Privacy policy

What we do with personal data, why we are allowed to, and what you can make us do about it.

Operator
Controller
Rocket Juice s. r. o.
Registered seat
Vajanského 1955/58, 921 01 Piešťany, Slovak Republic
Company ID (IČO)
57730393
Tax ID (DIČ)
2122903222
VAT
Not registered for VAT
Commercial register
Obchodný register Okresného súdu Trnava, oddiel: Sro, vložka č. 63692/T
Contact
marek@getrocketjuice.com
This document
Document
Rocket Juice — Privacy Policy
Applies to
getrocketjuice.com and the Rocket Juice platform
Last updated
18 August 2026
Version
2.0

1. WHO WE ARE

Rocket Juice s. r. o. operates the Rocket Juice platform at getrocketjuice.com. Where this policy says "we", "us" or "Rocket Juice", it means that company. Our identity and registration details are in the Operator panel above.

For everything described in this policy for which we decide the purposes and means, we are the controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the GDPR). Slovak Act No. 18/2018 Coll. on the protection of personal data applies alongside it.

Questions about this policy, and requests under the rights in section 10, go to marek@getrocketjuice.com or to [data protection contact / DPO — to be confirmed].

2. THE THREE ROLES THIS PLATFORM PUTS US IN

Rocket Juice sits between two businesses, and the same company can be a controller for one set of data and a processor for another. Which role we are in decides who you go to, so it is set out first rather than buried.

DataOur roleWho else is involved
Account, identity, communications, submissions, attribution results, earnings and ledger entries of creators and brand usersController (independent)The brand is a separate, independent controller for its own purposes; its own privacy notice applies to that processing. We are not joint controllers with a brand.
End-customer data from a brand's connected store and tracking parameters — order, conversion and device dataProcessor, on the brand's behalfThe brand is the controller and is responsible for the lawfulness of its own tracking and for any consent required. The Data Processing Agreement at getrocketjuice.com/dpa governs this processing.
People appearing in a creator's videoNeither — the creator is controllerThe creator is responsible for the consents and releases required by clause 4.3.1(c) of the Creator Terms.

This mirrors clause 7.1 of the Creator Terms and clause 6.1 of the Brand Terms. [Confirmation of the GDPR role mapping across the three-sided relationship — to be confirmed.]

3. WHAT WE COLLECT

3.1 If you are a creator

3.2 If you are a brand user

3.3 If you bought something from a brand that uses us

We are the brand's processor for this, not the controller. Your order arrives from the brand's store carrying far more than we need, so we discard the excess before storing it. What we keep is the order reference, the value and currency, the time and status of the order, and the tracking parameter that identifies which creator video the sale is attributed to.

What we do not keep, and delete on arrival: your name, e-mail address and phone number, your billing and shipping address, your IP address, your browser and device details, the page you arrived from, and any advertising click identifiers. Orders stored before 18 August 2026 have had the same data removed.

Where a brand has connected Meta and the sale is credited deterministically, we may also send Meta a server-side purchase event. What leaves our systems in that event is the SHA-256 hash of the e-mail address and of the phone number, together with the order id, value, currency and the page the purchase happened on. The raw e-mail address and phone number are hashed before the request is built and are not transmitted. A hash of this kind is still personal data under the GDPR — it is pseudonymised, not anonymised — which is why it is disclosed here.

3.4 If you are only visiting the website

The public pages set no analytics, no advertising and no tracking cookies, and we run no third-party analytics on them.

Every purpose below is tied to one of the legal bases in Article 6(1) GDPR. This table is the same set of bases the Creator Terms name in clause 7.2.1.

PurposeLegal basis
Creating and running your account; running programs, submissions, review and acceptance; measuring attributed sales; calculating remuneration; facilitating payment; messaging between a creator and a brandArticle 6(1)(b) — performance of the contract you entered into by accepting the Creator Terms or the Brand Terms
Accounting and tax records, statutory reporting, anti-money-laundering obligations, and keeping records we are required to keepArticle 6(1)(c) — compliance with a legal obligation
Keeping the platform secure; preventing and detecting fraud and unauthorised use of creator content; resolving disputes; improving the services; producing aggregated, de-identified benchmarks that identify no brand, creator or customerArticle 6(1)(f) — our legitimate interests. We have weighed these against your interests and rights; you can object at any time under section 10 and we will stop unless we can show compelling legitimate grounds
Marketing e-mails, and the uses of creator content described in clauses 6.7.3 and 6.7.4 of the Creator TermsArticle 6(1)(a) — your consent, which you may withdraw at any time without affecting processing already carried out

We do not sell personal data, we do not post or send messages as you, and we do not use your data to train models for anyone else.

5. WHO WE SHARE IT WITH

RecipientWhat they receiveWhy
The brand whose program you joinedYour profile, submissions, performance and the remuneration owed to youIt is a party to the commercial relationship; it is an independent controller for its own purposes
Besteron — Besteron a.s., Prešovská 38/B, Bratislava – mestská časť Ružinov 821 02, Slovak Republic, Company ID (IČO): 47866233, registered in the Commercial Register of the Municipal Court Bratislava III, section: Sa, insert no. 6004/B, a payment institution authorised and supervised by Národná banka Slovenska under licence no. ODB-6111/2015-7The payment identifiers and amounts needed to execute a paymentIt is the payment service provider through which a brand settles what it owes you
Google Cloud (Google Ireland Limited)All platform data at rest and in transit; and, for authentication, your e-mail address and sign-in identifierHosting, database, file storage, messaging and the Identity Platform that signs you in
Meta Platforms Ireland LimitedAdvertising account, page, Instagram and dataset identifiers; ad performance; and, for server-side purchase events, hashed e-mail and phone as described in section 3.3Running and measuring partnership ads a creator has approved, and attribution
Shopify and other connected e-commerce platformsCatalogue and order data, through the access the brand itself grantedAttribution and reporting for that brand
Apple, Google or Mozilla, depending on your browserA device push endpoint and a notification payload encrypted for your device, containing the notification title and a short text preview. Previews may include review, message or earnings information and may appear on your lock screen, depending on your device settingsDelivering optional device notifications through your browser's push service
Our hosting, monitoring and support providersAs set out in the current list at getrocketjuice.com/dpa#sub-processorsOperating the platform

We also disclose personal data where we are legally required to, and to professional advisers under a duty of confidence.

6. WHERE IT IS STORED, AND TRANSFERS OUTSIDE THE EEA

Platform data is stored in the European Union, in Google Cloud's europe-west3 region (Frankfurt, Germany).

Some of the recipients in section 5 are part of groups with operations outside the European Economic Area. Where personal data is transferred to a third country, the transfer is made on the basis of an adequacy decision under Article 45 GDPR, the European Commission's Standard Contractual Clauses under Article 46(2)(c), or another mechanism permitted by Chapter V GDPR, together with a transfer impact assessment and any supplementary measures assessed as necessary. [Transfer mechanism relied on per recipient — to be confirmed and listed.]

You can ask us for a copy of the safeguards relied on for any specific transfer.

7. HOW LONG WE KEEP IT

DataRetention
Account and profileFor as long as the account exists, and then for the periods below where they apply
Accounting, invoicing, payout and tax records[retention period — to be confirmed, e.g. 10 years for accounting records under Act No. 431/2002 Coll.]
Submissions, review decisions, acceptance events and attribution recordsAs the authoritative record of what was agreed and what became payable, for the period in clause 3.5.3 of the Creator Terms
Record of which terms you accepted, and whenFor as long as the account exists, and afterwards for as long as a claim under those terms could still be brought
Device notification subscriptionsRemoved on successful unsubscribe, session revocation or account erasure, or after 30 days without an app visit; delivery records expire after 7 days
Messages and notificationsWith the conversation they belong to, for as long as the account exists
Security and access logs[log retention period — to be confirmed]

Erasing your account does not erase records we are legally required to keep, the licences already granted under Article 6 of the Creator Terms, or claims that have already accrued. This is clause 7.3.2 of the Creator Terms, and it is a limit on the right in section 10.3 rather than an exception we invented.

8. COOKIES AND LOCAL STORAGE

We use one cookie and one browser storage key. Neither is used for advertising or analytics.

NameTypePurposeLifetime
rj_sessionCookie — httpOnly, Secure, SameSite=LaxKeeps you signed in. Without it the platform cannot tell one signed-in user from another7 days, or until you sign out
rj-themeLocal storageRemembers whether you chose the light or the dark appearanceUntil you clear it

Both are strictly necessary to provide a service you have explicitly requested, so under Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) as implemented in Slovakia they do not require consent, and we show no cookie banner because there is nothing to consent to.

A brand's own store is a different matter. Tracking on the brand's site, including any pixel or conversion tracking, is the brand's responsibility, and clause 6.1.4 of the Brand Terms requires the brand to obtain and honour the consent that requires.

9. AUTOMATED DECISION-MAKING

We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22(1) GDPR.

Attribution is automated: the platform assigns a sale to a submission and a creator by applying the attribution rules to the tracking parameters. We use automated content matching and similarity detection to detect unauthorised use of creator content. In both cases the output is evidence, not a conclusion — clause 4.6.5 of the Creator Terms requires human review before a deemed-acceptance event is recorded, and clause 5.12 gives you a route to dispute any amount.

We do not profile you for advertising.

10. YOUR RIGHTS

Under the GDPR you have the following rights in respect of the data we hold about you as controller.

10.1 Access — Article 15

To be told whether we process your data, and to receive a copy of it together with the information in this policy.

10.2 Rectification — Article 16

To have inaccurate data corrected and incomplete data completed.

10.3 Erasure — Article 17

To have your data deleted where one of the grounds in Article 17(1) applies. Section 7 explains what survives erasure and why.

10.4 Restriction — Article 18

To have processing restricted while an accuracy dispute or an objection is being resolved.

10.5 Portability — Article 20

To receive the data you gave us, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible. This applies to processing based on consent or on the contract.

10.6 Objection — Article 21

To object at any time to processing based on our legitimate interests. Where you object to direct marketing we stop, without exception and without balancing.

10.7 Withdrawing consent — Article 7(3)

Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it. A creator's approval of a brand partnership is given and withdrawn in their own Instagram account; when it is withdrawn we pause the ad.

10.8 How to exercise them

Write to marek@getrocketjuice.com from the address your account uses. We answer without undue delay and in any event within one month of receiving the request, as required by Article 12(3) GDPR. Where a request is complex, or where you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do and why.

10.9 Deleting your account

To have your account and the personal data we hold about you deleted — including data obtained through Meta platforms — write to marek@getrocketjuice.com from your account address with the subject "Delete my data". We confirm by reply. This is also the data deletion instructions URL our Meta app configuration points at.

10.10 Complaining to a supervisory authority — Article 77

You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic, or with the supervisory authority where you live or work. You do not have to come to us first.

11. SECURITY

We implement technical and organisational measures appropriate to the risk under Article 32 GDPR, including access control, encryption in transit, database roles that separate the application's read access from schema ownership, row-level security on tenant data, logging, and separated environments. Access tokens for connected stores and advertising accounts are held in a secret manager, never in plain text in the database. A fuller description is Annex II of the Data Processing Agreement at getrocketjuice.com/dpa#security.

If a personal data breach occurs, we notify the supervisory authority under Article 33 and, where the breach is likely to result in a high risk to you, we notify you under Article 34.

12. CHILDREN

The platform is for businesses. Both the Creator Terms and the Brand Terms are concluded exclusively between businesses, and you must be able to enter into a binding contract to use it. We do not knowingly collect data from children, and a brand must not transmit data of children to the platform.

13. CHANGES TO THIS POLICY

We update this policy when what we do with data changes. The version and date are in the panel at the top of this page. Where a change materially affects you we tell you before it takes effect, by e-mail or in the platform.

See also our Terms and conditions.