Skip to content

Privacy notice

Last updated: 15 August 2026

This document is published in German and in English. The German version is the binding one; the English version is a convenience translation and has not been reviewed by a lawyer. Where the two differ, the German version prevails.
Note: this is a careful draft describing the actual data processing at ClipRails, but it is not legal advice and has not yet been reviewed by a lawyer (the review happens before go-live).

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and further national data protection laws, for the processing of personal data on cliprails.com, is:

Antonio HerbinHändelstraße 1212623 BerlinGermany

Email: contact@cliprails.com

There is no statutory obligation to appoint a data protection officer, and none has been appointed. Please address data protection requests to the email address above.

Overview and purpose of this notice

ClipRails runs clipping campaigns: a Creator funds a campaign, and Clippers publish clips on their own social media accounts and are paid for the verified reach those clips earn. This notice describes which personal data we process along the way, for what purpose, on what legal basis, and which service providers receive it. We do not sell data and we do not use it for advertising.

Account and registration

For an account we process your email address, the username you choose and — if you upload one — a profile picture. If you register with a password, we store it exclusively as a cryptographic hash (bcrypt), never in clear text. Your account type (Creator or Clipper) and the campaigns you create or join are part of your account data as well.

Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).

Signing in with Google

You can alternatively sign in through Google (Google login). The login serves authentication only: it requests the standard scopes openid, email and profile, and what we use out of them is your email address, so that we can match it to your account. A name or profile picture from your Google account is not stored in your ClipRails account. The login reaches none of your other Google services. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The login is separate from connecting a YouTube channel, described under “Connected social accounts” below. They are two different consents, granted at two different moments, for two different purposes, and they run through two separate Google projects: signing in never gives us access to your YouTube data, and connecting a channel is not a login. You can grant either without the other.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps and performance) and Art. 6(1)(f) GDPR (secure sign-in).

Payment processing via Stripe

All money flows run through Stripe. That covers two touch-points:

  • Funding. A Creator pays a campaign's budget in via Stripe Checkout.
  • Connect payouts. For payouts to Clippers, Stripe Connect sets up an Express account; the identity and account verification required for it (KYC) is carried out by Stripe under its own responsibility.

Complete payment data (card or bank details, for instance) is collected and processed directly by Stripe; ClipRails does not store it, only references such as Stripe identifiers, amounts and payment status. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Stripe's own privacy notice applies in addition.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal obligations, among them the anti-money-laundering rules behind the KYC check).

Connected social accounts (TikTok, YouTube, Instagram)

When a Clipper connects a TikTok, YouTube or Instagram account, we store its stable account id, the display name, the public profile picture and an access token (plus a refresh token, where the platform issues one). These tokens are stored encrypted (encryption at rest).

On all three platforms the access is read-only and limited to the figures a payout is calculated from. On TikTok we use the scopes user.info.basic and video.list only, to read your display name and your public videos along with their public view counts — so that a submitted clip can be matched to your account and the payout it earned can be calculated.

On YouTube we request the single scope youtube.readonly, and we use it for exactly one call, at the moment you connect: reading the channel that authorised the connection — its channel id, its channel name and its channel picture. That is the whole purpose of the scope, and it is what lets us confirm which channel is yours, so that a clip submitted later can be matched to it. The view counts your payout is calculated from are not read with this authorisation: they come from the public YouTube Data API through an API key, the same data any visitor sees under the video. We hold no YouTube data beyond the three fields named above.

ClipRails uses YouTube API Services for this. The YouTube terms of service and Google's privacy policy apply in addition. You can withdraw the access you granted us at any time in your Google account under Third-party apps with account access, independently of the Disconnect control in ClipRails.

ClipRails' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular we do not use Google user data for advertising, we do not sell it, we do not train generalised AI models with it, we transfer it to no one except as needed to provide or improve the connect described here or where the law obliges us, and no human being reads it — apart from the case where you ask us to, where security demands it, or where we are legally required to.

On Instagram we request exactly two scopes. instagram_business_basic reads the identity of the connected account — its account id, username, display name, account type and profile picture — and the list of your own videos with their caption, thumbnail and publication date, so that you can pick a clip from that list and it can be matched to your account. instagram_business_manage_insights reads the view count of exactly those videos, which is what your payout is calculated from. Both are read-only and reach no further than your own posts. The access token that carries them is stored encrypted like every other (encryption at rest). The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland.

Instagram releases view counts for professional accounts only (Business or Creator). That is why the account type is among the fields we read when you connect: a personal account cannot be connected, and you are told so at that moment instead of finding out weeks later, through a clip that never earned anything.

On none of the three platforms do we post, comment or change anything, and we request no access to private data. You can disconnect a connected account at any time; disconnecting ends any future access, and what it removes is described under “Deleting your data” below.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

In-app notifications

Inside the application we show you notifications about events concerning your account — submitted clips, payouts or campaign status, for instance. These notifications are stored in our database and displayed in the app.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in a working platform).

Hosting, infrastructure and processors

We use service providers that process personal data on our behalf and on our instructions (processing under Art. 28 GDPR):

  • Vercel Inc. — hosting and operation of the application.
  • Supabase — managed PostgreSQL database; the data is held in an EU region (Frankfurt, eu-central-1).
  • Inngest — background and event processing (verifying reach and triggering payouts, for instance).
  • Vercel Blob — image storage: uploaded profile and community pictures, plus the profile pictures (avatars) mirrored from a social account when it is connected.

Where a service provider processes data outside the EU/EEA, or where a US provider is involved, we base the transfer on appropriate safeguards within the meaning of Art. 46 GDPR (in particular the European Commission's standard contractual clauses).

Recipients — who sees what

A Creator whose campaign you supply as a Clipper sees your submissions to that campaign: your connected account handle, the submitted clip and its verified reach. Beyond that we pass your data only to the processors named above and to Stripe for payment processing. There is no other disclosure unless we are legally obliged to make one.

How we protect this data

The measures below are the ones that actually run, not a list of intentions:

  • In transit. The whole site and every call to a platform API runs over TLS (HTTPS). There is no unencrypted route.
  • At rest. The access and refresh tokens of connected accounts are encrypted with AES-256-GCM before they ever reach the database, each with its own random nonce; the key lives outside the database, so a copy of the database alone yields no usable token. Passwords are only ever stored as a bcrypt hash. The database itself is a managed Postgres in the EU region (Frankfurt).
  • Access. Access to production data is limited to the controller named at the top. Tokens are never shown in the interface and never written to logs; they are decrypted only for the moment a call to the platform needs them.
  • Deletion. Disconnecting a connected account wipes its access token, refresh token and expiry from the database on the spot — not a flag, the values themselves. From that moment we can no longer call the platform on your behalf. What that leaves standing, and how to have the rest deleted, is the section right after this one.

Deleting your data

This section says how to have the data of a connected social account, or your whole ClipRails account, deleted — and what a deletion does not reach, so that nothing here promises more than actually happens.

Disconnecting a social account. Every connected account carries a Disconnect control under “Connected accounts” in ClipRails. It takes effect on the spot: the account's access token, refresh token and expiry are removed from the database — the values themselves, not a flag — and the account leaves your list. From that moment we make no further call to the platform in your name. On TikTok and Instagram that ends the reading of your clips' reach as well, because it runs on that authorisation; a YouTube clip's view count comes from the public API described above and is unaffected by it.

Withdrawing the authorisation on the platform itself. This works independently of the control above, and it works whether or not you still have a ClipRails account: on Instagram under Apps and websites, on YouTube under Third-party apps with account access in your Google account, and on TikTok in the app settings under “Security and permissions”. The authorisation ends either way, and the token stored here opens nothing from that moment on; on TikTok and Instagram the next read marks the account here as needing a reconnect. Use the Disconnect control as well if you want the stored value itself gone from the database.

Deleting your whole account — as a Clipper, in the app. Your settings carry a Delete account control (avatar menu → Settings, under Close account). It takes effect on the spot and cannot be undone: your email address, your username and an uploaded profile picture are erased, the picture file included, and the credentials of every social account you had connected are removed with them. You are signed out on every device, your old username and your old address are free again the same moment, and you can register anew under that address whenever you like. What is not erased is two paragraphs down.

Deleting a Creator account, and everything the app does not reach. A Creator account owns a whole Community — members, a public address, campaigns, possibly money still held in escrow — so it is closed with us rather than by a button: a message to contact@cliprails.com from the address the account is registered under is enough, no form is needed, and we act on it within the month Art. 12(3) GDPR allows. The same address is the way to anything left open after a Clipper deletion.

A payout still owed to you survives the deletion. We do not make erasure conditional on anything — Art. 17 GDPR gives you the right without conditions we get to set — and we take no waiver of money already earned. The claim therefore stays, and the app names the amount before the last click. What changes is only how you reach it: after the deletion there is no account to log into, so it runs through contact@cliprails.com.

Your Stripe payout account is not deleted with it. Where you completed the payout onboarding, the connected account you opened stays with Stripe: Stripe is a controller in its own right for it, with retention duties of its own under payment and money-laundering law, and we cannot erase it on your behalf. Their privacy notice and the way to reach them are linked under “Recipients” above.

What a deletion does not reach. Submissions, the reach recorded for them and the payouts made from them stay. They are the accounting behind money that has already moved: a Creator paid for that reach, a Clipper was paid for it, and a dispute about either can only be settled on those rows. They are therefore exempt from erasure for as long as the statutory retention periods run (Art. 17(3) GDPR, together with the tax and commercial retention duties under “Retention” below). Of the connected account itself what stays is its account id, its display name and the profile picture mirrored when it was connected — the row the submissions hang from. No token stays: those went with the disconnect. None of it carries your name any more: wherever your username stood, leaderboards and lists read “Deleted account”.

Retention

We keep account data for as long as your account exists. Recorded reach snapshots are kept as an audit trail for any payout disputes. Payment and accounting data is subject to the statutory retention periods (in particular under tax and commercial law, as a rule six to ten years). Once the respective purpose and any such period has passed, the data is deleted or anonymised.

Your rights

Under the GDPR you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on a legitimate interest (Art. 21). Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3)).

A message to contact@cliprails.com is enough to exercise them. Independently of that, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent one is the authority at the controller's seat: Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Changes to this notice

We update this privacy notice when the processing or the service providers we use change. The version published here is the one that applies; the date under “Last updated” at the top shows the most recent change.