Privacy Policy
Date of Last Revision: July 13, 2026
In short. This policy covers users worldwide, including the EU (GDPR), the UK (UK GDPR), and US residents under state privacy laws (California CCPA/CPRA, Virginia, Colorado, Connecticut, Utah, and others — see Section 11B). Coaching calls and 1:1 sessions are confidential — we do not record, store, or access their content (see Section 5A).
Welcome to CreatorStore ("CreatorStore," "we," "us," or "our"). CreatorStore is a platform that enables content creators ("Creators") to monetize their digital goods, content, services, consultations, and subscriptions ("Creator Content"), and enables Creators' fans and followers ("Customers") to discover and purchase such Creator Content. Our platform includes our website at https://creatorstore.co/ and related services (collectively, the "Service").
This Privacy Policy explains the personal information we collect from Creators and Customers (collectively, "you") via our Service, how we use and share that information, and your choices and rights concerning our information practices.
CreatorStore Labs LLC is the controller of your personal information under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), and comparable US state privacy laws. If you have any questions or comments about this Policy, please contact us at .
PLATFORM NATURE — IMPORTANT NOTICE. CreatorStore is a technology platform, not a seller, publisher, retailer, or provider of Creator Content. We host storefronts and provide the tools that enable independent Creators to run their own businesses. Every Creator on the Service is an independent business. When you as a Customer interact with a Creator — browse their store, subscribe to their newsletter, book a session, or make a purchase — the Creator is a separate and independent controller of the personal information you share with them. The Creator may collect, use, retain, and process your personal information for their own purposes independently of us, including to fulfill your order, provide support, market their own products, and comply with their own legal obligations. Each Creator may also have their own Terms & Conditions and privacy notice that govern the purchase. CreatorStore is not responsible for the actions, decisions, or data-handling practices of Creators or other third parties. Please review Section 4 for important details.
1. Personal Information We Collect
Personal Information You Provide
Account and Profile Information: Your name, email address, phone number, address, profile photo, username, password, and any additional information you provide when creating an account or using the Service. When you contact us, we also collect the content of your communications.
Financial Information: Our payment processors Stripe, Inc. ("Stripe") and PayPal, Inc. ("PayPal") collect the financial information necessary to process payments. Your financial data is processed pursuant to Stripe's services agreement and privacy policy at https://stripe.com/privacy, and PayPal's privacy statement at https://www.paypal.com/legalhub/privacy-full.
Billing Metadata: From our payment processors, we receive limited billing metadata about your transactions, including the amount, currency, last four digits of the card used, card brand, billing region, and receipt reference. We do not receive or store full card numbers, CVV codes, or bank account credentials.
Communication Information: Information you provide when you contact us or respond to questionnaires, surveys, or feedback requests. Providing this is optional.
Commercial Information: A history of the Creator Content you browse, make available, and/or purchase.
Other Information: Other information not specifically listed here, which we will use as described in this Policy or as disclosed at the time of collection.
Information Collected Automatically
Log Information: IP address, browser type and settings, date and time of your request, and how you interacted with the Service.
Cookies Information: See our Cookie Policy at https://creatorstore.co/cookies for details.
Device Information: Device name, operating system, and browser. May depend on device type and settings.
Usage Information: How you use the Service, including content viewed, features used, actions taken, and the time, frequency, and duration of activities.
Location Information: Approximate location data based on your IP address.
2. How We Use Personal Information
To Operate and Deliver the Service. We rely on performance of our contract with you and our legitimate business interests to: provide, operate, maintain, and secure the Service; provide support, assistance, and troubleshooting; send updates about administrative matters such as changes to our terms or policies; facilitate transactions between Customers and Creators.
To Improve, Personalize, and Protect the Service. Enrich your user experience and customize your relationship with us; protect the security of the Service; prevent and detect security threats, fraud, or other criminal or malicious activities.
Research and Development. It is in our legitimate business interest to develop, analyze, and improve the Service. We may create or use aggregated, de-identified, or anonymized data for internal research and product improvement, as further described in Section 3.
To Comply with Legal Obligations and Defend Legal Claims: comply with applicable laws, lawful requests, and legal process; protect our, your, or others' rights, privacy, safety, or property; audit our compliance with legal and contractual requirements; enforce the terms that govern the Service; prevent, identify, investigate, and deter fraudulent, harmful, or illegal activity.
For Marketing. We may contact you about products or services we believe may interest you.
Direct marketing: We may send special offers by email. You may opt out at any time.
Legal basis for marketing. For users in the EEA and the UK, we rely on your explicit consent for marketing communications; you may withdraw that consent at any time. For users elsewhere (including the United States), we rely on our legitimate business interests and provide an easy opt-out mechanism in every marketing message and in your account settings. We do not use your data for third-party advertising, cross-context behavioral advertising, or the sale of personal information as defined under CCPA/CPRA.
To Facilitate Corporate Transactions. We may use your personal information in connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider.
3. Sharing and Disclosure of Personal Information
We may share the categories of personal information described above with:
Creators (for Customer purchases): When you purchase Creator Content, we share your information with the relevant Creator. We do so because it is necessary to perform the purchase contract between you and the Creator. See Section 4.
Vendors and Service Providers: Hosting and cloud providers, IT services, email and marketing providers, payment processors (Stripe and PayPal), customer support, and web analytics. These parties process personal information solely to perform their duties to us, under contract.
Professional Advisors: Lawyers, accountants, auditors, where necessary.
Business Transfers: In a merger, acquisition, due diligence, reorganization, bankruptcy, sale of assets, or service transition.
Legal Requirements: Where required by law or where we believe in good faith disclosure is necessary to comply with law, protect rights or property, prevent fraud, protect personal safety, or protect against legal liability.
Aggregated/Statistical Information: De-identified and aggregated information that cannot reasonably be used to identify you, shared for internal research, product improvement, and public reporting (such as blog posts about creator earnings trends). We do not sell aggregated information to third-party advertisers.
4. Personal Information You Make Available to Creators
This section is important. Please read carefully.
Our Service is a multi-party platform. When you, as a Customer, make purchases on a Creator's page, communicate with a Creator, or express interest in Creator Content, the Creator will receive your personal information, including your name, email address, billing information (as needed to fulfill the order), and any communications you send them.
The Creator is an independent controller of your personal information for purposes they determine independently of us, including: fulfilling your purchase and providing support; processing refunds, returns, and chargebacks; marketing their own products or services to you; and complying with their own legal obligations. Refunds are handled directly between the Customer and the Creator. CreatorStore is a technology platform and is not the merchant of record for the underlying sale; the Creator sets its own refund policy and remains responsible for honoring it. CreatorStore may, at its discretion, facilitate the technical processing of a refund through Stripe or PayPal, but assumes no obligation to do so and no liability for the underlying transaction.
Each Creator, by using the Service to collect Customer data, is bound by data processing terms incorporated into the Creator Agreement, and may have their own Terms & Conditions and privacy notice describing how they handle your data. Before completing a purchase, you will be asked to agree to the relevant Creator's Terms & Conditions in addition to this Privacy Policy.
CreatorStore is not responsible for the actions of Creators or other downstream recipients of your personal information. Please review the applicable policies of the Creator before making a purchase. If you have a dispute with a Creator about their handling of your personal information, please contact them directly. We may, but are not obligated to, assist.
4A. Platform Role and Limitation of Our Responsibility
CreatorStore provides technology infrastructure that enables Creators to sell and Customers to buy. CreatorStore is not a party to any transaction between a Creator and a Customer, does not deliver Creator Content itself, and does not provide the services offered by Creators (including coaching, consulting, education, or any other professional services).
Creators are solely responsible for: the quality, legality, and delivery of their content and services; interactions with their Customers (including messaging, sessions, and post-purchase support); compliance with the professional licensing, tax, consumer protection, and privacy laws that apply to their specific business and jurisdiction; and the terms of any agreement they enter into with their Customers.
Customers are responsible for: reviewing the Creator's Terms & Conditions before purchase; interacting with the Creator directly regarding the Creator's services; and reporting any concerns about a Creator's conduct or content-handling to us at .
CreatorStore is not liable for the acts, omissions, statements, or content of any Creator or Customer, or for any dispute between them. We may, but are not obligated to, assist in resolving disputes.
5. Google API Services — User Data and Limited Use
CreatorStore uses Google API Services to provide scheduling and video conferencing features. This section discloses how we access, use, store, and share Google user data, in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
Google APIs we use:
Google Calendar API — to read your free/busy availability and create, update, or cancel calendar events for confirmed bookings.
Google Meet integration (via Calendar API) — to automatically attach a Google Meet video conference link to bookings.
What Google user data we access:
Your free/busy time slots (read-only); event creation, update, and cancellation — for confirmed customer bookings only. We do NOT access event titles, descriptions, attendee lists, or any other calendar content outside what we create through our Service.
How we use Google user data:
Only to provide and improve the scheduling and video call features visible in our app. Not for advertising. Not shared with third parties, except service providers under contract (e.g., hosting providers) and only as necessary to operate the Service.
How we store Google user data:
We store the minimum data necessary: OAuth tokens, event IDs we created, and references for booking management. Tokens are encrypted in transit and at rest. We do not duplicate or store the content of your Google Calendar beyond what's required for booking operations.
How users can revoke access:
Disconnect your Google account at any time from your account settings in CreatorStore. Upon disconnection, we delete the OAuth tokens immediately and stop accessing your Google data. You may also revoke access directly from your Google Account: https://myaccount.google.com/permissions.
Human review:
We do not allow humans to read or access your Google user data, except: (a) with your explicit consent for support purposes, (b) for security investigations (e.g., abuse), (c) to comply with applicable law, or (d) when data is aggregated and anonymized for internal operations.
Limited Use compliance:
CreatorStore's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5A. Confidentiality of Coaching Calls, Sessions, and Live Events
Coaching calls, 1:1 sessions, live webinars, and video meetings booked through CreatorStore take place on third-party video services (Google Meet, Zoom, Whereby, or any other provider chosen by the Creator). CreatorStore is not a participant in these calls.
What we do NOT do:
The Service does not currently include any built-in call recording, transcription, or content-storage functionality. We do not access the audio, video, chat, screen-sharing, or any other content of a call. We do not store transcripts, recordings, or notes on our infrastructure. CreatorStore does not enable, configure, request, or receive recordings on any Meet link we generate. Any recording behavior of Google Meet or other third-party video services depends on the Creator's own account settings and provider defaults, which are outside of our control. If we introduce any recording or content-processing feature in the future, we will update this Policy and, where required by law, obtain your consent before it applies to you.
What we DO have:
Booking metadata only: your name, email, the time and date of the call, the product purchased, and the video link. This is what makes the booking work — nothing about what happens on the call.
How video links work:
Video links are provided in one of two ways: (a) the Creator connects their own Google account, and CreatorStore auto-generates a Google Meet link inside the Creator's calendar via the Google Calendar API — the Meet room lives on the Creator's Google account, not ours; or (b) the Creator manually enters their own video link from any provider (Zoom, Whereby, personal Meet, or any other service). In both cases, the call takes place entirely on the Creator's video account. CreatorStore does not host, join, record, or transcribe the call.
What the Creator does after the call:
Anything the Creator does during or after the call — taking notes, saving recordings on their own device or account, keeping a session log, sharing the recording with third parties — is the Creator's independent responsibility as a separate controller of your personal information, governed by any agreement you have with the Creator directly. CreatorStore has no visibility into and no control over these activities. See Section 4.
Third-party providers. Google Meet, Zoom, and other video services collect data under their own privacy policies. Please review the policy of the specific service used by your Creator.
Not for licensed medical practice. CreatorStore is not HIPAA-certified. The Service is designed for coaches, consultants, educators, and creators — not for licensed medical or mental-health practitioners transmitting Protected Health Information (PHI) as part of clinical care. If you are a licensed therapist, psychologist, dietitian, or other healthcare provider billing insurance for your services, please use a HIPAA-compliant platform with a Business Associate Agreement.
6. Your Rights and Choices
Depending on where you are based, and subject to applicable law, you may have the right to: access; correct; erase; restrict processing; data portability; opt out of the sale or sharing of your personal information for interest-based advertising; opt out of profiling that produces legal or similarly significant effects on you (such as credit decisions, hiring, or access to essential services) — we do not engage in profiling for such decisions; object to processing; and withdraw consent where we rely on it.
To exercise these rights, contact us at . We may require you to verify your identity. You may use an authorized agent where your jurisdiction allows. We will respond to your request within thirty (30) days for GDPR and UK GDPR requests, or forty-five (45) days for CCPA/CPRA requests, except where the law permits a reasonable extension. You are entitled to exercise these rights free from discrimination. We may have valid legal reasons to refuse a request and will inform you if so.
Limits on Your Rights and Choices. Your choices may be limited where fulfilling a request would impair the rights of others, our ability to provide a requested service, or our ability to comply with legal obligations.
Opt Out of Direct Marketing. Follow the unsubscribe instructions in any marketing message. You will continue to receive non-marketing emails (service updates, account notifications).
Limit Online Tracking. Manage your preferences via Cookie Settings in our website footer; block or delete cookies in browser settings (instructions at https://www.allaboutcookies.org/); use privacy plug-ins or browsers such as Brave, Privacy Badger, Ghostery, or uBlock Origin; opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.
"Do Not Track" and Global Privacy Control. Because there is no industry standard for "Do Not Track" signals, we currently do not respond to them. If you send us a Global Privacy Control (GPC) signal, we treat it as an opt-out request in accordance with applicable law.
7. Data Retention
We keep personal information only for as long as necessary for the purposes described in this Policy, after which we delete or de-identify it. Our retention criteria include the duration of your account, the time needed to provide the Service, and applicable legal, tax, and accounting requirements. As general guidance:
Account and profile data: for the life of your account, then deleted or de-identified within a reasonable period after closure (generally not exceeding two (2) years), unless longer retention is required by law.
Transaction, billing, and tax records: retained for the period required by applicable tax and accounting law (commonly up to 7 years).
Support and communications: retained for as long as needed to handle your request and for a reasonable period afterward.
Marketing data and consents: until you withdraw consent or opt out, plus a record of the opt-out itself.
Logs and security data: retained for a limited period for security, fraud-prevention, and troubleshooting purposes.
Where data is no longer needed but cannot yet be deleted (for example, in backups), we isolate it and protect it from further processing until deletion is possible.
8. Children
Our Service is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 for users in the EEA and the United Kingdom), consistent with the U.S. Children's Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation (GDPR), and the UK GDPR. If you believe a child has provided personal information to us, contact us at and we will endeavor to delete it.
9. Links to Other Websites
The Service may contain links to other websites we do not control, including Creator-owned websites and social media services. Information you share with these third parties is governed by their policies, not this one. Please contact them directly for information on their practices.
10. Data Storage, Sub-Processors, and International Transfers
CreatorStore uses cloud infrastructure and sub-processors that operate globally, including in the United States, the European Union, and other regions. Depending on the specific service and provider, your personal data may be stored and processed in any of these regions.
For users in the EEA and the United Kingdom: where your data is processed outside the EEA/UK, we rely on appropriate transfer safeguards under GDPR Chapter V — including the European Commission Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and the EU-US Data Privacy Framework certifications of our sub-processors where applicable. For a current list of sub-processors and transfer mechanisms, contact .
For users elsewhere (including the United States): your data may be stored and processed in the United States and other countries that provide our service infrastructure. Data protection laws in those countries may differ from the laws where you reside.
By using the Service, you acknowledge that the transfer and processing of your personal data across borders is necessary to provide the Service to you.
11. Security
You use the Service at your own risk. We implement commercially reasonable technical, administrative, and organizational measures to protect personal information. However, no internet or email transmission is ever fully secure or error-free. Please consider what information you share via the Service or email.
11A. Data Breach Notification
If we become aware of a Personal Data Breach as defined by the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, or comparable data protection laws — meaning a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information we hold — we will act as follows.
a. Notification to Supervisory Authorities. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority (for example, the UK Information Commissioner's Office, or the applicable Data Protection Authority in the EEA) without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware of it. Where we are unable to provide complete information within seventy-two (72) hours, we will provide the information in phases without further undue delay.
b. Notification to Affected Users. Where the breach is likely to result in a high risk to the rights and freedoms of affected users, we will communicate the breach to affected users without undue delay in clear and plain language, describing the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address the breach. Communication may be by email, in-Service notification, or, where individual notification would involve disproportionate effort, by public communication or equivalent effective measure.
c. Notifications Under U.S. State Laws. Where a breach affects U.S. residents whose personal information is subject to state data breach notification laws (including but not limited to California Civil Code §§ 1798.29 and 1798.82), we will provide notifications in accordance with the timing, content, and method requirements of those laws.
d. Notification to Creators (as Independent Controllers). Where the breach affects personal data that a Creator processes as an independent or joint controller, we will notify the affected Creator without undue delay so they may fulfill their own notification obligations. Creators are solely responsible for their own onward notifications to their Customers and to competent authorities.
e. Records. We maintain internal records of all Personal Data Breaches, including the facts of the breach, its effects, and the remedial action taken, in accordance with Article 33(5) GDPR.
f. Cooperation. Where a Creator suffers a Personal Data Breach affecting personal data processed on their behalf by CreatorStore, we will cooperate reasonably with the Creator's investigation and provide the assistance required by the Data Processing Addendum incorporated into the Creator agreement.
11B. U.S. State Privacy Rights (California, Virginia, Colorado, Connecticut, Utah, and Others)
This Section provides additional disclosures required by U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), the Utah Consumer Privacy Act ("UCPA"), and comparable state laws.
a. Categories of Personal Information We Collect. In the past twelve (12) months we have collected the categories of personal information described in Section 1, which correspond to the following statutory categories: identifiers (name, email, IP address, account identifiers); customer records (billing and address information); commercial information (transactions, product interactions); internet or other network activity (browsing, usage data); geolocation data (approximate, IP-based only); professional or employment information (where you provide it); inferences drawn from the above; and sensitive personal information limited to account credentials (login and password). Identity verification of Creators for payment purposes is performed by our payment processors (Stripe and PayPal) directly; CreatorStore does not receive, view, or store government-issued identity documents. We do not collect or process biometric information (such as fingerprints, retina scans, voice prints, or facial geometry).
b. Purposes. We use these categories for the purposes described in Section 2 (operating the Service, security, marketing, legal compliance, and corporate transactions).
c. Categories Sold or Shared. We do not sell or share personal information in exchange for monetary or other valuable consideration, and we do not use it for targeted advertising as defined under the CCPA/CPRA, VCDPA, CPA, CTDPA, or UCPA. We do not knowingly sell or share personal information of consumers under sixteen (16) years of age.
d. Do Not Sell or Share My Personal Information; Opt Out of Targeted Advertising. California, Virginia, Colorado, Connecticut, and other state residents have the right to opt out of the sale or sharing of their personal information and targeted advertising. To exercise this right, use the "Do Not Sell or Share My Personal Information" link in our website footer, or email us at . We are implementing support for Global Privacy Control ("GPC") signals; if you send us a GPC signal, we will treat it as an opt-out request in accordance with applicable law.
e. Sensitive Personal Information. California residents may limit our use of "sensitive personal information" to purposes specified by law. We do not use sensitive personal information for purposes that would trigger this right.
f. Rights of Residents. Depending on the state where you reside, you may have the right to (i) know what personal information we hold about you; (ii) receive a copy in a portable format; (iii) correct inaccurate personal information; (iv) delete personal information (subject to permitted exceptions); (v) opt out of sale, sharing, or targeted advertising as described in (d); (vi) opt out of profiling that produces legal or similarly significant effects (we do not currently engage in such profiling); and (vii) not be discriminated against for exercising these rights. To exercise these rights, contact . We may require you to verify your identity before responding.
g. Authorized Agents. You may use an authorized agent to submit privacy requests on your behalf in states that permit this, subject to identity verification of the agent and, in some cases, of you.
h. Appeals. Virginia, Colorado, and Connecticut residents may appeal any refusal to act on a privacy rights request by emailing (Subject: "Privacy Rights Appeal"). We will respond to the appeal within the timeframe required by applicable law.
i. Retention. Our retention practices are described in Section 7.
j. Shine the Light (California). Under California Civil Code § 1798.83, California residents may request information about our disclosure of personal information to third parties for those third parties' direct marketing purposes during the immediately preceding calendar year. We do not disclose personal information to third parties for those third parties' own direct marketing purposes.
k. Users in Other US States. If you reside in a US state that has not yet enacted a comprehensive privacy law (such as New York, Illinois, Pennsylvania, Massachusetts, Michigan, Ohio, Georgia, or others), this Policy still applies to you in full. We offer the privacy practices described above — including access, correction, deletion, and opt-out from marketing — to all users worldwide as a matter of policy, in addition to any rights you have under your state's data breach notification (e.g., New York SHIELD Act), information security, and consumer protection laws.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version and update the "Date of Last Revision." For material changes, we will provide additional notice (e.g., email or in-Service notification) at least thirty (30) days before the changes take effect. Where the change materially reduces your rights or requires your consent under applicable law (including GDPR), we will obtain your explicit consent before applying the change to you. For non-material changes, your continued use of the Service after the update constitutes acknowledgment of the revised Policy.
13. Contact Us
CreatorStore Labs LLC
30 N Gould St, STE R, Sheridan, WY 82801, USA
Email:
EU and UK Representative. CreatorStore is in the process of appointing designated representatives in the European Union and the United Kingdom pursuant to Article 27 of the GDPR and the UK GDPR. Until such representatives are formally designated, users in the EEA and the UK may contact us directly at for all privacy-related matters. We will publish contact details for our representatives on this page once appointed.
If you wish to lodge a complaint, please contact us first. Depending on where you reside, you may also have the right to complain to a data protection regulator: in the UK, the Information Commissioner's Office (ICO) at ico.org.uk; in the EEA, your local Data Protection Authority (a list is maintained by the European Data Protection Board at edpb.europa.eu); in California, the California Attorney General's office at oag.ca.gov/privacy.