Our approach
We collect the information needed to operate creator economic workflows. We do not sell personal information or use customer confidential information for cross-customer model training without explicit permission.
1. Scope
This policy applies to CollabBook websites, Creator workspaces, Brand workspaces, support interactions, and related services. Future Brand capabilities are covered when they are made available and enabled.
2. Information we collect
Account and organization information
We receive information such as your name, email address, profile image, company, role, workspace membership, and account identifier. Our authentication provider handles sign-in credentials. CollabBook does not receive your password.
Creator and business records
Creator workspaces may contain creator profiles, brand contacts, opportunities, deals, rates, deadlines, invoices, payment status, notes, and portfolio information. Brand workspaces may contain brands, creator counterparties, engagements, contracts, amendments, obligations, deliverables, usage rights, purchase orders, invoices, payments, exceptions, approvals, comments, and audit history.
Documents and evidence
We store files you upload or import, including contracts, amendments, invoices, delivery evidence, and supporting records. We may create structured records, document versions, hashes, excerpts, and source references so the service can explain where information came from.
Connected services and imported data
If you connect a supported platform or business system, we receive the information authorized by that connection. This may include public social statistics, email or calendar metadata, and records imported from creator, finance, procurement, or payment systems. Connection credentials are handled separately from imported business records.
Invited creator activity
When a brand enables creator transparency, we may record invitation, authentication, viewing, confirmation, submission, discrepancy, upload, and access revocation events.
Usage, device, and diagnostic information
We collect information needed to operate and secure the service, such as IP address, browser and device type, pages and features used, timestamps, error reports, security events, and approximate location derived from an IP address.
3. How we use information
- Provide, secure, support, and improve CollabBook.
- Create and maintain workspaces, permissions, records, documents, and audit history.
- Provide available workflow features you request, which may include contract analysis, record organization, and reconciliation.
- Run AI features you request, including extraction, grounded analysis, explanations, and draft actions.
- Operate connected services, imports, exports, notifications, and customer support.
- Process subscriptions and maintain billing, tax, and transaction records.
- Detect misuse, investigate incidents, enforce our terms, and comply with law.
4. AI and document processing
When you request an AI feature, CollabBook sends the information needed for that request to an AI service provider. Source documents and imported content are treated as untrusted data and cannot authorize external actions. AI output may be stored with source references, model information, and review history when needed to provide the feature.
We do not use customer confidential information for cross-customer training, benchmarking, or model improvement unless the customer has given explicit contractual or product permission.
6. Retention, export, and deletion
We retain account and workspace information while the account or customer relationship is active and as needed to provide the service. Retention may also be set by a customer agreement or workspace configuration.
Available export and deletion tools vary by product. A Brand order may state the applicable deletion and retention scope. Brand workspace owners can export Phase 1 workspace records. Some security, audit, billing, tax, backup, and legal records may be retained for a limited period when required or permitted by law. Billing and tax records may be retained for up to seven years.
Revoking a connected service stops future syncs. Records already imported remain subject to the workspace retention setting or customer agreement.
7. Security and access
We use administrative, technical, and organizational safeguards designed to protect information. These include encrypted network connections, access controls, workspace authorization, secret management, and monitoring. No system is completely secure.
Workspace owners control member access. Creator transparency uses an access mechanism separate from brand workspace membership.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or receive a copy of personal information, object to or restrict certain processing, or withdraw consent where processing is based on consent.
You can update some information in the service. For other requests, contact privacy@collabbook.co. We may need to verify your identity and authority before completing a request. If a brand or other organization controls the workspace, we may direct the request to that organization.
10. Changes and contact
We may update this policy as the service changes. We will post the current version here and provide additional notice when required by law or contract.
Questions or privacy requests can be sent to privacy@collabbook.co.