Privacy Policy
Effective September 27, 2026
The controller of your personal data is Michal Schneedorfer, company ID (IČO) 19667302, Nad Nemocnicí 160, 381 01 Český Krumlov, Czech Republic. For anything in this policy, including requests about your data, write to support@creavu.co.
The Czech wording is binding. This English text is a courtesy translation.
This is a working draft written to describe precisely what the product does. It has not yet been reviewed by a lawyer qualified in Czech and EU law.
Who is responsible for what
creavu is a marketplace, so more than one controller decides about your data:
- We are the controller for your account, your orders, your use of the platform and the messages you send us.
- The creator you buy from is the seller and an independent controller of their customers' data: they see your email address, the name you gave, what you bought, when and for how much. They may use this only to fulfil your purchase and their legal duties, and for marketing only if they have their own legal basis. How they handle it is their responsibility.
- Stripe is an independent controller for payment and card data and for the data it collects from creators for identity verification and fraud prevention, under its own privacy policy.
- Google is an independent controller for the Google account you sign in with.
What we collect and why
| Who you are | What | Why | Legal basis |
|---|---|---|---|
| Visitor | The language and appearance you choose; IP address and browser details in hosting logs | Showing the site the way you want; security and operations | Legitimate interest |
| Visitor who accepted analytics | Usage events tied to a random browser identifier | Understanding how the site is used | Consent |
| Buyer | Email address, language, order, payment, access to the item, the moment of consent to immediate delivery and the terms version; a random browser identifier if you accepted analytics | Delivery, accounting record, defence in a dispute | Contract; legal obligation |
| Account holder | Name, email address and profile picture from Google; browser language at signup; IP address and browser for every session | Running the account, sign-in security | Contract; legitimate interest |
| Member (subscriber) | All of the above plus membership status, period and payment history | Managing the membership, cancellation, failed payments | Contract |
| Creator | Store profile, contact address, content, prices; your Stripe account identifier; sales overview | Running your store and payouts | Contract |
| Someone writing to us | Message, report reason, reply address, page and app version, an HMAC fingerprint of the IP address | Replying, acting on it, limiting spam | Legitimate interest; legal obligation for content reports |
| Anyone the site breaks for | A server-side error report without your email address or form contents | Finding and fixing the bug | Legitimate interest |
We keep a record of when and which version of the terms you accepted, at signup, at checkout and when you start selling, so we can answer a dispute about what you agreed to.
We do not sell your data, do not use it for advertising and do not profile you. No decision about you is made by an automated system.
The account a purchase creates
When you buy something or pay for a membership with just an email address, we create an account for that address once the payment goes through. You did not choose to register, and we say so openly. We do it so the purchase has an owner, so you can get back to it, and so we can honour a later request from you.
This account holds only your address, your language and your orders. You open it with a sign-in code we email you; we store the code only as a hash and it is valid for a few minutes. If you later sign in with Google using the same address, it is the same account. We do not use it for marketing. You can ask for erasure; see Your rights.
What the creator sees
The creator you buy from sees in their dashboard your email address, the name you gave, the item, the amount and the date, and for a membership its status. They receive the same details in a sale email. They see only their own buyers, never what you bought from other creators. This is necessary because the creator is the seller and cannot handle a complaint or a refund without identifying their customer. No one other than the creator you bought from sees your address.
Who processes data for us
These are the processors we actually use. Each receives only what it needs for its job. For providers based outside the EU, the transfer rests on the European Commission's standard contractual clauses or on an adequacy decision (EU-US Data Privacy Framework).
| Processor | Where | What it receives |
|---|---|---|
| Google (Google Ireland Ltd.) | EU | Sign-in through Google OAuth. Google handles the sign-in and returns your name, email address and profile picture. We host fonts ourselves, so loading a page makes no connection to Google. |
| Stripe (Stripe Payments Europe Ltd.; Stripe, Inc.) | EU/USA | Card and payment details, the billing country you choose, the email address for the payment receipt, and for memberships one customer record on our account. Card numbers never reach our servers. Creators go through identity verification directly with Stripe. |
| Neon | EU | Our database: everything in the table above that we store. Preview copies of the database used during development may hold production-like data. |
| Vercel | EU/USA | Application hosting and request logs (including IP address). We do not have Vercel's own analytics enabled. |
| Cloudflare | EU/USA | Storage for files and images uploaded by creators and for avatars (R2), image resizing, the domain and DNS, and forwarding of incoming mail. Nothing in storage is public; files are served through short-lived signed links. The storage location is set to Eastern Europe; that is a hint, not a contractual guarantee of jurisdiction. |
| Bunny (BunnyWay d.o.o., Slovenia) | EU | Videos uploaded by creators: storage, encoding and delivery. Storage is in the EU. Every video is played through a short-lived signed link issued only after checking that you have access; Bunny's CDN logs the requests (including IP address). |
| Resend | EU (Ireland) | The email addresses and contents of the emails we send you, plus delivery and bounce events. Resend sends through Amazon SES. Open and click tracking are off and the emails carry no tracking pixel. |
| PostHog (EU Cloud, Ireland) | EU | Product analytics, error reports and the messages you send us. See below. |
About PostHog. PostHog does three things for us: product analytics, error tracking, and keeping the messages you send us. They are handled differently:
- Analytics runs only if you accept it. If you decline, nothing leaves your browser for PostHog, neither an analytics event nor a browser-side error report. Everything on the site keeps working.
- Errors on our server and the messages you send us are not analytics. When something breaks on the server, the error is reported so we can fix it. When you send feedback or report a store, it is stored in our database and reaches PostHog whether or not you accepted analytics, because it is a message you knowingly sent us, not tracking. Before sending we strip email addresses, payment details and tokens from the report. Your reply address stays only in our database.
We serve PostHog through our own domain (/ingest) so a tracker blocker does not silently break the site. The requests therefore look like our own, but the data still goes to PostHog, and we would rather say so than let it appear otherwise.
How long we keep it
| What | How long |
|---|---|
| Accounting records (orders, payments) | 5 years from the end of the accounting period (Accounting Act) |
| Tax documents, if we ever issue any | 10 years (VAT Act) |
| Item access and accepted terms | With the order, for as long as a claim could arise from it |
| Account and profile | For the life of the account |
| Sessions (IP address, browser) | Until expiry or sign-out |
| Sign-in codes | A few minutes; we store only a hash |
| Messages and reports | Until you ask for erasure; a store report is a record of a notice and stays without your identity |
| Record of emails sent | Permanently, as proof that we told you something; without identity after erasure |
| Analytics events and error reports | For the period set in our PostHog project |
| A creator's content and files | Until the creator deletes them; items anyone bought remain available to buyers |
Your rights
You have the right to access your data, to have it corrected, to erasure, to restriction of processing, to object, to portability, and, where processing rests on consent, to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing before it. You withdraw analytics consent yourself with the Cookie settings link in the footer.
Write to support@creavu.co from the address you have with us. We reply within one month. To a request from an unknown address we cannot respond by saying whether we hold anything about you at all.
What erasure really does. We remove your identity, your name, email address, profile picture and the ability to sign in, and we delete your feedback messages and your person record in PostHog. Orders, payments, access records and accepted terms we keep with no identity attached, because the law requires us to keep the accounting record and because these records are what answers a dispute. Data the creator and Stripe hold about you must be requested from them; we will help you with the contact. If you buy again with the same address after erasure, a new account is created and the old purchase no longer belongs to it. We say this plainly rather than promise an erasure we cannot carry out.
If you believe we are handling your data wrongly, you can complain to the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7 (uoou.gov.cz).
Security
Your connection to creavu is encrypted. We never see card details. Files and videos are served through short-lived signed links only after checking that you have access to the item. Sign-in codes and tokens are stored only as hashes. Should a breach occur that puts your rights at risk, we will tell you without undue delay.
Children
creavu is not intended for children. Only people aged 18 or over may sell; anyone under 18 may buy only with a legal guardian's consent. We do not verify age. If we learn that we processed a child's data without the required consent, we delete the account.
Changes
We change this policy when what the product does changes. The date of the current version is at the top of the page; we inform you of a material change by email.
Cookies
See the cookie policy.