Application: StarAce Business (including the NOXEmail outreach module) · Domain: admin.starace-global.com
Controller: StarAce · Contact: admin@starace-global.com · Last updated: 11 October 2026
Summary. StarAce Business is an internal platform for influencer (KOL) marketing. It stores the creator and campaign data our team works with, and — when a user connects a mailbox — it sends the outreach email that user writes and shows the resulting conversation. We collect only what is needed to run those features, we never sell personal data, and we do not use Google user data for advertising or to train AI models.
This policy explains how StarAce ("we", "us") collects, uses, stores, shares and deletes personal data when you use the StarAce Business web application, its email outreach module (NOXEmail), and the related single sign-on entry provided inside our internal KOL platform (together, the "Service"). It applies to data we process about (a) our users — StarAce employees and invited collaborators — and (b) the business contacts (professional creators and their agencies) that our users manage in the Service.
| Category | What it includes | Source |
|---|---|---|
| Account & authentication data | Name, work email address, role, team/organisation, account status, password hash (salted, never stored in clear), session tokens, login and audit logs (time, IP address, user agent, action) | Provided by you or your administrator, or received from our company single sign-on |
| Creator / KOL contact data | Name or handle, public channel and profile links, region, language, audience and engagement statistics, rate card and pricing, agency or MCN, business email address and phone number, notes and communication history | Entered or imported by our users (from public profiles, business cards, agency lists or our own outreach) and stored in the Service |
| Campaign & commercial data | Campaign names and briefs, selected creators, schedules, orders, contracts, invoices, payment references, attached files (contracts, quotes, creatives) and their metadata | Entered or uploaded by our users |
| Email content and events | The subject and body of outreach emails our users compose, the mailbox used to send them, recipient address, delivery / bounce / open / click / reply events with timestamps, and the text of replies received in a connected mailbox | Generated by your use of the Service and by the mail providers involved (including Google if you connect a Google account) |
| Google user data | The Google account email address, OAuth access/refresh tokens (encrypted), and the Gmail messages and metadata needed for the features you enable — see section 4 | Google, only after you explicitly grant access through the OAuth consent screen |
| Technical data | IP address, browser and device type, page/API request logs, error logs, and cookie or local-storage values used to keep you signed in | Collected automatically when you use the Service |
| Purpose | Data used | Why we are allowed to (legal basis) |
|---|---|---|
| Create and administer accounts, authenticate users, enforce roles and permissions | Account & authentication data | Performance of our contract with you / our legitimate interest in securing the Service |
| Manage creator relationships: store and display contacts, campaigns, orders, contracts, invoices and notes | Creator/KOL contact data, campaign & commercial data | Performance of our contract; legitimate interests of our business |
| Send the outreach and follow-up email you compose, and show its delivery / open / click / reply status | Email content, email events, Google user data (if a Google mailbox is connected) | Your instruction and consent (you enable it by connecting the mailbox); our legitimate interest in operating the outreach workflow |
| Detect and display replies from creators so the team can respond | Email content, email events, Google user data | Your instruction and consent |
| Provide support, debug errors, monitor performance and prevent abuse or spam | Technical data, account data, email events | Legitimate interest in keeping the Service secure and working |
| Comply with legal, tax and accounting obligations (e.g. invoices and contracts) | Campaign & commercial data | Legal obligation |
We do not use your data — including Google user data — for advertising or profiling, and we do not sell it.
Connecting a Google account is optional. It is required only if you want to send outreach email from a Gmail mailbox and see the replies inside the Service.
https://www.googleapis.com/auth/gmail.send — send the outreach or follow-up email that you composed from the connected mailbox.https://www.googleapis.com/auth/gmail.readonly — read the messages of the conversation between you and that creator, so the Service can show who replied and what they said.https://www.googleapis.com/auth/gmail.modify — update conversation state (for example marking the outreach thread) so replies are tracked correctly and not missed.Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
OAuth access and refresh tokens are stored encrypted at rest, are used only server-side, and are never exposed in the browser or shared with other customers. Gmail message content is kept only as long as needed to show your conversation history, and is deleted when the thread, the contact or the account is deleted, or when you disconnect the mailbox (which removes the tokens immediately and stops all further access). You can also revoke access at any time at myaccount.google.com/permissions; we recommend doing both.
The Service is a logged-in business application; it does not use advertising or third-party tracking cookies. We use a first-party session cookie (and browser local storage) strictly to keep you signed in and to remember interface preferences. Clearing them simply signs you out.
We do not sell personal data. We share it only with:
All such providers act under contract and only on our instructions. We do not share data with data brokers or advertising networks.
Our servers and those of our providers may be located outside your country (for example in Singapore and China). Where personal data is transferred internationally we take steps to keep it protected — contractual confidentiality and security obligations with each provider, plus access control on our side.
| Data | Retention |
|---|---|
| Account data | For as long as the account exists; deleted or anonymised after the account is closed (security audit entries may be kept up to 12 months) |
| Creator / KOL contact data, campaigns, orders, contracts and invoices | While we have a business relationship with that creator/supplier, and afterwards for the period required by tax and contract law (typically up to 7 years for commercial records) |
| Outreach email content and delivery events | Up to 24 months, then deleted or aggregated |
| Gmail content read through the API | Only while needed to display your conversation history; deleted when the thread/contact/account is deleted or the mailbox is disconnected |
| OAuth tokens | Until you disconnect the mailbox, the account is deleted, or the token is revoked — whichever comes first |
| Technical/access logs | Up to 180 days |
| Backups | Encrypted daily backups kept for 30 days, then rotated out |
All traffic is encrypted in transit (HTTPS/TLS). Data is stored on access-controlled servers, database access is limited to the application and its administrators, passwords are stored as salted hashes, mailbox credentials and OAuth tokens are encrypted at rest, and access to the production environment is restricted and logged. We take daily encrypted backups. No system can be guaranteed perfect, but we maintain these controls and review them regularly.
Depending on where you live, you may have the right to:
Send requests to admin@starace-global.com. We may ask you to verify your identity, and we respond within 30 days. If you are a creator whose business contact details are stored in the Service, you can also write to the same address and we will pass the request to the StarAce team member responsible for that relationship.
The Service is a business tool intended for professionals aged 18 and over. We do not knowingly collect personal data from children and we do not direct the Service at them. If you believe a child's data has been provided to us, contact us and we will delete it.
We may update this policy to reflect changes in the Service or the law. The "last updated" date at the top always shows the current version; material changes affecting Google user data will be announced inside the application.
Data controller and contact for privacy questions, access requests and complaints:
StarAce
Email: admin@starace-global.com
Application home page: https://admin.starace-global.com/app · Terms of Service: /terms