1. Who we are and how to contact us
Entregraph is owned and operated by XPO8 Limited, a company based in Hong Kong. In this policy, “Entregraph”, “we”, “us” and “our” mean XPO8 Limited. For personal data for which we determine the purposes and means of processing, XPO8 Limited is the data user under Hong Kong law and the controller where that term is used under applicable data protection law.
XPO8 Limited1603, L. Plaza
367–375 Queen’s Road Central
Sheung Wan, Hong Kong Island
Hong Kong
Send privacy questions, access or correction requests, objections, deletion requests and complaints to contact@xpo8.com, with “Entregraph privacy” in the subject line. You may also write to the address above. Include the email associated with your account and enough information to identify your request. Do not send passwords, API keys, full payment card details or unnecessary identity documents.
2. Scope and important distinctions
This policy covers the Entregraph website, account and profile features, startup pages, workspaces, communities, feeds, map discovery, rankings, messaging, connected-account reporting, uploads, notifications and our related support communications, together the “Service”. It applies to visitors, account holders, community participants, startup owners, people contacting us and individuals whose information is lawfully supplied through these features.
“Personal data” means information relating to an identified or identifiable living individual, as defined by the law that applies. Business information, customer identifiers, transaction records and public usernames can be personal data when they identify, or can be linked to, an individual. Aggregation or removing a name does not automatically make information anonymous.
This policy describes our practices; it does not turn your use of the Service into consent for every processing activity. Where consent is legally required, we must obtain it separately. The Terms of Service govern your use of Entregraph. Third-party websites, connected providers and independently administered communities may also have their own notices and responsibilities.
Features and integrations may be unavailable, limited or enabled gradually. Describing an optional feature here does not mean it is active for every user.
3. Our role and startup customer data
We ordinarily act as controller for your Entregraph account, our relationship with you, platform safety, support, service administration and the visibility features you use. Startup owners and organizations remain responsible for their own customers, subscribers, users and connected provider accounts.
Where we import and calculate business metrics from customer records solely on an organization’s documented instructions, we may act as its processor or service provider for those records. That role is distinct from our controller role for operating Entregraph. Applicable contractual data processing terms govern that processing; this notice alone is not a substitute for a required data processing agreement or international transfer agreement.
If you are a customer of a startup using Entregraph, normally contact that startup first about its billing, account, analytics or imported customer records. It decides whether to connect its business accounts and what it is entitled to share. We will assist the responsible organization as applicable, and you may contact us directly about processing for which we are controller or if you cannot identify the responsible organization.
4. Information you provide
- Account and authentication: email address, account identifier, sign-in method, authentication credentials and recovery information. Password authentication is handled by our identity provider; credentials must never be posted in profiles, messages or support requests.
- Profile: name, handle, biography, profile image, social account links and other information you choose to make part of your identity on the Service.
- Location and availability: a city you select, whether it is visible, your willingness to meet, travel cities and travel date ranges.
- Startup information: business name, description, website, category, images, ownership association, audience, attribution, profile inclusion, selected communities and metric disclosure settings.
- Content and participation: posts, replies, images, links, startup requests, votes, reactions, follows, memberships, community submissions and related timestamps and identifiers.
- Messages: opening requests, message text, conversation participants, attachments where supported, delivery and read information, and your messaging preferences.
- Preferences and safety: notification choices, blocks, mutes, reports, report explanations and other settings.
- Support and legal correspondence: messages, contact details, diagnostic information you supply, evidence of an issue and records needed to handle rights requests, disputes or complaints.
Some information is required to create or secure an account or provide a feature you request. Optional profile content, travel entries, public disclosures and connected accounts are your choices. If you decline information required for a particular feature, that feature may not work; you may still be able to use public areas.
5. Technical and interaction information
When you access the Service, our application and infrastructure providers process network and request information needed to deliver it. Depending on the request and infrastructure configuration, this can include IP address, browser and device characteristics, operating system, requested URLs, referring information, timestamps, response status, session or account identifiers, error information and security-related events.
The Service also records information created by your interactions, such as membership changes, content timestamps, message read cursors, notification delivery state, connection health, synchronization outcomes and moderation actions. We use these records to make features work, investigate failures, prevent misuse and maintain reliable operations.
We do not ask you to provide access to your device contacts, microphone or continuous device location to use the current website. Selecting a file to upload gives us the selected file, rather than general access to your photo library or filesystem. Avoid putting secrets or sensitive information in URLs, filenames or error reports, because request and diagnostic records may include them.
6. Cities, travel and map requests
Entregraph’s location features use the home and travel cities you choose. They do not use your device’s GPS location or track your movement in the background. City coordinates describe the selected city, rather than your street address or precise position.
Depending on your settings and the relevant feature, your selected city, meeting availability and travel information can affect your profile, map discovery, city directories and community discovery. A travel city may appear during the dates you select. Review both home-city and travel settings before sharing: hiding one item should not be assumed to erase another item you have separately published.
Detailed map views may request tiles directly from OpenFreeMap or another configured map host. That host receives ordinary connection and request information, such as your IP address and the map tiles requested. Tile coordinates identify the map area being viewed and are not evidence that your device is physically there. GeoNames and OpenStreetMap-derived information supply geographic reference data.
7. Connected accounts, credentials and imported records
If you connect a provider account, we process the authorization or API credential you submit, the provider and account or project identifier, relevant permissions, connection status, synchronization settings, timestamps, errors and data returned by the authorized provider. Depending on availability, providers may include Stripe, RevenueCat, Paddle, Polar, Dodo Payments, Lemon Squeezy, PostHog, Google Analytics and X. An integration being described does not guarantee it is enabled.
Financial imports can include provider transaction and customer identifiers, subscription and product identifiers, prices, currencies, billing intervals, quantities, subscription status, charges, refunds, discounts, taxes, dispute adjustments and related dates. Analytics imports can include aggregate reporting periods, pageviews, user or session counts and other supported usage measures. We derive reporting values such as recurring revenue, net collections, paying customer counts and growth.
Our financial normalization is designed to retain calculation fields and stable identifiers while excluding unnecessary customer names, emails, addresses, arbitrary metadata and payment card details from stored normalized facts. A provider response can nevertheless contain additional information while it is being received and normalized. Stable identifiers and financial facts may still be personal data. We do not claim that connecting a provider involves no processing of your customers’ data.
Provider credentials are handled through a separate server-side connection service and credential vault using Google Cloud Secret Manager. They are not part of public metric displays or the account export. Access is restricted to systems that need it to establish, refresh, synchronize or clean up a connection.
Use the least privileged credential your provider supports and review the connection instructions. Some providers cannot issue a key restricted exclusively to reads; a broader key may require an explicit acknowledgement. Entregraph’s supported metric import is intended to read reporting information, but you should not infer that every supplied key is technically incapable of writes.
Only connect accounts you control or are authorized to administer. You are responsible for lawful collection, notices and any permissions needed for your customers’ records. Disconnecting stops future synchronization as the revocation and cleanup process takes effect; it does not automatically erase every previously imported record, derived metric or copy already shared. Revoke the credential with the original provider as well if you need to prevent further use of that credential immediately.
9. Public visibility and disclosure controls
Public means publicly accessible. Information you publish can be read by people without an Entregraph account, found through discovery features, copied by others and indexed by search engines. A later setting change cannot retrieve screenshots, exports or other copies someone has already made.
Profiles, public posts, public startup pages, selected social links, visible cities, community information and disclosed metrics may appear in feeds, directories, map results, rankings, profile summaries and other discovery surfaces. Community membership and participation may also be visible in the relevant context.
Startup audiences include public, selected-community and private visibility. Where offered, attribution and profile inclusion are separate controls. Metric settings can expose exact values, ranges, percentage growth or no public value, with a separate choice about sharing history. A private workspace is not the same as a public startup page; inspect the audience and disclosure settings for each startup and metric.
A “stealth” startup masks selected business identity fields on public displays; it is not a guarantee of anonymity. Disclosed metrics, associated people, posts, timing and other information can identify the business indirectly. Selected-community information is shared with eligible members, who may copy it; community visibility is not a confidentiality agreement.
For revenue-based message eligibility, the Service may evaluate private verified metrics without showing the underlying startup name or amount to the other person. Eligibility, ranking and aggregate results can still reveal limited information or allow inferences. We apply the relevant display rules rather than treating every internal metric as publicly shareable.
10. Messages, uploads and moderation
Messages and message requests are stored to provide conversations, participant access, delivery, read state and abuse reporting. Private messaging is not advertised as end-to-end encrypted. Authorized service systems, necessary service providers and personnel handling a lawful request, support issue or safety investigation may process relevant information with appropriate restrictions. Community conversations may be accessible to eligible community participants.
Recipients can retain, quote, forward or screenshot what you send. Message deletion, membership changes or account closure cannot make another person forget or erase a copy they control. Do not use Entregraph messages to transmit credentials, highly sensitive records or information requiring a specialized secure communication channel.
Uploaded images are processed for validation, resizing and delivery. The image pipeline re-encodes delivered images and is designed to remove source metadata such as EXIF. That does not mean the original file was never received, that every temporary or backup copy has already been deleted, or that visible text and other identifying details inside an image are removed.
We process reports, reported content, identifiers, reasons and moderation decisions to investigate misuse and enforce our terms. Reports may require review of the relevant message or content. We may disclose enough information to an affected person or competent authority to address a complaint, comply with law or allow a fair response, while limiting unnecessary disclosure of the reporter’s identity. We do not promise universal proactive monitoring or absolute reporter confidentiality.
11. Why we use personal data
- Register and authenticate accounts, recover access and maintain sessions.
- Operate profiles, workspaces, startup reporting, communities, posts, messaging, discovery, rankings and the sharing choices you request.
- Establish provider connections, synchronize authorized records, calculate metrics and explain their source, freshness and completeness.
- Apply message eligibility, privacy controls, blocks, mutes and notification preferences.
- Deliver service emails, security notices and support; investigate technical problems and improve usability and reliability.
- Prevent fraud, spam, unauthorized access, manipulated metrics and other misuse; handle reports and protect people and the Service.
- Respond to rights requests, legal process and regulatory obligations, maintain appropriate records, and establish, exercise or defend legal claims.
- Evaluate and carry out a lawful business reorganization or transfer with appropriate confidentiality and privacy safeguards.
We do not use private messages or imported customer records to sell advertising audiences or train a general-purpose AI model as part of the current Service. We do not sell personal data or share it for cross-context behavioral advertising. We do not give other XPO8 products unrestricted access to Entregraph personal data merely because they have the same owner.
12. Legal bases and compatible use
Hong Kong’s Personal Data (Privacy) Ordinance, Cap. 486 (“PDPO”), and its Data Protection Principles apply where relevant. We collect information for lawful purposes directly related to our activities, seek information that is adequate but not excessive, explain required information and relevant uses, and do not treat publication or an account relationship as permission for unrelated uses. A new purpose that requires prescribed consent must be addressed before the information is used for that purpose.
Where the EU GDPR, UK GDPR or another law requiring an identified legal basis applies, the basis depends on the activity:
| Purpose | Legal basis |
|---|---|
| Account administration and features you request | Performance of our contract with you or steps you request before a contract. |
| Security, proportionate diagnostics, support, prevention of abuse and legal claims | Legitimate interests in operating and protecting the Service, balanced against your rights; legal obligation where applicable. |
| Required regulatory records and responses to binding lawful requests | Compliance with a legal obligation applicable to us. |
| Optional activities for which the law requires an opt-in, including any future non-essential tracking or qualifying marketing | Your specific consent, which can be withdrawn prospectively. |
| Imported customer data processed for a startup | The startup determines its lawful basis; we process according to its lawful instructions and applicable processing terms. |
We do not rely on contractual necessity simply because an activity is mentioned in these documents. Where we rely on legitimate interests, you may object as provided by applicable law. Withdrawing consent does not invalidate processing that was lawful before withdrawal and does not prevent processing that has a separate lawful basis.
13. Who receives information
We disclose information where necessary for the purposes described above to the following categories of recipients:
- People and audiences you choose: the public, selected community participants, message recipients and other authorized users, according to the relevant visibility settings.
- Service providers: authentication, databases, hosting, storage, credential management, background processing, communications and other providers needed to operate the Service, with access appropriate to their task.
- Connected providers: the provider whose account you connect, including identifiers, authorization and requests needed to access that account.
- Authorized personnel and advisers: people supporting the Service and professional advisers, insurers or auditors where needed and subject to appropriate confidentiality duties.
- Authorities and relevant parties: where disclosure is required by law, a valid order or legal process, or is otherwise lawfully necessary to investigate wrongdoing, protect rights or address a serious safety or security issue.
- Business successors: in a proposed or completed merger, acquisition, restructuring or asset transfer, with disclosure limited to what is appropriate and subject to applicable restrictions.
We evaluate legal requests rather than assuming any request entitles a person to your data. Where lawful and appropriate, we may notify you of a compulsory disclosure. A provider can have its own controller responsibilities for matters such as its account relationship with you, legally required records and its own service security.
14. Principal providers and external services
| Provider or service | Function and relevant information |
|---|---|
| Supabase | Authentication, account and application database, authorized realtime updates and storage where configured; account information, content, messages, preferences and reporting records. |
| Vercel | Website hosting and application delivery; request and network metadata, and information processed by hosted application functions. |
| Google Cloud | Background processing, media storage, task delivery and Secret Manager; relevant files, job metadata, provider responses and connection credentials. |
| Twilio SendGrid, where email delivery is enabled | Service email delivery; recipient email, message template, delivery identifiers and delivery status. Authentication email may use a separately configured delivery route. |
| Scrape Creators, where social collection is enabled | Requests for linked public social account information and supported audience counts; platform and account identifiers. |
| OpenFreeMap or the configured map tile host | Browser map tile requests and ordinary connection metadata. Geographic reference datasets do not receive your account records simply by being used. |
| Your connected financial, analytics or social provider | Authorized connection and reporting requests, account or project identifiers, permissions and provider data described in this policy. |
| Google sign-in, if enabled and chosen | Authentication information and approved identity attributes from your Google account; Google also processes the sign-in under its own terms. |
Connecting your own PostHog or Google Analytics reporting account is different from Entregraph installing a visitor analytics tracker. The current website does not use those integrations as evidence of Entregraph advertising or visitor tracking. We will update the notice and obtain any required consent before introducing a materially different tracking use.
Providers may change as the Service evolves. Contact us for information relevant to your processing or a business processing agreement. A listing is not a claim that every provider is enabled, that every provider has the same legal role, or that processing is confined to one country.
16. Emails and direct marketing
We may send account, welcome, recovery, security and other service communications. Where message emails are enabled, their purpose is to tell you that there is a new message. The current new-message template does not include the sender’s identity or the message body. Email providers still process the destination email, template and delivery metadata.
You can control optional message emails through notification settings and the unsubscribe options provided. An unsubscribe action does not delete your account or stop every necessary security, recovery, legal or requested support message. The current SendGrid service-email implementation disables open and click tracking; visiting a link can still create ordinary website request records.
We do not treat consent to these terms or the presence of a public email as consent to promotional messages. If we introduce direct marketing, we will give the required notice about the intended use, data and marketing classes, obtain consent where required under the PDPO or other applicable law, and provide a way to withdraw it without charge. We do not transfer your personal data to another party for that party’s direct marketing without the consent and disclosures required by law.
17. International processing and transfers
XPO8 Limited is based in Hong Kong. Our current deployment documentation places principal database and background infrastructure in the United Kingdom, but our hosting, email, connected-account and other providers can process data in Hong Kong, the United Kingdom, the United States, the EEA and other places where they or their authorized subprocessors operate. A regional hosting setting does not guarantee that all support access, delivery, backups and provider processing remain in that region.
Privacy laws and available remedies can differ between countries. Where a transfer is restricted by applicable law, an appropriate lawful transfer mechanism and safeguards are required. Depending on the law and destination, these may include an adequacy decision, applicable standard contractual clauses, a UK addendum or international data transfer agreement, and supplementary technical or organizational measures. A limited statutory exception may apply in a specific case.
We do not rely on your general use of the Service as blanket consent to a restricted transfer. This notice does not itself execute standard contractual clauses or certify a provider under a transfer framework. You may ask contact@xpo8.com about destinations and safeguards applicable to your data, and request relevant information or a copy subject to lawful confidentiality restrictions and necessary redactions.
18. Retention and deletion
We retain personal data for as long as reasonably necessary for the purpose for which it was collected, subject to applicable law, legitimate recordkeeping and legal holds. We consider whether the account or connection remains active, the nature of the data, what is needed to provide the feature, security and complaint needs, applicable limitation periods and whether deletion or anonymization is feasible without impairing other people’s rights.
- Account and settings records: retained while needed to administer the account and handle closure, security, support and legal obligations.
- Published and community content: retained while needed for the content feature and relevant participation history, subject to valid removal or erasure requests and other participants’ rights.
- Messages: retained for conversations, participant access and proportionate safety or dispute purposes. Another participant’s lawful need for a conversation can affect what can be erased from a shared record.
- Imported facts, metrics and social observations: retained for reporting, reconciliation and the relevant processing instructions. Disconnecting a source stops future collection but is not an automatic instruction to erase all prior observations.
- Credentials: retained while needed for an authorized connection, with revocation and cleanup when it is disconnected, replaced or no longer required.
- Uploads, logs, delivery records and backups: retained for delivery, operational recovery and proportionate investigation needs. Temporary files and residual backup copies can require separate cleanup or rotation.
- Legal and rights-request records: retained as necessary to demonstrate our response, comply with law or establish, exercise or defend claims.
We do not state a universal fixed deletion period because different records and providers require different treatment. Removing something from a display, signing out, disabling an email or disconnecting a provider is not the same as complete erasure. Data subject to a lawful hold is restricted to the relevant purpose, and truly anonymized statistics may be retained without being treated as identifiable personal data.
Full automated account closure and coordinated deletion across all stores are not currently offered as a completed self-service workflow. Send a deletion or account-closure request to contact@xpo8.com. We will assess and act on it under the applicable law, explain any lawful limits or necessary steps, and do not promise instant deletion from every backup. Where backup copies cannot immediately be selectively removed, they must remain protected and not be restored to ordinary use without applying the relevant deletion restrictions.
19. Security and incident response
We use technical and organizational controls appropriate to the Service, including authenticated access, database access policies, restricted server-side credential handling, access checks for private content and controlled infrastructure permissions. Delivered images are re-encoded as described above. These measures reduce risk but cannot guarantee that a system, credential, communication or third-party service is never compromised.
You are responsible for a strong unique password, your email account and the devices you use. Review connected-account permissions, revoke compromised keys with their provider and tell us promptly if you suspect unauthorized access. Never send a working API key or password to the privacy mailbox.
We assess suspected incidents, take appropriate containment and investigation steps, and make notifications to affected people, responsible business customers and regulators when required by applicable law. The content and timing depend on the incident, risk and legal requirements. A public message feature or ordinary email is not a specialized system for storing highly sensitive information.
20. Automated calculations and eligibility
The Service automatically calculates metrics, growth, rankings, discovery groupings and certain message-request eligibility. These functions may use provider facts, disclosed metric values, current membership, following relationships, a chosen revenue threshold and freshness or completeness checks. A connection or verified label is a limited statement about source and calculation status; it is not an independent audit of an entire business.
These features are intended for reporting and social discovery, rather than decisions about credit, employment, housing, insurance or another legally significant entitlement. We do not represent that the current Service makes decisions producing legal or similarly significant effects solely through automated processing. If a particular use falls within special automated-decision rules, the relevant rights and safeguards must be addressed.
You can change settings within the available controls and contact us to question a calculation or eligibility outcome. For information that originates with a provider, correction may also require correcting the source account. We do not guarantee access to another person’s private metric values simply because those values contributed to a threshold check.
21. Your choices and privacy rights
You can edit supported profile information, home and travel entries, social links, notification and messaging preferences, startup audiences and metric disclosures through the Service. You can also ask us to address information not covered by those controls. The rights available depend on the applicable law, our role and the circumstances.
Hong Kong
Under the PDPO, you may request confirmation of whether we hold your personal data, access to that data and correction of inaccurate data, subject to statutory exceptions. For a qualifying data access or correction request, the statutory response period is generally 40 days. We may ask you to use the prescribed data access request form where applicable. Any permitted access fee must not be excessive; we will explain a fee or a lawful refusal and the relevant reasons as required. You can object to direct marketing and withdraw relevant consent.
EEA, United Kingdom and equivalent laws
Where these laws apply, you may have rights to access, rectify, erase, restrict processing, object to processing based on legitimate interests, receive certain data in a portable form, withdraw consent and obtain applicable safeguards for qualifying automated decisions. An objection to direct marketing must be respected. Requests under the GDPR or UK GDPR are generally answered within one month; where legally permitted, an extension of up to two further months may be needed for complexity or number of requests, with notice and reasons within the initial month.
California and other jurisdictions
Where the CCPA/CPRA or another local privacy law applies to us and your request, rights may include knowing the categories and specific information collected, its sources, purposes and recipient categories; access, correction, deletion and portability; and opting out of a sale, qualifying sharing or certain uses of sensitive personal information. We do not currently sell or share personal information for cross-context behavioral advertising or use sensitive information for an advertising profile. We do not offer a financial incentive program for personal data. Covered California requests are generally answered within 45 days, with a permitted further 45-day extension explained when needed. Other local deadlines and appeal rights apply where legally required.
We do not discriminate against you for exercising an applicable right. A request can nevertheless affect a feature that requires the data you ask us to remove. Rights are not absolute: legal obligations, proportionate security needs, third-party rights, confidentiality, legal claims and statutory exemptions may limit a request.
22. How to make a request and export information
Email contact@xpo8.com or write to the address in section 1. Identify the account, the information or processing concerned and the action you request. We may need reasonable verification to avoid giving your data to an unauthorized person, but should not request more identifying information than necessary. An authorized agent may act where the law permits and appropriate authority and identity checks are satisfied.
Signed-in users can request an account JSON export. It contains records currently accessible to that account, including available profile, content, message, metric and connection metadata. It excludes provider credentials and media file binaries. Content retained in communities you have left and additional information needed for a legally complete access or portability request may require a separate request. The convenience export does not narrow your statutory rights.
Where we act as processor for a startup, we may refer a request about its customer dataset to that startup and assist it under the processing terms. We will not use that referral to avoid our duties for data we control ourselves. If we cannot fulfill a request, we will explain the applicable reason and any available review, complaint or appeal route.
23. Sensitive information and children
Entregraph is intended for adults aged 18 or over and is not directed to children. Do not create an account if you are under 18. We do not knowingly solicit children’s personal data; if you believe a child has supplied information, contact us so we can assess and take appropriate action.
Do not submit government identity numbers, payment card security codes, health records, biometric identifiers, political or religious information, sexual-life information or other highly sensitive data unless we expressly request specific information for a lawful and necessary purpose through an appropriate channel. Business financial records can be confidential even where they are not a special category under a particular privacy law.
Public posts and free-text fields can reveal sensitive details voluntarily. Choosing to publish information does not remove applicable protections or give us unrestricted permission to use it for a different purpose. If you accidentally share sensitive information, restrict or remove it where possible and contact us for assistance.
24. Optional ZeroToBuilders reporting
If you join Entregraph through ZeroToBuilders, we use its invitation to prefill your name and biography and link your accounts after you authenticate, verify your email and finish your profile. Joining its community does not by itself authorize private reporting.
You may separately authorize ZeroToBuilders to read your profile, selected city even when hidden, availability and follower counts, and all current and future startups you own. This includes unpublished drafts, private or community-only startups, real stealth identities, exact stored metrics and reporting history even when public disclosure is hidden, and limited provider connection health. This permission does not change your public visibility settings. It excludes messages, provider credentials, raw customer or payment records, images, social audience history and travel itineraries.
ZeroToBuilders uses authorized reports to identify connected companies for its Company XP feature. You can decline reporting and still link your accounts and join the community. You can disconnect reporting in Settings; this stops future authorized reads without deleting your accounts or community membership. Leaving a community alone does not withdraw a separately accepted reporting grant. Programme revocation, account deletion or disabling the partner also stops reporting access.
ZeroToBuilders may retain reports it already received under its own disclosed retention policy. Disconnecting future access does not automatically delete those copies; contact ZeroToBuilders about them. New categories of shared data require renewed consent.
25. External links and independent communities
Startup websites, social profiles, embedded or linked resources and other external destinations are operated independently. Following a link can disclose ordinary connection and referring information to the destination. Its privacy notice applies to what it collects directly; this policy does not control its practices.
Community organizers may separately collect information through their own events, websites or communications. An organizer does not become authorized to receive your credentials, private imported facts or unrelated account records simply by creating a community on Entregraph. Contact that organizer about independent collection, and contact us about Entregraph’s own processing.
26. Complaints and supervisory authorities
If you have a concern, contact contact@xpo8.com and describe the relevant processing and outcome you seek. We will consider the concern and respond as appropriate. Contacting us first does not prevent you from exercising a statutory complaint or court right.
In Hong Kong, you can contact the Privacy Commissioner for Personal Data. Where the GDPR applies, you can complain to an appropriate supervisory authority, including one in your habitual residence, place of work or the place of the alleged infringement. Where the UK GDPR applies, you can contact the Information Commissioner’s Office. Other competent regulators or appeal mechanisms may be available under your local law.
27. Changes to this policy
We may update this policy to reflect changes to the Service, providers, processing or law. The effective date and version are shown at the top. For material changes, we will provide appropriate notice, such as a prominent website notice or an email where suitable, before the change takes effect where required.
An updated notice does not by itself authorize a new incompatible purpose or replace consent where consent is required. We will obtain any necessary permission and apply required safeguards before the affected processing. You can ask the privacy contact for clarification about a change or the policy applicable to a particular period.
8. Social links and audience history
When you attach social accounts, we store their platform, handle, URL, association with your profile or startup and relevant settings. Where tracking is enabled and supported, we may obtain public account identifiers, follower or subscriber counts, observation dates, freshness and collection status through a social data provider such as Scrape Creators. Collection may be disabled or unavailable for a platform.
Supported audience-history collection concerns linked public X, Instagram, TikTok and YouTube accounts. LinkedIn and GitHub links do not by themselves enable the same audience-history collection. We do not require your social account password for a public link.
Social audience history is a separate feature from financial metric disclosures. Exact, range, growth and hidden financial settings should not be assumed to control social history. Where the linked profile or startup is visible, its linked social account and available history may also be visible. A shared social account can have observations collected before you attached it, so displayed history does not necessarily begin on the attachment date. Removing a link or disabling future tracking does not necessarily delete shared historical observations.