Privacy Policy
Version 1.1
Operator: Sixth Degree Creator Marketplace Inc., an Ontario corporation ("Sixth Degree"). Questions or requests: privacy@sixthdegree.app. Last updated: August 8, 2026 (named the corporation and its registered office).
We run a marketplace connecting brands and creators. This policy explains what personal information we collect, why, who we share it with, and your rights under Canada's federal privacy law (PIPEDA).
1. What we collect, and why
Everyone (account basics).
Email, display name, role, authentication records. Why: to operate your account and send transactional email (sign-in links, collaboration notifications).
Creators.
Instagram/TikTok handles, city and neighbourhood, niches, follower count, typical rate, links to sample posts, verification materials, Stripe payout onboarding status (identity documents are collected by Stripe directly, see §3). During collaborations: submitted content, captions, live post URLs, and screenshots of post insights you choose to upload. Why: verification, the creator directory brands search, running collaborations, and paying you.
Brands.
Business name, website, category, neighbourhood, Instagram handle, logo, a short business description, campaign briefs, and conversion figures you report. Why: running your campaigns and showing creators who they'd work with.
Payments.
We store payment status, amounts, and Stripe reference IDs. We never see or store card numbers or bank details. Those go directly to Stripe.
Short-link clicks (visitors who tap a creator’s link).
When anyone clicks a sixthdegree.app/r/… link we log: a pseudonymized IP (a salted hash; we never store the raw IP; the salt is rotated quarterly, which breaks long-term linkability), browser user-agent, the referring site's origin (path and query stripped), and a timestamp. Why: counting genuine clicks for campaign reporting and filtering bots. This is the only data we collect about people who aren't platform users, and it is not used to identify them.
Automated processing (AI).
Campaign brief drafts, content compliance checks, verification assistance, and reading metrics out of insight screenshots may be processed by third-party AI providers (currently Anthropic and/or DeepSeek). AI never decides verification, our team does, and AI-read metrics are always labeled creator-reported.
We do not collect: precise location, contacts, biometrics, or data from your social accounts beyond what you provide (no Instagram API access today; if that changes this policy will be updated first).
2. Consent
Creating an account and providing information is your consent to the uses described here. Where we introduce a materially new use, we'll ask again. You can withdraw consent by closing your account (§6), subject to information we must retain (e.g., payment records for tax law).
3. Who we share it with (service providers)
We use, and share only what each needs: Supabase (database/auth hosting), Vercel (application hosting), Stripe (payments and creator payout identity verification; Stripe acts as its own data controller for KYC), Resend (transactional email), Anthropic / DeepSeek (AI processing as described above). Some providers store data in the United States; by using the platform you consent to that cross-border processing. We do not sell personal information, ever.
Within the platform: brands see verified creators' directory profiles (handle, niches, city, follower count, rate if provided, track record); creators see brand business profiles and campaign briefs. Counterparties in a collaboration see what the collaboration requires (submissions, post URLs, reported metrics).
4. Retention
Account data: for the life of the account and up to 24 months after closure. Payment and collaboration records: 7 years (tax and audit). Click logs: retained pseudonymized; salt rotation quarterly severs linkability. Voided/corrected reporting rows are retained as an audit trail (append-only by design).
5. Safeguards
Row-level security on every table, role-scoped access, service credentials never exposed to browsers, TLS everywhere, least-privilege internal access, and a nightly reconciliation audit on payment records. No system is breach-proof: if a breach creates a real risk of significant harm we will report it to the Privacy Commissioner of Canada and notify affected people, as PIPEDA requires.
6. Your rights
Email privacy@sixthdegree.app to: access the personal information we hold about you, correct it, or close your account and have personal information deleted (except what law requires us to keep; we'll tell you what and why). We respond within 30 days. If unsatisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
7. Cookies and analytics
We use only the cookies needed to keep you signed in. No advertising or cross-site tracking cookies.
We use PostHog for privacy-preserving product analytics: no cookies are set for anonymous visitors (nothing links one visit to the next), no session recording, and your browser's Do Not Track setting is respected. Analytics data is hosted in the United States (see §3 on cross-border processing).
8. Children
The platform is for adults (18+). We do not knowingly collect information from minors; if you believe we have, contact us and we'll delete it.
9. Changes
Material changes are announced in-app or by email with a new version number. The current version lives at app.sixthdegree.app/privacy.
Accountable person (PIPEDA Principle 1): Rohan Gandotra, Privacy Officer, Sixth Degree Creator Marketplace Inc., 650 King Street West, Apartment 405, Toronto, Ontario M5V 0H6.