CaraHub Privacy Policy

We value your privacy and want to be transparent about how your information is handled. Our privacy policy is simple: we do not collect, store, or track any of your personal data or usage patterns, except for the data required to run the service.

1. Data Collection

When you use our service, we collect the following data:

  • Email Address: If you sign up using your email and password, we collect and store your email address in our secure database powered by Payload CMS and PostgreSQL.
  • Username and Profile Information: Basic profile information you provide during registration and profile updates, including username, display name, and optional profile picture.
  • Content Data: Celebrity profiles, edit proposals, favorites, and other content you create within the platform. This data is stored securely in our PostgreSQL database.
  • Media Files: Images you upload are stored securely on Cloudflare R2, our cloud storage provider. For more details on their data handling practices, see Cloudflare's Privacy Policy.

We do not use your email for any purpose other than account management and communication related to the service.

2. Cookies and Third-Party Services

We use third-party services that may collect data and use cookies:

  • Payload CMS: We use Payload CMS for content management and user authentication. Your account data and content are stored securely in our PostgreSQL database. For more details, see Payload CMS Privacy Policy.
  • Cloudflare R2: We use Cloudflare R2 for secure media storage. For information on how Cloudflare handles data, see Cloudflare's Privacy Policy.

3. Data Usage

  • We use your email address solely for login authentication and communication regarding your account.
  • We do not sell, share, or misuse your personal data in any way.
  • The data is stored securely in compliance with the respective third-party services' security policies.
  • Your content contributions (celebrity profiles, edit proposals, etc.) are used to provide the collaborative platform service and may be visible to other users according to the platform's visibility settings.

4. Data Security

We implement industry-standard security measures to protect your data:

  • Encrypted Storage: All passwords are hashed and encrypted using secure cryptographic algorithms.
  • Secure Database: PostgreSQL database with access controls and regular security updates.
  • Cloud Security: Cloudflare R2 provides enterprise-grade security for media storage.
  • HTTPS: All data transmission is encrypted using SSL/TLS protocols.

5. Your Rights

You have the following rights regarding your data:

  • Access: You can access your personal data through your profile settings.
  • Update: You can update your profile information at any time.
  • Delete: You can request account deletion, which will remove all your personal data from our systems. Some content may be retained in anonymized form for platform integrity.
  • Export: You can request a copy of your data by contacting us.

6. Essential Cookies

We only use cookies that are necessary to run this website. These cookies are essential for the operation of the service and cannot be opted out of without affecting the website's functionality. These include:

  • Authentication Cookies: To maintain your login session and keep you logged in.
  • Preference Cookies: To remember your settings and preferences (e.g., theme selection, card style preferences).

7. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • Personal information (email, profile data) is permanently deleted within 30 days.
  • Some content contributions may be retained in anonymized form to maintain platform integrity and collaborative history.
  • Media files in Cloudflare R2 are deleted according to their retention policies.

8. Children's Privacy

Our service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us to have it removed.

9. Indemnification

We are not responsible for any data usage practices of third-party services. Please refer to the respective services' privacy policies for their handling of data:

10. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page and updating the "Last Updated" date. You are advised to review this privacy policy periodically for any changes.

11. Contact Us

If you have any questions or concerns about our privacy policy, please feel free to contact us:

Effective Date: October 1, 2025