Skip to content

Legal

Privacy Policy

What REMARQ collects about creators and brands, why it is needed to run a matching marketplace, who else sees it, and how to have it removed.

Version
1.0
Last updated

1. About this policy

REMARQ is an India-first marketplace where creators and brands find each other. This policy explains what information REMARQ collects when you use the platform, why it is collected, and what happens to it.

It covers both sides of the marketplace - creator accounts and brand accounts - and it covers the website, the application and the emails and messages REMARQ sends. By creating an account you are agreeing to the handling described here; the other document in this pair, the Terms of Service, sets out the rules of using the platform itself.

2. Information we collect

What REMARQ holds about you falls into the groups below. Nothing outside these groups is collected: there is no audience-demographic data, no contact-list upload, no location tracking and no advertising identifier anywhere in the product.

Account information

  • Your email address, which is how you sign in and how we reach you. Each address can be used by one account.
  • Your password, stored only as a bcrypt hash. REMARQ never stores or logs the password itself, and it cannot be recovered - a forgotten password has to be reset through a single-use link.
  • Which side you joined as - creator or brand. This decides which profile you build and which side of the marketplace you see.
  • Your username, the public handle shown on your profile, once you choose one during onboarding.
  • Your phone number, if you choose to verify one. It is optional. A number is only recorded on your account after you have entered a one-time code sent to it, and no two accounts can hold the same number.
  • Account state and history - your account status, when the account was created, and the time of your last sign-in.

Creator profile information

  • Your display name, profile photo, and the city, state and country you work from.
  • Your bio, the content formats you make, the kinds of collaboration you are open to, and the categories you work in.
  • Portfolio items you add: a title, a link, and an image where you upload one.
  • Your working preferences - a minimum budget, how many collaborations you will run at once, and whether you will travel - which are used to filter what you are shown and to score matches. They are not shown to brands as figures.

Brand profile information

  • Your brand name, logo, website, and any Instagram or LinkedIn links you add.
  • Your company size, the city, state and country you are based in, and a description of the brand.
  • The creator profiles you are looking for: follower range, minimum engagement rate, locations, collaboration types, and a typical budget range. Like a creator's preferences, these filter and score rather than being published.

Social accounts you tell us about, and the two we connect to

There are two different things here, and they carry different amounts of information.

  • Handles you type in yourself. For any platform, you can add a handle and a profile link, and supply a follower count and engagement rate by hand. REMARQ takes those at face value and marks the account as self-reported.
  • Instagram and YouTube connections. You can connect one of these accounts through the platform's own sign-in screen. When you do, and only then, REMARQ reads the following directly from the platform: your account identifier, handle, display name and profile picture; your follower (or subscriber) count, the number of accounts you follow, the number of posts or videos, and your total video views. These are re-read periodically so the numbers on your profile stay current. Connected accounts are marked as verified, which is what makes them count for marketplace eligibility.
  • The access and refresh tokens the platform issues. These are what let REMARQ read those numbers again later. They are encrypted before they are stored, are never shown on any screen, and are deleted the moment you disconnect the account - along with the metrics read through it.
  • Your engagement rate is never read from a platform. Neither Instagram nor YouTube exposes it to REMARQ, so the figure on your profile is whatever you entered yourself.

Images and other media you upload

Profile photos, brand logos and portfolio images are uploaded directly from your browser to our media provider, Cloudinary, using a signature REMARQ issues for that one upload. The image does not pass through REMARQ's own servers. REMARQ stores the resulting web address of the image, not the file, and the upload path is tied to your account so uploads stay attributable. Accepted formats are JPG, JPEG, PNG and WEBP.

Campaigns, applications, matches and collaboration requests

  • Campaigns a brand creates: title, description, category, platform, the creator size and engagement requirements, budget range, creator limit and deadline.
  • Applications a creator submits: the pitch, when it was submitted, and the brand's decision with any reason the brand gave.
  • Collaboration requests: who sent it, who it is for, the message attached, and how it was answered. An unanswered request expires on its own.
  • Matches, including the score behind them, and a record of which profiles you have viewed, passed on, or marked as interesting. This last record is what stops the same profile being shown to you twice, and it is personal to your account.

Messages and notifications

Messages you send to a match or a campaign participant are stored, with the sender and the time, so the conversation can be shown to both sides. Notifications about activity on your account are stored in the app; where a notification is also sent by email, the message preview may appear in that email.

Payments and subscriptions

Payments are processed by Razorpay. REMARQ receives and stores a record of the transaction: the amount, the currency, what it was for, the gateway's order and payment identifiers, the status, and any coupon applied. REMARQ does not receive your card number, UPI ID, bank details or any other payment instrument, and there is no field anywhere in the database that could hold one. The gateway sends REMARQ the event payload for each transaction, which is stored so a payment can be reconciled later.

Support requests and moderation records

If you contact support, the ticket and the conversation on it are stored. If an account is warned, suspended or banned, the decision and the reason are recorded, and so are reports made about an account.

Technical information

  • Your IP address, used for one purpose: limiting how many sign-ups and sign-in attempts can come from one place in an hour or fifteen minutes. Those counters are kept in a short-lived store and expire; the IP address is not written to the database and is not written to any log line.
  • The browser's user-agent string, recorded against a session when it is renewed, so that sessions can be told apart.
  • Phone numbers and email addresses in rate limits are stored only as one-way hashes, so the limiter can count attempts without holding a readable list of who tried to sign in.

3. How we use information

  • To run your account - signing you in, keeping you signed in, resetting a password, verifying a phone number.
  • To review your profile before it reaches the marketplace. Every profile is read by a person; this is why REMARQ is not an open directory, and it is why profile information is seen by staff as well as by other users.
  • To match. Your niche, audience size, engagement, location and preferred collaboration type are scored against the other side to order discovery and suggest matches. Matching is REMARQ's own computation; your information is not used to train anyone else's model.
  • To run transactions - subscriptions, trials, the connection fee, and the receipts for them.
  • To send you things you need to know about - a new match, a collaboration request, an application decision, a subscription change, a support reply. These are transactional messages about your own account rather than a marketing list.
  • To keep the marketplace safe - rate limiting, spam prevention, investigating reported accounts, and enforcing the Terms of Service.
  • To answer you when you contact support, and to keep an internal record of decisions so the same question can be answered the same way twice.

4. Cookies and storage in your browser

REMARQ sets no cookies at all. There is no advertising cookie, no analytics cookie and no third-party script on this site. Sessions are not held on the server either - every request carries a signed token.

Two things are kept in your browser, and both are needed to stay signed in:

  • The access token, in memory only. It is never written to storage, and it is gone when the tab is closed or reloaded.
  • The refresh token, in your browser's local storage under the key remarq.refresh_token. This is what makes a page reload not a sign-out. It is replaced on every renewal, expires after 30 days, and signing out removes it. Because it is in local storage, anyone with access to your browser profile has access to your session - so sign out on a shared machine.

A browser facility called a broadcast channel is used to keep the tabs you have open in step with each other when a session renews. It carries no information beyond the token exchange itself and does not persist.

5. Who else sees your information

REMARQ does not sell personal information, does not rent it, and does not share it for advertising. It is shared with the service providers a working marketplace cannot run without, and only in the course of providing those services:

  • Razorpay - payment processing. Razorpay receives the amount, the currency and a reference for what is being bought, and handles your payment instrument directly. REMARQ never sees it.
  • Cloudinary - image hosting. The images you upload are stored there and served to whoever can see your profile.
  • Resend - email delivery. Your email address and the contents of the message are passed to Resend so it can be delivered.
  • 2Factor - SMS delivery. If you verify a phone number, that number is passed to 2Factor so the code can be sent to it. The code itself is generated and checked by 2Factor; REMARQ never sees or stores it.
  • Meta (Instagram) and Google (YouTube) - only if you connect an account, and only to the extent of the permissions you grant on their own consent screens. You can withdraw that access from the platform itself at any time, as well as from your profile here.
  • Hosting, database and infrastructure providers - the services that serve this website and store the database it runs on.

Beyond those, information is disclosed only where the law requires it, where it is necessary to investigate fraud or abuse, or to protect the safety of a user. Some of these providers operate internationally, so information may be processed outside India.

What other users see is a separate question with a simpler answer: your profile as you filled it in, your public handle, the number on your connected social accounts, and whatever you write in a campaign, an application, a collaboration request or a message. Your email address, phone number, password and payment records are never shown to another user.

6. How we protect it

  • Passwords are stored as bcrypt hashes, never in a readable form.
  • Access and refresh tokens issued by Instagram and YouTube are encrypted with AES-256-GCM before they are written to the database.
  • Refresh tokens issued by REMARQ are stored as one-way hashes, and if an old one is used again every session on the account is ended.
  • Secrets - payment keys, mail keys, SMS keys, the token encryption key - live only on the server. None of them is present in anything sent to your browser.
  • Access to data is restricted by role, both on the server and in the admin screens, and administrative actions are recorded in an internal audit trail.
  • Traffic to REMARQ is served over HTTPS.

No system is perfectly secure, and REMARQ does not claim a certification it has not been audited for. If you believe your account has been compromised, write to us at the address at the end of this page.

7. How long we keep it

Information is kept for as long as your account exists, because a marketplace that forgets your history cannot match, verify or support you. Beyond that:

  • Verification codes expire ten minutes after they are sent, and the attempt limit on a code is enforced server-side. Rate-limit counters expire within an hour.
  • Images you remove from your profile stop being shown, but the file itself stays in our media storage until it is deleted there. There is no automatic purge, so if you want an uploaded image erased, ask us and we will remove it.
  • Payment and transaction records are kept after an account is closed, because tax and accounting rules require them and because a disputed payment years later has to be answerable.
  • The internal audit trail keeps a record of administrative actions, with the reference to the account it concerned removed if that account is deleted.

There is deliberately no fixed retention number printed here. REMARQ does not run a scheduled purge, and stating a period the codebase does not enforce would be a promise that nothing keeps.

8. Your information and what you can ask for

You can ask REMARQ for any of the following by writing to the address at the end of this page. These requests are handled by a person, and we will tell you if a request cannot be met and why.

  • To see what we hold. A copy of the information on your account.
  • To correct it. Most of it you can edit yourself on your profile; anything you cannot, ask us. A verified phone number or a connected social account can be changed by verifying or connecting the correct one - the platform checks the fact rather than trusting an edit.
  • To delete your account. There is no self-service delete button, so this is a request to us. When it is actioned, the account and the information attached to it - profile, connections, messages, matches, consent record - are removed. Where something has to be kept - a payment record we are required to retain, for instance - we will tell you what was kept and why. Deleting an account also ends any active subscription, and a subscription already paid for is not refunded for the unused part.
  • To withdraw consent or object. Withdrawing consent to this policy and the Terms means closing the account, since the two documents are what the marketplace is operated under.
  • To complain. Tell us first - we would rather fix it - and you also have whatever remedy the law where you live gives you.

9. Children

REMARQ is a business tool for people who are old enough to enter into commercial arrangements, and it is not intended for children. Accounts are for users aged 18 or over. We do not knowingly collect information from anyone under 18, and if we learn that an account belongs to someone younger we will close it and remove the information on it. If you believe a child has created an account, write to us at the address below.

10. Changes to this policy

This policy has a version number and a date at the top of the page, both of which change when the document does. The version a person accepted when they created their account is recorded, so a change here does not alter what anyone agreed to in the past.

If a change materially affects how information is used, REMARQ will tell you in the app or by email. Continuing to use the platform after a change takes effect means the new version applies - and if you do not accept it, you can close your account as described in section 8.

11. Contact

REMARQ is operated from India. For anything on this page - a question, a request about your information, or a complaint - write to us:

Questions about this document, or about how REMARQ handles your information, go to contact@remarq.in.