DiscoCollabsBack to log in

Privacy Policy

Last updated September 9, 2026

DiscoCollabs is a creator-marketing platform operated by Quorra Agency (“we”, “us”). This policy explains what we collect, why, who we share it with, and the choices you have — whether you are a merchant running a creator program or a creator interacting with one. Questions any time: cayla@quorra.agency.

1. The two roles we serve

  • Merchants — for merchant account and workspace data, we are the data controller.
  • Creators — creator data lives in a merchant’s workspace; the merchant is the controller and we process it on their instructions. Creators can contact their merchant directly, or us, about their data.

2. Data we collect

Merchant account and store data: name, work email, hashed authentication credentials (via Supabase Auth), workspace settings, Shopify store domain, products, qualifying order and fulfillment metadata, and billing status; plus Slack and Discord workspace identifiers you choose to connect. For eligible creator orders, the Shopify buyer email is transformed into a tenant-scoped HMAC and masked hint before event storage. The associated customer identifier is used to prevent erased data from being recreated by order replays. Inbound order-event storage excludes raw buyer email, name, phone, and shipping address. Merchant-managed roster contacts are separate records and can contain email addresses, including historical contacts added from tagged orders. New order tagging does not import buyer emails into the roster.

Creator data (processed for the merchant): profiles and creator-provided contact details, including the verified email used for their private account and reminders; social handles and optional connected-platform IDs; limited shipping details only when needed for a gift or return label; submitted content, usage-rights records, and campaign history. A creator-provided email is stored because it powers their account, communications, and safe matching to the tenant-scoped order identifier described above.

Discord authorization (creator-initiated): when a creator opens a brand’s join link and chooses Connect Discord, they authorize DiscoCollabs on their own Discord account with two permissions: identify (their Discord user ID and username, which we store to link them to that brand’s orders) and guilds.join, which we use once — to add them to that brand’s Discord server. We do not read their messages, their other servers, or their email through this authorization, and we never use it to join them to any server other than the one whose link they opened. A creator can revoke it at any time in Discord → Settings → Authorized Apps, and can leave the server independently of that.

Technical data: logs, device and usage information needed to secure and operate the Service. We never log passwords or session credentials.

3. How we use data

  • running gifting and content workflows;
  • orchestrating the platforms you connect (including Shopify, Discord, Slack, TikTok, and shipping providers) on your instructions;
  • securing accounts, preventing abuse, and debugging;
  • service communications (we do not sell personal data, and we do not use creator data for our own marketing).

4. Subprocessors and sharing

We share data only with the platforms that make the Service work, each under their own security and privacy commitments:

SubprocessorWhat it does for the Service
SupabaseDatabase, authentication, and storage for workspace data
RailwayApplication hosting and infrastructure
Cloudflare R2Object storage for creator content and encrypted files
ResendTransactional creator and merchant email delivery
ShopifyCommerce platform data and managed app billing
DiscordOptional creator community automation and direct messages
SlackOperational notifications to the merchant's workspace
TikTokOptional creator account connection and content authorization
ShippoOptional return-label rating and purchase

We may also disclose data where the law requires it, or as part of a merger or acquisition with notice to you. We never sell personal data.

5. Retention

  • Workspace data is kept while the merchant’s account is active.
  • After account closure or uninstall, workspace data is deleted or anonymized within 90 days, except records we must keep for legal, tax, or dispute purposes.
  • Shopify-mandated redaction webhooks (customer and shop redact) are honored automatically.

6. Security

Data is encrypted in transit (TLS) and at rest. Sessions use signed, httpOnly cookies; access to production systems is restricted and logged. No system is perfectly secure — report concerns to cayla@quorra.agency and we will investigate promptly.

7. Your rights (GDPR, CCPA, and friends)

Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing, and to non-discrimination for exercising those rights. California residents may also request details of categories collected and disclosed; we do not sell or “share” personal information as the CCPA defines those terms. EU/UK residents may lodge a complaint with their supervisory authority.

  • Merchants: email cayla@quorra.agency from your workspace email and we will act within 30 days.
  • Creators: your merchant is the controller of your campaign data — start with them; contact us and we will route and support the request.

8. International transfers

We operate from the United States and our subprocessors may store data in the US or other regions. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

9. Children

The Service is for business use and not directed to anyone under 16. We do not knowingly collect children’s data; if you believe we have, contact us and we will delete it.

10. Changes to this policy

We will post updates here and, for material changes, notify merchants by email or in-product notice before they take effect. The “Last updated” date above always reflects the current version.

11. Contact

Quorra Agency (operator of DiscoCollabs) — cayla@quorra.agency.

See also our Terms of service, our Data Processing Agreement, and our Data Retention & Deletion page.