Thirteen Degrees
    Creator marketplaceBecome a UGC creator

    Legal

    Privacy Policy

    Last updated: 10 June 2026 · Three's A Crowd PTY LTD · South Africa

    Three's A Crowd PTY LTD trading as Thirteen Degrees ("we", "us") respects your privacy. This Policy explains how we collect, use, share and protect personal information when you visit our site, brief us, become a client, apply as a creator or use our academy, portal, studio or AI tools. It is issued under the Protection of Personal Information Act 4 of 2013 ("POPIA"), and, where applicable, the EU and UK General Data Protection Regulations ("GDPR"), the ePrivacy Directive, the California Consumer Privacy Act ("CCPA/CPRA") and equivalent laws.

    1. Responsible party / Controller

    Three's A Crowd PTY LTD, Century City, Cape Town, South Africa. Information Officer: privacy@13-degrees.com.

    2. Our role

    We act as responsible party / controller for our own marketing site, portal accounts, recruitment and academy enrolments. We act as operator / processor when we handle personal information on behalf of a client (for example, when running paid campaigns, uploading audience lists, configuring Conversion APIs or briefing creators on behalf of a brand). Where we are processor, the client is the controller and is responsible for the lawful basis, notices and consents.

    3. What we collect

    • Identity & contact: name, email, phone, company, role.
    • Brief content: documents, briefs, brand assets and creative direction you upload.
    • Creator data: profile, handles, rate card, location, languages, content samples (creators only).
    • Account & usage: login, IP, device, page interactions, generation history, prompts and outputs.
    • Platform & campaign data: ad account IDs, page IDs, pixel events, conversion events, audience definitions, performance metrics and creative diagnostics returned by Meta, TikTok, Google/YouTube, Snap, Pinterest, X and similar Platforms.
    • Billing: billing entity, VAT number, banking details for invoicing.
    • Cookies & similar tech: see our Cookie Policy.

    4. Purpose & legal basis

    • Provide services under an SOW (performance of contract).
    • Operate the client portal, studio, chat, academy and AI tools (contract, legitimate interest).
    • Run paid media, measurement, attribution and audience activation on a client's instruction (processor, on the client's lawful basis).
    • Secure the Services, prevent abuse, debug and improve (legitimate interest).
    • Comply with tax, accounting, anti-money-laundering and advertising-regulation obligations (legal duty).
    • Marketing communications with consent or based on an existing client relationship (opt-out at any time).

    5. Social platforms, ads & tracking

    When we configure or run campaigns we work with social and ad platforms including Meta (Facebook, Instagram, WhatsApp), TikTok, Google (including YouTube, Google Ads, Google Analytics), Snap, Pinterest and X. These Platforms may:

    • Set cookies, pixels, SDKs or similar identifiers on properties they or our clients operate.
    • Receive hashed customer data ("Custom Audiences", "Customer Match", "Advanced Matching") and server-side conversion events ("Conversions API", "Events API", "Enhanced Conversions") to measure and optimise campaigns.
    • Act as independent or joint controllers for the personal information they receive, under their own privacy policies and data-processing terms.

    Where we instruct or configure such transfers on a client's behalf, the client is the controller of the underlying personal information and is responsible for obtaining all required consents, notices and opt-outs (including ePrivacy / cookie consent and "Do Not Sell or Share" / Global Privacy Control signals). We will not knowingly enable such transfers without the client's documented instruction.

    6. How we use AI processors

    We use vetted third-party AI model, voice, avatar and video providers under data-processing terms. We select providers whose terms prohibit training of foundation models on identifiable client data submitted via API. Brand assets, briefs and prompts are isolated per brand workspace. AI outputs may be inaccurate or fabricated and must be reviewed before use - see our Terms of Use.

    7. Sharing

    We share personal information only with:

    • Sub-processors who host or power our services (cloud, database, AI providers, email, analytics).
    • Advertising and social Platforms on a client's instruction (see section 5).
    • Casting partners and creators, where necessary to brief and pay them.
    • Payment processors, auditors, lawyers, banks and tax authorities where legally required.
    • Acquirers in the event of a corporate transaction, under confidentiality.

    We do not sell personal information.

    8. Cross-border transfers

    Some sub-processors and Platforms are located outside South Africa, the EU and the UK. Where personal information is transferred cross-border, we rely on POPIA section 72 grounds (contractual safeguards and recipient laws providing adequate protection) and, for GDPR / UK GDPR data, Standard Contractual Clauses or equivalent transfer mechanisms with the receiving Platform or sub-processor.

    9. Retention

    We retain personal information only for as long as needed for the purposes above, or as required by tax, advertising-regulation and statutory record-keeping (typically 5 years from end of engagement). Brand assets, prompts, generations and deliverables are retained for the contracted term plus 12 months for archival, unless deletion is requested in writing. Platform-side data (e.g. pixel events, audience hashes) is retained according to the relevant Platform's policies and is outside our control.

    10. Your rights

    • Access, correction, deletion, restriction, objection and data portability (where applicable).
    • Withdraw consent at any time (where processing is based on consent).
    • Opt out of targeted advertising / sale of personal information ("Do Not Sell or Share") where applicable.
    • Lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za, or with your local EU/UK or state data protection authority.

    Send requests to privacy@13-degrees.com. If your data was processed by us on behalf of a client (as processor), we will route your request to that client.

    11. Security

    We apply industry-standard technical and organisational measures, including encryption in transit and at rest, role-based access, audit logging and least-privilege provisioning. No system is fully secure - please report suspected incidents to security@13-degrees.com.

    12. Children

    Our services are not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided data, contact us and we will delete it.

    13. Updates

    We may amend this Policy from time to time. Material changes will be communicated to active clients and posted on this page with a new "Last updated" date.