1. Introduction
Welcome to Plugg ("we," "our," or "us"). We're committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy explains our practices regarding your personal data when you use our platform, website, and services.
By using Plugg, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please don't use our services.
2. Information We Collect
Information You Provide
- Account information (email address, username, profile details)
- Content you create and upload (videos, posts, descriptions)
- Communications with us and other users
- Payment and billing information for creator programs
- Feedback, reviews, and survey responses
Information We Collect Automatically
- Device information (browser type, operating system, device identifiers)
- Usage data (pages visited, time spent, interactions)
- Location data (IP address, general geographic location)
- Performance metrics (page load times, error rates)
- Analytics data through our analytics providers (see Section 4 for details)
Information from Third Parties
- Social media profile information when you connect accounts
- Partner and affiliate network data for deals and promotions
- Content from integrated platforms (TikTok embeds, etc.)
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services
- Personalise your experience, including content recommendations and other features powered by automated systems or Artificial Intelligence (AI). Our use of AI is designed to enhance your experience and will be in compliance with applicable laws, including the EU AI Act.
- Process creator payments and affiliate commissions
- Communicate with you about updates, promotions, and support
- Analyse usage patterns to enhance platform performance
- Prevent fraud, spam, and abuse
- Ensure the safety and integrity of our platform, including content moderation and compliance with legal obligations (such as those under the EU Digital Services Act and the UK Online Safety Act).
- Comply with legal obligations
- Facilitate partnerships and brand collaborations
4. Analytics and Tracking Technologies
We use various analytics providers and tracking technologies to understand how our platform is used and to improve your experience:
Analytics Providers
- Google Analytics: Tracks website usage, traffic sources, user behaviour, and conversion metrics. Data retention: up to 26 months.
- Firebase Analytics: Provides app performance metrics, user engagement data, crash reports, and real-time database usage statistics.
- PostHog: Product analytics platform that tracks feature usage, user journeys, A/B test results, and session recordings (with consent).
- Meta Pixel (Facebook): Measures advertising effectiveness, builds audiences for ad campaigns, and tracks conversions from Facebook and Instagram ads.
- TikTok Pixel: Tracks advertising performance, measures conversions, and optimises ad targeting for TikTok campaigns.
- Vercel Analytics: Monitors web performance metrics, Core Web Vitals, and real user monitoring data.
Types of Cookies We Use
- Essential Cookies: Required for basic site functionality and security
- Analytics Cookies: Help us understand how you use our platform
- Preference Cookies: Remember your settings and personalisation choices
- Marketing Cookies: Used to show relevant ads and measure campaign effectiveness
Your Choices
You can control cookies and tracking through:
- Browser settings to block or delete cookies
- Google Analytics opt-out browser add-on
- Ad preferences settings for Meta and TikTok
- Do Not Track browser signals (where supported)
Note that disabling certain cookies may affect functionality. For users in the UK, we adhere to the guidance from the Information Commissioner's Office (ICO) regarding cookies, ensuring you have clear choices and control over non-essential cookies.
5. Information Sharing and Disclosure
We may share your information in these situations:
- With Your Consent: When you explicitly agree to share information
- Service Providers: Third-party companies that help us operate our platform (Firebase, Google Cloud, payment processors, analytics providers listed in Section 4)
- Business Partners: Brands and affiliates for collaboration opportunities (with your permission)
- Legal Requirements: When required by law or to protect rights and safety
- Business Transfers: In case of merger, acquisition, or asset sale
We never sell your personal information to third parties for their marketing purposes.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit and at rest
- Regular security audits and monitoring
- Access controls and authentication
- Secure cloud infrastructure (Google Cloud Platform)
While we strive to protect your information, no method of transmission over the internet is 100% secure.
7. Your Rights and Choices
You have the right to:
- Access: Request a copy of your personal data. When you request access, we will conduct a reasonable and proportionate search to provide you with your personal information, in line with UK data protection guidance where applicable.
- Correct: Update or correct inaccurate information
- Delete: Request deletion of your personal data
- Port: Receive your data in a portable format
- Object: Opt out of certain data processing activities
- Restrict: Limit how we process your data
- Object to Automated Decisions: In certain circumstances, you may have the right to object to decisions made solely by automated means (including profiling) that produce legal effects concerning you or similarly significantly affect you.
To exercise these rights, please contact us using the details below. We will respond to your request in accordance with applicable data protection laws.
Complaints (UK Users)
If you are a user in the UK and have a privacy concern, we encourage you to contact us first so we can try to resolve it. You are generally expected to raise your complaint with us before contacting the Information Commissioner's Office (ICO), as per guidance related to the UK's data protection framework.
8. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Account data: Until you delete your account plus 30 days
- Analytics data: Varies by provider (Google Analytics: 26 months, Firebase: 60 days, PostHog: 90 days default, Meta/TikTok: per their policies)
- Content and posts: Until manually deleted by you
- Payment records: 7 years for tax and legal compliance
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place through standard contractual clauses and adequacy decisions where applicable.
For transfers of data from the European Economic Area (EEA) to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) and may implement supplementary measures where necessary to ensure a level of data protection equivalent to that in the EU.
For transfers of data from the UK, we rely on UK adequacy regulations (such as for transfers to the EEA and other countries deemed adequate by the UK Government). For transfers to other countries, we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Agreement (IDTA) or the Addendum to the EU Standard Contractual Clauses, to ensure your data protection is not materially lowered and is consistent with UK data protection law.
10. Children's Privacy
Our services are not intended for children under 13, and we do not knowingly collect personal information from children under 13\. If we become aware that we have collected personal data from a child under 13 without verification of parental consent, we take steps to remove that information from our servers.
If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us.
For users between the ages of 13 and 18, we may provide additional protections. In the UK, we are committed to complying with the Online Safety Act and implementing appropriate measures to protect users under 18, which may include age assurance processes and specific content suitability measures. The data processed for these purposes will be handled in accordance with this Privacy Policy.
11. Updates to This Policy
We may update this Privacy Policy from time to time. We'll notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after changes become effective constitutes acceptance of the updated policy.
12. Third-Party Analytics Provider Privacy Policies
Our analytics providers have their own privacy policies that govern their collection and use of data. We encourage you to review their policies:
You may opt out of certain third-party analytics by visiting the links above and following their opt-out procedures.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
Email: privacy@plugg.in
Mail: Plugg Privacy Team
[Company Address]