Privacy Policy
Your privacy matters to us. This policy explains how Odiwave Media collects, uses, and protects your information.
Our Commitment to Your Privacy
Odiwave Media ("we", "us", "our"), operated by Uplinemind Digital Services Pvt. Ltd., is committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, and share information when you use our platform at odiwavemedia.com and related services.
Information We Collect
Personal Information You Provide
- Account Registration: Full name, email address, phone number, city, and profile photo when you register as a creator.
- Social Media Profiles: YouTube, Instagram, Facebook, Twitter, and LinkedIn URLs and follower counts you voluntarily provide.
- Payment Information: Bank account details (account number, IFSC code, bank name) for processing creator payouts.
- Agreement Data: Digital signatures and full legal name when signing our creator representation agreement.
- Content Niche: Your content category/niche for brand matching purposes.
Information Collected Automatically
- Log Data: IP address, browser type, device information, pages visited, and timestamps.
- Cookies: Session cookies for authentication and functionality (see Cookies section).
- Activity Logs: Actions performed on the platform such as project acceptance, status changes, and payment events.
How We Use Your Information
We use the information we collect to:
Match Creators with Brands
Your profile, niche, and follower data help us connect you with relevant brand partnerships.
Process Payments
Bank details are used exclusively for processing your creator payouts securely.
Communications
Send project offers, payment notifications, status updates, and platform announcements.
Platform Improvement
Analyze usage patterns to improve our services, fix issues, and enhance user experience.
Gmail API & Email Access
Our platform integrates with Google's Gmail API to facilitate brand communications on behalf of creators. This section specifically addresses how we handle Gmail data:
What We Access
- Gmail Send (gmail.send): We send emails to brands on your behalf using your authorized Gmail account.
- Gmail Read (gmail.readonly): We read email metadata (sender, subject, date) and snippets to display brand conversation threads in your dashboard.
How Gmail Data Is Used
- Emails are sent only to brand contacts as directed by the admin for creator-brand communications.
- Email reading is limited to conversations with specific brand email addresses — we never browse your entire inbox.
- Gmail data is displayed in real-time and not stored permanently on our servers beyond email metadata logged for our records.
Authorization & Revocation
- Gmail access requires explicit authorization through Google's OAuth 2.0 consent screen.
- You can revoke access at any time from your Creator Dashboard (My Profile) or from your Google Account permissions page.
- Revoking access immediately stops all Gmail operations and deletes stored tokens.
Our use of Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, market research, or any purpose unrelated to the core functionality described above.
Data Sharing & Disclosure
We do not sell your personal information. We may share data in the following limited circumstances:
- With Brand Partners: Your public profile information (name, niche, social links, follower counts) is shared with brands for partnership matching. Bank details are never shared with brands.
- Service Providers: Trusted third-party services for email delivery, hosting, and analytics that process data on our behalf under strict confidentiality agreements.
- Legal Requirements: When required by law, regulation, legal process, or government request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: All data transmission uses SSL/TLS encryption (HTTPS).
- Token Security: OAuth tokens are stored securely in the database and refreshed automatically. Sensitive credentials are never exposed in client-side code.
- Access Control: Administrative access is restricted to authorized personnel only.
- Bank Details: Account numbers are masked in the UI and only revealed when explicitly requested.
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We encourage you to use strong passwords and safeguard your account credentials.
Cookies & Tracking
We use cookies for the following purposes:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session management, security (CSRF tokens) | Session |
| Functional | Remember preferences, dashboard settings | 30 days |
We do not use third-party advertising or tracking cookies.
Data Retention
- Account Data: Retained as long as your account is active. Deleted upon account closure request.
- Project & Payment Records: Retained for 7 years for tax and legal compliance as required by Indian law.
- Gmail Tokens: Stored only while authorization is active. Immediately deleted upon revocation.
- Activity Logs: Retained for 1 year for auditing purposes, then automatically purged.
Your Rights
You have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you.
Correction
Update or correct inaccurate personal information.
Deletion
Request deletion of your account and associated data.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing of your data for specific purposes.
Revoke Consent
Withdraw Gmail or other authorizations at any time.
To exercise any of these rights, contact us at privacy@odiwavemedia.com.
Third-Party Services
Our platform integrates with or links to the following third-party services, each governed by their own privacy policies:
- Google (Gmail API): For email communications — Google Privacy Policy
- YouTube, Instagram, Facebook: Social profile verification — governed by respective platform policies.
- Web Hosting: Hostinger — for server infrastructure and data storage.
Children's Privacy
Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we discover that we have collected data from a child under 18, we will promptly delete it. If you believe a minor has provided us with personal information, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this page.
- Notify registered users via email for material changes.
- Display a notice on the platform dashboard.
Your continued use of the platform after changes constitutes acceptance of the updated policy.
Contact Us
For any privacy-related questions, concerns, or data requests, please reach out to us: