legitimate interests is resolved (Article 18);

(e) port the data you gave us, in a machine-readable format (Article 20);

(f) object to processing based on our legitimate interests, including profiling, on grounds relating to your situation (Article 21). We will stop unless we have compelling grounds that override yours, or we need it for legal claims;

(g) withdraw consent at any time where consent is the basis, including the public ledger toggle. Withdrawal does not affect processing already carried out.

16.2 Write to hello@clipbeep.com. We answer within one month, free of charge. We may ask you to confirm your identity, and we will not use that verification data for anything else.

16.3 Complaints. If you think we have handled your data wrongly, tell us first, and we would genuinely rather fix it than argue. You also have the right to complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee), or to the supervisory authority in the EU country where you live or work.

17. Security

In plain words: least privilege, encryption, no raw IPs, and honesty if something goes wrong.

17.1 Data is encrypted in transit and at rest. Access to production data is limited to the people who need it, behind multi-factor authentication, and access is logged.

17.2 Row-level security is enforced in the database, so one account cannot read another's data even through a bug in the application layer.

17.3 We deliberately do not store raw IP addresses of link clicks (section 6), we store money as integer cents, and we make webhook handling idempotent so a replayed message cannot duplicate a financial record.

17.4 If a personal data breach is likely to result in a risk to you, we notify the Estonian Data Protection Inspectorate within 72 hours and tell you without undue delay where the risk is high. We will describe what happened plainly rather than in press-release language.

18. Children

18.1 clipbeep is for people aged 18 and over. We do not knowingly collect data from anyone younger. If we learn that an account belongs to someone under 18 we close it and delete the data, keeping only what the law requires us to keep.

18.2 If you believe a minor has an account, write to hello@clipbeep.com.

19. Changes to this policy

19.1 We give at least 15 days' notice by email and in-product before a material change to this policy takes effect. The version number and date at the top always tell you which version you are reading.

19.2 A change to the legal basis or purpose of processing that needs your consent will be asked for separately, not assumed from continued use.


Everlancer OÜ, a European Union company (Estonia) Registry code 17590253 Address Narva mnt 5, 10117 Tallinn, Estonia Contact hello@clipbeep.com

Version 1.0 draft, 30 August 2026, pending legal review.

Questions about these documents: hello@clipbeep.com. Payout numbers we already commit to live on the payout policy page.