Privacy
Last updated 31 August 2026
Cliptally helps a brand run a gifting round with the creators it already works with. The brand sends each creator one link; the creator uses it to claim a gift and, later, to hand back the URL of the post they published. This page says exactly what is stored, why, who else sees it, and how long it lives.
What is collected, and from whom
From the merchant, when they install and use the app:
- The shop domain, shop name and currency, from Shopify.
- Campaign names, post-by dates, and the product chosen as the gift — its title and image, read from the shop’s own catalogue.
- For each creator on their list: the handle, and optionally a name, a contact note, a gift label, a due date, a free-text note, and a record that a payment was made — its amount, currency and date.
From the creator, entered by them on their own link:
- The URL of the post they published.
- Where the brand has enabled the claim step: the fact and time that they agreed to post by the agreed date, and which option of the gift they chose.
The shipping address is not stored by Cliptally. When a creator gives it, it is written straight onto the $0 order in the brand’s own Shopify store so the gift can be posted, and then forgotten. It is never saved to Cliptally’s database, and the only copy is the one on the brand’s order.
Cliptally does not read the merchant’s customer list, and does not create customer records for creators. Creators have no account here and never will.
Why
To run that one gifting round: to create the order, to show the brand who has claimed, posted and been paid, and to let the brand chase the people who have not. Nothing is used for any other purpose.
Who else sees it
- Shopify — the gift order, including the shipping address, is written into the merchant’s own Shopify store.
- Railway — hosts the application and its database.
- TikTok and YouTube — when a creator submits a post link on one of those platforms, that URL is sent to the platform’s public oEmbed endpoint to confirm the post is live and who published it. Nothing else is sent, and no request is made for any other platform.
Personal data is never sold, never shared for advertising, and never sent anywhere else. Cliptally sends no email or messages to creators at all — the brand contacts them directly.
What Cliptally deliberately does not do
- No creator accounts, passwords or profiles.
- No profiling, scoring, ranking or automated decisions about people.
- No advertising, no marketing messages, no tracking pixels, no third-party analytics.
- No payment processing. A payment record is a note the brand writes down; no money moves through Cliptally.
How long it is kept
- Campaign and creator records live for as long as the merchant keeps the app installed.
- A creator link stops working 30 days after it was last opened.
- The brand can delete a creator at any time. That erases the handle, name, contact, submitted posts and payment record outright — not a flag, an actual delete — and takes their link with it.
- When a merchant uninstalls, Shopify sends a shop erasure request 48 hours later, and everything belonging to that shop is deleted.
- An erasure request for an individual deletes their record immediately.
- A record that an action happened is kept for security purposes. It holds no names, handles, emails or addresses — a person appears in it only as a short one-way hash. That hash cannot be read back into a handle, but someone who already had a list of handles could check whether one of them appears in it, so it is treated as personal data and deleted along with everything else belonging to the shop.
Rights
A creator can ask the brand that sent them the link to correct or erase their data, and the brand can do it themselves in one click. Requests can also be sent to support@cliptally.app and are passed to the brand and acted on. Requests arriving through Shopify’s own privacy channels are handled automatically.
For the data a brand collects from its creators, the brand decides what is collected and why, and Cliptally processes it on their instructions.
Security
Traffic is encrypted with HTTPS, and the database has no public address — it can be reached only by the application, over a private network. The link in a creator’s URL is never stored as you received it: what is kept is a one-way hash of it, plus a sealed copy that can only be opened with a key held outside the database. A copy of the database alone therefore yields no working links. Access is limited to the operator named below, over accounts protected by two-factor authentication, and test data is kept separate from live data.
Contact
Cliptally is operated by Stacklane, Thessaloniki, Greece. support@cliptally.app