Clip Army

Clip Army Privacy Policy

Oxygen Software V.O.F., trading as Clip Army Version 2.1 — 16 September 2026

1. Who we are

Clip Army is a trading name of Oxygen Software V.O.F., Netherlands Chamber of Commerce number 62971484, at Heliumweg 15, 3812 RD Amersfoort, the Netherlands. Oxygen Software V.O.F. is responsible for the processing of personal data described in this policy. Send questions and requests to info@cliparmy.nl or our postal address.

This policy applies to anyone whose personal data Clip Army processes in this context, including website visitors, clippers, clients, campaign managers, contacts and people appearing in submissions. Social media platforms also process information under their own privacy policies.

This privacy policy forms part of our terms. The use of the platform is also governed by our terms for clippers and our terms for clients; those documents refer back to this privacy policy.

2. Information we process

Account and profile. We process your name, email address, telephone number if you provide one, account identifier, user role, login and session information and confirmation that you are 16 or older. You may also provide a profile picture, biography and social media accounts. If you sign in with Google, we receive the name and email address Google provides for that sign-in. This does not give us access to your Gmail or private YouTube information.

Campaigns and submissions. We process the campaigns you participate in, submitted files and video links, usernames, account and video IDs, titles and video previews, checks that an account or video belongs to you, view counts, submission status, feedback, rejection reasons where relevant, campaign terms, bonus information and the calculation and settlement of your remuneration. Submitted material may also contain personal data. Do not provide unnecessary personal data about other people.

Payments and tax. We process your name, account holder, IBAN, address, whether you act as a business for the payment, and necessary invoice and payment information. For businesses, this may include Chamber of Commerce registration, VAT number and relevant VAT status. Where a statutory tax obligation requires it for your payment, we also process your Dutch citizen service number (BSN), date of birth and other legally required information and report it to the Dutch Tax Administration. We use your BSN only for that tax purpose.

Business enquiries, appointments and support. We process the information you provide, such as your name, email address, telephone number, company name, website, campaign requirements, correspondence and appointment information. We may also record which campaign or link brought you to us.

Usage, security and communications. We process technical information needed for security, including IP address, timestamp, requested URL, HTTP headers, browser and device information, login attempts, security events and error messages. Through Umami Cloud, we also process cookieless usage information to produce anonymised website statistics. With your consent, we process advertising events and, when you choose personalised email marketing, information about opening and clicking those marketing emails as explained in sections 5 and 6.

3. Sources, purposes and legal bases

Information comes from you, the client or manager of your campaign, Google when you choose Google sign-in, business register information through Overheid.io and the social media sources described in section 4. We also receive technical information through website use and, with the necessary consent, from advertising and email services.

PurposeLegal basis
Providing an account, taking steps you request, managing campaigns, checking submitted videos and calculating and paying agreed remuneration Performing our contract with you or taking steps at your request before entering into a contract
Communicating with business clients’ staff and handling business enquiries Our legitimate interest in business communications and organising campaigns; a contract where you personally are the contracting party
Tax records, mandatory reporting and handling privacy requests Compliance with the applicable legal obligation
Delivering website and API traffic, monitoring availability and performance, security, investigating abuse or incorrect view counts, handling complaints and legal claims Our legitimate interest in protecting the platform, the people involved and our legal position, balanced against your interests
Producing cookieless, anonymised website statistics to understand and improve the use and operation of our website Our legitimate interest in measuring and improving our website with minimal impact on visitors, balanced against your interests
Personalised email marketing and measurement of opens and clicks used to tailor that marketing Your consent
Non-essential cookies, pixels and advertising matching Your consent

You do not need to consent to marketing or advertising tracking to use an account or receive earned remuneration. Forms identify which information is required. Without necessary account or submission information we may be unable to provide the relevant service, and without necessary payment or tax information we may be unable to process a payment.

If a submission contains personal data about someone who is not a party to our contract, we process that information only where necessary to assess, handle and secure the campaign. We rely on our legitimate interest and take that person’s interests into account. We delete or restrict unnecessary information.

Where we receive personal data about you from someone else, we provide the information required by the GDPR no later than one month after obtaining it, but earlier if we communicate with you about that information or disclose it to another recipient before then. We do not repeat information you already have, and a statutory exception may apply where its conditions are met.

A social media authorisation gives us access only to the information and functions described on the authorisation screen. It is not consent to marketing.

4. Social media information and connections

4.1 Public information and links you submit

When you provide a social media account or clip, we use relevant public account and video information to identify the submission, check its relationship with your account and measure views. This can include your username, profile text, profile picture, account or video ID, video link, title, thumbnail and public view counts. Verification may involve temporarily placing a code in your public profile text.

Public information remains covered by this policy. For Facebook and Instagram account and insight information, we use the official Meta connection.

4.2 Facebook and Instagram

When you connect a Facebook or Instagram account, we use Meta's official integration to identify and verify your own account and videos, display existing Reels that you can submit, and retrieve available performance data for submitted Reels. We only use the data and permissions required for these purposes.

For Facebook Pages, we may receive your Meta user ID and name and display the Pages you have access to. For a selected Page, we may process its ID, name, username, profile picture and access token. For videos, we may process information including the video ID, owner, publication date and available performance data.

For this purpose, we use the permissions pages_show_list, pages_read_engagement and read_insights.

For Instagram Business and Creator accounts, we may process the account ID, username, account type and information about your own media, such as the media ID or shortcode.

For submitted Instagram and Facebook Reels, we may process available performance data including:

  • views;
  • average watch time;
  • total watch time;
  • likes or reactions;
  • comments;
  • shares.

The statistics available depend on the data Meta makes available for the relevant account and Reel.

For Instagram, we use instagram_business_basic and instagram_business_manage_insights.

This access is used only to read the user's connected accounts and own media and to retrieve performance data for submitted Reels. Clip Army does not use this access to publish or modify content, send messages, post comments or manage advertisements on behalf of users.

Access tokens are stored securely and are used only for the relevant connection. Data obtained through the Meta connection is not used for advertising targeting and is not combined with the Meta Pixel for that purpose.

4.3 TikTok

If you connect TikTok, we process your account ID, username, display name and avatar. To select and check videos and measure views, we may also process video ID, title, cover image, share link, view count, publication time and duration. We use user.info.basic, user.info.profile and video.list.

Access tokens and any refresh tokens are stored securely and used only for the TikTok connection. This connection is separate from the TikTok Pixel.

4.4 YouTube

Clip Army uses YouTube API Services with an API key. For videos you submit, we may retrieve public video statistics, including view counts. For verification, we may temporarily read public channel information and profile text. A video preview may include title, channel name and thumbnail.

You can request deletion through info@cliparmy.nl. This does not delete a video or channel from YouTube itself. The YouTube Terms of Service and Google Privacy Policy also apply to YouTube. Before accessing our YouTube functionality, we ask you to accept the applicable terms and this privacy policy; this is not consent to marketing or tracking.

4.5 Stopping access and deletion

You can disconnect a social media connection in your profile, revoke access at the relevant platform or email us. We then stop using that access and delete tokens and related information without undue delay, except where we are legally required to retain information.

For Meta, you can also revoke access through Meta’s settings. You can always send a deletion request to info@cliparmy.nl. See section 13 for more information.

5. Emails and personalised marketing

We send necessary account, security, enquiry and payment emails to provide our services. Personalised email marketing, such as news, campaign tips, new campaigns and offers, requires your prior consent. Klaviyo processes contact details, your marketing choice, communication preferences and the opening and click information described below.

If you choose personalised marketing, we may measure whether you open a marketing email and which links you click. We use this information to better tailor content and sending frequency to your interests. This can involve message identifiers, timestamps and technical browser or device information. We do not use this measurement in necessary service emails.

You can unsubscribe at any time using the link in every marketing email or by contacting info@cliparmy.nl. Unsubscribing stops both personalised marketing emails and the associated personal opening and click measurement, but not necessary service emails. We delete or anonymise personal measurement information and inferred interest profiles where there is no longer a valid basis to keep them. Necessary evidence of your earlier choice and a minimal unsubscribe record may be retained separately under section 9.

6. Cookies, analytics, pixels and external content

We use cookies, localStorage, sessionStorage, pixels and similar technologies. Necessary storage supports functions such as sign-in, security and remembering your settings. We ask for prior consent through our cookie banner before loading non-essential advertising tools or external content.

You can choose Reject all, Accept all or Settings. Non-essential categories are off by default. You can later change or withdraw your choice through Cookie settings at the bottom of the website. If you withdraw consent, we stop the relevant non-essential processing. We keep your cookie choice for up to 6 months before asking again, unless a relevant change requires a new choice sooner.

Google Tag Manager. We use Google Tag Manager to manage tags on the website. Tags that require consent load only after you have given that consent.

Privacy-friendly analytics: Umami

We use Umami Cloud from Umami Software, Inc. to understand how our website is used and where we can improve it. We process page views, pages visited, referring URLs, browser, operating system, device type and country derived from the IP address. We do not send names, email addresses, account information or other direct identifiers to Umami and do not use custom Umami identifiers or properties containing personal data.

Umami does not place cookies or store analytics identifiers in localStorage or other browser storage. It does not use fingerprinting or cross-site tracking. To group visits into a session, Umami derives a non-directly identifying hash from the IP address, user agent and our website ID; the raw IP address is not stored in the analytics data. These cookieless analytics are therefore always enabled and do not depend on your cookie choice. We rely on our legitimate interest, not consent, for this limited technical processing. More information is available in Umami’s privacy documentation.

Website security and delivery: Cloudflare

We use Cloudflare as a DNS service, reverse proxy and content delivery network (CDN) in front of our website and APIs. Website and API traffic therefore passes through Cloudflare’s network first. Cloudflare processes information including the IP address, timestamp, requested URL, HTTP headers such as user agent and referring page, network and TLS information, security events and, depending on the request, transmitted content. Public content may be cached temporarily.

We use this processing for DNS and TLS, fast and reliable delivery, caching, DDoS protection, the web application firewall (WAF), abuse detection and security logging. We rely on our legitimate interest in providing secure, available and well-performing services. Cloudflare acts as our processor for transmitted content and Customer Logs. For limited account and operational network information, Cloudflare may act as an independent controller under Cloudflare’s Privacy Policy.

Advertising: Meta and TikTok

The Meta Pixel measures page views and relevant registration events after consent. Meta may receive IP address, browser and device information, visited URL, referring page and cookie or advertising identifiers. Events used are PageView and Lead. We do not send email addresses, telephone numbers, BSNs or bank details for Meta matching and do not use information from a Meta account connection for advertising targeting.

The TikTok Pixel measures page views and the events ViewContent, Lead, ClickButton and CompleteRegistration after consent. For advertising measurement and matching, we may also send SHA-256-hashed versions of your email address, telephone number if available and an external identifier. Hashed information is not anonymous: TikTok can compare it with its own information. This advertising processing is separate from the TikTok account connection.

We do not send tax information, bank details, access tokens, sensitive form contents or personal message contents to advertising pixels.

External content

Embedded YouTube or Calendly content loads only after you enable external content. A normal link to YouTube or Calendly can be shown without that choice; clicking it takes you away from our website. An embed may send technical information to the provider and use cookies or similar storage.

Main browser storage

Storage/technologyPurposeMaximum/usual duration
cliparmy_cookie_consent_v1Remember your cookie choice6 months
Login and session storageSign-in and session securityUntil logout or session termination
_fbp and, where applicable, _fbc Meta advertising measurement and attribution, only after consent Meta generally uses periods of up to about 90 days for these technologies
_ttp, ttcsid* and, where applicable, ttclid TikTok advertising measurement and attribution, only after consent TikTok documents periods of up to 13 months depending on the technology

External providers may use additional storage when enabled. Cookie settings show the categories and providers currently enabled. A browser cookie lifetime is not automatically the same as server-side retention; our own retention periods are set out in section 9.

Advertising-cookie consent is separate from consent to personalised email marketing and from social-media authorisations. More information about Meta, TikTok and international processing appears in sections 7 and 8.

7. Recipients

We do not sell your personal data. We share only information needed for the relevant purpose.

RecipientPurpose
Lovable Cloud and the infrastructure used with it Website, accounts, database, files, server functions and operational email
Cloudflare EU-based D1 payment and administration environment, as well as DNS, TLS, reverse proxy, CDN and caching, DDoS protection, WAF, and network and security logging
DigitalOcean, LLC Cloud infrastructure, hosting and data storage in the EU
Umami Software, Inc. (Umami Cloud) Cookieless, anonymised website statistics as described above
AFAS Software B.V. (planned) Bookkeeping, invoice, payment and tax administration once we migrate that administration to AFAS
Klaviyo Personalised email marketing and the opening and click measurement described above
Google / YouTube / Google Tag Manager Google sign-in, the described YouTube features and management of website tags
Google WorkspaceBusiness email, documents and collaboration
Meta and TikTok Account connections and, separately after consent, advertising pixels
Overheid.ioRelevant business-register information
Monday.com and Pipedrive, where used Following up business enquiries and CRM administration
CalendlyScheduling appointments when you use Calendly
Banks, our accountant and the Dutch Tax Administration Payments, administration and statutory tax obligations
Clients and authorised campaign managers Necessary campaign, submission, result and remuneration information

AFAS is not yet in use for this administration. If we migrate to AFAS, we will process there only the information needed for bookkeeping, payments and tax obligations and will update this policy if the actual processing changes.

Providers acting solely on our instructions process information under our instructions. Some platforms, banks and public authorities also process information for their own purposes under their own privacy rules.

8. Storage locations and transfers outside the EEA

Our primary Lovable Cloud database and Cloudflare D1 database for payment information are located in the EU. Our DigitalOcean infrastructure and the information we store there are also located in an EU region selected by us. Other parts of our services may process personal data outside the European Economic Area (EEA).

For transfers outside the EEA, we use, where applicable, an adequacy decision, the EU-US Data Privacy Framework for certified US recipients or the European Commission’s Standard Contractual Clauses (SCCs). Contact info@cliparmy.nl for more information or a copy of safeguards relevant to our processing.

ProviderRelevant locationsSafeguard
Lovable Cloud and supporting infrastructure Primary database in the EU; supporting infrastructure and email delivery may involve processing outside the EEA, including in the United States. Adequacy decisions where applicable and otherwise appropriate contractual safeguards, including SCCs.
Cloudflare D1 storage for payment information in the EU. As a reverse proxy, Cloudflare processes, inspects and caches traffic through its global edge network. Request information, transmitted content and Customer Logs may therefore be processed globally, including in the United States. EU-US Data Privacy Framework where applicable and otherwise SCCs.
DigitalOcean Our cloud infrastructure and data storage are located in an EU region. DigitalOcean, LLC is based in the United States, so support and subprocessors may involve processing outside the EEA. Data processing agreement and the EU-US Data Privacy Framework where applicable; otherwise SCCs.
Umami Cloud Umami Cloud uses data regions in the EU and United States; the storage region follows our account configuration. Umami Software, Inc. and some subprocessors are based in the United States. Data processing agreement and SCCs where information is processed outside the EEA.
Klaviyo Klaviyo determines, based on the service used and account configuration, whether customer data is stored in the United States or, where EU data residency applies, in the EU. Support and subprocessors may also process data outside the EU. EU-US Data Privacy Framework where applicable and otherwise SCCs.
Calendly Processing occurs in the United States and may also occur in other countries through subprocessors. EU-US Data Privacy Framework where applicable and otherwise SCCs.
Monday.com The primary region depends on account configuration and may be in the EU, the United States or the Asia-Pacific region. Processing may also occur in Israel and the United States. Adequacy decisions where applicable (including Israel) and otherwise SCCs.
Pipedrive Hosting may occur in the EU, United Kingdom, United States, Canada or Australia depending on the account region; support may also take place from other countries. Adequacy decisions or the EU-US Data Privacy Framework where applicable and otherwise SCCs.
Google services (Google Workspace, YouTube and Google Tag Manager) and Meta These services use international infrastructure, including processing in the United States. Adequacy decisions and the EU-US Data Privacy Framework where applicable and otherwise appropriate contractual safeguards.
TikTok TikTok describes storage and processing for EEA users in, among other locations, the United States, Malaysia and Singapore. Adequacy decisions where applicable and otherwise SCCs.

9. Retention

We retain information only for as long as needed for its purpose. The following are our maximum ordinary periods or retention criteria. A valid deletion request or a shorter applicable platform deadline may require earlier deletion.

InformationRetention policy
Account and profile During active use. After 24 months without meaningful account activity, we give 30 days’ notice of closure. Outstanding campaigns, claims or balances are handled first.
Unfinished clipper registration Up to 30 days after the last activity in the registration process.
Business enquiry not followed by a contractUp to 12 months after the last substantive contact.
Campaign administration, submitted data, associated performance data (including views, average and total watch time, likes/reactions, comments and shares), review and feedback Up to 12 months after final campaign settlement. Platform information is kept for a shorter period where required by the relevant platform.
Raw social media responses, caches and individual view snapshots Up to 30 days after retrieval.
Social media tokens While the connection is active and needed. After revocation, we stop using the access and remove tokens from active storage within 24 hours.
Necessary tax records and payment evidence Normally 7 years under the applicable statutory tax retention period. A specific different statutory period takes precedence.
Support correspondenceUp to 24 months after resolution.
Technical, access, security and audit logs Up to 12 months for security, troubleshooting, abuse and fraud detection, and reconstruction of relevant system and administrator actions. We minimise log contents and do not include BSNs, full bank details or full access tokens. Information forming part of a specific incident, fraud investigation or legal dispute may be retained longer for as long as demonstrably necessary, with periodic review.
Cloudflare traffic and security logs Under the retention period of the active Cloudflare service and our account configuration, and only for as long as needed for security, availability and troubleshooting. Limited operational network information that Cloudflare processes as an independent controller is governed by Cloudflare’s own retention policy.
Cookieless Umami analytics information In Umami Cloud for the retention period of our active plan and only for as long as needed for website analysis and trend comparison. Fully and irreversibly anonymised totals may be retained for longer.
Marketing profile Until withdrawal or up to 24 months without meaningful interaction.
Personal email opening and click information and related interest profiles Up to 6 months after the event. After withdrawal, we delete or anonymise this information without undue delay unless another legal basis requires limited retention.
Our raw advertising event logs Up to 30 days after the event. Following withdrawal, we delete or anonymise them sooner where no other legal basis for retention applies.
Marketing email consent evidence 5 years after the last marketing email relying on that consent, retaining only necessary evidence.
Evidence of cookie choices Up to 24 months after the choice was last relied upon as a legal basis.
Minimal unsubscribe record Up to 5 years after unsubscribing, solely to honour the choice and prevent unwanted re-import.
Privacy request handling Minimum necessary request and handling evidence, up to 24 months after closure.

Tax retention requirements apply only to information needed for those records. We do not keep operational accounts, tokens or other social media information for longer solely because tax records must be retained.

YouTube information retrieved without user authorisation is refreshed or deleted within 30 calendar days. Following an applicable deletion request, we delete that information as soon as possible and within 7 calendar days, except where a legal retention duty applies.

Deleted information may remain in secure recovery backups for up to 30 days. These backups are used only for recovery, and previous deletions are reapplied after restoration.

For a specific audit, complaint or lawsuit, we may retain relevant information for longer for as long as this is necessary and permitted. We then delete or anonymise it. Fully and irreversibly anonymised statistics may be retained for longer.

10. Security

We use appropriate technical and organisational security measures, including encrypted connections, role-based access restrictions and protection of access tokens. Bank and tax information is processed in the designated administration environment. Access is limited to people who need the information for their work.

Do not send a BSN, full bank details, passwords or a copy of an identity document by ordinary email. We use a secure route for this information.

11. Automated calculations and assessment

Software may process view counts and calculate remuneration under the terms of a campaign, such as eligible views, rates, thresholds, bonuses and caps.

You can challenge a count, calculation, rejection or other important outcome through info@cliparmy.nl. Where the GDPR requires human intervention, an authorised person carries out a substantive review. We do not make fraud or final exclusion decisions solely on the basis of an automated signal.

For personalised marketing, we may use opening and click information to decide which marketing email is more relevant to your interests. This does not affect your right to campaign remuneration.

12. Age

Clipper registration is available from age 16. We ask you to confirm that you are 16 or older when registering. If we have reason to believe an account is being used by someone under 16, we may investigate, restrict or delete the account, except where information remains lawfully necessary.

Are you 16 or 17 years old? Then you need permission from your parent or legal guardian to take part in Clip Army. We ask you to confirm this when you register. From the age of 16 you can make your own privacy and marketing choices.

13. Your rights and how to exercise them

Objecting to marketing

You can object to direct marketing, including related profiling, at any time and without giving a reason. We then stop using your personal data for that purpose. Use the unsubscribe link or email info@cliparmy.nl. This does not affect necessary service communications or your right to earned remuneration.

Deleting your data

You can request deletion of your entire Clip Army account or only information associated with a social media connection. No built-in deletion function is available for this. Send your request to info@cliparmy.nl, preferably from your account email address, and state what you want deleted. You do not need to give a reason.

If you revoke a social media connection, we stop using that access and delete active tokens as soon as possible. When an account is deleted, we also erase other personal data for which no retention duty or other legal basis remains and, where required, pass the deletion on to our processors.

Necessary tax records may need to remain for longer by law, normally under the period in section 9. We limit this retention to what is actually necessary. Outstanding payments or tax obligations do not justify retaining your entire profile indefinitely.

If you use the Meta connection, you can also revoke access through Meta. The deletion instructions in this privacy policy also apply to information we receive through Meta.

Other rights and requests

You can request access, correction, deletion or restriction of processing. Where the right to portability applies, you can receive the relevant information in a commonly used, machine-readable format or have it transmitted. You may object to processing based on legitimate interests and always to direct marketing. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Send your request to info@cliparmy.nl, preferably from your account email address. If we reasonably doubt your identity, we may ask for proportionate additional verification.

Privacy requests are normally handled free of charge. Only within limited statutory exceptions, for example a demonstrably manifestly unfounded or excessive request, may we charge a reasonable fee or refuse a request; we explain that decision. An access request can also ask which specific recipients received your information.

There is no built-in download function for your information. Email info@cliparmy.nl to request access or a copy. Where the right to data portability applies, we provide the relevant information in a commonly used, machine-readable format. Sensitive information is provided through a secure route.

We respond without undue delay and within one month of receipt. Where the GDPR allows an extension because of complexity or the number of requests, we may extend by up to two further months, notifying you and explaining why within the first month. Shorter platform-data deletion deadlines continue to apply. If we cannot fulfil all or part of a request, we explain the reason, information concerned and your options.

You may complain to the Dutch Data Protection Authority or another competent supervisory authority. You do not need to complete our internal process first.

14. Changes

We update this policy when our processing or applicable rules change. The version and date appear above. For important changes, we inform affected users through the website or a functional notice. If a new processing activity requires consent, we ask for it separately before that processing begins.

Version 2.1 — 16 September 2026 · info@cliparmy.nl