Plekt.

Last updated on 26 September 2026

Privacy Policy

Only the Dutch version of this policy is legally binding. This English translation is provided for information only.

Plekt brings local businesses and creators together. To do that, we process personal data. On this page you can read, honestly and concretely, what we store, why we do it and how you stay in control of it yourself.

What data we collect

We only ask for what is needed to show your profile and make deals work. Concretely, that means:

  • Name and profile. Your name or business name, a bio, your city or region, your category and a profile photo.
  • Social links. The links to your public profiles on, for example, Instagram or TikTok that you add yourself.
  • Connected social accounts. If you connect an account, we receive your username, an account id and your follower or subscriber count from that platform. For platforms other than LinkedIn, this also includes the public metrics of your own posts that you link to a collaboration yourself. Read more below under “Connecting your social accounts”.
  • Verified reach. The follower count you display, through a connected account or through a screenshot you submit yourself for review.
  • Email address. For your login and important notifications about your account and your deals.
  • Signing in with Google. If you sign in with Google, Google gives us your name, your email address and your profile photo. We never see your Google password.
  • Activity on Plekt. Deals you post or respond to, messages in the chat and reviews you leave.
  • When you were last active. We record when you log in and when you last used Plekt. That is how we show in the chat whether someone is online. For a business, we also use it to pause its open deals when no one on the team has been active for 14 days. Our administrators can see when you were last active.
  • Two-step verification and your devices. If you turn on two-step verification, our processor Supabase stores the secret key of your authenticator app. We only keep your recovery codes in hashed form, so no one can read them back. Under Security you see which devices you are logged in on: the browser, the system and when you were last active there. Our administrators only see whether two-step verification is on, never your key or your codes.
  • A log of your actions. We record what happens on your account: a deal created or changed, an application submitted, withdrawn, accepted, declined or expired, content uploaded or delivered, a delivery approved, a report made, a failed attempt to connect a social account and whether someone did not show up or did not deliver. We do this so we can establish what actually happened when two users are in dispute, to prevent misuse and fraud and to be able to help you with support. This log is not visible to other users; only our administrators can read it.
  • Your address for a shipping Deal. If a business ships you a product, you give a delivery address and an email address for the confirmation when you apply. The business only sees them after it accepts you.
  • Push notifications. If you turn on notifications on your device, we store the address your browser issues for that, two keys to encrypt the message and the kind of browser. Sending runs through the push service of your browser or operating system (Google, Apple or Mozilla), which sees the address but not the content. If you turn notifications off, we delete that data.
  • No money is involved. Plekt is completely free today and every deal is a barter deal. So we process no payment data, no bank account numbers and no invoices, and we report nothing to the tax authorities. If that changes, we will update this page before it takes effect.

Your contact details stay hidden

We never show your phone number or email address to other users. All communication between a business and a creator runs through the in-app chat. That way your private details stay private and everyone can make arrangements safely within Plekt, without contact happening outside the platform.

Connecting your social accounts

You can voluntarily connect one or more social accounts to have your reach verified and displayed. This works with Instagram, Facebook, TikTok, YouTube, Pinterest and LinkedIn. Connecting happens through the platform's own official login page; we never see or store your password.

What we receive and use per platform:

  • LinkedIn. We use “Sign in with LinkedIn using OpenID Connect” and receive only your name and a profile id, so you can link your LinkedIn account to your Plekt profile. We do not read your posts, connections or followers.
  • Instagram, TikTok, YouTube and Pinterest. We receive your username, an account id and your follower or subscriber count. If you deliver content for a collaboration, we read the public metrics (views, likes and comments) of the posts you link yourself, to show the result to the business.
  • Facebook. As a business, you connect a Facebook Page you manage. We read the public data of that Page, such as the name and the number of followers, not your personal profile.

YouTube and Google. If you connect your YouTube account, Plekt uses the YouTube API Services to read your subscriber count and the public metrics of your videos. By connecting your YouTube account, you agree to the YouTube Terms of Service. The data we receive through Google is subject to the Google Privacy Policy. You can revoke Plekt's access to your Google data at any time through the Google security settings.

Plekt's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use this data only to verify your account, display your reach and substantiate the result of a collaboration. Our access is read-only: we never post, like, follow or send anything on your behalf and we do not sell or share this data with third parties for advertising.

The access keys (tokens) the platform gives us are stored securely on our servers. They are never visible to other users. You can disconnect an account at any time via Settings; we then delete the corresponding tokens. You can also always revoke access in the settings of the platform itself.

What we use your data for

We use your data to show your profile to the right people, to make matches between businesses and creators possible, to make the chat and notifications work and to prevent misuse. We do not sell your data and do not use it for third-party advertising.

Content you put on Plekt may also appear in our own communication: on our website, on our socials, in ads and in presentations. If your face or your voice is in it, that is personal data. We do this based on the right of use you give us in the terms. The business you made content for may also use it in its own advertising, paid ads included. If you do not want a specific piece in our advertising, email us at the contact address below.

The basis on which we do this

Privacy law asks us to state, for each purpose, what we rely on. For Plekt there are four:

  • To perform our agreement with you. Your account and profile, showing your profile to the right people, deals and applications, the chat and notifications. Without this data we simply cannot provide Plekt.
  • Because the law requires it. Keeping what we need to be able to show about a report and a moderation decision, and answering a lawful request from an authority. As long as Plekt is free there is no accounting or tax retention duty: there are no invoices and nothing is reported.
  • On the basis of a legitimate interest. The activity log, finding errors and outages, preventing misuse, fraud and spam. Also keeping the listings current: we pause the deals of a business that has not been active for 14 days. Our interest is keeping Plekt safe and reliable for everyone; we limit ourselves to what is needed for that and you can object to it (see “Your rights and control”).
  • With your consent. Cookies and measurement tools for statistics and connecting a social account to show your reach. Consent is always voluntary and you can withdraw it at any time, just as easily as you gave it; what we did before remains valid, but we stop immediately.

Who can access your data

Other users only see your public profile and what you share yourself. Within Plekt our administrators can see more and we would rather be honest about what that means.

  • Our administrators can view your account data, your activity log and reported messages when this is needed for support, a dispute or moderation. They can also export that data. Who does so is recorded in our log.
  • For support purposes, a member of the Plekt team can temporarily work inside your account, exactly as you see it, to find and fix a problem. We would rather say too much about this than too little: that person then has the same rights as you and can therefore also change or send something, and that happens in your name. We only do this to help you and never without reason. The start and end of every session are recorded, along with who it was, and the mode expires by itself after a short while. If you want to know whether this happened on your account, ask us via the contact address at the bottom.
  • We do not read the content of your conversations by default. We only look at a conversation if someone reports a message or during an investigation into misuse or fraud.
  • If someone reports a problem with a collaboration, a file opens and our admins can read the messages of that one collaboration so they can decide with the facts in hand. That is limited to the period of that collaboration, is only possible while the file is open, and every access is logged. Once a decision is made, nobody can view those messages any more.

Where your data is held

We deliberately choose processing in Europe. Your profile, your messages and your files are held by Supabase in Zurich, Switzerland. That is not an EU country, but the European Commission recognises Switzerland as offering an equivalent level of protection, so no extra formality is needed. Our servers that build the pages run in Frankfurt, and our error tracking and statistics also run on European servers.

Videos you upload also get a copy at Cloudflare, so that they play smoothly on a slow connection. The original stays at Supabase. Cloudflare serves that copy from the node closest to the viewer, so outside Europe that can be a server outside Europe.

Some of our service providers are companies from the United States, even where they process your data in Europe. Specifically, these are our email service Resend, our hosting partner Vercel and Cloudflare. For that transfer we rely on the European Commission's standard contractual clauses and, where the party is certified for it, on the EU-US Data Privacy Framework. If you would like to see a copy of those safeguards, just ask via the contact address at the bottom.

How we protect your data

We protect your data and sensitive data in particular such as your contact details and the access keys (OAuth tokens) of your linked social accounts, with the following measures:

  • Encryption in transit. All traffic between you and Plekt runs over an encrypted HTTPS/TLS connection.
  • Encryption at rest. Your data is stored encrypted (encryption at rest) at our database and storage provider.
  • Row-level access control. Our database enforces row-level security: sensitive data is readable only by its owner. Your contact details and your OAuth tokens are never world-readable and never visible to other users.
  • Protected tokens. The OAuth tokens of your linked accounts (including Google/YouTube) are kept in a restricted table that only you and, for support and moderation, our admins can read. They are written only through a trusted server-side path, never by the browser.
  • Least privilege, read-only. We request the narrowest possible access and use it only to show your reach and performance. We never post, like, follow or send anything on your behalf.
  • Deletion. If you unlink an account or delete your Plekt account, we erase the associated tokens. You can also revoke Plekt's access at any time in the security settings of the platform itself.

How long we keep your data

We keep your data as long as you have an account. If you delete your account, we erase your profile and your personal data within thirty days. Messages and deals that involve another user may be kept anonymously to the extent this remains necessary for the other party or for a legal obligation.

Getting your data deleted

Want us to delete your data? There are two ways. Delete your account in Settings, or email us at info@plekt.be with the subject “Deletion request”.

What happens then: we erase everything that points to you as a person. Your name, photo, bio, city, phone number, address and date of birth. Your @ is replaced by a neutral code, your profile is no longer findable and your email address becomes available again. Your connections with TikTok, YouTube, Instagram, Facebook, Pinterest and LinkedIn are cut: we revoke the access at the platform itself and delete the matching keys, so we can no longer pull anything about you. The same applies if you disconnect just one channel.

If our team called or emailed you as a creator, we kept a short note of it so we could help you properly. Those notes are deleted too. For a business, they belong to the business page and stay for as long as that page exists.

What stays, and why. Content you delivered through a deal stays with the business you worked with: a right of use was agreed in the terms and it keeps applying. The numbers of that content keep counting towards that business's results. The collaboration itself also stays, because it is just as much the other party's history. Plekt advertising that already features your content keeps running. We do not make new advertising with it.

Finally, we keep an encrypted fingerprint of your email address, together with any warnings or a suspension. That is an irreversible code and not an address: we cannot contact anyone with it, but it lets us recognise someone who was suspended trying to start over.

Your rights and control

You stay in charge of your data. Via Settings you can at any time:

  • view your data and see what we store about you;
  • correct or complete your profile;
  • download a copy of your data;
  • permanently delete your account and your data.

You also have three rights that you exercise with us rather than through a button. You can object to processing that rests on our legitimate interest, ask us to restrict processing while a dispute is running, and withdraw consent you have given (you change your cookie preferences yourself; you disconnect a linked social account in Settings). Email us for this via the contact address below; we reply within one month.

If something does not work through Settings, we are happy to help you via the contact address below. If you are unhappy with how we handle your data, you can always lodge a complaint with the Belgian supervisory authority: the Data Protection Authority, Drukpersstraat 35, 1000 Brussels. Naturally we would rather hear it from you first, so we can put it right.

Processors

Plekt is made possible and built by Let's Connect. This party processes data on behalf of Plekt to run and maintain the platform. In addition, we work with a limited number of specialised service providers:

  • Supabase (database, login and storage; servers in Zurich) and Vercel (hosting, servers in Frankfurt).
  • Cloudflare for playing videos: a copy of your video is stored there and served from their network.
  • The push service of your browser or device(Google, Apple or Mozilla), only if you turn on notifications on your device. That service sees your device's address, not the content of the notification.
  • Resend for sending emails (your email address and the content of the notification).
  • Sentry (EU servers) for error tracking, without session recordings and without unnecessary personal data.
  • PostHog (EU servers) for usage statistics, Vercel Analytics for visitor numbers and Microsoft Clarity for heatmaps and session replay. All three only start after you consent to statistics. Session replay is not a video of your screen: it is a reconstruction of the page along with your mouse movements, clicks and scrolling, with text you type masked. PostHog has that feature switched off; with Clarity we use it. If you withdraw consent, Clarity erases its cookies and stops measuring.
  • The social media platforms you connect yourself (see “Connecting your social accounts”), the European Commission's VIESservice (verification of businesses' VAT numbers) and Komoot (photon.komoot.io, servers in Germany), an address lookup service based on OpenStreetMap.
  • Synctomatefor the chatbot on our website and in the app. See “The chatbot” below for exactly what goes there.

We make agreements with every processor about the protection of your data and choose processing within the EU wherever possible.

The chatbot

There is a chatbot on our website and in the app. It is provided by Synctomate and runs on chat.plekt.be. When you are logged in, the chatbot can look up your own Plekt data to answer your question: your profile, your deals, your applications, your collaborations and so on. It can only read and never changes anything in your account.

For this the app gives the chatbot a key that is valid for fifteen minutes and can only retrieve your own data. When you log out, that key stops working immediately.

What goes to a language model. Your question, the knowledge base fragments that were found and the data the bot retrieved for you. This runs through the Vercel AI Gateway with Zero Data Retention: the model provider deletes the data after processing and does not use it to train its model. One step falls outside that: re-ranking the search results in the knowledge base happens without Zero Data Retention and outside the EU (United States and Canada). Only your question plus public knowledge base fragments go there, never the data from your Plekt account. Your question itself can be personal, for example when you mention a business name.

What does not go there. The content of your conversations with a business or creator. The chatbot can see that a conversation exists and with whom, but not what was written.

What Synctomate stores.Your question, the bot's answer and a summary of the conversation. That answer often repeats the data the bot retrieved, so assume that whatever the bot may look up ends up in that conversation history.

Deletion. If you delete your Plekt account, we pass that on to Synctomate automatically. They then erase your conversations, your messages, the stored memories, the quality signals, the analytics events and the knowledge base suggestions that came out of your conversations. Two things remain. They deliberately keep consent records, because it must remain demonstrable that consent was given or withdrawn. And conversations can produce aggregated insights that cannot be traced back to a person; to make that second sentence true, learning patterns across customers is switched off for our chatbot. A deleted row can also still sit in a database backup until that backup expires.

Contact

Do you have a question about your privacy or want to exercise a right? Email us at info@plekt.be. We respond as quickly as possible. This page explains how we work and is not legal advice.