Privacy Policy

Effective date: 31 July 2026  ·  Last updated: 31 July 2026

English Deutsch

This Privacy Policy explains how BookInfluencers ("we", "us", "our") processes personal data when you use our iOS app, our website at bookinfluencers.app and related services (together, the "Services").

We are based in Germany. Processing is governed by the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Digital Services Data Protection Act (TDDDG). This policy also satisfies the disclosure requirements of Meta, Google/YouTube, TikTok and the Apple App Store.

The short version.

We process what is needed to run a booking marketplace: your profile, your bookings, your messages and the payment data required to pay you. We do not run advertising or tracking. Our app contains no advertising SDK, no analytics SDK and no crash-reporting SDK. We do not use the advertising identifier (IDFA), we do not track you across apps or websites, and we do not sell your data. Our website sets no analytics or advertising cookies.

1. Controller and Contact

The controller responsible for the processing described here (Art. 4(7) GDPR) is:

[Legal name and legal form]
[Street and number]
[Postal code and city], Germany
Represented by: [Managing director / owner]
Email: info@bookinfluencers.app

Data protection officer: [We have not appointed a data protection officer because the statutory thresholds of Art. 37 GDPR / § 38 BDSG are not met. / Our data protection officer can be reached at …]

For any request concerning your data — access, rectification, erasure, restriction, portability, objection or withdrawal of consent — write to info@bookinfluencers.app. We respond within one month (Art. 12(3) GDPR); where a request is complex we may extend this by two further months and will tell you.

2. Who Is Responsible for What

BookInfluencers is a marketplace. That has a consequence for data protection that is easy to miss:

We are not joint controllers with brands or creators, and we do not act as their processor.

3. What We Process, Why, and on What Legal Basis

The table below lists every category of personal data we process, why we process it, and the legal basis under Art. 6(1) GDPR.

DataPurposeLegal basis
Account data — email address, password (stored only as a salted hash), user ID, role (brand or creator), login timestamps; with Sign in with Apple, the Apple user ID and, where applicable, the anonymised relay address Creating and securing your account, authentication, support Art. 6(1)(b) — performance of the platform contract
Profile data — display name, profile picture, bio, niches, languages, location, prices, availability, ratings and reviews Displaying your profile, discovery and matching by brands Art. 6(1)(b)
Brand data — company name, website, industry, description, logo, budget range, billing details Brand profile, bookings, invoicing Art. 6(1)(b); invoicing also Art. 6(1)(c)
Social account data — platform user ID, username, follower and subscriber counts, average views, likes, comments, shares, story views, reach, watch time, engagement rate, plus the OAuth access and refresh tokens Verifying your reach, populating your creator profile, verifying views in Reach Packages Art. 6(1)(a) — your consent when connecting the account; you can withdraw it at any time by disconnecting
Booking data — campaigns, briefs, packages, deliverables, deadlines, submitted content and screenshots, approvals, statuses, disputes Processing bookings between brands and creators Art. 6(1)(b)
Messages — content and metadata of in-app chats Communication about a booking; retained as evidence for disputes and for platform safety Art. 6(1)(b); retention as evidence Art. 6(1)(f) — our legitimate interest in resolving disputes and preventing abuse
Payment data — Stripe customer and Connect account ID, transaction IDs, amounts, fees, payment status, wallet entries, invoices and credit notes. We never receive or store full card numbers Processing payments and payouts, fee settlement, accounting Art. 6(1)(b); retention of accounting records Art. 6(1)(c)
Tax data — legal name, date of birth, tax identification number, tax country, residential address, annual payout totals Reporting obligations for platform operators (PStTG, implementing EU Directive DAC7) towards the German Federal Central Tax Office (BZSt) Art. 6(1)(c) — legal obligation
Push tokens — Apple device token, platform, language preference Sending notifications about bookings, messages and payouts Art. 6(1)(b); the notification permission on your device is granted by you and can be revoked in iOS settings at any time
Consent records — which version of the terms, privacy policy and age confirmation you accepted, and when Proof of consent and of contract formation Art. 6(1)(c) in conjunction with Art. 7(1) GDPR; Art. 6(1)(f)
Safety data — reports you submit, users you block, warnings, restrictions, records of violations Protecting users, moderating content, enforcing the terms Art. 6(1)(f) — legitimate interest in a safe platform; Art. 6(1)(c) where we are legally obliged to act
Verification and fraud data — view snapshots over time, anomaly markers and reasons, duplicate-participation checks Verifying delivered reach, detecting manipulated or purchased reach Art. 6(1)(b) and Art. 6(1)(f) — legitimate interest in fraud prevention (see Section 11)
Technical log data — IP address, timestamp, requested resource, error and access logs of our servers, app version, device model and operating system version where transmitted for error diagnosis Operating, securing and stabilising the Services, defending against attacks Art. 6(1)(f) — legitimate interest in security and availability

Where we rely on legitimate interests (Art. 6(1)(f)), we have weighed those interests against your rights. You may object at any time under Art. 21 GDPR (see Section 16).

Providing data. Account, profile and booking data are necessary to use the Services; without them a contract cannot be performed. Tax data is required by law before a payout can be reported. Connecting a social account is voluntary — without it, verified reach metrics and Reach Packages are unavailable.

4. What We Deliberately Do Not Do

Because this is unusual for an app in this category, we state it explicitly. We verified the following against the app's source code and its Apple privacy manifest:

5. Data from Linked Social Accounts

Social APIs

Connecting a social account is voluntary and always requires your explicit consent through the provider's own OAuth screen. We store the access and refresh tokens issued to us — they are readable only by our backend service role, never by other users — and we use them solely to retrieve the metrics listed in Section 3.

Withdrawing consent. You can disconnect a social account in the app at any time, and you can additionally revoke our access in the provider's own settings (links in Sections 6–8). Upon disconnection we delete the stored tokens and the metrics retrieved from that account, unless we are required to keep specific figures as evidence for a booking that has already been paid (see Section 15).

Where we obtain data about you from a social network rather than from you directly, we do so on the basis of your consent, and Art. 14 GDPR applies — the categories and sources are those set out in Sections 6 to 8.

6. Meta Platform API (Facebook & Instagram)

Meta Platform

Our Services integrate Meta's APIs, which may include the Instagram Graph API, Instagram Basic Display API and Facebook Login. By connecting your Instagram or Facebook account you also agree to Meta's Platform Terms and Meta's Privacy Policy.

Data we receive from Meta

How we use Meta data

Important: We do not sell, license or share Meta-sourced data with third parties for advertising or for any purpose beyond operating the BookInfluencers platform. We store only the minimum necessary and delete it when you disconnect your Meta account or close your account.

You can revoke our access at any time in your Facebook App Settings or Instagram Account Access.

7. Google API Services (YouTube)

Google / YouTube

BookInfluencers uses the YouTube Data API v3 so that users can connect their YouTube channel and display performance data within the platform.

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

YouTube API Services: This application uses YouTube API Services. By connecting your YouTube account you agree to be bound by the YouTube Terms of Service and Google's Privacy Policy. You can revoke our access at any time through Google's Security Settings.

Data we receive from YouTube / Google

We store YouTube data only for as long as your account is connected and your account is active, and we do not use it for advertising or share it with unauthorised third parties.

8. TikTok API

TikTok

We integrate the TikTok API (TikTok Login Kit and/or Display API) so that users can link their TikTok account and show their creator metrics. Your use of TikTok features is subject to TikTok's Privacy Policy and TikTok's Terms of Service.

Data we receive from TikTok

You can revoke our access at any time in TikTok's privacy settings under "Manage app permissions".

9. Payments and Stripe

Stripe

All payments and payouts are processed by Stripe Payments Europe, Ltd. (Ireland) and its affiliates. Payments from brands are routed directly to the creator's Stripe Connect account; we do not hold funds.

We never see your card details.

Card numbers, CVC and bank credentials are entered inside Stripe's own components and transmitted directly to Stripe. They never reach our servers. What we store is the Stripe customer or Connect account ID, transaction IDs, amounts, fees and payment status.

To receive payouts, creators must complete Stripe's identity verification (KYC). Stripe collects the identity documents and personal data required for this as its own controller under anti-money-laundering law; we receive only the verification status, not the documents. Stripe's processing is described in Stripe's Privacy Policy.

Legal basis: Art. 6(1)(b) for processing your bookings, Art. 6(1)(c) for accounting and anti-money-laundering obligations, and Art. 6(1)(f) for preventing payment fraud and chargeback abuse.

10. AI-Supported Matching

Anthropic · Claude

When a brand uses the optional "AI match" feature, we send the brand's campaign brief together with a shortlist of candidate creator profiles to the Claude API operated by Anthropic PBC (United States), which returns a suitability score and a short justification for each candidate.

What is transmitted

No email addresses, contact details, payment data, tax data, messages or social media tokens are transmitted. The data sent is limited to what is already visible to brands on the public creator profile.

Legal basis: Art. 6(1)(f) — our legitimate interest, and that of both sides of the marketplace, in relevant matches. You can object to this processing under Art. 21 GDPR at info@bookinfluencers.app; we will then exclude your profile from AI matching. Your profile remains findable through the ordinary search and filter functions.

Anthropic acts as our processor under Art. 28 GDPR on the basis of a data processing agreement; the transfer to the United States is covered by the European Commission's Standard Contractual Clauses (see Section 14). The AI result is a ranking suggestion for the brand — it does not decide anything about you; the brand decides who to contact (see Section 11).

11. Automated Decisions, Profiling and Fraud Detection

We are transparent about the three places where the platform evaluates data automatically. Under Art. 22 GDPR you have the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects you.

11.1 Fraud detection in Reach Packages

To ensure that only genuinely delivered reach is paid for, we automatically compare the view figures retrieved from the social networks against your own historical averages and against the plausibility of the growth curve. Concretely, a participation is marked as conspicuous if the views are implausibly high compared with your average, if the growth within a short period is unnaturally steep, or if the engagement rate is implausibly low relative to the views.

Consequence: the participation receives the status fraud_flagged and the payment is withheld pending review. This automatic marking is not a final decision. No payment is permanently refused without a human review. If your participation is flagged, you can contact us at info@bookinfluencers.app at any time and are entitled to human intervention, to state your position and to contest the decision (Art. 22(3) GDPR). Legal basis: Art. 6(1)(b) and Art. 6(1)(f) — our legitimate interest and that of the paying brands in preventing fraud.

11.2 Contact-detail scanning in messages

Before a message is sent, the app checks the text against fixed patterns for email addresses, phone numbers and messenger handles, and warns you or redacts the details. This is a pattern check on your device — no AI is used, and messages are not analysed for content beyond these patterns. Purpose: preventing circumvention of the platform and protecting users from being moved into unprotected side channels. Legal basis: Art. 6(1)(f) and Art. 6(1)(b).

11.3 Matching scores

The scores described in Section 10 and the sorting in search results rank profiles. They are decision aids for brands and produce no automated legal effect for you — a brand always decides for itself whom to book.

11.4 Restrictions and account closures

Warnings, restrictions and account closures are always decided by a person, not automatically. You will be given the essential reasons and can object (Section 11 of our Terms of Service).

12. Apple, App Store and Push Notifications

Apple App Store

Our app is distributed through the Apple App Store. Downloading it involves a relationship between you and Apple; Apple processes your Apple Account data as its own controller. We receive no personal data from Apple in connection with the download, only aggregated, non-personal statistics.

Sign in with Apple

If you register with Sign in with Apple, we receive a pseudonymous Apple user ID and, depending on your choice, either your email address or an anonymised Apple relay address. Apple provides your name only once, at first sign-in, which is why we store it at that moment. Legal basis: Art. 6(1)(b).

Push notifications

Notifications are delivered via the Apple Push Notification service (APNs). We transmit your device token and the notification text (e.g. "New message about your campaign") to Apple. Notifications are limited to events relating to your bookings, messages and payouts — we do not send advertising push messages. You can revoke the permission at any time in the iOS settings.

App Store privacy label

The data categories declared for the App Store correspond to the app's privacy manifest: contact info (name, email), identifiers (user ID), user content (photos, campaign content, messages), payment information and other financial information — all linked to your account, all used solely for app functionality, and none of it used for tracking.

In-app purchases

If paid features are offered, they are processed exclusively through Apple's payment system. We receive no Apple Account credentials and no payment card details, only the status of your purchase.

13. Recipients and Processors

We use carefully selected service providers, each bound by a data processing agreement under Art. 28 GDPR where they act on our behalf:

RecipientPurposeRole / location
Supabase (Supabase, Inc. / Supabase Pte. Ltd.) Database, authentication, file storage, backend functions — our core hosting Processor · servers in [EU region — please confirm in the Supabase dashboard]
Stripe (Stripe Payments Europe, Ltd., Ireland) Payments, payouts, KYC identity verification Own controller for payment services and KYC; EU/US
Apple (Apple Distribution International Ltd., Ireland) App distribution, Sign in with Apple, push notifications, in-app purchases Own controller; EU/US
Anthropic (Anthropic PBC, USA) AI matching (Section 10) Processor; USA — Standard Contractual Clauses
Meta, Google/YouTube, TikTok Retrieving the metrics you release (Sections 6–8) Own controllers; EU/US
Google (Firebase Hosting) Delivering our website Processor; EU/US
German Federal Central Tax Office (BZSt) Statutory platform operator reporting (PStTG / DAC7) Public authority; Germany
Tax advisors, auditors, lawyers, courts and authorities Accounting, legal defence, statutory obligations Own controllers; Germany/EU

In addition, other users receive the data that the platform inherently makes visible: brands see creator profiles and metrics, creators see brand profiles and briefs, and both sides see the messages and booking data of their shared campaign. Reviews you write are visible to other users.

14. International Transfers

We aim to keep processing within the EU. Where data is transferred to a third country — in particular to the United States (Anthropic, and the US parent companies of Stripe, Apple, Google, Meta and TikTok) — we ensure an adequate level of protection through:

You can request a copy of the safeguards in place at info@bookinfluencers.app.

15. Retention, Deletion and Anonymisation

DataRetained
Account and profile dataFor as long as your account exists; then deleted or anonymised (see below)
Social account tokens and metricsDeleted when you disconnect the account or close your account
Messages and booking dataUntil the booking is complete, then up to 3 years (statutory limitation period, § 195 BGB) for evidence in disputes
Invoices, credit notes, payment and tax records10 years — mandatory retention under § 147 AO and § 257 HGB
Consent recordsFor the duration of the account plus the limitation period, as proof under Art. 7(1) GDPR
Reports, blocks, records of violationsUp to 3 years, to detect repeated violations
Technical log dataAs a rule 30 days, longer only for a specific security incident
How account deletion actually works.

You can delete your account in the app at any time. What happens then depends on whether financial records exist:

This is the restriction of processing provided for in Art. 17(3)(b) GDPR — the right to erasure does not apply where processing is necessary to comply with a legal obligation.

Please note: content you have published (e.g. campaign posts on your own channels) and data that other users have received are not affected by our deletion — those users are their own controllers (Section 2).

16. Your Rights

You have the following rights in relation to your personal data:

Your right to object (Art. 21 GDPR).

You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f). This applies in particular to AI matching (Section 10) and to the use of your data for platform security purposes. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves the establishment, exercise or defence of legal claims. We do not use your data for direct marketing, so no unconditional right to object arises in that regard.

To exercise your rights, write to info@bookinfluencers.app. So that we do not disclose data to the wrong person, we may need to verify your identity.

Right to lodge a complaint. You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or of the alleged infringement (Art. 77 GDPR). The authority competent for us is: [Competent supervisory authority of the federal state in which the company has its seat].

17. Security

We take technical and organisational measures appropriate to the risk, in particular:

No transmission over the internet can be made completely secure. If a personal data breach is likely to result in a high risk to your rights, we will notify you without undue delay (Art. 34 GDPR) and report it to the supervisory authority within 72 hours (Art. 33 GDPR).

18. Cookies, Local Storage and § 25 TDDDG

Website. Our website is a static presentation page. It sets no analytics or advertising cookies, and there is no tracking pixel and no consent banner because none is needed. Fonts are loaded from Google Fonts, which means your IP address is transmitted to Google in the process; legal basis Art. 6(1)(f), our legitimate interest in a consistent presentation. Access to our web server is logged as described in Section 3.

App. The app stores your login session and your settings (e.g. language) locally on your device. This is strictly necessary to provide the service you expressly requested, so it does not require consent under § 25(2)(2) TDDDG. Deleting the app removes this local data.

19. Minors

The Services are intended exclusively for persons aged 18 and over; you confirm your age at registration. We do not knowingly process data of minors. If we become aware that an account belongs to a minor, we will block it and delete the data, subject to Section 15. If you believe a minor has provided us with data, contact us at info@bookinfluencers.app.

20. Changes and Contact

We will update this Privacy Policy when the processing described here changes — for example if we add a new service provider or a new feature. We will publish the updated version on this page with a new date and, if the change is material, notify you in the app or by email.

BookInfluencers
[Legal name and address — see Section 1]
info@bookinfluencers.app
bookinfluencers.app

See also: Terms of Service  ·  Datenschutzerklärung (deutsche Fassung)