DPDP First • GDPR Where Applicable

Privacy Policy

How ClipRaft collects, uses, shares, retains, and protects your personal data.

Last Updated: August 23, 2026

This Privacy Policy applies to ClipRaft's services for creators ("Clippers"), businesses ("Brands"), and website visitors. Our primary privacy framework is India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), taking account of their phased commencement. Where the EU General Data Protection Regulation (GDPR) applies to particular processing, the additional GDPR section below also applies.


1. Who Is Responsible for Your Data

ClipRaft determines why and how personal data is processed and is the Data Fiduciary under the DPDP Act. Where GDPR applies, ClipRaft is the controller. Our privacy and grievance contact is available at dpo@clipraft.in.

2. Personal Data We Process and Why

We collect data you provide, data generated when you use ClipRaft, and limited data received from payment, authentication, campaign, or social-platform services you choose to use.

Data categoryExamplesSpecified purpose
Account and identityName, email, role, account identifiers, authentication and age-confirmation recordsCreate and secure your account, authenticate access, provide support, and communicate service notices.
Creator and campaign dataSocial handles, content URLs or uploads, campaign participation, views, likes, shares, and other engagement metricsAdminister campaigns, verify submissions and performance, calculate earnings, and detect manipulation.
Business and verification dataOrganisation details, PAN, GST information, and supporting verification documents where requiredVerify Brands, administer campaigns, prevent fraud, and meet tax or legal requirements.
Payment and payout dataUPI ID, bank or payout details, payment identifiers, transaction, refund, and earnings recordsFund campaigns, process payouts and refunds, reconcile transactions, and maintain tax and audit records.
Technical and usage dataIP address, browser or device information, session data, cookies, timestamps, security and audit logsOperate and secure ClipRaft, prevent abuse, diagnose faults, remember preferences, and measure performance.
Communications and choicesSupport requests, complaints, consent records, cookie choices, and referral informationRespond to you, document choices, resolve grievances, and administer referrals.

Core account information is required to register and provide ClipRaft. Financial, verification, campaign, or social data is required only when you use the related feature. If required data is not provided, that feature may be unavailable.

3. DPDP Grounds, Consent, and Purpose Limitation

Under the DPDP framework, we process personal data for a lawful purpose based on your valid consent or for a permitted legitimate use under the DPDP Act, where applicable. Consent is requested in clear language for specified purposes and is limited to data necessary for those purposes. We may also process or retain data where Indian law requires or authorises it.

  • You may withdraw consent through Settings or by emailing us. It must be as easy to withdraw as it was to give.
  • After withdrawal, we stop consent-based processing within a reasonable time unless another law requires or authorises it.
  • Withdrawal does not affect the lawfulness of processing completed before withdrawal and may prevent us from providing a feature that needs the relevant data.

4. Sharing and Data Processors

We do not sell or rent personal data. We share only what is reasonably necessary with:

  • authentication, database, hosting, storage, security, communications, and analytics providers;
  • payment and payout providers, banks, and transaction partners;
  • Brands or Clippers where needed to administer a campaign, verify a submission, or resolve a dispute;
  • professional advisers, auditors, insurers, and prospective transaction parties under appropriate confidentiality duties; and
  • courts, regulators, law-enforcement bodies, or other authorities where disclosure is required or authorised by law.

Service providers process data under contractual and security obligations appropriate to their role.

5. Retention and Erasure

We retain personal data only while it is needed for the stated purpose or for a legal, security, payment, tax, audit, fraud-prevention, or dispute-resolution requirement.

  • Account data: retained while your account is active and then erased or de-identified when no longer needed, subject to lawful exceptions.
  • Campaign and financial records: retained for fulfilment, reconciliation, disputes, fraud controls, and applicable tax or accounting periods.
  • Security and processing logs: retained for the period required by applicable DPDP Rules or other law, including the one-year minimum where those Rules apply.
  • Backups: removed or overwritten on routine backup cycles, with access restricted until deletion.

A deletion request does not require deletion of data that must be retained for a specified purpose or compliance with law.

6. Adults Only

ClipRaft is intended only for people aged 18 or older. We do not permit a person under 18 to register. If we learn that an account belongs to a person under 18, we may suspend the account and erase the related personal data unless retention is required by law. This platform rule is stricter than relying on parental consent under DPDP Section 9 and the verification process described in DPDP Rule 10.

7. Your DPDP Rights

Subject to the DPDP Act and applicable Rules, you may:

  • Access information (Section 11): request a summary of your personal data and processing activities and prescribed information about sharing.
  • Correct and erase (Section 12): correct inaccurate data, complete or update data, and request erasure where retention is not necessary.
  • Seek grievance redressal (Section 13): raise a complaint with ClipRaft and, after using our grievance process, complain to the Data Protection Board of India.
  • Nominate another person (Section 14): nominate an individual to exercise your rights in the event of death or incapacity.
  • Withdraw consent (Section 6): withdraw consent for consent-based processing at any time.

We may ask for reasonable information to verify your identity before acting on a request.

8. GDPR: Additional Information Where Applicable

GDPR applies only when the processing falls within its territorial scope, including relevant services offered to individuals in the EU/EEA or monitoring of their behaviour there. Where it applies, our legal bases may include performance of a contract, compliance with legal obligations, our legitimate interests in platform security, fraud prevention and service improvement, and consent for optional activities.

In addition to applicable DPDP rights, you may have GDPR rights to access, rectification, erasure, restriction, objection, data portability, withdrawal of consent, and protection concerning solely automated decisions. You may also complain to the supervisory authority where you live, work, or believe an infringement occurred. We respond to GDPR rights requests without undue delay and generally within one month, subject to lawful extensions.

ClipRaft may use automated checks to flag suspicious engagement or transactions. We do not intend to make a solely automated decision producing legal or similarly significant effects unless applicable law permits it and appropriate safeguards are provided.

9. International Transfers

Service providers may process personal data outside India. Under the DPDP framework, transfers may be made subject to restrictions or requirements notified by the Central Government and any other Indian law providing greater protection. Where GDPR applies to a transfer outside the EEA, we use a lawful transfer mechanism such as an adequacy decision, appropriate contractual safeguards, or a permitted derogation, as applicable.

10. Security and Personal Data Breaches

We use reasonable technical and organisational safeguards appropriate to risk, including access controls, protected transmission and storage, monitoring, logs, backups, and processor safeguards. No system can be guaranteed completely secure.

Where the DPDP breach rules apply, we notify affected Data Principals and the Data Protection Board of India without delay and provide the Board with the required detailed update within 72 hours unless a longer period is allowed. Where GDPR applies, we notify the competent supervisory authority within 72 hours where feasible unless the breach is unlikely to create a risk, and notify affected individuals without undue delay where a high risk exists.

11. Cookies and Similar Technologies

Essential cookies support login, security, and requested functions. Optional analytics or preference technologies are used according to your choices and applicable law. See our Cookie Policy and manage optional choices through the consent controls.

12. Requests, Grievances, and Contact

Use the privacy controls in Settings or email from your registered address with the request and enough information for us to identify your account.

Data Fiduciary / ControllerClipRaft, India
Privacy and Grievance ContactMr. Nikhil Shilla
Response periodWe respond within the period required by applicable law. Under DPDP Rule 14, the published grievance period must be reasonable and no longer than 90 days when that Rule applies; GDPR requests are generally handled within one month.

13. Policy Changes

We may update this Policy when our practices, services, or legal requirements change. We will post the revised version with a new date and provide additional notice of material changes where required.