Privacy Policy — StarAce Business

Application: StarAce Business (including the NOXEmail outreach module) · Domain: admin.starace-global.com
Controller: StarAce · Contact: admin@starace-global.com · Last updated: 11 October 2026

Summary. StarAce Business is an internal platform for influencer (KOL) marketing. It stores the creator and campaign data our team works with, and — when a user connects a mailbox — it sends the outreach email that user writes and shows the resulting conversation. We collect only what is needed to run those features, we never sell personal data, and we do not use Google user data for advertising or to train AI models.

1. Scope of this policy

This policy explains how StarAce ("we", "us") collects, uses, stores, shares and deletes personal data when you use the StarAce Business web application, its email outreach module (NOXEmail), and the related single sign-on entry provided inside our internal KOL platform (together, the "Service"). It applies to data we process about (a) our users — StarAce employees and invited collaborators — and (b) the business contacts (professional creators and their agencies) that our users manage in the Service.

2. Data we collect

CategoryWhat it includesSource
Account & authentication dataName, work email address, role, team/organisation, account status, password hash (salted, never stored in clear), session tokens, login and audit logs (time, IP address, user agent, action)Provided by you or your administrator, or received from our company single sign-on
Creator / KOL contact dataName or handle, public channel and profile links, region, language, audience and engagement statistics, rate card and pricing, agency or MCN, business email address and phone number, notes and communication historyEntered or imported by our users (from public profiles, business cards, agency lists or our own outreach) and stored in the Service
Campaign & commercial dataCampaign names and briefs, selected creators, schedules, orders, contracts, invoices, payment references, attached files (contracts, quotes, creatives) and their metadataEntered or uploaded by our users
Email content and eventsThe subject and body of outreach emails our users compose, the mailbox used to send them, recipient address, delivery / bounce / open / click / reply events with timestamps, and the text of replies received in a connected mailboxGenerated by your use of the Service and by the mail providers involved (including Google if you connect a Google account)
Google user dataThe Google account email address, OAuth access/refresh tokens (encrypted), and the Gmail messages and metadata needed for the features you enable — see section 4Google, only after you explicitly grant access through the OAuth consent screen
Technical dataIP address, browser and device type, page/API request logs, error logs, and cookie or local-storage values used to keep you signed inCollected automatically when you use the Service

3. How and why we use data

PurposeData usedWhy we are allowed to (legal basis)
Create and administer accounts, authenticate users, enforce roles and permissionsAccount & authentication dataPerformance of our contract with you / our legitimate interest in securing the Service
Manage creator relationships: store and display contacts, campaigns, orders, contracts, invoices and notesCreator/KOL contact data, campaign & commercial dataPerformance of our contract; legitimate interests of our business
Send the outreach and follow-up email you compose, and show its delivery / open / click / reply statusEmail content, email events, Google user data (if a Google mailbox is connected)Your instruction and consent (you enable it by connecting the mailbox); our legitimate interest in operating the outreach workflow
Detect and display replies from creators so the team can respondEmail content, email events, Google user dataYour instruction and consent
Provide support, debug errors, monitor performance and prevent abuse or spamTechnical data, account data, email eventsLegitimate interest in keeping the Service secure and working
Comply with legal, tax and accounting obligations (e.g. invoices and contracts)Campaign & commercial dataLegal obligation

We do not use your data — including Google user data — for advertising or profiling, and we do not sell it.

4. Google user data (Gmail) — what we access and how we handle it

Connecting a Google account is optional. It is required only if you want to send outreach email from a Gmail mailbox and see the replies inside the Service.

4.1 Scopes we request and what each is used for

4.2 Limited Use disclosure

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

4.3 Security, storage and deletion of Google data

OAuth access and refresh tokens are stored encrypted at rest, are used only server-side, and are never exposed in the browser or shared with other customers. Gmail message content is kept only as long as needed to show your conversation history, and is deleted when the thread, the contact or the account is deleted, or when you disconnect the mailbox (which removes the tokens immediately and stops all further access). You can also revoke access at any time at myaccount.google.com/permissions; we recommend doing both.

5. Cookies and local storage

The Service is a logged-in business application; it does not use advertising or third-party tracking cookies. We use a first-party session cookie (and browser local storage) strictly to keep you signed in and to remember interface preferences. Clearing them simply signs you out.

6. Sharing and sub-processors

We do not sell personal data. We share it only with:

All such providers act under contract and only on our instructions. We do not share data with data brokers or advertising networks.

7. International transfers

Our servers and those of our providers may be located outside your country (for example in Singapore and China). Where personal data is transferred internationally we take steps to keep it protected — contractual confidentiality and security obligations with each provider, plus access control on our side.

8. Retention

DataRetention
Account dataFor as long as the account exists; deleted or anonymised after the account is closed (security audit entries may be kept up to 12 months)
Creator / KOL contact data, campaigns, orders, contracts and invoicesWhile we have a business relationship with that creator/supplier, and afterwards for the period required by tax and contract law (typically up to 7 years for commercial records)
Outreach email content and delivery eventsUp to 24 months, then deleted or aggregated
Gmail content read through the APIOnly while needed to display your conversation history; deleted when the thread/contact/account is deleted or the mailbox is disconnected
OAuth tokensUntil you disconnect the mailbox, the account is deleted, or the token is revoked — whichever comes first
Technical/access logsUp to 180 days
BackupsEncrypted daily backups kept for 30 days, then rotated out

9. Security

All traffic is encrypted in transit (HTTPS/TLS). Data is stored on access-controlled servers, database access is limited to the application and its administrators, passwords are stored as salted hashes, mailbox credentials and OAuth tokens are encrypted at rest, and access to the production environment is restricted and logged. We take daily encrypted backups. No system can be guaranteed perfect, but we maintain these controls and review them regularly.

10. Your rights

Depending on where you live, you may have the right to:

Send requests to admin@starace-global.com. We may ask you to verify your identity, and we respond within 30 days. If you are a creator whose business contact details are stored in the Service, you can also write to the same address and we will pass the request to the StarAce team member responsible for that relationship.

11. Children

The Service is a business tool intended for professionals aged 18 and over. We do not knowingly collect personal data from children and we do not direct the Service at them. If you believe a child's data has been provided to us, contact us and we will delete it.

12. Changes to this policy

We may update this policy to reflect changes in the Service or the law. The "last updated" date at the top always shows the current version; material changes affecting Google user data will be announced inside the application.

13. Contact

Data controller and contact for privacy questions, access requests and complaints:

StarAce
Email: admin@starace-global.com
Application home page: https://admin.starace-global.com/app · Terms of Service: /terms