This is a structured working document, not a published policy. It sets out what Numal intends to collect and why, so a qualified privacy lawyer can turn it into something binding. Anything in [brackets] is a decision still to be made. Do not rely on this as a legal notice, and do not publish it as one.
On this page
1. Who we are
[Registered entity] operates Numal, a service that measures the reach of videos posted by a business's employees and pays those employees when agreed view milestones are reached. For data protection purposes the controller is [entity and address]. Our data contact is privacy@numal.com.
[Decide whether a DPO is required, and whether an EU/UK representative is needed.]
2. What we collect from employees
- Identity and contact. Name, email, job role and the workplace you name at signup.
- Social account. The handle you link and the platform it's on. We connect through the platform's own login and never receive or store your password.
- Content data, limited to the campaign. View counts, captions, tags and post dates on videos you have tagged for your workplace. We do not collect messages, follower lists, drafts, private activity, or anything you post that isn't tagged for work.
- Payout details. Bank or wallet information, handled by our payment provider. [Confirm whether Numal ever stores these, or only a provider token.]
- Usage data. Device, browser and IP when you use the site, for security and to fix faults.
3. What we collect from businesses
- Contact details of the person setting the account up, and their role.
- Business name, address and identifiers used to verify the business is real and yours.
- Payment method and billing records for the subscription and the payout balance.
- Campaign configuration: ladders, caps, rules and approvals.
4. What we get from social platforms
When you link an account we request the narrowest set of permissions that lets us count views on the specific videos in scope. What each platform grants differs and changes over time.
[List the exact scopes requested per platform, and review them whenever the platform APIs change.]
We use platform-reported figures and apply our own filtering to exclude traffic that looks bought or automated before a milestone is credited.
5. Why we process it
| Purpose | Basis |
|---|---|
| Running your account | Performance of a contract with you |
| Measuring views and calculating payouts | Performance of a contract |
| Verifying accounts and detecting bought views | Legitimate interests — paying only for genuine reach |
| Making payments | Contract, and legal obligation for records |
| Tax and accounting records | Legal obligation |
| Product emails you asked for | Consent, withdrawable at any time |
[Bases above are drafted against GDPR-style thinking. Confirm the correct framing for California and any other state law that applies.]
6. Who we share it with
- Your employer, but only what's described in section 7.
- Our payment provider, to move money to you. [Name the provider.]
- Infrastructure and support suppliers under written terms. [List sub-processors.]
- Authorities, where we are legally required to.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
7. What your employer can see
This is the section most people are actually asking about, so it is deliberately specific. Your employer sees:
- Your name, role and linked handle.
- The videos you tagged for them, with view counts and what each has earned.
- Totals paid to you through Numal.
Your employer does not see your payout details, your other posts, your followers, your messages, or any activity outside the videos in scope. Unlinking your account stops new data being collected immediately.
8. How long we keep it
[Set concrete periods. Suggested starting point: account data for the life of the account plus 30 days; payout and tax records for the statutory period, likely 7 years; view-count records for the life of the account; usage logs for 12 months.]
9. Your rights
Depending on where you live you may have the right to access, correct, delete, port or restrict your data, to object to certain processing, and to withdraw consent. California residents have specific rights under the CCPA as amended, including the right not to be discriminated against for exercising them.
Write to privacy@numal.com. We'll confirm receipt and respond within the period the law allows.
One thing to be aware of: deleting your data doesn't reverse payments already made, and we're required to keep certain payment records regardless. We'll tell you exactly what has to stay and why.
10. Security, cookies and changes
[Describe encryption in transit and at rest, access controls, and the breach notification process.]
[Add a cookie table once the site's actual cookies and analytics are decided. The current pages set no cookies.]
If we make a material change we'll tell affected users by email before it takes effect, rather than quietly updating a date at the top of the page.