Effective date: June 17, 2026
Who Operates Cravgen
Cravgen is operated by HASHMARK (PRIVATE) LIMITED ("we", "us", "our"). HASHMARK (PRIVATE) LIMITED provides the Cravgen software platform for influencer–brand collaboration, social publishing, analytics, automation, and lead engagement.
Marketing website: https://www.cravgen.com
Application: https://admin.cravgen.com
Company: HASHMARK (PRIVATE) LIMITED
This Privacy Policy describes how we collect, use, store, share, and delete information when you visit our website, create an account, connect social platforms, publish content, run campaigns, or use marketplace and automation features. By using Cravgen you agree to this policy and our Terms & Conditions.
1. Information We Collect
- Account data: name, email address, organization, role, login credentials, subscription and billing details you provide when registering or upgrading a plan.
- Connected social accounts: platform identifiers, Page or profile names, usernames, profile images, follower counts, permissions you grant, access tokens (stored securely), and metadata returned by platforms you authorize.
- Collaboration and influencer data: campaign briefs, creator profiles, marketplace listings, brand–creator communications, performance metrics, and eligibility information needed for collaborations you participate in.
- Content and campaign data: posts, captions, media, schedules, drafts, comments, insights, and lead-form submissions you create or import.
- Usage and technical data: IP address, device/browser type, logs, cookies, session identifiers, and product analytics used for security, reliability, and improvement.
- Communications: messages you send to our support team or through in-product contact flows.
2. Third-Party Platforms and APIs
Cravgen may access information from third-party platforms when you authorize integrations. We use this information solely to provide the functionality you request— not for unrelated advertising or resale.
Platforms we may connect to include:
- Meta (Facebook and Instagram)
- YouTube
- TikTok
- LinkedIn
- WhatsApp Business
- Google (where sign-in or maps features are enabled)
Each platform's own terms and privacy policies apply to your use of that platform. We only receive data that you (or your organization administrator) explicitly authorizes through OAuth or similar connection flows.
3. Meta Platform Data (Facebook & Instagram)
Because Cravgen is an influencer and brand collaboration platform, connecting Facebook or Instagram is optional and used for features you choose — such as campaign management, collaboration workflows, publishing, analytics, comment management, and automation.
When users connect their Facebook or Instagram accounts, Cravgen may access profile information, Pages, business or creator account information, permissions granted by the user, and related data necessary to provide campaign management, collaboration, analytics, and automation features. We do not use Meta Platform Data for purposes unrelated to these features.
Permissions we request and why:
- public_profile: Identify your connected Facebook personal account (name and profile picture) and associate Facebook Pages and Instagram accounts with the correct Cravgen user.
- pages_show_list: List Facebook Pages you manage so you can choose which Page to connect to Cravgen.
- pages_manage_posts: Publish posts, images, and videos to Facebook Pages you authorize, including scheduled and AI-assisted publishing workflows.
- pages_read_engagement, pages_read_user_content: Read Page engagement metrics, comments on Facebook posts published through Cravgen, and related content needed to display performance analytics, Timeline comment threads, and publishing status in Cravgen.
- instagram_basic: Access Instagram Business/Creator profile information (username, profile picture, account identifiers) for connected accounts.
- instagram_content_publish: Publish photos, reels, stories, and other media to Instagram accounts you connect and authorize.
- instagram_manage_comments: Read and reply to comments on Instagram content published through Cravgen, including the Timeline comments panel (with optional real-time webhook updates or periodic API sync, depending on your settings).
- instagram_manage_insights: Retrieve Instagram insights and follower metrics to power analytics dashboards and campaign reporting.
We do not sell Meta Platform Data. We do not use it to build unrelated user profiles for third-party advertising. Access is limited to personnel and subprocessors who need it to operate the service under confidentiality obligations, in compliance with Meta Platform Terms.
4. TikTok Platform Data
When you connect your TikTok account to Cravgen, we access information from TikTok only with your explicit authorization through TikTok Login Kit and Content Posting API. We use this data solely to provide features you choose — such as account connection, profile display, analytics, and publishing videos you create or schedule in Cravgen.
We do not read individual TikTok comment text, direct messages, or private account content through our integration. Comment counts shown in Cravgen come from aggregate video insights where available.
Permissions we request and why:
- user.info.basic: Identify your connected TikTok account (open ID, avatar, and display name) and associate it with the correct Cravgen user on the Connections page.
- user.info.profile: Read your TikTok username, bio description, profile links, and verified status to display your connected account profile in Cravgen.
- user.info.stats: Read follower count, following count, likes count, and video count to show account statistics and analytics in Cravgen.
- video.list: Read your public TikTok video metadata and aggregate engagement metrics (views, likes, comment counts, shares) to power post insights and analytics in Cravgen. We do not access individual comment text or direct messages through this scope.
- video.upload: Upload video files you create or schedule in Cravgen to TikTok as part of the publishing workflow you authorize.
- video.publish: Publish videos directly to your TikTok profile when you schedule or publish content through Cravgen.
We do not sell TikTok Platform Data. We do not use it for unrelated advertising or to build third-party marketing profiles. Access is limited to personnel and subprocessors who need it to operate the service under confidentiality obligations, in compliance with TikTok Developer Terms, TikTok's Privacy Policy, and TikTok's applicable policies.
5. YouTube & Google Platform Data
When you connect your YouTube channel to Cravgen, we access information from Google and YouTube only with your explicit authorization through Google OAuth. We use this data solely to provide features you choose — such as channel connection, publishing videos and Shorts, displaying performance metrics on post cards, analytics in the Insights tab, and viewing or replying to comments on videos you published through Cravgen from the Timeline panel.
We do not read your private YouTube messages, unrelated channel content you have not published through Cravgen, or data from channels you have not connected. Metrics such as watch time and subscribers gained are retrieved from YouTube Analytics for videos you publish or monitor through Cravgen. YouTube comment text we display in Timeline is fetched from YouTube and may be stored in our database to show your comment history; YouTube does not send real-time comment webhooks, so updates are synchronized periodically while you use Timeline.
Permissions we request and why:
- openid, email, profile: Sign you in with Google, identify your Google account, and associate your YouTube channel(s) with the correct Cravgen user on the Connections page.
- youtube.upload (https://www.googleapis.com/auth/youtube.upload): Upload and publish videos and YouTube Shorts you create or schedule in Cravgen to the YouTube channel(s) you authorize.
- youtube.readonly (https://www.googleapis.com/auth/youtube.readonly): Read your YouTube channel profile, video metadata, and public statistics (such as view counts, likes, and comment counts) to display connected account information, post performance, and insights in Cravgen.
- yt-analytics.readonly (https://www.googleapis.com/auth/yt-analytics.readonly): Retrieve YouTube Analytics metrics for videos you publish through Cravgen — including watch time, average view duration, and subscribers gained — to power insights dashboards and campaign reporting.
- youtube.force-ssl (https://www.googleapis.com/auth/youtube.force-ssl): View comments on your YouTube videos published through Cravgen and post replies from the Timeline comments panel on your behalf. Comment threads are synchronized from YouTube on a periodic basis while you use Timeline (YouTube does not provide real-time comment webhooks).
We do not sell YouTube or Google Platform Data. We do not use it for unrelated advertising or to build third-party marketing profiles. Access is limited to personnel and subprocessors who need it to operate the service under confidentiality obligations, in compliance with Google API Services User Data Policy, Google's Privacy Policy, and YouTube's Terms of Service.
6. How We Use Information
- Authenticate users and maintain secure sessions.
- Connect and manage social accounts you authorize.
- Publish, schedule, and monitor posts and campaigns on your behalf.
- Facilitate brand–creator collaborations and marketplace workflows.
- Display analytics, insights, comments, and workflow status.
- Power AI-assisted content, automation, and lead features.
- Provide customer support, billing, fraud prevention, and legal compliance.
- Improve performance, reliability, and product experience.
7. Legal Basis for Processing
Where applicable law requires a legal basis (for example, in the European Economic Area or United Kingdom), we process personal information on one or more of the following grounds:
- Consent: when you connect a social account, accept cookies, or opt in to optional features.
- Contractual necessity: to provide the service you signed up for, including publishing, analytics, and collaboration tools.
- Legitimate interests: to secure our platform, prevent abuse, improve products, and support customers, balanced against your rights.
- Legal obligations: to comply with law, respond to lawful requests, and meet tax or regulatory requirements.
8. Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure product usage, and protect against abuse. You can control cookies through your browser settings; some features may not work if cookies are disabled.
9. How We Share Information
We do not sell personal information. We may share limited data with:
- Service providers (hosting, email, analytics, payment processors) under contractual safeguards.
- Platforms you connect (such as Meta, YouTube, or TikTok) when you direct us to publish or sync content.
- Collaboration participants (brands, creators, team members) when you use shared campaign or marketplace features.
- Authorities when required by law or to protect rights, safety, and security.
10. Data Retention
We retain information while your account is active and as needed to provide the service, resolve disputes, enforce agreements, and meet legal obligations. Connected-account tokens are removed when you disconnect an account or request deletion. Aggregated or de-identified data may be kept longer for analytics and security.
11. Your Choices & Data Deletion
You may request deletion of your account and associated personal data at any time. Upon verification of your identity, we will process the request within 30 days unless a longer retention period is required by law (for example, billing records or fraud prevention).
You can delete or limit your data as follows:
- Account settings: sign in at https://admin.cravgen.com/users/user-account-settings to update profile information, disconnect integrations, or delete your account where that option is available.
- Disconnect social accounts: in Cravgen go to Connections and disconnect Facebook, Instagram, YouTube, TikTok, or other platforms. This revokes our access to publish and read data from those accounts going forward.
- Remove YouTube / Google app authorization: in Cravgen go to Connections and disconnect your YouTube channel. You may also revoke Cravgen's access in your Google Account permissions (Third-party apps with account access). We delete stored YouTube access tokens when you disconnect or when Google notifies us that authorization was removed.
- Remove TikTok app authorization: in the TikTok app go to Settings → Security → Manage app permissions (or TikTok's equivalent app management screen) and remove Cravgen. You may also disconnect TikTok from Cravgen Connections at any time. We delete stored TikTok access tokens when you disconnect or when TikTok notifies us that authorization was removed.
- Remove Meta app authorization: in Facebook Settings → Apps and Websites, remove Cravgen. Meta may notify us through their data-deletion callback.
- Email a deletion request: send a message to privacy@cravgen.com from the email address associated with your account with the subject line "Data deletion request". Include your full name and, if applicable, connected Facebook, Instagram, YouTube, or TikTok account names.
- Meta data-deletion callback: Meta-initiated deletion requests are processed at https://api.cravgen.com/api/oauth/facebook/data-deletion. User instructions for data deletion are published at https://www.cravgen.com/privacy-policy/#data-deletion. After processing, users receive a confirmation code and status URL on this page.
12. Security
We use administrative, technical, and organizational measures—including access controls, encryption in transit, and monitoring—to protect data against unauthorized access, loss, or misuse. No online service is completely risk-free; please use strong passwords and protect your account credentials.
13. Your Rights
Depending on your location, you may have rights to access, correct, export, restrict, or delete personal information, or to object to certain processing. Contact privacy@cravgen.com to exercise these rights. We may need to verify your identity before fulfilling a request.
14. Children's Privacy
Cravgen is not intended for individuals under the age of 13 (or the applicable minimum age in their jurisdiction, such as 16 in some regions). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@cravgen.com and we will take steps to delete it.
15. International Transfers
Your information may be processed and stored in countries other than where you live, including countries where our servers, cloud hosting providers, and subprocessors operate. Those locations may have different data-protection laws than your country. Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
16. Policy Updates
We may update this policy to reflect legal, product, or operational changes. We will post the revised version on this page and update the effective date. Continued use after changes constitutes acceptance where permitted by law.
17. Contact
Questions about this Privacy Policy or your data: privacy@cravgen.com, support@cravgen.com, or Contact Us.