Privacy policy

Effective from

In short

PactReach is operated by Neerstack LTD. We follow the Nigeria Data Protection Act: collect only what we need to run campaigns, verify identity, and move money; keep it secure; and honour access, correction, and deletion requests at [email protected]. YouTube uses youtube.readonly. Instagram uses Instagram Login. Threads uses Threads Login. Snapchat uses Login Kit (user.display_name and user.external_id). Draft with AI sends product copy you enter to OpenAI. We never sell your data. Audience analytics shown to brands are aggregated, never individual follower records.

Who we are

The PactReach platform is owned and operated by Neerstack LTD (RC8530959). Registered office: 19, Church Street, Ilupeju Iloye, Adalemo, Sango Ota, Ogun State, Nigeria. Where these policies refer to “PactReach”, “we”, or “us”, they mean Neerstack LTD acting through the PactReach product. Neerstack LTD is the data controller for personal data processed on PactReach. Contact [email protected] for privacy requests.

How this policy relates to Nigerian law

We handle personal data in line with the Nigeria Data Protection Act 2023 (NDPA): lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. This page is the notice those principles require. It does not mean we have completed a separate filing with the Nigeria Data Protection Commission (NDPC). You can still complain to the NDPC if you are unhappy with how we handle your data (see Your rights).

Why we process your data (lawful bases)

  • Contract. Creating an account, running campaigns and deals, escrow, verification, settlement, and support.
  • Legal obligation. Identity and business verification (KYC/KYB), keeping transaction records, and responding to lawful requests.
  • Consent. Connecting a social account, marketing email or SMS, and analytics cookies. You can withdraw those without losing the core product, except that disconnecting a platform means we cannot verify placements on it.
  • Legitimate interest. Security, fraud prevention, and keeping the marketplace fair, balanced against your rights. We do not use this basis to sell data or to profile clickers for advertising.

What we collect

  • Account details: name, email, phone, password hash, and the organisation you represent.
  • Verification data: identity or business documents, submitted to meet our regulatory obligations for handling funds.
  • Social account data: with your authorisation, aggregate metrics from platforms you connect (follower counts, engagement rates, and post-level insights on placements you run through PactReach).
  • Payment data: bank account details for payouts, and transaction records. Card details are handled by our payment partners and never reach our servers.
  • Usage data: pages visited, actions taken, and a hashed form of IP address plus device signals used for security and fraud controls. We do not store raw IP addresses.

Google and YouTube access

PactReach uses YouTube API Services so creators can connect a YouTube channel for brand deals. Optional Sign in with Google is a separate Google API used only to create or access a PactReach account. This section discloses how we access, use, store, share, and protect Google user data. By connecting YouTube, you also agree to be bound by the YouTube Terms of Service. Google's own practices are described in the Google Privacy Policy.

Google user data we access

Creators who run YouTube deals connect Google with the youtube.readonly scope only. Through YouTube API Services we access:

  • Google account identifiers needed to complete OAuth (and encrypted access and refresh tokens).
  • YouTube channel identity: channel id, title, handle, and public profile URL.
  • Public channel counters: subscriber count and video count, used for campaign fit.
  • On posts you submit for delivery verification: public video id, title, privacy status (to confirm the post is public), and public views, likes, and comments.

Optional Sign in with Google only receives your Google name and email so we can create or sign you into PactReach. Connecting YouTube still requires the read-only channel consent above. We do not read Gmail, Drive, Calendar, contacts, or other Google products.

Minimum relevant permissions

We request only the Google permissions needed for features that exist today. Creators who connect YouTube grant youtube.readonly so we can confirm channel ownership and read public channel and video stats used for matching and settlement. That access has a direct benefit on PactReach: brands can judge campaign fit, and escrow can settle on measured delivery. We do not request YouTube Analytics, upload, comment, or manage-channel scopes. We do not request extra Google scopes to future-proof features we have not built. We request YouTube access in context, when you choose Connect YouTube, not when you create a PactReach account. Sign in with Google is a separate, optional flow. You can use PactReach without a Google Account. We do not insert, update, share, or delete videos or channel settings on your behalf.

How we use Google user data

We use Google user data only to provide and improve PactReach's user-facing features: confirming the Google account owns the YouTube channel used for brand deals, showing public subscriber and video counts so brands can judge campaign fit, and reading public views, likes, and comments on posts you submit so escrow can settle on measured delivery. Sign in with Google is used only to create or access your account.

We comply with the Google API Services User Data Policy, including Limited Use. We do not use Google user data for targeted, personalized, retargeted, or interest-based advertising; we do not sell it to data brokers or information resellers; we do not use it to determine credit-worthiness or for lending; and we do not use it to develop, improve, or train generalized or non-personalized AI or ML models.

How we share Google user data

We do not sell Google user data. We do not transfer or disclose it to third parties for purposes other than providing PactReach, except:

  • Brands on PactReach see aggregated public channel and placement figures (subscriber count, video count, and public views, likes, and comments on submitted posts). They never see your Google tokens or individual viewer records.
  • Infrastructure providers who host the platform process encrypted tokens and cached public metrics solely to run PactReach. Employees, agents, contractors, and successors who handle Google user data must comply with the Google API Services User Data Policy, including Limited Use.
  • We may use or disclose Google user data to investigate abuse or a security incident, or where legally compelled.
  • If Neerstack LTD is involved in a merger, acquisition, or sale of assets, we transfer Google user data only with your explicit prior consent, or as required by law.

How we store Google user data

We store Google user data on our servers, not in the browser, so we can keep your YouTube channel connected and verify delivery. While the connection is active we store encrypted OAuth access and refresh tokens, Google account identifiers needed to complete OAuth, YouTube channel identity, and cached public channel and video metrics.

How we protect Google user data

Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information. Google user data is encrypted in transit with HTTPS/TLS (including calls to YouTube API Services) and at rest with AES-256-GCM field encryption. The full list of data protection mechanisms for sensitive data, including staff access and credential rotation, is under Data protection mechanisms for sensitive data.

For the full explanation and setup steps, see the Connect socials YouTube guide.

Instagram Login

Creators who run Instagram deals connect with Instagram Login (Business Login for Instagram), not Facebook Login. The Instagram account must be Professional (Business or Creator). A Facebook Page is not required. We request instagram_business_basic and instagram_business_manage_insights so we can confirm the account and read insights used for matching and settlement.

  • We read Instagram identity (id, username, name, profile picture).
  • We read public account counters: followers, following, and media count.
  • When Meta exposes them (typically Professional accounts with at least 100 followers), we read aggregated follower demographics: country, city, age band, and gender split. Brands see those aggregates only, never individual follower records.
  • On posts you submit for verification, we read likes, comments, and post insights (impressions, reach, plays, saves, shares) and confirm the media belongs to the connected account (permalink, caption, media type, owner).
  • We do not post, comment, or change Instagram settings. We do not require a Facebook Page for Instagram.

Setup steps are in the Connect socials Instagram guide.

Threads access

Creators who run Threads deals can connect with Threads Login. We request threads_basic and threads_manage_insights to confirm the account used for brand deals and to read public profile metrics for campaign fit. On posts you submit we may read likes and replies if the API returns them. Those figures do not settle CPV. We do not ask to post, message, or manage your profile.

  • We store the handle, public profile URL, and public metrics the API returns.
  • Post URLs you submit must be on threads.net or threads.com and match the connected username. CPV does not settle on Threads impressions. CPC uses PactReach tracked links.
  • We do not read DMs, private posts, or individual follower records.

Setup steps are in the Connect socials Threads guide.

Snapchat access

Creators who run Snapchat deals can connect with Snapchat Login Kit. We request user.display_name and user.external_id to confirm the Snapchat account used for brand deals. We do not use that grant to read private Snaps, chats, or to post on your behalf.

  • We store the display name, Snapchat external id, and public profile URL.
  • Post URLs you submit must be on snapchat.com and match that account. This path does not receive Snapchat post impressions. Delivery is measured with PactReach tracked links.
  • We do not read private Snaps, chats, or non-public profile fields.

Setup steps are in the Connect socials Snapchat guide.

Draft with AI

Brands can use Draft with AI on the campaign wizard Creative direction step. We send the product name, product description, campaign objective, selected platforms, and any niches, tone, or extra notes you enter to our AI provider (OpenAI) so it can return a draft (key messages, do and do not lists, hashtags, and a caption starter).

  • We do not send creator profiles, wallet or payout details, identity documents, or social OAuth tokens on this path.
  • If the provider is unavailable, we generate a local heuristic draft without that call.
  • The draft is applied to your campaign for you to edit. Identical input the same UTC day replays without charging credits again.

How it works in the product is in the Draft with AI guide.

What we do with it

  • Operate the platform: matching, offers, escrow, verification and settlement.
  • Verify who you are, as required for handling funds and for fraud prevention.
  • Measure placements, including counting clicks on the tracked links we issue.
  • Communicate with you about your deals, and (only with your consent) about the product.

What brands can see about creators

A brand can see your public profile, your connected platforms and their verified follower and engagement figures, your rate card, and your reliability score. Where they unlock audience analytics, they see aggregated demographics (country, city, age band, gender split, language). They never see individual followers, your private messages, or any data from accounts you have not connected.

Tracked links

When someone clicks a PactReach tracked link we record the click, a coarse location, the referring platform, and hashed device signals used solely to filter duplicates and bots. We do not store raw IP addresses. We do not build advertising profiles of the people who click, and we do not sell or share this data.

Cookies

We use essential first-party storage so the product works (for example theme preference and keeping you signed in). When a Google Analytics measurement ID is configured, and only with your consent, we also load Google Analytics cookies to measure aggregated site usage. Analytics scripts do not run until you accept. You can choose “Essential only” or change your choice later via Cookie settings in the site footer. See the cookie policy for the current request, or email [email protected].

Data protection mechanisms for sensitive data

Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information. Sensitive data on PactReach includes Google user data (YouTube channel identity, public metrics we cache, and OAuth tokens), identity documents, payout account numbers, payment records, and social OAuth tokens.

  • In transit: the website, APIs, and calls to Google and other providers use HTTPS/TLS.
  • At rest: OAuth access and refresh tokens, identity-document identifiers, payout account numbers, and other sensitive data are stored with AES-256-GCM field encryption. Session tokens use a separate encryption key from field encryption.
  • Passwords are stored as one-way hashes, not plaintext. Card numbers are handled by our payment partners and never reach our servers.
  • Google and YouTube tokens are exchanged and stored on our servers, not in the browser.
  • Access to production data is limited to authorised staff who need it for support, fraud review, or legal compliance. Humans do not read Google user data except as needed for those purposes, with your consent, or as required by law.
  • We monitor for unauthorised access and revoke or rotate credentials when a connection is disconnected or an account is closed.
  • If a personal-data incident is likely to put you at high risk (for example leaked credentials, identity documents, or payout details), we will notify affected users and handle the incident through [email protected].

Retention

We retain personal information for as long as needed to fulfil the purposes in this policy, unless a longer period is required or permitted by law. Transaction, escrow, payout, and KYC or KYB records are kept for the period our financial obligations require (including after an account closes). Other personal data on a deleted account is anonymised 30 days after deletion, once any creator withdrawal window has ended. When the retention period expires for a given type of data, we delete or destroy it, or anonymise it so it is no longer personal data.

Google and YouTube connection data (channel identity, public metrics we cached, and encrypted tokens) is kept while the YouTube account stays connected and your PactReach account is open. When you disconnect YouTube, or revoke PactReach in Google security settings, we revoke our tokens and delete Google Authorized Data (encrypted tokens and cached channel connection data) as soon as possible and within 7 calendar days, except records we must keep because they formed part of a settled deal or a legal obligation (for example a verified placement that released escrow).

Your rights

Under the Nigeria Data Protection Act you may request access to your data, correction of inaccuracies, deletion, or a copy in a commonly used electronic form. Email [email protected] from the address on your account. We aim to acknowledge within 5 business days and to complete a verified request within 30 days. Brand and creator account owners can download a copy of their data from Settings (JSON, plus CSV of deals and wallet rows) or email us. Identity numbers such as BVN or NIN are not included in that file. Owners can also soft-delete from Settings when deals and balances allow. For step-by-step deletion, including Meta-connected Instagram or Facebook data, see User data deletion instructions. Some records must be retained for regulatory reasons even after an account closes (for example KYC and ledger entries), and we will tell you where that applies.

If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission.

In addition to PactReach's deletion process, you can revoke PactReach's access to your Google account at any time from Google Account permissions (also at Google security settings). Creators can disconnect YouTube from Creator Socials. Questions or complaints about these privacy practices: [email protected].

Sharing

We do not sell personal data. We share it only with processors who help us run PactReach, and only for the purposes in this policy:

  • Our payment processor - wallet top-ups, escrow float, and payouts. Card numbers never reach our servers.
  • Dojah - Nigerian identity and business verification (BVN, NIN, CAC) and name screening against watchlists. A confirmed sanctions match blocks payouts.
  • Cloudinary - images you upload (including identity documents and signature marks).
  • Hosting, database, and email providers - to store and send what the product needs.
  • OpenAI - only the product copy you enter in Draft with AI.
  • Social platforms you connect (Meta, Google, TikTok, Snapchat, LinkedIn, Threads) - to complete OAuth and read the metrics described in this policy.

Some of those processors are outside Nigeria. We use them because the product cannot run without them (for example Google for YouTube, or OpenAI for Draft with AI). The same list is on Who we share data with. We disclose data to authorities only where legally compelled. How we share Google user data is under Google and YouTube access.

Children

PactReach is not directed at children under 13. We do not knowingly collect Google user data from children under 13. Sign in with Google and YouTube connect are optional. You can use PactReach without a Google Account.

Changes

If we change how we collect, use, store, or share Google user data, we will update this policy and prompt you to consent before we use that data in a new way or for a different purpose than originally disclosed. For other personal data, we will update this policy and notify you before we use that data in a new way. Continuing to use PactReach after the updated effective date constitutes acceptance of the revised policy for those other practices.

Company

Neerstack LTD (RC8530959)
19, Church Street, Ilupeju Iloye, Adalemo, Sango Ota, Ogun State, Nigeria