Privacy Policy
This Privacy Policy explains how Cr8tiveHub Digital Studios (Pty) Ltd. collects, uses, shares, and protects your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). It is the single, company-wide Privacy Policy covering all Cr8tivehub properties: the public website at cr8tivehub.com, the Cr8tivehub mobile application, the account portal at accounts.cr8tivehub.com, and the agency portal at agency.cr8tivehub.com.
1. Who We Are
Cr8tiveHub Digital Studios (Pty) Ltd. (“Cr8tiveHub”, “we”, “us”, “our”) operates the public website at cr8tivehub.com, the Cr8tiveHub mobile application (available on Android), the web account portal at accounts.cr8tivehub.com, and the agency portal at agency.cr8tivehub.com.
We are a South African company registered as a responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). Our Information Officer is Thokozani Dube, registered with the Information Regulator of South Africa under registration number 2026-011645 in accordance with section 55 of POPIA.
Information Officer contact: admin@cr8tivehub.com.
Cr8tiveHub is a creative talent marketplace that connects creative professionals — including musicians, actors, photographers, DJs, producers, stylists, and other creatives — with individuals and organisations seeking creative talent across Africa.
For any privacy-related enquiries, you may contact us at legal@cr8tivehub.com.
2. Information We Collect
We collect the following categories of personal information when you use our services. For each category, we describe what we collect, why, and the legal basis under POPIA that permits the processing.
Account Data
What: Full name, email address, profile photo, bio, city, country, profession, and hashtags.
Why: To create and maintain your account, enable discovery by other users, and personalise your experience.
Legal basis: Contractual necessity (section 11(1)(b) of POPIA) — this data is required to provide the service you signed up for.
Private Data
What: Phone number, date of birth, and full legal name. This data is stored in a restricted Firestore subcollection with owner-only access — no other users or staff can view it without explicit authorisation.
Why: For identity verification, age verification (our service is restricted to users aged 18 and older), and account recovery.
Legal basis: Contractual necessity and legal obligation (sections 11(1)(b) and 11(1)(c) of POPIA).
Content Data
What: Portfolio items (images, video, audio), credits, and opportunities posted.
Why: To provide portfolio showcasing, opportunity listing, and talent discovery features — the core of our service.
Legal basis: Contractual necessity (section 11(1)(b) of POPIA).
Usage Data
What: Login timestamps, session data, feature usage, and last active timestamp.
Why: To improve our service, detect security anomalies, and maintain platform integrity.
Legal basis: Legitimate interest (section 11(1)(f) of POPIA) — we have a legitimate interest in understanding how our service is used and ensuring its security.
Device Data
What: Firebase Cloud Messaging (FCM) push notification tokens (Android).
Why: To deliver push notifications about messages, bookings, and platform updates.
Legal basis: Consent (section 11(1)(a) of POPIA) — you may disable push notifications at any time via your device settings.
Financial Data
What: Subscription tier, billing cycle, and transaction records. We do not store credit or debit card numbers — payment card data is handled exclusively by PayFast (Pty) Ltd, our PCI DSS-compliant payment processor.
Why: To manage your subscription, process billing, and maintain financial records as required by law.
Legal basis: Contractual necessity and legal obligation (sections 11(1)(b) and 11(1)(c) of POPIA).
Verification Data
What: Verification level, selfie check results, and identity document metadata. We do not store the identity document itself.
Why: To establish trust and authenticity on the platform, helping talent seekers identify verified professionals.
Legal basis: Consent (section 11(1)(a) of POPIA) — verification is voluntary.
Location Data
What: City, country, and latitude/longitude (if provided for discovery).
Why: To enable location-based discovery of creative talent and opportunities.
Legal basis: Consent (section 11(1)(a) of POPIA) — providing precise location is optional and can be withdrawn at any time.
Communications
What: Direct messages, live stream chat, and notification history.
Why: To enable communication between users, deliver notifications, and maintain records for safety and content moderation.
Legal basis: Contractual necessity (section 11(1)(b) of POPIA).
Behavioural Data
What: Follow relationships, portfolio likes/views, opportunity applications, and match scores.
Why: To power our discovery and matching algorithms, improving the quality of recommendations for both creatives and talent seekers.
Legal basis:Legitimate interest (section 11(1)(f) of POPIA) — we have a legitimate interest in improving the relevance of our platform's recommendations.
Website Browsing Data
What: IP address, user-agent string, page URLs visited, time of visit, referrer.
Why: Site security (rate limiting, abuse detection), basic operational logging, troubleshooting.
Legal basis: Legitimate interest (section 11(1)(f) of POPIA).
Retention: Server access logs retained for 90 days, then purged.
Inquiry & Agency Contact Form Data
What: Name, email address, organisation name (optional), message text submitted through enquiry or agency contact forms on cr8tivehub.com.
Why: To respond to your enquiry about partnerships, agency sign-up, press, or general questions.
Legal basis: Consent (section 11(1)(a) of POPIA).
Retention: 24 months after the last interaction relating to that enquiry, then deleted.
Newsletter / Mailing List (if you opt in)
What: Email address, plus (optional) name and area of interest.
Why: To send you product updates, opportunities, or news you have asked to receive.
Legal basis: Consent (section 11(1)(a) and section 69 of POPIA).
Retention: Until you unsubscribe. Every email contains a one-click unsubscribe link.
Cookies and Similar Technologies
We use a small number of strictly necessary cookies. With your consent, we may also use analytics and marketing cookies. See the Cookies section of this policy for details.
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing and improving the service: Operating the Cr8tiveHub platform, maintaining your account, and developing new features.
- Matching creatives with opportunities: Using our automated matching algorithm to connect creative professionals with relevant opportunities and talent seekers.
- Enabling live streaming and portfolio features: Hosting and delivering your portfolio content and live streams to other users.
- Processing subscription payments: Managing billing, subscriptions, and transaction records through our payment processor PayFast.
- Sending push notifications and emails: Delivering important account notifications, booking updates, messages, and (where you have opted in) marketing communications.
- Responding to enquiries: Responding to enquiries, agency sign-up requests, and contact-form messages submitted through our website.
- Sending newsletters and updates: Sending you newsletters and updates where you have opted in.
- Content moderation and safety: Automatically scanning uploaded media to detect and prevent illegal or harmful content, and reviewing flagged content to maintain community safety.
- Fraud prevention and security: Detecting and preventing fraudulent activity, unauthorised access, and abuse of the platform, including bot traffic and spam.
- Legal compliance: Fulfilling our obligations under South African law, including POPIA, the Companies Act 71 of 2008, and tax legislation administered by SARS.
- Analytics and product improvement: Understanding usage patterns to improve the user experience and develop features that better serve our community.
We do not sell your personal information. We do not share it with third parties for their own marketing.
4. Cross-Border Data Transfers & Third-Party Processors
We use the following third-party service providers to operate Cr8tiveHub. Where data is transferred outside of South Africa, we ensure appropriate safeguards are in place as required by section 72 of POPIA.
Google Firebase (Google LLC, United States)
Services: Authentication, Firestore database, Cloud Functions, Cloud Storage, and Firebase Cloud Messaging (FCM) push notifications.
Data transferred: User profiles, authentication data, portfolio content, messages, and usage data.
Data location: Our Firebase project is configured to store data in the europe-west1 (Belgium) region. Belgium is a member of the European Union, which is recognised as providing an adequate level of data protection under POPIA.
Safeguards:Google's Standard Contractual Clauses (SCCs) and adequacy decisions provide additional protection for any data that may be processed in the United States.
Privacy policy: https://policies.google.com/privacy
PayFast (PayFast (Pty) Ltd, South Africa)
Services: Payment processing for subscriptions.
Data transferred: Name, email address, payment amount, and subscription tier. No credit or debit card data ever touches our servers — all card processing is handled entirely by PayFast.
Data location: PayFast is a South African entity. No cross-border data transfer occurs for payment processing.
Safeguards: PayFast is PCI DSS compliant, ensuring the highest standards of payment data security.
Privacy policy: https://www.payfast.co.za/legal/privacy-policy
LiveKit (LiveKit Inc, United States)
Services: Real-time live streaming infrastructure.
Data transferred: Audio/video streams and room metadata.
Safeguards: Standard Contractual Clauses (SCCs) are in place to ensure an adequate level of data protection for data transferred to the United States.
Privacy policy: https://livekit.io/privacy
Google reCAPTCHA (Google LLC, United States)
Services: Bot prevention on the public website and the web account portal.
Data transferred: Browser behaviour signals and IP address.
Safeguards:Google's Standard Contractual Clauses (SCCs).
Privacy policy: https://policies.google.com/privacy
SendGrid (Twilio Inc., United States)
Services: Newsletter and transactional email delivery for the public website.
Data transferred: Email address, and any name or content included in the email.
Data location: United States.
Safeguards: Standard Contractual Clauses (SCCs) are in place to ensure an adequate level of data protection for data transferred to the United States.
Cloudflare (Cloudflare, Inc., if used)
Services: Content delivery network (CDN), bot mitigation, and DDoS protection.
Data transferred: IP address and request metadata.
Data location: Globally distributed.
Safeguards: Standard Contractual Clauses (SCCs).
5. Data Retention
We retain your personal information only for as long as is necessary for the purposes described in this policy, or as required by applicable law. The following table summarises our retention periods:
| Data Type | Retention Period |
|---|---|
| Active account data | Duration of account + 3 years after last activity |
| Deleted account data | Soft-deleted immediately, hard-deleted within 90 days |
| Transaction / payment records | 7 years (SARS and Companies Act compliance) |
| Audit / security logs | 5 years |
| Push notification tokens | Until logout or app uninstall |
| Messages | Duration of account, deleted with account |
| Verification records | 5 years after account closure |
| Backup data | Encrypted backups retained for 30 days, then purged |
When data is deleted, anonymised transaction records may be retained for up to 7 years as required for financial compliance under the Companies Act 71 of 2008 and SARS tax legislation.
6. Your Rights Under POPIA
As a data subject under the Protection of Personal Information Act, you have the following rights:
- Right of access (section 23): You have the right to request confirmation of whether we hold personal information about you, and to request a copy of that information. Submit your request to support@cr8tivehub.com.
- Right to correction (section 24): You have the right to request correction of inaccurate, incomplete, or misleading personal information. You can update most information directly through the Cr8tiveHub app or the web account portal at accounts.cr8tivehub.com/settings.
- Right to deletion (section 24): You have the right to request deletion of your personal information. You can delete your account through the app or by contacting support. Upon deletion, your data will be soft-deleted immediately and hard-deleted within 90 days, subject to the retention periods described above.
- Right to object (section 11(3)): You have the right to object to processing of your personal information for direct marketing purposes. You can opt out of marketing communications at any time via your notification settings or by contacting us.
- Right to object to automated processing (section 71): You have the right to object to decisions made solely by automated means, including our opportunity matching algorithm. See the Content Moderation & Automated Processing section below for details.
- Right to lodge a complaint: If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the Information Regulator of South Africa.
Information Regulator of South Africa
7. Security
We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. These measures include:
- Firebase security rules restricting database and storage access to authorised users only.
- HTTP-only session cookies that cannot be accessed by client-side JavaScript, reducing the risk of cross-site scripting (XSS) attacks.
- Encryption in transit using TLS 1.2 or higher for all data transmitted between your device and our servers.
- Encrypted backups ensuring data at rest is protected.
- Automated content moderation to detect and remove harmful content.
- Rate limiting and fraud detection on authentication and sensitive API endpoints.
- CSRF protection on all mutating API endpoints.
While we implement robust security measures, no system can guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Regulator as required by section 22 of POPIA as soon as reasonably possible after discovery of the breach.
8. Content Moderation & Automated Processing
Automated Content Moderation
We use automated content moderation powered by Google Cloud Vision (via Firebase Storage triggers) to scan uploaded media for illegal or harmful content. This includes detection of nudity, violence, and other content that violates our Acceptable Use Policy. Content may be removed and users notified without prior notice if a violation is detected.
Opportunity Matching Algorithm
Our platform uses an automated matching algorithm that analyses your profile data, skills, location, and behavioural data (such as portfolio engagement and application history) to recommend relevant opportunities and surface your profile to talent seekers. This is an automated decision-making process as defined by section 71 of POPIA.
Your Right to Object
You have the right to object to decisions made solely by automated means that significantly affect you. If you wish to object to automated processing or request human review of an automated decision, please contact us at legal@cr8tivehub.com. We will review your request and respond within 30 days.
9. Children's Privacy
Cr8tiveHub is strictly intended for users aged 18 years and older. We do not knowingly collect, process, or store personal information from anyone under the age of 18.
If we discover that an account belongs to a person under 18, we will immediately terminate the account and delete all associated personal information within 72 hours of discovery.
If you believe a minor has created an account on Cr8tiveHub, please notify us immediately at legal@cr8tivehub.com.
10. Push Notifications
We use Firebase Cloud Messaging (FCM) to deliver push notifications to your Android device. Notifications may include:
- New direct messages from other users
- Booking requests and confirmations
- Opportunity recommendations matching your profile
- Subscription and billing updates
- Platform announcements and feature updates
- Security alerts (e.g., new device sign-in)
You can disable push notifications at any time through your device's notification settings or within the Cr8tiveHub app settings. When you disable notifications or uninstall the app, your FCM push token is deleted from our systems.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by:
- Sending a notification to your registered email address
- Displaying an in-app notification within the Cr8tiveHub app
- Posting the updated policy on this page
Your continued use of Cr8tiveHub after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of the service and delete your account.
13. Contact & Complaints
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:
Contact details
Information Officer: Thokozani Dube (Registration 2026-011645)
Information Officer contact: admin@cr8tivehub.com
Privacy enquiries: legal@cr8tivehub.com
General support: support@cr8tivehub.com
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa:
Information Regulator of South Africa
Cr8tiveHub Digital Studios (Pty) Ltd. Registered in South Africa.