Version 2, published October 8, 2026
Privacy policy, version 2
Version 2. In force from 8 October 2026. Replaces version 1, which was a placeholder.
This is what information Hollaro handles about you, why, who gets it, how long we keep it, and what rights you have. The policy covers webshops and their people, creators, creators we have built a profile about, people who click a creator's link, and visitors to hollaro.com. The Danish text is the master; this English text matches it.
1. Controller
SVEA IT, a sole proprietorship (enkeltmandsvirksomhed), CVR 36606061, Alstrup Skovvej 18, 4840 Nørre Alslev, Denmark. E-mail: hello@hollaro.com. Write to that address about anything to do with your information. We have no data protection officer, because our processing does not require one.
2. Webshops and their people
- What: name, e-mail, password (only as a code that cannot be read), language, role in the company, two-step sign-in, and which terms you accepted. About the company: name, CVR, address and VAT number. Campaigns, deals, messages and what you did on the platform.
- Why: to run the account and the deals (GDPR Art. 6(1)(b)), to meet the Danish Bookkeeping Act (Art. 6(1)(c)), and to keep the platform safe and prevent cheating (Art. 6(1)(f), our legitimate interest).
- Payment: the card is entered in Stripe's form. We never see the card number, only Stripe's answer, such as whether the payment went through.
- Without name, e-mail and company details we cannot create an account.
3. Creators
- What: name, e-mail, language, country, the categories you chose, two-step sign-in and which terms you accepted.
- From your platform account (TikTok, Instagram or YouTube), when you sign in: an ID for the account, username, display name and the public numbers the platform gives us, such as follower count, average views, engagement, when you last posted, and whether you have a link field. We only use totals. We never store information about your individual followers.
- Deals: drafts, posts, post links, our checks of them, messages, deadlines and payments.
- Payouts: Stripe creates your payout account and checks your identity. We are told whether the account is ready, and Stripe's ID for it. We never see your full account number or your ID documents.
- Tax (DAC7): before the first payout, your name, address, date of birth, CPR number or foreign tax number, and CVR and VAT number if you have them. Each quarter we total how much you were paid, the fees and the number of deals. We report this to the Danish Tax Agency (Skattestyrelsen) once a year and tell you by 31 January what we reported.
- Why: the contract with you (Art. 6(1)(b)), the Bookkeeping Act and the DAC7 rules (Art. 6(1)(c)), and security and cheating (Art. 6(1)(f)).
- Without this information you cannot take deals or be paid out.
4. Profiles we built from public data
This section is also our notice under GDPR Art. 14, for information we did not get from you. We send the same notice the first time we contact you.
- Source: only the platforms' official access to public data, such as YouTube's public channel statistics. We do not scrape against the platforms' rules.
- What: username, display name, the platform's ID for the account, follower count, average views, engagement, when you last posted, whether you have a link field, suggested categories, country and language.
- Why: to be able to invite you to Hollaro, and so webshops can see how many possible creators there are. Possible creators are shown apart from creators who have joined and are never counted as someone who can take an offer. The basis is our legitimate interest (Art. 6(1)(f)) in finding creators who could benefit from the platform.
- How long: at most 12 months, unless you make the profile yours.
- Your choice: with one click in the invite you can say no. We then delete the profile and stop collecting information about you. To respect that, we keep only the platform's ID for the account, as a one-way code that cannot be read back. You can also object by writing to us.
5. When you click a creator's link
- Links from creators go through our domain (addresses with /r/). When you click, we store the time, the link, browser type and country, and a code made from your IP address and your browser's user agent with a random salt. We do not store your IP address. The salt changes every day and is deleted after 2 days, so the code cannot be traced back to you.
- We set no cookie. The address of the shop gets a click ID and UTM fields added, which the shop and its analytics tool can read.
- Why: to count clicks for the webshop and the creator, and to filter out bots, repeat clicks and cheating (Art. 6(1)(f)).
- How long: individual clicks are deleted after 90 days. After that we keep only the number of clicks per day.
6. Visitors and cookies
- We use only necessary cookies: one that holds your session, one that keeps you signed in, and one that remembers your cookie choice. On the page where a webshop pays for a campaign, Stripe also sets cookies to prevent fraud. The full list, with durations and who can read them, is at hollaro.com/cookies.
- Your cookie choice is stored with a random ID, the version of the cookie list and the text you saw, and the time. No IP address or user agent. The choice lasts 12 months.
- If something goes wrong in your browser on our site, we store the error message and the page for 30 days, without IP address and without who you are.
- When you are signed in, we store the IP address and browser for each sign-in, so you and we can see where you are signed in. A sign-in lasts at most 30 days.
- When you accept terms, we store a code made from your IP address, never the address itself, as proof of acceptance.
7. Automated checks and AI
- When a creator submits a post, we check it with fixed rules and an AI model (Google Vertex AI, in the EU). The AI only gets the public post: link, text and images or video, product names and the brief's messages. Never the creator's name or contact details.
- The AI suggests; a person decides. No pay is held back, no post is refused and no account is restricted on automation alone. No decision about you is made solely by automated means with legal effect, as GDPR Art. 22 describes.
- Clicks are sorted automatically (bot, repeat, unusual, valid). This affects numbers, not pay, because creators are paid per post today.
8. Who gets the information
- Webshops see what is needed about a creator for the deal: name, profile, public numbers, posts, messages and a delivery address if you give one. The webshop is the controller of what it uses. Creators see the webshop's name, campaigns and measured record.
- Stripe (payments and payouts). Stripe is the controller of the information it collects to check identity and prevent fraud, under its own privacy policy: https://stripe.com/privacy.
- Resend sends and receives our e-mail from servers in the EU, as our processor.
- Google (Vertex AI in the EU) runs the AI-assisted check of public posts, as our processor.
- TikTok, Meta (Instagram) and Google (YouTube and Google sign-in), when you choose to sign in with them. They are the controllers of the sign-in. We only get what section 3 says.
- Your browser's push service (for example from Google, Apple or Mozilla), if you turn on notifications on your phone. The notification is encrypted and never contains the text of a message, only what happened and a link.
- Hosting: the platform runs on a server in the EU, as our processor.
- Company lookups: we look up CVR numbers at cvrapi.dk and check VAT numbers in the European Commission's VIES. We send only the number.
- The Danish Tax Agency (DAC7, section 3) and other authorities, when the law requires it.
- We never sell information, and we do not use it for ads.
9. Transfers outside the EU
We choose suppliers that process data in the EU. Where a supplier or its sub-processors can access data from a country outside the EU, such as the United States, this happens under the European Commission's standard contractual clauses or the EU-US Data Privacy Framework, as stated in the supplier's data processing agreement.
10. How long we keep it
- Account and profile: while the account is open, and 3 years after it is closed.
- Accounting (payments, ledger entries, payouts, refunds): 5 years from the end of the financial year they belong to, under the Bookkeeping Act. If you close your account, deals and ledger entries are made anonymous instead of deleted.
- DAC7 information: as long as the reporting rules require.
- Deal messages: they are part of the deal and are not deleted while the deal is kept. When the account is deleted, they are made anonymous.
- Profiles built from public data: at most 12 months unless someone makes them theirs. If you delete the profile, that happens at once.
- E-mails to us: 2 years.
- Individual clicks: 90 days. The salt for the click code: 2 days.
- Sign-ins: at most 30 days.
- Error reports: 30 days.
- Push notifications: the address of your phone's push service, until you turn notifications off.
- Cookie choices: the choice lasts 12 months and is then kept as proof for at most 3 years.
11. Your rights
- You can see your information and get a copy, have wrong information corrected, have it deleted, have its use restricted, and get information you gave us in a machine-readable format.
- You can object to processing we do on the basis of our legitimate interest, such as a profile built from public data. We then stop, unless we have compelling reasons that come first.
- Where we ask for consent, you can always withdraw it.
- Some information we must keep by law, such as accounting and DAC7. We make it anonymous or delete it as soon as we may.
- Write to hello@hollaro.com. We answer within one month.
- Complaints: you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, www.datatilsynet.dk.
12. Security
We encrypt the connection, store passwords as codes that cannot be read back, encrypt access keys to platforms, offer two-step sign-in, and log when our team reads messages or makes decisions. Only the people who need access have it.
13. Changes
If we change this policy, it becomes a new version with a number and a date. If the change is significant, you are told by e-mail before it applies.