CC Club – Privacy Policy
Last updated: 19 September 2026
This Privacy Policy applies to the CC Club mobile app (available on the App Store and Google Play) and its website — together, “CC Club” or the “Service”. CC Club is operated by Rádi Software Solutions & Consulting Kft. Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Hungarian law.
1. Data controller
The data controller is:
- Company: Rádi Software Solutions & Consulting Kft.
- Registered seat: 1074 Budapest, Rákóczi út 82. 3. em. 11. ajtó
- Tax number: 32709186-2-42
- Company registration number: 01 09 438553
- Contact person: Rádi Kristóf
- Email: [email protected]
We are not required to appoint a Data Protection Officer and have not done so. For any privacy matter, please contact us at the email above.
2. Who this policy applies to
This policy applies to all users of the platform:
- Brands (clients): businesses and their representatives who create and fund campaigns;
- Creators: individuals who produce content through the mobile app and receive payouts;
- Visitors: people who use the public website or the waitlist.
3. Categories of personal data
In providing the service we process the following categories of data:
- Account data: email address, phone number, display name, password (stored in encrypted form by Firebase Authentication), user role (brand/creator/administrator);
- Profile data: profile picture, bio, language and notification preferences;
- Connected social account data: TikTok and Instagram username (@handle), profile picture, follower count, verified status, biography, and the statistics of submitted and public content (view, like, comment and share counts, reach);
- Campaign and content data: links and identifiers of submitted videos, performance metrics, leaderboard ranking, applications and their status;
- Financial data – brands: billing name and address, tax number, and the customer identifier held at the payment provider (Stripe). We do not see or store full card details;
- Financial data – creators: bank details required for payout (IBAN, account holder name), tax number (for self-billing and statutory withholding), and records of amounts earned and paid;
- Technical data: device identifiers, push notification tokens (FCM), log data, limited diagnostic data;
- Communications: messages exchanged with support and in relation to payouts.
We do not collect special (sensitive) categories of data. Please do not include such data in your submissions or messages.
4. Purposes and legal bases
The following GDPR legal bases apply to our processing:
- Creating an account and providing the service (campaigns, applications, content submission, leaderboards) — basis: performance of a contract [Art. 6(1)(b)];
- Processing payouts and collecting the brand fee — basis: performance of a contract and compliance with accounting obligations [Art. 6(1)(b) and (c)];
- Connecting social accounts and measuring content performance — basis: performance of a contract and your explicit consent when connecting the account [Art. 6(1)(a) and (b)];
- Sending transactional and system notifications (email and push) — basis: performance of a contract [Art. 6(1)(b)];
- Fraud prevention, verifying the authenticity of views, and platform security — basis: legitimate interest [Art. 6(1)(f)];
- Marketing communications and the waitlist newsletter — basis: your consent [Art. 6(1)(a)], which you may withdraw at any time;
- Establishing legal claims and complying with legal obligations — basis: legitimate interest and legal obligation [Art. 6(1)(f) and (c)].
6. Processors and recipients
We use the following processors to operate the service, under agreements that ensure lawful processing:
- Google Ireland Ltd. / Google LLC (Firebase) — cloud infrastructure: authentication, database (Firestore), server-side functions and push notifications (FCM);
- Google Ireland Ltd. / Google LLC (Google Analytics / Firebase Analytics) — aggregated, statistical measurement of how the website and app are used, only where you have consented;
- Cloudinary Ltd. — storage and delivery of uploaded images and videos, and access-controlled storage of invoice documents;
- Stripe Payments Europe Ltd. — processing brand payments (platform fee and campaign settlement);
- Számlázz.hu (KBOSS.hu Kft.) — issuing invoices to brands and self-billed invoices for creator payouts; invoice data is reported to the Hungarian tax authority (NAV Online Számla) as required by law;
- Wise Europe SA — processing creator payout transfers;
- Resend (Plus Five Five, Inc.) — delivery of transactional and informational emails;
- TikTok Technology Ltd. and Meta Platforms Ireland Ltd. — connecting social accounts and retrieving content statistics (only for the account you connect).
Some providers may process data outside the European Economic Area (e.g. in the United States). Where this occurs, the transfer is based on appropriate safeguards under the GDPR (e.g. the European Commission’s Standard Contractual Clauses or an adequacy decision).
By the nature of the platform, brands can access the public profile data and content performance of applicants and creators participating in their campaigns. Brands cannot see creators’ bank details.
Disclosures required by law and for enforcing claims: we disclose invoice, payout and withholding data to the Hungarian tax authority (NAV) as required by tax law, including — where CC Club qualifies as a reporting platform operator — the annual reporting of creators’ identification data, tax number, bank account identifier and the consideration paid to them under the DAC7 rules (Act XXXVII of 2013). If a brand fails to pay for a campaign, we may disclose the brand’s identifying and campaign data to the creators concerned, and to a debt-collection provider or legal adviser, to the extent necessary to enforce the claim (legitimate interest).
7. Retention periods
- Account and profile data are kept for the life of the account and deleted or anonymised within a reasonable time after an erasure request or account closure;
- Accounting documents (e.g. fee payments, payouts) are retained for 8 years under Act C of 2000 on Accounting;
- Fraud-prevention and security logs are kept for as long as necessary for that purpose;
- Data processed on the basis of consent (e.g. newsletter) are kept until you withdraw consent.
8. Your rights
You have the following rights regarding your personal data:
- access to your processed data;
- rectification of inaccurate data;
- erasure (the “right to be forgotten”), within the limits of statutory retention obligations;
- restriction of processing;
- data portability (data you provided, in a machine-readable format);
- objection to processing based on legitimate interest;
- withdrawal of consent at any time, without affecting processing carried out before withdrawal.
To exercise your rights, write to [email protected]. We respond without undue delay and at the latest within one month.
9. Data security
We apply appropriate technical and organisational measures to protect data: encrypted transmission (TLS), access controls, server-side authorisation rules, and — for payment data — the PCI-DSS compliance of our specialised provider (Stripe). Our systems do not store full card details.
11. Minors
The service is intended for persons aged 18 or over. We do not knowingly process the data of persons under 18. If we become aware that such data has entered our systems, we delete it without delay.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes on the platform or by email. The current version is always available on this page, with the update date shown above.
14. Remedies
If you believe our processing infringes your rights, please contact us first. You may also lodge a complaint with the supervisory authority or a court:
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11.; mailing address: 1363 Budapest, Pf. 9.; email: [email protected]; web: www.naih.hu;
- the competent court of your place of residence or stay.
See also
Terms of Service
5. Connecting social accounts
Creators may connect their accounts through the official OAuth flow of TikTok and Instagram (Meta). During this process you grant access on the social platform’s own screen; we never see your password. We request only the data necessary for the service (profile data and content performance metrics).
You can revoke access at any time by disconnecting the account in the app, or via your TikTok/Instagram account settings. After disconnection we no longer retrieve further data.