Partner Privacy Policy
1. Controller and scope
032 Ventures GmbH, Rosenstraße 7, 71034 Böblingen, Germany. Managing director Stefan Nisik. Local Court of Stuttgart HRB 806402. E-mail contact@032-ventures.com. For Creators creators@032-ventures.com, for Brands seller@032-ventures.com.
This policy applies to:
| Service | Address | Who |
|---|---|---|
| Company website | 032-ventures.com | visitors, applicants |
| Creator Center | creators.032-ventures.com | Creators |
| App "032 Creator Center" | App Store, Google Play | Creators |
| Seller Center | seller.032-ventures.com | Brands, their team members and contact persons |
| Manuals | docs.creators.032-ventures.com, docs.seller.032-ventures.com | readers |
The marketplaces of 032 Ventures GmbH are separate services on their own domains with their own privacy policy. For customers of the marketplaces, that policy applies, not this one.
Creators and Brands use a shared database (the "partner platform"), separated by roles. The marketplaces each have their own. What is exchanged between the partner platform and the marketplaces is set out in sections 7 and 9.
A data protection officer has not been appointed.
2. Legal bases
Art. 6(1)(a) GDPR, Regulation (EU) 2016/679 (consent: promotional e-mails, push notifications, applications kept on file), Art. 6(1)(b) (contract: Creator Agreement, Brand Agreement, application procedure), Art. 6(1)(c) (legal obligations: § 22f UStG, German VAT Act, PStTG, retention, self-billing invoices), Art. 6(1)(f) (legitimate interests: operation and security, protection against misuse, evidence). In addition § 26 BDSG (German Federal Data Protection Act) for applications and § 25 TDDDG (German Telecommunications Digital Services Data Protection Act) for the terminal equipment.
3. Website 032-ventures.com
What the website does not do: it sets no cookies, stores nothing in your browser, uses no analytics, tracking or advertising services and loads no third-party content. Fonts, images, styles and scripts come from our domain. It has no contact form and no log-in form. The marketplace selection on the pages "For Brands" and "For Creators" runs in your browser and transmits nothing. For that reason there is no consent banner.
Delivery (Cloudflare): the website and all other services covered by this policy are delivered via Cloudflare, Inc. In doing so, Cloudflare processes IP address, time, address accessed, volume of data, response status, browser, operating system and referring page, in order to deliver the pages and to ward off attacks. Cloudflare is a processor. The network is worldwide, the transfer is safeguarded by standard contractual clauses. Legal basis: Art. 6(1)(f) GDPR.
Knowledge articles: the articles under "Knowledge" are static pages without data processing beyond section 3.
4. Contact by e-mail
If you write to us, we process your address, your name and the content in order to reply. The mailboxes run at Microsoft Ireland Operations Ltd. (EU tenant). Legal basis: Art. 6(1)(b) or (f) GDPR. Retention period: until the enquiry has been dealt with, subject to statutory retention. E-mail is not end-to-end encrypted. For confidential matters we agree another route.
5. Job applications
Applications reach us by e-mail to the address stated in the job advertisement. We process name, contact details, curriculum vitae and attachments in order to decide on the establishment of an employment relationship (§ 26 (1) BDSG, Art. 6(1)(b) GDPR). Rejections: erasure six months after completion of the procedure (periods under the AGG, German General Equal Treatment Act). At your request we retain documents for future positions on the basis of your consent, revocable at any time. If you are hired, the documents become part of the personnel file.
6. Manuals (docs.creators and docs.seller)
The manuals are public, static pages without log-in, forms, cookies or tracking. Only section 3 (delivery) applies. The root forwards you on the basis of the language of your browser. This is not stored.
7. Creator Center
7.1 Creating an account, earlier applications
Creating an account. You create your account in the Creator Center with an e-mail address and a password. There is no application and no decision by us: you are enabled as soon as the information listed in section 7.2 is complete, and that check is purely a check for completeness (section 15). If you create an account and never complete the set-up, we delete it, together with the log-in, after 90 days without any change (section 7.2).
Earlier applications. Until 30 September 2026 it was possible to apply without an account at creators.032-ventures.com/bewerbung, providing name, e-mail address, country, channel, reach and, if desired, a message to us. We no longer accept new applications; the address now leads to account creation. Applications already received continue to be processed on the basis of Art. 6(1)(b) GDPR (pre-contractual). Rejected applications are deleted six months after the decision, accepted ones have been absorbed into the account (section 13).
7.2 Account and enablement
E-mail address, password (hash), code chosen, address, tax status, tax number or VAT identification number, consent to the self-billing procedure (with time stamp), your declaration that you act as a trader (with time stamp and version), where the two-factor log-in is switched on the secret of the second factor (held in encrypted form by our authentication service) and verification values of your recovery codes, language, countries of your audience (voluntary), settings for notices. Purpose: Creator Agreement, enablement, self-billing invoices, security. Legal basis: Art. 6(1)(b) and (c) GDPR.
Address verification: we send street, postcode, town and country, on entry and on every change, to the Google Address Validation API (Google Ireland Ltd.), in order to verify the address for the self-billing invoice (§ 14 (4) UStG). Only these four fields are transmitted. The result and the time are stored. Legal basis: Art. 6(1)(c) GDPR.
Verification of the VAT identification number: via the confirmation procedure of the European Commission (VIES) on entry and at regular intervals thereafter. The result and the time are stored (Art. 6(1)(c) GDPR).
Enablement on all marketplaces: upon enablement we create in each marketplace a record containing your e-mail address and your code, so that the code applies there and sales are assigned to you. All marketplaces belong to 032 Ventures. This is not a transfer to third parties, but a consolidation across several services, which we expressly name here. Legal basis: Art. 6(1)(b) GDPR.
Accounts that were never fully set up: if you have created an account but never completed the set-up and have not changed anything about it for 90 days, we delete it, including the log-in, on our own initiative. Nothing remains. Legal basis: Art. 5(1)(e) and Art. 17(1)(a) GDPR.
7.3 Earnings and payout
For each sale made with your code we receive from the marketplace date, product, marketplace, amount and status. For the self-billing invoice we additionally receive, aggregated per Brand, the name and the invoicing details of the Brand for which you have referred sales, together with the number of items and the total. You do not receive any customer data of the purchasers. For payouts you set up an account with Stripe Payments Europe, Ltd. You enter identity and bank details directly with Stripe, we receive the account identifier and the status. For identity verification, fraud prevention and regulatory obligations Stripe is a separate controller (anti-money laundering and payment services law), and for the pure payment processing it is our processor. We issue self-billing invoices in the name of the Brand containing your mandatory information. The Brand receives a duplicate of the document by e-mail. It carries your name, your address including country and your tax number or your VAT identification number, because § 14 (4) UStG requires this information on a self-billing invoice and the Brand is the issuer (§ 14 (2) sentence 2 UStG). The Brand may use it only for its accounting and its tax obligations. Legal basis for this: Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(b) GDPR (performance of the self-billing procedure to which you consented in the Creator Center). We hand over document data to our accounting software (sevdesk GmbH, Offenburg). Legal basis: Art. 6(1)(b) and (c) GDPR. Retention period: self-billing invoices and the information contained in them eight years (§ 14b (1) UStG, German VAT Act, § 147 (3) sentence 1 AO, German Fiscal Code).
7.4 What Brands see about you
Once you have brought about a sale for a Brand with your code, that Brand sees in the Seller Center your name, your Creator code and, if provided, your channel, your reach and the countries of your audience, together with the marketplaces on which you have sold for the Brand, the number of those sales, the commission earned with the Brand and the commission still outstanding, and the date of your last sale for it. Via the Seller Center we do not disclose your postal address, country of residence or tax details to the Brand. The duplicate of the self-billing invoice, by contrast, carries them. This is required by § 14 (4) UStG and described in section 7.3. Purpose: the promotional agreement between you and the Brand (contact regarding samples, queries, reports). Legal basis: Art. 6(1)(b) GDPR. We pass your e-mail address on to the Brand only if you have separately given your consent in the Creator Center (Art. 6(1)(a) GDPR). You can withdraw the consent at any time with effect for the future. The Brand may use the data only for the Creator programme.
7.5 Tax reports
Insofar as 032 Ventures is obliged to report as a platform operator under the Plattformen-Steuertransparenzgesetz (PStTG, German Platform Tax Transparency Act), we transmit your identification data, tax number, account identifier and remuneration annually to the Bundeszentralamt für Steuern (German Federal Central Tax Office) (Art. 6(1)(c) GDPR) and inform you of the data reported.
7.6 Notices
We send contractual notices (amendments, conditions, security, settlement) by e-mail. They are part of the contract (Art. 6(1)(b) GDPR). For every mandatory notice we keep a log for each recipient (template, address, language, time, delivery status). Promotional e-mails only with your consent, which we log with time and wording and which you can withdraw at any time. Dispatch via Resend, Inc. (USA, standard contractual clauses). Suppression list for undeliverable addresses permanently.
Your address at the dispatch service: with your consent to promotional e-mails we additionally create your address as a contact at Resend and record the subscription there. If you withdraw, we set it there to "unsubscribed". The contact itself remains in place, so that the unsubscription can be observed permanently. We arrange complete removal upon your request.
7.7 Deletion of the account
You delete your account in the Creator Center or in the app. If you had no earnings, we delete everything. If you had earnings, we permanently deactivate log-in and codes, anonymise your profile and keep name, address and tax number with the self-billing invoices for the statutory period. To check whether there are earnings we query all marketplaces. If one of them does not respond, we abort the deletion and change nothing, rather than leaving a half-deleted account. You receive a notice and can try again shortly afterwards.
7.8 Complaint against a decision (Art. 20 DSA)
If we have taken a measure against you, for example removed content, withheld a payout or restricted your account, you may object to this within six months of the communication (Creator Agreement annex 2, Brand Agreement § 22 section 4 no. 1). For this we process your party assignment, the contested measure, the area, your statement of reasons, the time of receipt, the time limit for our reply, our decision together with its reasons, the person handling it and the type of file. We keep the same file for objections to the assignment of a sale, an earnings line, a self-billing invoice or a chargeback. The complaint is examined by a person other than the one who took the contested decision. Purpose: conduct of the complaint procedure and the annually published statistics on it. Legal basis: Art. 6(1)(c) GDPR (Art. 20 and 21 DSA, Art. 11 and 12 of the P2B Regulation). Retention period: with your account, and thus at the latest until expiry of the deletion period under section 9.9 or 7.7. For the published statistics only figures remain thereafter, no files.
The internal note on a decision. In addition to the text that is sent to you, we record internally what we based a measure on. The note is not visible to you, forms part of the file on the decision and is kept for six months after the decision has been communicated. Purpose: traceability and the handling of a complaint against it. Legal basis: Art. 6(1)(c) GDPR.
8. App "032 Creator Center"
The app shows the same data as the Creator Center with the same log-in. In addition:
Push notifications: only if you switch them on. In that case a device identifier (push token) is transmitted via Firebase Cloud Messaging (Google Ireland Ltd. / Google LLC) and the Apple Push Notification Service (Apple Distribution International Ltd.) and is assigned to your account with us. Content of the notifications: enablement, first commission, payout on its way, in your language. If you switch the notifications off in the app, we delete the token. If instead you withdraw the permission in the settings of your device, the app learns nothing of this: no further notifications will arrive, but the token remains stored with us until you switch it off in the app or delete your account. Legal basis: Art. 6(1)(a) GDPR, § 25 (1) TDDDG.
Screen lock: Face ID, Touch ID or fingerprint is checked by the operating system on the device. We receive no biometric data, only the result.
Sharing: sharing a link hands the link over to the app you have chosen. We do not learn where to.
No tracking: the app contains no analytics or advertising SDKs, no access to location, contacts, camera, microphone or photos. Crashes are not reported to third parties.
Stores: when you obtain the app, Apple and Google process data in accordance with their own policies. We receive no personal data from this.
9. Seller Center (Brands)
9.1 Account, brand, team
E-mail address and password (hash) of the account holder and of each team member. Brand name, logo, website. Address, country of dispatch, telephone number, tax number, VAT identification number, whether you are entered in a commercial register and, if so, the registering court and the register number, returns address, contact person, e-mail address for customer enquiries. Links to general terms and conditions, privacy policy and legal notice. Time and version of the acceptance of the agreement. Time and version of your self-certification that you will only offer products that comply with Union law (Art. 30(1)(e) of Regulation (EU) 2022/2065). Settings for notices. Where the two-factor log-in is switched on, the secret of the second factor (held in encrypted form by our authentication service) and verification values of your recovery codes, as described in section 7.2. Purpose: Brand Agreement, statutory records (§ 22f UStG), traceability of the trader (Art. 30 of Regulation (EU) 2022/2065), display of the Brand as seller on the marketplaces. Legal basis: Art. 6(1)(b) and (c) GDPR.
Address verification (Google Address Validation API) and verification of the VAT identification number (VIES) as in section 7.2, here on the basis of § 22f and § 25e UStG.
Address suggestions. If you enter an address in the Seller Center, your own or the return address, we suggest matching addresses from the third character onwards. For this purpose we transmit the characters entered, the selected language and a random session identifier via our server to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which acts for us as a processor (section 11). Your IP address is not transmitted to Google in the process. We do not store the entries, not even in the event of an error; only the address you submit is stored. Use is voluntary. Legal basis: Art. 6(1)(b) GDPR (performance of the Brand Agreement) and Art. 6(1)(f) GDPR (complete and deliverable addresses).
Proof of insurance. The Brand Agreement (§ 3(7)) requires public and product liability insurance. For that purpose you provide the insurer, the policy number, the sum insured and the expiry date, and upload the proof as a file (PDF, JPEG or PNG, no more than 10 MB). A policy document regularly carries the name and address of the insured person. If you are a sole trader, those are your own data. The file is held in a non-public file store at our database service (section 11), in a separate folder for each Brand. It can be read only by those who belong to your Brand, and by us via the internal administration surface (section 10). It is served exclusively via a link that expires after five minutes. You may replace or delete the file at any time. Purpose: evidence of the obligation under § 3(7) and the ability to establish with whom a Brand is insured if a product causes damage. Legal basis: Art. 6(1)(b) and (f) GDPR. We remind you by e-mail 60 and 14 days before the expiry date. Retention period: ten years after the end of the Brand Agreement. The longer period is due to product liability: damage may become apparent long after the sale, and it must then remain possible to establish with whom you were insured at the time of the sale. You may replace the file in the Seller Center at any time; deletion before that period expires is possible only to the extent that it does not conflict with the retention obligation.
Registration numbers from producer registers. For each country you ship to, you provide your registration number in that country's packaging or producer register (§ 3(3) of the Brand Agreement, § 7(7) VerpackG for Germany, Art. 45 of the Packaging Regulation (EU) 2025/40). We store the country, the number and the time of your declaration. We do not verify the number. There is no official facility for doing so. Without a number we block dispatch to the country concerned. Legal basis: Art. 6(1)(c) GDPR.
Publicly visible on the marketplaces: brand name, logo, legal name, address as seller, telephone number, e-mail address for customer enquiries, legal notice, links to terms and privacy policy, the link to your withdrawal instructions, whether you are entered in a commercial register and, if so, the registering court and the register number, the fact that you have given the self-certification, a technical flag indicating whether your payout account has been fully set up, the returns address (in the customer's order portal), product data and, in the brand directory, the designed catalogue page.
9.2 Shopify connection
If you connect a Shopify shop, we store the shop domain, the shop e-mail address and the access token issued by Shopify. We read products, variants, prices, images, stock and shipping regions, create orders from the marketplaces in your shop and read their shipping status. For the directory commission we additionally read order number, date, net goods value and source information of paid orders of your own shop, no customer data. Shopify International Ltd. (Ireland, with parent company in Canada, adequacy decision) is a separate controller for your shop. Legal basis: Art. 6(1)(b) GDPR.
9.3 Orders, customer data, support
Orders from the marketplaces reach you with name, delivery address, items and contact details of the customer. For this data you are yourself responsible as seller (Brand Agreement § 12). You handle support enquiries from customers in the Seller Center. Messages are retained for 24 months after completion, photos for 12 months.
9.4 Payment, payout, direct debit
For payouts you set up an account with Stripe Payments Europe, Ltd. (Stripe Connect). Identity and bank details go directly to Stripe, we receive the account identifier and the status. Stripe is a separate controller for this and our processor for the payment processing. For the brand directory you grant a SEPA direct debit mandate via Stripe. We store the mandate reference and the last digits of the IBAN. You pay for advertising services via Stripe Checkout. We store commission invoices and self-billing invoices to Creators in your name for eight years (§ 14b (1) UStG, § 147 (3) sentence 1 AO), settlements and payment data for each order for at most ten years. We hand over document data to sevdesk GmbH (accounting). Legal basis: Art. 6(1)(b) and (c) GDPR.
9.5 Tax records and reports
We record the information required under § 22f UStG and submit it to the tax authorities on request. Under the Plattformen-Steuertransparenzgesetz we report annually by 31 January to the Bundeszentralamt für Steuern your identification data, tax numbers, address, account identifier, remuneration per quarter and fees withheld. You can see the data reported in the Seller Center. Legal basis: Art. 6(1)(c) GDPR.
9.6 Creator programme
Where a Creator has brought about a sale for your products with their code, you see them with name and Creator code and, where provided, with channel, reach and target countries, together with the marketplaces on which they have sold for you, the number of those sales, the commission earned with you and the commission still outstanding, and the date of the last sale for you. You see the e-mail address only with the Creator's separate consent (section 7.4). The Seller Center does not show the postal address, country of residence or tax details. You receive this information with the duplicate of every self-billing invoice that we issue in your name and send to you by e-mail: § 14 (4) UStG requires the name, address and tax number or VAT identification number of the supplier on the document, and you are the issuer of the document. You may use it only for your accounting and your tax obligations, not for advertising directed at the Creator and not for disclosure to third parties. You do not see Creators who have not yet brought anything about for you. We store assignments of sales to Creator codes and the self-billing invoices in your name for the purposes of settlement.
9.7 Brand directory
We count clicks on your entry with Brand, type of event, target, time, region and a counting key. The counting key is a pseudonym of the person clicking: a salted hash of the IP address, changing daily, or a session identifier from the browser. It is therefore personal data, which we do not assign to any account, do not link beyond the day and do not pass on to you as the Brand. You see daily totals. It prevents the same click from being charged more than once. Raw data 120 days, daily totals thereafter. Orders in your shop are assigned to clicks via a referral parameter and the order fields named in 9.2.
9.8 Notices
Mandatory notices (agreement, prices, maintenance, security) by e-mail as part of the agreement, with a log for each recipient (template, address, language, time, delivery status), which is retained with the account. Mandatory notices go to the account address and to the Brand's support address. Promotional e-mails only after consent in the Seller Center, revocable at any time. Dispatch via Resend, Inc. Section 7.6 applies accordingly to the permanent contact there.
9.9 Termination
After termination of the Brand Agreement we retain the data of the Brand for as long as statutory obligations require (invoices and self-billing invoices eight years, the remaining documents subject to retention obligations at most ten years) and delete the remaining data six months after the end of the agreement. We give a reminder of that period 90 and 30 days in advance. The end of the agreement is the day on which the Brand is no longer active on any marketplace. "Delete" means: everything apart from the information appearing on documents subject to retention obligations is removed or anonymised.
9.10 Complaint against a decision
Section 7.8 applies accordingly to complaints against measures and to objections to a settlement, a self-billing invoice or a chargeback. Brands and Creators keep the same file in the same database, distinguished only by the party.
10. Internal administration surface
Trained staff of 032 Ventures access the data of Brands, Creators and marketplaces via an access-protected internal area, insofar as this is necessary for support, settlement, moderation and statutory obligations. Access is limited to those persons who need it for their task, and they are bound to confidentiality. Changes to data are logged.
11. Recipients and processors
| Category | Provider | Seat and place of processing |
|---|---|---|
| Database, log-in, file storage, functions (partner platform and marketplaces) | Supabase, Inc. | USA. Hosting Frankfurt (eu-central-1). Standard contractual clauses |
| Delivery, protection against attacks, access protection of the administration surface | Cloudflare, Inc. | USA. Worldwide network. Standard contractual clauses |
| Payment, payout, identity verification, direct debit mandate | Stripe Payments Europe, Ltd. | Ireland (group USA). Processor for payment processing, separate controller for fraud prevention, identity verification and regulatory law |
| Shop system of the Brands | Shopify International Ltd. | Ireland (group Canada, adequacy decision). Separate controller for the shop |
| Address verification | Google Ireland Ltd. (Address Validation API) | EU/USA. Address fields only |
| Address suggestions in the Seller Center | Google Ireland Ltd. (Places API) | EU/USA. Only the characters typed, the language and a random session identifier, not your IP address (section 9.1) |
| Push notifications of the app | Google (Firebase Cloud Messaging), Apple Distribution International Ltd. (APNs) | EU/USA. Push token |
| Translation of product and manual texts (Art. 6(1)(f)) and of the statements of reasons for our decisions to Brands and Creators (Art. 6(1)(c) with Art. 17(1) DSA) | Google Ireland Ltd. (Cloud Translation) | EU/USA. Only the text, without name and contact data of the recipient. If a statement of reasons itself names a person, the name goes with it |
| E-mail dispatch | Resend, Inc. | USA (Amazon SES). Standard contractual clauses |
| Mailboxes, log-in to the administration surface | Microsoft Ireland Operations Ltd. | Ireland (EU tenant) |
| Accounting | sevdesk GmbH | Offenburg, Germany |
| Bundeszentralamt für Steuern, tax authorities | public authorities | Germany. Statutory reports |
| Brands and Creators among each other | see 7.3, 7.4 and 9.6 | separate controllers |
Further recipients: tax advisers, legal advisers, banks, public authorities, insofar as provided for by law.
12. Transfers to third countries
The basis consists of adequacy decisions of the EU Commission (Canada and, for providers certified under the EU-U.S. Data Privacy Framework, the United States) and standard contractual clauses (Art. 46(2)(c) GDPR) with supplementary measures. You can obtain a copy on request.
13. Retention periods
| Data category | Retention period |
|---|---|
| Creator application, rejected | six months |
| Creator application on which no decision was taken | until a decision is taken on the application. No maximum period has been fixed for this, and no deletion run covers these applications. You may request deletion at any time (section 14) |
| Job application, rejected | six months |
| Account Creator, created and never fully set up | 90 days without any change, then deleted |
| Account Creator / Brand / team member | until deletion or six months after the end of the agreement (section 9.9) |
| Complaint and objection files (Art. 20 DSA, P2B) | with the account (section 7.8) |
| Self-billing invoices and commission invoices including the mandatory information on them | eight years (§ 14b (1) UStG, § 147 (3) sentence 1 AO, § 257 (4) HGB) |
| Settlements and the remaining documents subject to retention obligations | at most ten years (§ 147 (3) sentence 1 AO, § 257 (4) HGB) |
| Records under § 22f UStG | ten years after the end of the year |
| PStTG reporting data | ten years |
| Verification logs for VAT identification number and address | with the account |
| Information under Art. 30 of Regulation (EU) 2022/2065 (telephone number, registering court, register number, wording of the self-certification) | six months after the end of the agreement (Art. 30(5)) |
| Uploaded proof of insurance | ten years after the end of the agreement (section 9.1) |
| Insurance details in the portal (insurer, policy number, sum insured, expiry date) | when your account ends. The uploaded proof carries the same details and remains for ten years |
| Registration numbers from producer registers | with the account |
| Support messages / photos | 24 months / 12 months after completion |
| Suppression list of undeliverable addresses | permanently |
| Contact at the dispatch service Resend | remains in place, after a withdrawal marked "unsubscribed" (section 7.6) |
| Push token | until notifications are switched off in the app or the account is deleted (section 8) |
| Catalogue clicks (raw data) | 120 days |
| Internal note on a decision | six months after the decision has been communicated (section 7.8) |
| Log of mandatory notices | with the account |
| Failed attempts at the two-factor recovery code | one hour, cleared hourly. Only the attempts of the last 15 minutes count towards the lock-out |
14. Your rights
Access, rectification, erasure, restriction, data portability, the right to object to processing on the basis of legitimate interests and to direct marketing, withdrawal of consents with effect for the future (Art. 15 to 21 and Art. 7(3) GDPR). You manage your account and notices yourself in the Creator Center or the Seller Center. Everything else by informal message to the address in section 1. Complaint to a supervisory authority (Art. 77 GDPR): the authority competent is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart.
15. No automated decision-making
The automatic enablement of Creators and Brands checks only whether mandatory information is complete and verified. It does not evaluate any person. Decisions on applications, suspensions and terminations are taken by human beings.
16. Data security
Encrypted transmission. Row level access rules. Separate data holdings for each marketplace. Two-factor log-in on request in the Creator Center, in the Seller Center and in the app, with recovery codes. Separate access protection and separate log-in for the internal administration surface. No storage of payment or identity document data. Logs of security-relevant events.
17. Amendments
We adapt this policy if law, services or processing change. The current version is available at 032-ventures.com/privacy. We notify Brands and Creators of material amendments as a mandatory notice.