Privacy Policy

Effective: April 8, 2026 · Last updated: April 8, 2026

Speislink is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and how we use and protect it. We process your data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Italian privacy law. Fields marked [YOUR COMPANY NAME], [YOUR REGISTERED ADDRESS], [YOUR CITY], and [YOUR VAT NUMBER] must be replaced with actual legal entity details before publication.

1.Data Controller

The Data Controller responsible for processing your personal data is:

  • ▸Company: [YOUR COMPANY NAME]
  • ▸Registered address: [YOUR REGISTERED ADDRESS], [YOUR CITY], Italy
  • ▸VAT number: [YOUR VAT NUMBER]
  • ▸Email: privacy@speis.link
  • ▸Website: https://speis.link

For all data protection inquiries or to exercise your rights under the GDPR, please contact us at privacy@speis.link.

2.Data We Collect

We collect the following categories of personal data:

  • ▸Account Data: Your email address and chosen username, collected when you register.
  • ▸Profile Data: Information you voluntarily add to your public profile, including display name, bio, and avatar image.
  • ▸Content Data: Links, link groups, and digital product files that you create or upload on the Platform.
  • ▸Payment and Transaction Data: We work with Stripe for subscription payments and product purchases. We do not store your full payment card details. We retain transaction IDs, subscription status, amounts, currencies, and timestamps.
  • ▸Stripe Connect Data: If you sell products, we store your Stripe Connect Account ID, onboarding status, and payout-related information.
  • ▸Creator Analytics Data: Aggregate statistics for your public profile page, including page views, link clicks, referrer domains, country-level geographic data (derived from IP addresses that are not stored individually), and device type classifications.
  • ▸Usage Data: Data about how you interact with the Service, collected via PostHog, including pages visited, features used, and session duration.
  • ▸Technical Data: Browser type and version, operating system, session tokens, and similar technical identifiers used for security and operational purposes. IP addresses are used transiently and are not stored permanently at an individual level.
  • ▸Communications: Records of any correspondence with us, including support or legal inquiries.

We do not collect special categories of personal data (such as health, racial origin, political opinions, or biometric data) and ask that you not submit such data through the Service.

4.How We Use Your Data

We use your personal data to:

  • ▸Create, manage, and authenticate your account.
  • ▸Provide the Service, including hosting your public Speislink page and processing link clicks and page views.
  • ▸Process subscription payments and manage billing via Stripe.
  • ▸Facilitate digital product sales, including secure file delivery and download token generation.
  • ▸Provide Creator analytics (page views, clicks, referrers, and geographic data).
  • ▸Send transactional communications, including magic link authentication emails and important service notices.
  • ▸Detect, investigate, and prevent fraud, spam, abuse, and security incidents.
  • ▸Comply with legal obligations and respond to lawful requests from authorities.
  • ▸Improve, develop, and troubleshoot the Service.

We do not sell, rent, or trade your personal data to third parties. We do not use your data for profiling or automated decision-making that produces legal or similarly significant effects without human review.

5.Data Sharing and Processors

We share your personal data only with the following categories of recipients, each bound by data processing agreements consistent with GDPR requirements:

ProcessorPurposeLocationTransfer Safeguard
Supabase, Inc.Database hosting, file storage, user authenticationUSA (AWS us-east-1)Standard Contractual Clauses (SCCs)
Stripe, Inc.Subscription payment processing, Stripe Connect payoutsUSASCCs + Stripe Data Processing Agreement
PostHog, Inc.Product analytics and usage trackingEU — Frankfurt, GermanyEU-based infrastructure; no EEA transfer
Cloudflare, Inc.Content delivery network, edge computing, DDoS and bot protectionUSA + global edgeSCCs

Stripe for Creators: If you are a Creator, your Stripe Connect Account ID and payout information are shared with Stripe to facilitate payouts. Buyers' payment information is processed directly by Stripe and is subject to Stripe's Privacy Policy.

Legal Disclosures: We may disclose personal data if required by law, court order, or governmental authority, or if we reasonably believe disclosure is necessary to protect rights, property, or safety, or to detect, prevent, or address fraud or security issues.

Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity under equivalent protections.

6.International Data Transfers

Some of our processors (Supabase, Stripe, Cloudflare) are based in or operate infrastructure in the United States or other countries outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we rely on appropriate safeguards as required by GDPR Article 46, including Standard Contractual Clauses (SCCs) approved by the European Commission.

PostHog analytics data is processed exclusively on EU-based infrastructure (Frankfurt, Germany) and does not leave the EEA.

You may request a copy of the relevant transfer safeguards we have in place by contacting us at privacy@speis.link.

7.Data Retention

We retain your personal data only for as long as necessary for the purposes described in this Policy, or as required by law:

Data CategoryRetention Period
Account data (email, username)Until account deletion + 30 days for backup expiry
Profile data (links, bio, settings, avatar)Until account deletion + 30 days
Product files uploaded by CreatorsUntil deletion by Creator + 30 days
Transaction records (purchases, subscriptions)10 years (Italian Civil Code and tax law — Art. 2220 c.c.)
Aggregate analytics events13 months rolling window
Support and legal correspondence3 years from last communication
Database backup snapshotsUp to 90 days after the applicable retention period

After the applicable retention period, we delete or irreversibly anonymize your data. Note that account deletion initiates the deletion process, but data may remain in encrypted backups for up to 90 additional days.

8.Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights under the GDPR. To exercise any of these rights, contact us at privacy@speis.link. We will respond within one (1) month; for complex or multiple requests, we may extend by up to two additional months with prior notification.

  • ▸Right of Access (Art. 15): Request a copy of all personal data we hold about you and information about how we process it.
  • ▸Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • ▸Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your data where it is no longer necessary for its original purpose, or where you withdraw consent. Note: we are legally required to retain financial records for 10 years.
  • ▸Right to Restriction of Processing (Art. 18): Request that we limit how we process your data in certain circumstances (e.g., while we verify the accuracy of disputed data).
  • ▸Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format and transmit it to another controller, where processing is based on contract or consent and is automated.
  • ▸Right to Object (Art. 21): Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
  • ▸Rights Related to Automated Decision-Making (Art. 22): We do not engage in fully automated decision-making that produces legal or similarly significant effects.
  • ▸Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

We may ask you to verify your identity before processing your request. Exercising your rights is free of charge in most cases. If requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act.

9.Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • ▸Encryption of all data in transit using TLS/HTTPS.
  • ▸Encryption of sensitive data at rest in Supabase storage.
  • ▸Role-based access controls and Row-Level Security (RLS) on database tables.
  • ▸Secure, signed download URLs for product files with 48-hour expiry.
  • ▸Passwordless authentication to eliminate credential theft vectors.
  • ▸Regular security reviews and dependency updates.

No method of electronic storage or transmission is 100% secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected users without undue delay.

10.Cookies and Tracking Technologies

We use cookies and similar tracking technologies as described in our Cookie Policy. By using the Service, you consent to our use of cookies in accordance with the Cookie Policy. You can manage your cookie preferences at any time through your browser settings.

11.Children's Privacy

The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe we have inadvertently collected personal data from a child under 16, please contact us at privacy@speis.link and we will promptly delete the data upon verification.

12.Changes to This Policy

We may update this Privacy Policy from time to time. For material changes — such as new categories of data collected, new purposes, or new third-party sharing — we will notify you by email at least thirty (30) days before the changes take effect, and by posting the updated Policy on our website with a revised effective date.

Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. If you do not agree with the changes, you may delete your account before the new Policy takes effect.

13.Contact and Supervisory Authority

For questions, concerns, or to exercise your rights under this Privacy Policy, contact us at:

  • ▸Email: privacy@speis.link
  • ▸Company: [YOUR COMPANY NAME]
  • ▸Address: [YOUR REGISTERED ADDRESS], [YOUR CITY], Italy

If you are not satisfied with our response or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali):

  • ▸Website: www.garanteprivacy.it
  • ▸Address: Piazza Venezia 11, 00187 Roma, Italy
  • ▸Phone: +39 06 696771
  • ▸Email: garante@gpdp.it

If you reside in another EU member state, you may also lodge a complaint with the data protection authority of your country of residence.