Privacy

What we collect,
and what we don't.

The short version: view counts and captions on the videos you tagged for work. Not your messages, not your followers, not anything you post outside it.

Draft v0.1 · Prepared 31 August 2026 · Not in force

Draft — not yet in force

This is a structured working document, not a published policy. It sets out what Numal intends to collect and why, so a qualified privacy lawyer can turn it into something binding. Anything in [brackets] is a decision still to be made. Do not rely on this as a legal notice, and do not publish it as one.

1. Who we are

[Registered entity] operates Numal, a service that measures the reach of videos posted by a business's employees and pays those employees when agreed view milestones are reached. For data protection purposes the controller is [entity and address]. Our data contact is privacy@numal.com.

[Decide whether a DPO is required, and whether an EU/UK representative is needed.]

2. What we collect from employees

3. What we collect from businesses

4. What we get from social platforms

When you link an account we request the narrowest set of permissions that lets us count views on the specific videos in scope. What each platform grants differs and changes over time.

[List the exact scopes requested per platform, and review them whenever the platform APIs change.]

We use platform-reported figures and apply our own filtering to exclude traffic that looks bought or automated before a milestone is credited.

5. Why we process it

PurposeBasis
Running your accountPerformance of a contract with you
Measuring views and calculating payoutsPerformance of a contract
Verifying accounts and detecting bought viewsLegitimate interests — paying only for genuine reach
Making paymentsContract, and legal obligation for records
Tax and accounting recordsLegal obligation
Product emails you asked forConsent, withdrawable at any time

[Bases above are drafted against GDPR-style thinking. Confirm the correct framing for California and any other state law that applies.]

6. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

7. What your employer can see

This is the section most people are actually asking about, so it is deliberately specific. Your employer sees:

Your employer does not see your payout details, your other posts, your followers, your messages, or any activity outside the videos in scope. Unlinking your account stops new data being collected immediately.

8. How long we keep it

[Set concrete periods. Suggested starting point: account data for the life of the account plus 30 days; payout and tax records for the statutory period, likely 7 years; view-count records for the life of the account; usage logs for 12 months.]

9. Your rights

Depending on where you live you may have the right to access, correct, delete, port or restrict your data, to object to certain processing, and to withdraw consent. California residents have specific rights under the CCPA as amended, including the right not to be discriminated against for exercising them.

Write to privacy@numal.com. We'll confirm receipt and respond within the period the law allows.

One thing to be aware of: deleting your data doesn't reverse payments already made, and we're required to keep certain payment records regardless. We'll tell you exactly what has to stay and why.

10. Security, cookies and changes

[Describe encryption in transit and at rest, access controls, and the breach notification process.]

[Add a cookie table once the site's actual cookies and analytics are decided. The current pages set no cookies.]

If we make a material change we'll tell affected users by email before it takes effect, rather than quietly updating a date at the top of the page.