Privacy Policy
Last updated: 28 June 2026
1. Who We Are
Nova Drop (novadrop.lk) is a UGC and influencer marketplace connecting Sri Lankan brands with content creators.
Contact: dwaynedehoedt@gmail.com
2. What Data We Collect
- Full name and email address
- Profile photo via Google OAuth
- Social media handles and portfolio links
- Payment information (bank transfer references and payslip documents)
- Brief details, submissions, and campaign content
- Social media analytics data (follower count, engagement rate, video metrics, audience demographics) when a creator voluntarily connects their social media account
- OAuth access tokens from connected social media platforms (stored securely, never shared)
3. How We Use Your Data
- To create and manage your account
- To facilitate transactions between brands and creators
- To send transactional emails (invoices, payment confirmations, notifications)
- To improve the platform
- To display creator analytics to brands for the purpose of campaign matching
- To verify creator metrics through connected social media accounts
4. Cookies We Use
Nova Drop uses only strictly necessary cookies required for the platform to function. We do not use tracking, advertising, or analytics cookies.
The following cookies are set automatically when you log in:
These cookies are set by Supabase, our authentication provider. They contain no personal data other than an encrypted session identifier. You cannot opt out of these cookies as they are required for the platform to function.
5. Third-Party Social Media Connections
Creators may optionally connect social media accounts including TikTok, Instagram, YouTube, and Facebook to their Nova Drop profile.
When you connect a social media account:
- We access only read-only analytics data including follower count, engagement rate, video performance metrics, and audience demographics
- We never access, read, or store your private messages or DMs
- We never post, publish, or modify content on your behalf
- We never store your social media passwords
- Connections are made via each platform's official OAuth 2.0 flow
- Your analytics data is displayed to brands on Nova Drop solely for campaign matching purposes
- We do not sell this data to any third party
You can disconnect any connected social media account at any time from your account settings. Disconnecting immediately revokes Nova Drop's access to that platform's data.
6. Data Storage
Your data is stored securely on Supabase (PostgreSQL database) hosted on AWS. Campaign videos and payment documents are stored on Google Drive.
7. Sharing Your Data
We do not sell your data to third parties.
We share data only with:
- Supabase (authentication and database)
- Google Drive (file storage)
- Resend (transactional email delivery)
- TikTok (when creator connects their TikTok account via OAuth)
- Meta/Instagram (when creator connects their Instagram or Facebook account via OAuth)
- Google/YouTube (when creator connects their YouTube account via OAuth)
8. Your Rights (Sri Lanka PDPA)
Under Sri Lanka's Personal Data Protection Act:
- Right to access your personal data
- Right to correct inaccurate data
- Right to withdraw consent
- Right to request deletion of your data
Contact dwaynedehoedt@gmail.com to exercise any of these rights.
9. Changes to This Policy
We may update this policy. We will notify you by email of any significant changes.