1. Overview & Who We Are
AutX Tech operates ClipRon ("ClipRon") — a two-sided marketplace connecting "Business" users (brands, creators, and campaign owners) with "Clipper" users (short-form video editors and distributors). Our platform facilitates campaign creation, task assignment, content submission, performance analytics via Instagram's Graph API, and automated payments via an escrow system.
By accessing or using ClipRon, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our Services immediately.
Registered Address: India. For formal correspondence, please use the contact details in Section 15.
2. Data We Collect
2.1 Account & Identity Data
- Full name, display name, username
- Email address (used for authentication via Supabase Auth)
- Password (stored as a bcrypt hash — never in plaintext for email/password accounts)
- Single Sign-On (SSO) Data: If you sign in via Google or Facebook, we receive your name, verified email address, profile avatar URL, and provider-issued account identifier solely to authenticate your account
- Profile photo URL (if provided)
- Role selection: "Business" (brand/creator) or "Job" (clipper)
- Bio, location (city/country), languages, content categories, open-to-collaborate preference
2.2 ClipTagram Profile Data
ClipTagram is our creator analytics profile feature. When you set up your ClipTagram profile, we additionally store:
- Display bio and content niche categories
- Location (as manually entered by you)
- Preferred collaboration languages
- Open-to-collaborate status (boolean)
2.3 Campaign & Task Data
- Campaign names, descriptions, goals, budgets, deadlines
- Task assignments: which clipper is assigned to which campaign task
- Content submission URLs (links to Instagram Reels or other video content)
- Submission review status, approval/rejection logs, timestamps
2.4 Communications Data
- In-platform messages between users (stored in our database)
- Support tickets and support chat transcripts
- Email notifications (sent via our email service provider)
2.5 Technical & Usage Data
- IP address, browser type, device type, operating system
- Pages visited, features used, timestamps
- Error logs and crash reports
- Session metadata (collected via Supabase Auth session tokens)
3. Instagram / Meta API Data
3.1 What We Access from Instagram (Meta Graph API v25.0)
When you connect your Instagram Professional Account to ClipRon, we access:
- Account identity: Instagram user ID, username, account type, profile picture URL
- Audience metrics: Total follower count, follows count
- Media & content metrics (per post/reel): Impressions, reach, views (video play count), likes, comments, shares, saves, watch time/average watch time (where available via API)
- Audience demographics (where granted by Meta): Age distribution, gender distribution, top countries, top cities — these are aggregate audience insights, not individual follower identities
- Historical media snapshots: We periodically capture and store metric snapshots (e.g., daily reach, engagement) to power historical trend analytics within ClipRon
3.2 What We Store
- Access token (encrypted): Your Meta OAuth access token is encrypted using AES-256 before storage in our database. The encryption key is managed separately from the database itself. This token allows us to fetch your Instagram data on your behalf.
- Refresh tokens: Where applicable, we store refresh tokens encrypted using the same standard to maintain continuous access without requiring you to re-authenticate frequently.
- Metric snapshots: Stored in our
instagram_media_snapshotstable for historical analytics and ClipTagram score calculation. - Connection metadata: Date connected, last sync timestamp, reauth-required flag.
3.3 What We Do NOT Do With Instagram Data
- We do not sell or license your Instagram data to third parties
- We do not post to your Instagram account — we have read-only access to metrics
- We do not access your Instagram DMs, followers' personal information, or private posts
- We do not use your audience demographics to build advertising profiles for third parties
- We do not retain Instagram data beyond the connection period (see Section 9)
3.4 Disconnecting Instagram
You may disconnect your Instagram account at any time via your Socials settings page (/socials). Upon disconnection, we immediately invalidate the stored access token in our database and cease future data fetches. Historical metric snapshots may be retained for up to 90 days for analytics continuity before permanent deletion, unless you request immediate deletion (see Section 10).
3.5 Meta Platform Policy Compliance
Our use of the Instagram Graph API is governed by Meta's Platform Terms and Developer Policies. We are committed to compliance with Meta's data use restrictions. We only request permissions necessary for the features described above (instagram_basic, instagram_manage_insights, pages_show_list).
4. Payment & Wallet Data
4.1 Payment Gateway (Cashfree Payments)
ClipRon uses Cashfree Payments(a PCI-DSS compliant payment service provider) to process all financial transactions. We do not directly collect or store your full card numbers, CVV, or UPI credentials. Sensitive payment credentials are handled exclusively by Cashfree's PCI-compliant infrastructure.
4.2 What We Store Ourselves
- Wallet balance: Your in-platform wallet balance (escrow credits) stored in our database
- Transaction ledger: Records of every deposit, withdrawal, escrow lock, task payment, and payout — with timestamps and amounts
- Payout details for Clippers: Bank account details (account number, IFSC code, beneficiary name) or UPI VPA required for initiating payouts. These are stored encrypted in our database and transmitted to Cashfree via TLS for payout initiation.
- Transaction IDs: Cashfree order IDs and payment reference numbers for dispute resolution and audit trails
4.3 Escrow System
When a Business user funds a campaign, the funds are moved into an escrow pool. This amount is locked until tasks are completed and approved, at which point it is released to the Clipper's wallet. All escrow operations are logged in our transaction ledger for transparency and auditability.
4.4 KYC / AML
For payouts above applicable thresholds, we may be required by Indian law to collect Know Your Customer (KYC) information (PAN card number, Aadhaar, or other government ID). Such information is collected and retained in compliance with RBI guidelines and applicable anti-money laundering (AML) regulations. We do not use KYC data for any purpose other than regulatory compliance.
5. How We Use Your Data
We use the data we collect for the following purposes:
- Platform operation: Creating and managing your account, enabling campaign creation, task assignment, content submission, and review workflows
- Analytics & insights: Powering your ClipTagram profile, computing engagement scores, displaying historical metric trends using your Instagram data
- Payments & payouts: Processing deposits, managing escrow, initiating UPI/bank payouts via Cashfree
- Communication: Sending transactional emails (account verification, payment confirmations, task notifications), in-platform notifications
- Safety & integrity: Detecting fraud, spam, fake accounts, and policy violations; enforcing our Terms of Service
- Legal compliance: Complying with applicable Indian laws, court orders, and regulatory requirements
- Product improvement: Understanding how users interact with features to improve the platform (aggregate, anonymised usage analytics only)
We do not use your data for targeted advertising to third parties or sell it to data brokers.
6. Data Sharing & Third Parties
6.1 Service Providers (Data Processors)
We share data with the following trusted processors who act solely on our instructions:
- Supabase Inc.— Database, authentication, and storage infrastructure. Data is processed in Supabase's data centers (us-east-1 / eu-west region). Supabase is SOC 2 Type II certified.
- Cashfree Payments India Pvt. Ltd. — Payment processing and payout disbursement. PCI-DSS Level 1 certified.
- Meta Platforms Inc.— We interact with Meta's Graph API to fetch Instagram data. This is a data source relationship, not a data sharing relationship.
- Email Service Provider — For transactional email delivery (name withheld from this policy version; updated in our Data Processing Addendum on request).
6.2 Between Users
- Business users can view a Clipper's ClipTagram profile (username, bio, location if set, engagement metrics) when browsing potential collaborators — only data you have chosen to make visible
- Campaign details are visible to Clippers who apply or are assigned to tasks
- We never share private messages between users with third parties
6.3 Legal Disclosures
We may disclose your data if required by law, court order, or government authority in India or where legally compelled. We will, to the extent permissible by law, notify you of such disclosures.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of substantially all assets, user data may be transferred. We will provide notice and, where required, obtain consent before such transfers.
6.5 No Sale of Personal Data
We do not sell, rent, or trade your personal data to any third party for commercial purposes.
7. Data Security & Encryption
- Transport security: All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS)
- Instagram access tokens: Encrypted using AES-256 at rest. Encryption keys are stored separately from the database using environment-level secrets management.
- Payout bank details: Encrypted at rest before storage in our database
- Passwords: Hashed using bcrypt via Supabase Auth — never stored in plaintext
- Database access: Restricted via Supabase Row-Level Security (RLS) policies. Users can only access their own data; cross-user access requires admin-level service role keys (not exposed to clients)
- Admin access: Strictly limited to authorised ClipRon staff with multi-factor authentication
- Security incidents: We maintain an incident response plan. In the event of a data breach affecting your data, we will notify you as required under applicable law (within 72 hours of discovery where GDPR applies, and as required under Indian IT Rules 2021)
While we take commercially reasonable measures to protect your data, no system is 100% secure. We encourage you to use a strong, unique password and enable any available account security features.
8. Data Retention
- Active account data: Retained for as long as your account is active
- Instagram metric snapshots: Retained for up to 24 months from capture, or until you disconnect Instagram, whichever is earlier. Upon disconnection, snapshots are deleted within 90 days (or immediately upon your written request)
- Transaction records: Retained for 7 years as required by Indian financial and tax law (GST Act, Income Tax Act)
- Support communications: Retained for 2 years from resolution
- Account deletion: Upon account deletion, personal profile data is permanently deleted within 30 days. Anonymised transaction records may be retained for legal compliance.
- Backups: Data may persist in encrypted backups for up to 30 additional days after deletion before being purged from backups
9. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data (subject to legal retention obligations)
- Right to Data Portability: Receive your data in a structured, machine-readable format (JSON/CSV)
- Right to Withdraw Consent: Disconnect Instagram, remove payment details, or close your account at any time
- Right to Object: Object to processing of your data for purposes other than those strictly necessary for service delivery
- Right to Restriction: Request we restrict processing of your data in certain circumstances
To exercise any of these rights, email us at privacy@clipron.com with "Data Rights Request" in the subject line. We will respond within 30 days. Identity verification may be required.
You may also delete your account directly from the Account Settings page (/account), which triggers immediate data deletion workflows.
11. Children's Privacy
ClipRon is not directed to individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has registered, please contact us at privacy@clipron.com.
12. Indian Law Compliance
12.1 Information Technology Act, 2000 & IT (Amendment) Act, 2008
We comply with the provisions of the Information Technology Act, 2000 as amended, including Section 43A regarding protection of sensitive personal data or information (SPDI). The data we classify as SPDI includes: passwords, payment card information, bank account details, and biometric data (if collected in the future for KYC).
12.2 IT (Reasonable Security Practices & Procedures and Sensitive Personal Data or Information) Rules, 2011
We maintain a comprehensive information security program aligned with IS/ISO/IEC 27001 standards as required under Rule 8. We appoint a Grievance Officer as required under Rule 5(9) — see Section 15.
12.3 Digital Personal Data Protection Act, 2023 (DPDP Act)
We are actively preparing for compliance with India's Digital Personal Data Protection Act, 2023 as its provisions come into force. This includes:
- Maintaining lawful basis for all data processing (consent, legitimate use, legal obligation)
- Providing clear notice at collection
- Honouring data principal rights (access, correction, erasure, grievance)
- Maintaining records of processing activities
- Cross-border transfer compliance (data localisation requirements as notified)
12.4 RBI / Payment Regulations
Payment operations are conducted via Cashfree Payments, a Payment Aggregator regulated by the Reserve Bank of India. We comply with applicable RBI guidelines on payment aggregators and data localisation for payment data.
13. International Users
ClipRon is operated from India. If you access our Services from outside India, your data may be transferred to and processed in India, where data protection laws may differ from your home country.
For users in the European Economic Area (EEA) or United Kingdom, we rely on the following legal bases for processing: (a) your explicit consent for Instagram data access; (b) contractual necessity for account and payment data; (c) legitimate interests for fraud prevention and platform security. You have the right to lodge a complaint with your local supervisory authority.
For California residents under CCPA: We do not sell personal information. You have the right to know, delete, and opt-out of sale (which we do not conduct). Contact us to exercise these rights.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Posting the updated policy with a new effective date on this page
- Sending an email to your registered email address for significant changes
- Showing an in-platform notification banner
Continued use of ClipRon after the effective date of any changes constitutes your acceptance of the updated policy.
15. Contact & Grievance Officer
For privacy-related queries, data rights requests, or complaints, contact us at:
Data Controller: AutX Tech
Privacy Enquiries: privacy@clipron.com
Grievance Officer (as per IT Rules 2011, Rule 5(9)):
Name: To be appointed — contact grievance@clipron.com
Grievances will be acknowledged within 48 hours and resolved within 30 days.
If you are dissatisfied with our response, you may approach the relevant data protection authority in your jurisdiction or, for Indian residents, the Data Protection Board of India once constituted under the DPDP Act 2023.
Last updated: 26 September 2026
© 2026 AutX Tech. ClipRon is a product of AutX Tech.