Privacy Policy

Last updated: April 1, 2026

Effective Date: April 1, 2026

1. Introduction & Scope

BigFame Inc. ("BigFame," "we," "us," or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your personal information when you use the BigFame.ai website, mobile applications, APIs, and related services (collectively, the "Services").

This Privacy Policy applies to all users of the Services, including creators, brands, advertisers, website builders, e-commerce merchants, and visitors. It covers information collected through the BigFame.ai platform, our TikTok creator marketplace, AI brand matching tools, website builder, CRM, marketing automation features, e-commerce storefront, domain registration services, and all integrations accessible through the platform.

By accessing or using the Services, you acknowledge that you have read, understood, and agree to the collection and use of your information as described in this Privacy Policy. If you do not agree with our data practices, please discontinue your use of the Services. This Privacy Policy should be read in conjunction with our Terms of Service, available at bigfame.ai/terms.

For individuals in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, BigFame Inc. is the data controller for the personal data we process. For California residents, additional rights and disclosures are provided in Sections 14 and 17 of this Policy.

2. Information We Collect

We collect several categories of information depending on how you interact with the Services:

2.1 Personal Information

Information that identifies or can be used to identify you as an individual, including:

  • Full name, email address, phone number, and mailing address
  • Date of birth (for age verification)
  • Profile photograph and biographical information
  • Business name, tax identification number (for merchants and agencies), and business address
  • Social media handles and profile URLs (including TikTok, Instagram, YouTube, and other platforms)
  • Government-issued identification (when required for identity verification or payouts)

2.2 Usage Data

Information about how you interact with the Services, including:

  • Pages visited, features used, buttons clicked, and time spent on various sections
  • Search queries and filter selections
  • Content creation and editing activity
  • Campaign participation history and performance metrics
  • Website builder usage patterns, template selections, and publishing activity
  • Integration activation and usage data

2.3 Device & Technical Information

  • IP address, browser type and version, operating system
  • Device type, unique device identifiers, and screen resolution
  • Language preferences and time zone settings
  • Referring URLs, exit pages, and navigation paths
  • Network connection type and internet service provider

2.4 Cookie Data

Information collected through cookies, web beacons, pixel tags, and similar tracking technologies, as described in detail in Section 9 of this Policy.

2.5 Firebase Authentication Data

When you create an account or log in using Google Firebase Authentication, we collect your Firebase UID, authentication token data, email address associated with your authentication provider, display name, and profile photo URL. This data is used solely for authentication, account management, and security purposes.

2.6 TikTok API Data

When you connect your TikTok account to BigFame.ai, we collect data through the TikTok API, including:

  • Public profile information (username, display name, bio, profile image, verified status)
  • Follower count, following count, and video count
  • Audience demographics (age ranges, gender distribution, geographic regions)
  • Content performance metrics (views, likes, comments, shares, engagement rates)
  • Video metadata (titles, descriptions, hashtags, posting dates)

We access this data in accordance with TikTok's API Terms of Service and only with your explicit authorization. You may revoke TikTok access at any time through your TikTok account settings or your BigFame.ai account settings.

2.7 Payment Data

Payment processing is handled by Stripe, Inc. When you make a payment or receive a payout, Stripe collects and processes your payment card details, bank account information, and billing address. BigFame.ai does not directly store your full payment card numbers or bank account details. We receive from Stripe limited payment information, including the last four digits of your card, card brand, expiration date, billing address, and transaction history, which we use for account management, invoicing, and fraud prevention.

3. How We Collect Information

We collect information through the following methods:

3.1 Directly Provided by You

  • When you create an account and complete your profile
  • When you subscribe to a paid plan or make a purchase
  • When you create or edit website content, campaigns, or storefront listings
  • When you communicate with our support team via email, chat, or phone
  • When you submit forms, surveys, or feedback on the platform
  • When you participate in contests, promotions, or events
  • When you register a domain name through our platform

3.2 Automatically Collected

  • Through cookies, web beacons, and similar tracking technologies when you visit our website or use the Services
  • Through server logs that record requests made to our servers
  • Through analytics tools that track usage patterns and performance metrics
  • Through error reporting and crash analytics systems

3.3 From Third-Party Sources

  • TikTok: Public profile data, audience analytics, and content performance metrics when you connect your TikTok account
  • Google: Authentication data (name, email, profile photo) when you sign in with Google; Google Analytics data for website performance
  • Stripe: Payment confirmation, transaction history, and limited billing details
  • Social Media Platforms: Public profile information from connected accounts (Instagram, YouTube, X/Twitter, and others)
  • Domain Registrars: WHOIS data and domain status information
  • Third-Party Integrations: Data shared through the 207+ integrations available on our platform, as authorized by you
  • Publicly Available Sources: Business registration records, public social media profiles, and publicly available content relevant to brand matching and verification

4. How We Use Your Information

We use the information we collect for the following purposes:

4.1 Service Delivery & Operations

  • To create, maintain, and secure your account
  • To provide, operate, and improve the Services, including the website builder, CRM, e-commerce tools, domain registration, and marketing automation features
  • To process transactions, subscriptions, and payouts
  • To facilitate creator-brand connections and campaign management
  • To provide customer support and respond to inquiries
  • To manage domain registrations, transfers, and renewals

4.2 AI Matching & Personalization

  • To power our AI brand-creator matching algorithms, which analyze audience data, engagement metrics, content categories, and brand preferences
  • To generate personalized content recommendations, optimal posting times, and audience insights
  • To provide AI-powered website design suggestions, SEO recommendations, and marketing automation workflows
  • To improve the accuracy and relevance of our AI models using aggregated and anonymized data

4.3 Analytics & Insights

  • To generate analytics dashboards, performance reports, and business intelligence insights
  • To measure campaign effectiveness, ROI, and audience engagement
  • To provide aggregated industry benchmarks and trend analysis
  • To monitor platform health, usage patterns, and feature adoption

4.4 Marketing & Communications

  • To send transactional emails (receipts, confirmations, service updates)
  • To send promotional communications about new features, special offers, and platform news (with your consent or where permitted by law)
  • To deliver targeted advertising and retargeting campaigns
  • To conduct user research, surveys, and feedback collection

4.5 Security & Fraud Prevention

  • To detect, prevent, and investigate fraud, unauthorized access, and security incidents
  • To verify user identity and prevent fake accounts
  • To enforce our Terms of Service and Acceptable Use Policy
  • To comply with legal obligations, including anti-money laundering (AML) and know-your-customer (KYC) requirements
  • To protect the rights, safety, and property of BigFame, our users, and the public

6. Creator-Specific Data Practices

If you use BigFame.ai as a creator, we collect and process additional categories of data specific to the creator experience:

6.1 TikTok Data

When you connect your TikTok account, we access your public profile information and content metrics through the TikTok API. This data is refreshed periodically (typically daily) to provide up-to-date analytics. We store historical performance data to generate trend analyses and growth reports. You can disconnect your TikTok account at any time, which will stop future data collection. Previously collected data may be retained in accordance with Section 11 (Data Retention Periods).

6.2 Audience Analytics

We process audience demographic data (including age ranges, gender distribution, and geographic locations) to generate audience insights, power our AI matching algorithm, and provide brands with aggregated audience information. Individual audience member data is not collected; we only process aggregate statistics provided by platform APIs.

6.3 Brand Matching Data

Our AI matching system uses your content categories, audience demographics, engagement rates, brand affinity scores, prior campaign history, and stated preferences to recommend brand partnerships. Your creator profile (including selected metrics) may be visible to brands browsing the marketplace, subject to your privacy settings. You can control what information is visible to brands through your Creator Hub privacy settings.

6.4 Revenue & Earnings Data

We process data related to your earnings from brand campaigns, including payment amounts, payment dates, campaign identifiers, tax withholding information, and payout details. This data is used for payment processing, tax reporting (including generation of 1099 forms where applicable under US law), platform fee calculations, and earnings analytics. Earnings data is retained for a minimum of seven (7) years to comply with tax and financial regulations.

7. Information Sharing & Disclosure

We do not sell your personal information to third parties. We may share your information in the following circumstances:

7.1 Service Providers

We share information with trusted third-party service providers who perform services on our behalf, including cloud hosting (e.g., AWS, Google Cloud), payment processing (Stripe), email delivery, customer support tools, analytics providers, and security services. These providers are contractually obligated to use your data only for the purpose of providing services to us and are required to maintain appropriate security measures.

7.2 Brand Partners (With Your Consent)

For creators, your public creator profile information (including audience demographics, engagement metrics, and content samples) may be shared with brands browsing the marketplace. When you accept a brand campaign, additional information may be shared with the brand as specified in the campaign terms. You will be informed of what data will be shared, and your consent is required before sharing non-public creator data with specific brands.

7.3 Legal Requirements

We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to: (a) comply with a legal obligation, court order, or legal process; (b) protect and defend the rights or property of BigFame Inc.; (c) prevent or investigate possible wrongdoing in connection with the Services; (d) protect the personal safety of users of the Services or the public; or (e) protect against legal liability.

7.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, asset sale, or other business transfer involving BigFame Inc., your personal information may be transferred as part of the transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy. Where required by law, we will seek your consent before such transfer.

7.5 Aggregated & Anonymized Data

We may share aggregated or anonymized data that cannot reasonably be used to identify you with third parties for research, analytics, benchmarking, marketing, and other purposes. This data does not constitute personal information under applicable data protection laws.

8. Third-Party Services & Integrations

BigFame.ai integrates with numerous third-party services to provide comprehensive functionality. The following are key third-party services and their data practices:

8.1 Stripe (Payment Processing)

Stripe processes all payment transactions on our platform. When you provide payment information, it is collected and processed directly by Stripe in accordance with Stripe's Privacy Policy (stripe.com/privacy). Stripe is PCI-DSS Level 1 certified, the highest level of payment security compliance.

8.2 Firebase (Authentication & Infrastructure)

We use Google Firebase for user authentication, real-time database services, and cloud functions. Firebase processes authentication data, session tokens, and application performance data in accordance with Google's Privacy Policy and Firebase Terms of Service.

8.3 Google Analytics

We use Google Analytics to collect and analyze website usage data, including page views, session duration, bounce rates, and traffic sources. Google Analytics uses cookies and may collect IP addresses (which are anonymized). You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

8.4 TikTok API

Our integration with TikTok uses the TikTok API to access creator profiles and content metrics with creator authorization. Data accessed through the TikTok API is used in accordance with TikTok's API Terms of Service and this Privacy Policy. We do not access private messages, unpublished content, or login credentials from TikTok.

8.5 207+ Additional Integrations

BigFame.ai offers over 207 integrations with third-party services including social media platforms, email marketing providers, e-commerce tools, CRM systems, analytics platforms, and productivity applications. Each integration you enable may share data between BigFame.ai and the third-party service. We recommend reviewing the privacy policies of any third-party services you connect to your BigFame.ai account. We are not responsible for the privacy practices or data handling of third-party services.

9. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities and to distinguish you from other users. This helps us provide a better experience and improve our Services.

9.1 Essential Cookies

Required for the operation of the Services. These include cookies for authentication, session management, security, load balancing, and user preferences. These cookies cannot be disabled as the Services would not function without them.

9.2 Analytics Cookies

Used to collect information about how you use the Services, including which pages you visit, how long you stay, and what errors you encounter. This data helps us understand usage patterns and improve the platform. We use Google Analytics and internal analytics tools. Analytics cookies can be disabled through your cookie preferences.

9.3 Marketing Cookies

Used to track your activity across websites and deliver targeted advertising. These cookies may be set by us or by third-party advertising partners. They are used to build a profile of your interests and show you relevant advertisements on other sites. Marketing cookies require your explicit consent and can be managed through your cookie preferences.

9.4 Cookie Management

You can manage your cookie preferences through the cookie consent banner displayed when you first visit our website, through your browser settings, or through your account settings on the platform. Most browsers allow you to refuse or delete cookies. Please note that blocking certain cookies may impact the functionality of the Services. For more information about cookies and how to manage them, visit allaboutcookies.org.

10. Data Security Measures

We take the security of your personal information seriously and implement appropriate technical, administrative, and physical safeguards to protect your data from unauthorized access, alteration, disclosure, or destruction.

10.1 Encryption

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
  • Sensitive data at rest is encrypted using AES-256 encryption
  • Payment data is encrypted and processed in PCI-DSS compliant environments
  • Passwords are hashed using industry-standard bcrypt algorithms and are never stored in plain text

10.2 Access Controls

  • Role-based access controls (RBAC) limit employee access to personal data on a need-to-know basis
  • Multi-factor authentication (MFA) is required for all internal systems
  • Regular access reviews and privilege audits are conducted
  • All access to production systems is logged and monitored

10.3 Compliance & Certifications

BigFame.ai is committed to achieving and maintaining SOC 2 Type II compliance, which demonstrates our commitment to security, availability, processing integrity, confidentiality, and privacy. Our infrastructure is hosted on SOC 2 and ISO 27001 certified cloud platforms.

10.4 Incident Response

We maintain a documented incident response plan that includes procedures for detecting, containing, investigating, and remediating security incidents. In the event of a data breach that affects your personal information, we will notify you and the relevant supervisory authorities within the timeframes required by applicable law (72 hours under GDPR). Notifications will include a description of the breach, the data affected, the measures taken, and recommendations for protecting yourself.

While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to continuous improvement of our security posture.

11. Data Retention Periods

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, to provide the Services, and to comply with legal obligations. Specific retention periods are as follows:

Data TypeRetention Period
Account profile informationDuration of account + 30 days after deletion
Website content & filesDuration of account + 90 days after deletion
Payment & billing records7 years (tax and financial compliance)
Creator earnings & payout data7 years (tax and financial compliance)
TikTok analytics dataDuration of account + 30 days after disconnection
Campaign & brand deal records3 years after campaign completion
Customer support communications3 years after last interaction
Usage & analytics data26 months in aggregated form
Server logs90 days
Cookie dataUp to 13 months (varies by cookie type)
Marketing consent recordsDuration of consent + 5 years
Domain registration recordsDuration of registration + 1 year after expiry

After the applicable retention period expires, we will securely delete or anonymize your data. Aggregated and anonymized data that can no longer identify you may be retained indefinitely for statistical and research purposes.

12. International Data Transfers

BigFame Inc. is based in the United States, and your personal information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from the laws of your jurisdiction.

12.1 Standard Contractual Clauses (SCCs)

For transfers of personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on the European Commission's Standard Contractual Clauses (SCCs) as a lawful transfer mechanism. These contractual provisions ensure that your data receives equivalent protection regardless of where it is processed. We use the most current version of the SCCs adopted by the European Commission, supplemented by additional safeguards where required.

12.2 EU-U.S. Data Privacy Framework

BigFame Inc. is committed to complying with the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework, as applicable, for the transfer of personal data from the European Union, United Kingdom, and Switzerland to the United States.

12.3 Additional Safeguards

In addition to SCCs and the DPF, we implement supplementary technical and organizational measures to protect transferred data, including encryption in transit and at rest, access controls, data minimization, and regular assessments of the legal framework of recipient countries. We ensure that our sub-processors are contractually obligated to maintain equivalent data protection standards.

13. Your Privacy Rights — GDPR

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and equivalent local laws:

13.1 Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it. We will respond to your request within one (1) month, which may be extended by two additional months for complex or numerous requests.

13.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data. You can update much of your information directly through your account settings, or contact us for assistance with data that cannot be self-corrected.

13.3 Right to Erasure ("Right to Be Forgotten")

You have the right to request the deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing and there are no overriding legitimate grounds. Please note that we may need to retain certain data for legal compliance, dispute resolution, or the exercise or defense of legal claims.

13.4 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV), and to transmit that data to another controller without hindrance, where processing is based on consent or contract and carried out by automated means.

13.5 Right to Restriction of Processing

You have the right to request restriction of processing of your personal data in certain circumstances, including when you contest the accuracy of the data, when processing is unlawful, or when we no longer need the data but you require it for legal claims.

13.6 Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop processing your data for that purpose immediately. For other objections, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

13.7 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

13.8 Right to Lodge a Complaint

If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with your local supervisory authority (Data Protection Authority). We would appreciate the opportunity to address your concerns before you approach the supervisory authority, so please contact us first at privacy@bigfame.ai.

To exercise any of these rights, please contact us at privacy@bigfame.ai or through your account settings. We will verify your identity before processing your request. Requests are generally processed free of charge, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

14. Your Privacy Rights — CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following rights regarding your personal information:

14.1 Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected the information, the business or commercial purpose for collecting or selling the information, and the categories of third parties with whom we share the information. You may make a verifiable request up to twice within a 12-month period.

14.2 Right to Delete

You have the right to request the deletion of your personal information that we have collected, subject to certain exceptions as provided by law (such as data needed to complete a transaction, detect security incidents, comply with a legal obligation, or exercise free speech).

14.3 Right to Opt-Out of Sale or Sharing

BigFame.ai does not sell your personal information to third parties as defined by the CCPA. If our practices change in the future, we will update this Policy and provide an opt-out mechanism. We may share personal information with service providers for business purposes, which is not considered a "sale" under the CCPA. For cross-context behavioral advertising, you have the right to opt out of the sharing of your personal information by contacting us at privacy@bigfame.ai or through the "Do Not Sell or Share My Personal Information" link on our website.

14.4 Right to Correct

You have the right to request correction of inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes of processing.

14.5 Right to Non-Discrimination

BigFame.ai will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices, provide a different level or quality of service, or suggest that you may receive a different price or quality of goods or services as a result of exercising your rights.

To exercise your CCPA/CPRA rights, contact us at privacy@bigfame.ai or call (617) 401-7650. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf, subject to proper verification.

15. Children's Privacy

BigFame.ai is not intended for use by children under the age of 13 (or under the age of 16 in the EEA/UK). We do not knowingly collect, use, or disclose personal information from children under 13.

In compliance with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations, if we become aware that we have collected personal information from a child under 13 without verification of parental consent, we will take immediate steps to delete that information from our servers.

If you are a parent or guardian and believe that your child under 13 has provided personal information to us, please contact us immediately at privacy@bigfame.ai. We will promptly investigate and take appropriate action, including deletion of the child's information.

Users between the ages of 13 and 17 may only use the Services under the supervision of a parent or legal guardian who agrees to be bound by these Terms and this Privacy Policy. BigFame.ai reserves the right to require age verification at any time.

16. Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals to the websites and other online services with which the browser communicates. There is currently no universally accepted standard for how companies should respond to DNT signals. At this time, BigFame.ai does not respond to DNT signals. However, you can manage your tracking preferences through the cookie settings described in Section 9 of this Policy.

We honor the Global Privacy Control (GPC) signal as a valid opt-out of the sale or sharing of personal information for California residents, in accordance with the CCPA/CPRA. If we detect a GPC signal from your browser, we will treat it as a request to opt out of the sale or sharing of your personal information associated with that browser.

17. California Privacy Rights (Shine the Light)

Under California Civil Code Section 1798.83 ("Shine the Light" law), California residents who have an established business relationship with BigFame Inc. may request information about our disclosure of personal information to third parties for their direct marketing purposes during the preceding calendar year.

To make such a request, please send an email to privacy@bigfame.ai with the subject line "Shine the Light Request" or write to us at: BigFame Inc., Attn: Privacy Team, 33 Arch St, Boston, MA 02109.

Please include your name, mailing address, and a clear statement that you are making a request under the Shine the Light law. We will respond within thirty (30) days of receiving your request. Please note that BigFame.ai does not currently disclose personal information to third parties for their direct marketing purposes.

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make changes, we will:

  • Update the "Last updated" date at the top of this Policy
  • Post the revised Policy on our website at bigfame.ai/privacy
  • For material changes that affect how we process your personal data, provide at least thirty (30) days' advance notice through email, platform notification, or a prominent banner on our website
  • Where required by law (such as under GDPR), obtain your consent before implementing changes that require it

Your continued use of the Services after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. If you do not agree to the changes, you should stop using the Services and contact us to delete your account.

We encourage you to review this Privacy Policy periodically to stay informed about our data practices. Prior versions of this Privacy Policy are available upon request.

19. Data Protection Officer

BigFame Inc. has appointed a Data Protection Officer (DPO) to oversee compliance with data protection laws and to serve as a point of contact for data subjects and supervisory authorities.

You may contact our Data Protection Officer for any questions or concerns about our data processing practices, to exercise your data protection rights, or to submit a complaint about our handling of your personal information:

  • Title: Data Protection Officer
  • Email: dpo@bigfame.ai
  • Mailing Address: BigFame Inc., Attn: Data Protection Officer, 33 Arch St, Boston, MA 02109, United States

Our DPO will respond to all inquiries within thirty (30) days. For complex requests, we may extend this period by an additional sixty (60) days, in which case we will notify you of the extension and the reasons for the delay.

20. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your personal information, please contact us through any of the following channels:

  • Company: BigFame Inc.
  • Privacy Inquiries: privacy@bigfame.ai
  • Data Protection Officer: dpo@bigfame.ai
  • General Support: support@bigfame.ai
  • Phone: (617) 401-7650
  • Mailing Address: 33 Arch St, Boston, MA 02109, United States

By using BigFame.ai, you acknowledge that you have read this Privacy Policy, understand it, and agree to the collection, use, and disclosure of your information as described herein.

Copyright 2026 BigFame Inc. All rights reserved.