Privacy Policy
Version 2.0, 3 August 2026
This policy explains what personal data Building Bridges processes, why we do so, how long we keep it and what rights you have. It applies to our platform (accounts, campaigns, payouts, Bridge City) and to the social media connections you can enable yourself.
1. Who we are and how to reach us
The data controller is Building Bridges B.V., Groeneweg 162W, Bunnik, Nederland, Chamber of Commerce no. 89282507. We operate the Building Bridges platform, where brands and artists run campaigns and creators are paid per 1,000 views.
For any privacy question, data request or complaint, email info@buildingbridgesagency.com. We respond within 30 days. All contact details are also on our contact page.
2. What personal data we collect
- Account and profile: name or artist name, email address, password (stored hashed, we can never read it), profile picture, bio, language, role (creator, business or artist) and account status.
- Creator application: your motivation, experience, portfolio links, content type and the social channels you provide. We use this only to review your application.
- Social accounts: the usernames and profile links of your channels (TikTok, Instagram, Snapchat, Facebook, YouTube) and their public metrics, such as followers and views.
- Business details: company name, Chamber of Commerce number, billing address and contact person if you run campaigns as a business or artist.
- Campaign and financial data: submitted video links, approved views, earnings, balance, invoices and payouts.
- Messages and reports: what you send us through the platform or by email, and reports made about your account.
- Technical data: IP address, browser and device information and log files, for security and abuse prevention.
We never ask for your TikTok password or that of any other platform. Bank details are entered directly with Stripe and never reach our servers.
3. What data we retrieve from TikTok and Instagram
You can connect your TikTok account through TikTok Login Kit. This is always your own choice: the platform works without it. When you connect, TikTok's own screen shows you exactly which permissions you grant. We retrieve only the following:
- Basic profile (scope user.info.basic): your unique TikTok ID (open id), display name, @username and profile picture. We use this to confirm the channel is really yours.
- Account statistics (scope user.info.stats): your follower count, total likes and number of videos.
- Videos (scope video.list): per video the ID, title or description, view, like, comment and share counts, the publication time and the share link.
- Access tokens: the access and refresh tokens issued by TikTok. They are stored in our database, are only reachable from our server, and are used solely to retrieve the data listed above on your behalf.
We use this data for exactly two purposes: confirming that the connected channel belongs to you, and counting the views of your campaign videos so you are paid correctly.
We do not read private messages, we do not access your contacts, we never post content on your behalf, and we do not sell, rent or licence TikTok data to anyone. We do not use it for advertising or profiling, and we do not combine it with data from other sources to track you outside the platform. Advertisers see only the results of their own campaign (which video and how many approved views), never your tokens or full account data.
Our use of the TikTok API follows the TikTok Developer Terms of Service and the TikTok Privacy Policy.
Instagram. You can also connect your Instagram professional account (business or creator) through Instagram Login. This too is your own choice; the platform works without it. Instagram's own screen shows you exactly which permissions you grant. We retrieve only the following: basic data (instagram_business_basic): your Instagram account ID, @username, name, account type, profile picture, follower count and your media (ID, caption, type, permalink, timestamp, likes and comments). And insights (instagram_business_manage_insights): performance data for your account and your media, such as views, reach and interactions. The access token issued by Instagram is stored in our database, is only reachable from our server, and is used solely to retrieve this data on your behalf.
We do not read Instagram messages or comments, we never post on your behalf, and we do not sell, rent or licence Instagram data to anyone. The data is used to confirm the channel is yours and to show your performance in your own dashboard and Creator ID. Our use of the Instagram API follows the Meta Platform Terms and the Instagram Privacy Policy.
4. Why we use your data, and on what legal basis
- Performance of a contract: managing your account, showing and assigning campaigns, reviewing submissions, counting views, tracking balances, invoicing and paying out.
- Consent: connecting your social accounts and retrieving your metrics there, and showing your verified metrics on your public profile or the leaderboard. You can withdraw consent at any time, see section 9.
- Legitimate interest: fraud prevention (checks for bought views, bots and view farms), platform security, abuse detection and improving our service using aggregated statistics.
- Legal obligation: statutory retention of invoices and financial records.
5. Leaderboard and public profiles
The leaderboard and public profile pages show verified accounts only, with your name or @username, profile picture, verified followers and views, growth and badges earned. We never publish exact earnings. You can switch off leaderboard participation and your public profile at any time in your settings or by emailing us.
6. Who we share data with
We do not sell personal data. We share only with parties needed to run the platform:
- Railway (hosting of the application and database).
- Stripe (invoices and payouts; Stripe processes your identity and bank details under its own responsibility).
- Resend (sending emails such as confirmations and password resets).
- TikTok and, where you connect them, other social platforms, solely for the connection you activated yourself.
- EnsembleData (public view counts of shared video links, for campaigns without an official connection).
- Google, only if you choose to sign in with Google.
- Advertisers on the platform: per campaign they see which creator takes part, which video was submitted and how many approved views it has. They receive no access tokens, no email addresses and no financial data of creators.
- Supervisory authorities, our accountant or public authorities where the law requires it.
7. How long we keep data
- Account data: for as long as your account exists. After closure we keep it for 30 days (for recovery), then delete or anonymise it.
- TikTok data and tokens: for as long as the connection is active. If you disconnect, we delete the tokens and retrieved profile data immediately.
- Campaign data (video links and approved views): for as long as needed to settle and account for the campaign.
- Invoices and financial records: 7 years, statutory retention period.
- Fraud files and reports: at most 2 years after they are closed.
- Log files: at most 12 months.
8. How we protect your data
- All traffic runs over an encrypted HTTPS connection.
- Passwords are stored hashed; recovery tokens are short-lived and single-use.
- TikTok access tokens live in a database that is only reachable from our server and are never exposed in the browser or to third parties.
- Access to admin functions and the database is limited to a small number of administrators and protected with strong, unique passwords.
- We request no more permissions than strictly necessary and delete what we no longer use.
- Suspect a leak or misuse? Email info@buildingbridgesagency.com and we will act immediately.
9. Disconnecting your TikTok or Instagram account and withdrawing consent
You can withdraw your consent at any time, without giving a reason. There are two ways:
- In the platform: go to Settings, the Connected accounts block, select TikTok and click Disconnect. We then revoke access with TikTok immediately and delete your tokens, TikTok ID and retrieved profile data from our database.
- In TikTok itself: open the TikTok app, go to Settings and privacy, Security and permissions, App permissions, and remove Building Bridges there. Access stops immediately.
- Instagram, in the platform: go to Settings, the Connected accounts block, select Instagram and click Disconnect. We then delete your access token, Instagram account ID, username and retrieved profile data from our database.
- In Instagram itself: open the Instagram app, go to Settings, Website permissions (Apps and websites) and remove Building Bridges there. Access stops immediately.
Withdrawing consent does not affect earnings you have already built up. Without a connection we can only verify new views through public metrics.
10. Deleting your data or your account
To have your data or your entire account deleted, email info@buildingbridgesagency.com from the address on your account with the subject "Deletion request". We confirm within 5 working days and delete your data within 30 days.
We then delete your profile, connected accounts, TikTok tokens and the metrics we retrieved. Two things we cannot simply erase: invoices and financial records must be kept for 7 years for the Dutch tax authorities, and records of proven fraud are kept for as long as needed to prevent repetition. If you still have a balance, we pay it out first.
11. Your rights under the GDPR
You have the right to access the data we hold about you, to rectification of incorrect data, to erasure, to restriction of processing, to object to processing based on legitimate interest, and to data portability: a copy of your data in a common file format. You may withdraw consent at any time, without affecting processing that already took place.
Send a request by email to info@buildingbridgesagency.com. We respond within 30 days and may ask for additional details to verify your identity. If you are not satisfied, you can lodge a complaint with the Dutch Data Protection Authority.
12. Minors
The platform is intended for users aged 16 and over. For payouts to users under 18 we ask for permission from a parent or guardian. We do not knowingly collect data from children under 16; if we find such an account, we delete it.
13. Cookies
We use functional cookies and local storage only: a cookie to keep you signed in, and preferences such as your language and light or dark mode. We place no advertising cookies and use no third-party trackers to follow you across websites.
14. Transfers outside the European Economic Area
Our suppliers (including Railway, Stripe, Resend and TikTok) may process data on servers outside the EEA, including in the United States. This takes place on the basis of the European Commission's standard contractual clauses or a valid adequacy decision.
15. Changes
We may update this policy. The current version is always on this page, with the date at the top. We will inform you through the platform or by email about material changes.