OutSponsor← Back to home

Privacy Policy

Last updated: 21 July 2026

This Privacy Policy explains how Zan - Zari Labs OÜ ("OutSponsor", "we", "us") collects, uses and shares personal data in connection with the OutSponsor platform at brands.outsponsor.com (the "Service").

Controller: Zan - Zari Labs OÜ, Estonian registry code 17286420, Tartu mnt 67/1-13b, 10115 Tallinn, Harju maakond, Estonia.

Contact for all privacy matters: support@outsponsor.com

We have not appointed a Data Protection Officer. We keep this under review as our processing scale changes.


1. Who this policy covers

This policy addresses two groups, and your rights differ depending on which applies to you.

Customers — people who create an account, use the Service, or contact us. You provide this data to us directly.

Creators — social media content creators whose publicly available posts and profiles we analyse in order to detect sponsorship activity. If you are a creator and your data appears in OutSponsor, you did not give it to us directly. Section 7 sets out your rights, including how to remove yourself permanently.


2. Data we collect about Customers

Account data. Name, email address, company name, password (stored hashed), two-factor authentication settings, and account preferences.

Billing data. Subscription plan, billing history and payment records. Card details are handled entirely by Stripe and never reach our systems.

Configuration data. Competitor brands you track, hashtags you monitor, campaign briefs, budgets and rate ranges, brand voice samples, FAQ content, and other settings you enter.

Connected accounts. Where you connect an email account or a social account for outreach, we store the access credentials and the messages sent and received through those connections in the course of your campaigns. We do not access correspondence unrelated to OutSponsor campaigns.

Usage data. Log data, IP address, browser and device information, pages viewed, and feature usage.

Communications. Records of your correspondence with us.


3. Data we collect about Creators

To provide the Service we collect and analyse publicly available information from Instagram, TikTok, YouTube and Facebook:

  • Public profile information: username, display name, biography, profile image, follower count, stated category and stated location
  • Public posts, captions, hashtags, and engagement metrics
  • Business contact details that creators have chosen to publish on their public profiles or on pages they link to
  • Information we derive from the above: detected sponsorship relationships, apparent exclusivity or ambassador commitments, content topic classification, and language

We also process what creators send to our Customers through the Service — replies, rate quotes, and any audience data or analytics a creator chooses to share during a negotiation, including screenshots.

We do not collect content behind login walls or privacy settings, private correspondence unrelated to Customer campaigns, or special category data as defined in Article 9 GDPR. Where such information appears incidentally in public content, we do not use it as the basis for any decision.

Notifying creators. Article 14 GDPR would ordinarily require us to contact each individual whose data we collect from public sources. Contacting every creator in our index would involve disproportionate effort within the meaning of Article 14(5)(b). We therefore rely on that exemption, and in place of individual notification we publish this policy, limit collection to information published in a commercial capacity, and provide an immediate and permanent opt-out described in Section 7.


4. Why we process this data, and our legal basis

PurposeDataLegal basis (GDPR Art. 6)
Providing the ServiceCustomer account, configuration and usage dataContract (6(1)(b))
Billing and paymentBilling dataContract (6(1)(b))
Detecting and indexing sponsorship activityCreator public dataLegitimate interests (6(1)(f))
Enabling Customers to contact creators about partnershipsCreator public business contact detailsLegitimate interests (6(1)(f))
Sending outreach and managing replies on a Customer's behalfMessage content, creator contact detailsLegitimate interests (6(1)(f)); the Customer is controller for their own campaigns
Security, fraud prevention and abuse monitoringUsage and log dataLegitimate interests (6(1)(f))
Meeting legal and accounting obligationsBilling and account recordsLegal obligation (6(1)(c))
Improving the ServiceAggregated usage dataLegitimate interests (6(1)(f))
Marketing emails to CustomersEmail addressConsent (6(1)(a))

On legitimate interests. Where we rely on legitimate interests, we have assessed that our interest in operating a business-to-business sponsorship intelligence service, and our Customers' interest in identifying commercial partners, is not overridden by the rights of the individuals concerned. We reach that view because the data is limited to what creators have published publicly in a commercial capacity; because any creator can opt out at any time with immediate and permanent effect; and because we do not make automated decisions producing legal effects. You may request a summary of this assessment at support@outsponsor.com.


5. How we share data

Sub-processors. Third parties who process data on our instructions in order to deliver the Service:

Sub-processorPurposeLocation
SupabaseDatabase, authentication and application data storageEuropean Union (AWS eu-west-1, Ireland)
VercelApplication hosting and content deliveryUnited States, with global edge network
ResendTransactional email we send to Customers — invitations, notifications, digests and service alertsUnited States
StripePayment processingIreland and United States
ApifyCollection of publicly available social media contentEuropean Union
Google (Gemini API)Analysis of public content to detect sponsorship signalsUnited States
Anthropic (Claude API)Generating outreach drafts and classifying repliesUnited States
DeepInfraModel inference for content classificationUnited States
UnipileUnified messaging transport for outreach — connecting your Gmail, Outlook or IMAP mailbox and your Instagram account, and sending and receiving messages through themEuropean Union (France)

We will give at least 30 days' notice before adding a new sub-processor.

Customers. Creator data is made available to the Customer whose account surfaced it, for the purpose of evaluating and pursuing a commercial partnership.

Legal and safety. We may disclose data where required by law, to enforce our Terms of Service, or to protect the rights and safety of any person.

Business transfers. If we are involved in a merger, acquisition or sale of assets, personal data may transfer. We will notify affected individuals before their data becomes subject to a different privacy policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.


6. International transfers

Several sub-processors are located outside the European Economic Area, principally in the United States. Where we transfer personal data outside the EEA we rely on:

  • An adequacy decision by the European Commission, where one applies; or
  • Standard Contractual Clauses approved by the European Commission, together with supplementary measures where our transfer risk assessment identifies a need for them.

You may request a copy of the relevant safeguards at support@outsponsor.com.


7. Your rights

Under the GDPR you have the right to access your data, rectify it, erase it, restrict processing, object to processing based on legitimate interests, receive your data in a portable format, and withdraw consent where processing relies on it.

You may also lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia. You may also complain to the authority where you live or work.

If you are a creator

You can object at any time, and we will stop. Email support@outsponsor.com from an address associated with your public profile, or use the unsubscribe link in any message you receive through our Service.

Opting out is comprehensive. When you opt out we suppress your record across every channel — email, Instagram and TikTok — for every Customer on the platform, permanently. This suppression is checked before any message is sent, ahead of every other rule in the system.

You can request erasure. Where we have no overriding legitimate ground to continue, we will delete your record. We retain a minimal suppression record so that your opt-out continues to be honoured.

We respond within one month. We may ask for information to verify your identity, limited to what is necessary. We will not charge a fee unless a request is manifestly unfounded or excessive.


8. Retention

DataRetention
Customer account dataLife of the account, then 12 months
Billing records7 years, as required by Estonian accounting law
Creator profile and sponsorship data24 months from last detected activity
Campaign message contentLife of the Customer's account, then 12 months
Opt-out and suppression recordsRetained indefinitely, so the opt-out continues to be honoured
Logs and usage data12 months

When a Customer removes a tracked competitor from their workspace, the detection data associated with that competitor is deleted.


9. Security

We use encryption in transit and at rest, hashed passwords, optional two-factor authentication, httpOnly session cookies scoped to the paths that need them, scoped access credentials, and audit logging.

OutSponsor is operated by a single person. Access to production data is therefore limited to one individual, which reduces exposure but also means we do not maintain the segregation-of-duties controls larger organisations have. We consider this proportionate to our current scale and will revisit it as the business grows.

No system is perfectly secure and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay where required.


10. Automated processing

OutSponsor uses automated systems to classify content, detect sponsorships, score relevance, draft messages and propose figures within ranges the Customer has authorised.

These are decision-support tools. A human Customer reviews and approves outreach before it is sent, and any first message proposing a monetary figure is presented as a draft requiring human approval, even where automated sending is enabled. We do not make decisions producing legal or similarly significant effects on individuals by automated means alone within the meaning of Article 22 GDPR.


11. Children

The Service is not directed at anyone under 18 and we do not knowingly process children's data. If you believe we hold data about a minor, contact support@outsponsor.com and we will delete it.


12. Changes

We may update this policy. Material changes will be notified by email to Customers and by notice in the Service at least 14 days before taking effect. The date above always reflects the current version.


13. Contact

Zan - Zari Labs OÜ Tartu mnt 67/1-13b, 10115 Tallinn, Harju maakond, Estonia Estonian registry code 17286420 support@outsponsor.com

Privacy PolicyTerms of ServiceCookie PolicyContact
© 2026 Zan - Zari Labs OÜ