FITRA Privacy Policy
Last updated: September 26, 2026
This policy explains how FITRA ("FITRA", "we") handles personal information when brands use the FITRA service (the "Service") and when we process information about Instagram creators. Contact: privacy@fitra.io (privacy) · support@fitra.io (support).
1. Who this covers
- Customers: brands and their team members who use FITRA.
- Creators: people with public Instagram accounts whom our customers may want to work with.
- Website visitors.
2. Information we collect
From customers - Account information: account name, login credentials, plan, billing status. Payments are processed by Stripe; we do not store full card numbers. - Campaign information: brand and product descriptions, targeting preferences, notes, email drafts, shortlist decisions, outreach status, and results you enter. - Connected accounts: - Gmail: your email address and an app password, stored encrypted and used only to send the emails you approve. - Shopify: an encrypted access token with read-only order access. We read order totals and the discount codes used, to attribute sales to creators. We do not request or store your shoppers' names, addresses, or contact details. - Business mailing address, which is added to outreach emails as required by anti-spam law. - Technical data: login session cookies, basic logs (e.g. timestamps, errors), and usage counts per campaign.
From people who request a demo - The details you enter in the "Book Demo" form on fitra.io: name, business email, brand website or Instagram, approximate monthly creator spend, and your message. We use them only to contact you about FITRA.
About creators (from public sources or provided by customers) - Public profile information: username, name as displayed, bio, follower/following counts, public posts and their captions, images or video frames, likes/comments counts, and a business contact email if publicly listed. - Images: a copy of the public profile picture and of one public post (the most recent post, or the post our analysis found most relevant to a campaign), stored in our file storage so the customer can recognize the creator. They are removed with the rest of the creator's data on a deletion request. - Derived information: engagement metrics, AI-generated fit analysis and scores for a specific customer's campaign. - Outreach records: which customer emailed the creator, when, the delivery result, and any opt-out.
3. How we use information
- To provide the Service: finding and analyzing creators for a customer's campaign, drafting and sending the outreach emails a customer approves, and tracking results.
- To enforce opt-outs across all customers (see section 6).
- To secure, maintain, and improve the Service, and to handle billing and support.
- To comply with legal obligations.
We do not sell personal information, and we do not use creators' data for advertising. Creator analyses are created for, and shown only to, the customer whose campaign they belong to. FITRA also keeps a shared library of public creator profile information (username, display name, bio, website, follower count, recent public posts) so it does not have to collect the same public data again and can suggest relevant creators to other customers. The library never contains customers' notes, decisions, messages or sales data, is refreshed regularly, and a creator can ask to be removed from it at privacy@fitra.io (see section 6).
4. Legal bases (EEA/UK)
Where GDPR applies: performance of a contract (customer accounts); legitimate interests (helping brands find relevant collaborators using public information, security, service improvement), balanced against creators' rights; and legal obligation (e.g. anti-spam compliance).
5. Sharing and sub-processors
We share information only with service providers that help us run FITRA, under contracts that limit their use of it: | Provider | Purpose | |---|---| | Render | Application hosting | | Supabase | Database and file (image) storage | | OpenAI | AI analysis and email drafting (API data not used to train models per their API terms) | | Apify; Meta (Instagram Graph API) | Collecting public creator profile data | | Google (Gmail SMTP, Google Workspace) | Sending emails from the customer's own account; our own support and service-notification email | | Shopify | Reading order data from the customer's connected store | | Stripe | Payments |
We may also disclose information if required by law, to protect rights and safety, or as part of a merger or acquisition (with notice).
6. Creator choices: opt-out and deletion
- Opt-out: every outreach email contains an unsubscribe link. Opting out adds the email address and username to a platform-wide suppression list (stored as a one-way hash), so no FITRA customer can email that person again. We lift an opt-out only if the creator asks us in writing to be contacted again; we keep a record of that request.
- Deletion and access: creators can ask us to access, correct, or delete their data at privacy@fitra.io. We will delete their profile, analyses and stored images from FITRA and keep only the hashed suppression entry so they are never contacted again.
7. Retention
- Customer data: kept while the account is active and deleted 30 days after the account is closed, unless we must keep it longer by law (e.g. billing records).
- Creator data: kept while it is part of an active customer campaign; refreshed or deleted when stale within 12 months of last use.
- Creator images: kept with the creator's profile and replaced when the profile is refreshed.
- Demo requests: kept up to 24 months, or deleted sooner on request.
- Opt-out hashes: kept indefinitely to honor the opt-out; records of a lifted opt-out are kept as proof of the creator's request.
8. Security
We use encryption in transit (HTTPS), encryption at rest for connected-account credentials, access controls between customers, and restricted database access. No system is perfectly secure; we will notify affected users of a breach as required by law.
9. Your rights
Depending on where you live (e.g. GDPR, UK GDPR, California CCPA/CPRA), you may have rights to access, correct, delete, or port your data, to object to or restrict processing, and to not be discriminated against for exercising them. Contact privacy@fitra.io; we respond within the time required by law. You may also complain to your local data-protection authority.
10. International transfers
We are based in the United States and our providers may process data in the US and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
11. Cookies
The dashboard uses a necessary cookie to keep you signed in. [List any analytics cookies if you add them later.]
12. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly analyze creators we know to be under 18; tell us and we will delete the data.
13. Changes
We will post updates here and, for material changes, notify customers by email or in the Service.