Privacy Policy
Last updated · July 17, 2026
How Delivvo collects, uses, stores, and protects personal data across the product and client portals.
This Privacy Policy explains how Delivvo collects, uses, stores, shares, and protects personal data when you use our website, dashboard, private client portals, the Cutroom desktop application, and related services. It applies to freelancers, agency users, invited client users, Cutroom licence holders, and visitors to delivvo.io.
This policy is written to reflect Delivvo's current product and operating model. Because Delivvo serves users in multiple regions, this policy is intended to account for the UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data (the "UAE PDPL"), the EU General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
Scope and roles
When Delivvo collects and uses personal data for account creation, authentication, product operations, support, billing administration, and security, Delivvo acts as a controller or business for that information.
When a freelancer or agency uses Delivvo to upload client information, share files, send contracts or invoices, and manage communications inside a project portal, Delivvo generally acts as a processor or service provider on behalf of that freelancer or agency. In that situation, the freelancer or agency decides what client data to upload, why to use it, and how long to keep it. If you are a client user and want to ask questions about project-specific data, you should first contact the freelancer or studio that invited you to the portal.
Cutroom. Cutroom is our desktop video editor, sold at delivvo.io/cutroom as a one-time purchase. It is a separate product from the Delivvo platform and carries its own Cutroom Licence Agreement, which is the contract for the software itself. This Privacy Policy is what that agreement points to for personal data, and it covers Cutroom in full. For everything we hold about a Cutroom licence, Delivvo is the controller. Cutroom is also something you buy from us outright, so for that sale we are the seller, the same as we are for a Delivvo subscription. Neither has anything to do with the money your clients pay you, which we never touch. See Cutroom licensing data below for what the software sends us, which is licensing traffic and nothing else.
Personal data we collect
We collect different categories of personal data depending on how you use Delivvo.
Information you provide directly
If you create a Delivvo account, we may collect:
- your name
- email address
- password or authentication credentials
- business name
- profile details such as tagline, website, discipline, logo, or avatar
- plan selections, onboarding answers, and support requests
If you are invited to a client portal, we may collect:
- your name
- email address
- optional company name, phone number, or notes provided by the freelancer or by you
- information you enter into messages, approvals, remarks, uploads, contracts, or intake responses
If you contact support, request a demo, ask for a refund, or execute a DPA, we may collect the information you provide in those requests, including business contact details and correspondence records.
Project and file data
Delivvo is designed to host business workflow data. That means we may store:
- project titles, descriptions, deadlines, milestones, and status fields
- client records created by freelancers
- contracts, invoices, proposals, deliverables, and comments
- files uploaded by freelancers or client users, including metadata such as file name, size, upload time, and project association
- approval records, signature names, timestamps, and related workflow history
Project messages
Delivvo runs a two-way message thread on every project so freelancers and clients can communicate inside the workspace instead of email. Message bodies are end-to-server encrypted: the text is encrypted with AES-256-GCM before it is written to our database, using a key that lives in our server environment configuration and never in the database itself. Anyone with read access to the database table (including ourselves running operational queries) sees ciphertext only. The plaintext is decrypted in memory at the moment a request is served and is shown only to the authenticated freelancer and to the authenticated client who is a participant in that project.
We do not read your messages for advertising, model training, content moderation, or analytics. We do not share them with any third party. Our staff does not have a "view a thread" tool and would have to take a deliberate operational action involving the encryption key to read message content; we do that only where required by law (for example, a valid court order) or where it is strictly necessary to investigate abuse of the service.
Email notifications for new messages do not include the message body. They tell the recipient that a new message arrived and link to the portal where the encrypted body is decrypted for reading. This keeps the content out of the email-delivery pipeline (Resend) and out of the recipient's mailbox.
Message bodies remain encrypted until the corresponding project, the freelancer's workspace, or the user account is deleted; at that point the message rows are deleted alongside their parent records on the timelines described in Data retention below.
Contract signing audit trail
When a client signs a contract through a Delivvo signing link, we capture additional fields server-side at the moment of signing as part of the legal audit trail described in our Terms of Service:
- the typed name and, when supplied, the drawn signature image
- the signing timestamp in coordinated universal time (UTC)
- the IP address from which the signing request was submitted
- the User-Agent string presented by the signer's browser
- a best-effort approximation of country, region, and city derived from the IP address through a third-party IP-geolocation lookup
- a SHA-256 fingerprint computed over the contract content, the signer's typed name, the IP address, and the signing timestamp
We collect this information to provide a meaningful evidence record that a contract was signed, by whom, and from where, and to allow after-the-fact detection of edits to the contract content. The audit trail is rendered as part of the signed PDF, retained alongside the contract for the lifetime of the contract record on Delivvo, and disclosed to: (a) the freelancer or studio that owns the project, (b) the client who signed, where they have authenticated access to the relevant portal, and (c) Delivvo personnel who need access for support, security, or compliance reasons.
Approximate geolocation is not represented as authoritative. It is derived from the IP address and may be incorrect. The IP address itself is the legal anchor for location and is what we record as canonical.
The legal basis for capturing this audit trail is our legitimate interest (and yours) in maintaining a meaningful evidentiary record of consent to signed agreements, and the performance of the contract between you and Delivvo. Where you are an EU/UK data subject acting in your individual capacity, our interest is balanced against your right to object. We will not process the audit trail for any purpose other than dispute resolution, security, fraud prevention, and the operation of the signing flow itself.
Billing and subscription data
Delivvo uses Stripe to process subscription payments, custom-plan billing, and related transactions. When you subscribe to a paid plan or are otherwise charged, we may collect and store:
- plan, subscription status, trial status, renewal dates, and billing references
- invoices, amounts, and payment status data
- customer IDs and subscription IDs from Stripe
We do not store full card numbers or other raw payment credentials on our own systems. Card data is collected and processed by Stripe under Stripe's own privacy and security practices.
If you buy a Cutroom licence, that is a one-time purchase from us rather than a subscription, and we are the seller. The payment itself is taken on Stripe's own hosted checkout page, where Stripe collects your card details and, where the card requires one, a billing address, under its own privacy notice. What we keep is the email address on your account, Stripe's checkout-session and payment identifiers, and the licence we issue against your account. We do not store your card number or your billing address.
Technical and usage data
We automatically collect limited technical and operational data when you use Delivvo, such as:
- IP address or approximate network information
- browser type, device type, operating system, and language settings
- timestamps for logins, portal access, file activity, and workflow events
- server logs, error logs, and audit trails
- cookie or session identifiers used to keep you signed in or remember preferences
We use this data to operate the service, maintain security, investigate abuse, and improve performance.
The list above describes the website, the dashboard, and the client portals, meaning the things you reach through a browser. The Cutroom desktop application is a different piece of software and sends us different data. It is covered on its own below.
Cutroom licensing data
Cutroom runs on your computer. Your footage, your projects, and your exports stay there. We do not upload, receive, view, or store your media, and we never see the API keys you give the app for third-party AI or stock-media providers, because those are encrypted on your own device and are never sent to us. What does reach us is licensing traffic, limited to what a licence needs in order to work:
- the email address on your account
- an opaque fingerprint of each computer you activate, which identifies a machine to us without describing it
- your licence key, its status, the plan, and the version of the app
- the time of each activation and of each later licence check
- the IP address and approximate location (country and city) of each activation and licence check
- what the app reports about its own integrity, which is how we learn that a copy of the software has been modified
- your acceptance of the Cutroom Licence Agreement: the version you accepted, the time you accepted it, the drawn signature you sign it with, an identifier for the device you signed on, the IP address and approximate location (country, region, city) you accepted it from, and the User-Agent string of the app or browser you accepted it in
The location is approximate. It is derived from the IP address by the network that serves our site, not by a separate lookup service, and it identifies a city and a country, never an address or a person's whereabouts. We record it only for licence holders who have accepted version 1.2.0 or later of the Cutroom Licence Agreement, which is the version that first discloses it. If you accepted an earlier version and have not accepted that one, your licence checks are recorded with no location on them at all.
We do not keep a record of every check. The app checks in regularly, and we write a record only when the check carries something new: a machine we have not seen, a different country, a different network, or a change in what the app reports about itself. Every activation writes one. When nothing changes, we write at most one record a day for each computer.
We use this data for one purpose, which is to tell whether a single licence is being used by more than one person. That is what section 3 of the Cutroom Licence Agreement does not allow, and it is the only thing these records are read for. Our checks may flag a licence for a person to review. A flag does not affect your use of the software: nothing is blocked, paused, slowed, or withheld because a licence has been flagged, and no automated process revokes anything. Suspending or revoking a licence is always a decision a person makes.
Buying Cutroom does not create a Delivvo workspace for you, and it does not put you on any Delivvo plan. If you never open the platform, we hold nothing about you beyond what is listed here and the purchase record described above.
How we use personal data
We use personal data for the following purposes:
- to create, maintain, and secure user accounts
- to authenticate freelancers and invited client users
- to host project portals and display project content to authorized users
- to send transactional emails such as login links, one-time passcodes, invoice reminders, portal invites, support responses, and product notices
- to generate contracts, invoices, PDFs, signatures, and approval records
- to enforce plan limits, storage caps, and abuse-prevention controls
- to issue Cutroom licences, verify them when the app checks in, and tell whether one licence is being used by several people
- to respond to support tickets, disputes, and legal requests
- to comply with applicable law, defend our rights, and maintain audit records
- to improve product quality, reliability, and security
We do not use the product data you store in Delivvo to build advertising profiles about you, and we do not sell your personal information.
Where we send marketing or broadcast emails, every such message includes an unsubscribe link, and you can opt out at any time without affecting your account. Transactional and service emails (such as login links, one-time passcodes, invoice reminders, portal invites, security notices, and support responses) are necessary to operate your account and are not subject to that unsubscribe link.
Legal bases for processing
Depending on your location and the context, Delivvo relies on one or more of the following legal bases:
- Contractual necessity. We process personal data as needed to provide Delivvo, maintain accounts, operate project portals, and perform our obligations under our Terms or another contract with you.
- Legitimate interests. We process data where necessary for security, fraud prevention, service reliability, abuse prevention, product administration, and internal analytics that do not override applicable rights.
- Consent. We rely on consent where required, such as when you voluntarily provide certain optional information or where local law requires consent for particular processing.
- Legal obligation. We may process data to comply with tax, accounting, law-enforcement, court-order, sanctions, consumer-protection, or data-protection obligations.
For users in the UAE, Delivvo intends to process personal data consistently with the UAE PDPL. For users in the EU or EEA, Delivvo intends to process personal data consistently with the GDPR. For California residents, Delivvo provides the notices in this policy to satisfy applicable CCPA disclosure requirements.
Delivvo's operator is a UAE-registered freelance entity holding a Freelancer Licence issued by the Abu Dhabi Department of Economic Development (ADDED) via the TAMM platform. The UAE is the controller's primary place of establishment for purposes of this policy. The same entity operates Cutroom.
When a freelancer's client pays an invoice, the payment is processed by the gateway the freelancer connected to their own account (Stripe, PayPal, Tap, Telr, PayTabs, or Checkout.com). For those payments Delivvo is not the merchant of record, takes no percentage, and does not store raw card data. Those data flows are governed by the respective gateway's own privacy notice. The only money that is ours is what you pay us directly: your Delivvo subscription, and a Cutroom licence if you buy one. Stripe charges both of those on our behalf, and for them we are the seller.
Cookies and similar technologies
Delivvo uses a small set of cookies and similar technologies to operate the service and remember user preferences. These include authentication cookies, client portal session cookies, and theme-preference cookies. At the time of this policy, Delivvo does not use analytics cookies or advertising cookies on the public product experience.
Examples of cookies or local storage values that may be used include:
sb-access-tokenandsb-refresh-tokenfor authenticated freelancer sessions, including the sign-in that a Cutroom purchase runs throughportal_sessionfor authenticated client portal access after OTP verificationdlv_workspaceto remember which workspace you are viewing, for people who belong to more than onedelivvo_localeto remember whether you read the site in English or Arabicdelivvo_impersonate, an admin-only cookie set during an active, audited support-impersonation session in which a Delivvo administrator views an account to provide support
Your theme and your display currency are not cookies. They are saved in your browser's local storage, which stays on your device.
When a client pays an invoice through a portal, Stripe's payment form is loaded into the page and Stripe sets its own cookies for fraud prevention, under Stripe's privacy notice rather than ours. The Cutroom desktop application is not a browser and sets no cookies.
Development-only cookies may also exist on local or demo environments, but they are not intended for production users.
For more detail, please see our Cookie Policy.
How we share personal data
We share personal data only where necessary to operate Delivvo, comply with law, or protect rights and safety. We may share personal data with the following categories of recipients:
- service providers and infrastructure vendors that host, authenticate, deliver email, process payments, or support the service
- professional advisers such as lawyers, auditors, or insurers where needed for legitimate business purposes
- law enforcement, regulators, courts, or other third parties when required by law or to protect Delivvo, our users, or the public
- a buyer, investor, or successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections
We do not sell personal data. We also do not share personal data for cross-context behavioral advertising as those terms are commonly used under California privacy law.
Current subprocessors
Delivvo currently relies on a limited set of subprocessors and infrastructure providers. These may include:
- Supabase for database hosting, authentication, and file storage. Delivvo's current Supabase stack is configured in the
ap-southeast-1region. - Vercel for application hosting and content delivery, where applicable. Vercel's network is also what tells us the approximate country and city behind a request, from the IP address, for the display currency you are shown and for the Cutroom records described above. That is a property of the connection we already have, not a lookup sent to anyone else.
- Resend for transactional email delivery.
- Stripe for the money you pay Delivvo directly: subscription billing, custom-plan billing, and one-time Cutroom licence purchases. Stripe is not used to process payments between freelancers and their clients, and Delivvo takes no part of those.
- ipapi.co for best-effort geolocation in the contract-signing audit trail, and only there. We look up the signing IP address once, at the moment a contract is signed.
- Sentry for error monitoring and application performance diagnostics.
Delivvo's Supabase project also hosts a small, unrelated application built by the same operator. Each application keeps its data in its own database schema, with row-level security on every table, so neither application's users can reach the other's records. The two share Supabase's authentication layer, which is how Supabase is designed to work: if you happened to hold an account in both, your login record would be the same row. Nothing else crosses between them. No Delivvo project, file, message, invoice, or client record is available to that application or to the people using it.
Payments that a freelancer's clients make flow through the payment gateway the freelancer connects to their own account (Stripe, PayPal, Tap, Telr, PayTabs, Checkout.com, or a manual method such as IBAN, Wise, or Payoneer). Those gateways act as independent controllers or processors of the payer's data under their own privacy notices. Delivvo is not the merchant of record, does not hold those funds, and takes no percentage of them.
We may update our provider list from time to time as the product evolves. If we add materially new providers that affect how data is handled, we will update this policy.
International transfers
Because Delivvo uses cloud providers and serves users in multiple jurisdictions, personal data may be processed in countries other than the country where the user is located. This may include the UAE, Singapore, the United States, and other locations where our providers operate.
When applicable, we take steps intended to support lawful transfers, such as using contractual commitments, vendor data-processing terms, and other safeguards appropriate to the transfer and the roles of the parties. If you are in the EU or EEA, you may contact us for additional information about relevant transfer safeguards.
Data retention
We retain personal data for as long as necessary for the purposes described in this policy, including to provide the service, maintain account continuity, support the freelancer-client workflow, comply with law, resolve disputes, and enforce our agreements.
As a general rule:
- account and workspace data is kept while the account remains active
- activity-log history is retained according to the account's plan: 7 days on Free, 30 days on Starter, 1 year (365 days) on Pro, and 3 years (1095 days) on Agency and on Custom plans. A daily job enforces this, and a downgrade takes effect on the next run
- uploaded files are retained for the life of the project and account, subject to the storage caps that apply to the account's plan
- the record of each transactional email we sent you (recipient, subject, and delivery status, never the message body of a project message) is kept for 365 days
- if an account is deleted, we aim to remove associated personal data from active systems within 30 days, unless we must retain some records longer for legal, tax, fraud-prevention, or security reasons
- support records, audit trails, and limited backup copies may remain for a reasonable period where necessary for business continuity or compliance
For Cutroom:
- the trail of activations and licence checks, meaning the IP address and approximate location recorded against each one, is deleted after 180 days. The same daily job enforces this, by age alone. We do not extend it for a licence we happen to find interesting
- the licence itself, and the record of each computer activated against it, are kept while the licence exists. That per-machine record holds the machine's fingerprint and the last IP address and approximate location we saw it check in from, and it is not aged out at 180 days the way the trail is. Deleting the licence deletes both
- the record of your acceptance of the Cutroom Licence Agreement is kept while the licence exists, because it is the proof that you agreed to it
Retention may vary depending on the nature of the data, the requests of the account owner, and the legal obligations that apply.
Security
We use administrative, technical, and organizational measures intended to protect personal data. These measures include encrypted transport over HTTPS, access controls, role restrictions, password protection, audit logging, and security monitoring. Where supported by our infrastructure providers, data is also encrypted at rest.
No method of transmission or storage is perfectly secure. For that reason, while we work to protect personal data, we cannot guarantee absolute security. Users are also responsible for protecting account credentials, using strong passwords, and controlling access to project information on their side.
Payment gateway credentials
When a freelancer connects a payment gateway (Stripe, PayPal, Tap Payments, Telr, PayTabs, Checkout.com, or similar), the gateway's API keys, secret keys, and webhook signing secrets are encrypted at the application layer using authenticated symmetric encryption (AES-256-GCM) before they are written to our database. The decryption key lives only in the runtime service's environment configuration; it is not stored in the database, not surfaced through any administrative interface, and not retrievable through queries that bypass the runtime helper. Delivvo personnel do not have a workflow that returns plaintext gateway credentials.
The Payments feature does not cause Delivvo to process or hold any client funds. Payment instrument details (card numbers, bank-account numbers, etc.) entered by the freelancer's clients are submitted directly to the chosen gateway through that gateway's hosted UI or its embedded SDK; Delivvo does not see, store, or transmit those details. The gateway is responsible for processing them in accordance with its own privacy policy, security obligations, and PCI/applicable regulatory regime.
What Delivvo does record about a payment is limited to the metadata necessary to keep the freelancer's invoice in sync with the gateway: the freelancer to whom the payment belongs, the invoice it relates to, the gateway used, the gateway's transaction or charge identifier, the amount, currency, and resulting status (succeeded, failed, refunded, etc.) as reported by the gateway's webhook. We do not store full payment instrument numbers, CVV codes, or banking account numbers in any context.
For payment links (public URLs that allow a freelancer's clients to pay a stated amount without first signing in to a portal) Delivvo additionally captures the email address the payer supplies on the payment form so that we can match the resulting transaction back to the right link, surface a status receipt, and let the freelancer reconcile incoming payments. The payer email is treated like any other client contact field under this policy.
For recurring invoices, Delivvo stores the schedule itself (start date, cadence, end condition, line items) and the per-cycle invoice records that the schedule produces. The actual charge for each cycle is processed by the gateway and produces the same metadata described in the preceding paragraph.
For saved client payment methods, where the gateway supports retaining a payer's payment instrument for future use, Delivvo stores only the gateway-issued customer identifier and any opaque token the gateway returns to reference the saved method; the card number, expiry, CVV, and equivalent banking details remain at the gateway and are governed by the gateway's privacy and security practices.
For refunds and disputes, Delivvo records the existence and lifecycle of each refund attempt or dispute (status, amount, reason code, gateway identifiers, and resulting effect on the related invoice) so the freelancer's activity log and accounting view stay accurate. Delivvo does not store the supporting documents a freelancer uploads to a gateway to contest a dispute; those flow through the gateway's own evidence-submission interface where applicable.
Administrator access to payment and archive data
Delivvo personnel with administrator privileges can view freelancer-level payment metadata and the document archive (signed contracts and paid invoices) for support, fraud-investigation, and compliance reasons. Opening an individual archive document (viewing it on screen, downloading the PDF, or permanently deleting an archive row) is recorded in an internal audit log under the administrator's identity, together with minimal metadata about the document. We retain audit-log rows for as long as the underlying account exists on the platform, plus a reasonable additional period for legal, security, and compliance purposes. Administrators do not have a workflow that returns plaintext gateway credentials, webhook signing secrets, or any payment-instrument data covered by the preceding subsection.
Your privacy rights
Depending on where you live, you may have some or all of the following rights, subject to applicable conditions and exceptions:
- access personal data we hold about you
- know what categories of data we collect, the sources of that data, the purposes for using it, and the categories of recipients to whom it is disclosed
- request correction of inaccurate or incomplete personal data
- request deletion of personal data
- request restriction of processing, or object to certain processing
- withdraw consent where processing is based on consent
- request portability of personal data in a usable format
- appeal or complain to a supervisory authority or regulator, where available
If you are a California resident, you may also request information about the categories of personal information collected, disclosed for business purposes, corrected, or deleted during the previous 12 months. Delivvo does not sell personal information and does not share personal information for cross-context behavioral advertising, so there is currently no "Do Not Sell or Share" workflow specific to that activity.
Delivvo does not use sensitive personal information for purposes that would require a special California right-to-limit workflow beyond what is reasonably necessary to provide the service.
How to exercise your rights
To submit a data access, correction, deletion, portability, or other privacy request, email the Support button at the bottom of any page on delivvo.io. Account holders can also download a complete copy of their account data themselves at any time from their account settings, without contacting Support, using the self-service data export. That export covers your Delivvo workspace: your profile, projects, clients, documents, files, and activity. It does not include Cutroom licensing records, so if you want those, ask us through the support link on delivvo.io/cutroom and we will provide them. We may ask for additional information to verify identity and confirm that the requester is entitled to make the request. Where Delivvo acts only as a processor or service provider for a freelancer or agency, we may direct the request to the relevant account owner or ask you to contact them directly.
We aim to respond within the time required by applicable law. In many cases that will be within 30 days, though some requests may take longer if legally permitted and reasonably necessary.
Children's data
Delivvo is designed for business use and is not directed to children. We do not knowingly collect personal data from children under 18. If you believe a child has provided personal data to Delivvo, contact us and we will take appropriate steps to investigate and, where appropriate, delete the data.
Changes to this policy
We may update this Privacy Policy from time to time to reflect product changes, legal developments, or operational requirements. If we make a material change, we will revise the "updatedAt" date and may also provide notice through the product or by email where appropriate.
Contact
For privacy requests or questions about this policy, contact the Support button at the bottom of any page on delivvo.io.