← FITRA

FITRA Privacy Policy

Last updated: September 26, 2026

This policy explains how FITRA ("FITRA", "we") handles personal information when brands use the FITRA service (the "Service") and when we process information about Instagram creators. Contact: privacy@fitra.io (privacy) · support@fitra.io (support).

1. Who this covers

2. Information we collect

From customers - Account information: account name, login credentials, plan, billing status. Payments are processed by Stripe; we do not store full card numbers. - Campaign information: brand and product descriptions, targeting preferences, notes, email drafts, shortlist decisions, outreach status, and results you enter. - Connected accounts: - Gmail: your email address and an app password, stored encrypted and used only to send the emails you approve. - Shopify: an encrypted access token with read-only order access. We read order totals and the discount codes used, to attribute sales to creators. We do not request or store your shoppers' names, addresses, or contact details. - Business mailing address, which is added to outreach emails as required by anti-spam law. - Technical data: login session cookies, basic logs (e.g. timestamps, errors), and usage counts per campaign.

From people who request a demo - The details you enter in the "Book Demo" form on fitra.io: name, business email, brand website or Instagram, approximate monthly creator spend, and your message. We use them only to contact you about FITRA.

About creators (from public sources or provided by customers) - Public profile information: username, name as displayed, bio, follower/following counts, public posts and their captions, images or video frames, likes/comments counts, and a business contact email if publicly listed. - Images: a copy of the public profile picture and of one public post (the most recent post, or the post our analysis found most relevant to a campaign), stored in our file storage so the customer can recognize the creator. They are removed with the rest of the creator's data on a deletion request. - Derived information: engagement metrics, AI-generated fit analysis and scores for a specific customer's campaign. - Outreach records: which customer emailed the creator, when, the delivery result, and any opt-out.

3. How we use information

We do not sell personal information, and we do not use creators' data for advertising. Creator analyses are created for, and shown only to, the customer whose campaign they belong to. FITRA also keeps a shared library of public creator profile information (username, display name, bio, website, follower count, recent public posts) so it does not have to collect the same public data again and can suggest relevant creators to other customers. The library never contains customers' notes, decisions, messages or sales data, is refreshed regularly, and a creator can ask to be removed from it at privacy@fitra.io (see section 6).

4. Legal bases (EEA/UK)

Where GDPR applies: performance of a contract (customer accounts); legitimate interests (helping brands find relevant collaborators using public information, security, service improvement), balanced against creators' rights; and legal obligation (e.g. anti-spam compliance).

5. Sharing and sub-processors

We share information only with service providers that help us run FITRA, under contracts that limit their use of it: | Provider | Purpose | |---|---| | Render | Application hosting | | Supabase | Database and file (image) storage | | OpenAI | AI analysis and email drafting (API data not used to train models per their API terms) | | Apify; Meta (Instagram Graph API) | Collecting public creator profile data | | Google (Gmail SMTP, Google Workspace) | Sending emails from the customer's own account; our own support and service-notification email | | Shopify | Reading order data from the customer's connected store | | Stripe | Payments |

We may also disclose information if required by law, to protect rights and safety, or as part of a merger or acquisition (with notice).

6. Creator choices: opt-out and deletion

7. Retention

8. Security

We use encryption in transit (HTTPS), encryption at rest for connected-account credentials, access controls between customers, and restricted database access. No system is perfectly secure; we will notify affected users of a breach as required by law.

9. Your rights

Depending on where you live (e.g. GDPR, UK GDPR, California CCPA/CPRA), you may have rights to access, correct, delete, or port your data, to object to or restrict processing, and to not be discriminated against for exercising them. Contact privacy@fitra.io; we respond within the time required by law. You may also complain to your local data-protection authority.

10. International transfers

We are based in the United States and our providers may process data in the US and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

11. Cookies

The dashboard uses a necessary cookie to keep you signed in. [List any analytics cookies if you add them later.]

12. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly analyze creators we know to be under 18; tell us and we will delete the data.

13. Changes

We will post updates here and, for material changes, notify customers by email or in the Service.