Privacy Policy
Last updated: 19 August 2026
This policy explains what personal data CreatorLink.bio collects, why, on what legal basis, how long we keep it, and who else touches it. It covers two different groups of people: the creators who hold an account, and the visitors who click a short link. If anything here is unclear, write to us — the address is at the bottom.
1. Who is responsible for your data
The data controller is:
NICOLASAGLIANO.COM di Nicola Sagliano
Via Paracelso 6, 42122 Reggio Emilia (RE), Italy
VAT / P.IVA: IT02887470348 — REA: RE-332892
Privacy contact: privacy@creatorlink.bio
We are a one-person business and have not appointed a Data Protection Officer, which is not required for processing of this scale. Privacy requests are handled by the owner directly.
2. The short version
- We hold your name, email and profile picture from Google Sign-In, the links you create, and your credit history.
- We never see or store your card details — Stripe handles payments.
- When someone clicks one of your short links we record the click: country, region, city, device, browser, language, referrer and time. The IP address is used to build a daily hash and is never stored in readable form.
- Our product analytics does not use cookies and receives your account id, never your email or name.
- You can download everything we hold, or delete your account entirely, from Settings.
- We do not sell data, and we do not run advertising.
3. Data about you (account holders)
Identity and contact. Name, email address and profile picture, received from Google when you sign in. We never receive your Google password.
Content you create. The destination URLs you shorten, the metadata we fetch from those pages (title, description, preview image), your affiliate identifiers, and your preferences.
Billing. Your Stripe customer identifier, the packages you bought, and your credit balance and transaction history. Card numbers, billing address and tax identifiers are collected and stored by Stripe, not by us.
Product usage. Pages visited and actions taken inside the app, tied to your account identifier, through PostHog (EU region).
Support and reports. Anything you send us by email, and abuse reports you submit.
4. Data about visitors who click a short link
This section is for people who clicked a crl.bio or creatorlink.bio link, not for our customers. When a short link is opened we record, for statistical purposes:
- Country, region, city and continent, derived from the IP address by our hosting provider
- Device type, operating system, browser, rendering engine and CPU architecture
- Browser language and the time of the click
- The referring domain (the site or app the click came from), never the full referring URL
- Whether the click was handed over to a native mobile app
The IP address is not stored. It is truncated (the last octet is dropped), combined with the date, the link identifier and a secret key, and turned into an irreversible hash whose only purpose is to count the same visitor once per day. That hash is deleted automatically after 48 hours. Everything else is stored as daily totals per link — counters, not individual records — so no click can be traced back to a person.
Roles. The creator who owns the link decides to measure their own audience and is the controller for those statistics; we act as their processor and provide them with a data processing agreement (available here). For the security of the service — fraud, abuse and malware prevention — we act as controller on the basis of our legitimate interest.
Clicks identified as coming from bots and crawlers are not recorded at all.
5. The public link checker
Our affiliate link checker and URL expander are free tools that need no account. When you submit a link:
- Our server requests that URL and follows its redirects. Your browser never contacts the destination.
- We store the submitted URL and the chain it resolved to for 6 hours, so that the same link is not fetched repeatedly. That cache expires and deletes itself automatically.
- The cache is not linked to you. We do not record who submitted which link, and there is no way for us or for anyone else to look up a history of checks.
- Your IP address is used only as a counter for the rate limit (60 checks per five minutes) and is not attached to the URL you checked.
A URL you paste may itself contain personal data — a token or an identifier in the query string, for instance. That is the reason for the short retention and for the absence of any lookup function. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in offering a transparency tool and in preventing its abuse.
6. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Providing the service: accounts, links, redirects, statistics | Identity, content, usage | Performance of a contract (6.1.b) |
| Payments, invoicing and accounting records | Billing data | Contract (6.1.b) and legal obligation (6.1.c) |
| Click statistics shown to the link owner | Visitor data of section 4 | Processed on the creator's instructions (art. 28); their basis is legitimate interest |
| Security: abuse, phishing and malware prevention | Destination URLs, click data, abuse reports | Legitimate interest (6.1.f) |
| Weekly performance email about your own links | Email address, link statistics | Legitimate interest (6.1.f), objectable at any time from Settings or the unsubscribe link |
| Product analytics to improve the service | Account identifier, in-app events | Legitimate interest (6.1.f), no cookies used |
7. How long we keep it
| Data | Retention |
|---|---|
| Account, links and their statistics | Until you delete the account, then removed immediately |
| Visitor deduplication hash | 48 hours, deleted automatically |
| Aggregated daily click counters | Life of the link; no personal data |
| Accounting and payment records | 10 years, as Italian tax law requires |
| Links submitted to the public checker | 6 hours, deleted automatically; never linked to who asked |
| Abuse reports and the decisions taken | 24 months |
| Support emails | 24 months from the last message |
8. Who else processes your data
We use the following processors. Each is bound by a data processing agreement, and none of them is allowed to use your data for their own purposes.
| Provider | Role | Location |
|---|---|---|
| Vercel Inc. | Application hosting and delivery | USA (EU edge regions) |
| MongoDB Atlas | Database | EU region |
| Google Ireland / Google LLC | Sign-in, Safe Browsing checks on destination URLs | EU / USA |
| Stripe Payments Europe | Payments, invoicing, tax calculation | EU / USA |
| PostHog | Product analytics (EU cloud, cookieless) | EU |
| Resend | Transactional and digest email | USA |
We do not sell personal data, we do not share it with advertising networks, and we disclose it to authorities only where the law obliges us to.
9. International transfers
The database and product analytics run inside the European Union. Some processors listed above are established in the United States or process data there. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards in place for any specific provider.
11. Your rights
Under the GDPR you have the right to:
- Access the data we hold about you — in the app: Settings → Your data → Download
- Rectify inaccurate data
- Erase your data — in the app: Settings → Your data → Delete account
- Restrict or object to processing based on legitimate interest, including the weekly email
- Data portability — the export is machine-readable JSON
- Withdraw consent where processing is based on it, without affecting what was done before
Write to privacy@creatorlink.bio for anything the app cannot do itself. We answer within one month, as the GDPR requires.
You also have the right to lodge a complaint with a supervisory authority. In Italy that is the Garante per la protezione dei dati personali; if you live elsewhere in the EU, your national authority.
12. Security
The measures actually in place, stated plainly rather than in marketing terms:
- All traffic is encrypted in transit (HTTPS/TLS); the database is encrypted at rest by MongoDB Atlas
- Authentication is delegated to Google — we never handle passwords
- Access to production data is limited to the business owner, protected by two-factor authentication
- Every destination URL is screened against Google Safe Browsing when created and re-screened periodically
- Security headers, rate limiting and server-side authorisation checks on every request
- Automated database backups provided by MongoDB Atlas
No system is perfectly secure. If a breach were to affect your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it. If you find a vulnerability, please report it to security@creatorlink.bio— we will not pursue researchers who act in good faith.
13. Children
The service is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a minor has created an account, contact us and we will remove it.
14. Changes to this policy
When this policy changes we update the date at the top of the page. For changes that materially affect how we use your data, we will tell you by email before they take effect.
15. Contact
Privacy matters: privacy@creatorlink.bio
Everything else: support@creatorlink.bio
Abuse reports: creatorlink.bio/abuse
NICOLASAGLIANO.COM di Nicola Sagliano — Via Paracelso 6, 42122 Reggio Emilia (RE), Italy — P.IVA IT02887470348
On this page