Privacy Policy
Version v1.2.0 · Effective August 15, 2026
This Policy describes the data Castify actually processes in its marketplace and collaboration workspace, including data you provide, operating data, and read-only data authorized through TikTok, Meta/Facebook, and Google/YouTube. It identifies the sources, purposes, recipients, retention periods, and revocation or deletion controls.
1. Who we are and where this policy applies
Castify is an influencer-marketing marketplace and collaboration workspace operated for brands and creators. Castify determines how personal data is processed for account, discovery, campaign, booking, communication, review, payment, trust, and support features.
This policy applies to castify.io.vn, Castify workspaces, public creator and campaign pages, and our official social-platform integrations. Third-party sites and apps have their own terms and privacy practices.
Questions, privacy requests, and complaints may be sent to support@castify.io.vn. We use the information in a request only to verify identity, respond, and maintain a defensible request record.
2. Information we collect
Account and profile data includes name, email, hashed password, role, avatar, bio, contact email/phone, gender, region, niches, brand information, packages, portfolio, settings, and verification evidence you submit.
Collaboration data includes saved creator lists, campaigns, applications, invitations, briefs, bookings, messages and attachments, tasks, content submissions, feedback/approvals, reviews, disputes, usage rights, and workflow history created in Castify.
Payment and compliance data includes bank code/name, account number, and holder name; the number is masked in ordinary interfaces but stored to support payment workflows. KYC data may include document type/number, front/back and face images, OCR/match results, status/risk notes; consent and audit data includes version, hash, time, IP, and user agent. Castify never asks for social passwords.
Technical data includes refresh/session cookies, browser-side access-token state, locale, time zone, theme, request/session identifiers, IP and user agent where needed for consent/audit/security, access time, and error logs. Castify does not currently set advertising cookies; optional future analytics will be disclosed and consented to where required.
3. Social-platform data and exact permissions
TikTok Login Kit requests user.info.basic, user.info.profile, and user.info.stats. Castify receives open_id, avatar, display name, username, follower count, following count, video count, and total likes; Castify derives the public profile URL from the username. These scopes do not give Castify email, passwords, video lists, or verification status.
Facebook Login requests pages_show_list and pages_read_engagement. Castify receives the app-scoped user ID and Pages you manage, then stores only the Page you choose with its ID, name, username, URL, avatar, followers, Page likes, and published-post count.
Google OAuth requests only https://www.googleapis.com/auth/youtube.readonly. Through YouTube API Services, Castify receives the channel ID, name, handle/custom URL, image, subscriber count, video count, and total channel views. Those values come from YouTube; if a Castify-calculated summary appears alongside them, it is Castify product information and is not represented as a metric supplied by YouTube.
Instagram currently uses a code you place in the public bio of a professional account instead of Instagram OAuth. Castify reads only the public profile and statistics needed for verification. Current OAuth connections are read-only: Castify cannot publish, edit, delete, like, comment, or manage social content.
4. Where information comes from and what becomes public
We receive data directly from you, from other campaign participants, from official provider APIs after your explicit authorization, and from public profiles or lookup sources that you ask Castify to verify.
Creator public pages may show the name, avatar, bio, location, niches, connected social profile names and metrics, service packages, aggregate ratings, and public brand reviews selected for marketplace discovery. Brand campaign pages may show brand identity, campaign requirements, budget, deadline, location, and requested platforms.
Before starting OAuth, Castify displays the exact requested scopes, data categories, purpose, retention rule, current disclosure version, Privacy Policy, and deletion controls. We keep an append-only, secret-free record of that acknowledgement and subsequent grant or revocation.
5. How and why we use information
Account and technical data is used to register and verify accounts, manage sessions, remember locale/time zone/theme, provide support, detect abuse, and protect the service.
Profile, business, and social data is used to verify control of a profile, Page, or channel; display a connection; refresh permitted statistics; create a public creator profile; and help brands discover creators. TikTok Information is used only to develop, maintain, and support the Castify functionality approved by TikTok; YouTube data remains subject to YouTube API Services restrictions.
Campaign and collaboration data is used to match participants, deliver briefs, coordinate bookings/messages/content/deadlines/reviews, preserve payment evidence, reconcile activity, resolve disputes, and send service notices.
Where applicable, processing grounds include performance of a contract, consent for social connections or optional marketing, legitimate interests in operating a safe marketplace, and legal, accounting, fraud-prevention, or dispute obligations. Withdrawal does not invalidate processing already carried out lawfully.
6. Who receives information
Castify does not sell personal or social data, provide it to data brokers, or use social API data for third-party advertising, credit, employment, or unrelated profiling decisions.
Visitors, brands, and creators see only fields made public on a profile or campaign, or information needed for a collaboration they are authorized to join. Contact details, briefs, messages, files, and payments do not become public discovery data.
Infrastructure, file-storage, email, identity, error-monitoring, and support providers may process only the data needed to provide services to Castify under instructions and confidentiality duties. We do not allow them to use social data for an incompatible independent purpose.
We may disclose data in response to a valid legal demand, to protect users or the service, investigate fraud or abuse, or in a corporate transaction with notice and appropriate safeguards. Internal access is restricted by role and work-related need.
7. Retention, revocation, and deletion
Account and collaboration data is kept while the account, agreement, or related obligation requires it. When Castify accepts a whole-account deletion request, it immediately disables the account and sessions, queues provider revocation, returns a confirmation code/status URL, and deletes or pseudonymizes data through the published workflow.
TikTok and Facebook Authorized Data is retained while the selected connection is active and removed from active systems after disconnection, a valid deletion callback, or account deletion. OAuth tokens are encrypted at rest, then deleted, and Castify asks the provider to revoke the grant.
YouTube API Data is refreshed or deleted within 30 days. After you disconnect, request data deletion, or delete the Castify account, related YouTube data is deleted as soon as possible and no later than 7 calendar days.
Collaboration, message, submitted-content, payment, contract, review, consent, security/audit records and related evidence may remain in restricted or pseudonymized form for agreed rights, accounting, fraud prevention, dispute, or legal obligations. Reusable OAuth credentials are not retained for those purposes.
8. Your choices and rights
You can access and correct profile information, choose what appears publicly, change preferences, disconnect each social account, or request complete account deletion from Settings. Disconnecting does not delete your account or content on the provider platform.
You can also revoke Google access in Google Account permissions, remove Facebook access in Business Integrations, or manage TikTok authorization in TikTok settings. Provider revocation may take effect before Castify next receives a callback, so our scheduled checks also detect expired or revoked grants.
Subject to applicable law, you may request access, correction, portability, restriction, objection, or deletion. We may request reasonable identity verification and may deny or limit a request only when a documented legal exception applies.
You can unsubscribe from marketing messages while continuing to receive authentication, security, campaign, payment, deletion-status, and other necessary service communications.
9. Security, international processing, and minors
Castify uses role and ownership checks, HTTPS, password hashing, OAuth-token encryption, masked bank-number responses in ordinary interfaces, scoped access, upload checks, revocation workflows, audit trails, and secret-free logs. No online service can guarantee absolute security.
Infrastructure providers or social platforms may process data outside Vietnam. For cross-border processing, we apply access controls and contractual or technical safeguards appropriate to the data and destination.
Castify accounts are for people aged 18 or older, or otherwise legally capable of entering the commercial arrangements offered. If we learn that an ineligible minor's data was supplied without valid authority, we will restrict and delete it as required by applicable law.
10. Cookies, policy versions, and contact
Castify uses essential cookies and local storage for refresh/session state, sign-in, language, time zone, theme, security, and core functionality. We do not currently set advertising cookies; future analytics or optional technology will be disclosed and consented to where required.
Each policy version has an effective date and document-manifest hash, and Castify retains evidence of the version you accepted. For a material change, signed-in users receive notice and must affirmatively accept; silence or continued browsing alone is not recorded as consent.
For privacy questions or requests, email support@castify.io.vn, use the Contact page, or open Privacy choices in Settings. The Data deletion instructions describe each request type and display status using a confirmation code.
Social-platform terms and privacy controls
These direct links let you review provider terms, inspect current access, or request deletion without searching through Castify.
If you have questions about this content, email support@castify.io.vn or visit the Contact page.