Privacy policy
What we do with personal data, why we are allowed to, and what you can make us do about it.
- Controller
- Rocket Juice s. r. o.
- Registered seat
- Vajanského 1955/58, 921 01 Piešťany, Slovak Republic
- Company ID (IČO)
- 57730393
- Tax ID (DIČ)
- 2122903222
- VAT
- Not registered for VAT
- Commercial register
- Obchodný register Okresného súdu Trnava, oddiel: Sro, vložka č. 63692/T
- Contact
- marek@getrocketjuice.com
- Document
- Rocket Juice — Privacy Policy
- Applies to
- getrocketjuice.com and the Rocket Juice platform
- Last updated
- 18 August 2026
- Version
- 2.0
1. WHO WE ARE
Rocket Juice s. r. o. operates the Rocket Juice platform at getrocketjuice.com. Where this policy says "we", "us" or "Rocket Juice", it means that company. Our identity and registration details are in the Operator panel above.
For everything described in this policy for which we decide the purposes and means, we are the controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the GDPR). Slovak Act No. 18/2018 Coll. on the protection of personal data applies alongside it.
Questions about this policy, and requests under the rights in section 10, go to marek@getrocketjuice.com or to [data protection contact / DPO — to be confirmed].
2. THE THREE ROLES THIS PLATFORM PUTS US IN
Rocket Juice sits between two businesses, and the same company can be a controller for one set of data and a processor for another. Which role we are in decides who you go to, so it is set out first rather than buried.
| Data | Our role | Who else is involved |
|---|---|---|
| Account, identity, communications, submissions, attribution results, earnings and ledger entries of creators and brand users | Controller (independent) | The brand is a separate, independent controller for its own purposes; its own privacy notice applies to that processing. We are not joint controllers with a brand. |
| End-customer data from a brand's connected store and tracking parameters — order, conversion and device data | Processor, on the brand's behalf | The brand is the controller and is responsible for the lawfulness of its own tracking and for any consent required. The Data Processing Agreement at getrocketjuice.com/dpa governs this processing. |
| People appearing in a creator's video | Neither — the creator is controller | The creator is responsible for the consents and releases required by clause 4.3.1(c) of the Creator Terms. |
This mirrors clause 7.1 of the Creator Terms and clause 6.1 of the Brand Terms. [Confirmation of the GDPR role mapping across the three-sided relationship — to be confirmed.]
3. WHAT WE COLLECT
3.1 If you are a creator
- Account: e-mail address, display name, profile picture, the sign-in identifier issued by our authentication provider, account status, and the time of your last sign-in.
- Your acceptance of these terms: which version you agreed to, when you agreed, and the IP address the agreement was sent from. We keep the IP address so that we can show, if it is ever disputed, that the agreement was actually given. It is used for nothing else — it is never used to identify you, to locate you, or to decide anything about your account.
- Profile: Instagram handle and Instagram user id, your written profile description, category, follower count as reported by Instagram, and the portfolio media you upload.
- Shipping address, where you ask a brand for a product sample.
- Submissions: the videos and images you upload, your notes on them, their status history, and the unique identifying code attached to each.
- Money: earnings, their status and payment dates, payout records, and the ledger entries behind them.
- Communications: messages you exchange with a brand through the platform, including any images attached, and the notifications we generate for you.
- Optional device notifications: if you enable them, we store your browser push subscription endpoint and encryption keys, linked to your account. We use them only to deliver platform notifications to that device.
3.2 If you are a brand user
- Account and profile as above, plus your role in the brand and the brand's own details.
- Connection metadata for the store and advertising accounts you connect — account, page, Instagram and dataset identifiers. Access tokens are held in a secret manager and are never stored in plain text in our database.
- Your review decisions, notes and messages, and the commercial records of programs, retainers and payouts.
3.3 If you bought something from a brand that uses us
We are the brand's processor for this, not the controller. Your order arrives from the brand's store carrying far more than we need, so we discard the excess before storing it. What we keep is the order reference, the value and currency, the time and status of the order, and the tracking parameter that identifies which creator video the sale is attributed to.
What we do not keep, and delete on arrival: your name, e-mail address and phone number, your billing and shipping address, your IP address, your browser and device details, the page you arrived from, and any advertising click identifiers. Orders stored before 18 August 2026 have had the same data removed.
Where a brand has connected Meta and the sale is credited deterministically, we may also send Meta a server-side purchase event. What leaves our systems in that event is the SHA-256 hash of the e-mail address and of the phone number, together with the order id, value, currency and the page the purchase happened on. The raw e-mail address and phone number are hashed before the request is built and are not transmitted. A hash of this kind is still personal data under the GDPR — it is pseudonymised, not anonymised — which is why it is disclosed here.
3.4 If you are only visiting the website
The public pages set no analytics, no advertising and no tracking cookies, and we run no third-party analytics on them.
4. WHY WE PROCESS IT, AND ON WHAT LEGAL BASIS
Every purpose below is tied to one of the legal bases in Article 6(1) GDPR. This table is the same set of bases the Creator Terms name in clause 7.2.1.
| Purpose | Legal basis |
|---|---|
| Creating and running your account; running programs, submissions, review and acceptance; measuring attributed sales; calculating remuneration; facilitating payment; messaging between a creator and a brand | Article 6(1)(b) — performance of the contract you entered into by accepting the Creator Terms or the Brand Terms |
| Accounting and tax records, statutory reporting, anti-money-laundering obligations, and keeping records we are required to keep | Article 6(1)(c) — compliance with a legal obligation |
| Keeping the platform secure; preventing and detecting fraud and unauthorised use of creator content; resolving disputes; improving the services; producing aggregated, de-identified benchmarks that identify no brand, creator or customer | Article 6(1)(f) — our legitimate interests. We have weighed these against your interests and rights; you can object at any time under section 10 and we will stop unless we can show compelling legitimate grounds |
| Marketing e-mails, and the uses of creator content described in clauses 6.7.3 and 6.7.4 of the Creator Terms | Article 6(1)(a) — your consent, which you may withdraw at any time without affecting processing already carried out |
We do not sell personal data, we do not post or send messages as you, and we do not use your data to train models for anyone else.
5. WHO WE SHARE IT WITH
| Recipient | What they receive | Why |
|---|---|---|
| The brand whose program you joined | Your profile, submissions, performance and the remuneration owed to you | It is a party to the commercial relationship; it is an independent controller for its own purposes |
| Besteron — Besteron a.s., Prešovská 38/B, Bratislava – mestská časť Ružinov 821 02, Slovak Republic, Company ID (IČO): 47866233, registered in the Commercial Register of the Municipal Court Bratislava III, section: Sa, insert no. 6004/B, a payment institution authorised and supervised by Národná banka Slovenska under licence no. ODB-6111/2015-7 | The payment identifiers and amounts needed to execute a payment | It is the payment service provider through which a brand settles what it owes you |
| Google Cloud (Google Ireland Limited) | All platform data at rest and in transit; and, for authentication, your e-mail address and sign-in identifier | Hosting, database, file storage, messaging and the Identity Platform that signs you in |
| Meta Platforms Ireland Limited | Advertising account, page, Instagram and dataset identifiers; ad performance; and, for server-side purchase events, hashed e-mail and phone as described in section 3.3 | Running and measuring partnership ads a creator has approved, and attribution |
| Shopify and other connected e-commerce platforms | Catalogue and order data, through the access the brand itself granted | Attribution and reporting for that brand |
| Apple, Google or Mozilla, depending on your browser | A device push endpoint and a notification payload encrypted for your device, containing the notification title and a short text preview. Previews may include review, message or earnings information and may appear on your lock screen, depending on your device settings | Delivering optional device notifications through your browser's push service |
| Our hosting, monitoring and support providers | As set out in the current list at getrocketjuice.com/dpa#sub-processors | Operating the platform |
We also disclose personal data where we are legally required to, and to professional advisers under a duty of confidence.
6. WHERE IT IS STORED, AND TRANSFERS OUTSIDE THE EEA
Platform data is stored in the European Union, in Google Cloud's europe-west3 region (Frankfurt, Germany).
Some of the recipients in section 5 are part of groups with operations outside the European Economic Area. Where personal data is transferred to a third country, the transfer is made on the basis of an adequacy decision under Article 45 GDPR, the European Commission's Standard Contractual Clauses under Article 46(2)(c), or another mechanism permitted by Chapter V GDPR, together with a transfer impact assessment and any supplementary measures assessed as necessary. [Transfer mechanism relied on per recipient — to be confirmed and listed.]
You can ask us for a copy of the safeguards relied on for any specific transfer.
7. HOW LONG WE KEEP IT
| Data | Retention |
|---|---|
| Account and profile | For as long as the account exists, and then for the periods below where they apply |
| Accounting, invoicing, payout and tax records | [retention period — to be confirmed, e.g. 10 years for accounting records under Act No. 431/2002 Coll.] |
| Submissions, review decisions, acceptance events and attribution records | As the authoritative record of what was agreed and what became payable, for the period in clause 3.5.3 of the Creator Terms |
| Record of which terms you accepted, and when | For as long as the account exists, and afterwards for as long as a claim under those terms could still be brought |
| Device notification subscriptions | Removed on successful unsubscribe, session revocation or account erasure, or after 30 days without an app visit; delivery records expire after 7 days |
| Messages and notifications | With the conversation they belong to, for as long as the account exists |
| Security and access logs | [log retention period — to be confirmed] |
Erasing your account does not erase records we are legally required to keep, the licences already granted under Article 6 of the Creator Terms, or claims that have already accrued. This is clause 7.3.2 of the Creator Terms, and it is a limit on the right in section 10.3 rather than an exception we invented.
8. COOKIES AND LOCAL STORAGE
We use one cookie and one browser storage key. Neither is used for advertising or analytics.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| rj_session | Cookie — httpOnly, Secure, SameSite=Lax | Keeps you signed in. Without it the platform cannot tell one signed-in user from another | 7 days, or until you sign out |
| rj-theme | Local storage | Remembers whether you chose the light or the dark appearance | Until you clear it |
Both are strictly necessary to provide a service you have explicitly requested, so under Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) as implemented in Slovakia they do not require consent, and we show no cookie banner because there is nothing to consent to.
A brand's own store is a different matter. Tracking on the brand's site, including any pixel or conversion tracking, is the brand's responsibility, and clause 6.1.4 of the Brand Terms requires the brand to obtain and honour the consent that requires.
9. AUTOMATED DECISION-MAKING
We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22(1) GDPR.
Attribution is automated: the platform assigns a sale to a submission and a creator by applying the attribution rules to the tracking parameters. We use automated content matching and similarity detection to detect unauthorised use of creator content. In both cases the output is evidence, not a conclusion — clause 4.6.5 of the Creator Terms requires human review before a deemed-acceptance event is recorded, and clause 5.12 gives you a route to dispute any amount.
We do not profile you for advertising.
10. YOUR RIGHTS
Under the GDPR you have the following rights in respect of the data we hold about you as controller.
10.1 Access — Article 15
To be told whether we process your data, and to receive a copy of it together with the information in this policy.
10.2 Rectification — Article 16
To have inaccurate data corrected and incomplete data completed.
10.3 Erasure — Article 17
To have your data deleted where one of the grounds in Article 17(1) applies. Section 7 explains what survives erasure and why.
10.4 Restriction — Article 18
To have processing restricted while an accuracy dispute or an objection is being resolved.
10.5 Portability — Article 20
To receive the data you gave us, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible. This applies to processing based on consent or on the contract.
10.6 Objection — Article 21
To object at any time to processing based on our legitimate interests. Where you object to direct marketing we stop, without exception and without balancing.
10.7 Withdrawing consent — Article 7(3)
Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it. A creator's approval of a brand partnership is given and withdrawn in their own Instagram account; when it is withdrawn we pause the ad.
10.8 How to exercise them
Write to marek@getrocketjuice.com from the address your account uses. We answer without undue delay and in any event within one month of receiving the request, as required by Article 12(3) GDPR. Where a request is complex, or where you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do and why.
10.9 Deleting your account
To have your account and the personal data we hold about you deleted — including data obtained through Meta platforms — write to marek@getrocketjuice.com from your account address with the subject "Delete my data". We confirm by reply. This is also the data deletion instructions URL our Meta app configuration points at.
10.10 Complaining to a supervisory authority — Article 77
You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic, or with the supervisory authority where you live or work. You do not have to come to us first.
11. SECURITY
We implement technical and organisational measures appropriate to the risk under Article 32 GDPR, including access control, encryption in transit, database roles that separate the application's read access from schema ownership, row-level security on tenant data, logging, and separated environments. Access tokens for connected stores and advertising accounts are held in a secret manager, never in plain text in the database. A fuller description is Annex II of the Data Processing Agreement at getrocketjuice.com/dpa#security.
If a personal data breach occurs, we notify the supervisory authority under Article 33 and, where the breach is likely to result in a high risk to you, we notify you under Article 34.
12. CHILDREN
The platform is for businesses. Both the Creator Terms and the Brand Terms are concluded exclusively between businesses, and you must be able to enter into a binding contract to use it. We do not knowingly collect data from children, and a brand must not transmit data of children to the platform.
13. CHANGES TO THIS POLICY
We update this policy when what we do with data changes. The version and date are in the panel at the top of this page. Where a change materially affects you we tell you before it takes effect, by e-mail or in the platform.
See also our Terms and conditions.