Plans & PricingAffiliate
Log InSign up free
Plans & PricingAffiliateSupport

Privacy Policy

Last updated: July 27, 2026

1. About this Policy

This Privacy Policy explains what personal data Onlink (“Onlink”, “we”, “us”) collects, why we collect it, and what your rights are. It covers on.link, dash.on.link, app.on.link, and every related service, whether you are a creator, a buyer, or a visitor.

Onlink is the controller of the personal data described here. We are based in Portugal and operate under the EU General Data Protection Regulation (GDPR). If anything in this policy is unclear, write to us at [email protected].

2. What We Collect

Account data. When you create a creator account, we collect your name, email address, and a password — stored only as a modern cryptographic hash, never in plain text. If you sign in with Google, we receive your name and email from your Google account instead.

Creator content. Everything you add to your page — text, links, images, video, audio, products, prices — is collected and stored so we can host and display it. Your page content is public by design.

Purchase data. When you buy from a creator, we receive your name and email from the payment flow, plus the product, amount, and date of each purchase, so we can provision your access and show creators their sales. We never see or store your card number: payments are processed entirely by Stripe.

Checkout record. When you subscribe to a paid plan or buy from a creator, we also record the IP address and browser you used, the moment you paid, what you were shown, the terms you accepted, and the result of your card's security checks (3-D Secure, and the address and security-code verification your bank returns). A card payment can be disputed with the bank for months afterwards, and this is the record that shows what was bought and agreed. It is kept with the transaction, not with the short-lived logs described below.

Billing data. For paid creator accounts we keep your plan, billing status, and invoices through Stripe, our payment provider.

Connected accounts. If you are a creator and turn on bookings, you can connect your own Google account. When you do, you grant Onlink permission to create and manage calendar events or video meetings on your behalf, and we securely store that connection so we can add an event or meeting whenever someone books with you. We use this access only to schedule your bookings — we do not read your existing calendar, contacts, or files — and you can disconnect at any time from your booking settings.

Sign-in record. We keep a record of sign-ins to your account — the IP address, the browser, and the time — for thirteen months. If a payment to us is disputed, this is what shows the bank that the account was actually used.

Lead data. When you give a creator your name and email to receive a free download, we store them and pass them to that creator. Nothing else is collected, and you are not charged.

Technical data. Beyond the records above, our servers retain short-lived logs (IP address, browser type, timestamps) strictly for security, abuse prevention, and keeping the service running.

3. What We Do Not Collect

Public Onlink pages are served without cookies and without third-party trackers: visiting a creator’s page does not create an advertising profile of you, and we run no third-party analytics scripts on it. We do not collect phone numbers at checkout, we do not buy data about you from data brokers, and we do not use your content or data to train AI models.

Our own marketing pages — the Onlink home page, pricing, and the affiliate page — are the one exception, and only if you agree. There we ask whether we may use Google Analytics to measure how the pages perform; nothing is loaded and no cookie is set unless you say yes, and you can say no. Creator pages never carry it, whatever you choose.

4. How We Use Your Data

We use personal data to: provide the service you signed up for — hosting your page, processing sales, provisioning buyer access, sending transactional email such as sign-in verification and purchase receipts (legal basis: performance of a contract); keep Onlink secure — preventing fraud, abuse, and unauthorized access (legal basis: our legitimate interest in running a safe platform); answer disputed payments — showing the bank what was bought, when, and what was agreed, if a card payment is later challenged (legal basis: our legitimate interest in defending payments made to us, and performance of a contract); and meet legal obligations — accounting, tax, and responding to lawful requests (legal basis: legal obligation).

We do not use your data for third-party advertising, and we will not send you marketing email without your consent.

5. Public by Design

An Onlink page is a public website. Whatever a creator publishes on their page — including their name, photo, bio, social links, and products — is visible to anyone with the link and may be indexed by search engines. Do not publish anything on your page that you want to keep private.

6. What Creators See About Buyers

When you buy from, book with, or donate to a creator, that creator receives your name, email address, and the details of the transaction (product, amount, date). This is necessary to deliver what you bought and is part of the sale: the creator is the seller of record.

Creators must handle buyer data lawfully — using it to deliver the purchase and provide support, not for unrelated marketing without your consent. Misusing buyer data is a violation of our Terms & Conditions.

7. Referrals & the Affiliate Program

If you take part in our affiliate program, we record which accounts were created through your affiliate link or your public Onlink page, when they were created, and whether each one subscribed to a paid plan. We need this to attribute referrals, work out what you are owed, and pay it. The legal basis is the performance of the affiliate agreement described in our Terms & Conditions, and our legal obligations for the payments we make.

What an affiliate can see about a referral is limited to what the program needs: that an account was created through them, when, and whether it qualified. Affiliates are not shown a referral’s name, email address, page content, or sales.

If you were referred by an affiliate, we keep the link between your account and theirs for as long as a reward can be earned, reversed, or audited, and afterwards for as long as tax and accounting law requires us to keep records of what we paid.

8. Who Processes Data for Us

We share personal data only with the service providers that make Onlink work, under contracts that bind them to protect it: Stripe (payments and billing), Google (optional sign-in, calendar scheduling for creator bookings, our business email, and — only with your consent, only on our marketing pages — Analytics), Resend (transactional email delivery), and Cloudflare (content delivery, DNS, and media storage). Our application servers are hosted in the European Union.

When a creator connects their Google account to offer bookings, Onlink uses the Google Calendar API to create and manage the events for those bookings on the creator’s behalf. Onlink’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: this access is used only to provide the booking feature the creator enabled, is never sold or used for advertising, and is not read by any human except with the creator’s consent, for security, or where the law requires.

Beyond these processors, we disclose personal data only when the law requires it, or to protect Onlink or its users from fraud or abuse, or as part of a corporate transaction such as a merger — in which case this policy continues to apply.

9. International Transfers

Some of our processors are based in the United States. Where personal data leaves the European Economic Area, it is protected by recognized safeguards — the EU–US Data Privacy Framework or Standard Contractual Clauses approved by the European Commission.

10. How Long We Keep Data

Account and content data are kept while your account exists. When you delete your account, your personal data — name, email, password, connected sign-ins, and profile picture — is erased immediately, and it cannot be restored. What remains is an anonymous record with no name or email attached, kept for thirty days so that anyone who bought from you keeps access to what they paid for; after that it is removed too.

Two things outlive that, because the law and the card networks require it. The checkout record described in section 2, and our record of the payments you made to us, are kept for as long as tax and accounting law requires and in any case for at least thirteen months, because a card payment can still be disputed long after it was made — they are kept without your name or email attached once your account is gone. Sign-in records are kept for thirteen months for the same reason. Short-lived operational logs are separate from all of this and are kept only briefly.

If you have a buyer account for purchases you made, it is kept while you have access to what you bought. You can delete it yourself at any time from your library's account menu, or write to [email protected]. If you gave a creator your email for a free download, the delivery email contains a link to remove your details from that creator's list.

11. Your Rights

Under the GDPR you can ask us to: access the personal data we hold about you; correct it; delete it; hand it over in a portable format; restrict how we process it. You can also object to our processing, and withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email [email protected] — we will respond within a month. You also have the right to complain to a supervisory authority: in Portugal, the CNPD (Comissão Nacional de Proteção de Dados), or the data protection authority of the country where you live.

12. Cookies

Public Onlink pages — every creator page — set no cookies at all, which is why you see no cookie notice on them. The creator dashboard and buyer library use only essential cookies: the session cookie that keeps you signed in. We use no advertising cookies anywhere.

On our own marketing pages (the Onlink home page, pricing, and the affiliate page) we ask before loading Google Analytics. Decline and nothing is loaded; agree and it sets its own analytics cookies, which you can clear at any time in your browser. Your answer is remembered on your device, not in an account.

13. Security

All traffic to Onlink is encrypted in transit. Passwords are stored with a modern, memory-hard hashing algorithm, accounts have a single active session at a time, and access to production data is restricted. No online service can promise perfect security, but if a breach ever affects your personal data we will notify you and the authorities as the law requires.

14. Children

Onlink accounts are for adults: you must be at least 18 to create one. We do not knowingly collect personal data from children; if you believe a child has provided us with data, contact us and we will delete it.

15. Changes to this Policy

When we make a material change to this policy, we will tell you — by email or with a notice in the product — before the change takes effect. The date at the top always shows the latest revision.

16. Contact

Privacy questions and data requests: [email protected]. General help: [email protected]. Postal contact details are available on request.

Get startedLog InSign upPlans & PricingAffiliate
ResourcesSupportFAQReport a Violation
LegalTerms & ConditionsPrivacy Policy
© 2026 Onlink. All rights reserved.
EnglishEspañolPortuguêsFrançaisDeutsch