Vitaay Logo
HomeAbout UsBlogs

Privacy Policy

Last Updated: April 23, 2026

Effective Date: April 23, 2026

Website: https://www.vitaay.ai

Contact: connect@vitaay.ai

1. Introduction

Welcome to Vitaay ("Vitaay," "we," "us," or "our"). This Privacy Policy explains how Vitaay collects, uses, shares, and protects your personal information when you access or use the Vitaay platform, an AI-powered marketplace that connects brands with influencers and content creators to forge authentic marketing partnerships.

This Privacy Policy applies to all users worldwide, including users in the United States, the European Economic Area (EEA), the United Kingdom, Canada, India, Brazil, Australia, Japan, South Korea, and all other jurisdictions. By registering for, accessing, or using Vitaay in any capacity (as a Brand, Creator, or visitor), you agree to the terms of this Privacy Policy. If you do not agree, please do not use our platform.

2. Who We Are & Data Controller Information

Vitaay is operated from India and serves users globally. For the purposes of applicable data protection laws:

  • Data Controller (EEA/UK, GDPR/UK GDPR): Vitaay, accessible at connect@vitaay.ai, with EU/UK representative arrangements in place as required
  • Data Controller (USA): Vitaay as described above, with privacy rights exercised via connect@vitaay.ai
  • Data Controller (India, DPDPA): Vitaay, with user rights and grievance redressal available via connect@vitaay.ai in accordance with applicable Indian data protection laws

Vitaay serves two primary user categories:

  • Brands - Companies and businesses seeking to partner with creators for marketing campaigns
  • Creators - Influencers, content creators, and digital personalities seeking brand collaboration opportunities

3. Information We Collect

3.1 Information Provided by Brands

  • Company name, registered business details, and business registration number
  • Contact name, email address, phone number, and job title.
  • Product information and analytics (e-commerce): This includes details about your products, such as descriptions, pricing, inventory, and performance data (e.g., engagement, conversions, and sales metrics)
  • Industry category and campaign budget range
  • Campaign briefs, project details, and creative requirements
  • Billing and payment information (processed via secure third-party payment providers; we do not store full card details)

3.2 Information Provided by Creators

  • Full name, email address, and date of birth (to verify age eligibility)
  • Location (city or country)
  • Social media handles (such as Instagram, TikTok, YouTube, Twitter/X, and other connected platforms), along with associated analytics and information, including content, reach, engagement metrics (likes, comments, shares), and audience interactions.
  • Content niche and category (Fashion & Beauty, Lifestyle, Technology, Food & Cooking, Health & Fitness, Travel, Comedy, Education, Gaming, etc.)
  • Audience size and engagement rate data
  • Profile bio, content description, and portfolio samples
  • Banking or payment details for receiving compensation (processed securely via third-party providers)

3.3 Information Collected Automatically

  • IP address and approximate geographic location
  • Browser type, operating system, device identifiers, and screen resolution
  • Pages visited, time spent, click patterns, and navigation behavior on vitaay.ai
  • Referral sources and search terms used to reach our platform
  • Device advertising identifiers (IDFA/GAID) where applicable and consented
  • Cookies, web beacons, pixel tags, and similar tracking technologies (see Section 9)

3.4 Information from Third Parties

  • Social media platform APIs (where you grant permission) for verifying follower counts and engagement metrics
  • E-commerce platforms: Includes product details (descriptions, pricing), order data, and key performance metrics (such as conversions and sales) used for analytics and campaign optimization
  • Payment processors for transaction verification and fraud prevention
  • Identity verification providers (KYC/AML checks where legally required)
  • Analytics partners for platform performance data
  • Publicly available information (e.g., public social media profiles for creator verification)

3.5 Sensitive Personal Information

We do not intentionally collect sensitive personal information such as racial or ethnic origin, religious beliefs, health data, biometric data, or political opinions. Please do not submit such information. If such data is incidentally received, it will be deleted.

4. How We Use Your Information

For All Users (Brands and Creators):

  • To create, verify, and manage your account on the Vitaay platform
  • To facilitate introductions, AI-powered matches, and partnership agreements between brands and creators
  • To communicate with you about campaigns, opportunities, platform updates, and support
  • To process applications, agreements, and payments
  • To verify identity and eligibility, including age verification
  • To provide customer support and respond to enquiries
  • To improve platform features, user experience, and AI matching algorithms
  • To detect, investigate, and prevent fraud, abuse, spam, or violations of our Terms
  • To comply with applicable legal obligations across all jurisdictions in which we operate
  • To defend legal claims and protect the rights of Vitaay and its users

For Brands Specifically:

  • To match your campaign requirements with suitable creators using our AI systems
  • To provide campaign performance analytics and reporting dashboards
  • To manage billing, invoicing, and campaign budget allocation

For Creators Specifically:

  • To build and display your creator profile to relevant brands
  • To surface relevant brand partnership opportunities based on your niche and audience
  • To track campaign deliverables, milestones, and performance metrics
  • To calculate and process collaboration fees or compensation

Marketing Communications:

We may send you marketing emails or in-platform notifications about Vitaay features, promotions, and relevant industry news where you have opted in or where permitted by applicable law. You may opt out at any time using the unsubscribe link in any email or by contacting us at connect@vitaay.ai.

5. Legal Basis for Processing

5.1 GDPR (EEA & UK Users)

Where applicable under the General Data Protection Regulation (EU) 2016/679 and the UK GDPR, we process your personal data on the following legal bases:

  • Contract Performance (Art. 6(1)(b)) — Processing necessary to fulfill our agreements with you and provide platform services
  • Legitimate Interests (Art. 6(1)(f)) — To improve our platform, prevent fraud, maintain security, and conduct analytics
  • Consent (Art. 6(1)(a)) — Where you have explicitly provided consent (e.g., marketing communications, optional social API access, non-essential cookies)
  • Legal Obligation (Art. 6(1)(c)) — Where required by applicable European, UK, or other law

5.2 India (DPDPA 2023)

For users in India, we process personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA). Our legal bases include consent, contractual necessity, legitimate uses as defined under the Act, and compliance with legal obligations.

5.3 United States

For US residents, our data practices comply with applicable US federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (ColoPA), the Connecticut Data Privacy Act (CTDPA), and other applicable state laws. We do not sell personal information. We do not use sensitive personal information for purposes beyond those permitted under applicable law.

5.4 Canada (PIPEDA / Law 25)

For Canadian users, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws including Quebec's Law 25 (Act 25). We collect, use, and disclose personal information only with meaningful consent and for the purposes disclosed herein.

5.5 Brazil (LGPD)

For Brazilian users, we comply with the Lei Geral de Proteção de Dados (LGPD). We process personal data on applicable legal bases including consent, contract performance, legitimate interest, and legal obligation, as defined under the LGPD.

5.6 Australia (Privacy Act)

For Australian users, we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We handle personal information in accordance with these principles, including providing access and correction rights.

6. Data Sharing & Disclosure

We share your data only in the following circumstances, and never sell, rent, or trade your personal information to third parties for advertising or commercial purposes:

6.1 Between Brands and Creators

Core profile information — such as creator name, content niche, audience size, and social handles; or brand company name and industry — is shared to facilitate partnerships. Full contact details are only shared upon mutual agreement to collaborate.

6.2 Service Providers (Data Processors)

We engage trusted third-party vendors for hosting, cloud infrastructure, payment processing, email communications, analytics, identity verification, and security monitoring under strict data processing agreements (DPAs) that bind them to confidentiality and appropriate security obligations. Our key categories of service providers include:

  • Cloud hosting and infrastructure providers (e.g., AWS, Google Cloud, or equivalent)
  • Payment processors (e.g., Stripe, Razorpay, or equivalent)
  • Email and communication platforms
  • Analytics and performance tracking tools
  • Identity verification and fraud prevention services

6.3 Legal Compliance

We may disclose data when required by applicable law, valid court order, government authority, regulatory inquiry, or to protect the legal rights, safety, or property of Vitaay, our users, or the public.

6.4 Business Transfers

In the event of a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, user data may be transferred to the successor entity. We will provide advance notice to affected users and the successor entity will be bound by this Privacy Policy or provide equivalent protections.

6.5 Aggregated / Anonymized Data

We may share aggregated, anonymized, or de-identified data — which cannot reasonably be used to identify you — with partners, researchers, or the public for industry insights and platform improvement.

7. Data Security

We implement industry-standard and best-practice security measures to protect your personal information:

  • Encrypted data transmission using TLS 1.3 for all data in transit
  • AES-256 encryption for data stored at rest
  • Secure cloud infrastructure with restricted, role-based access controls
  • Regular security audits, vulnerability assessments, and penetration testing
  • Multi-factor authentication (MFA) options for user accounts
  • Employee data handling training and confidentiality agreements
  • Incident response procedures for breach detection and notification

While we take all reasonable and technically feasible precautions, no internet-based service can guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us immediately of any suspected unauthorized access.

8. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Our retention schedule includes:

Data CategoryRetention Period
Account profile dataDeleted within 30 days of account closure
Transaction & contract recordsUp to 7 years (financial/tax compliance)
Support & communications records3 years from last contact
Platform log dataUp to 12 months, then anonymized
Aggregated / anonymized analyticsRetained indefinitely (cannot identify individuals)

9. Cookies & Tracking Technologies

Vitaay uses cookies and similar technologies to enhance your experience, analyze usage, and improve our platform. We use the following categories of cookies:

  • Strictly Necessary Cookies — Required for platform operation, authentication, and security. Cannot be disabled.
  • Functional Cookies — Remember your preferences such as language and display settings.
  • Analytics Cookies — Understand how users interact with our platform (e.g., pages visited, session duration). Used with your consent.
  • Performance Cookies — Monitor platform speed and stability. Used with your consent.

We do not use cookies for third-party advertising or cross-site behavioral tracking.

You can manage cookie preferences through our in-platform cookie consent tool or your browser settings. For EEA/UK users, we obtain your consent before placing non-essential cookies, consistent with the ePrivacy Directive. For California users, our cookie practices comply with applicable CCPA/CPRA opt-out requirements.

10. Your Privacy Rights

10.1 Rights Available to All Users

  • Access — Request a copy of the personal data we hold about you
  • Correction / Rectification — Request correction of inaccurate or incomplete data
  • Deletion / Erasure — Request deletion of your personal data (subject to legal retention requirements)
  • Data Portability — Request your data in a structured, machine-readable format (JSON or CSV)
  • Objection — Object to certain types of data processing based on legitimate interests
  • Restriction of Processing — Request restriction of processing in certain circumstances
  • Withdrawal of Consent — Withdraw consent where processing is based on consent, without affecting prior processing

10.2 Additional Rights for California Residents (CCPA/CPRA)

  • Right to Know — Know what personal information we collect, use, disclose, and share about you
  • Right to Delete — Request deletion of personal information, subject to exceptions
  • Right to Correct — Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing — We do not sell or share personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information — We do not use sensitive personal information beyond permitted purposes
  • Right to Non-Discrimination — We will not discriminate against you for exercising your privacy rights

10.3 Additional Rights for EEA/UK Users (GDPR / UK GDPR)

EEA and UK residents may lodge a complaint with their national supervisory authority (e.g., the UK Information Commissioner's Office) if they believe their rights have been violated.

10.4 Additional Rights for Indian Users (DPDPA)

Indian users have rights under the DPDPA 2023, including the right to access information about personal data processed, the right to correction and erasure, and the right to grievance redressal. You may nominate a representative to exercise these rights on your behalf.

10.5 How to Exercise Your Rights

To exercise any of these rights, contact us at connect@vitaay.ai with the subject line: "Data Rights Request — Vitaay". Please include your full name, email address associated with your account, and a description of your request. We will verify your identity and respond within:

  • 30 days for GDPR / UK GDPR requests (extendable by 60 days for complex requests with notice)
  • 45 days for CCPA/CPRA requests (extendable by an additional 45 days with notice)
  • 30 days for DPDPA requests

11. Children's Privacy

Vitaay is strictly intended for users aged 13 years and above. We do not knowingly collect personal information from minors under 13 years of age (or the applicable age of majority in the user's jurisdiction, if higher).

In accordance with the Children's Online Privacy Protection Act (COPPA) in the United States and equivalent laws globally, if we become aware that a minor has registered on our platform, we will immediately delete their account and all associated personal data. If you believe a minor has submitted personal information to us, please contact us at connect@vitaay.ai.

12. Third-Party Links & Integrations

The Vitaay platform may link to or integrate with third-party social media platforms (Instagram, TikTok, YouTube, Twitter/X, LinkedIn, e-commerce) and other external services. These platforms have their own privacy policies, and we are not responsible for their data practices, privacy standards, or terms of service. We encourage you to review the privacy policies of any third-party services you connect with Vitaay.

When you authorize Vitaay to access your social media accounts via API, you are also subject to those platforms' terms and data policies. You may revoke Vitaay's access to these accounts at any time through the relevant platform's settings.

13. International Data Transfers

Vitaay is operated from India and may transfer your personal data to countries outside your home jurisdiction, including India, the United States, and other countries where our service providers operate. We ensure appropriate safeguards are in place for all cross-border data transfers, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for EEA data transfers
  • UK International Data Transfer Agreements (IDTAs) for UK data transfers
  • Compliance with India's DPDPA cross-border transfer provisions and any notified adequacy frameworks
  • Data processing agreements with all service providers receiving your data

By using Vitaay, you acknowledge that your data may be transferred to and processed in countries that may have different data protection standards than your home country. We take steps to ensure that your data receives an equivalent level of protection regardless of where it is processed.

14. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, Vitaay will:

  • Notify affected users within 72 hours of becoming aware of the breach (consistent with GDPR requirements)
  • Notify relevant supervisory authorities as required by applicable law
  • Notify the Indian Data Protection Board as required under the DPDPA
  • Notify affected US users as required by applicable US state breach notification laws
  • Take immediate remedial action to contain, investigate, and prevent recurrence of the breach
  • Provide details of the nature of the breach, data categories affected, likely consequences, and steps taken

15. AI & Automated Decision-Making

Vitaay uses AI and machine learning algorithms to match brands with creators, analyze platform performance, and detect fraudulent activity. Where this automated processing produces decisions that have a significant or legal effect on you:

  • EEA/UK users have the right not to be subject to solely automated decisions under GDPR Art. 22, and may request human review
  • We will explain the logic of significant automated decisions upon request
  • Our AI matching algorithms use data such as content niche, audience demographics, engagement rates, and campaign parameters — they do not use sensitive personal characteristics such as race, religion, or health data

16. Do Not Track & Global Privacy Control

Some browsers transmit "Do Not Track" (DNT) signals. Our platform currently does not alter its behavior in response to DNT signals due to the lack of a uniform industry standard. We do, however, honor Global Privacy Control (GPC) signals for California residents as required under CCPA/CPRA, which will be treated as an opt-out of the sale or sharing of personal information.

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, applicable law, or regulatory requirements. We will notify you of material changes by:

  • Sending an email notification to your registered email address at least 14 days before material changes take effect
  • Displaying a prominent notice on the Vitaay platform
  • Updating the "Last Updated" date at the top of this Policy

Your continued use of Vitaay after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree to material changes, please cease using the platform and contact us to close your account.

18. Contact — Privacy Enquiries

For any privacy-related questions, requests, or concerns, please contact:

Privacy Team: Vitaay

Email: connect@vitaay.ai

Subject Line: Privacy Enquiry — Vitaay

Website: https://www.vitaay.ai

Response Time: Within 30 days of receipt

VITAAY

Privacy PolicyTerms of Use© vitaay 2026