How we collect data
This is the transparency notice required by Article 14 UK/EU GDPR, for personal data we did not collect from you directly. It is linked from every profile page.
What we hold, and where it comes from
Public, professional-context data only: handle, display name, public bio, public follower and post counts, profile URL, and content categories. Sources, in order of preference: official platform APIs; data you provide when claiming your profile; and public professional facts curated by an operator with the source and collection date recorded on the profile itself. We do not collect private accounts, DMs, personal contact details not self-published for business, or anything requiring a login to view.
What we never do
- No inference of gender, or of any special-category data (race, religion, health, politics, orientation). Gender appears only if you declare it yourself on claim.
- No profiles of minors. Accounts suspected to belong to under-18s are excluded pending review.
- No rehosting of your images — media is embedded from the platform's own official endpoints.
- No sale of raw profile data, and no bulk contact exports — the product contains no such feature.
Lawful basis
Legitimate interest (Art. 6(1)(f)) in indexing public professional information to help brands find and fairly hire creators. A Legitimate Interests Assessment is maintained and reviewed; the balance depends on the strict public-professional scope above and on the strength of the objection rights below.
Your rights
- Erasure / objection: every profile carries a removal control needing no account — remove your profile. Effective immediately, permanent, and re-ingestion-proof via a suppression list.
- Rectification: claim your profile via platform sign-in and edit anything.
- Access: claimed profiles can export everything held.
- CCPA/CPRA: the removal form also serves “Do Not Sell or Share” requests.
- You may also complain to the ICO or your local supervisory authority.
Controller: Roster (https://internetchicks.sa.com). Contact: via the removal form while email routing is being configured — requests are logged with timestamps either way.