Privacy Policy
Last updated: 14 August 2026
Issued by Stickteck LLC, EDRPOU 45548110, 18018 Cherkasy, vul. Solomianska 25, apt. 70, Ukraine.
1. Four kinds of people#
Most policies in this category lump everyone together. We don't, because the person who publishes a page and the person who fills in a form on it are in genuinely different positions.
| You are a… | Meaning | Our role |
|---|---|---|
| Website visitor | You visit stick.so without signing in | We are the controller |
| Creator | You have a stick account and publish pages | We are the controller |
| Published-page visitor | You look at a page someone published | We are the controller, for limited non-identifying statistics |
| Contact | You filled in a form on someone's page | The creator is the controller; we are their processor |
If you are a Contact, the creator whose page you used decides what happens to your data and their privacy notice governs, not this one. We hold it on their instructions under Terms §8. Ask them for corrections or deletion; if you cannot reach them, write to help@stick.so and we will help.
2. If you are a Creator#
What we collect. Your email address — that is genuinely all we require for a magic-link account. We do not ask for your name, we have no profile table, and we do not collect date of birth, gender, phone or address. Google sign-in gives us your email and basic profile; we do not request Drive, Calendar or Contacts access. Beyond that: what you build (pages, drafts, uploads, settings), support messages you send us, and technical data when you use the editor — IP, browser, device and error diagnostics.
If you only visit stick.so, we do not know your account email. When product analytics are enabled in
production, we measure page views, navigation and calls to action. In the signed-in product we also measure
feature use. Signed-in analytics use the Supabase user ID as the identifier, not the account email.
We do not buy data about you and we do not build advertising profiles.
Why, and on what basis:
| Purpose | Legal basis |
|---|---|
| Running your account, serving the editor, publishing your pages | Contract |
| Security, abuse and fraud prevention | Legitimate interests |
| Fixing errors, improving the product | Legitimate interests |
| Service email — security, billing, changes to terms | Contract / legal obligation |
| Product marketing email | Consent, withdrawable any time |
| Complying with law | Legal obligation |
We make no automated decisions about you with legal or similarly significant effects, and we do not profile you.
Cookies and analytics on stick.so and in the editor. Signing in sets Supabase authentication cookies
(sb-<project>-auth-token, plus a short-lived verifier during sign-in). They are strictly necessary — the
editor cannot work without them — so we do not ask consent for them. The current Supabase browser client sets
them SameSite=Lax, host-scoped to app.stick.so, and readable by the browser authentication client; they are
not shared with published pages.
When the production analytics keys are configured, stick.so and the editor use PostHog for product analytics
and Google Tag Manager to deliver configured measurement tags. These tools can use browser storage or cookies.
PostHog session replay is disabled everywhere except the page editor; in the editor it records clicks, drags
and layout changes while masking every input value. We do not use these tools to build advertising profiles.
3. If you visit a published page#
Published stick pages set no cookies of ours. None. No analytics cookie, no session cookie, no consent cookie, and no local or session storage. That is a property of how the pages are built, not a promise we are asking you to take on trust.
What we measure. Page views and link clicks, so creators can see whether their page works. Per event:
which page and block; your country only, derived at the network edge — never a city or precise location;
the hostname that referred you (instagram.com, never the full URL); coarse device, browser and operating
system categories derived from the user-agent; and a visitor hash. The raw user-agent is not stored.
How the hash works. We take your IP and user-agent, combine them with the creator's site ID and a secret salt we rotate at midnight UTC, hash it, and keep only the result. So:
- Your IP address and user-agent are never written to our database. They exist in memory long enough to compute the hash, then are discarded.
- The hash cannot be reversed to recover your IP.
- Because the salt changes daily, the same person's hash changes daily — we cannot follow you across days, build a profile, or link your activity across different creators' pages.
This is deliberately less capable than the analytics our competitors run, and we accept that trade.
We do not act on Do Not Track signals because we do not do the cross-site tracking DNT exists to stop.
Retention. Individual events are deleted automatically after 90 days. What survives is aggregate daily counts — views, clicks, referrer hostnames, country totals — containing nothing about any individual.
Legal basis: our legitimate interest, and the creator's, in knowing whether a page works. We store no direct identifier and no identifier that persists beyond a day.
4. If you are a Contact#
When you submit a form, we store it so the creator can see it. That always includes an email address (our forms require one) and may include your name, phone, free-text answers and checkbox responses — whatever that creator asked for. We keep the individual submission and a merged per-creator contact record, so repeat submissions from the same address appear once.
We do not use this for our own purposes. We do not market to you, sell it, share it with other creators, or add you to anything. We hold it for the creator, on their instructions.
We do not send campaigns to page contacts. Authentication emails for Creators are delivered through Supabase, but Stick does not provide a campaign-sending service for Contact records. If a creator emails you, they do it from their own tool, and their unsubscribe applies.
The creator is responsible for telling you why they collected it, having a lawful basis, and handling your requests. Retention: for as long as the creator keeps their account and has not deleted the record. If they delete their site or account, it goes too.
5. Third parties on published pages#
A creator can add blocks that make your browser contact other companies. Their own privacy policies apply, and the creator, not us, chose to include them:
| Feature | Third party | What they see |
|---|---|---|
| Embeds — YouTube, Vimeo, Twitch, Spotify, SoundCloud, Apple Music, TikTok | The provider, in a sandboxed iframe | Your IP, and their cookies once you interact |
| Embeds — Instagram, Threads, X, Telegram | The provider, running their code in the page itself | Your IP, page context, their own cookies. X is loaded with dnt: true. |
| Map block | Google Maps | Your IP and the embedded location |
| Link thumbnails (default) | Google's favicon service | Your IP and the hostname of the link shown |
| Stickers | GIPHY | Your IP |
| Emoji | Google's asset CDN | Your IP |
The four in the second row matter most: they execute third-party JavaScript with full page privileges and can set their own cookies. Where consent is required for that, it is the creator's responsibility.
Note that link thumbnails default to fetching a favicon from Google, so most pages disclose their outbound link hostnames to Google. Typography is self-hosted — we do not call Google Fonts for fonts.
6. Who we share with#
We do not sell personal data and do not share it for behavioural advertising. Our providers:
| Provider | For | Where | Data |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | AWS eu-central-1, Frankfurt | Account data, page content, contacts, uploads |
| Vercel Inc. | Hosting and delivery | Global delivery network | Requests to the website, editor and published pages |
| PostHog Inc. | Product analytics and editor replay, when enabled | EU ingestion endpoint | Page and product events, browser/device data, masked editor replay |
| Google LLC | Google Tag Manager, when enabled | Google infrastructure | Browser requests and data sent by configured measurement tags |
Our error tracking is self-hosted on our own server in Germany, not a third-party error-tracking service, so diagnostics stay on infrastructure we operate. It runs only in the editor — no error monitoring runs on published pages, so Visitors are never included.
Beyond these we disclose data only if the law requires it, to enforce our Terms, to protect someone from harm, or to a buyer of our business (we will tell you first, and this policy continues until replaced).
Not used by Stick on published pages: PostHog, Google Tag Manager and our self-hosted error monitoring do
not run on pages at *.stick.site. Embedded third-party blocks listed above can still contact their providers.
We do not use Mixpanel, Amplitude, Segment, Hotjar, FullStory or LogRocket. There are no AI or LLM features —
nothing you write is sent to a model provider.
7. Uploaded images are public#
Anything you upload is stored in a publicly readable bucket. The file is reachable by anyone with its URL; this is true whether or not your site is published; and unpublishing does not make images private again. Do not upload anything you would not want public. Images only (JPEG, PNG, GIF, WebP, AVIF, SVG), up to 10 MB.
8. How long we keep things#
| Data | Retention |
|---|---|
| Account data, pages, uploads | While your account exists |
| Contacts and form submissions | While the creator's account exists and they have not deleted them |
| Analytics events (individual) | 90 days, then dropped automatically |
| Analytics aggregates | Indefinitely — no individual data |
| Error diagnostics | 90 days |
| Product analytics and masked editor replay | According to the configured PostHog project retention; deleted sooner when required for a valid request |
| Backups | Daily, kept for 7 days, then overwritten |
We publish real numbers because neither Linktree nor Stan Store publishes any retention periods at all.
9. Where data goes#
We are established in Ukraine. Core account, page, contact and upload data is stored in the European Union —
the database and file storage are in Frankfurt (AWS eu-central-1), error diagnostics are on our own server in
Germany, and PostHog events go to its EU ingestion endpoint. Vercel serves requests through its global delivery
network. Google Tag Manager is delivered through Google's infrastructure and can transfer the data handled by
configured tags outside this core EU storage.
Supabase, Inc., Vercel Inc., PostHog Inc. and Google LLC are US companies. Their staff or infrastructure may process data outside the EU for support, maintenance or delivery as described above.
Data is encrypted in transit, and the database is encrypted at rest.
10. Your rights#
You can ask us to access, correct, delete, restrict or object to our use of your personal data, to port it, or to withdraw consent where we relied on it.
Write to help@stick.so. We respond within 30 days, free of charge, and will tell you if a complex request needs longer. We may need to verify who you are.
If you are a Contact, send these to the creator whose form you used — they are the controller. We will help if you cannot reach them.
You can complain to your data protection authority: in Ukraine the Ukrainian Parliament Commissioner for Human Rights, in the EU or UK your national supervisory authority or the ICO.
11. Children#
stick is not for anyone under 16, and you must be 16 to hold an account. We do not knowingly collect personal data from children under 16 — if you believe we have, write to help@stick.so and we will delete it. This single threshold applies everywhere.
12. Security#
Access to creator data is enforced at the database by row-level security, so one creator cannot read
another's data even if the application has a bug. Traffic is encrypted in transit. Auth cookies are
SameSite=Lax and host-scoped to the editor. Form submissions are validated server-side against the stored field schema, and
contact writes happen only in server-side code — never directly from a visitor's browser. Analytics are
built so the identifying inputs are never stored at all.
No system is perfectly secure and we do not claim otherwise. Report vulnerabilities to help@stick.so — we will not pursue good-faith research.
13. Changes and contact#
If we change this policy in a way that materially affects you, we will email you and give notice in the product at least 30 days beforehand. Smaller corrections take effect when published.
Reach us at help@stick.so for anything — privacy and data requests, security reports, or general questions. By post: Stickteck LLC, 18018 Cherkasy, vul. Solomianska 25, apt. 70, Ukraine.