Legal

Privacy Policy

How Crestline Connect collects, uses, stores, and protects personal data, and the rights you have under the GDPR.

Last updated: July 2026.

1. Data controller

Crestline Connect ("we", "us", "our") is the data controller for personal data collected through this website. We are based in Ireland. You can contact us about privacy matters at hello@crestlineconnect.live.

2. Information we collect

  • Contact details you submit through our forms (name, email, company).
  • Creator application details (channel link, subscriber and view counts, niche, additional information).
  • Correspondence exchanged during enquiries and active campaigns.
  • Standard technical data your browser sends (IP address, user agent, pages viewed) via our hosting provider.

We do not run analytics, advertising, or third-party tracking cookies on this site. We do not knowingly collect data from children.

3. Purposes and legal bases

  • Responding to enquiries and creator applications — legal basis: our legitimate interests (Art. 6(1)(f) GDPR) in operating our business and responding to people who contact us. You can object at any time.
  • Coordinating and delivering campaigns — legal basis: performance of a contract (Art. 6(1)(b)) with brand or creator partners.
  • Meeting legal, tax, and accounting obligations — legal basis: legal obligation (Art. 6(1)(c)).
  • Site security and abuse prevention — legal basis: legitimate interests.

Providing information through our forms is not a statutory or contractual requirement, but if you do not provide the requested details we may not be able to respond to your enquiry or evaluate a creator application.

4. Sharing and processors

We do not sell personal data. Information is shared only with the parties involved in a specific engagement (for example, connecting a brand and a creator) and with the service providers we use to operate the business:

  • Resend — transactional email delivery (United States).
  • Supabase / Lovable Cloud — website hosting and backend infrastructure.
  • Cloudflare — content delivery and DDoS protection.

5. International transfers

Some of our processors are located outside the European Economic Area (notably Resend in the United States). Where personal data is transferred outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism.

6. Retention

  • Enquiry correspondence: up to 24 months from our last contact, then deleted.
  • Creator applications: up to 24 months from submission, then deleted.
  • Campaign records: for the duration of the engagement plus 6 years to meet accounting and tax obligations.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request erasure of your data;
  • request restriction of processing;
  • data portability;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email hello@crestlineconnect.live. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.

8. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

9. Security

We use industry-standard technical and organisational measures, including TLS in transit and access-controlled storage, to protect personal data. No system is perfectly secure, but we take reasonable steps to safeguard the information you share with us.

10. Changes to this policy

We may update this policy from time to time. The current version will always be posted on this page with an updated date.

11. Contact

Questions about this policy or your data? Email hello@crestlineconnect.live.