PushBrands Privacy Policy

Tadafuq Al-Nomou Marketing Company

Commercial Registration No.: 4030552035 | VAT No.: 312150536300003

1. Introduction

This Privacy Policy explains how PushBrands collects, uses, processes, shares, and protects personal data when you use our main website at https://pushbrands.app, our creator portal at https://creator.pushbrands.app, the mobile application, or any other digital services associated with the platform.

This Policy applies to all users of the platform, including clients or brands, creators, website or app visitors, and anyone who communicates with the platform through forms, email, social media accounts, or support channels.

By using PushBrands, registering for an account, or using any of its services, you acknowledge that you have read and understood this Policy.

2. Scope of This Policy

This Policy applies to personal data collected by PushBrands through the website, mobile application, account registration and profile creation, wallet and payments, chats and orders, social media account linking, customer support communications, invoicing and tax information requests, and any other forms, correspondence, or services offered through the platform.

2.1 Platform Links

This Privacy Policy applies to the following PushBrands properties:

3. Data We Collect

3.1 Account and Registration Data

  • Name
  • Email address
  • Mobile number
  • Password or login credentials
  • Profile photo
  • City or country
  • Account type
  • Sign-in data through third-party providers such as Google or Apple, where available

3.2 Creator Data

  • Linked social media account names and profile URLs.
  • Publicly available social media identifiers, follower counts, view numbers, reach, and historical engagement metrics.
  • Data retrieved through authorized technical integrations (including TikTok's Official Developer API and Instagram Graph API).
  • Services added by the creator, service pricing, delivery times, and number of allowed revisions.
  • Portfolio items and content uploaded directly to the platform profile.
  • Banking details and identification/freelance certificates required for secure withdrawals.
  • Address and delivery details if an order requires sending products or physical samples.

3.3 Client or Brand Data

  • Entity name or representative name.
  • Email address and mobile number.
  • Company details, tax registration number, and invoicing details.
  • Store or business activity descriptions.
  • Wallet, balance, and transaction payment data.
  • Selected orders, campaign briefs, and specific service instructions.

3.4 Order and Chat Data

  • Messages exchanged through the platform's internal system.
  • Attachments, content files, deliverables, and revision logs.
  • Disputes, support tickets, and complaints.
  • Order execution timestamps (acceptance, cancellation, and delivery dates).

3.5 Financial and Invoicing Data

  • Wallet top-up records, balances, and transfer logs.
  • Financial transaction statuses and payment breakdowns (fees, tax, and totals).
  • Tax invoices and supporting accounting data.

3.6 Technical Usage Data

  • IP address, device type, operating system, and browser type.
  • Device identifiers, session records, and app crash reports.
  • Cookies and similar tracking technologies where authorized.

4. How We Collect Data

We collect personal data directly when you create an account, fill out profiles, link social media accounts, upload files, use the internal wallet, create/fulfill orders, or contact support. We also collect specific technical metrics through third-party platforms and official social media APIs strictly to the extent permitted by your explicit authorization and integration permissions.

5. Purposes of Processing

5.1 Operating the Platform and Providing Services

  • Managing accounts and facilitating platform core functions.
  • Enabling matching, orders, communication, and legal compliance between clients and creators.
  • Managing operational wallets, automated payouts, and invoicing.

5.2 Verification, Compliance, and Protection

  • Verifying identity and validating technical ownership of linked accounts.
  • Preventing identity fraud, automated abuse, or platform circumvention.
  • Complying with legal, tax, regulatory, or judicial requirements.

5.3 Displaying Data Within the Platform

Displaying creator profiles, service terms, and verified public social media performance statistics to registered clients or authorized platform users to support data-driven contracting decisions.

6. Legal Basis for Processing

PushBrands processes personal data based on lawful grounds, including the performance of a contract, compliance with regulatory obligations, the legitimate business interests of the platform (ensuring security and performance), and the explicit consent of the data subject where mandatory.

7. Third-Party Platform Integrations & Social Media Account Linking

When a creator chooses to link an external social media account (e.g., TikTok or Instagram), the creator explicitly authorizes PushBrands to access public data and performance statistics made available through that platform's official, approved developer API interfaces.

PushBrands utilizes this data solely to populate the creator's visible portfolio profile on PushBrands and display it to prospective brand clients. PushBrands updates this data periodically to maintain data accuracy. We do not guarantee continuous availability if third-party API availability, data policies, or access permissions change.

8. Chats, Content, and Attachments

All transactions, deliveries, and communications are carried out via our internal chat system. PushBrands reserves the right to review chats, messages, and files exclusively for quality assurance, dispute resolution, anti-fraud moderation, policy violations, or compliance with legal inquiries.

9. Financial Data and Wallet

PushBrands processes financial records strictly for processing deposits, managing balance allocations for active orders, processing withdrawal transfers, and ensuring tax/accounting compliance. Creators may be requested to complete separate KYC or banking verification before payouts are released.

10. Invoicing and Tax Data

Business and tax details added by clients are used strictly to generate official invoices. Tax information must be provided prior to financial checkouts or within permitted internal policy grace periods to guarantee continuous accounting records.

11. Sharing Data with Third Parties

PushBrands may share essential data with technical service providers (cloud hosting), authorized payment gateways, SMS/email notification vendors, internal analytics providers, and regulatory or judicial authorities if required by law. PushBrands minimizes data sharing strictly to the necessary technical scope required to execute requested services.

12. Data Transfers Outside the Kingdom

Data may be securely stored or processed using technical cloud architecture operating either inside or outside the Kingdom of Saudi Arabia. In all instances, PushBrands implements structural safeguards to protect personal datasets in alignment with applicable local data protection standards.

13. Data Retention and Deletion

PushBrands retains personal data for as long as your account remains active or as required by financial, tax, and legal storage obligations. If an integration or account is disconnected, all related temporary metrics and authorization codes are immediately queued for deletion, as outlined further in Section 21.

14. Data Protection and Security

We enforce robust administrative, technical, and cryptographic protection protocols designed to minimize data loss, unauthorized leakages, or structural cyber threats. While we employ industry-standard safety practices, no electronic transmission over the internet is completely impregnable. Users are explicitly responsible for maintaining the strict confidentiality of their personal login credentials.

15. Data Subject Rights

Subject to local legal limitations, users retain the right to query how their data is used, request access to their data profiles, correct inaccurate information, withdraw previously granted consent, or demand the deletion of personal files when processing reasons no longer exist.

16. Children's Privacy

PushBrands services are strictly restricted to individuals aged 18 and older. If we discover an account belongs to a minor without verified legal authority, we will instantly restrict or delete the profile and clear all related data arrays.

17. Cookies and Similar Technologies

We utilize technical cookies and device identifiers to optimize session logins, remember choices, and monitor operational site performance. Users can configure cookie constraints within their browser preferences.

18. External Links and Services

Our systems contain external links and digital bridges (such as payment systems and social media networks). PushBrands does not control and is not liable for the independent privacy policies or internal processing mechanisms managed by third-party services.

19. Changes to This Privacy Policy

PushBrands reserves the right to revise this Privacy Policy to align with new system features or changing legal obligations. Revised terms become functionally active the moment they are published. Continued use of our systems signifies full acceptance of revised policies.

20. Contact Us

For privacy questions, access inquiries, or data deletion requests, you may officially reach out to us through our approved customer support channels inside the application or website.

21. Connected Social Media Accounts & TikTok API Compliance

Our platform allows content creators to link external social media accounts (specifically TikTok and Instagram) to display public analytical metrics to brand clients.

When you choose to connect a TikTok account, we request your explicit consent through the official TikTok OAuth interface. Upon your authorization, we access only the following public data via TikTok's Official Developer API:

  • Public Profile Information: Display name, username, unique identifier (open_id), profile avatar, and public bio.
  • Public Audience Statistics: Live public follower count, following count, and total public post counts.
  • Public Engagement Metrics: Video view counts, likes, comment tallies, and sharing statistics for recent public video posts.

21.1 Use, Caching, and Disconnection Limits

  • Strict Purpose Limitation: We use this data strictly to: (1) verify ownership of the connected channel during your onboarding setup, and (2) aggregate public engagement statistics on your PushBrands creator profile, enabling brands to assess channel performance. We do not use TikTok platform data for any other purposes, including profiling beyond this scope or sharing data with data brokers.
  • Data Caching and Synchronization: To prevent unnecessary API load and ensure performance, TikTok platform data is safely cached on our secure servers. This cached data is regularly refreshed to ensure accuracy.
  • Account Disconnection & Stored Data Deletion: You can terminate the link to your social media accounts at any time by navigating to Settings > Social within the creator dashboard. Once disconnected, PushBrands automatically and permanently deletes all cached profile metrics, removes your access tokens, and erases refresh tokens from our active database systems.
  • Data Restrictions: PushBrands does not request, access, read, store, or process your private direct messages (DMs), draft content, account passwords, or any private metadata.

21.2 Revocation of Access via Third-Party Platform Settings (TikTok)

In compliance with developer terms, users retain full, independent control over their third-party account authorizations. Aside from disconnecting the account inside the PushBrands panel, creators can manually revoke PushBrands' access and authorization tokens directly at any time via their TikTok account settings:

How to Revoke Access on TikTok: Go to your TikTok App > Profile > Settings and Privacy > Security > Manage App Permissions > Select "PushBrands" > Click "Remove Access".

Once access is revoked via TikTok, our API authorization keys immediately become invalid, and all associated platform analytics sync processes will permanently cease.

Last updated: 18 April 2026