Privacy Policy
This Privacy Policy explains how Cr8tiveHub Digital Studios (Pty) Ltd. collects, uses, shares, and protects your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). It is the single, company-wide Privacy Policy covering all Cr8tivehub properties: the public website at cr8tivehub.com, the Cr8tivehub mobile application, the account portal at accounts.cr8tivehub.com, and the agency portal at agency.cr8tivehub.com.
1. Who We Are
Cr8tiveHub Digital Studios (Pty) Ltd. (“Cr8tiveHub”, “we”, “us”, “our”) operates the public website at cr8tivehub.com, the Cr8tiveHub mobile application (available on Android), the web account portal at accounts.cr8tivehub.com, and the agency portal at agency.cr8tivehub.com.
We are a South African company registered as a responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). Our Information Officer is Thokozani Dube, registered with the Information Regulator of South Africa under registration number 2026-011645 in accordance with section 55 of POPIA.
Information Officer contact: admin@cr8tivehub.com.
Cr8tiveHub is a creative talent marketplace that connects creative professionals — including musicians, actors, photographers, DJs, producers, stylists, and other creatives — with individuals and organisations seeking creative talent across Africa.
For any privacy-related enquiries, you may contact us at legal@cr8tivehub.com.
2. Information We Collect
We collect the following categories of personal information when you use our services. For each category, we describe what we collect, why, and the legal basis under POPIA that permits the processing.
Account Data
What: Full name, email address, profile photo, bio, city, country, profession, and hashtags.
Why: To create and maintain your account, enable discovery by other users, and personalise your experience.
Legal basis: Contractual necessity (section 11(1)(b) of POPIA) — this data is required to provide the service you signed up for.
Private Data
What: Phone number, date of birth, and full legal name. This data is held in a restricted, access-controlled store with owner-only access — no other users or staff can view it without explicit authorisation.
Why: For identity verification, age verification (our service is restricted to users aged 18 and older), and account recovery.
Legal basis: Contractual necessity and legal obligation (sections 11(1)(b) and 11(1)(c) of POPIA).
Content Data
What: Portfolio items (images, video, audio), credits, and opportunities posted.
Why: To provide portfolio showcasing, opportunity listing, and talent discovery features — the core of our service.
Legal basis: Contractual necessity (section 11(1)(b) of POPIA).
Usage Data
What: Login timestamps, session data, feature usage, and last active timestamp.
Why: To improve our service, detect security anomalies, and maintain platform integrity.
Legal basis: Legitimate interest (section 11(1)(f) of POPIA) — we have a legitimate interest in understanding how our service is used and ensuring its security.
Device Data
What: Firebase Cloud Messaging (FCM) push notification tokens (Android).
Why: To deliver push notifications about messages, application updates, and platform updates.
Legal basis: Consent (section 11(1)(a) of POPIA) — you may disable push notifications at any time via your device settings.
Financial Data
What: Subscription tier, billing cycle, and transaction records. We do not store credit or debit card numbers — payment card data is handled exclusively by PayFast (Pty) Ltd, our PCI DSS-compliant payment processor.
Why: To manage your subscription, process billing, and maintain financial records as required by law.
Legal basis: Contractual necessity and legal obligation (sections 11(1)(b) and 11(1)(c) of POPIA).
Verification Data
What: Your verification result (verified, not verified, or in review), which of the identity checks below passed, the type and issuing country of the identity document you used, and a record of your consent.
Why: To establish trust and authenticity on the platform, helping talent seekers identify verified professionals.
Legal basis: Consent (section 11(1)(a) of POPIA) — verification is voluntary. You can use Cr8tiveHub without it.
Biometric Data (identity verification only)
What: If you choose to verify your identity, a photograph of your identity document, a live selfie and a liveness check are captured, and the selfie is compared against the photograph on the document (a face match).
How — Didit (our primary method): The check is performed by our identity-verification provider Didit, acting as our operator under section 21 of POPIA. You capture your document, selfie and liveness recording in Didit's verification flow, and Didit performs the document, liveness and face-match checks. We do not receive or store your identity document images, your selfie or the liveness recording. Didit returns to us only the result (verified, not verified, or in review), which checks passed, and the document type and issuing country. If Didit cannot reach a decision automatically, a trained member of the Cr8tiveHub team decides using Didit's result.
How — in-app review (fallback): On older versions of the app, or if we temporarily switch away from Didit, the check is done in the Cr8tiveHub app instead: you take a selfie with a short liveness check (you are asked to blink and turn your head), with face detection running on your device, and you upload a photograph of your identity document. The selfie and document image are stored in our Google Cloud Storage (EU region) and reviewed by a trained member of the Cr8tiveHub team.
Why: To confirm that the person creating the profile is the person on the identity document. This is what makes a verified badge mean anything to a casting director, and it is the only purpose we use this data for. We do not use it for surveillance, advertising, or to identify you anywhere else on the platform.
Legal basis: Facial images used to identify you are special personal information under section 26 of POPIA. We process them only with your express written consent under section 27(1)(a), which you give in the app before the check begins. Verification is entirely optional and you may decline or withdraw at any time.
Retention: Under Didit, the images and liveness recording are held by Didit, not by us, for six months, and they are deleted sooner than that if you erase your account — when your account is erased we delete your verification session at Didit as well. Six months is the shortest period that still allows us to reconsider a decision you question, including an objection to an automated decision under section 71, which we answer within 30 days. Under the in-app fallback, the selfie and the identity document image are deleted once a decision has been made, and a storage rule deletes anything left over after 90 days at the latest. In both cases what we keep afterwards is the outcome — the result, which checks passed, the document type and issuing country, and your consent record — not the images themselves. If you delete your account, the verification record is erased with it.
Agency Verification Data
What:When an agency owner verifies their agency, they upload a company registration document issued by the CIPC (for example a CoR 14.3 or a disclosure certificate) and identity documents: if the owner is a listed director, a certified copy of their own ID; if not, a copy of their own ID, a certified copy of the ID of a director who can sign for the company, and a letter of appointment signed by that director. These documents contain personal information about the agency owner and, where applicable, a director — a third party — whose information the owner provides on the director's behalf. As an alternative, we may use Didit's business verification, in which Didit checks the company against the company registry and verifies a director's identity; in that case we receive only the result of those checks, not the company documents or the director's personal data.
Why: To confirm that an agency is a real, registered business and that the person acting for it is authorised to do so. Agencies must be verified before they can publish opportunities to creatives.
Legal basis: Legitimate interest (section 11(1)(f) of POPIA) in protecting creatives from fraudulent or exploitative opportunities, and contractual necessity (section 11(1)(b)) in respect of the agency owner.
Retention: Uploaded documents are reviewed by the Cr8tiveHub team and deleted once a decision has been made. We keep the outcome of the verification. The verification record is erased when the agency owner's account is erased.
Location Data
What: City, country, and latitude/longitude (if provided for discovery).
Why: To enable location-based discovery of creative talent and opportunities.
Legal basis: Consent (section 11(1)(a) of POPIA) — providing precise location is optional and can be withdrawn at any time.
Communications
What: Direct messages, live stream chat, and notification history.
Why: To enable communication between users, deliver notifications, and maintain records for safety and content moderation.
Legal basis: Contractual necessity (section 11(1)(b) of POPIA).
Behavioural Data
What: Follow relationships, portfolio likes/views, opportunity applications, and match scores.
Why: To power our discovery and matching algorithms, improving the quality of recommendations for both creatives and talent seekers.
Legal basis:Legitimate interest (section 11(1)(f) of POPIA) — we have a legitimate interest in improving the relevance of our platform's recommendations.
Website Browsing Data
What: IP address, user-agent string, page URLs visited, time of visit, referrer.
Why: Site security (rate limiting, abuse detection), basic operational logging, troubleshooting.
Legal basis: Legitimate interest (section 11(1)(f) of POPIA).
Retention: Server access logs retained for 90 days, then purged.
Inquiry & Agency Contact Form Data
What: Name, email address, organisation name (optional), message text submitted through enquiry or agency contact forms on cr8tivehub.com.
Why: To respond to your enquiry about partnerships, agency sign-up, press, or general questions.
Legal basis: Consent (section 11(1)(a) of POPIA).
Retention: 24 months after the last interaction relating to that enquiry, then deleted.
Newsletter / Mailing List (if you opt in)
What: Email address, plus (optional) name and area of interest.
Why: To send you product updates, opportunities, or news you have asked to receive.
Legal basis: Consent (section 11(1)(a) and section 69 of POPIA).
Retention: Until you unsubscribe. Every email contains a one-click unsubscribe link.
Cookies and Similar Technologies
Our websites use only strictly necessary cookies and similar technologies — for signing in and bot protection. We do not use analytics or marketing cookies on our websites. See the Cookies section of this policy for details.
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing and improving the service: Operating the Cr8tiveHub platform, maintaining your account, and developing new features.
- Matching creatives with opportunities: Using our automated matching algorithm to connect creative professionals with relevant opportunities and talent seekers.
- Enabling live streaming and portfolio features: Hosting and delivering your portfolio content and live streams to other users.
- Processing subscription payments: Managing billing, subscriptions, and transaction records through our payment processor PayFast.
- Sending push notifications and emails: Delivering important account notifications, application updates, messages, and (where you have opted in) marketing communications.
- Responding to enquiries: Responding to enquiries, agency sign-up requests, and contact-form messages submitted through our website.
- Sending newsletters and updates: Sending you newsletters and updates where you have opted in.
- Content moderation and safety: Automatically scanning uploaded media to detect and prevent illegal or harmful content, and reviewing flagged content to maintain community safety.
- Fraud prevention and security: Detecting and preventing fraudulent activity, unauthorised access, and abuse of the platform, including bot traffic and spam.
- Legal compliance: Fulfilling our obligations under South African law, including POPIA, the Companies Act 71 of 2008, and tax legislation administered by SARS.
- Analytics and product improvement: Understanding usage patterns to improve the user experience and develop features that better serve our community.
We do not sell your personal information. We do not share it with third parties for their own marketing.
4. Cross-Border Data Transfers & Third-Party Processors
We use the following third-party service providers to operate Cr8tiveHub. Where data is transferred outside of South Africa, we ensure appropriate safeguards are in place as required by section 72 of POPIA.
Google Firebase (Google LLC, United States)
Services: Authentication, Firestore database, Cloud Functions, Cloud Storage, Firebase Cloud Messaging (FCM) push notifications, Crashlytics (crash reporting from the mobile app), App Check (abuse protection for our APIs), Remote Config (feature settings), ML Kit face detection (runs on your device; used only in the in-app verification fallback), and the Cloud Vision API (automated content moderation of uploaded images and video frames).
Data transferred: User profiles, authentication data, portfolio content, messages, usage data, crash logs and device information, and uploaded media while it is scanned for moderation.
Data location: Our Firebase project is configured to store data, and to run Cloud Functions, in the Belgium (EU)region (europe-west1). Belgium is a member of the European Union, which is recognised as providing an adequate level of data protection under POPIA. Some services — Crashlytics, the Cloud Vision API, Cloud Messaging, App Check and Remote Config — may process data in the United States or on Google's globally distributed infrastructure.
Safeguards:Google's Standard Contractual Clauses (SCCs) and adequacy decisions provide additional protection for any data that may be processed in the United States.
Privacy policy: https://policies.google.com/privacy
PayFast (PayFast (Pty) Ltd, South Africa)
Services: Payment processing for subscriptions.
Data transferred: Name, email address, payment amount, and subscription tier. No credit or debit card data ever touches our servers — all card processing is handled entirely by PayFast.
Data location: PayFast is a South African entity. No cross-border data transfer occurs for payment processing.
Safeguards: PayFast is PCI DSS compliant, ensuring the highest standards of payment data security.
Privacy policy: https://www.payfast.co.za/legal/privacy-policy
Apple (Apple Inc., United States) and Google (Google LLC, United States)
Services: In-app purchases made through Google Play — currently the verification badge and visibility boosts. Purchases through the Apple App Store are coming soon and are not yet available.
Data transferred: The purchase itself is handled entirely by the store. We receive a transaction identifier and the purchase status so we can grant what you bought. We never receive your card number, and the store does not tell us your billing address.
Safeguards: Standard Contractual Clauses (SCCs) for data transferred to the United States.
Privacy policy: apple.com/legal/privacy · policies.google.com/privacy
Typesense (Typesense Cloud)
Services: The hosted search index (Typesense Cloud) that powers talent discovery and agency search.
Data transferred: Only the public fields of a creative profile — professional name, professions, location, and the attributes you have chosen to make visible. Contact details, identity documents and private data are never indexed.
Data location: The region of our Typesense Cloud cluster is being confirmed and will be stated here.
Safeguards:Processed under Typesense's data-processing terms for Typesense Cloud.
Privacy policy: typesense.org/privacy
LiveKit (LiveKit Inc, United States)
Services: Real-time live streaming infrastructure.
Data transferred: Audio/video streams and room metadata.
Safeguards: Standard Contractual Clauses (SCCs) are in place to ensure an adequate level of data protection for data transferred to the United States.
Privacy policy: https://livekit.io/privacy
Google reCAPTCHA (Google LLC, United States)
Services:Bot prevention on the public website's report and enquiry forms, and — through Firebase App Check — on the account portal and the agency portal.
Data transferred: Browser behaviour signals and IP address.
Safeguards:Google's Standard Contractual Clauses (SCCs).
Privacy policy: https://policies.google.com/privacy
SendGrid (Twilio Inc., United States)
Services: Delivery of all email sent by the platform — account and security emails, notifications, transactional email, and the newsletter.
Data transferred: Email address, and any name or content included in the email.
Data location: United States.
Safeguards: Standard Contractual Clauses (SCCs) are in place to ensure an adequate level of data protection for data transferred to the United States.
Didit (Didit Identity Spain, S.L. and Didit Identity, Inc.)
Services:Identity verification for creatives — identity document check, live selfie, liveness detection and face match — and, where we use it, business verification for agencies (a company registry check and a director's identity check). Didit acts as our operator under section 21 of POPIA.
Data transferred:The identity document images, selfie and liveness recording you capture in Didit's verification flow, and the personal information Didit reads from your document. These are collected by Didit directly; we do not receive them. Didit returns to us only the verification result, which checks passed, and the document type and issuing country.
Data location:Didit Identity Spain, S.L. (Calle Nápoles 227, 08013 Barcelona, Spain) operates Didit's EU data plane, and Didit Identity, Inc. (Delaware, United States) serves Didit's global customers. Your verification data may therefore be processed in the European Union and/or the United States.
Safeguards:Didit states that it relies on the European Commission's 2021 Standard Contractual Clauses and on adequacy decisions for international transfers. Didit keeps the verification media for six months, and we delete your verification session at Didit when your account is erased.
Privacy policy: https://didit.me/terms/privacy-policy/
Vercel (Vercel Inc., United States)
Services: Hosting of our websites — cr8tivehub.com, accounts.cr8tivehub.com, agency.cr8tivehub.com and our internal administration console.
Data transferred: IP address, request metadata and server logs, and the personal information that passes through those websites when you use them.
Data location:United States and Vercel's globally distributed network.
Safeguards:Vercel's data processing addendum.
Privacy policy: https://vercel.com/legal/privacy-policy
Google AdMob (Google LLC, United States)
Services: Advertising in the mobile app, shown only to users without an ad-free subscription.
Data transferred: Advertising ID (only if you allow it), device data, and ad interaction events.
Safeguards:Google's Standard Contractual Clauses (SCCs). Personalised ads are shown only with your consent, collected through Google's consent tool in the app.
Privacy policy: https://policies.google.com/privacy
5. Data Retention
We retain your personal information only for as long as is necessary for the purposes described in this policy, or as required by applicable law. The following table summarises our retention periods:
| Data Type | Retention Period |
|---|---|
| Active account data | Duration of account + 3 years after last activity |
| Deleted account data | Deactivated immediately; permanently erased after 30 days (support can restore the account within those 30 days). Erasure includes deleting your verification session at Didit. |
| Transaction / payment records | 7 years (SARS and Companies Act compliance) |
| Audit / security logs | 5 years |
| Push notification tokens | Until logout or app uninstall |
| Messages | Duration of account, deleted with account |
| Verification records (result, checks passed, document type and issuing country, consent record) | Duration of account, erased with the account |
| Identity images (in-app fallback) and agency verification documents | Deleted once a verification decision is made (90 days at most for in-app fallback images) |
| Identity images and liveness recordings held by Didit | Held by Didit for six months; deleted at Didit sooner if your account is erased |
| Backup data | Encrypted backups retained for 30 days, then purged |
When data is deleted, anonymised transaction records may be retained for up to 7 years as required for financial compliance under the Companies Act 71 of 2008 and SARS tax legislation.
6. Your Rights Under POPIA
As a data subject under the Protection of Personal Information Act, you have the following rights:
- Right of access (section 23): You have the right to request confirmation of whether we hold personal information about you, and to request a copy of that information. Submit your request to support@cr8tivehub.com.
- Right to correction (section 24): You have the right to request correction of inaccurate, incomplete, or misleading personal information. You can update most information directly through the Cr8tiveHub app or the web account portal at accounts.cr8tivehub.com/settings.
- Right to deletion (section 24): You have the right to request deletion of your personal information. You can delete your account through the app or by contacting support. Upon deletion, your account is deactivated immediately and your data is permanently erased after 30 days, subject to the retention periods described above. Within those 30 days you can ask support to restore your account. Erasure includes deleting your identity-verification session held by Didit.
- Right to object (section 11(3)): You have the right to object to processing of your personal information for direct marketing purposes. You can opt out of marketing communications at any time via your notification settings or by contacting us.
- Right to object to automated processing (section 71): You have the right to object to decisions made solely by automated means, including our opportunity matching algorithm and automated identity-verification decisions, and to ask for a human review. See the Content Moderation & Automated Processing section below for details.
- Right to lodge a complaint: If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the Information Regulator of South Africa.
Information Regulator of South Africa
7. Security
We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. These measures include:
- Access controls restricting database and storage access to authorised users only.
- HTTP-only session cookies that cannot be accessed by client-side JavaScript, reducing the risk of cross-site scripting (XSS) attacks.
- Encryption in transit using TLS 1.2 or higher for all data transmitted between your device and our servers.
- Encrypted backups ensuring data at rest is protected.
- Automated content moderation to detect and remove harmful content.
- Rate limiting and fraud detection on authentication and sensitive API endpoints.
- CSRF protection on all mutating API endpoints.
While we implement robust security measures, no system can guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Regulator as required by section 22 of POPIA as soon as reasonably possible after discovery of the breach.
8. Content Moderation & Automated Processing
Automated Content Moderation
We use automated content moderation to scan uploaded media for illegal or harmful content. This includes detection of nudity, violence, and other content that violates our Acceptable Use Policy. Content may be removed and users notified without prior notice if a violation is detected.
Opportunity Matching Algorithm
Our platform uses an automated matching algorithm that analyses your profile data, skills, location, and behavioural data (such as portfolio engagement and application history) to recommend relevant opportunities and surface your profile to talent seekers. This is an automated decision-making process as defined by section 71 of POPIA.
Automated Identity Verification
When you verify your identity through Didit, Didit's systems automatically check your identity document, liveness and face match and may approve or decline the verification without a person reviewing it. A decline means you do not receive the Identity Verified badge, so this is an automated decision that can significantly affect you under section 71 of POPIA. Where Didit cannot decide automatically, a trained member of the Cr8tiveHub team makes the decision using Didit's result.
If your verification is declined automatically and you believe the decision is wrong, you can ask for it to be reviewed by a person by contacting support@cr8tivehub.com. You can also make your representations about the decision to us in the same way. You may also simply try again — retries are included in the one-off verification payment.
Your Right to Object
You have the right to object to decisions made solely by automated means that significantly affect you. If you wish to object to automated processing or request human review of an automated decision, please contact us at legal@cr8tivehub.com. We will review your request and respond within 30 days.
9. Children's Privacy
Cr8tiveHub is strictly intended for users aged 18 years and older. We do not knowingly collect, process, or store personal information from anyone under the age of 18.
Signing up requires a date of birth, and an account that gives a date of birth under 18 cannot be created.
If an account is nevertheless found to belong to a person under 18, it is removed from public view and from discovery. The public profile is taken down, the account is removed from search and from every public listing, other people cannot browse or contact it, and it cannot host a live stream. Where the account's own details show the person is under 18 — or simply do not establish that they are an adult — this happens automatically, without waiting for anyone to review it.
A member of our team then deals with the account and deletes the personal information held for it. We do not destroy a suspected minor's account automatically on a timer: an account that is the subject of a child-safety concern may hold the only record of what happened to that child, and erasing it the moment it is flagged would erase that record too. Deletion is therefore a deliberate, recorded step taken by a person.
You do not have to wait for us to find it. Anyone — a parent, a guardian, or the young person themselves — can ask us directly to remove an account and delete the information held for it, and we will act on that request.
If you believe a minor has created an account on Cr8tiveHub, please notify us immediately at legal@cr8tivehub.com.
10. Push Notifications
We use Firebase Cloud Messaging (FCM) to deliver push notifications to your Android device. Notifications may include:
- New direct messages from other users
- Opportunity recommendations matching your profile
- Subscription and billing updates
- Platform announcements and feature updates
- Security alerts (e.g., new device sign-in)
You can disable push notifications at any time through your device's notification settings or within the Cr8tiveHub app settings. When you disable notifications or uninstall the app, your FCM push token is deleted from our systems.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by:
- Sending a notification to your registered email address
- Displaying an in-app notification within the Cr8tiveHub app
- Posting the updated policy on this page
Your continued use of Cr8tiveHub after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of the service and delete your account.
13. Contact & Complaints
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:
Contact details
Information Officer: Thokozani Dube (Registration 2026-011645)
Information Officer contact: admin@cr8tivehub.com
Privacy enquiries: legal@cr8tivehub.com
General support: support@cr8tivehub.com
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa:
Information Regulator of South Africa
Cr8tiveHub Digital Studios (Pty) Ltd. Registered in South Africa.