Privacy Policy
Effective date: 29 July 2026
This policy explains what personal data CreatorCount collects, why we collect it, how long we keep it, and the rights you have over it. It is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
CreatorCount is operated by Jack Wilson, a sole trader established in the United Kingdom (“CreatorCount”, “we”, “us”). We are the data controller for the personal data described in this policy.
Postal address: 20 Wenlock Road, London, England, N1 7GU, United Kingdom
Email: hello@creatorcount.com
We are not required to appoint a Data Protection Officer. Privacy questions go to the email address above.
2. What CreatorCount does
CreatorCount gives brands and agencies (each a “workspace”) a dashboard showing how the public TikTok videos of the UGC creators they work with are performing. A creator appears in a workspace only after they have personally connected their own TikTok account through TikTok’s official Login Kit and granted consent on TikTok’s consent screen.
We access TikTok data through TikTok’s official Display API, read-only. We cannot post, edit, delete, or interact with anything on a creator’s TikTok account.
3. Personal data we collect
3.1 Creator data received from TikTok
When a creator authorises CreatorCount, we request exactly three TikTok scopes and nothing more:
- user.info.basic — TikTok Open ID and Union ID, display name, and avatar image URL
- user.info.stats — follower count, following count, total likes count, and total video count
- video.list— the creator’s public videos: the TikTok video ID, post date, title, description, duration, cover image URL, share URL, and the view, like, comment, and share counts for each
We also store the OAuth access and refresh tokens that TikTok issues, the scopes granted, and their expiry times, so that we can keep statistics up to date without asking the creator to reconnect daily.
3.2 Data we generate ourselves
- A label chosen by the workspace to identify the creator internally (for example “Sarah – skincare account”)
- A single-use invitation link token used to tie a creator’s TikTok authorisation to the right workspace
- Connection status and timestamps: when the account was connected, when it was last refreshed, and any error returned by TikTok on the last refresh
- A time-series history of the public metrics above. Each time we refresh, we store a dated snapshot of the counts so the dashboard can show performance over time
3.3 Workspace account data
For the person administering a workspace, we hold the email address used to sign in and a session cookie that keeps them logged in. The sign-in cookie is strictly necessary for the service to function.
3.4 What we never receive
We do notreceive or store TikTok passwords, private or draft videos, direct messages, comment content, audience demographics, or the email addresses and phone numbers attached to a creator’s TikTok account. TikTok never shares credentials with us; the authorisation happens entirely on TikTok’s own systems.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Showing a creator’s public profile and video statistics to the one workspace they authorised | Consent (Art. 6(1)(a)), given by the creator on TikTok’s consent screen |
| Storing dated snapshots so the workspace can see performance trends over time | Consent (Art. 6(1)(a)) |
| Refreshing OAuth tokens and running the daily sync that keeps figures current | Consent (Art. 6(1)(a)) |
| Operating, securing, debugging, and maintaining the service; keeping records of consent and deletion requests | Legitimate interests (Art. 6(1)(f)) — running a secure, reliable service and being able to demonstrate compliance |
| Authenticating the workspace administrator | Contract (Art. 6(1)(b)) — providing the service they signed up for |
Where we rely on consent, a creator can withdraw it at any time (see section 8). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
We do not sell personal data, we do not use it for advertising or profiling, we do not use it to train machine learning models, and we do not make automated decisions that produce legal or similarly significant effects.
5. Who we share data with
A creator’s data is visible only to the single workspace they authorised. It is never shown to other workspaces or other creators.
We use the following processors to run the service:
- Vercel Inc. (United States) — application hosting and the scheduled job that refreshes statistics
- Neon Inc. (United States) — the PostgreSQL database where the data described above is stored
Each is bound by a data processing agreement permitting them to process data only on our instructions. We also exchange data with TikTok (TikTok Information Technologies UK Limited and its affiliates), which is the source of the creator data and an independent controller of it under its own privacy policy.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever sold or transferred, data may pass to the acquirer, who would remain bound by this policy.
6. International transfers
Our hosting and database providers store and process data in the United States. This means personal data is transferred outside the United Kingdom.
For these transfers we rely on the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, incorporated into our agreements with Vercel and Neon, and where applicable on those providers’ certification under the UK Extension to the EU–US Data Privacy Framework. You can request a copy of the relevant safeguards by emailing us.
7. Security
- TikTok access and refresh tokens are encrypted at rest with AES-256-GCM using a key held separately from the database. They are never sent to a browser, never shown to a workspace, and never shared with a third party.
- All traffic to and from the service is encrypted over HTTPS.
- The dashboard is behind authentication, and each workspace can query only its own creators.
- The invitation link that starts the connect flow is a single-purpose random token, and the authorisation flow is protected against cross-site request forgery.
No system is perfectly secure, but if a breach occurs that risks people’s rights and freedoms we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell affected people directly where the risk to them is high.
8. Retention and deletion
We keep a creator’s data for as long as their connection to a workspace is active, because the product’s purpose is to show performance over time. There are three ways it ends:
- The creator revokes access in TikTok.In the TikTok app, go to Settings and privacy → Security and permissions → Manage app permissions, and remove CreatorCount. All future syncing stops immediately. Ask us to erase the history we already hold and we will.
- The workspace removes the creator. This revokes our TikTok token and permanently deletes the creator record together with every video and snapshot belonging to it.
- Either party asks us directly. Email hello@creatorcount.com and we will erase the data within 30 days and confirm when it is done.
Deletion is a hard delete, not a flag. Backups held by our database provider are overwritten on a rolling cycle and are fully cycled out within 30 days. If a workspace closes its account, we delete its creators and their data within 30 days.
9. Your rights
Under UK data protection law you have the right to: be informed about how your data is used; access a copy of it; have inaccurate data corrected; have your data erased; restrict or object to our processing of it; receive it in a portable, machine-readable format; and withdraw consent at any time.
To exercise any of these, email hello@creatorcount.com. We respond within one month, and we do not charge for it. We may ask you to confirm your identity — normally by demonstrating control of the TikTok account concerned — so that we do not disclose data to the wrong person.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113). We would appreciate the chance to put things right first.
10. Cookies
We use a small number of strictly necessary cookies: a session cookie that keeps a workspace administrator signed in, and a short-lived cookie used during the TikTok authorisation flow to protect against cross-site request forgery. We do not use advertising, analytics, or tracking cookies, which is why you are not asked for cookie consent.
11. Children
CreatorCount is a business tool and is not directed at children. In keeping with TikTok’s own minimum age, creators must be at least 13 years old (and old enough under local law to consent to this processing) to connect an account. If we learn that we hold data about a child below that age, we will delete it.
12. Changes to this policy
We will post any changes on this page and update the effective date above. Where a change materially affects how we use personal data, we will contact affected workspaces and, where we rely on consent, ask for it again.