Privacy Policy

Last updated: February 2026

1. Introduction

Creator Investment Market ("CIM", "we", "us", or "our") operates the YouTube Valuation Calculator service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

Creator Investment Market

Rihhard Rekkaro

Georg-Hermann-Allee 123

Email: rihhard.rekkaro@creatorinvestmentmarket.com

3. Data We Collect

3.1 Simple Calculator (No Account)

When you use our simple calculator without creating an account:

  • No personal data is collected or stored
  • All calculations happen locally in your browser
  • No data is transmitted to our servers

3.2 Account Registration

When you create an account, we collect:

  • Email address
  • Password (stored securely using one-way hashing)
  • Account creation timestamp

3.3 Google OAuth & YouTube Data

When you connect your YouTube account, we collect:

  • Google account identifier and email
  • OAuth access and refresh tokens (for API access)
  • YouTube channel information (name, ID, handle, creation date)
  • YouTube Analytics data (subscriber count, views, revenue metrics)

We request read-only access to your YouTube data. We cannot post, comment, or modify anything on your channel.

3.4 Valuation Certificates

When you generate a valuation certificate, we store:

  • Certificate ID and creation date
  • Channel name and handle
  • Valuation amount and metrics used
  • Subscriber count at time of generation

3.5 Technical Data

We automatically collect:

  • Session cookies (for authentication)
  • Server logs (IP address, browser type, access times)

4. Legal Basis for Processing

We process your personal data based on the following legal grounds (GDPR Article 6):

  • Consent - When you connect your Google/YouTube account
  • Contract Performance - To provide our valuation calculator service
  • Legitimate Interests - For security, fraud prevention, and service improvement

5. How We Use Your Data

We use your personal data to:

  • Create and manage your account
  • Authenticate you when you sign in
  • Calculate your YouTube channel valuation
  • Generate valuation certificates
  • Provide customer support
  • Improve our service

6. Third-Party Services

We use the following third-party services:

DigitalOcean (Hosting)

Our service is hosted on DigitalOcean servers located in Frankfurt, Germany (EU). DigitalOcean may process certain data as a data processor on our behalf. DigitalOcean is a US-based company and participates in the EU-US Data Privacy Framework.

Google OAuth & YouTube API

Used to authenticate your Google account and fetch YouTube Analytics data. Google's Privacy Policy applies to data processed by Google.

7. Data Retention

  • Account data: Retained until you request deletion
  • OAuth tokens: Retained until you disconnect your YouTube account
  • Valuation certificates: Retained indefinitely for verification purposes
  • Session data: Expires after 24 hours
  • Server logs: Retained for 90 days

8. Cookies & Tracking

We use only strictly necessary cookies, for which no consent is required under Art. 5(3) of the ePrivacy Directive:

Cookie Purpose Duration
session Session management & authentication (strictly necessary) Session
csrf_token Security — prevents cross-site request forgery Session
language Stores your language preference 1 year
cookie_consent Stores your cookie consent choice 1 year

Analytics — no tracking cookies

We analyse traffic exclusively via server-side nginx access logs. This means:

  • No tracking scripts are loaded
  • No analytics cookies are placed
  • No personal data is permanently stored

Logs contain technical access data (IP address, URL, timestamp, HTTP status, user agent) used only for aggregate traffic statistics. Raw log data is overwritten after at most 30 days. IP addresses are only counted in aggregate and never stored in the application database.

You can change your cookie preferences at any time:

9. Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right to Access - Request a copy of your personal data
  • Right to Rectification - Request correction of inaccurate data
  • Right to Erasure - Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing - Request limitation of processing
  • Right to Data Portability - Receive your data in a machine-readable format
  • Right to Object - Object to processing based on legitimate interests
  • Right to Withdraw Consent - Withdraw consent at any time (disconnect YouTube)

To exercise these rights, please contact us at: rihhard.rekkaro@creatorinvestmentmarket.com

10. Data Security

We implement appropriate security measures to protect your data:

  • Passwords are hashed using industry-standard algorithms
  • All data is transmitted over HTTPS encryption
  • Session cookies are HttpOnly and Secure
  • CSRF protection on all forms

11. International Transfers

Your data is primarily stored on servers located in Frankfurt, Germany (EU), hosted by DigitalOcean. However, as DigitalOcean is a US-based company, some data may be transferred to or accessible from the United States for operational and support purposes.

When you connect your YouTube account, your data is also processed by Google, which may transfer data to the United States.

Both DigitalOcean and Google participate in the EU-US Data Privacy Framework, ensuring adequate protection for your data in accordance with GDPR requirements.

12. Complaints

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection supervisory authority.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.