Legal

Privacy Policy

Last updated January 10, 2025

This policy explains what data Flenxa collects, how we use it, and the choices you have. We try to keep it plain and short — if anything's unclear, email us at hello@flenxa.app.

Who we are

Flenxa is a two-sided creator marketing platform. On one side, Creators sign up to earn money by joining public campaigns (submitting short-form videos in exchange for a reward) or by being booked directly by brands at rates the creator has published. On the other side, Advertisers (brands, agencies, and individual marketers) sign up to launch those campaigns and book those creators, with money held in escrow until delivery is approved.

When this policy says "we", "us", or "our", we mean Flenxa. When it says "you", we mean the person using the platform — as either a Creator or an Advertiser. The two account types are separate: signing up as a Creator does not create an Advertiser account, and vice versa. If you use both roles, they are two separate records under the same email.

What we collect

We only collect what Flenxa actually needs to run. Concretely:

When you register as a Creator, we collect the name and email you enter, a username, a hashed password (we never see your plaintext password), your country, and optionally a phone number and profile photo. If you later fill in your public media kit, we also store your bio, content niches, portfolio items (image and link uploads), and the per-deliverable rates you publish (e.g. "TikTok Video — $500").

When you register as an Advertiser, we collect your full name, your work email, your company or brand name, and optionally a company address and phone number for invoicing and tax purposes. We require you to verify your email address before you can book a creator or fund a campaign.

When you connect TikTok, Flenxa receives — through the official TikTok API and only within the scopes you approve — your public TikTok display name, avatar, follower count, and the metadata of videos you post (video URL, thumbnail, view count, like count, comment count, share count). We do not receive your TikTok password, private messages, or the ability to post to your account on your behalf. We use this data solely to display your stats on your Flenxa profile and to verify campaign submissions.

When you take part in a campaign or booking, we store the brief you or the brand wrote, the deliverable URLs you submit, any notes attached to the delivery, timestamps of every state change (submitted, funded, delivered, released, disputed, refunded), and the agreed and actual amounts of money involved. For each booking we also generate a public tracking token — anyone the sender shares this token URL with can see a limited view of the booking's status.

When money moves, we store the amount, the currency, the payment method, the internal transaction ID, and the reference returned by the payment provider. For payouts we store the destination (your PayPal email, wallet address, or bank details you enter into the withdrawal form). Raw card numbers, CVVs, and bank credentials are never sent to or stored on Flenxa servers — they are collected on the payment provider's own hosted page, and we only receive a status callback.

Technical data that any web application collects: your IP address, browser and device fingerprint (user-agent), the pages you visit on Flenxa, and cookies (see the Cookies section). We use this for authentication, session security, rate-limiting, and abuse investigation.

Support correspondence: any email, ticket, or dispute message you send us, and our replies.

How we use it

Every field Flenxa collects maps to a specific job:

  • Running your account — logging you in, showing your dashboard, matching Creator profiles to Advertiser searches, delivering in-app notifications.
  • Verifying submissions — when a Creator submits a video URL for a campaign, we fetch that video's public metrics from TikTok to confirm it exists, belongs to the connected account, and hits any minimum views, likes, comments, or duration set by the Advertiser. Rewards are calculated from those metrics.
  • Escrow and payouts — we use your identity, bank/wallet details, and the booking record to route money correctly: Advertiser → escrow → Creator wallet on release, or Advertiser wallet on refund. We keep an internal ledger of every credit and debit for accounting and dispute resolution.
  • Enforcing the platform — detecting fake submissions, view-inflation bots, duplicate accounts, and payment fraud. This can involve reviewing linked social account data, IP history, and transaction patterns.
  • Dispute mediation — when a booking is disputed, our admin team reads the brief, the delivered content, both sides' notes, and the escrow history to decide whether to release or refund. Dispute records are retained for audit.
  • Transactional email — booking requests, escrow-funded alerts, delivery submitted, auto-release warnings, payout confirmations, password resets. You cannot opt out of transactional email while your account is active.
  • Product email — occasional product announcements, feature releases, or opportunity emails. These are separate from transactional email and you can unsubscribe from them at any time via the link in the email footer.
  • Legal compliance — meeting tax, anti-money-laundering, and record-keeping requirements in the jurisdictions where we operate.

Flenxa does not sell your personal data to third parties, ever. We do not run behavioural ad networks and we do not share your data with data brokers.

How we share it

Data leaves Flenxa's servers in a limited number of well-defined situations:

  • Creator profiles are public. Your Creator username, name, avatar, bio, niches, portfolio, published rates, and aggregate engagement stats (across approved campaign submissions) are visible to anyone on the internet at your public profile URL. Do not put anything in these fields you would not want indexed by search engines.
  • Between the two sides of a booking. When an Advertiser books a Creator, each party sees the other's identifying details (name, avatar, primary contact email/username), the full brief, the agreed price, the delivered URLs, any notes, and the escrow state. Neither side sees the other's payment method or bank details.
  • Public booking tracking pages. Each booking has a randomly generated tracking token. Anyone the Advertiser gives that token URL to can see a public tracking view of the booking's status. Do not share the tracking URL with anyone you don't want to see it.
  • Payment processors. We share the transaction amount, currency, reference, and the payer's or payee's identifying details with the specific gateway you chose for that transaction (PayPal, Paystack, Cryptomus, Bachs, Perfect Money, or Monnify). We share nothing with processors you did not use.
  • Infrastructure sub-processors. Our hosting, email delivery, and error-monitoring providers process data on our behalf strictly under contract, and are not permitted to use it for their own purposes.
  • Admin review. Our internal admin team can read the data described above when investigating disputes, fraud reports, and support tickets. Access is logged.
  • Legal requests. If we receive a valid subpoena, court order, or law-enforcement request in a jurisdiction we operate in, we will comply — but we scrutinise overbroad requests and push back where appropriate.
  • Business transfers. If Flenxa is acquired, merged, or reorganised, your data may transfer as part of that transaction. We will notify you before any such transfer takes effect and give you a reasonable chance to delete your account first.

Cookies

Flenxa uses cookies and equivalent client-side storage for the following, and nothing else:

  • Session cookie — keeps you logged in for the length of your session. Deleting it logs you out.
  • CSRF token cookie — protects forms and API calls from cross-site request forgery. Required.
  • Remember-me token — if you tick "remember me" at login, we store a long-lived cryptographic token so you don't need to log in every visit.
  • Theme preference — remembers whether you chose light or dark mode.
  • Locale preference — remembers your language selection.

We do not use advertising cookies, third-party retargeting pixels, or cross-site tracking. We do not sell cookie-derived data. If we ever add optional analytics or product-experiment cookies, they will be opt-in and toggleable in your account.

Your rights

Depending on where you live — GDPR (EU/UK), CCPA/CPRA (California), Nigeria's NDPR, and comparable frameworks elsewhere — you have some or all of the following rights over the data Flenxa holds on you:

  • Access — request a copy of the personal data we hold on you.
  • Correction — fix inaccurate data. Most fields (name, bio, niches, rates, portfolio, connected accounts, payout details) can be edited directly from your Settings without contacting us.
  • Deletion — request permanent removal of your account. See "Data retention" below for what happens to financial and audit records after deletion.
  • Portability — receive your data in a machine-readable format (JSON or CSV).
  • Objection — object to specific kinds of processing, such as product marketing emails.
  • Withdrawal of consent — where we relied on your consent (for example the TikTok connection), you can revoke it at any time from your Settings, and we will delete the associated tokens on the next sync.
  • Complaint — lodge a complaint with your local data-protection authority if you believe we have mishandled your data.

To exercise any of these rights, email hello@flenxa.app from the address on your account. We will respond within 30 days, and may ask for reasonable proof of identity if the request could expose someone else's data.

Data retention

Flenxa retains data only for as long as it needs to, and grouped by category:

  • Active account data is kept for as long as your account exists.
  • Deleted accounts — profile, contact, and content data are removed or anonymised within 30 days of deletion. Your public profile URL stops resolving immediately.
  • Financial records — bookings, payments, escrow ledgers, and payouts are retained for up to 7 years after the transaction, because tax and anti-money-laundering law in most jurisdictions requires it. These are anonymised where the underlying account has been deleted (your name is redacted but the transaction record remains for audit).
  • Dispute records — for our own legal defence and to spot repeat abuse, we retain dispute reasons, admin decisions, and the surrounding messages for up to 3 years after the dispute is closed.
  • Server logs — request logs, error traces, and IP audit logs are kept for up to 90 days for security investigation, then rotated out.
  • Email suppression list — if you unsubscribe from a specific email stream, we retain the suppression record indefinitely so we don't accidentally re-add you.

Security

Flenxa takes protecting your data seriously. Specifically:

  • All traffic is served over HTTPS. The site rejects non-encrypted requests at the load balancer.
  • Passwords are stored as bcrypt hashes, never in plaintext. We cannot recover your original password if you forget it — you have to reset it.
  • Escrow is race-safe. Fund, release, and refund operations use row-level database locks and re-verify state inside the transaction, so a stuck double-click, a network retry, or a duplicate webhook cannot double-pay or double-refund.
  • Payment providers are PCI-compliant, and card details are collected on the provider's own hosted page, never on ours.
  • Access to admin tooling is role-limited and audit-logged, so we know who read or edited what and when.
  • The TikTok integration uses only the OAuth scopes the platform explicitly needs, and tokens are stored encrypted at rest.

No system is invulnerable. If Flenxa ever suffers a security incident that affects your personal data, we will notify affected users and any required regulators within the time limits set by applicable law.

Third-party services

Flenxa sends specific data to specific third parties. This is the complete list — each provider has its own privacy policy which governs what they do with what they receive:

  • TikTok — for the "Connect TikTok" feature (OAuth) and to fetch public video metrics used for campaign verification.
  • PayPal — to process card payments, PayPal-balance payments, and to send Creator payouts to PayPal email addresses.
  • Paystack — to process card payments, primarily for African markets.
  • Cryptomus — to process cryptocurrency payments and payouts.
  • Bachs — to process card payments in additional supported regions.
  • Perfect Money — to process Perfect Money e-currency transactions.
  • Monnify — to process Nigerian bank-transfer payments.
  • SMTP email provider — to deliver transactional and product email.
  • Hosting provider — to run our servers and store our database.

We do not use Google Analytics, Meta Pixel, or any third-party advertising or attribution SDK. If that changes, this list will be updated first.

Children

Flenxa is not intended for anyone under 16. We do not knowingly collect personal data from anyone under that age. Some payment providers and jurisdictions require a higher minimum (18) for financial transactions, and in those cases the higher limit applies. If you believe a minor has registered, email hello@flenxa.app and we will remove the account and any associated data.

Changes to this policy

We update this policy when the platform changes materially — for example when we add a new payment provider, a new social integration, or a new user-facing feature that processes personal data in a new way. When we make a material change, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify active users by email at least 14 days before the change takes effect where the change materially affects your rights.
  • Keep the previous version available on request.

Continued use of Flenxa after the effective date of a revised policy means you accept the new version. If you don't, you may delete your account before then.

Contact us

For any question, request, or complaint about your data, contact us at hello@flenxa.app. Please email from the address on your account so we can identify you without extra verification steps.