Privacy Policy
1 Scope & controller
This policy explains how [Legal entity name] (“voko”) processes personal data as a data controller under the EU General Data Protection Regulation (GDPR). It covers account holders (brands and creators) and visitors who click a voko-tracked link or land on a page running the voko pixel.
2 Data we collect
Account data
- Brands: work email, name, company name.
- Creators: the public X profile we import once (name, handle, photo, bio, follower count, average impressions), plus the professional details you provide for payment (status, business name, SIREN/SIRET, VAT status, legal address).
Usage & billing data
- Campaigns, briefs, posts and transactions you create.
Click & conversion data
- For each click on a tracked link: a hashed and salted IP address (never the raw IP), user agent, referrer, and country.
- For each conversion reported by the pixel: event type (visit / signup / purchase), the tracked link identifier, an opaque user reference you supply (never a plaintext email — any value that looks like an email is hashed), page URL and referrer.
3 Click tracking & IP hashing
When someone clicks a voko-tracked link, we record the click to measure and bill campaigns. We do not store raw IP addresses: the IP is combined with a secret salt and hashed with SHA-256 before storage. The hash lets us detect duplicates and bots without keeping an identifiable address.
The exact, objective definition of a “qualified click” is set out in our Commercial Terms and mirrors the rules enforced in our code.
4 The conversion pixel & cookies
Brands may install the voko pixel (px.js) on their site to attribute signups and purchases back to the creator post that drove them. The pixel:
- reads the
rkparameter from the URL and stores it in a first-party cookie and local storage for up to 30 days; - sends a “visit” event, and any “signup” / “purchase” events the brand chooses to report, to voko.
Because the pixel shares identifiers with a third party (voko) for commercial attribution, it is not exempt audience measurement. Brands deploying the pixel are responsible for obtaining valid prior consent from their visitors (e.g. via their cookie banner) before it loads, in line with GDPR and local ePrivacy rules.
5 Legal bases
- Contract — to provide accounts, run campaigns, and process payments.
- Legitimate interest — to secure the platform, prevent fraud, and measure campaign performance in aggregate.
- Consent — for the conversion pixel on a brand's site (obtained by the brand).
- Legal obligation — to issue invoices and keep accounting records.
6 How we use data
To operate the marketplace, match brands and creators, generate briefs, attribute clicks and leads, bill qualified clicks, pay creators, prevent fraud, and comply with our legal obligations. We do not sell personal data.
8 Retention
We keep account and transaction data for the life of the account and the periods required by accounting and tax law. Hashed click and conversion records are retained for attribution and billing transparency, then aggregated or deleted [define your retention period].
9 Your rights
Under GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to certain processing. To exercise these rights, contact [privacy@your-domain]. You may also lodge a complaint with your supervisory authority (in France, the CNIL).
10 International transfers
Where a processor is located outside the EEA, transfers are covered by appropriate safeguards (such as the EU Standard Contractual Clauses).
11 Security
Access to the database is protected by row-level security. IP addresses are hashed and salted before storage. Secrets are held server-side and never exposed to the browser. No system is perfectly secure, but we take reasonable measures to protect your data.
12 Contact
Privacy questions or requests: [privacy@your-domain]. Postal address: [Registered address].
Last updated July 25, 2026. Questions about this document? Contact [contact@your-domain].