Privacy Policy
Last updated: September 9, 2026
This policy explains what personal data NextVip ("we", operated by NEXTVIP LLCIt covers the website at nextvip.app, the test deployment at nextvip-isolated-mvp.vercel.app, and the NextVip application.
Data we collect
Data you give us
- Account. Your email address and, if you provide one, your name. Passwords are handled by our authentication provider and are never visible to us.
- Videos. The video files you upload, along with any title and caption you write.
- Affiliate links. The destination URLs you enter, plus the labels, programs and campaign tags you attach to them.
Data we receive from connected platforms
When you connect a TikTok, YouTube, Instagram or Facebook account, that platform sends us an access token so we can post on your behalf. We store the token, the account identifier, the display name, the profile picture and the list of permissions granted. We request the narrowest set of permissions the feature needs.
Data generated by using the service
- Distribution records. Which video went to which account, when, and the resulting post identifier and URL.
- Link clicks. When someone clicks one of your NextVip short links, we record the time, the referring page, the browser user agent and the country the request came from. We do not store the visitor’s IP address and we do not set advertising cookies on the redirect.
- Billing. Your subscription plan and the customer and subscription identifiers issued by our payment processor. Card numbers never reach our servers.
2. Why we use it
| Purpose | Data used |
|---|---|
| Signing you in and keeping your account | Email, name |
| Publishing your videos to the accounts you connected | Videos, captions, platform tokens |
| Showing you how your links perform | Link clicks, distribution records |
| Charging for a paid plan and enforcing plan limits | Plan, payment processor identifiers |
| Keeping the service secure and diagnosing failures | Error records tied to your account |
We do not sell personal data. We do not use your videos, captions or audience data to train machine learning models, and we do not share them with other users.
3. Who we share it with
Depending on the feature you use and the provider configured for it, we use the services below. Connected social platforms also handle data under their own terms and privacy policies.
- Supabase — database, authentication and video storage.
- Vercel — hosting and delivery of the website.
- Resend — transactional email, including verification and account security messages. This includes the recipient address, message content and delivery records.
- ScrapeCreators and product-data providers — retrieving video and product information from the public URLs or product identifiers needed for your selected workflow. Product-data integrations include RapidAPI, OpenWeb Ninja and DataForSEO; only the provider configured for an operation receives its request.
- AI processing — supported local models process content on the worker. When the configured Google fallback is used, the relevant text, product information or media needed for that task is sent to Google. Local processing does not mean that every task is performed locally.
- Optional publishing intermediaries — when a connection uses Zernio, that provider handles the account authorization and content needed for the enabled publishing feature.
- Stripe — subscription payments. Stripe receives your billing details directly; we receive only the identifiers and the subscription status.
- The platforms you connect — TikTok, YouTube (Google), Instagram and Facebook (Meta) receive the video, caption and link you asked us to publish.
Where processing takes place
Our primary database is configured in Oregon, United States, our Vercel server functions in Washington, D.C., and our transactional email sending in North Virginia. The local worker operates in Pennsylvania. These locations do not guarantee that all processing remains in the United States: delivery networks, connected platforms and service providers may process information in other countries. Contact us for information about a particular feature or provider.
We disclose data to anyone else only if the law requires it, and we will tell you when we are permitted to.
4. YouTube API Services
NextVip uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service , and Google’s handling of your data is governed by the Google Privacy Policy .
You can revoke NextVip’s access to your Google account at any time from the Google security settings page . Doing so stops all future publishing to that channel. You can also disconnect the channel inside NextVip, which deletes the stored token immediately.
We use YouTube API data only to upload the videos you have asked us to publish and to record the resulting video identifier. We do not build audience profiles from it, and we delete stored YouTube API data when you disconnect the channel or within 30 days of it being refreshed, whichever comes first.
5. TikTok and Meta
Connecting a TikTok account is governed by TikTok’s own terms and privacy policy; connecting an Instagram or Facebook account is governed by Meta’s. You can revoke NextVip’s access from the settings of each platform, and disconnecting inside NextVip deletes the stored token immediately.
6. How long we keep it
- Account data — until you delete your account.
- Platform tokens — until you disconnect the account or the token is revoked by the platform.
- Videos — until you delete them, or 90 days after your account is closed.
- Click records — 24 months, after which they are aggregated into counts that no longer describe individual visits.
- Billing records — as long as tax and accounting law requires.
7. Security
NextVip uses HTTPS in transit, database access policies and server-side ownership checks to restrict access to account data. Trusted server processes access the data needed to perform authorized tasks. We never receive or store card numbers.
No service can promise perfect security. If we ever discover a breach affecting your data, we will tell you and the relevant authority without undue delay.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop processing it. You can disconnect a connected account from the dashboard. For data exports, deletion or account closure requests, write to nextvip.app@gmail.com and we will respond within 30 days.
Depending on where you live you may also have the right to complain to a data protection authority. Nothing in this policy limits that right.
9. Children
NextVip is not intended for anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has created an account, write to us and we will remove it.
10. Changes
If we change this policy in a way that affects how we use data you have already given us, we will tell you by email before the change takes effect.
11. Contact
NEXTVIP LLC — nextvip.app@gmail.com. This policy is governed by the law of the Commonwealth of Pennsylvania, United States.