CreatorLiftRequest access

Privacy Policy

Last updated: 15 August 2026. This policy explains how CreatorLift (creatorlift.mnbresearch.com), operated by Abrobot Technologies (MNB Research), New Delhi, India ("we", "us"), collects and handles personal data. It covers both account holders and people who click a CreatorLift tracking link.

1. What we collect

Account data. Your email address, password (stored hashed by our authentication provider — we never see it), the name you supply, and whether you signed up as a brand or a creator.

Workspace data you enter. Campaigns, creators, fees and commission rates, promo codes, deliverables, payout records, and sales you record manually or import by CSV. This is your business data; we process it only to run the service for you.

Click data on tracked links.When someone clicks a CreatorLift link we record the time, the referring page, the browser user-agent string, a derived device category, the country supplied by our hosting provider's edge network, and a SHA-256 hash of the IP address. We do not store raw IP addresses. The hash exists only to count unique visitors approximately; it is not used to identify or profile anyone, and it is not shared.

Sales data from connected stores. If you connect Shopify or Stripe, we receive order webhooks containing the order or session reference, amount, currency, any discount code used, product line items, and whether the buyer was a first-time customer. Order webhooks also carry the buyer's name, email, phone and addresses; those fields are stripped out before the delivery is stored, and we never use them. Attribution runs on the discount code and the tracking link, never on a person. We do not receive or store payment card details.

No advertising trackers. CreatorLift sets no advertising or cross-site tracking cookies. The only cookies we use are the session cookies required to keep you signed in.

Credentials you connect.If you connect Shopify's Admin API, supply your own Google AI key, or enable our generic sales endpoint, we store those credentials encrypted so we can act on your behalf — creating the discount codes your creators use, and receiving your sales. You can remove any of them at any time under Settings → Connections.

Sales you send us directly. As well as Shopify and Stripe, we accept sales posted to our own endpoint by any other system you use. We store the order reference, amount, currency, any discount code, and the time — the same fields, whichever route they arrive by.

1a. If you apply for access

Accounts are opened by application. When you submit the form at /access we store what you enter — your name, email, company, role, website, country, the size bands you select for creator spend and volume, the platforms you run creators on, your timeline, and anything you write in the message field — together with a one-way hash of your IP address for abuse prevention. We never store the raw IP.

We use this only to assess whether CreatorLift is a fit and to size an account, and we email it to ourselves so a person can read it. If you would like your application deleted, whether or not it was approved, write to contact@mnbresearch.com and we will remove it.

2. How we use it

To operate the service: authenticate you, attribute sales to creators, compute analytics and payouts, generate the reports and shareable pages you ask for, and provide support. We also use aggregate, non-identifying usage information to fix problems and improve the product. We do not sell personal data, and we do not use your workspace data to train AI models.

3. AI features

Copilot, campaign briefs, and outreach drafts send the relevant subset of your own measured datato Google's Gemini API to generate a response. Only data already visible to you in your workspace is included, and only when you invoke one of those three features — nothing is sent in the background.

By default these calls use CreatorLift's own Google API key, so that AI works without setup. That means the prompt is sent to Google under our account rather than yours. If your data policy requires prompts to go to your own provider account, add your own Google AI key under Settings → Connections and every call from your workspace will use it instead. Either way, Google's handling of that data is governed by their API terms, and no number in CreatorLift is produced by a model — every figure is calculated in our own code.

4. Sub-processors

We rely on a small number of service providers, each bound by their own data-protection terms: Supabase (database, authentication), Vercel (hosting and edge network), Google (Gemini API, for AI features — see section 3), Resend (transactional email: access-application notifications, invitation codes, invoices and payment reminders, and the weekly summary), and Cashfree Payments (payment processing). Payment card details are handled entirely by Cashfree and never reach our servers.

5. Shared and public pages

Verified results pages, creator media kits, and creator portals are reachable by anyone holding the link. You choose when to create these and can revoke any of them at any time from within the app, which immediately disables the link. These pages are marked noindex and are excluded from our sitemap, so search engines should not list them — but treat any live link as shareable until you revoke it.

6. Retention

We keep your data for as long as your account is active. If you delete a campaign or creator, the associated records are deleted with it; deleting a whole workspace is done by asking us. You can also set a retention window under Settings, after which clicks, sales, stored webhook deliveries and the audit trail older than that window are deleted permanently and cannot be recovered. Ask us to delete your account and we will remove your personal data and workspace contents within 30 days, except where we must retain transaction records to meet Indian tax and accounting obligations.

7. Security

All traffic is served over HTTPS. Workspace data is isolated by row-level security at the database layer, so one workspace's queries cannot reach another's. Every webhook endpoint requires a cryptographic signature before any sale is recorded.

Credentials you connect — a Shopify Admin API token, your own Google AI key, the signing secret for our generic sales endpoint — are encrypted with AES-256-GCM before they are written to the database, and are never returned to the browser. We show you only a fragment, such asshpat_1a2b••••9x8y, so you can tell which one is stored.

No system is perfectly secure, but if a breach affects your personal data we will notify you promptly.

8. Your rights

You may request access to, correction of, or deletion of your personal data, and you may export your workspace data as CSV at any time from within the app. To exercise any of these rights, or to withdraw consent, write to contact@mnbresearch.com. We respond within 30 days. If you are unhappy with our response you may escalate to the relevant data-protection authority.

9. Children

CreatorLift is a business tool and is not directed at children under 18. We do not knowingly collect their personal data.

10. International transfers

Our providers may process data on servers outside India. Where that happens we rely on the provider's standard contractual protections for such transfers.

11. Changes

We will update this page when our practices change and revise the date above. Material changes affecting account holders will be notified by email.

12. Contact

Abrobot Technologies (MNB Research) — contact@mnbresearch.com · +91 97114 88480 · New Delhi, India.