Skip to content
Crealenty policies

Privacy Notice

This notice explains what Crealenty handles, including optional Google Analytics and subscription-billing data, why it is used, who receives it, how long selected records remain, and the controls available to you.

Version 2026-08-24

Controller and privacy contact

Nerdy Clock is the personal information controller and legal operator of this Crealenty pilot.

Operator address: Philippines

Privacy contact or data-protection representative: Data Protection Officer, crealenty_privacy@nerdyclock.com

Information we handle

The information involved depends on whether you browse publicly, join as talent, or manage a recruiter workspace.

  • Account and identity data, such as email, authentication identifiers, display name, role, preferences, active workspace, and policy acceptance. Acceptance evidence includes the policy versions and content digests, the exact public controller/contact snapshot, a server timestamp, browser information, request reference, and—when configured—a dedicated keyed hash derived from the connection address. Crealenty does not store the raw address in that record and cannot join this hash to browsing analytics.
  • Profile and portfolio data, including biography, location, categories, skills, rates, availability, links, media, embeds, custom presentation code, and visibility choices.
  • Marketplace and safety data, including job posts, applications, drafts, invitations, auditions, attachments, offers, bookings, reviews, shortlists, team membership, messages, blocks, reports, moderation actions, and related history.
  • Subscription and billing data, including the selected plan, billing interval, USD price, promotion, PayPal payer and subscription identifiers, transaction identifiers, payment status and amount, renewal and paid-through dates, cancellation, refund, reversal and dispute details, and provider-verification events. Crealenty does not receive or store your full card number or bank-account credentials.
  • Technical and usage data, including IP-derived abuse signals, hashed viewer identifiers, browser or device information, referrer, profile views, search appearances, timestamps, logs, security events, and—only after analytics consent where the optional feature is enabled—the limited Google Analytics information described below.

How we use and show information

We use information to create and secure accounts; operate discovery and hiring workflows; start, verify, administer, cancel, refund, and reconcile Crealenty software subscriptions; deliver messages and notices; apply limits; prevent abuse and payment fraud; investigate reports and disputes; maintain accounting and audit records; understand marketplace use; troubleshoot; and improve the pilot. We use consent where required and otherwise rely on the need to provide the requested service, protect legitimate safety and operational interests, or comply with law.

Published talent profiles, selected portfolio content, public reviews, and open jobs can be visible without signing in and may be indexed or copied by others. Drafts, private auditions, internal shortlist notes, team details, and other restricted workflow records are limited to authorized participants according to the product controls, but no system can promise absolute confidentiality.

Direct messages are stored by Crealenty and are not end-to-end encrypted. Message content may be processed for delivery, unread-message email notices, abuse prevention, support, report investigation, legal compliance, and enforcement. Avoid sending information that is not necessary for the collaboration.

Processors, recipients, and third parties

We disclose only what is reasonably needed to users involved in a workflow, to authorities when legally required, during a legitimate business transfer, or to provider categories that operate the service for us.

  • Cloud hosting, database, authentication, object storage, content delivery, backup, and search-index providers.
  • Email delivery and operational communications providers.
  • PayPal processes Crealenty subscription checkout, recurring charges, cancellations, refunds, reversals, and disputes. Crealenty sends PayPal the selected plan and internal subscription reference and receives the payer, agreement, transaction, amount, currency, status, and event data needed to administer access. PayPal handles information under its own terms and privacy notice.
  • Security, logging, performance, and error-monitoring providers, if enabled for the deployment.
  • Services you or another user choose to embed or contact from a portfolio, such as supported video, audio, or social platforms. Those third parties receive requests under their own policies. Sandboxed portfolio code can make restricted HTTPS requests but cannot use camera, microphone, location, payments, or forms through the sandbox.

Optional Google Analytics

When this feature is enabled, Crealenty uses Google Analytics 4 on an allowlist of public Crealenty-owned pages only after you choose Allow analytics. Declining does not restrict the service. Before consent, or after you decline or withdraw, Crealenty does not load the Google tag or send Google Analytics measurements.

We use consented analytics to understand aggregate public-site traffic, page and session engagement, and broad usage patterns so we can troubleshoot and improve Crealenty. The platform tag disables Google Signals, advertising storage, advertising user data, and ad personalization, and it does not request advertising or remarketing measurement.

  • Google receives a sanitized public page location and path, a generic page title, the origin of the referrer, a timestamp, a pseudonymous first-party client or session identifier, and ordinary request information such as browser, device, language, and connection IP. Google Analytics may derive approximate location from the IP and says it discards the raw IP after use. Crealenty does not receive raw IP addresses in Google Analytics reports.
  • Crealenty does not send Google Analytics account identifiers, email addresses, form or message content, URL query strings or fragments, or private application URLs. Public job and talent identifiers are replaced with generic placeholders. A public blog article slug can remain in its sanitized page path.
  • After consent, Google Analytics can set host-only first-party cookies whose names begin with cr_site to distinguish visitors and sessions. Their default expiry is up to two years from creation or update, subject to shorter browser limits and earlier deletion when you withdraw or clear browser data. Crealenty stores your allow or decline choice in local browser storage until you change it or clear that storage.
  • Crealenty configures its standard Google Analytics property to retain user-level and event-level data for 2 months, with reset on new activity turned off; expired data is then deleted on Google’s monthly schedule. Standard aggregated reports are not removed by that setting and may be kept longer for trend reporting until no longer needed. Withdrawing consent stops future collection but does not reverse processing that occurred before withdrawal; earlier measurements remain subject to these retention and deletion rules.
  • Google receives and processes this analytics information under the Google Analytics terms and data-protection arrangements. Google operates geographically distributed facilities, so analytics information may be processed outside the Philippines or your country, including in places with different data-protection laws. Crealenty remains responsible for its use of the service and applies the available contractual and transfer safeguards.
  • Use Analytics privacy on an eligible public page to review the choice. Withdrawing immediately stops future collection by disabling platform analytics, removes Crealenty’s cr_site analytics cookies, clears the saved preference, and reloads a fresh consent prompt. You can also clear browser storage, use Google’s Analytics opt-out browser add-on, or contact the privacy address above about an analytics-data request.
  • A creator may separately configure analytics or other integrations on their published portfolio. Those run in a separate public portfolio document with a separate consent prompt and send information to destinations selected by that creator. The creator is responsible for disclosing those services and obtaining any required consent; your Crealenty platform-analytics choice does not automatically authorize a creator’s integrations.

Retention and account deletion

Raw search-appearance records are scheduled for deletion after 30 days. Raw profile-view records are scheduled for deletion after 90 days. Sent or cancelled hiring-email delivery records are deleted after 30 days. Production request and error logs must be configured for no more than 30 days unless a specific security incident or legal hold requires longer preservation. Optional Google Analytics retention is described in its dedicated section above.

Crealenty keeps subscription, transaction-status, cancellation, refund, reversal, dispute, and provider-verification records while the subscription or account is active and afterward for only as long as reasonably needed for accounting, tax, fraud prevention, chargeback or dispute handling, security audit, and legal obligations. A deletion request may not erase billing records that must still be retained for those purposes. PayPal retains its own payment records under its policies.

We keep account and portfolio data while the account is active. After deletion, shared workflow, message, booking, offer, review, report, and safety records are reviewed at least annually and are deleted or anonymized when no longer needed for a counterparty record, dispute, safety investigation, fraud prevention, or legal obligation. A documented legal hold may extend that event-based period. Published content can remain in third-party caches or copies outside our control.

Deleting your account removes or clears public profile and portfolio details, private drafts, saved items, analytics tied to your profile, preferences, and other removable data. Crealenty retains an anonymized profile tombstone and may retain non-public transaction, booking, offer, application, audition, message, review, report, moderation, and media evidence needed to preserve shared history, safety, or legal claims. Your authentication account is detached and deleted; retained records no longer use your public identity.

Your choices and rights

Use profile visibility, portfolio publishing, notification, block, report, workspace, account, and Analytics privacy controls to manage common uses. Do not publish information you want to keep private.

Depending on applicable law, you may ask to access, correct, export, object to, restrict, or delete personal information, or withdraw consent. Contact Support with the account email and enough detail to verify and handle the request. You may also complain to your local privacy regulator.

We use access controls, scoped service roles, transport security, rate limits, and restricted media and script handling, but no online service is risk-free. Use a unique password, keep your account secure, and report suspected compromise promptly.

We will publish a new version when this notice changes materially. Append-only policy acceptance records are retained only as evidence of the notice and terms presented, for the life of the account and then with its anonymized tombstone while shared workflow or safety records remain. They are removed if that tombstone is finally erased and are not used for analytics.