Privacy Policy
Last updated: August 2026
Effective: August 2026
1. Who we are
Castor ("Castor", "we", "us", "our") is a creator marketing marketplace that connects social media creators with brands and agencies.
Castor is a service operated by:
- Legal entity: ECHO PR COMPANY LIMITED
- Company registration number: 0105567094590
- Registered address: 67/8, Mu 3, Chim Phli Sub-district, Taling Chan District, Bangkok 10170, Thailand
- Website: https://castorsocial.com
- General contact: support@castorsocial.com
- Privacy contact: privacy@castorsocial.com
"Castor" is a trading name of ECHO PR COMPANY LIMITED. Where this policy refers to Castor, the legal entity responsible is ECHO PR COMPANY LIMITED.
We are the data controller for the personal data described in this policy, as that term is used in Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA").
This policy covers the Castor website at castorsocial.com, the Castor mobile applications for iOS and Android, and any related services (together, the "Services").
2. Summary
- We collect only what we need to run a marketplace: your identity, your public content performance, and your work history with brands on Castor.
- We connect to TikTok and other social platforms only with your explicit authorization, and only with read access.
- We never post, message, comment, follow, or change anything on your social accounts.
- We do not sell your personal data.
- You can disconnect any social account, or delete your Castor account entirely, at any time, from your settings. Disconnecting stops all further collection and deletes the access token immediately; section 11 sets out exactly what is deleted and what is kept in each case.
3. Information we collect
3.1 Data you provide directly
| Data | Why we need it |
|---|---|
| Name, email address | Account creation, login, security notifications, support |
| Password (stored as a salted hash — we never see it) | Account security |
| Profile details: bio, location, languages, content categories, rate card | Your public creator profile and matching with campaigns |
| Company name and business details (brands and agencies) | Identifying the organisation you represent |
| Messages you send through Castor | Delivering communications between creators and brands, and resolving disputes |
| Content you upload (draft videos, images, captions) | Delivering work to the brand that engaged you |
| Sizes and fit, if you provide them: clothing and shoe size, shade range, skin or hair type, pet size | Shown on your Media Kit so a brand can send a product that fits. Optional — see section 6.1.1 |
| Delivery addresses, if you provide them: recipient name, phone number, and address | Sending you product on a campaign you accepted. Never published, and shared with a brand only when you choose to — see section 6.1.1 |
| Dietary needs, only with your explicit consent (sensitive personal data) | So a brand sending you food or supplements sends something you can consume. Never published — see section 6.1.1 |
3.2 Data we receive from TikTok
When you choose to connect your TikTok account using TikTok Login Kit, TikTok asks you to approve specific permissions. We receive only the data covered by the permissions you approve, and nothing else. TikTok does not give us your email address, password, phone number, direct messages, or private account data.
We request the following four permissions:
| TikTok permission (scope) | Data we receive | How we use it |
|---|---|---|
| user.info.basic | Open ID, Union ID, display name, username, avatar URL, profile deep link | To create your Castor account, confirm you control the TikTok account you claim, prevent impersonation, and display your handle and picture on your Castor profile |
| user.info.profile | Profile bio, verified status, profile link | To populate your Castor creator profile so you do not have to re-enter it |
| user.info.stats | Follower count, following count, likes count, video count | To display audience size on your media kit, and to match you to campaigns with a suitable audience |
| video.list | Public video ID, title, description, cover image URL, duration, share URL, view count, like count, comment count, share count | To build your media kit, calculate your engagement rate, and — for posts delivered under a Castor campaign — report performance to the brand you worked with |
How we use TikTok data — and how we do not:
- We use TikTok data only to provide the Castor Services to you, the account holder who authorized it.
- We display your TikTok metrics on your own Castor profile and media kit, which is visible to brands and agencies registered on Castor.
- We do not use TikTok data for advertising, ad targeting, or audience building.
- We do not sell, rent, license, or trade TikTok data.
- We do not combine TikTok data with data obtained from any other source to build a profile of a person who has not authorized us.
- We do not use TikTok data to train general-purpose or foundation machine learning models, and we do not share it with any third party for that purpose.
- We do not attempt to identify, track, or profile any TikTok user other than the account holder who connected their account.
- We do not remove, obscure, or alter watermarks or other creator attribution.
- We do not store copies of your TikTok videos. We store only the metadata listed above and, where TikTok provides them, references to TikTok-hosted URLs.
3.3 Data we receive from Instagram
When you choose to connect your Instagram account, we use the Instagram API with Instagram Login, provided by Meta Platforms, Inc. Instagram asks you to approve specific permissions, and we receive only the data covered by the permissions you approve. Instagram does not give us your password, your email address, your phone number, or the content of your direct messages.
Connecting Instagram requires a Professional account (Business or Creator). Instagram does not make this data available for personal accounts.
We request the following two permissions:
| Instagram permission (scope) | Data we receive | How we use it |
|---|---|---|
| instagram_business_basic | Instagram user ID, username, account type, display name, biography, profile picture URL, follower count, following count, media count, and for your published posts: media ID, caption, media type, permalink, thumbnail URL, timestamp, like count and comment count | To confirm you control the Instagram account you claim, prevent impersonation, populate your Castor creator profile and media kit, calculate your engagement rate, and match you to campaigns suited to your audience and content |
| instagram_business_manage_insights | Aggregate performance metrics for your own account and posts, such as reach and views | To show accurate reach on your media kit rather than follower count alone, and — for posts delivered under a Castor campaign — to report performance to the brand you worked with |
How we use Instagram data — and how we do not:
- We use Instagram data only to provide the Castor Services to you, the account holder who authorized it.
- We display your Instagram metrics on your own Castor profile and media kit, which is visible to brands and agencies registered on Castor.
- We do not use Instagram data for advertising, ad targeting, or audience building.
- We do not sell, rent, license, or trade Instagram data.
- We do not combine Instagram data with data obtained from any other source to build a profile of a person who has not authorized us.
- We do not use Instagram data to train general-purpose or foundation machine learning models, and we do not share it with any third party for that purpose.
- We do not attempt to identify, track, or profile any Instagram user other than the account holder who connected their account.
- We do not access, read, send, or store your Instagram direct messages.
- We do not store copies of your Instagram photos or videos as media files. Where we analyse a post to understand its subject matter, we process it to produce a numerical representation used for campaign matching, and retain the metadata listed above together with Instagram-hosted references.
Access tokens. Instagram issues us a long-lived access token that expires after 60 days. We refresh it automatically while your account remains connected so your media kit stays current. If you disconnect Castor from within Instagram, the token is invalidated immediately and we stop receiving any further data.
Deleting Instagram data. You can disconnect Instagram at any time from your Castor settings, or request deletion through Instagram itself. See section 11 for what each option does. Requests made through Instagram are handled automatically and you are given a confirmation code to check the status of your request.
3.3.1 Data we receive from other platforms
If you connect another supported platform, we receive equivalent profile and public post-performance data under the permissions you approve on that platform. The same restrictions in sections 3.2 and 3.3 apply.
3.4 Campaign data
Records of briefs you apply to, quotes, agreed fees, delivery dates, approvals, revisions, and completed campaigns. We use this to operate the marketplace and to maintain your on-time delivery record.
Castor does not currently process payments. Fees agreed on Castor are settled directly between you and the brand. We record the agreed amount but do not collect your bank account details, card details, or payment credentials.
3.5 Technical data collected automatically
IP address, device type and model, operating system, app version, browser type, language, time zone, pages or screens viewed, and crash logs. We use this to keep the Services secure, diagnose faults, and understand aggregate usage.
4. Automated processing and machine learning
Castor uses machine learning to match campaign briefs with creators. You should understand how this works.
- We generate mathematical representations ("embeddings") of the public content of creators who hold a Castor account and have connected that platform. These embeddings let a brand describe a campaign in plain language and receive relevant creators in response.
- Embeddings derived from your data are used only to rank you within Castor's own search results. They are not sold, shared, published, or used to train models offered to anyone else.
- We do not build embeddings, profiles, or records of people who do not hold a Castor account.
- Matching produces a suggestion, not a decision with legal effect. A person at the brand decides who to invite and who to engage. You can ask us how a particular match was produced by writing to privacy@castorsocial.com.
- If you delete your account or disconnect a platform, the embeddings derived from that platform are deleted along with the underlying data, within the timeframes in section 8.
5. Legal basis for processing
Under the PDPA, and under the GDPR where it applies to users in the European Economic Area and the United Kingdom, we rely on:
| Purpose | Legal basis |
|---|---|
| Connecting your social accounts and displaying that data on your profile | Consent (PDPA s.19; GDPR Art. 6(1)(a)) — given when you approve the platform's permission screen, and withdrawable at any time |
| Creating and operating your account, matching, and campaign management | Performance of a contract (PDPA s.24(3); GDPR Art. 6(1)(b)) |
| Fraud prevention, security, service improvement, and aggregate analytics | Legitimate interest (PDPA s.24(5); GDPR Art. 6(1)(f)) |
| Accounting records and responding to lawful requests | Legal obligation (PDPA s.24(6); GDPR Art. 6(1)(c)) |
| Marketing emails | Consent, withdrawable via the unsubscribe link in any such email |
| Sending you a delivery address and sizes so a brand can ship product on a campaign you accepted | Performance of a contract (PDPA s.24(3); GDPR Art. 6(1)(b)) — and each disclosure to a brand is a separate choice you make, per campaign |
| Dietary needs (sensitive personal data) | Explicit consent (PDPA s.26; GDPR Art. 9(2)(a)) — given by the tick box beside the field, and withdrawable by clearing it, which deletes it |
Withdrawing consent does not affect processing carried out before the withdrawal.
6. How we share your information
We do not sell your personal data. We share it only as described below.
6.1 With brands and agencies on Castor
- Before you apply to a brief: brands searching Castor can see your public creator profile — display name, handle, avatar, category, location, languages, audience size, engagement rate, sample public posts, and your stated rate. They cannot see your email address or your account credentials.
- After you apply or are engaged: the brand additionally sees your quote, your messages to them, the content you deliver, and the performance of posts delivered under their campaign.
- After a campaign ends: the brand retains a record of the campaign and its results for their own reporting.
6.1.1 Sizes, fit, and delivery addresses
Some campaigns send you a physical product. Two kinds of information make that possible, and we treat them differently because they carry different risk.
- Sizes and fit — clothing and shoe size, shade range, skin or hair type, pet size, and similar details, where you choose to provide them. These appear on your public Media Kit, so a brand can tell whether a sample will fit before contacting you. You can clear any of them at any time in Settings.
- Delivery addresses — never published, and never visible to a brand browsing Castor. An address is disclosed to one brand, for one campaign, only when you choose to share it, and only once that brand has accepted you. We record each disclosure — which brand, which campaign, and when — and you can see that record and stop sharing at any time on your Addresses page. Stopping prevents the brand seeing the address from that point on; it cannot recall an address a brand has already seen, and we will not tell you otherwise.
- Dietary needs — treated as sensitive personal data under section 26 of the PDPA, because answers such as "Halal" or "No pork" can reveal religious belief. We store them only if you explicitly agree, they are never shown on your Media Kit, and they are disclosed only to a campaign that has specifically asked for them in order to send you food or supplements. Withdraw by clearing the field, which deletes it.
A brand that receives your address may only use it to send you product for that campaign. Once a brand has been shown an address, that disclosure is outside our technical control, which is why we log it and why sharing is always your decision rather than something a brand can request automatically.
6.2 With service providers
We use the following processors, who may only act on our instructions and may not use your data for their own purposes:
| Purpose | Provider | Location of processing |
|---|---|---|
| Cloud hosting, databases, and file storage | Google Cloud Platform (Google Cloud EMEA Limited / Google LLC) | asia-southeast1 (Singapore) |
| Transactional email and notifications | Resend (Plus Five Five, Inc.) | United States |
Customer support is handled directly by our own staff. We do not currently use a third-party payment processor, identity verification provider, error monitoring service, or product analytics service. If that changes, we will update this policy and notify you as described in section 15.
6.3 Other disclosures
We may disclose personal data where required by law, court order, or a lawful request from a public authority; to establish, exercise, or defend legal claims; or to a buyer in connection with a merger or acquisition, in which case we will notify you before your data becomes subject to a different policy.
7. International transfers
ECHO PR COMPANY LIMITED is based in Thailand. Our infrastructure is hosted on Google Cloud Platform in asia-southeast1 (Singapore), and our transactional email provider processes data in the United States. Your personal data may therefore be transferred to and processed outside Thailand.
Where we transfer personal data outside Thailand, we do so on the basis of appropriate safeguards, including the standard contractual clauses incorporated into our agreements with Google Cloud and Resend, as permitted by PDPA sections 28 and 29. You can request further detail by writing to privacy@castorsocial.com.
8. How long we keep your data
| Data | Retention period |
|---|---|
| Data obtained from TikTok or another connected platform | Deleted within 30 days of you disconnecting that platform, revoking access on the platform, or deleting your Castor account |
| Platform access tokens and refresh tokens | Deleted immediately on disconnection; otherwise expired and rotated per the platform's rules, with unused tokens purged after 90 days |
| Embeddings derived from your content | Deleted with the underlying data, within 30 days |
| Account profile and login data | For as long as your account is active, then deleted within 30 days of account deletion |
| Messages between creators and brands | 24 months after the campaign closes, to allow dispute resolution |
| Content you delivered under a campaign | 24 months after the campaign closes, then deleted |
| Campaign records and any associated accounting records | 10 years, where required by the Thai Revenue Code and Accounting Act — these records cannot be deleted on request |
| Delivery addresses and sizes | Kept while your account is active so you do not have to retype them, and deleted immediately when you remove them or delete your account. You can remove them at any time without closing your account |
| Our record of which brand you shared an address with, and when | Kept for 24 months after the campaign closes, alongside the messages, so a delivery dispute can be resolved. The address itself is removed when you delete it; what remains is the fact that a disclosure happened, which identifies nobody |
| Security and access logs | 12 months |
| Backups | Purged on a rolling 35-day cycle; deleted data disappears from backups within that period |
9. Security
We protect your data with:
- Encryption in transit (TLS 1.2 or higher) and at rest
- Access tokens stored encrypted, never in plain text, and never exposed to client applications
- Role-based access control, with staff access to production data limited to named personnel and logged
- Multi-factor authentication on all staff accounts with production access
- Passwords stored as salted hashes, never in recoverable form
- Regular dependency scanning and periodic review of our security practices
- A documented incident response process. If a breach is likely to result in a high risk to your rights, we will notify you and the Office of the Personal Data Protection Committee within 72 hours of becoming aware of it, as required by PDPA section 37(4)
No system is perfectly secure. If you believe your account has been compromised, contact security@castorsocial.com immediately.
10. Your rights
Under the PDPA you have the right to:
- Access the personal data we hold about you and receive a copy
- Portability — receive your data in a machine-readable format, or have it sent to another controller
- Rectification — have inaccurate or incomplete data corrected
- Erasure — have your data deleted, subject to records we must keep by law
- Restriction — ask us to suspend processing while a dispute is resolved
- Objection — object to processing based on legitimate interest, and to direct marketing at any time
- Withdraw consent at any time, including by disconnecting a social account
- Complain to a supervisory authority (see section 13)
How to exercise them: most rights can be exercised directly in the app under Settings → Privacy, including downloading your data and deleting your account. Otherwise write to privacy@castorsocial.com. We respond within 30 days, as required by the PDPA. We may ask you to verify your identity first. Exercising these rights is free; we may charge a reasonable fee only for manifestly excessive or repetitive requests.
11. Disconnecting a platform and deleting your data
This section explains exactly what happens to platform data. Disconnecting and deleting are different actions, and we describe each precisely below rather than treating them as the same thing.
Option 1 — Disconnect inside Castor.
Go to Settings → Social Integrations and disconnect the platform. In every case we immediately delete the access token and stop all further data collection. What happens to data already held depends on where it came from, and we want to be exact about that rather than imply more than we do:
- Instagram — we hold Instagram data only because you authorized it, so disconnecting unlinks the account and removes it from your Castor profile and media kit. To erase the data already collected, use Option 2 or Option 4.
- TikTok — disconnecting unlinks your TikTok account from your Castor account and removes it from your profile and media kit. Your public TikTok catalog entry — the profile and post metrics we compile from publicly available information — is not deleted by disconnecting, because it is not created by your Castor account and in most cases predates it. To have that removed as well, use Option 4 or write to us.
Option 2 — Request deletion from Instagram.
In the Instagram app, go to Settings and privacy → Website permissions → Apps and websites, find Castor, and remove it, choosing the option to request deletion of your data. Instagram sends us a signed deletion request, which we verify and act on automatically: we delete your Instagram profile data, post metadata, and every embedding derived from it, and we remove the connection entirely. You are given a confirmation code and a link where you can check the status of that request at any time.
Removing Castor from Instagram without requesting deletion revokes our access immediately and stops all further collection, but leaves previously collected data in place until you ask us to delete it.
Option 3 — Revoke access from TikTok.
In the TikTok app, go to Profile → Menu → Settings and privacy → Security and permissions → Manage app permissions, find Castor, and remove it. Our access ends immediately, and we delete the associated data within 30 days.
Option 4 — Delete your Castor account entirely.
Go to Settings → Delete account, or email privacy@castorsocial.com. This happens immediately, not within 30 days, and it is irreversible.
We delete your profile, your name, your email address, your avatar, your personas, your rate cards, your handle claims, your notifications, your saved sessions, every stored access token, your cached recommendations, the messages you wrote, and all Instagram data including posts and the embeddings derived from them.
Two things deliberately survive, and you should know what they are:
- Your public TikTok catalog entry, unlinked from your Castor account. It is compiled from publicly available information under a separate lawful basis and usually predates your signup. If you want it removed too, say so and we will remove it.
- Campaigns, applications, offers and reports involving you, attributed to an anonymous account rather than to you by name. These are also records of the brands you worked with, and their history should not disappear because you left. Nothing in them identifies you.
If you are the only owner of an organization, we ask you to transfer ownership or delete the organization first, so its campaigns and other members are not stranded.
What survives deletion, and why. Accounting records relating to completed transactions are retained where Thai law requires it. Content already published to your own social account remains there — it belongs to you and is under your control on that platform, not ours.
12. Children
Castor is not intended for children. You must be at least 18 years old to create a Castor account, because using Castor involves entering into commercial arrangements.
We do not knowingly collect personal data from anyone under 18. If we learn that we hold data of a person under 18, we delete it promptly. If you believe a minor has created an account, contact privacy@castorsocial.com.
13. Complaints
If you are unhappy with how we handle your personal data, please contact privacy@castorsocial.com first — we would like the chance to fix it.
You also have the right to complain to:
Office of the Personal Data Protection Committee (PDPC)
Ministry of Digital Economy and Society, Bangkok, Thailand
https://www.pdpc.or.th
If you are in the EEA or UK, you may complain to your local data protection authority.
14. Cookies and similar technologies
Our website uses cookies that are strictly necessary for login and security. We do not currently use advertising or third-party analytics cookies. Our mobile apps do not use advertising identifiers for tracking, and we do not operate an advertising SDK. You can manage cookies through your browser settings.
15. Changes to this policy
We may update this policy. If we make a material change — for example, collecting a new category of data, adding a payment provider, or sharing data with a new category of recipient — we will notify you by email and in the app at least 14 days before the change takes effect, and where the change requires it, ask for your consent again. The "last updated" date at the top always reflects the current version. Previous versions are available on request.
16. Contact
| Privacy and data protection | privacy@castorsocial.com |
| Security issues | security@castorsocial.com |
| General support | support@castorsocial.com |
| Postal | ECHO PR COMPANY LIMITED, 67/8, Mu 3, Chim Phli Sub-district, Taling Chan District, Bangkok 10170, Thailand |
We aim to respond to all privacy enquiries within 5 business days, and always within the 30 days required by the PDPA.