Privacy Policy

Last updated: 19 August 2026

This policy explains what personal data CreatorLink.bio collects, why, on what legal basis, how long we keep it, and who else touches it. It covers two different groups of people: the creators who hold an account, and the visitors who click a short link. If anything here is unclear, write to us — the address is at the bottom.

1. Who is responsible for your data

The data controller is:

NICOLASAGLIANO.COM di Nicola Sagliano

Via Paracelso 6, 42122 Reggio Emilia (RE), Italy

VAT / P.IVA: IT02887470348 — REA: RE-332892

Privacy contact: privacy@creatorlink.bio

We are a one-person business and have not appointed a Data Protection Officer, which is not required for processing of this scale. Privacy requests are handled by the owner directly.

2. The short version

  • We hold your name, email and profile picture from Google Sign-In, the links you create, and your credit history.
  • We never see or store your card details — Stripe handles payments.
  • When someone clicks one of your short links we record the click: country, region, city, device, browser, language, referrer and time. The IP address is used to build a daily hash and is never stored in readable form.
  • Our product analytics does not use cookies and receives your account id, never your email or name.
  • You can download everything we hold, or delete your account entirely, from Settings.
  • We do not sell data, and we do not run advertising.

3. Data about you (account holders)

Identity and contact. Name, email address and profile picture, received from Google when you sign in. We never receive your Google password.

Content you create. The destination URLs you shorten, the metadata we fetch from those pages (title, description, preview image), your affiliate identifiers, and your preferences.

Billing. Your Stripe customer identifier, the packages you bought, and your credit balance and transaction history. Card numbers, billing address and tax identifiers are collected and stored by Stripe, not by us.

Product usage. Pages visited and actions taken inside the app, tied to your account identifier, through PostHog (EU region).

Support and reports. Anything you send us by email, and abuse reports you submit.

4. Data about visitors who click a short link

This section is for people who clicked a crl.bio or creatorlink.bio link, not for our customers. When a short link is opened we record, for statistical purposes:

  • Country, region, city and continent, derived from the IP address by our hosting provider
  • Device type, operating system, browser, rendering engine and CPU architecture
  • Browser language and the time of the click
  • The referring domain (the site or app the click came from), never the full referring URL
  • Whether the click was handed over to a native mobile app

The IP address is not stored. It is truncated (the last octet is dropped), combined with the date, the link identifier and a secret key, and turned into an irreversible hash whose only purpose is to count the same visitor once per day. That hash is deleted automatically after 48 hours. Everything else is stored as daily totals per link — counters, not individual records — so no click can be traced back to a person.

Roles. The creator who owns the link decides to measure their own audience and is the controller for those statistics; we act as their processor and provide them with a data processing agreement (available here). For the security of the service — fraud, abuse and malware prevention — we act as controller on the basis of our legitimate interest.

Clicks identified as coming from bots and crawlers are not recorded at all.

6. Purposes and legal bases

PurposeDataLegal basis (GDPR art. 6)
Providing the service: accounts, links, redirects, statisticsIdentity, content, usagePerformance of a contract (6.1.b)
Payments, invoicing and accounting recordsBilling dataContract (6.1.b) and legal obligation (6.1.c)
Click statistics shown to the link ownerVisitor data of section 4Processed on the creator's instructions (art. 28); their basis is legitimate interest
Security: abuse, phishing and malware preventionDestination URLs, click data, abuse reportsLegitimate interest (6.1.f)
Weekly performance email about your own linksEmail address, link statisticsLegitimate interest (6.1.f), objectable at any time from Settings or the unsubscribe link
Product analytics to improve the serviceAccount identifier, in-app eventsLegitimate interest (6.1.f), no cookies used

7. How long we keep it

DataRetention
Account, links and their statisticsUntil you delete the account, then removed immediately
Visitor deduplication hash48 hours, deleted automatically
Aggregated daily click countersLife of the link; no personal data
Accounting and payment records10 years, as Italian tax law requires
Links submitted to the public checker6 hours, deleted automatically; never linked to who asked
Abuse reports and the decisions taken24 months
Support emails24 months from the last message

8. Who else processes your data

We use the following processors. Each is bound by a data processing agreement, and none of them is allowed to use your data for their own purposes.

ProviderRoleLocation
Vercel Inc.Application hosting and deliveryUSA (EU edge regions)
MongoDB AtlasDatabaseEU region
Google Ireland / Google LLCSign-in, Safe Browsing checks on destination URLsEU / USA
Stripe Payments EuropePayments, invoicing, tax calculationEU / USA
PostHogProduct analytics (EU cloud, cookieless)EU
ResendTransactional and digest emailUSA

We do not sell personal data, we do not share it with advertising networks, and we disclose it to authorities only where the law obliges us to.

9. International transfers

The database and product analytics run inside the European Union. Some processors listed above are established in the United States or process data there. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards in place for any specific provider.

10. Cookies and similar technologies

We use no advertising cookies, no profiling cookies and no third-party trackers. That is why you are not being asked to accept anything. What is actually stored on your device:

  • Session cookie (authjs.session-token) — keeps you signed in. Strictly necessary; expires when the session ends.
  • Sign-in security cookies — CSRF and callback tokens used during Google Sign-In. Strictly necessary, short-lived.
  • Theme preference — stored in your browser's local storage so the app remembers light or dark mode. Never leaves your device.
  • Stripe sets its own cookies on the checkout page it hosts, for fraud prevention. See Stripe's privacy policy.

Our product analytics (PostHog) is configured without cookies and without persistent local storage: it keeps state in memory for the duration of the page visit only.

11. Your rights

Under the GDPR you have the right to:

  • Access the data we hold about you — in the app: Settings → Your data → Download
  • Rectify inaccurate data
  • Erase your data — in the app: Settings → Your data → Delete account
  • Restrict or object to processing based on legitimate interest, including the weekly email
  • Data portability — the export is machine-readable JSON
  • Withdraw consent where processing is based on it, without affecting what was done before

Write to privacy@creatorlink.bio for anything the app cannot do itself. We answer within one month, as the GDPR requires.

You also have the right to lodge a complaint with a supervisory authority. In Italy that is the Garante per la protezione dei dati personali; if you live elsewhere in the EU, your national authority.

12. Security

The measures actually in place, stated plainly rather than in marketing terms:

  • All traffic is encrypted in transit (HTTPS/TLS); the database is encrypted at rest by MongoDB Atlas
  • Authentication is delegated to Google — we never handle passwords
  • Access to production data is limited to the business owner, protected by two-factor authentication
  • Every destination URL is screened against Google Safe Browsing when created and re-screened periodically
  • Security headers, rate limiting and server-side authorisation checks on every request
  • Automated database backups provided by MongoDB Atlas

No system is perfectly secure. If a breach were to affect your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it. If you find a vulnerability, please report it to security@creatorlink.bio— we will not pursue researchers who act in good faith.

13. Children

The service is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a minor has created an account, contact us and we will remove it.

14. Changes to this policy

When this policy changes we update the date at the top of the page. For changes that materially affect how we use your data, we will tell you by email before they take effect.

15. Contact

Privacy matters: privacy@creatorlink.bio
Everything else: support@creatorlink.bio
Abuse reports: creatorlink.bio/abuse

NICOLASAGLIANO.COM di Nicola SaglianoVia Paracelso 6, 42122 Reggio Emilia (RE), Italy — P.IVA IT02887470348