Privacy Policy
Last updated July 17, 2026
DiscoCollabs is a creator-marketing platform operated by Quorra Agency (“we”, “us”). This policy explains what we collect, why, who we share it with, and the choices you have — whether you are a merchant running a creator program or a creator interacting with one. Questions any time: cayla@quorra.agency.
1. The two roles we serve
- Merchants — for merchant account and workspace data, we are the data controller.
- Creators — creator data lives in a merchant’s workspace; the merchant is the controller and we process it on their instructions. Creators can contact their merchant directly, or us, about their data.
2. Data we collect
Merchant account and store data: name, work email, hashed authentication credentials (via Supabase Auth), workspace settings, Shopify store domain, products, orders, discount codes, and billing status; Slack and Discord workspace identifiers you connect.
Creator data (processed for the merchant): profiles and contact details, social handles and platform metrics, Discord IDs and server activity relevant to campaigns, shipping addresses for gifting, submitted content and usage-rights records, commission ledgers, and campaign history.
Discord authorization (creator-initiated): when a creator opens a brand’s join link and chooses Connect Discord, they authorize DiscoCollabs on their own Discord account with two permissions: identify (their Discord user ID and username, which we store to link them to that brand’s orders) and guilds.join, which we use once — to add them to that brand’s Discord server. We do not read their messages, their other servers, or their email through this authorization, and we never use it to join them to any server other than the one whose link they opened. A creator can revoke it at any time in Discord → Settings → Authorized Apps, and can leave the server independently of that.
Sensitive payout and tax data: creator PayPal email addresses, and IRS Form W-9 details collected for the merchant’s tax compliance. W-9 data is encrypted at rest and handled only on the merchant’s behalf — access is restricted to the merchant workspace it belongs to.
Technical data: logs, device and usage information needed to secure and operate the Service. We never log passwords or session credentials.
3. How we use data
- running gifting, content, quest, and commission workflows;
- orchestrating the platforms you connect (Shopify, Discord, PayPal, Slack) on your instructions;
- securing accounts, preventing abuse, and debugging;
- service communications (we do not sell personal data, and we do not use creator data for our own marketing).
4. Subprocessors and sharing
We share data only with the platforms that make the Service work, each under their own security and privacy commitments:
| Subprocessor | What it does for the Service |
|---|---|
| Supabase | Database, authentication, and storage for workspace data |
| Railway | Application hosting and infrastructure |
| Cloudflare R2 | Object storage for creator content and encrypted files |
| Slack | Operational notifications to the merchant's workspace |
| Discord | Creator community automation (roles, briefs, messages) |
| PayPal | Commission payouts initiated from the merchant's account |
| Shopify | Commerce platform data (store, products, orders, discounts) |
We may also disclose data where the law requires it, or as part of a merger or acquisition with notice to you. We never sell personal data.
5. Retention
- Workspace data is kept while the merchant’s account is active.
- After account closure or uninstall, workspace data is deleted or anonymized within 90 days, except records we must keep for legal, tax, or dispute purposes.
- Encrypted W-9 records follow the merchant’s retention obligations; merchants can request earlier deletion where the law allows.
- Shopify-mandated redaction webhooks (customer and shop redact) are honored automatically.
6. Security
Data is encrypted in transit (TLS) and at rest, with additional application-layer encryption for W-9 tax documents. Sessions use signed, httpOnly cookies; access to production systems is restricted and logged. No system is perfectly secure — report concerns to cayla@quorra.agency and we will investigate promptly.
7. Your rights (GDPR, CCPA, and friends)
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing, and to non-discrimination for exercising those rights. California residents may also request details of categories collected and disclosed; we do not sell or “share” personal information as the CCPA defines those terms. EU/UK residents may lodge a complaint with their supervisory authority.
- Merchants: email cayla@quorra.agency from your workspace email and we will act within 30 days.
- Creators: your merchant is the controller of your campaign data — start with them; contact us and we will route and support the request.
8. International transfers
We operate from the United States and our subprocessors may store data in the US or other regions. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
9. Children
The Service is for business use and not directed to anyone under 16. We do not knowingly collect children’s data; if you believe we have, contact us and we will delete it.
10. Changes to this policy
We will post updates here and, for material changes, notify merchants by email or in-product notice before they take effect. The “Last updated” date above always reflects the current version.
11. Contact
Quorra Agency (operator of DiscoCollabs) — cayla@quorra.agency.