nx8up is a marketplace: sponsors fund campaigns, studios fund playtesting engagements, and creators do the work and get paid. Running that means holding personal data — who you are, what you can do, what you delivered, and where the money goes. This page states what we hold, why we hold it, and how to have it changed or removed.
Who this policy covers
This policy applies to everyone who uses nx8up: creators, sponsors, studios, and visitors who have not signed up. Where something applies to only one of those, it says so.
What we collect
We collect what the marketplace needs in order to function, and it arrives from six places.
- Account and identity
- Your email address, username, and sign-in credentials are handled by Clerk, our authentication provider. We store your Clerk user id, your role — creator, sponsor, studio, or admin — and whether you have finished onboarding. We never see or store your password.
- What you tell us about yourself
- Whatever you enter during onboarding and in your profile: age, location, languages, content types and game categories, audience ranges, and — for testers — the operating systems you can test on, your timezone, and whether you are open to testing. Sponsors and studios also give us company and brand details.
- Connected gaming and video platforms
- If you link Twitch, YouTube, or Steam, we read public statistics about your channel or profile: handle and channel name, follower and subscriber counts, average views, broadcaster type, avatar, and — from Steam — the games you own and recently played, your playtime, and achievement progress for a game you are testing. Access and refresh tokens are stored encrypted and used only to refresh those statistics. You can disconnect a platform at any time.
- Work you do on the platform
- Applications, deal submissions and proof-of-work links, engagement submissions and session reports, survey and feedback answers, disputes, reputation events, and the notifications we send you.
- Payments and payouts
- Payments are processed by Stripe. Card and bank details go to Stripe directly — they never reach our servers. We store the identifiers Stripe gives us, along with amounts, fees, and status, so that campaigns and engagements can be funded, creators paid, and refunds issued.
- Technical and referral data
- Standard request data reaches our hosting provider as part of serving the site. If you arrive through a creator's affiliate link we record the click, whether it looked like a bot, and — only if you accepted analytics cookies — a random visitor id and a salted, one-way hash of your IP address used purely as a fraud signal. That hash cannot be reversed and is never used to identify you.
Why we use it
Every use below is one the marketplace cannot run without, or one you asked for.
- Matching creators to the campaigns and engagements they qualify for.
- Running the work itself: applications, submissions, acceptance, and feedback.
- Moving money — funding, platform fees, payouts, and refunds.
- Reputation, tiers, and the trust signals other users see.
- Notifications and emails about your account and the work you are part of.
- Fraud prevention, abuse handling, and keeping the platform secure.
- Measuring whether the product works — in aggregate, and only with your consent where a cookie is involved.
Our legal grounds
Where the GDPR or a similar law applies: most of what we do is necessary to perform our contract with you — running your account, the work, and the payments. Fraud prevention, security, and aggregate product measurement rest on our legitimate interests. Analytics cookies rest on your consent, which you can withdraw. Tax and accounting records are kept to meet legal obligations.
Who else sees it
We do not sell personal data and we do not share it for advertising. We do rely on processors to run the platform:
- Clerk — authentication and account management.
- Stripe — payments, payouts, and the identity checks a connected payout account requires.
- Vercel — hosting, and aggregate analytics that never receive an identifier.
- Our database host — where everything described above is stored.
- Twitch, YouTube, and Steam — only when you link one, and only to read the statistics you authorized.
Other users see far less. Sponsors and studios see the profile, platform statistics, reputation, and tester signals of creators relevant to their campaign or engagement, plus the work those creators submit. They never see your sign-in credentials or your payment details.
We may also disclose data where the law requires it, or to establish or defend legal claims.
Cookies
The platform sets very few cookies, and exactly one of them is optional.
- Sign-in session
- Set by Clerk to keep you signed in. Strictly necessary — the site cannot work without it.
- Language (NEXT_LOCALE)
- Remembers the language you chose, so the site renders in it on your next visit.
- Referral attribution (nx8_ref)
- Set when you follow a creator's affiliate link, so that creator is credited if you sign up. It carries a referral code, never an identifier for you, and expires after 30 days.
- Consent decision (nx8_consent)
- Remembers whether you accepted or declined analytics, so we do not ask again on every page. It carries a decision, never an identifier, and expires after 180 days — after which we ask again.
- Analytics visitor id (nx8_rv) — optional
- Set only if you accept, and only if you arrived through a referral link. It is a random value that lets us measure how many referred visitors reach sign-up. Declining costs you nothing: your referral is still attributed, and the creator who referred you is still credited.
To change your answer, clear this site's cookies and the banner will ask again. Declining analytics never affects your account, your payouts, or your reputation.
How long we keep it
Account and profile data is kept while your account exists. Records of completed work, payments, and payouts are kept longer, because tax, accounting, and dispute-resolution rules require it. Referral click and analytics visitor records are kept only as long as they are useful for measuring and protecting the referral programme. When you delete your account, the data attached to it goes with it, apart from records we are required to retain.
Your rights
Depending on where you live, you can:
- Ask for a copy of the personal data we hold about you.
- Correct anything inaccurate — most of it you can edit directly in your profile.
- Delete your account and the data attached to it.
- Withdraw analytics consent, or disconnect a linked platform, at any time.
- Object to or restrict processing that rests on our legitimate interests.
- Complain to your local data protection authority.
The fastest route for most of these is your own settings. For the rest, contact us and we will respond within the time your local law allows.
Age
nx8up is for adults. You must be at least 18 to hold an account, and we do not knowingly collect data from anyone younger. If you believe a minor holds an account, tell us and we will remove it.
Where the data goes
nx8up runs on providers that host and process data in several countries, including the United States. Where the law requires a transfer safeguard, we rely on those providers' standard contractual clauses.
How we protect it
Access to production data is limited to what running the platform requires. Platform access tokens are encrypted at rest, payment details never touch our servers, and IP addresses in referral records are stored only as salted one-way hashes. No system is perfect; if a breach affects you, we will notify you as the law requires.
Changes to this policy
We update this page whenever the platform changes what it collects or why. The date at the top is the date of the last change. Continued use after an update means you accept the revised policy, where local law permits.