Privacy Policy
Last updated: 21 July 2026
This Privacy Policy explains how Zan - Zari Labs OÜ ("OutSponsor", "we", "us") collects, uses and shares personal data in connection with the OutSponsor platform at brands.outsponsor.com (the "Service").
Controller: Zan - Zari Labs OÜ, Estonian registry code 17286420, Tartu mnt 67/1-13b, 10115 Tallinn, Harju maakond, Estonia.
Contact for all privacy matters: support@outsponsor.com
We have not appointed a Data Protection Officer. We keep this under review as our processing scale changes.
1. Who this policy covers
This policy addresses two groups, and your rights differ depending on which applies to you.
Customers — people who create an account, use the Service, or contact us. You provide this data to us directly.
Creators — social media content creators whose publicly available posts and profiles we analyse in order to detect sponsorship activity. If you are a creator and your data appears in OutSponsor, you did not give it to us directly. Section 7 sets out your rights, including how to remove yourself permanently.
2. Data we collect about Customers
Account data. Name, email address, company name, password (stored hashed), two-factor authentication settings, and account preferences.
Billing data. Subscription plan, billing history and payment records. Card details are handled entirely by Stripe and never reach our systems.
Configuration data. Competitor brands you track, hashtags you monitor, campaign briefs, budgets and rate ranges, brand voice samples, FAQ content, and other settings you enter.
Connected accounts. Where you connect an email account or a social account for outreach, we store the access credentials and the messages sent and received through those connections in the course of your campaigns. We do not access correspondence unrelated to OutSponsor campaigns.
Usage data. Log data, IP address, browser and device information, pages viewed, and feature usage.
Communications. Records of your correspondence with us.
3. Data we collect about Creators
To provide the Service we collect and analyse publicly available information from Instagram, TikTok, YouTube and Facebook:
- Public profile information: username, display name, biography, profile image, follower count, stated category and stated location
- Public posts, captions, hashtags, and engagement metrics
- Business contact details that creators have chosen to publish on their public profiles or on pages they link to
- Information we derive from the above: detected sponsorship relationships, apparent exclusivity or ambassador commitments, content topic classification, and language
We also process what creators send to our Customers through the Service — replies, rate quotes, and any audience data or analytics a creator chooses to share during a negotiation, including screenshots.
We do not collect content behind login walls or privacy settings, private correspondence unrelated to Customer campaigns, or special category data as defined in Article 9 GDPR. Where such information appears incidentally in public content, we do not use it as the basis for any decision.
Notifying creators. Article 14 GDPR would ordinarily require us to contact each individual whose data we collect from public sources. Contacting every creator in our index would involve disproportionate effort within the meaning of Article 14(5)(b). We therefore rely on that exemption, and in place of individual notification we publish this policy, limit collection to information published in a commercial capacity, and provide an immediate and permanent opt-out described in Section 7.
4. Why we process this data, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service | Customer account, configuration and usage data | Contract (6(1)(b)) |
| Billing and payment | Billing data | Contract (6(1)(b)) |
| Detecting and indexing sponsorship activity | Creator public data | Legitimate interests (6(1)(f)) |
| Enabling Customers to contact creators about partnerships | Creator public business contact details | Legitimate interests (6(1)(f)) |
| Sending outreach and managing replies on a Customer's behalf | Message content, creator contact details | Legitimate interests (6(1)(f)); the Customer is controller for their own campaigns |
| Security, fraud prevention and abuse monitoring | Usage and log data | Legitimate interests (6(1)(f)) |
| Meeting legal and accounting obligations | Billing and account records | Legal obligation (6(1)(c)) |
| Improving the Service | Aggregated usage data | Legitimate interests (6(1)(f)) |
| Marketing emails to Customers | Email address | Consent (6(1)(a)) |
On legitimate interests. Where we rely on legitimate interests, we have assessed that our interest in operating a business-to-business sponsorship intelligence service, and our Customers' interest in identifying commercial partners, is not overridden by the rights of the individuals concerned. We reach that view because the data is limited to what creators have published publicly in a commercial capacity; because any creator can opt out at any time with immediate and permanent effect; and because we do not make automated decisions producing legal effects. You may request a summary of this assessment at support@outsponsor.com.
5. How we share data
Sub-processors. Third parties who process data on our instructions in order to deliver the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and application data storage | European Union (AWS eu-west-1, Ireland) |
| Vercel | Application hosting and content delivery | United States, with global edge network |
| Resend | Transactional email we send to Customers — invitations, notifications, digests and service alerts | United States |
| Stripe | Payment processing | Ireland and United States |
| Apify | Collection of publicly available social media content | European Union |
| Google (Gemini API) | Analysis of public content to detect sponsorship signals | United States |
| Anthropic (Claude API) | Generating outreach drafts and classifying replies | United States |
| DeepInfra | Model inference for content classification | United States |
| Unipile | Unified messaging transport for outreach — connecting your Gmail, Outlook or IMAP mailbox and your Instagram account, and sending and receiving messages through them | European Union (France) |
We will give at least 30 days' notice before adding a new sub-processor.
Customers. Creator data is made available to the Customer whose account surfaced it, for the purpose of evaluating and pursuing a commercial partnership.
Legal and safety. We may disclose data where required by law, to enforce our Terms of Service, or to protect the rights and safety of any person.
Business transfers. If we are involved in a merger, acquisition or sale of assets, personal data may transfer. We will notify affected individuals before their data becomes subject to a different privacy policy.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. International transfers
Several sub-processors are located outside the European Economic Area, principally in the United States. Where we transfer personal data outside the EEA we rely on:
- An adequacy decision by the European Commission, where one applies; or
- Standard Contractual Clauses approved by the European Commission, together with supplementary measures where our transfer risk assessment identifies a need for them.
You may request a copy of the relevant safeguards at support@outsponsor.com.
7. Your rights
Under the GDPR you have the right to access your data, rectify it, erase it, restrict processing, object to processing based on legitimate interests, receive your data in a portable format, and withdraw consent where processing relies on it.
You may also lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia. You may also complain to the authority where you live or work.
If you are a creator
You can object at any time, and we will stop. Email support@outsponsor.com from an address associated with your public profile, or use the unsubscribe link in any message you receive through our Service.
Opting out is comprehensive. When you opt out we suppress your record across every channel — email, Instagram and TikTok — for every Customer on the platform, permanently. This suppression is checked before any message is sent, ahead of every other rule in the system.
You can request erasure. Where we have no overriding legitimate ground to continue, we will delete your record. We retain a minimal suppression record so that your opt-out continues to be honoured.
We respond within one month. We may ask for information to verify your identity, limited to what is necessary. We will not charge a fee unless a request is manifestly unfounded or excessive.
8. Retention
| Data | Retention |
|---|---|
| Customer account data | Life of the account, then 12 months |
| Billing records | 7 years, as required by Estonian accounting law |
| Creator profile and sponsorship data | 24 months from last detected activity |
| Campaign message content | Life of the Customer's account, then 12 months |
| Opt-out and suppression records | Retained indefinitely, so the opt-out continues to be honoured |
| Logs and usage data | 12 months |
When a Customer removes a tracked competitor from their workspace, the detection data associated with that competitor is deleted.
9. Security
We use encryption in transit and at rest, hashed passwords, optional two-factor authentication, httpOnly session cookies scoped to the paths that need them, scoped access credentials, and audit logging.
OutSponsor is operated by a single person. Access to production data is therefore limited to one individual, which reduces exposure but also means we do not maintain the segregation-of-duties controls larger organisations have. We consider this proportionate to our current scale and will revisit it as the business grows.
No system is perfectly secure and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay where required.
10. Automated processing
OutSponsor uses automated systems to classify content, detect sponsorships, score relevance, draft messages and propose figures within ranges the Customer has authorised.
These are decision-support tools. A human Customer reviews and approves outreach before it is sent, and any first message proposing a monetary figure is presented as a draft requiring human approval, even where automated sending is enabled. We do not make decisions producing legal or similarly significant effects on individuals by automated means alone within the meaning of Article 22 GDPR.
11. Children
The Service is not directed at anyone under 18 and we do not knowingly process children's data. If you believe we hold data about a minor, contact support@outsponsor.com and we will delete it.
12. Changes
We may update this policy. Material changes will be notified by email to Customers and by notice in the Service at least 14 days before taking effect. The date above always reflects the current version.
13. Contact
Zan - Zari Labs OÜ Tartu mnt 67/1-13b, 10115 Tallinn, Harju maakond, Estonia Estonian registry code 17286420 support@outsponsor.com