Creators Docket

Security Policies

Creators Docket, operated by Three Days LLC

Creators Docket holds a creator's income history and their payout details. This page describes the controls that protect it.

A note on scope. This document describes controls that are actually in place, not an aspirational framework. Where something is not yet implemented it has been left out rather than implied. Security questions and reports: support@creatorsdocket.com.

1. Access control

User access

Administrative access

2. Data classification

We hold four classes of data and protect them differently.

ClassExamplesProtection
Highly sensitive Bank account and routing numbers; third-party access tokens Encrypted at rest with AES-256-GCM under a key held outside the database and outside source control. The ciphertext is authenticated, so tampering fails to decrypt rather than silently returning something else.
Sensitive Income figures, invoices, brand terms and fees Isolated per user, transmitted only over TLS, never shared with third parties for advertising or analytics.
Personal Name, email address, business address, phone Collected only as needed to operate the service and produce invoices.
Public These policy pages, help content No protection required.

In transit: all traffic is served over HTTPS. At rest: the highest class is encrypted at the application layer as described above, and endpoints used to administer the service run full-disk encryption.

3. Information security

4. Network security

5. Vulnerability management

6. Incident response

Classification

Process

Contain first, then assess, then remediate, then notify, then record. Affected credentials and tokens are revoked before anything else. Every incident is written up with what happened, what was affected, and what changed as a result.

Notification

7. Data retention and deletion

DataRetained
Account and business recordsWhile the account is open. This is the user's own business history, and its value is that it goes back years.
Backups14 days, then deleted
Deployment snapshotsThe five most recent
Third-party access tokensDeleted on disconnection

Deleting a record in the application removes it from the live database immediately. Copies persist in backups for up to 14 days and then age out. A user may request deletion of their entire account by contacting support@creatorsdocket.com; we action it within 30 days and confirm when it is done.

At the end of a contractual relationship with a platform partner, data obtained through that partner is deleted from live systems and ages out of backups on the schedule above.

8. Subprocessors

We use a small number of providers to operate the service. Each receives only what it needs. The full list, and what reaches each of them, is in the Privacy Policy. We review that list before adding any provider that would handle customer data.

9. Compliance

10. Policy maintenance

These policies are reviewed at least annually, and additionally when the infrastructure materially changes, when a new subprocessor is added, or following any incident. The date at the top of this page reflects the last review.

11. Contact

Security reports and general enquiries: support@creatorsdocket.com
Three Days LLC