Privacy Policy

Last updated: August 31, 2026

1. Overview

CreativeWork AS operates CreativeWork, a Norway-first marketplace for booking creative services. This Privacy Policy explains how we process personal information needed to provide accounts and profiles, operate marketplace services, manage bookings, facilitate payments, support communication, handle support and disputes, and secure the service.

It should be read with the Terms of Service, Cookie Policy, Rights & Usage, and Payments & Disputes.

2. Who This Policy Applies To

This policy applies to clients, creators, and other people who use CreativeWork, visit public pages, or send us a contact request.

It covers information CreativeWork processes. Some information is collected directly by third-party providers such as Stripe or Firebase when you use their services.

3. Information You Provide

Depending on how you use CreativeWork, you may provide:

  • account details, such as email, username, and profile name
  • profile and creator information, such as bio, expertise tags, service areas, social links, and images
  • service-listing and portfolio content
  • booking and project information
  • messages, reviews, ratings, and reports
  • support or contact requests
  • uploaded files and images

Not all fields are required. Optional profile and creator details can be left blank.

4. Account and Profile Information

When you create or manage an account, CreativeWork may process:

  • email address, and a pending email address if you request a change
  • username and profile name
  • avatar and banner images
  • country and currency settings
  • account status, including verification, active or deleted state, and whether the account is a creator account
  • a Google / Firebase identifier if you sign in or link Google
  • notification preferences
  • saved services or creators (bookmarks)

CreativeWork does not currently collect or store phone numbers as part of your account.

5. Creator and Service Information

If you use CreativeWork as a creator, you may also provide:

  • creator roles
  • service areas
  • bio, expertise tags, and social links
  • service listings, including title, description, price, duration, location, cover image, add-ons, and whether Drop-in is offered
  • portfolio items and related media

CreativeWork may store Stripe connected-account identifiers and onboarding-completion status. Identity, business, and bank details required for payouts are provided to Stripe, not stored by CreativeWork as full KYC or bank documents.

6. Booking and Project Information

When users create or manage a booking, CreativeWork may process:

  • service, date and time, and location
  • whether the request is Drop-in
  • project description and selected add-ons
  • reference materials attached to the booking, if any
  • booking status, creator response deadline, and delivery notes or status
  • cancellation, refund, dispute, and completion information
  • payment-schedule and payment-status metadata

Booking records are shared with the client and creator on that booking. They are not published as a public listing.

7. Messages, Reviews and Support

CreativeWork stores messages needed to provide chat and booking communication, including system and booking-status messages, reactions, read state, mute or archive state, and block state.

Chat may include file attachments. If you delete a message, it is hidden from ordinary chat display. The original content may remain in CreativeWork records for authorized dispute, safety, or trust-and-safety review.

Reviews and ratings are associated with platform activity and may include the reviewer’s username, profile name, and avatar. Reports and dispute information may be reviewed to resolve issues and enforce platform rules.

Contact requests submitted through the Contact page include name, email, inquiry type, and message. CreativeWork stores those submissions and may email them to the operational support inbox.

8. Payment Information

Payments are processed through Stripe. Details are in Payments & Disputes.

CreativeWork may store or process payment-related identifiers and records such as:

  • Stripe customer and connected-account IDs
  • payment-method identifiers and limited card metadata returned by Stripe, such as brand and last four digits
  • Stripe payment IDs and related identifiers used to operate checkout and charges
  • amounts, currency, payment reason, and payment or refund status
  • payout-status metadata and related Stripe transfer or payout identifiers
  • receipt and payment-history records

CreativeWork does not store full card numbers, CVC codes, or creator bank or KYC documents. Those are handled by Stripe.

9. Files, Images and Other Content

Users may upload profile avatars and banners, service cover images, portfolio media, chat attachments, and other files used on the platform.

Uploaded files are stored on CreativeWork’s hosting and storage infrastructure so they can be displayed or transmitted through the service. Ownership and permitted use of content are described in Rights & Usage. Uploading content does not transfer ownership to CreativeWork.

10. Information Collected Automatically

CreativeWork may process limited technical information to operate and secure the service, including:

  • IP address, used for rate limiting, security, and service operation
  • timestamps and request or error logs, such as request path and status
  • session and authentication storage, including the access_token cookie and Firebase Authentication browser storage
  • first-party preferences stored in localStorage, such as display currency, analytics-consent choice, saved-item cache, and chat sound preference

On some public pages, if you have not already chosen a display currency, your browser may request an approximate country from a third-party IP lookup (ipapi.co) so prices can be shown in a relevant currency. That request is not analytics.

CreativeWork does not operate device fingerprinting or precise location tracking.

11. How We Use Information

CreativeWork uses information to:

  • create and manage accounts
  • display profiles and services
  • facilitate bookings and related records
  • enable messages and notifications
  • process and facilitate payments through Stripe
  • provide support and resolve disputes
  • prevent fraud and security abuse
  • enforce the Terms
  • maintain, debug, and operate the service
  • send service and account updates, subject to your notification preferences where those controls apply
  • understand platform use through optional analytics where configured and accepted

12. Legal / Operational Reasons for Processing

Where data-protection law applies, CreativeWork typically processes information because it is needed to provide the service you request, because CreativeWork has a legitimate interest in operating and securing the marketplace, because a legal obligation applies, or because you have given consent — for example optional Google Analytics.

Not every reason applies to every piece of information.

13. How Information Is Shared

CreativeWork does not sell personal data.

Other users

Information needed for a booking, message, review, or dispute may be shared with the other party. Username, profile name, and avatar may be visible to other users in those contexts.

Public pages

Creator profile, service, portfolio, and some review information may be visible as described in section 18.

Service providers

Information may be processed by providers that help operate CreativeWork, including Stripe, Firebase / Google Authentication, hosting and storage infrastructure, and Google Analytics when configured and accepted.

Legal and safety

Information may be disclosed where required by law or reasonably necessary to prevent fraud, enforce the Terms, or protect users or the platform.

14. Stripe and Payment Providers

Stripe processes payments, saved payment methods, payouts, and creator onboarding. Creators may provide identity, business, and bank information directly to Stripe as part of Connect onboarding.

Stripe processes that information under its own terms and privacy policy. CreativeWork receives identifiers, status, and limited metadata needed to operate bookings and payouts.

15. Authentication Providers

Accounts may be created or verified with email or Google sign-in through Firebase Authentication. Firebase / Google may process authentication data to keep you signed in and verify your identity.

CreativeWork stores the related account email and, if used, a Google identifier. Session tokens are stored in an httpOnly cookie named access_token, normally for 7 days.

16. Hosting and Infrastructure Providers

CreativeWork uses hosting, storage, and other technical infrastructure to run the application, store uploaded files, send email, and keep the service available. Those providers may process information on CreativeWork’s behalf as needed to provide their services.

17. Analytics and Cookies

Essential cookies and storage are used for sign-in, security, payments, and requested preferences. When Google Analytics is configured for the environment you are using, it loads only after you accept. CreativeWork currently uses Google Analytics only for usage measurement, not advertising, remarketing, or ads personalization.

You can Accept or Decline analytics, and later change that choice using Cookie settings in the public footer. Details are in the Cookie Policy.

18. Public Information

Creator profiles, service listings, portfolio items, and some reviews are designed to be public. Visitors who are not signed in may be able to view them. Public creator information may include profile name, username, avatar, banner, bio, expertise tags, service areas, roles, social links, services, portfolio, and ratings.

Client accounts do not have the same public marketplace profile unless the user also has a creator profile. A client’s email, payment identifiers, and private account settings are not treated as public profile content.

Username, profile name, and avatar may still appear to other users in bookings, messages, reviews, or search.

19. Data Retention

CreativeWork keeps information for as long as reasonably necessary to operate the account and service, complete bookings, maintain payment and accounting records, resolve disputes, prevent fraud or security abuse, and comply with legal obligations.

CreativeWork does not publish a single retention period for every category. Public profile and service content is removed from ordinary public use when deleted or when an account is closed, subject to backups and records described below.

20. Account Deletion

You can deactivate or delete your account from Settings.

Deactivation stops ordinary use of the account. Deletion goes further:

  • the account is marked deleted and deactivated
  • display profile information is removed, including name, bio, images, social links, roles, and service areas
  • services, portfolio items, and related uploaded files are removed where possible
  • username is released so another user may claim it
  • email is retained so it cannot be used to create a new account
  • booking records associated with the account are removed from ordinary platform use
  • payment and transaction records are retained as financial records and detached from the deleted account
  • reviews may be retained in anonymized form
  • chat memberships and messages you sent are removed

CreativeWork also requests deletion of the related Stripe customer or connected account and Firebase authentication user where applicable. An account cannot be deleted while a connected Stripe account has pending or available funds.

Deletion from public display does not immediately remove backups, payment records, anonymized reviews, or records CreativeWork must keep for disputes, fraud, security, accounting, or law.

21. Security

CreativeWork uses authentication, access controls, HTTPS/TLS for data in transit, Stripe for payment-card handling, and infrastructure providers to help protect the service. Account and security events may be monitored where those controls are in place.

No system is completely secure. CreativeWork does not claim absolute security, independent security certifications, or end-to-end encryption of messages or files.

22. International Processing

CreativeWork is Norway-based. Authentication, payment, analytics, email, and hosting providers may process information in other countries according to their own infrastructure and safeguards.

This policy does not describe a specific legal transfer mechanism beyond the use of those providers to operate the service.

23. Your Privacy Rights

Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Not every right applies in every circumstance.

You can update much of your account and profile information in Settings. Analytics consent can be changed using Cookie settings in the public footer. For other privacy requests, use the Contact page and choose Customer support, or email privacy@creativework.com.

24. Children / Age Requirements

The Terms of Service do not currently set a published minimum age. You must be able to use CreativeWork lawfully and provide accurate account information.

CreativeWork does not knowingly collect personal data from children where that is not permitted. If you believe a child has provided personal data, contact us.

25. Changes to This Policy

CreativeWork may update this policy. Material changes apply prospectively, subject to applicable law. Significant changes may be communicated through the platform or by email.

26. Contact

For privacy questions or requests, use the Contact page and choose Customer support, or email privacy@creativework.com.