Privacy Policy
Last updated: June 10, 2026
1. Introduction
MuziQ ("Platform", "MuziQ", "we", "us", or "our") respects your privacy. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it. It covers our website, web app, native apps, and APIs.
We act as a data controller for personal data we collect from our Users (artists and creators) and as a data processor where we handle campaign metrics on an artist's behalf. By using the Platform you confirm you have read this Policy. If you do not agree, please do not use the Platform.
2. Information We Collect
2.1 Account information
Name, email address, password hash (or Google OAuth identifier), profile picture, handle, role (artist or creator), country, and language preference. Creators may also provide social media handles, payout details, and tax identification information.
2.2 Campaign and content data
Artists upload music files, brief text, album artwork, budget settings, and TikTok sound IDs. Creators submit post URLs, descriptions, and screenshots if requested. We store derived data such as approval status, payout calculations, and dispute history.
2.3 TikTok data (only if you connect TikTok)
When you authorize TikTok via OAuth 2.0, we receive and store only the fields needed to operate MuziQ:
open_id,union_id— stable identifiers used to link your TikTok identity to your MuziQ account and to scope metric queries.display_name,username, profile deep link,avatar_url— shown on your MuziQ profile so artists can verify you.follower_count,following_count,likes_count,video_count— refreshed at sign-in and once per day so artists can vet reach before inviting you to paid collabs.- For posts you submit to a campaign:
video_id,create_time,view_count,like_count,comment_count,share_count— read once per day per active campaign via the Video Query API, scoped to youropen_idand the campaign's TikTok sound/post ID. - For the auto-repost feature: the publish status (success/failure) and TikTok
publish_idreturned when an artist's promo video is posted directly to your profile viavideo.publish(Direct Post). You opt in per campaign before any post is made. - An encrypted OAuth refresh-token row so we can refresh access without prompting you each time. We do not store long-lived access tokens in plaintext.
We do not read your TikTok DMs, drafts, friends list, private videos, or account settings. We do not query videos outside active campaigns. We do not sell TikTok data. The TikTok data we hold is used only to operate the Platform, calculate payouts, prevent fraud, and provide campaign analytics to the relevant artist.
2.4 Payment and payout information
Card and bank processing is handled by Stripe. We do not store full card numbers, full bank account numbers, or CVCs. We do store: a Stripe customer ID, a Stripe Connect account ID, payout history, wallet balances, fee calculations, the last 4 digits and brand of payment instruments shown in your dashboard, and tax-form metadata where required by law.
2.5 Usage and device data
IP address, browser/user-agent, device type, OS, approximate location (city-level, derived from IP), pages visited, referring URL, timestamps, error logs, and feature interactions. Collected for security, debugging, fraud prevention, and product analytics.
2.6 Cookies and similar technologies
We use strictly-necessary cookies for sign-in and session management, and a limited set of analytics cookies/local storage for product analytics. We do not use third-party advertising cookies. You can manage cookies in your browser; disabling strictly-necessary cookies will break sign-in.
3. How We Use Your Information
- Operating the marketplace: creating accounts, matching artists with creators, running campaigns, verifying submissions, calculating payouts.
- Authentication and security: verifying your identity, protecting against unauthorized access, OAuth session management, fraud and abuse detection.
- Payments and payouts: charging artists, holding funds in escrow with our processor, paying creators, refunds, chargebacks, tax reporting.
- TikTok integration: showing verified TikTok profile info on MuziQ, optional auto-repost of artist-supplied videos to your TikTok Inbox, daily metric sync for campaigns you joined.
- Communications: transactional emails (sign-up, password reset, campaign approval, payout notifications, dispute updates), service announcements, and — only with your opt-in — marketing emails.
- Analytics and product improvement: understanding feature usage in aggregate.
- Legal compliance: tax, anti-money-laundering, sanctions screening, responding to lawful requests, enforcing our Terms.
Legal bases (UK/EU users): performance of contract (operating your account and campaigns), legal obligation (tax, AML), legitimate interests (fraud prevention, product improvement, securing the Platform), and consent (marketing emails, optional analytics).
Automated decision-making: KPI-based payouts are calculated automatically from TikTok metrics. Submissions may also be auto-flagged for fraud review. You can request human review of any auto-decision by emailing privacy@muziqcollab.com.
4. How We Share Your Information
We do not sell your personal data and we do not use it for cross-context behavioral advertising. We share data only as follows:
- Service providers (sub-processors): Stripe (payments, payouts, Connect onboarding, tax forms), TikTok (Login Kit, Display API, Content Posting API, Research API), Supabase (database, auth, storage), Cloudflare (hosting, edge, security), Resend or similar (transactional email), Google (OAuth sign-in), and product-analytics providers. Each is contractually bound to process data only on our instructions.
- Between Users: campaign-relevant data (submission URLs, verified public metrics, payout amounts, your TikTok handle, follower count, and avatar) is shared between the artist and creator on that campaign so the artist can vet, approve, and report on the work they funded.
- Legal: we may disclose data in response to a subpoena, court order, or other lawful request, or where we reasonably believe disclosure is necessary to protect rights, property, or safety.
- Corporate transactions: if MuziQ is involved in a merger, acquisition, financing, or asset sale, your data may be transferred under equivalent privacy protections; you will be notified of any change in controller.
5. International Data Transfers
We are based in the United States and use sub-processors located in the US, EU/EEA, and UK. Where personal data is transferred out of the EEA, UK, or other regions with similar protections, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and we apply additional safeguards (encryption in transit and at rest, access controls, pseudonymization where feasible).
6. Data Retention
- Account data: while your account is active and for 12 months after closure, unless a longer period is required.
- Campaign records and payout history: at least 7 years for tax, accounting, and audit purposes.
- TikTok-derived profile fields (handle, avatar, counts): purged within 30 days after you disconnect TikTok or delete your MuziQ account.
- Per-post TikTok metrics that justified a payout: retained with the related payout record for 7 years to evidence the transaction, then deleted or anonymized.
- OAuth refresh tokens: deleted within 7 days of disconnection or revocation.
- Server and security logs: typically 12 months.
- Backups: rolled off on our standard backup cycle (up to 35 days after deletion in primary stores).
7. Data Security
We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, hashed passwords, role-based access controls, audit logging, least-privilege service accounts, and regular review of access. No system is perfectly secure; if we discover a breach affecting your personal data, we will notify you and the appropriate authorities within the timelines required by applicable law (e.g. 72 hours under GDPR).
8. Your Rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data, subject to legal retention requirements (e.g. tax records).
- Port your data in a structured, machine-readable format.
- Restrict or object to certain processing, including direct marketing.
- Withdraw consent at any time where processing is based on consent.
- Complain to your local data protection authority (e.g. the UK ICO or your EU supervisory authority).
California residents (CCPA/CPRA): you have the right to know, delete, correct, and limit use of sensitive personal information, and the right to opt out of "sale" or "sharing" — we do not sell or share personal information as those terms are defined. You can also designate an authorized agent.
To exercise any of these rights, email privacy@muziqcollab.com. We will respond within 30 days (or sooner where required by law). We may need to verify your identity before fulfilling the request.
9. Children's Privacy
The Platform is not intended for anyone under 18. We do not knowingly collect personal data from children. If we learn we have collected data from a child under 18, we will delete it promptly. Contact privacy@muziqcollab.com if you believe a child has provided us data.
10. Third-Party Services
The Platform integrates with third parties whose privacy practices are governed by their own policies:
11. Disconnecting and Deletion
You can disconnect TikTok at any time from your MuziQ profile settings. Disconnection revokes our OAuth grant, stops future API calls (including auto-reposts and daily metric sync), and triggers the retention rules in Section 6. You can request full account deletion by emailing privacy@muziqcollab.com; we will delete personal data subject to the legal-retention items listed above, and confirm in writing when done.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or by a prominent notice on the Platform at least 14 days before they take effect (or immediately where required by law). The "Last updated" date at the top of this page shows when the policy was last revised.
13. Contact Us
Privacy questions or requests: privacy@muziqcollab.com
Data Protection Officer / EU & UK representative: privacy@muziqcollab.com (we will route as needed)
Postal: MuziQ, Legal Department, Wilmington, Delaware, USA.