FrameYield
DashboardJoin beta
Back to FrameYieldPRIVACY & DATA

Measure attention. Not people.

FrameYield is designed around aggregate campaign delivery, limited account data and clear retention states.

Controlled betaControlled beta notice · legal review pendingLast updated 5 September 2026
Plain-language operating policy

FinalFlow · CVR 46076842, Tulipanhaven 142, 1. 3, 8200 Aarhus N, Denmark, is the data controller for the FrameYield controlled launch. Privacy requests may be sent to privacy@frameyield.com. Processor roles, hosting regions and transfer safeguards still require final review before public onboarding.

EMAIL

Optional campaign announcements

You may opt into email announcements about funded campaigns open for creator matching, even before completing a creator application. This is optional marketing based on your consent, separate from necessary account and payment communications.

  • We use your signed-in email address and account identifier, and save your consent version and time. We do not ask for YouTube access or payment details to join this email list.
  • Resend processes the recipient address, message content and delivery information to send these emails on our behalf. Campaign emails do not contain your YouTube analytics or bank details. Cloudflare stores the preference and delivery records.
  • Every campaign announcement includes an unsubscribe link and email-client one-click unsubscribe headers. You can also turn off campaign emails on the campaign page or in dashboard settings. No sign-in is required to use the unsubscribe link in an email.
  • Opting out stops further announcements; an email already being delivered may still arrive. It does not close the account, cancel an accepted offer, or stop necessary security, account and payment messages.
  • We retain your preference while subscribed. After opt-out, a minimal suppression and consent record is retained for 180 days and removed in the next maintenance cycle, together with associated announcement-delivery records. The campaign page provides a downloadable export of your email preference and delivery history.
  • For access, deletion or a complaint about campaign emails, contact privacy@frameyield.com. No campaign emails are sent merely because you create an account.
01

Data we collect

We collect the information needed to run accounts, review eligibility, match campaigns, report delivery and settle funds.

  • Account: name, email, role, country, currency, acquisition source and versioned acceptance records.
  • Creator: channel URL, category, aggregate analytics, connection state, disclosure attestations and payout state.
  • Payout: Stripe account/transfer/payout ids, KYC readiness, human-readable due requirements, destination type/label/last four digits, currency, arrival estimate, failure/hold state and receipts.
  • Brand: company, website, industry, budget range, regions, billing state and a non-secret referral code.
  • Billing declarations: legal party name, business or individual capacity, billing address, business registration number if supplied, VAT status and number if supplied, declaration time and revision. These fields are account-owner declarations, not automated tax verification. Do not submit CPR numbers or personal tax identifiers through the billing form.
  • Referral: attribution code, referrer and referred brand account ids, qualification status, applicable terms version, calculated media-credit fields and related audit events.
  • Campaign: briefs, creative versions, approvals, aggregate delivery, exclusions, disputes and ledger events.
02

Read-only platform connections

A production analytics connection requests only the two read-only YouTube scopes needed for channel binding and official reach reporting. FrameYield does not need permission to publish, edit or delete videos, read private messages or take over a social account.

  • YouTube Data API read-only is used to identify the connected channel and eligible video IDs.
  • YouTube Analytics read-only is used to request aggregate channel and thumbnail-reach reporting data.
  • The billable private-beta scope is accepted YouTube long-form video IDs; Shorts, Reels and TikTok covers are excluded.
  • Access tokens are encrypted and separated from ordinary profile data.
  • Connected analytics are used for eligibility, measurement, fraud review and reporting.
  • Disconnecting attempts to delete FrameYield’s YouTube Reporting job and revoke the Google grant, then always removes local OAuth credentials, raw imported daily analytics and sync history. Settled financial, campaign-order and audit records may remain where required for payment, disputes or law.
  • You can also review or revoke FrameYield directly from your Google Account permissions at any time.

Open Google Account third-party connections.

03

Why we use data

Data is used to perform accepted campaign services, secure the marketplace, attribute approved referrals, comply with law and improve aggregate product performance.

  • We do not sell personal data or private-message data.
  • We do not bill brands from private chat exposure or external link-preview guesses.
  • A campaign response link stores only an aggregate placement-and-day redirect count. FrameYield does not retain the visitor’s IP address, cookie identifier or user-agent fingerprint for this count; it is reported as a raw redirect, not a unique person or verified conversion.
  • Referral source and code data are used to preserve first attribution, prevent self-referrals and duplicate claims, review qualification and record any future credit decision.
  • Automated signals may flag unusual delivery, but a person reviews material holds or account actions.
  • Billing declarations support contract administration and invoice preparation. Processing for actual bookkeeping and tax duties relies on the applicable legal obligation; saving this declaration is not marketing consent.
  • Security and reliability monitoring uses our legitimate interest in operating a safe service. Operational incident emails go only to configured administrators and include an event reference and code, not private exception messages, YouTube analytics or bank information. Delivery attempts and provider acceptance references are retained to prevent duplicate sends and investigate failures.
  • Product analytics should be aggregated or minimised wherever individual identity is unnecessary.
04

Who receives, transfers or discloses data

Participants receive only what is necessary for the campaign. Brands see approved creator identity and aggregate delivery, not Google credentials or private analytics. Creators see the relevant brand, brief, rate and settlement record.

  • Google receives the OAuth request and consent decision. FrameYield receives the connected channel identity, eligible video identifiers and the aggregate reporting data returned by the YouTube APIs. Google user data is used only for channel binding, eligibility, measurement, fraud review and reporting.
  • Cloudflare and the configured hosting identity layer process FrameYield account, campaign, encrypted-token, reporting and ledger data to host the application, database, assets and authenticated sessions.
  • Stripe receives payment, KYC and payout information through its hosted flows. FrameYield is designed to retain provider status, requirement names, account and transfer identifiers, destination label/last four digits and receipts, not raw identity documents or full bank numbers.
  • FrameYield staff and contracted reviewers may access limited records when needed for support, fraud review, payout holds, legal requests or campaign disputes. Access is role-based and audited.
  • No Google user data is sold, used for advertising, transferred to data brokers or used to train a general-purpose model.
  • Authorities, accountants, lawyers and auditors receive data only when legally required or when needed to establish, exercise or defend a legal claim.
  • Cross-border transfers use the safeguards required for the launch market; the final processor list, regions and transfer mechanism are recorded before public onboarding.
05

Retention

The proposed beta schedule is shown for transparency but remains subject to legal review: incomplete local drafts stay on the device; rejected or abandoned applications are deleted or anonymised after 180 days; OAuth credentials are erased on disconnect; operational backups expire within 30 days; campaign, tax, payout, fraud and dispute records are retained for the legally required accounting/reporting period, proposed as five years after the relevant financial year.

  • A shorter period applies where the purpose ends and no legal duty remains.
  • Deletion requests remove data that is no longer required for an active account, security evidence or legal record.
  • Frame PNGs and hashes follow the associated campaign/dispute retention state.
  • The final production schedule and legal basis will be published before public onboarding.
06

Choices and rights

Depending on location, participants may request access, correction, deletion, restriction, portability or objection, and may complain to a data protection authority.

  • Requests may be sent to privacy@frameyield.com; identity may be checked before account data is disclosed or changed.
  • An authenticated account can download a structured JSON snapshot and open an access, correction or deletion review from dashboard settings. The request records a response deadline and remains in an audited admin queue.
  • A request is not marked fulfilled until identity verification, completion evidence and any legal retention exceptions are recorded.
  • You can disconnect a social account without deleting the FrameYield account.
  • Marketing communication is optional and separate from operational campaign notices.
  • Identity verification data is handled by the configured provider under the disclosures shown at collection.
07

Security

FrameYield uses least-privilege access, encrypted transport, protected secrets, audit trails and role-based controls. No service can promise absolute security, so incident response and notification procedures are part of production readiness.

  • Password handling is delegated to the platform authentication layer rather than a custom password database.
  • Sensitive payment details stay with the configured payment provider where possible.
  • Participants should report suspected account access through the authenticated support channel shown in the dashboard.
08

Processors and transfers

The controlled-beta stack uses Cloudflare for application, database and object hosting, the configured hosting identity layer for authenticated sessions, Google for YouTube OAuth and Reporting API access, and Stripe for payment, KYC and payout services. Each provider receives only the data required for its stated service.

  • Stripe collects raw bank-account, identity-document and sensitive KYC fields on its hosted flow; FrameYield is designed to retain only the status, requirement names, destination label/last four digits and provider receipts needed to operate and audit payout.
  • Additional tax/DAC7 seller data is not assumed to be covered by Stripe KYC and receives its own collection notice where legally required.
  • Google tokens are encrypted with a separate application key and removed on disconnect. Imported raw analytics and the local sync history are also removed on disconnect, except for settled financial, campaign-order and audit records that must be retained.
  • Cloudflare-hosted account, campaign, encrypted connection and reporting records may be processed in the regions made available by the configured service. The production release records the applicable hosting region, subprocessors and transfer safeguard before public onboarding.
  • Resend processes configured administrator addresses and limited event references for operational alerts, and recipients and message content for account and campaign emails. Provider acceptance is not treated as proof that an email reached an inbox. Optional marketing and necessary operational messages remain separate.
  • Monitoring and support providers may be added only after contract and privacy review.
09

Cookies and device storage

The product uses essential session mechanisms supplied by the hosting identity layer and browser storage for an unfinished local onboarding draft. Non-essential analytics or advertising cookies require a separate inventory and consent decision before activation.

  • Local drafts are not submitted until the user chooses to send them.
  • No third-party advertising pixel is part of the controlled-launch build.
  • A production cookie table will list name, provider, purpose and lifetime.
10

Controller and production notice

FrameYield is a product operated by FinalFlow, a Danish sole proprietorship owned by Thomas Tobias Hansen, CVR 46076842, at Tulipanhaven 142, 1. 3, 8200 Aarhus N, Denmark. Privacy contact: privacy@frameyield.com.

  • Before public onboarding, this notice must also include the final processor inventory, hosting regions, cookie choices, lawful bases and jurisdiction-specific supplements.
  • Real OAuth and authorised payment tests may be used within the controlled operating scope. Live credentials do not automatically approve public transactions or automated creator payouts.
  • Any material change receives a new effective date.
  • Campaign-specific processing terms may supplement this notice for business customers.
END OF POLICY

Clear before live.

Every participant sees the applicable rate, frame, dates, disclosure wording and measurement method before approving a placement.

Join as creator Join as brand