Privacy at UGC Bakery · July 27, 2026

Privacy policy

Start free

What this means in practice

This privacy page explains the information used by the UGC Bakery website, free standalone Shopify product-shortlist app, brand dashboard, and managed creator-collaboration service. It describes why information is needed and the choices available to visitors and participating brands. The standalone app is separate from the dashboard and managed service. Separate accepted service terms may provide additional context for a specific engagement.

Information visitors provide

When a visitor chooses to send a shortlist request, we may record the brand name, store URL, niche, and work email, plus the request time and browser information. The dashboard uses a separate email sign-in flow. A request is not an accepted service engagement, a creator reservation, or permission to send marketing messages beyond the requested follow-up.

Visitors should provide only information needed to discuss a potential service fit. Passwords, one-time codes, access tokens, payment details, customer addresses, and other secrets should not be entered in the public form. An inquiry is separate from an accepted service engagement.

Optional measurement and advertising readiness

Optional measurement is off by default. If a visitor accepts it in Privacy choices, UGC Bakery records only the first landing path, referrer origin, campaign tags, and ad click IDs. It does not copy other query values, such as a name, email address, token, or payment information. Declining keeps essential website operation only.

We retain these limited measurement values for up to 13 months alongside a completed inquiry, sign-up, or purchase receipt so we can understand which entry points work. The current website does not include a Google tag, Google Ads account, or a request to an advertising provider. Any future provider connection must require both a configured identifier and an affirmative current choice.

Dashboard and service information

The brand dashboard and managed service may use brand and store details, product settings, creator and social information, creator contact details, pitch terms, and collaboration status. Records may also cover product approval, shipment and tracking, submitted content, partnership confirmation, quality control, and specific usage rights.

Dashboard access is intended to show a participating brand the information relevant to its service relationship. Creator contact details used for outreach are not presented as a public directory. Content and rights information remains tied to the applicable collaboration and accepted terms.

How UGC Bakery uses information

Information is used to review website inquiries, operate dashboard access, manage agreed creator outreach, record brand approvals, and keep collaboration milestones connected. It can also support product gifting, shipment follow-up, creator submissions, quality control, partnership confirmation, and time-bounded rights records.

Information may be used to keep the service secure, understand the state of a requested action, and resolve questions about access, gifting, fulfilment, tracking, or a collaboration record. Individual accepted terms govern the actual deliverables and responsibilities for an engagement.

Standalone Shopify shortlist and session data

The UGC Bakery Shopify app requests the product, order, draft-order, and discount permissions needed for an eligible approved creator gift and merchant-configured code. It uses only the minimum order information needed to associate a locally created gift or creator-code redemption, and keeps merchant and creator workflow records private.

Shopify app sessions and local connection records support authenticated access for the installed store. When the app is uninstalled, Shopify removes the app-owned shortlist, and UGC Bakery removes the matching local Shopify session and connection records for that installation. Dashboard session cookies, including email one-time-password sessions, belong to the separate managed creator-collaboration service and are not required for the standalone app.

Privacy and redaction choices and questions

Shopify customer-data-request and redaction webhooks are authenticated, their required identifiers are validated in memory, and the payload is then discarded without querying Shopify customer or order records or storing or logging the payload. A shop-redact request removes matching local Shopify session and connection records when no current installation exists. Merchants should continue to use Shopify's applicable privacy-request process for their store.

Use the fixed Privacy choices button to change an optional measurement choice. Send non-sensitive privacy questions to info@ugcbakery.com. Visitors and participating brands should not place a privacy request or personal-data payload in the public website form or email.

Ready when you are

Start your first five creator collaborations free.

Sign in with your work email to create your dashboard, choose a plan, and prepare your first creator brief.

Start free