Privacy Policy
Last updated 30 August 2026
creatorSea is an affiliate marketplace. Creators share tracked links to brands' products, and creatorSea records which creator referred a sale so commission can be paid. This policy explains what we collect, why, and how long we keep it.
Who we are
creatorSea (“we”) operates the creatorSea platform and the creatorSea Shopify application. For questions about this policy or your data, contact privacy@creator-sea.com.
What we collect
Brands
Company name, business email, industry, country, and the details of any Shopify store you connect. When you connect a store we store an access token so we can read your product catalogue and order totals. We also store your product titles, descriptions, images and prices.
Creators
Name, email, country, niche, biography, social profile links, follower counts and an optional avatar. We record the affiliate links you create and their performance.
When you request a payout we store the details needed to send the money: the account holder name, and either an InstaPay address or mobile number, or a bank name, IBAN or account number and optional SWIFT code. You can save these for future withdrawals or enter them each time. We store them so we can pay you, and for the records we are required to keep about payments made.
These details are visible only to you and to Creator Sea staff
processing your payout. Lists and queues show a masked version, such as
····4821; the full value is read only when a payment is
being made, and each read is logged. We are not a payment provider and
do not hold funds: transfers are made through a bank or payment service.
Shoppers
We do not collect shopper names, email addresses, phone numbers or postal addresses. When someone clicks an affiliate link we record:
- a randomly generated visitor identifier, stored in a first-party cookie
- the affiliate link clicked and the time
- the device class (mobile, tablet or desktop)
- a salted, truncated hash of the IP address, used only to detect abuse
- the referring page, where the browser provides one
When a purchase is made through a connected Shopify store we receive the order from Shopify and retain only the order reference, currency, subtotal, total and payment status. Customer identity fields present in Shopify's data are discarded on receipt and are never written to our systems.
Cookies
We set one first-party cookie on the merchant's storefront
(_cs_ref) holding the affiliate reference and visitor
identifier, and one on our redirect domain (cs_vid) holding
the visitor identifier. They exist solely to attribute a purchase to the
creator who referred it. On merchant storefronts our tracking runs
through Shopify's Web Pixel, which loads only where the shopper's
consent choices permit it. Where a shopper declines, no attribution data
is collected.
Why we process this data
- to attribute a sale to the creator who referred it
- to calculate and pay commission
- to show brands and creators their own performance
- to detect fraudulent or abusive activity
- to meet accounting and tax obligations
We do not sell personal data, we do not use it for advertising, and we do not carry out automated decision-making that produces legal effects.
How long we keep it
| Data | Retention |
|---|---|
| Click records | 24 months from the click |
| Attribution records | 24 months after the sale settles |
| Order references, commission and payment records | 7 years, to meet accounting obligations |
| Shopify access tokens | Deleted when the app is uninstalled |
| All other merchant data | Deleted within 30 days of uninstall |
| Payout destination details | Until you delete them, or 30 days after account closure |
| Payment records and transfer receipts | 7 years, to meet accounting obligations |
| Account data | Deleted within 30 days of account closure |
Merchants using our Shopify app
We request the minimum Shopify permissions the app needs: reading
products, reading order totals, and creating the tracking pixel. We do
not request access to customer names, email addresses, phone numbers or
addresses. We respond to Shopify's
customers/data_request, customers/redact and
shop/redact requests. On a shop redaction we delete
sessions and personal data within 48 hours, retaining only anonymised
financial records required for accounting.
Sharing
Brands can see which creators drove sales for their products and the commission owed. Creators can see their own performance. Neither can see the other's wider account data. We use Supabase for database and hosting, Shopify for merchant integration, and Vercel for this website. We share data with them only to operate the service.
Security
Data is encrypted in transit using TLS and at rest by our hosting provider. Shopify access tokens are stored in a table that no client application can read; only our server can access them. Access to production data is limited to named administrators.
Payout information
Payout details and transfer receipts are held under stricter controls than the rest of the platform. Saved destinations can only be read by the creator they belong to; administrators reach them through an audited route that records every access. Transfer receipts are kept in private storage that is never publicly reachable and are visible only to Creator Sea staff — creators do not see receipts, because a bank receipt can expose account balances or unrelated transactions.
You can delete a saved payout destination at any time from your wallet. Records of payments already made are retained for accounting purposes.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. Contact privacy@creator-sea.com and we will respond within 30 days. Shoppers who bought through a merchant using creatorSea should contact that merchant, who can raise the request with us through Shopify.
Changes
We will update this page when our practices change and revise the date above. Material changes affecting merchants will be notified directly.