Privacy Policy

TLNTConnect Privacy Policy

Our collection, use, disclosure, retention, security, international-transfer, and privacy-rights practices.

Last updated July 21, 2026

Scope And Company Information

Tlnt Connect LLC, operating as TLNTConnect ("TLNTConnect," "we," "us," or "our"), is organized in Delaware. Our business mailing address is 611 South Dupont Highway, Dover, DE 19901. This policy applies to tlntconnect.com, the TLNTConnect application, workspaces, portals, public share links, provider integrations, and related support.

For account, security, product-improvement, marketing, and direct customer-relationship data, TLNTConnect generally acts as a controller or business. For creator, campaign, mailbox, brand-contact, and similar Customer Data submitted under an agency's instructions, TLNTConnect generally acts as a processor or service provider and the agency remains responsible for its own notices and lawful instructions.

Notice at Collection

At or before collection, we collect the categories described below for account administration, workspace and portal operation, creator and campaign management, communications, provider connections, security, support, legal compliance, and—when enabled—billing and accounting. We do not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising. We do not use sensitive personal information to infer characteristics about individuals.

Providing account and workspace information is necessary to create and administer an account. Provider permissions, optional profile fields, AI prompts, and integration data are optional, but the related feature may not work without them.

Information We Collect

  • Identifiers and account data: name, email, account and workspace identifiers, agency or brand name, role, invitations, authentication and legal-acceptance records, and support communications.
  • Agency and commercial operations: creator rosters, public social profiles, contacts, rates, notes, campaigns, deliverables, files, tasks, approvals, brand contacts, messages, reports, contracts, invoices, payout records, and accounting configuration.
  • Internet and technical activity: IP-derived security signals, device/browser and user-agent data, authentication cookies, local-storage preferences, request and audit logs, webhook and provider-sync events, errors, and feature activity.
  • Professional, demographic, and inference data: creator category, audience location/age/gender aggregates, performance metrics, niche, engagement, and suitability or match signals supplied by customers, public sources, or data providers.
  • Communications and connected-provider data: Gmail content and metadata, social-platform analytics, OAuth identifiers and token metadata, QuickBooks company/accounting records, and Shopify shipping details when an authorized user enables those features.
  • AI feature data: prompts, instructions, selected workspace context, tool results, responses, approvals, and safety/usage metadata processed to provide Atlas AI and related assistance.

Sources of Personal Information

We collect information directly from users; from the agency, brand, creator, or other organization that supplies or authorizes it; from connected services such as Clerk, Google/Nylas, Intuit, Shopify, and payment providers; from publicly available social profiles and websites; and from creator-data providers such as Modash, Apify, Bright Data, and CreatorDB/influencers.club.

If we receive information about you indirectly, the customer that supplied it is responsible for having authority to do so. Where GDPR Article 14 or similar law requires TLNTConnect to provide an indirect-collection notice, this policy describes the categories, sources, purposes, recipients, and rights that apply.

How And Why We Use Information

  • Perform a contract and provide requested features, accounts, workspaces, portals, collaboration, provider connections, support, and communications.
  • Pursue legitimate interests in securing, debugging, measuring, and improving the service; preventing fraud and abuse; maintaining auditability; and operating the business, balanced against individual rights.
  • Comply with legal, tax, accounting, security, sanctions, and law-enforcement obligations and establish or defend legal claims.
  • Use consent where required for optional provider access, sensitive information, marketing, or other processing that cannot rely on another legal basis. Consent may be withdrawn prospectively.

Legal Bases For EEA And UK Processing

Where the GDPR or UK GDPR applies, our Legal Bases are performance of a contract, legitimate interests described above, compliance with legal obligations, and consent where required. We do not rely on consent when it is not freely given or where another basis is more appropriate.

Connected Providers, QuickBooks, Google, And AI

An authorized admin may connect QuickBooks Online. We may process realm ID and company identifiers, customers, items, accounts, tax settings, invoices, balances, payments, sync tokens, transaction identifiers, and errors only for the agency-directed accounting workflow. We do not sell QuickBooks data or use QuickBooks Online Data for advertising, credit eligibility, consumer reporting, or unrelated brokerage.

For Gmail features, Google user data may include mailbox identifiers, messages, body text, snippets, headers, participants, provider message and thread identifiers, attachment metadata, raw provider metadata, send state, and provider events. Requested Gmail permissions may include gmail.modify and gmail.send. YouTube connections may request youtube.readonly and yt-analytics.readonly. Our use and transfer of Google user data is limited to user-requested features consistent with the Google API Services User Data Policy and Google Limited Use requirements.

Atlas AI may send prompts, selected workspace context, and tool results to OpenAI or another disclosed AI subprocessor to generate responses. We do not permit an AI provider to use Customer Data to train generalized models unless a customer expressly opts into a separately disclosed program. AI output can be incomplete or inaccurate and should be reviewed before consequential use.

Connected Social Accounts

A creator may authorize TLNTConnect to read data from the creator's Instagram, TikTok, or YouTube account. Instagram data may include profile identifiers and profile fields, follower and media counts, recent-media captions, links, thumbnails, timestamps, likes and comments, media and account insights such as views, reach, interactions, shares, saves, replies, follows, and profile-link taps, and aggregate follower demographics when Meta makes those reports available. TikTok data may include OpenID, profile and avatar fields, follower, following, like, and video counts, and authorized recent-video metadata and engagement statistics such as views, likes, comments, and shares. YouTube data may include channel identity and profile fields, subscriber, channel-view, and video counts, recent-video titles, links, thumbnails, publication times, views, likes, and comments, and YouTube Analytics reports such as views, likes, comments, shares, watch time, average view duration, subscriber gains and losses, and aggregate audience age, gender, and country percentages when Google makes those reports available.

We use connected-social data to verify the creator's platform identity; create, populate, and refresh the creator's TLNTConnect profile; calculate and display performance and engagement metrics; and provide creator-authorized analytics to the creator and the creator's authorized agency workspace. Authorized workspace users may include selected metrics in customer-directed portals, media kits, reports, or tokenized share links. The current connected-social feature uses read-only permissions and does not publish, edit, or delete social-platform content on the creator's behalf.

We store provider account and channel identifiers, granted scopes and expiration metadata, synchronized profile and performance metrics, and selected recent-content metadata used by the visible product features. We store OAuth access and refresh tokens, where the provider issues them, in encrypted form on the server and do not expose them to agency users, creators, public links, or client-side application code. We do not collect a creator's Instagram, TikTok, YouTube, or Google password.

Disconnecting a social account clears its stored OAuth access and refresh tokens from the active connection and stops future first-party API synchronization. A creator may also revoke TLNTConnect in the connected platform's account settings. Previously synchronized social-account data may remain in the workspace as historical profile, reporting, audit, or customer-directed share data after disconnect. A creator may request deletion of that data through the Privacy Request Center or by emailing privacy@tlntconnect.com, subject to documented legal-hold, security, and backup exceptions.

We do not sell connected-social data, use it for cross-context behavioral advertising or targeted advertising, or disclose it to data brokers. We disclose it only as described in this policy, including to the authorizing creator, authorized workspace users and customer-directed recipients, service providers that operate the requested feature, a connected service at the user's direction, or when required for security or law.

How We Disclose Information

We disclose information to authorized workspace members and recipients of customer-directed portals or tokenized links; to subprocessors that provide hosting, database, authentication, email, provider connectivity, AI, payments, support, and security; to third-party services a user directs us to connect; and when required for legal process, safety, fraud prevention, financing, merger, or acquisition.

Our current named providers and their roles are maintained on the Subprocessors page. Providers must process information under applicable contractual restrictions, although a connected third-party service may act under its own privacy policy for data it receives directly.

Cookies, Local Storage, Do Not Track, And Global Privacy Control

We use authentication and security cookies and local or session storage for sign-in, routing, theme, sidebar, and workflow preferences. We do not currently use third-party advertising cookies or cross-context behavioral advertising trackers.

Because there is no uniform industry response to browser Do Not Track signals, TLNTConnect does not respond to DNT. We do not currently sell or share personal information for behavioral advertising, so a Global Privacy Control signal does not change that processing. If those practices change, we will provide required controls and honor supported universal opt-out signals where law requires.

Authentication, hosting, connected-provider, and security vendors may collect request or device information while acting for us. Other parties do not have permission from TLNTConnect to track users across unrelated websites for their own advertising through our service.

Retention And Deletion

Our retention schedule uses the shortest period reasonably necessary for each purpose. Account and workspace data is retained while the account is active and for a limited wind-down period; mailbox and provider content is retained while the connection or feature requires it; security logs are retained for investigation and audit needs; financial, acceptance, and transaction records are retained for applicable legal and accounting periods; privacy-request evidence is retained to demonstrate compliance; and backups expire through normal rotation.

We consider account status, customer instructions, feature need, data sensitivity, contractual commitments, limitation periods, tax/accounting rules, security needs, backup cycles, and legal holds. When a period ends, information is deleted or de-identified. Legal holds and records needed to establish or defend claims override ordinary deletion until released.

Disconnecting a provider stops new API access after revocation where supported. Historical accounting references, audit events, and minimal security records may remain when necessary. When requested, we delete locally stored Gmail message content, including body text, snippets, headers, participants, provider message and thread identifiers, attachment metadata, raw provider metadata, queued provider events, and sync jobs unless a documented legal-hold or security exception applies.

State Privacy Rights

Depending on residence and legal applicability, individuals may request access, correction, deletion, portability, a list of third-party categories, or confirmation of processing, and may opt out of sale, targeted advertising, or qualifying profiling. We do not discriminate for exercising a privacy right.

Submit a request through our Privacy Request Center or email privacy@tlntconnect.com. We will verify the request proportionately, respond within the legally required period, and explain any denial. If we deny a request, the response will describe how to appeal. Appeals may be submitted through the same center by selecting Appeals.

An Authorized Agent may submit a request where law permits. We may require signed authorization, verification of the individual's identity, and direct confirmation unless a valid power of attorney applies.

EEA, UK, And International Rights

Where applicable, individuals may request access, rectification, erasure, restriction, portability, or objection; withdraw consent; and complain to the supervisory authority in their country. Individuals also have rights concerning solely automated decisions that produce legal or similarly significant effects. TLNTConnect does not currently make such decisions about individuals solely by automated means.

Information may be processed in the United States and other provider locations. Where required, transfers rely on adequacy decisions, the European Commission Standard Contractual Clauses, the UK Addendum, or another lawful mechanism, supplemented by technical and organizational safeguards as appropriate.

Security And Incident Response

We use tenant scoping, role and token checks, encryption or provider-managed secret storage, audit logging, access controls, and incident procedures designed to protect information. No system is perfectly secure. If a qualifying breach occurs, we will notify affected parties and regulators as required by applicable law.

Children And Minor Creators

TLNTConnect accounts are for people at least 18 years old. The service is not directed to children under 13. Agencies may maintain business records about minor creators only when they have lawful authority, give required notices, obtain required parent or guardian consent, and avoid entering unnecessary sensitive information. Contact us if you believe a child's information was submitted without proper authority.

Changes To This Policy

We will post updated versions with a new effective date and retain version history. We will provide additional notice before a material change when required. Material changes apply prospectively unless law permits and we clearly disclose otherwise.

Contact

Tlnt Connect LLC, 611 South Dupont Highway, Dover, DE 19901. Privacy requests: privacy@tlntconnect.com. Security reports: security@tlntconnect.com. General support: support@tlntconnect.com.