Privacy Policy
Voltr, a service operated by Voltr, Inc. ("Voltr," "we," "us," or "our"), is committed to protecting your privacy. This policy describes what personal information we collect, how we use it, how we disclose it, how long we retain it, your rights, and how to contact us with questions or requests.
1. Scope of This Policy
This Privacy Policy describes how Voltr collects, uses, discloses, retains, and protects personal information in connection with our website, platform, integrations, beta services, communications, and related services. This policy applies to:
- Users: Businesses and individuals who create Voltr accounts, request access, use the platform directly, or act as authorized users of a customer workspace.
- Creators: Individuals whose profile information, content, performance metrics, contact information, or other data may be accessed through third-party platform APIs or otherwise processed in connection with creator discovery, outreach, campaign management, attribution, advertising, or analytics, regardless of whether those individuals have a Voltr account.
- End Customers: Individuals whose personal information may be processed when a customer connects Shopify or another e-commerce, advertising, or analytics platform to Voltr.
- Website Visitors and Prospects: Individuals who visit our website, request access, subscribe to updates, communicate with us, or interact with our marketing.
Depending on the context, Voltr may act as a controller/business for account, billing, website, security, legal, analytics, and business operations data, and as a processor/service provider for personal information processed on behalf of a customer through the Subscription Services. Our Data Processing Addendum describes these roles in more detail.
If you are a creator, end customer, parent, guardian, or other individual whose data has been processed by Voltr and you wish to exercise privacy rights, please contact us at contact@getvoltr.com. We will respond to verifiable requests in accordance with applicable law.
2. Information We Collect
From Users:
- Account data: Name, email address, company name, billing information.
- Usage data: Platform activity, campaign performance, and feature interactions.
- Connected platform credentials: OAuth tokens and permissions for TikTok, TikTok Shop, Meta, and Shopify integrations.
- E-commerce data: If you connect a Shopify or similar store, we may receive merchant-level business data and, separately, personal data about your end customers.
- Device data: IP address, browser type, and device identifiers for security and fraud prevention.
- Playbook and newsletter signups: If you request a guide or email series, we collect the name, email address, and campaign parameters you submit so we can deliver the requested material and follow-up sequence. Every series email includes an unsubscribe mechanism.
- AI feature data: If you use Voltr's AI-enabled features, we may process campaign briefs, creator profiles, public creator content, performance metrics, outreach history, customer instructions, and related context to generate outreach drafts, recommendations, forecasts, summaries, classifications, and analysis. We do not intentionally send payment card data, passwords, or sensitive end-customer personal information to AI providers.
About Creators (via third-party APIs):
- Public profile information (name, handle, biography, profile image).
- Publicly available content performance metrics (follower counts, engagement rates).
- Contact information made publicly available by the creator on the applicable platform.
Creator data is accessed through official third-party platform APIs, customer-authorized platform connections, customer-provided or creator-provided data, and other lawful sources permitted by applicable law and platform terms. We do not scrape or collect creator data through unauthorized means.
Browser-assisted inbox features: If Voltr grants you access and you affirmatively enable our browser extension, the extension reads only the TikTok conversation you have open. It sends your TikTok handle and a short recent conversation snippet to Voltr, which sends the snippet to Anthropic to classify the conversation. Conversation text is processed in transit but is not stored by Voltr. We store a one-way hash of the thread identifier, the classification label and confidence, and account-linked product or error events that do not contain message text. The pairing credential is stored locally by your browser and only its cryptographic hash is stored by Voltr. Suggested responses come from reply pools you approve. The feature does not send messages, accept message requests, or agree to commercial terms for you.
3. How We Use Your Data
- To provide, maintain, and improve the Voltr platform.
- To process payments and manage subscriptions.
- To send transactional emails, product updates, service notices, and marketing communications where permitted by law.
- To prevent fraud and ensure platform security.
- To comply with legal obligations and respond to lawful requests.
- To facilitate creator discovery and outreach campaigns as directed by Users.
- To provide AI-enabled features, including outreach drafts, creator recommendations, campaign analysis, forecasts, ad analysis, summaries, and workflow automation, subject to the limitations in this Privacy Policy, our Terms of Service, applicable law, and applicable third-party platform terms.
Platform Data obtained through TikTok, TikTok Shop, Meta, Instagram, Shopify, or other third-party platform integrations is used only to provide, secure, maintain, troubleshoot, and support the customer-authorized integration; to comply with applicable law; and as otherwise permitted by the applicable platform terms and developer policies. We do not sell Platform Data or use it to train general-purpose AI models.
We do not use creator data for purposes beyond those described above and those permitted by the applicable third-party platform's developer policies.
4. Data Sharing
We do not sell your personal information. We do not share personal information for cross-context behavioral advertising as defined under the California Privacy Rights Act (CPRA), and we do not engage in the "sharing" of personal information as defined under CPRA. We may share data with:
- Service providers and sub-processors that process data on our behalf and under contractual restrictions. Our current sub-processors include: Supabase (database, authentication, and file storage), Vercel (application hosting and edge delivery), Resend (transactional and lifecycle email), Anthropic (AI-enabled features), OpenAI (audio transcription and related AI-enabled features), Sentry (error monitoring and diagnostics), and Stripe (payment processing). We will update this list as our processors change.
- Third-party platforms (TikTok, TikTok Shop, Meta, Shopify) as necessary to operate integrations you have authorized.
- Law enforcement or regulatory authorities when required by applicable law or valid legal process.
- A successor entity in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
Where we use AI providers to support Voltr features, those providers process data as service providers or sub-processors under contract and may not use Customer Content or Platform Data to train general-purpose models except as expressly permitted by our agreement with them and applicable platform terms.
5. End-Customer Data
If you integrate an e-commerce store with Voltr, we may receive personal data about your end customers (individuals who have purchased from your store). End-customer data is treated as a distinct and more sensitive data category. We process end-customer data solely to provide the services you have requested and do not use it for any independent purpose. You are responsible for ensuring that your collection and sharing of end-customer data with Voltr is disclosed in your own privacy notices to those customers.
If a customer connects a Shopify store to Voltr, Voltr may process Shopify store, order, customer, and related e-commerce data as a service provider or processor on behalf of that customer. Voltr processes Shopify data only to provide, secure, maintain, troubleshoot, and support the customer-authorized Shopify integration; to comply with applicable law; and as otherwise permitted by Shopify's applicable terms and policies.
For Shopify integrations, Voltr processes Shopify privacy webhooks relating to customer data access requests, customer redaction requests, and shop redaction requests, including customers/data_request, customers/redact, and shop/redact. When Voltr receives a valid Shopify privacy webhook, Voltr will acknowledge receipt and complete the required access, deletion, redaction, or shop-level deletion action within the timeframe required by Shopify and applicable law, unless retention is legally required or permitted.
6. Data Retention and Deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the platform, maintain integrations, support customers, comply with legal obligations, prevent fraud and abuse, resolve disputes, enforce agreements, and maintain security.
Unless a shorter period is required by law, platform policy, or a verified deletion request, our general retention periods are:
- Creator profile data sourced through TikTok, TikTok Shop, Meta, Instagram, Shopify, or other third-party platform APIs: retained for up to 12 months from the last campaign activity involving that creator, then deleted, de-identified, or anonymized, unless a shorter period is required by the relevant platform terms or applicable law.
- Campaign and outreach records: retained for up to 24 months for analytics, auditability, customer reporting, and historical reporting, then deleted, de-identified, or anonymized.
- User account data: retained while the account is active and for up to 7 years after account closure where needed for tax, accounting, legal, security, dispute, and compliance purposes.
- Billing records: retained as required for tax, accounting, audit, chargeback, and legal compliance.
- Marketing and website analytics: retained for up to 13 months, then deleted, aggregated, or anonymized.
- Playbook and newsletter signups: retained while the requested series is active and afterward as needed to honor unsubscribe and suppression choices, respond to requests, and measure campaign performance. You may unsubscribe from the series at any time.
- Server logs and security data: retained for up to 12 months for fraud prevention, security, debugging, and incident response, unless a longer period is needed for investigation or legal compliance.
- Browser-assisted inbox feature data: pairing-token hashes, approved reply pools, thread hashes, classification labels, confidence values, and account-linked product events are retained while the feature or account is active and under the applicable periods above. Pairing tokens expire after 90 days and may be revoked sooner. Account deletion or a verified deletion request removes the creator-scoped active records, subject to the legal, security, and backup exceptions described below.
Platform Data may be subject to shorter retention or deletion periods required by the relevant third-party platform. If a third-party platform revokes Voltr's access, sends a deletion or redaction request, or changes its data use restrictions in a way that requires deletion, we will delete, de-identify, restrict, or render inaccessible the affected Platform Data, typically within 7 days of receiving the request or within the period required by the applicable platform terms.
If you submit a verified deletion request, we generally delete or de-identify personal information within 30 days, unless a different period is required or permitted by applicable law. Some privacy laws give us up to 45 days or longer to respond to certain rights requests, and GDPR requests are generally addressed within one month unless an extension is permitted by law.
After account termination, Customer Content and stored Creator Content are deleted from active systems within 90 days unless a verified deletion request, platform deletion request, or applicable law requires a shorter period, or unless retention is legally required or reasonably necessary for security, fraud prevention, disputes, accounting, tax, or legal compliance. Deleted data may remain in encrypted backups until those backups are overwritten or expire in the ordinary course. Backup data is isolated from active systems and is not restored except for disaster recovery, security, legal, or compliance purposes.
You may request earlier deletion of personal information by contacting contact@getvoltr.com.
7. Cookies, Similar Technologies, and Opt-Out Signals
We use cookies and similar technologies to operate the website and platform, secure accounts, remember preferences, understand product usage, and improve our services. Cookies generally fall into these categories:
- Essential cookies: Required for the platform to function (session management, authentication, security). These are set without additional consent as they are strictly necessary.
- Functional cookies: Used to remember preferences and improve the product experience.
- Analytics cookies: Used to understand website and platform usage, diagnose issues, and improve performance.
- Advertising or marketing cookies: Used only if we enable advertising, retargeting, or similar marketing technologies.
Where required by law, we will request consent before placing non-essential cookies or provide an opt-out mechanism. You may adjust cookie preferences through the cookie banner or account settings where available, or by contacting us. We do not currently sell personal information or share personal information for cross-context behavioral advertising. Where legally required and applicable to our practices, we will honor recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of sale or sharing.
8. Your Privacy Rights
Depending on your state or jurisdiction of residence, you may have the following rights regarding your personal data:
- Right to know/access: Request disclosure of the categories and specific pieces of personal data we have collected about you.
- Right to deletion: Request deletion of personal data we have collected, subject to certain exceptions.
- Right to correction: Request correction of inaccurate personal data.
- Right to opt out of sale or sharing: We do not sell or share personal data as defined under CCPA/CPRA. If this practice changes, we will update this policy and provide an opt-out mechanism.
- Right to limit use of sensitive data: To the extent we process sensitive personal data (as defined under applicable law), you may have the right to limit its use.
- Right to non-discrimination: We will not discriminate against you for exercising any of the above rights.
These rights may apply to residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, Indiana, Montana, Tennessee, New Hampshire, New Jersey, Nebraska, Maryland, Minnesota, and other states with applicable privacy laws, as well as to creators whose data we process regardless of account status, where required by law.
To exercise privacy rights, contact us at contact@getvoltr.com. We may need to verify your identity or authority before fulfilling a request. If you submit a request through an authorized agent, we may require proof of authorization and may ask you to verify your identity directly unless prohibited by law.
If we deny your request, you may appeal by replying to our decision email with "Privacy Appeal" in the subject line or by emailing contact@getvoltr.com. We will respond to appeals within the timeframe required by applicable law.
9. International Users and GDPR
While Voltr is operated from and primarily directed to the United States, we may process personal data of individuals located in the European Economic Area (EEA), the United Kingdom, or other jurisdictions outside the U.S.
Lawful basis under GDPR. Where the General Data Protection Regulation applies, we rely on the following lawful bases under Article 6(1):
- Performance of a contract - to provide platform services to Users.
- Legitimate interests - to operate, improve, and secure the platform, and to facilitate creator outreach as directed by Users, balanced against creators' privacy interests.
- Consent - where required for non-essential cookies and certain marketing communications.
- Legal obligation - to comply with applicable law.
Your GDPR rights. If GDPR applies to you, you have the right to access, rectify, erase, restrict processing of, port, and object to processing of your personal data. You may exercise these rights at contact@getvoltr.com. You also have the right to lodge a complaint with your local supervisory authority.
International transfers. Personal data we collect may be transferred to and processed in the United States. Where required, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms to safeguard such transfers.
Where Voltr processes personal data on behalf of a customer as a processor, Voltr processes that data under the customer's documented instructions and the Voltr Data Processing Addendum. Where required for international transfers, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.
10. Security
We implement security measures consistent with industry standards for SaaS platforms handling personal data, including:
- Encryption in transit (TLS 1.2+) for all data exchanged between users, our servers, and third-party APIs.
- Encryption at rest for all data stored in our primary database (Supabase PostgreSQL with AES-256 encryption).
- Role-based access controls and audit logging on all production systems.
- Secrets and OAuth tokens stored in encrypted form using platform-managed key management.
- Regular dependency and vulnerability scanning, with timely patching of security advisories.
- Incident response procedures including notification to affected users and regulators where required by applicable law.
No system can be guaranteed perfectly secure. If you become aware of a security issue, please report it to contact@getvoltr.com.
11. Third-Party Links
Our platform may contain links to third-party sites. We are not responsible for their privacy practices.
12. Children's Privacy and Minor Creators
Voltr is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13.
Because Voltr processes creator data obtained through third-party platforms, some creator information may relate to individuals under 18. We do not knowingly target, profile, or facilitate outreach to creators under 18 unless permitted by applicable law, platform policy, and the relevant customer's documented authorization. If you are a creator, parent, or guardian and believe Voltr has processed data relating to a minor in a manner that is not permitted, contact us at contact@getvoltr.com and we will review the request.
13. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or platform notification prior to the changes taking effect.
14. Contact
For privacy-related questions, rights requests, security issues, or general support, contact contact@getvoltr.com.