Privacy Policy
Last updated: 21 July 2026
Issued by Stickteck LLC, EDRPOU 45548110, 18018 Cherkasy, vul. Solomianska 25, apt. 70, Ukraine.
1. Three kinds of people
Most policies in this category lump everyone together. We don't, because the person who publishes a page and the person who fills in a form on it are in genuinely different positions.
| You are a… | Meaning | Our role |
|---|---|---|
| Creator | You have a stick account and publish pages | We are the controller |
| Visitor | You look at a page someone published | We are the controller, for limited non-identifying statistics |
| Contact | You filled in a form on someone's page | The creator is the controller; we are their processor |
If you are a Contact, the creator whose page you used decides what happens to your data and their privacy notice governs, not this one. We hold it on their instructions under Terms §8. Ask them for corrections or deletion; if you cannot reach them, write to help@stick.so and we will help.
2. If you are a Creator
What we collect. Your email address — that is genuinely all for a magic-link account. We do not ask for your name, we have no profile table, and we do not collect date of birth, gender, phone or address. Google sign-in gives us your email and basic profile; we do not request Drive, Calendar or Contacts access. Beyond that: what you build (pages, drafts, uploads, settings), support messages you send us, and technical data when you use the editor — IP, browser, device and error diagnostics.
We do not buy data about you and we do not build advertising profiles.
Why, and on what basis:
| Purpose | Legal basis |
|---|---|
| Running your account, serving the editor, publishing your pages | Contract |
| Security, abuse and fraud prevention | Legitimate interests |
| Fixing errors, improving the product | Legitimate interests |
| Service email — security, billing, changes to terms | Contract / legal obligation |
| Product marketing email | Consent, withdrawable any time |
| Complying with law | Legal obligation |
We make no automated decisions about you with legal or similarly significant effects, and we do not profile you.
Cookies in the editor. Signing in sets Supabase authentication cookies (sb-<project>-auth-token, plus a
short-lived verifier during sign-in). They are strictly necessary — the editor cannot work without them — so
we do not ask consent for them. They are HttpOnly, Secure in production, SameSite=Lax, and scoped to
app.stick.so only: not shared with published pages. We run no advertising or analytics trackers in the
editor.
3. If you are a Visitor
Published stick pages set no cookies of ours. None. No analytics cookie, no session cookie, no consent cookie, and no local or session storage. That is a property of how the pages are built, not a promise we are asking you to take on trust.
What we measure. Page views and link clicks, so creators can see whether their page works. Per event:
which page and block; your country only, derived at the network edge — never a city or precise location;
the hostname that referred you (instagram.com, never the full URL); and a visitor hash.
How the hash works. We take your IP and user-agent, combine them with the creator's site ID and a secret salt we rotate at midnight UTC, hash it, and keep only the result. So:
- Your IP address and user-agent are never written to our database. They exist in memory long enough to compute the hash, then are discarded.
- The hash cannot be reversed to recover your IP.
- Because the salt changes daily, the same person's hash changes daily — we cannot follow you across days, build a profile, or link your activity across different creators' pages.
This is deliberately less capable than the analytics our competitors run, and we accept that trade.
We do not act on Do Not Track signals because we do not do the cross-site tracking DNT exists to stop.
Retention. Individual events are deleted automatically after 90 days. What survives is aggregate daily counts — views, clicks, referrer hostnames, country totals — containing nothing about any individual.
Legal basis: our legitimate interest, and the creator's, in knowing whether a page works. We store no direct identifier and no identifier that persists beyond a day.
4. If you are a Contact
When you submit a form, we store it so the creator can see it. That always includes an email address (our forms require one) and may include your name, phone, free-text answers and checkbox responses — whatever that creator asked for. We keep the individual submission and a merged per-creator contact record, so repeat submissions from the same address appear once.
We do not use this for our own purposes. We do not market to you, sell it, share it with other creators, or add you to anything. We hold it for the creator, on their instructions.
We send you no email. stick has no email-sending infrastructure at all. If a creator emails you, they do it from their own tool, and their unsubscribe applies.
The creator is responsible for telling you why they collected it, having a lawful basis, and handling your requests. Retention: for as long as the creator keeps their account and has not deleted the record. If they delete their site or account, it goes too.
5. Third parties on published pages
A creator can add blocks that make your browser contact other companies. Their own privacy policies apply, and the creator, not us, chose to include them:
| Feature | Third party | What they see |
|---|---|---|
| Embeds — YouTube, Vimeo, Twitch, Spotify, SoundCloud, Apple Music, TikTok | The provider, in a sandboxed iframe | Your IP, and their cookies once you interact |
| Embeds — Instagram, Threads, X, Telegram | The provider, running their code in the page itself | Your IP, page context, their own cookies. X is loaded with dnt: true. |
| Map block | Google Maps | Your IP and the embedded location |
| Link thumbnails (default) | Google's favicon service | Your IP and the hostname of the link shown |
| Stickers | GIPHY | Your IP |
| Emoji | Google's asset CDN | Your IP |
The four in the second row matter most: they execute third-party JavaScript with full page privileges and can set their own cookies. Where consent is required for that, it is the creator's responsibility.
Note that link thumbnails default to fetching a favicon from Google, so most pages disclose their outbound link hostnames to Google. Typography is self-hosted — we do not call Google Fonts for fonts.
6. Who we share with
We do not sell personal data and do not share it for behavioural advertising. Our providers:
| Provider | For | Where | Data |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | AWS eu-central-1, Frankfurt | Account data, page content, contacts, uploads |
| Vercel Inc. | Hosting and delivery | Frankfurt (fra1) | Requests to the editor and published pages |
Our error tracking is self-hosted on our own server in Germany, not a third-party error-tracking service, so diagnostics stay on infrastructure we operate. It runs only in the editor — no error monitoring runs on published pages, so Visitors are never included.
Beyond these we disclose data only if the law requires it, to enforce our Terms, to protect someone from harm, or to a buyer of our business (we will tell you first, and this policy continues until replaced).
Not used, so you don't have to wonder: no Google Analytics, Tag Manager, Meta Pixel, PostHog, Mixpanel, Amplitude, Segment, Hotjar, FullStory or LogRocket. No advertising network. No AI or LLM features — nothing you write is sent to a model provider. No email provider, because we send no email.
7. Uploaded images are public
Anything you upload is stored in a publicly readable bucket. The file is reachable by anyone with its URL; this is true whether or not your site is published; and unpublishing does not make images private again. Do not upload anything you would not want public. Images only (JPEG, PNG, GIF, WebP, AVIF, SVG), up to 10 MB.
8. How long we keep things
| Data | Retention |
|---|---|
| Account data, pages, uploads | While your account exists |
| Contacts and form submissions | While the creator's account exists and they have not deleted them |
| Analytics events (individual) | 90 days, then dropped automatically |
| Analytics aggregates | Indefinitely — no individual data |
| Error diagnostics | 90 days |
| Backups | Daily, kept for 7 days, then overwritten |
We publish real numbers because neither Linktree nor Stan Store publishes any retention periods at all.
9. Where data goes
We are established in Ukraine. Your data is stored in the European Union — the database in Frankfurt
(AWS eu-central-1), hosting and delivery in Frankfurt, error diagnostics on our own server in Germany.
Supabase, Inc. and Vercel Inc. are US companies, so their staff may access the systems for support and maintenance from outside the EU, but the data itself is not stored outside it.
Data is encrypted in transit, and the database is encrypted at rest.
10. Your rights
You can ask us to access, correct, delete, restrict or object to our use of your personal data, to port it, or to withdraw consent where we relied on it.
Write to help@stick.so. We respond within 30 days, free of charge, and will tell you if a complex request needs longer. We may need to verify who you are.
If you are a Contact, send these to the creator whose form you used — they are the controller. We will help if you cannot reach them.
You can complain to your data protection authority: in Ukraine the Ukrainian Parliament Commissioner for Human Rights, in the EU or UK your national supervisory authority or the ICO.
11. Children
stick is not for anyone under 16, and you must be 16 to hold an account. We do not knowingly collect personal data from children under 16 — if you believe we have, write to help@stick.so and we will delete it. This single threshold applies everywhere.
12. Security
Access to creator data is enforced at the database by row-level security, so one creator cannot read
another's data even if the application has a bug. Traffic is encrypted in transit. Auth cookies are
HttpOnly and Secure. Form submissions are validated server-side against the stored field schema, and
contact writes happen only in server-side code — never directly from a visitor's browser. Analytics are
built so the identifying inputs are never stored at all.
No system is perfectly secure and we do not claim otherwise. Report vulnerabilities to help@stick.so — we will not pursue good-faith research.
13. Changes and contact
If we change this policy in a way that materially affects you, we will email you and give notice in the product at least 30 days beforehand. Smaller corrections take effect when published.
Reach us at help@stick.so for anything — privacy and data requests, security reports, or general questions. By post: Stickteck LLC, 18018 Cherkasy, vul. Solomianska 25, apt. 70, Ukraine.