Skip to content
StreamrList
Features FAQ Pricing About Blog Login
Join beta Login

LEGAL

Privacy Policy

Last updated: 31 July 2026. This policy explains how StreamrList (“we”, “us”) processes personal data when you use StreamrList.

This is a template based on how the product works today. Have it reviewed by counsel for your jurisdiction and fill in your legal entity details via environment configuration.

1. Data controller

The controller of personal data is:

  • StreamrList (operator of the StreamrList application)
  • 5 Gelliwastad Road, Pontypridd, CF37 2BP
  • Email: help@streamrlist.com

2. What we collect

  • Account data — name, email address, password hash, and account role (agency, creator, staff, or admin).
  • Profile & roster content — public profile details, social links, avatars, and roster information you choose to publish.
  • Billing data — subscription status and related identifiers. Card payments are processed by Stripe; we do not store full card numbers.
  • Technical data — IP address, browser type, and security logs needed to operate and protect the service. For first-party analytics we may store a one-way daily visitor hash (not your raw IP) plus profile view and link-click counts.
  • Live platform data — status and metadata retrieved from platforms you connect by username (for example Twitch, TikTok, or Kick) to show live status on rosters and profiles.
  • Authorised social account data — when you connect YouTube (Google) or TikTok via OAuth for Recent videos, we receive and store the categories of Google and TikTok user data described in section 3.

3. Connected Google (YouTube) and TikTok accounts

Creators on eligible plans may authorise StreamrList to access their YouTube account through Google OAuth and/or their TikTok account through TikTok Login Kit. This section describes how we access, use, store, share, protect, retain, and delete that data, in line with Google’s OAuth verification expectations and TikTok’s platform requirements.

3.1 Google user data we access (YouTube)

When you connect YouTube, StreamrList requests the Google OAuth scope youtube.readonly and may access:

  • Your YouTube channel identifier, channel title, and channel avatar
  • Lists of your channel playlists (when you choose playlist-based sync)
  • Metadata for recent videos from your uploads and/or selected playlists (for example video ID, title, thumbnail URL, permalink, publish time, and duration)
  • OAuth access and refresh tokens needed to call the YouTube Data API on your behalf

We do not request write access to your YouTube account. We do not upload, edit, or delete your YouTube videos through this integration.

3.2 TikTok user data we access

When you connect TikTok, StreamrList requests the scopes user.info.basic and video.list and may access:

  • Your TikTok open ID, display name, and avatar
  • Metadata for recent videos (for example video ID, title, cover image URL, share URL, create time, and duration)
  • OAuth access and refresh tokens needed to call the TikTok API on your behalf

We do not request permission to post, edit, or delete TikTok content through this integration.

3.3 How we use this data

We use Google (YouTube) and TikTok user data solely to provide and improve StreamrList features you request, including:

  • Linking your authorised account to your creator profile
  • Syncing and caching recent video metadata so you can choose which videos appear on your public StreamrList profile
  • Where an agency/team roster feature is enabled and you are connected to that agency, showing permitted recent video metadata on that agency’s roster pages according to agency and member settings
  • Refreshing access tokens so sync continues until you disconnect

Limited use. We do not use Google user data or TikTok user data for targeted advertising, selling to data brokers, credit or lending decisions, interest-based or retargeted ads, building unrelated databases, or developing, improving, or training non-personalised AI/ML models. We do not use Google Workspace APIs for those prohibited purposes.

3.4 How we store this data

  • OAuth access and refresh tokens are stored in our application database encrypted at rest (AES-256).
  • Account identifiers, display names, avatars, sync settings (for example YouTube playlist selections and Shorts inclusion), and cached video metadata are stored in our database so we can display Recent videos without calling the platform APIs on every page view.
  • Data is hosted with our infrastructure providers listed in section 6.

3.5 How we share, transfer, or disclose this data

  • Public display you control — video titles, thumbnails, permalinks, and related metadata you choose to show may appear on your public StreamrList profile and, if applicable, on agency roster pages that include Recent videos.
  • Service providers — hosting and related infrastructure vendors process data only as needed to run StreamrList.
  • Platform providers — Google/YouTube and TikTok receive authentication and API requests when you authorise, sync, or disconnect; their own policies also apply.
  • We do not sell Google or TikTok user data, and we do not transfer it to third parties for advertising, data brokerage, credit/lending, or generalised AI/ML training.
  • We may disclose data if required by law or to protect the security and integrity of the service.

3.6 Protection of sensitive credentials

Security procedures are in place to protect the confidentiality of OAuth credentials and related account data. In particular:

  • Tokens are encrypted before storage
  • Access to production systems and databases is restricted to authorised operators
  • Connections use HTTPS for OAuth redirects and API calls
  • You can revoke access at any time from StreamrList (disconnect) and/or from your Google or TikTok account security settings

3.7 Retention and deletion

  • We retain connection and cached video data while the connection remains authorised and your account is active, for as long as needed to provide Recent videos and related features.
  • When you disconnect YouTube or TikTok in StreamrList, we attempt to revoke the platform token and delete the stored connection; associated cached videos for that connection are removed with it.
  • When you delete your StreamrList account, we delete stored social connections and cached videos for your profile as part of account deletion.
  • Backup copies may persist for a limited operational period before being overwritten, unless a longer retention is required or permitted by law.

You may also request deletion of your Google or TikTok-related data by contacting us at help@streamrlist.com or by using in-app disconnect / account deletion.

4. Why we process data (lawful bases)

  • Contract — to create and manage your account, publish rosters/profiles, provide Recent videos after you authorise a platform, and provide billed features.
  • Legitimate interests — to secure the service, prevent abuse, and improve reliability.
  • Consent — for optional preference storage and any analytics cookies, via our cookie banner; and for connecting Google/YouTube or TikTok accounts, which you initiate and can withdraw by disconnecting. You can also withdraw cookie consent at any time using Cookie settings.
  • Legal obligation — where we must retain records for tax or regulatory reasons.

5. Cookies and similar technologies

We use a strictly necessary session cookie for login and security. Optional preference storage is only used if you accept. Details are in our Cookie Policy.

6. Subprocessors and third parties

We use the following categories of subprocessors to operate StreamrList:

  • Stripe, Inc. — payment processing and subscription billing when you subscribe to a paid plan.
  • Hosting — Heart Internet (application hosting and related infrastructure).
  • Email — Heart Internet (transactional mail such as verification and invites).
  • Twitch Interactive, Inc. — live status and related metadata for connected Twitch accounts.
  • Google LLC / YouTube — OAuth authentication and YouTube Data API access when you authorise YouTube for Recent videos; live or public metadata may also be used where you provide a YouTube link.
  • TikTok / ByteDance — OAuth authentication and TikTok API access when you authorise TikTok for Recent videos; live status and related metadata for TikTok usernames you connect for live tracking.
  • Kick — live status and related metadata for connected Kick accounts where configured.

When you leave our site to complete checkout, complete OAuth consent, or open a platform link, those services apply their own privacy policies (including Google’s Privacy Policy and TikTok’s privacy terms).

7. International transfers

Some processors may process data outside the UK/EEA. Where required, we rely on appropriate safeguards such as standard contractual clauses or the processor’s equivalent mechanism.

8. Retention

We keep account and roster data while your account is active. After you delete your account we soft-delete immediately: your login is deactivated and personal fields on your profile are scrubbed, and authorised social connections / cached videos are removed as described in section 3.7. Billing and subscription records may be retained for legal/tax obligations. Uploaded media may be purged from storage after a further operational period. After long inactivity we remove or anonymise remaining personal data within a reasonable period unless a longer retention is required by law.

9. Your rights (including in-app)

Depending on your location, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw consent at any time.

In the product you can:

  • Export your data — from Account settings, download a JSON copy of your account, profile, links, and related subscription metadata.
  • Delete your account — from Account settings, confirm with your email and password. We cancel applicable Stripe subscriptions where possible and soft-delete your account as described above.
  • Remove YouTube or TikTok access — from Recent videos, Links, or My account. This de-authorises the connection, revokes tokens, and deletes cached videos for that platform.
  • Update profile details — edit name, email, password, and public profile content in your dashboard.
  • Manage cookies — use Cookie settings in the footer or cookie banner.

You can also contact us at help@streamrlist.com. You may lodge a complaint with your local supervisory authority.

10. Children

StreamrList is not directed at children under 16. If you believe we have collected data from a child, contact us so we can delete it.

11. Changes

We may update this policy when our practices change, including how we access, use, store, or share Google or TikTok user data. The “Last updated” date at the top will change when we do. We will notify users of material changes to Google or TikTok data practices through an updated policy date and, where appropriate, in-product notice.

Related: Cookie Policy · Terms of Service

StreamrList

Create, manage, and share live creator rosters.

ProductFeaturesPricingDemo
CompanyAboutBlogContact
LegalTermsPrivacyCookiesCookie settings
Cookies & privacy

We use a strictly necessary session cookie to run the site (login and security). Optional preference storage (theme and UI choices) is only used if you accept. See our Cookie Policy and Privacy Policy.

Cookie preferences

Choose which optional categories you allow. Essential cookies are always on.

  • Essential Required for security, login, and form protection. Always active.
    Always on