Skip to main content

Privacy Policy

Last updated: September 8, 2026

1. Overview

CreativeWork AS operates CreativeWork, a Norway-first marketplace for booking creative services. This Privacy Policy explains how we process personal information needed to provide accounts and profiles, operate marketplace services, manage bookings, facilitate payments, support communication, handle support and disputes, and secure the service.

It should be read with the Terms of Service, Cookie Policy, Rights & Usage, and Payments & Disputes.

2. Who This Policy Applies To

This policy applies to clients, creators, and other people who use CreativeWork, visit public pages, or send us a contact request.

It covers information CreativeWork processes. Some information is collected directly by third-party providers such as Stripe or Firebase when you use their services.

3. Information You Provide

Depending on how you use CreativeWork, you may provide:

  • account details, such as email, username, and profile name
  • profile and creator information, such as bio, expertise tags, service areas, social links, and images
  • service-listing and portfolio content
  • booking and project information
  • messages, reviews, ratings, and reports
  • support or contact requests
  • uploaded files and images

Not all fields are required. Optional profile and creator details can be left blank.

4. Account and Profile Information

When you create or manage an account, CreativeWork may process:

  • email address, and a pending email address if you request a change
  • username and profile name
  • avatar and banner images
  • country and currency settings
  • account status, including verification, active or deactivated state, suspension state, deleted state, and whether the account is a creator account
  • a Google / Firebase identifier if you sign in or link Google
  • notification preferences
  • saved services or creators (bookmarks)

CreativeWork does not currently collect or store phone numbers as part of your account.

5. Creator and Service Information

If you use CreativeWork as a creator, you may also provide:

  • creator roles
  • service areas
  • bio, expertise tags, and social links
  • service listings, including title, description, price, duration, location, cover image, add-ons, and whether Drop-in is offered
  • portfolio items and related media
  • an optional Norwegian organisation number for business identity

Creators may optionally provide a Norwegian organisation number for business identity on CreativeWork. Where that number is used, CreativeWork may query Brønnøysundregistrene for publicly available Norwegian organisation information related to that number. This supports limited business-identity checks (for example VAT registration status) and does not mean CreativeWork performs full company due diligence.

CreativeWork may store Stripe connected-account identifiers and onboarding-completion status. Identity, business, and bank details required for payouts are provided to Stripe, not stored by CreativeWork as full KYC or bank documents.

6. Booking and Project Information

When users create or manage a booking, CreativeWork may process:

  • service, date and time, and location
  • whether the request is Drop-in
  • project description and selected add-ons
  • reference materials attached to the booking, if any
  • booking status, creator response deadline, and delivery notes or status
  • cancellation, refund, dispute, and completion information
  • payment-schedule and payment-status metadata

Booking records are shared with the client and creator on that booking. They are not published as a public listing.

7. Messages, Reviews and Support

CreativeWork stores messages needed to provide chat and booking communication, including system and booking-status messages, reactions, read state, mute or archive state, and block state.

Chat may include file attachments. If you delete a message, it is hidden from ordinary chat display. The original content may remain in CreativeWork records for authorized dispute, safety, or trust-and-safety review.

Reviews and ratings are associated with platform activity and may include the reviewer’s username, profile name, and avatar. Reports and dispute information may be reviewed to resolve issues and enforce platform rules.

Contact requests submitted through the Contact page include name, email, inquiry type, and message. CreativeWork stores those submissions and may email them to the operational support inbox.

8. Payment Information

Payments are processed through Stripe. Details are in Payments & Disputes.

CreativeWork may store or process payment-related identifiers and records such as:

  • Stripe customer and connected-account IDs
  • payment-method identifiers and limited card metadata returned by Stripe, such as brand and last four digits
  • Stripe payment IDs and related identifiers used to operate checkout and charges
  • amounts, currency, payment reason, and payment or refund status
  • payout-status metadata and related Stripe transfer or payout identifiers
  • receipt and payment-history records

CreativeWork does not receive or store full payment-card numbers or CVC/security codes. Payment-card details are handled by Stripe. CreativeWork also does not store creator bank account numbers or KYC documents; those are handled by Stripe Connect. CreativeWork may retain Stripe identifiers and limited card metadata returned by Stripe, such as brand and last four digits.

9. Files, Images and Other Content

Users may upload profile avatars and banners, service cover images, portfolio media, chat attachments, booking reference images, and other files used on the platform.

Profile, service or space cover, and portfolio marketplace media is public by design. Chat attachments, dispute evidence, and booking reference images are private and served only to authenticated, authorized users such as the relevant chat members or booking parties, and to support or admin access where applicable. Files are not end-to-end encrypted.

Uploaded files are stored on CreativeWork’s hosting and storage infrastructure so they can be displayed or transmitted through the service. For some image upload types, CreativeWork may process, convert, and optimize the file before storing the version used by the platform. Ownership and permitted use of content are described in Rights & Usage. Uploading content does not transfer ownership to CreativeWork.

10. Information Collected Automatically

CreativeWork may process limited technical information to operate and secure the service, including:

  • IP address, used for rate limiting, security, and service operation
  • timestamps and request or error logs, such as request path and status
  • session and authentication storage, including the access_token cookie and Firebase Authentication browser storage
  • first-party preferences stored in localStorage, such as display currency, analytics-consent choice, saved-item cache, and chat sound preference

On first visit, if you have not already chosen a display currency, CreativeWork’s website may ask a third-party geolocation provider (ipapi.co) to return an approximate country based on your IP address. CreativeWork uses that approximate country only to choose a default display currency, stores the resulting currency preference in localStorage, and does not use that lookup for analytics. The provider necessarily receives the IP address used to make the request. CreativeWork does not store the raw IP response as a profile field.

CreativeWork does not operate device fingerprinting or precise location tracking.

11. How We Use Information

CreativeWork uses information to:

  • create and manage accounts
  • display profiles and services
  • facilitate bookings and related records
  • enable messages and notifications
  • process and facilitate payments through Stripe
  • provide support and resolve disputes
  • prevent fraud and security abuse
  • enforce the Terms
  • maintain, debug, and operate the service
  • send service and account updates, subject to your notification preferences where those controls apply
  • understand platform use through optional analytics where configured and accepted

12. Legal / Operational Reasons for Processing

Where data-protection law applies, CreativeWork typically processes information because it is needed to provide the service you request, because CreativeWork has a legitimate interest in operating and securing the marketplace, because a legal obligation applies, or because you have given consent — for example optional Google Analytics.

Not every reason applies to every piece of information.

13. How Information Is Shared

CreativeWork does not sell personal data.

Other users

Information needed for a booking, message, review, or dispute may be shared with the other party. Username, profile name, and avatar may be visible to other users in those contexts.

Public pages

Creator profile, service, portfolio, and some review information may be visible as described in section 18.

Service providers

Information may be processed by providers that help operate CreativeWork, including Stripe, Firebase / Google Authentication, hosting and storage infrastructure, Google Analytics when configured and accepted, and — where a Norwegian organisation number is used — Brønnøysundregistrene for organisation lookups.

Legal and safety

Information may be disclosed where required by law or reasonably necessary to prevent fraud, enforce the Terms, or protect users or the platform.

14. Stripe and Payment Providers

Stripe processes payments, saved payment methods, payouts, and creator onboarding. Creators may provide identity, business, and bank information directly to Stripe as part of Connect onboarding.

Stripe processes that information under its own terms and privacy policy. CreativeWork receives identifiers, status, and limited metadata needed to operate bookings and payouts.

15. Authentication Providers

Accounts may be created or verified with passwordless email one-time codes (OTP) or Google sign-in through Firebase Authentication. Firebase / Google may process authentication data to keep you signed in and verify your identity. CreativeWork does not store user passwords for the email OTP flow.

CreativeWork stores the related account email and, if used, a Google identifier. Session tokens are stored in an HttpOnly cookie named access_token (a browser cookie that scripts on the page cannot read), normally for 7 days.

16. Hosting and Infrastructure Providers

CreativeWork uses hosting, storage, and other technical infrastructure to run the application, store uploaded files, send email, and keep the service available. Those providers may process information on CreativeWork’s behalf as needed to provide their services.

17. Analytics and Cookies

Essential cookies and storage are used for sign-in, security, payments, and requested preferences. When Google Analytics is configured for the environment you are using, it loads only after you accept. CreativeWork currently uses Google Analytics only for usage measurement, not advertising, remarketing, or ads personalization.

You can Accept or Decline analytics, and later change that choice using Cookie settings in the public footer or on the Cookie Policy page. Details are in the Cookie Policy.

18. Public Information

Creator profiles, service listings, portfolio items, and some reviews are designed to be public. Visitors who are not signed in may be able to view them. Public creator information may include profile name, username, avatar, banner, bio, expertise tags, service areas, roles, social links, services, portfolio, and ratings.

Client accounts do not have the same public marketplace profile unless the user also has a creator profile. A client’s email, payment identifiers, and private account settings are not treated as public profile content.

Username, profile name, and avatar may still appear to other users in bookings, messages, reviews, or search.

19. Data Retention

CreativeWork keeps information for as long as reasonably necessary to operate the account and service, complete bookings, maintain payment and accounting records, resolve disputes, prevent fraud or security abuse, and comply with legal obligations.

CreativeWork does not publish a single retention period for every category. Public profile and service content is removed from ordinary public use when deleted or when an account is closed, subject to backups and records described below.

20. Account Deactivation and Deletion

You can deactivate or delete your account from Settings, subject to CreativeWork’s account-lifecycle checks.

Deactivation stops ordinary signed-in use of the account. You may be able to reactivate later. Deactivation does not by itself delete your profile content or booking history.

Deletion/closure goes further:

  • the account is marked deleted and deactivated
  • display profile information is cleared, including name, bio, images, social links, roles, and service areas
  • services and spaces are deactivated, and portfolio items and related uploaded files are removed where possible
  • the username is replaced with an internal deleted identifier so the previous username may become available again
  • the email address is retained so it cannot be used to create a new account
  • Stripe customer and connected-account identifiers may remain on the retired account record
  • booking, payment, review, chat, and related transactional records are retained as operational and financial records rather than being wiped

An account cannot be deactivated or deleted while there are active bookings, unresolved payment or dispute obligations, or other outstanding financial obligations that must be resolved first. An account also cannot be deleted while a connected Stripe account has pending or available funds. CreativeWork does not currently delete the related Stripe customer or connected account as part of platform account deletion. Where a Google / Firebase authentication user is linked, CreativeWork attempts to delete that authentication user as part of closure.

Deletion from public display does not immediately remove backups or records CreativeWork must keep for payments, accounting, disputes, fraud, security, or law. Account suspension by CreativeWork is separate from voluntary deactivation and deletion.

21. Security

CreativeWork uses authentication, access controls, HTTPS/TLS for data in transit, Stripe for payment-card handling, and infrastructure providers to help protect the service. Account and security events may be monitored where those controls are in place.

No system is completely secure. CreativeWork does not claim absolute security, independent security certifications, or end-to-end encryption of messages or files.

22. International Processing

CreativeWork is Norway-based. Authentication, payment, analytics, email, and hosting providers may process information in other countries according to their own infrastructure and safeguards.

This policy does not describe a specific legal transfer mechanism beyond the use of those providers to operate the service.

23. Your Privacy Rights

Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Not every right applies in every circumstance.

You can update much of your account and profile information in Settings. Analytics consent can be changed using Cookie settings in the public footer or on the Cookie Policy page. For other privacy requests, use the Contact page, or email privacy@creativework.app.

24. Children / Age Requirements

The Terms of Service do not currently set a published minimum age. You must be able to use CreativeWork lawfully and provide accurate account information.

CreativeWork does not knowingly collect personal data from children where that is not permitted. If you believe a child has provided personal data, contact us.

25. Changes to This Policy

CreativeWork may update this policy. Material changes apply prospectively, subject to applicable law. Significant changes may be communicated through the platform or by email.

26. Contact

For privacy questions or requests, use the Contact page, or email privacy@creativework.app.