Privacy Policy
Effective date: August 25, 2026
1. Introduction
Sherbet Solutions, Inc. (“Sherbet,” “we,” “us,” or “our”) operates the Sherbet platform at sherbet.io, a two-sided field-marketing marketplace that connects brands and marketing agencies (“Organizations”) with campus student ambassadors (“Students”). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our website, platform, and related services (collectively, the “Services”).
This Privacy Policy is a notice about our data practices, not a request for consent and not a contract. Where we rely on your consent for a particular activity, we ask for it separately and you may withdraw it as described below. The Services are also governed by our Terms of Service.
Our role as controller or processor
Sherbet acts as a controller or business when it determines why and how personal information is used, including for Student accounts and cross-Organization profiles, public-site visitors, billing, security, fraud prevention, legal compliance, and the other purposes described in this policy. When an Organization directs Sherbet to process personal information it controls — such as information about its personnel, prospects, campaign participants, tours, or leases — Sherbet may instead act as that Organization’s processor or service provider under an applicable Data Processing Agreement (“DPA”). In that situation, the Organization is responsible for its own privacy notice, lawful basis, and instructions, and requests about that Organization’s processing may need to be directed to it. The DPA is a business contract and does not replace this policy for processing where Sherbet determines the purposes and means.
2. Who This Policy Applies To
This policy applies to all visitors and registered users of the Services, including:
- Organization users: brand or agency employees who use Sherbet to create programs, manage campaigns, and engage student ambassadors.
- Student ambassadors: individuals who register on Sherbet to participate in brand programs, complete deliverables, and receive compensation.
- Visitors: individuals who browse sherbet.io without creating an account.
Where this policy distinguishes between these groups, we will say so explicitly. Otherwise, all provisions apply equally.
The Services are launched for use in the United States. Students must be U.S. residents, and Organization personnel may access the Services only while located in the United States for their Organization’s U.S. operations. An Organization’s place of incorporation does not change this geographic user restriction.
3. Information We Collect
3.1 Account & Profile Information
Information you provide when registering or updating your profile:
- Name, email address, and password (stored in hashed form)
- Phone number (required for SMS-enabled features)
- Profile photo
- Students only: school / university, graduation year, major, social media handles (Instagram, TikTok, Twitter/X, LinkedIn, etc.), short bio
- Organization users only: company name, industry, company size, website URL, business address, and billing contact
3.2 Program, Campaign & Event Activity
- Program enrollments, activity participation history, and deliverable statuses
- Event agreement details: event name, venue, date, quoted compensation, agreed scope, escrow payment amounts, and agreement signatures
- Deliverable submissions: photos, videos, content drafts, post links, and proof-of-work images
- Field task responses submitted via SMS (including MMS photo attachments)
- Attendance check-ins and completion records
- Performance metrics: scan counts, web traffic referrals, conversions, and commission data
3.3 Communications
- Messages sent between Organizations and Students through the platform (in-app message threads and SMS negotiations)
- Replies to automated SMS messages sent from our Twilio-managed phone numbers
- Feedback and support requests submitted to Sherbet
3.4 Payment & Financial Data
- Payment processing is handled by Stripe. We do not store credit card numbers, full bank account details, or card security codes on our servers. Stripe collects and stores payment instruments under its own privacy policy and PCI-DSS compliance program.
- We retain records of: invoice amounts, escrow amounts, subscription fees, payment dates, payment statuses, refund records, and Stripe transfer IDs for accounting and legal compliance.
- For student payouts, we facilitate transfers to Stripe Connect accounts. Stripe may require identity verification (KYC) information from Students, which is collected and held by Stripe directly.
- We may issue IRS Form 1099 to Students where required by U.S. tax law. To do that we collect a Form W-9 directly on the platform: your legal name, any business name, tax classification, home address, and your taxpayer identification number (SSN or EIN). This is collected by Sherbet, not by Stripe.
- We do not keep your taxpayer ID. Your SSN or EIN is used to complete your W-9 and is then discarded — Sherbet retains only the last four digits, so that you and our finance team can confirm which number is on file. The full number is held by Stripe, which collects it during payout onboarding and prepares your 1099 from it. We keep the rest of the W-9 (legal name, tax classification, and address) as the record that you certified it, and every administrative view of student tax records is logged.
3.5 Content Submissions & Uploaded Media
- Photos, videos, documents, and other media you upload are stored on Cloudflare R2 (see Section 7). Files that contain personal information — deliverable uploads, proof-of-work and SMS photos, profile photos, resumes submitted with role applications, and lease documents — are stored privately: they are not readable from a public address, and are served only through short-lived links that we generate for users who are authorized to view that specific file. Those links expire automatically, in no case more than 30 minutes after they are issued.
- Marketing material that we embed in outbound email — brand logos and property flyers — is served from a public address so that it renders in your email client. That material is supplied by Organizations and is not personal information about you.
- Brand logos and marketing assets uploaded by Organization users.
3.6 Affiliate & Referral Tracking Data
- Students enrolled in affiliate programs receive unique tracking links managed through Tapfiliate. Click data, referral conversions, and commission calculations associated with those links are shared with Tapfiliate (see Section 7).
- QR code scan events are logged with timestamp and associated ambassador.
3.7 Usage & Technical Data
We automatically collect certain technical information when you use the Services:
- IP address, browser type and version, operating system, device identifiers
- Pages and features accessed, timestamps, and session duration
- HTTP request logs, error logs, and API response times (retained for debugging and security)
- Cookies and similar tracking technologies (see Section 9)
3.8 Information We Receive From Third Parties
- If you connect a social media account (e.g., Instagram, TikTok) to the platform, we may receive basic profile information such as username and follower count via OAuth, subject to the privacy settings of those platforms.
- Payment status updates from Stripe webhooks (e.g., payment succeeded, refund processed).
- Publicly available social-profile information, such as handles and follower counts, from public social pages and search providers used for student discovery.
- Contact and engagement information supplied by an Organization when it invites you to a program or records its campaign, tour, or leasing activity in the Services.
4. How We Use Your Information
We use the personal information we collect for the following purposes:
- Providing and operating the Services: creating and maintaining accounts, facilitating program enrollment and deliverable review, processing payments and payouts, and managing event agreements.
- Transactional communications: sending confirmations, program invitations, deliverable reminders, deadline alerts, payment notifications, and agreement signature requests via email and/or SMS where you have provided your phone number.
- Platform communications between users: routing in-app messages and SMS-based event negotiations between Organizations and Students.
- Performance analytics: aggregating and reporting on deliverable completion rates, affiliate conversions, scan data, and campaign outcomes for Organization dashboards.
- Affiliate & commission tracking: attributing conversions and calculating commissions for student affiliate links via Tapfiliate.
- Fraud prevention & platform integrity: detecting and preventing fake deliverable submissions, unauthorized access, bot activity, and fee circumvention.
- Legal compliance & financial record-keeping: maintaining transaction records, responding to legal requests, satisfying tax obligations, and complying with applicable laws.
- Platform improvement: analyzing usage patterns to improve existing features, fix bugs, and develop new functionality. We rely on aggregated or de-identified data for this purpose where practicable.
- Safety & security: monitoring for and investigating security incidents, unauthorized access attempts, and account abuse.
5. Legal Bases for Processing
Where applicable law requires a legal basis for processing personal data (e.g., the EU General Data Protection Regulation), we rely on the following:
- Performance of a contract: processing necessary to create your account, execute program agreements, process payments, and deliver the Services you requested.
- Legitimate interests: operating and improving the platform, fraud prevention, security monitoring, and analytics, where these interests are not overridden by your privacy rights.
- Legal obligation: retaining financial records, responding to lawful government requests, and complying with tax reporting requirements.
- Consent: sending marketing or promotional messages by email or SMS, and processing data for purposes that require your explicit opt-in. Marketing email is sent only to people who asked for it — we record the opt-in, when it was given, and which form it came from. Transactional messages about your account, your work, or your money are sent on the other bases above and are not marketing. You may withdraw consent at any time, from any message or from your settings, without affecting the lawfulness of prior processing.
6. Data Sharing & Disclosure
We do not sell your personal information. We share it only in the following circumstances:
Between Platform Users
- Organization users can view the profile information of Students enrolled in their programs, including name, school, social handles, and submitted deliverables.
- Students can view the name, logo, and program details of Organizations who have invited them or whose programs they have discovered.
- Event agreement data (compensation, scope, deliverable details) is shared between the Organization and Student who are party to that agreement.
Service Providers
We share personal data with third-party vendors who process it on our behalf (see Section 7). These vendors are contractually bound to use personal data only to provide services to us and to apply appropriate security measures.
Legal & Regulatory Disclosures
- We may disclose personal information if required by law, court order, subpoena, or government authority.
- We may disclose information to protect the rights, property, or safety of Sherbet, our users, or the public, for example to investigate fraud or respond to a security incident.
Business Transfers
If Sherbet Solutions, Inc. undergoes a merger, acquisition, asset sale, or bankruptcy proceeding, personal information may be transferred as part of that transaction. We will provide notice via email or an in-app notification before your personal information is transferred and becomes subject to a different privacy policy.
We do not sell your personal information to third parties.
7. Third-Party Service Providers
We use the following third-party providers to operate the platform. Each operates under its own privacy and security practices; links to their privacy policies are provided for reference.
- Stripe (privacy policy): payment processing, payouts to students via Stripe Connect, and identity verification for payout recipients. Stripe is PCI-DSS Level 1 certified and does not allow Sherbet to access full card numbers or bank account details.
- Twilio (privacy policy): SMS delivery for program reminders, event negotiations, and bot interactions. Twilio retains message logs in accordance with its data retention policy.
- SendGrid (Twilio) (privacy policy): transactional and operational email delivery (invitations, reminders, notifications). Email content is logged by SendGrid for deliverability tracking.
- Tapfiliate (privacy policy): affiliate link generation, click tracking, and commission attribution for ambassador programs. Click and conversion data associated with student affiliate links is shared with Tapfiliate.
- Cloudflare R2 (privacy policy): cloud object storage for uploaded media (deliverable photos, proof-of-work images, profile photos, resumes, lease documents, brand assets). Files containing personal information are stored privately and released only through expiring, individually-generated links, as described in Section 3.5.
- MongoDB Atlas (MongoDB, Inc.) (privacy policy): managed cloud database hosting for all platform data. Atlas is deployed in a dedicated cluster and subject to MongoDB’s data processing agreements.
- Railway (privacy policy): backend API hosting and cron job execution. Application logs, environment variables, and process output are retained by Railway.
- Vercel (privacy policy): frontend hosting, CDN delivery, and edge network. Vercel may collect IP addresses and request metadata for performance and security.
- Google Cloud Vision (privacy policy): automated image moderation. Images you upload (deliverable photos, proof-of-work images) may be sent to Google’s SafeSearch API to screen for inappropriate content before they are shared with Organizations.
- Google Workspace (Sheets) (privacy policy): waitlist entries and campus role applications (including name, contact details, and resume/LinkedIn links) are synced to access-restricted spreadsheets for internal review.
- Expo (privacy policy): mobile push notification delivery. Your device push token and notification content are transmitted through Expo’s push service when you use the Sherbet mobile app.
- Instagram (Meta) and TikTok APIs (privacy policy): only if you choose to connect a social account, we exchange OAuth tokens with the platform and retrieve the profile and post metrics you authorize. Tokens are stored encrypted and deleted when your account is deleted or the connection is removed.
- SearchAPI.io (privacy policy): retrieval of publicly available social profile information (handles and follower counts) used for discovery and catalog features.
- Redis (managed cache): short-lived operational data (rate limits, queues, cached lookups) used to run the platform.
We review the data practices of our service providers and require them, by contract, to handle personal data consistently with this policy and applicable law.
Changes to this list. Before we add a new service provider that will process your personal data, or replace one on this list, we will update this section and note the change on the effective date above. If you have a data processing agreement with us, we will give you advance notice as that agreement requires, and you may object.
8. SMS / Text Messaging
By providing your mobile phone number and opting into our SMS program, you consent to receive text messages from Sherbet for the following purposes:
- Program invitations and enrollment confirmations
- Deliverable deadline reminders and proof-submission prompts
- Event negotiation messages from Organizations
- Agreement ready and signature request alerts
- Payment confirmation and payout release notifications
- Account security notifications (e.g., password reset)
Message frequency varies based on your program participation. Standard message and data rates may apply.
- Reply STOP at any time to opt out of all SMS messages. You can also disable SMS notifications in your Profile settings under “Notification Preferences.”
- Reply HELP for assistance, or contact us at general@sherbet.io.
- Carriers are not liable for delayed or undelivered messages.
- Opting out of SMS will not affect in-app notifications or email communications unless you separately adjust those preferences.
We use dedicated phone numbers from a pool managed by Twilio. Reply messages you send may be processed by automated systems to record deliverable submissions or confirm attendance. For event negotiations, your replies are routed to the applicable Organization user.
8A. Automated Decision-Making & AI
We use one automated system that can affect you directly. Images you upload as deliverables or proof of work are screened by Google Cloud Vision SafeSearch before they are shared with an Organization, to detect adult, violent, or otherwise inappropriate content.
Because a rejected submission can delay or prevent payment for that work, you have the right to a human review of any automated rejection. Contact us at general@sherbet.io and a member of our team will review the submission themselves, tell you the outcome, and reinstate it if the automated screen was wrong. If you are in the EEA or UK, this is your right under Article 22 of the GDPR; we extend the same right to everyone.
Beyond image screening, we do not use automated decision-making that produces legal or similarly significant effects. Program matching, leaderboards, and analytics are descriptive: they surface and rank information for human users, who make the decisions.
We do not use your content to train AI models, and we do not license it to anyone else for that purpose. Sentiment labels shown on brand feedback are produced by a simple keyword rule, not a machine-learning model, and are never used to make a decision about you.
9. Cookies & Tracking Technologies
We and our service providers use the following types of tracking technologies:
- Strictly necessary cookies: session tokens and authentication cookies required to keep you logged in and secure your account. These cannot be disabled without breaking core platform functionality.
- Functional storage: preferences you set yourself — a collapsed sidebar, the last program you viewed, a dismissed prompt — kept in your browser so the interface behaves the way you left it. These are not used to identify or track you and are not shared with anyone.
- Analytics: we collect first-party usage data (pages visited and features used, associated with your account) to improve the platform. These records are retained for no more than 90 days, are never shared with advertising networks, and are not used for cross-site advertising. We do not use any third-party analytics, session replay, or advertising trackers.
- Affiliate tracking: affiliate link clicks and conversions are attributed server-side through Tapfiliate. We do not place Tapfiliate scripts, pixels, or cookies in your browser.
Most browsers allow you to block or delete cookies through your browser settings. Blocking strictly necessary cookies will prevent you from logging in. We do not use cookies for behavioral advertising or sell cookie-based data to advertising networks.
Why you are not asked to accept cookies. We do not show a cookie banner because we do not place anything on your device that would require your consent: no advertising or analytics cookies, no third-party tags, and no cross-site tracking. What we do store is limited to keeping you signed in and remembering preferences you set yourself. Our usage analytics are recorded on our own servers against your account, not through anything stored in your browser. If we ever introduce tracking that requires consent, we will ask for it first.
Global Privacy Control. Some browsers send a Global Privacy Control (GPC) or “Do Not Sell or Share” signal. That signal is a request to opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell or share personal information for that purpose for any user, whether or not a signal is sent, so there is nothing for the signal to switch off. If our practices ever change, we will honor GPC signals and update this section before that change takes effect.
10. Data Retention
- Active accounts: We retain personal data for as long as your account is active or as needed to provide the Services.
- Account deletion: When you delete your account, we promptly anonymize and scrub your personal information. Your name, email, phone number, and social media handles are replaced with non-identifying placeholders (e.g.,
deleted_[timestamp]@sherbet.io), and we delete your demographics, addresses, school and work profile details, follower counts, profile photo (including the stored file), device push tokens, and any connected social account tokens. Your program activity history may be retained in this anonymized form to preserve program integrity records for Organizations. - Service providers and backups: Where required, we instruct service providers that hold personal data for us to delete it as well. Residual copies may remain temporarily in access-restricted backups until they are overwritten through the provider’s ordinary backup cycle. We do not use backup copies for ordinary business purposes, and if a backup is restored we re-apply completed deletion requests.
- Tax documentation: If you have received payouts, your W-9 information (excluding your taxpayer ID, which we do not keep) and payment processor references are retained with our financial records for the period below; if you were never paid, they are deleted with the rest of your personal data.
- Financial records: Payment records, invoice data, escrow records, and related financial documents are retained for a minimum of 7 years from the date of the transaction to satisfy U.S. tax and accounting obligations, regardless of account deletion.
- Communications & logs: SMS message logs are subject to Twilio’s retention policy, and inbound messages tied to event threads are stored on the platform as part of those records. Product analytics events are retained for no more than 90 days, and security event logs for no more than 13 months. Administrative and payment audit logs are retained as long as needed for security, fraud investigation, and financial-integrity purposes; payment audit records follow the financial-records retention period above.
- Uploaded media: Your profile photo is deleted from storage when you delete your account. When a deliverable is deleted by the sponsoring Organization, every file attached to it — including the pre-watermark originals of any photos you sent by text — is deleted from storage at the same time. Campaign deliverables that have not been deleted are business records licensed to the sponsoring Organization and are retained in anonymized association after account deletion.
- Organization accounts: When an Organization closes its account, its business identity (legal name, billing address), its stored logo and brand imagery, and the personal information of every member are removed, and all members are signed out. Invoices, payments, and escrow records are retained under the financial-records period above.
See our standalone Data Deletion Policy for step-by-step request instructions and a summary of what is deleted, anonymized, or retained.
11. Your Privacy Rights & Choices
All Users
- Notification preferences: you can control which types of in-app and email notifications you receive from your Profile settings (for Students) or Organization settings (for brand users).
- SMS opt-out: reply STOP to any SMS or disable SMS in your Profile notification preferences.
- Contactability settings: Students can restrict which Organizations are permitted to contact them through the platform.
- Account deletion: Students may permanently delete their account from the Account tab of Profile settings. Organization administrators may close their organization’s account from Organization settings, which removes the personal information of every member. Deletion triggers immediate anonymization of personal data (see Section 10).
California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have the right to:
- Know & access: request a copy of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom it has been shared.
- Delete: request deletion of your personal information, subject to exceptions (e.g., legal retention obligations, completing a transaction, security purposes).
- Correct: request correction of inaccurate personal information we hold about you.
- Opt out of sale / sharing: we do not sell or share personal information for cross-context behavioral advertising; this right is satisfied by our current practices.
- Non-discrimination: we will not deny you Services, charge you different prices, or provide a lower quality of service because you exercised a CCPA right.
EEA, UK & Swiss Residents (GDPR / UK GDPR / FADP)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights. Swiss residents may also contact the Federal Data Protection and Information Commissioner (FDPIC):
- Right of access: obtain a copy of your personal data and information about how it is processed.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) request deletion of your data where there is no overriding legal basis for retention.
- Right to restriction: request that we restrict processing of your data in certain circumstances.
- Right to data portability: receive a machine-readable copy of personal data you have provided to us and, where technically feasible, have it transmitted to another controller.
- Right to object: object to processing based on legitimate interests, including profiling.
- Right to withdraw consent: withdraw consent at any time where consent is our legal basis, without affecting processing that was lawful before the withdrawal.
- Right to lodge a complaint: you have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK or the relevant EU data protection authority).
To exercise any of the rights above, contact us at general@sherbet.io. We may need to verify your identity before fulfilling a request. Response times differ by jurisdiction, and we apply whichever is shorter for you:
- California (CCPA): within 45 days, with a possible 45-day extension for complex requests, on notice to you.
- EEA & UK (GDPR): within one month, extendable by up to two further months for complex or numerous requests, on notice to you within that first month.
- Everywhere else: within 45 days.
Requests are normally free. If we do not act on a request, we will explain why and tell you about any applicable right to appeal, complain to a supervisory authority, or seek a judicial remedy. We will also notify recipients of a correction, erasure, or restriction where applicable and reasonably possible.
12. Children’s Privacy
The Services are intended for users who are 18 years of age or older, and creating an account requires you to confirm that you are. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from someone under 18, we will delete that information and close the account. The Services are not directed to children under 13, and we do not knowingly collect any information from them.
If you believe we have inadvertently collected information from a minor, please contact us immediately at general@sherbet.io.
13. Data Security
We implement reasonable technical, administrative, and organizational security measures to protect your personal information from unauthorized access, use, alteration, disclosure, or destruction. These measures include:
- Encryption at rest: sensitive credentials (API keys, third-party access tokens) are encrypted using AES-256-GCM before being stored in the database.
- Encryption in transit: all data transmitted between your browser and our servers is protected using HTTPS/TLS.
- Authentication: passwords are stored using a strong one-way hashing algorithm. We support two-factor authentication (2FA) for added account security.
- Access controls: access to production systems and personal data is restricted to authorized Sherbet personnel on a need-to-know basis.
- Audit logging: administrative actions affecting user data are recorded in an audit log with timestamps and actor identity.
- Payment security: card data is handled exclusively by Stripe, a PCI-DSS Level 1 certified processor. Sherbet servers never receive or store raw card numbers.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach that affects your rights or freedoms, we will notify affected users as required by applicable law.
14. International Data Transfers
Sherbet is based in the United States. If you access the Services from outside the United States, your personal information will be transferred to and processed in the United States, which may have data protection laws different from those in your jurisdiction.
Our Services are directed to and launched for use in the United States. Students must be U.S. residents, and Organization personnel may use the Services only while located in the United States for U.S. operations. We do not currently offer the Services to people located in the United Kingdom, the EEA, or Switzerland.
If we later permit use by people in those locations, we will assess the applicable territorial-scope, representative, and international-transfer requirements before that processing begins. Where required, we will implement an appropriate transfer mechanism, such as the UK International Data Transfer Addendum, European Commission Standard Contractual Clauses, or the Swiss addendum, and enter into an appropriate data processing agreement. For more information, contact us at general@sherbet.io.
An Organization’s contracting entity may also have controller, processor, or international-transfer obligations even when its authorized users and the individuals whose information is processed are in the United States. We address those customer-specific obligations in the applicable DPA and transfer documents before the affected production processing begins.
Our third-party service providers (Stripe, Twilio, MongoDB Atlas, Cloudflare, Vercel, Railway) may also process personal data in their own jurisdictions. Each maintains its own transfer mechanisms and compliance certifications as described in their respective privacy policies.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. For material changes that meaningfully affect your rights or how we use your data, we will notify you via email and/or an in-app notification at least 30 days before the changes take effect.
The “Effective date” at the top of this page reflects when the policy was last updated. Where a change requires consent or a new contractual agreement, we will ask for it separately. You may stop using the Services and close your account if you object to a change.
16. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
Sherbet Solutions, Inc.
Controller for the Sherbet-determined processing described in this policy
Customer service: (650) 815-9473
Email: general@sherbet.io
We will acknowledge receipt of your inquiry within 5 business days and provide a substantive response within the timeframe that applies to you under Section 11 — one month for EEA and UK residents, 45 days otherwise.