Legal
Privacy Policy
Effective date: March 11, 2026
This policy explains what data Duwiz processes, why it is processed, and your privacy rights.
1. Scope
- • This Privacy Policy describes how Duwiz collects, uses, stores, shares, and protects personal data when you access or use our platform.
- • It applies to all users, including creators, brands, administrators, and visitors interacting with our website and services.
- • By using Duwiz, you acknowledge that you have read and understood this Privacy Policy.
2. Data We Collect
- • Account data: name, email address, role (creator or brand), password (hashed), and authentication method (email/password or third-party sign-in such as Google).
- • Profile data: creator or brand onboarding details, social media handles and follower counts, bio, avatar, portfolio items, rate cards, niches, location, company information, and website.
- • Campaign and content data: campaign configurations, proposals, selected deliverables, activity submissions, proof of work, in-app negotiation messages, chat history, and user-uploaded media and files.
- • Subscription and billing data: subscription plan, billing cycle, subscription status, and payment transaction identifiers. Note: full payment card details are processed and stored exclusively by our payment provider Creem and are never stored on Duwiz servers.
- • Technical data: IP address, browser type and version, device information, operating system, referring URLs, page views, access timestamps, and security telemetry.
3. How We Use Data
- • To provide core platform functionality including accounts, creator and brand profiles, campaigns, proposals, messaging, file hosting, dashboards, and subscription management.
- • To process subscription payments through our third-party payment provider.
- • To maintain security, detect and prevent fraud, abuse, and unauthorized access, and to enforce our Terms of Service.
- • To provide customer support, troubleshoot issues, and improve the product experience.
- • To generate aggregated, anonymized analytics and statistics for platform improvement (e.g., total creator count, campaign activity).
- • To comply with legal obligations, respond to lawful requests, and protect the rights and safety of our users and the platform.
4. Legal Bases for Processing (where applicable)
- • Contract: processing personal data necessary to provide the services you have requested and to fulfill platform interactions and obligations.
- • Legitimate interests: security monitoring, fraud prevention, analytics, content moderation, and continuous service improvement.
- • Consent: where required by applicable law for specific types of processing, such as marketing communications.
- • Legal obligations: compliance with applicable laws, regulations, court orders, and governmental requests.
5. Data Sharing
- • With other platform users: as necessary to facilitate collaborations, including displaying creator and brand profiles, campaign details, proposals, rate cards, and enabling messaging between matched users.
- • With payment processors: subscription payment data is shared with Creem (creem.io), our third-party payment provider, solely for the purpose of processing subscription transactions. Creem handles payment data in accordance with its own privacy policy and applicable payment security standards.
- • With service providers: we use trusted third-party providers for cloud hosting, analytics (including Vercel Analytics), authentication, email delivery, file storage, and platform operations, all under appropriate data processing agreements and safeguards.
- • With authorities: when legally required, or when necessary to protect the rights, safety, and security of our users, the platform, or the public.
- • We do not sell your personal data to third parties.
6. Cookies and Tracking Technologies
- • Duwiz uses cookies and similar technologies to provide essential platform functionality, maintain user sessions, remember preferences, and ensure security.
- • We use Vercel Analytics and Vercel Speed Insights for aggregated, privacy-friendly performance monitoring and usage analytics. These tools do not use cookies for cross-site tracking and do not collect personally identifiable information.
- • Authentication cookies are essential for maintaining your logged-in session and cannot be disabled while using the platform.
- • Duwiz does not currently respond to Do Not Track (DNT) browser signals, as there is no industry-wide standard for compliance.
7. International Data Transfers
- • Your data may be processed and stored in countries other than your country of residence, including the United States and other jurisdictions where our service providers operate.
- • Where required by law, we ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection regulations.
8. Data Retention
- • We retain your personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including service delivery, security, legal compliance, and legitimate business purposes.
- • Retention periods vary by data type, account status, and statutory requirements. For example, account data is retained while your account remains active and for a reasonable period after deletion to comply with legal obligations.
- • You may request account deletion at any time, after which your data will be removed or anonymized in accordance with applicable law and our retention policies.
9. Data Security
- • We implement appropriate technical and organizational security measures designed to protect your data from unauthorized access, alteration, disclosure, or destruction, including encryption in transit, secure authentication, and access controls.
- • No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. Users are responsible for safeguarding their own login credentials and devices.
- • In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
10. Your Rights
- • Depending on your jurisdiction, you may have rights to access, correct, update, delete, restrict processing of, object to processing of, or request portability of your personal data.
- • If we process your data based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing.
- • You may request account deletion by contacting us or through your account settings, subject to legal and contractual retention obligations.
- • To exercise any of your rights, please contact us at support@duwiz.com. We will respond to your request within the timeframe required by applicable law.
- • If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority.
11. Third-Party Services
- • Duwiz integrates with third-party services to provide platform functionality. These include but are not limited to: Creem (payment processing), Vercel (hosting and analytics), and cloud storage providers.
- • Each third-party service has its own privacy policy governing the data it processes. We encourage you to review the privacy policies of these services.
- • Duwiz is not responsible for the privacy practices or content of third-party websites, services, or applications linked from the platform.
12. Children's Privacy
- • Duwiz is not intended for individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from minors.
- • If we become aware that we have collected personal data from a minor without verified parental consent, we will take steps to delete such data promptly.
13. Policy Updates
- • We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data practices.
- • We will update the effective date at the top of this page and publish the revised version. Material changes will be communicated with reasonable notice.
- • Your continued use of the platform after any updates constitutes your acceptance of the revised Privacy Policy.
14. California Privacy Rights (CCPA)
- • If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information.
- • Duwiz does not sell personal information as defined by the CCPA.
- • To exercise your California privacy rights, please contact us at support@duwiz.com.
15. Contact
- • For privacy requests, questions about this policy, or to exercise your data protection rights, please contact us at support@duwiz.com or through the in-app support channels available in your account.
Review our Terms of Service for platform usage rules.