IndstrySign in

Privacy Policy

Effective date: 15 March 2025

Indstry (“we”, “us”, “our”) operates a platform connecting creative professionals with opportunities. This privacy policy explains how we collect, use, store, and share your personal data when you use our website, applications, and services (collectively, the “Platform”).

We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. AI Processing

We use artificial intelligence to enhance your experience on the Platform. Specifically:

  • Search and matching: We generate vector embeddings from your profile information, portfolio items, and job postings using OpenAI’s text-embedding-3-small model. These embeddings are numerical representations of your content stored in our database and used to power search, discovery, and matching between creative professionals and opportunities.
  • Onboarding assistance: During the onboarding process, we may use OpenAI’s GPT-4o-mini model to help you complete your profile by suggesting improvements or extracting relevant information from content you provide.

AI processing is performed only with your explicit consent. You can opt in or out of AI processing at any time through your account settings. By default, AI processing is disabled for new accounts.

2. Embedding Generation and Storage

When you enable AI processing, we generate vector embeddings from:

  • Your profile information (display name, headline, biography, skills, industry tags)
  • Your portfolio items (titles, descriptions, tags)
  • Job postings you create (title, description, requirements)

These embeddings are stored using pgvector in our PostgreSQL database hosted by Neon. They are used exclusively for search relevance and matching purposes within the Platform. Embeddings are deleted when you delete the associated content or disable AI processing.

3. Third-Party Data Processors

We share your personal data with the following third-party processors, each acting under a data processing agreement:

ProcessorPurpose
OpenAIAI embedding generation and onboarding assistance
StripePayment processing, subscriptions, and billing
ClerkAuthentication and identity management
ManyChatWhatsApp notifications (opt-in only)
UploadcareImage and document hosting and CDN delivery
MuxVideo hosting and streaming
SanityContent management for editorial content and brand assets
ResendTransactional email delivery
LoopsMarketing email communications (consent-gated)
PostHogProduct analytics (consent-gated)
SentryError monitoring and performance tracking
NeonDatabase hosting (PostgreSQL)
InngestBackground job processing
VercelWebsite hosting and edge delivery

Marketing email contact sync to Loops occurs only when you have given explicit marketing email consent.

4. Your Rights and Opt-Out Controls

Under the UK GDPR, you have the right to:

  • Access your personal data and request a copy of it.
  • Rectify inaccurate or incomplete personal data.
  • Erase your personal data (“right to be forgotten”). You can delete your account at any time through your settings, which triggers removal of all associated data.
  • Restrict processing of your personal data in certain circumstances.
  • Object to processing based on legitimate interests.
  • Data portability — receive your data in a structured, commonly used format.

Opt-out controls

  • AI processing: You can disable AI processing at any time via your account settings. This is controlled by your AI processing consent preference, which defaults to off. When disabled, no new embeddings will be generated from your data and existing embeddings will be removed.
  • Analytics: Analytics tracking via PostHog is only activated after you accept analytics cookies through our cookie consent banner. You can withdraw consent at any time by updating your cookie preferences.
  • Marketing emails: Marketing communications via Loops are only sent with your explicit consent. You can unsubscribe at any time via the link in any marketing email or through your account settings.
  • WhatsApp notifications: WhatsApp messages via ManyChat are only sent if you have explicitly opted in. You can opt out at any time through your notification preferences.

5. Cookies

We use the following cookies:

CookieTypeDurationPurpose
__clerk_*EssentialSessionAuthentication and session management via Clerk
aw_draft_tokenEssential30 daysPre-registration identity verification. This cookie stores a securely hashed token that links your pre-registration activity to your account during the onboarding process. It is HttpOnly and cannot be accessed by client-side scripts.
ph_*Analytics1 yearPostHog product analytics. Only set after you accept analytics cookies via our consent banner.

6. Data Retention

We retain your personal data for the following periods:

Data CategoryRetention Period
Account and profile dataUntil account deletion, then removed within 30 days
Portfolio content and mediaUntil deleted by user or account deletion
Vector embeddingsUntil source content is deleted or AI processing is disabled
Payment and billing records7 years (UK legal requirement for financial records)
Application dataUntil account deletion or 2 years after job expiry, whichever is sooner
Pre-registration lead data90 days if not converted to a full account
Analytics data24 months, then automatically anonymised
Error logs and diagnostics90 days

When you delete your account, we initiate a deletion process that removes your personal data, profile content, portfolio items, and associated embeddings. Some data may be retained where required by law (e.g. financial records).

7. Pre-Registration Token Security

During our onboarding process, we issue a secure token to link your pre-registration activity (such as early access sign-up via WhatsApp) to your eventual account. This token is:

  • Cryptographically hashed before storage — we never store the raw token value in our database.
  • Stored as an HttpOnly cookie with a 30-day rolling expiry, preventing access by client-side scripts.
  • Used solely to verify your identity during the transition from pre-registration to full account status.
  • Automatically expired and removed after successful account creation or after the 30-day period elapses.

Contact Us

If you have questions about this privacy policy or wish to exercise your data protection rights, please contact us at [email protected].

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data protection rights have been violated.