Privacy Policy
Last updated: 8 October 2026
livelinks (livelinks.me) is a free link-in-bio page for live streamers. This policy explains, in plain English, what personal data we collect, where it comes from, why we use it, the lawful basis for each use, who helps us process it, how long we keep it and what rights you have. It applies to streamers who create an account and to everyone who visits a livelinks page.
1. Who we are
[Operator name and address to be added]
livelinks is run by one person in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the operator named above is the controller of the personal data described in this policy. In this policy, "we", "us" and "our" mean that operator, and "you" means anyone who uses livelinks, whether as an account holder or a visitor.
We have not appointed a Data Protection Officer because we are not required to. For anything to do with your data, email Livelinkuk@outlook.com.
2. The short version
- We collect what we need to give you an account and a public page, show you simple stats and send live notifications to people who ask for them.
- Everything you put on your page is public.
- We do not sell personal data, we do not show ads and we do not use advertising or analytics trackers.
- Our page view and click counts do not record the visitor's IP address or any identifier. They only note broad categories: country, the app or website the visitor came from, and whether it was a phone, tablet or computer.
- You can delete your account and page yourself, at any time, from Settings.
3. What we collect and why
The table below lists each type of personal data we hold, where it comes from, what we use it for, our lawful basis under Article 6 of the UK GDPR, and how long we keep it. "Contract" means the processing is necessary to provide the service you signed up for (Article 6(1)(b)). "Legitimate interests" means it is necessary for our legitimate interests, or those of a third party, and those interests are not overridden by yours (Article 6(1)(f)). "Consent" means you agreed to it and can withdraw that agreement at any time (Article 6(1)(a)). "Legal obligation" means we must do it by law (Article 6(1)(c)).
| Data | Source | Purpose | Lawful basis | Retention |
|---|---|---|---|---|
| Email address and password (email sign-up) | You | Creating your account, logging you in, confirming your address, password resets and essential service messages | Contract | Until your account is deleted. Passwords are stored only as a one-way hash by our authentication provider; we cannot see them. |
| Sign-in provider details (Google, Discord, Twitch) | The provider you choose | Creating and logging into your account; your name from the provider becomes your starting display name | Contract | Until your account is deleted |
| TikTok sign-in details | TikTok | Creating and logging into your account; suggesting your TikTok username as your link; using your TikTok picture and name as your starting profile | Contract | Until your account is deleted |
| Sign-in and session records (IP address, browser type, times) | Your device, recorded by our authentication provider | Keeping you signed in, security, preventing abuse and investigating problems | Legitimate interests (keeping accounts secure) | Session records go when you log out or your account is deleted; security logs are kept by our providers for their standard periods |
| Username, display name, bio and profile picture | You (or your sign-in provider at first) | Showing your public page at livelinks.me/yourname | Contract | Until you change them or delete your account |
| Page content: links, social handles, text, headings, stream schedule, countdowns, embedded videos and music, images, contact email button, top gifters list | You | Showing your public page | Contract | Until you remove it or delete your account |
| Badges, including custom badge names and images | You; the "verified" mark is set by us | Showing badges on your page; checking and marking claims as verified | Contract; legitimate interests (keeping badges honest) | Until you remove them or delete your account |
| Design and page settings (theme, fonts, layout, 18+ warning, live status, page title and description, notification bell on/off, editor tour and set-up progress, your answer to "Where do you stream?") | You | Showing your page the way you designed it and running the editor | Contract | Until you change them or delete your account |
| Plan details: Free or Pro, how Pro was unlocked (invite code, or a past free trial), any trial end date, invite codes you redeemed and when | You and our systems | Giving you the right features, ending trials on time, making sure each code and trial is used properly | Contract; legitimate interests (preventing misuse of trials and codes) | Until your account is deleted |
| Page views and link clicks | Visitors' browsers | Showing the page owner how many views and clicks their page gets | Contract (for the page owner); legitimate interests (for visitors, whose identity is not recorded) | Until the page owner's account is deleted |
| Live notification subscriptions (a push address and encryption keys for a browser) | Visitors who tap the bell and allow notifications | Sending that streamer's "is LIVE" notifications | Consent | Until the visitor turns them off, the browser reports the subscription has ended, or the streamer's account is deleted |
| Uploaded images (profile pictures, image blocks, custom badges) | You (and TikTok, for a TikTok profile picture) | Showing them on your page | Contract | Until your account is deleted. Images you replace or remove in the editor may stay in storage until then (see section 11). |
| Emails you send us (support, reports, rights requests, takedown notices) | You | Answering you, handling reports and complaints, keeping a record of what we did | Legitimate interests; legal obligation where the law requires us to act on or keep records of reports | Up to 2 years after the matter is closed, or longer if needed for a legal claim or required by law |
| Technical logs held by our hosts (IP address, browser, pages or files requested, time) | Your device, recorded by Netlify and Supabase | Delivering the site, security, preventing abuse, fixing faults | Legitimate interests | The providers' standard log periods, which are usually short; we do not copy them elsewhere |
If we ever need to share data with the police, a regulator or a court, our lawful basis is legal obligation or, where there is no obligation but there is a serious risk to someone, our legitimate interest in protecting people (and, in an emergency, someone's vital interests under Article 6(1)(d)).
We do not collect special category data (such as health, religion or sexual orientation) on purpose. If you choose to put something like that on your public page, you are making it public yourself.
4. Data from sign-in providers
You can sign up with an email address and password, or sign in with Google, Discord, Twitch or TikTok. We never receive your password for those services and we never post to them.
Google, Discord and Twitch
These sign-ins are handled by our authentication provider, Supabase. After you agree on the provider's own screen, the provider sends the basic profile it shares with apps, which usually means your email address, your name or username, a link to your profile picture and your user ID with that provider. Supabase stores that information with your account. We copy your name into your livelinks display name, which you can change. We do not put your provider's profile picture on your page; it stays only in your account record.
TikTok
TikTok sign-in runs through our own small server function, because our authentication provider does not support TikTok. When you sign in with TikTok we ask TikTok only for basic profile information. TikTok sends us:
- your TikTok open ID (an identifier TikTok creates for you that is specific to livelinks), which we use to recognise you each time you sign in;
- your TikTok display name, which becomes your starting livelinks display name;
- your TikTok username, which becomes your livelinks link if nobody else has it; and
- links to your TikTok profile picture. Because TikTok's picture links expire, we download a copy of the picture and store it in our own storage as your profile picture. You can replace or remove it at any time.
TikTok does not give us your email address. So that your account works with our sign-in system, we create an internal address of the form tiktok-…@users.livelinks.gg. It is not a real mailbox and we never send email to it. We use TikTok's temporary access token once, to fetch the details above, and we do not store it. During TikTok sign-in we also set a short-lived security cookie (see the Cookie Policy).
How each provider handles your data on its own side is covered by that provider's privacy policy.
5. Your page is public
Everything you put on your livelinks page is public. Anyone with the link can see it, it can be found by search engines, and it can be shared, copied, screenshotted or archived by other people and services. This includes your username, display name, bio, pictures, links, badges, schedule, top gifters list and any email address you add to an email button.
The information that makes up your page is also readable by anyone through the same public data connection the page itself uses. That includes your plan (Free or Pro) and, if you are on a trial, when it ends; your design and page settings; and the content of blocks you have hidden from your page. Please do not put anything in a hidden block that you would not want to be public.
When you change or delete something, it disappears from livelinks, but we cannot remove copies other people or services have already made, such as search engine caches, web archives or screenshots. You may be able to ask search engines to refresh or remove out-of-date results using their own tools.
6. Visitors to livelinks pages
You do not need an account to look at a livelinks page. When you do:
- Page views and clicks. When a page opens, and when you tap a link on it, we record that a view or click happened, which page it was on, which link (for clicks) and the time. We also note three broad categories: your country (worked out by our server from your connection at the moment you visit; your IP address is not stored), the app or website that sent you (for example TikTok or Discord), and whether you're on a phone, tablet or computer. We do not record your IP address, exact location, browser details or any identifier for you, so these records can't be linked to you. The page owner sees only totals.
- Live notifications (only if you ask). If you tap the bell and your browser asks whether to allow notifications and you agree, your browser creates a push subscription. We store its push address (a web address at your browser's push service) and the two encryption keys needed to send to it, linked to that streamer. We use it only to send that streamer's "is LIVE" notifications, at most once every 30 minutes. Notification content is encrypted on its way through your browser maker's push service. You can turn notifications off by tapping the bell again, which deletes the subscription for that streamer, or by blocking notifications for livelinks in your browser settings. Your browser also stores a small service worker file from livelinks so it can show notifications.
- 18+ warning. Some pages ask you to confirm you are 18 or older before they open. Your answer is not stored.
- Server logs. Our hosting providers (Netlify for the website and Supabase for the data behind it) automatically log technical details of each request, such as IP address, browser type and the address requested, to deliver the site and keep it secure.
- Third-party content. Fonts, some icons and code libraries load from outside providers, and a page may include embedded YouTube, TikTok or Spotify players chosen by the page owner. Embedded players only load after you agree through the cookie banner or tap a player's Load button. Your browser then connects to those providers directly, so they receive your IP address and may set their own cookies. See section 9 and the Cookie Policy.
- Links. When you tap a link on a page you leave livelinks. The website you go to has its own privacy policy, and we are not responsible for it.
7. Information about other people
Some features let account holders add information about other people, for example the names of top gifters, a supporter's name in text, or images that show other people. When you do this, you are responsible for making sure you have the right to share it, that it is accurate, and that the person would reasonably expect it to appear on your page. Do not add anyone's private information, such as a home address, phone number or real name they have not made public (see our Acceptable Use Policy).
If you are named on someone's page and want it removed, ask them first. If they will not remove it, or you cannot reach them, use our report page and we will look at it.
8. Cookies and browser storage
livelinks does not use advertising cookies, analytics cookies or tracking pixels. Our own storage on your device is limited to what the site needs to work: keeping you signed in, carrying your chosen username through sign-up, a short-lived security cookie during TikTok sign-in, and remembering whether you turned on or dismissed live notifications for a page. Embedded YouTube, TikTok and Spotify players that a page owner adds are run by those companies and may set their own cookies. Every item is listed in our Cookie & Storage Policy.
9. Who processes data for us
We use a small number of providers. Some process data only on our instructions (processors). Others receive data directly from your browser or when you choose to use them, and decide themselves how to use it under their own privacy policies (independent controllers).
| Provider | What they do | Data involved | Role |
|---|---|---|---|
| Supabase, Inc. | Our database, user accounts and sign-in, image storage, account emails (confirmation and password reset) and the server functions for TikTok sign-in and live notifications | All account and page data in section 3, sign-in and request logs | Processor |
| Netlify, Inc. | Hosts and delivers the website | IP address, browser details and request logs | Processor |
| Google (Google Fonts) | Serves the fonts used on the site and on pages (including the extra fonts a page owner chooses, which load only when needed) | IP address and browser details sent by your browser | Independent controller |
| jsDelivr and unpkg | Public content delivery networks that serve the code library we use to talk to Supabase (jsDelivr) and the icon set used on the home page and editor (unpkg) | IP address and browser details sent by your browser | Independent controllers |
| Google, Discord, Twitch and TikTok (sign-in) | Let you sign in with an existing account, only if you choose to | The profile details described in section 4 | Independent controllers |
| Browser push services (for example Google for Chrome, Mozilla for Firefox, Apple for Safari, Microsoft for Edge) | Deliver live notifications to visitors who turned them on | The push address and an encrypted notification message | Independent controllers |
| YouTube (Google), TikTok and Spotify (embedded players) | Show videos and music that a page owner has embedded | IP address, browser details and any cookies those companies set | Independent controllers |
We may also share data if we sell or transfer livelinks to someone else (they would have to keep protecting it in line with this policy), or if the law requires it. We do not share data with anyone else.
10. International transfers
Some of the providers above are based in, or use servers in, countries outside the UK, including the United States, so your data may be processed outside the UK. We have not confirmed that our database is hosted in the UK, so you should assume it may be outside the UK.
When personal data we control is transferred outside the UK, we rely on one of the safeguards allowed by UK data protection law:
- UK "adequacy regulations", which recognise that a country (such as those in the European Economic Area) protects personal data to a standard the UK accepts;
- for US companies certified under it, the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"); or
- the International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, which our providers include in their data processing terms.
You can ask us for more information about the safeguard used for a particular provider.
11. How long we keep data
- Your account and page: for as long as your account exists. We do not currently delete inactive accounts automatically, but we may contact you, and then close an account and free its username, if it has been unused for a long time (see our Terms).
- Images you replace or remove: when you upload a new picture, the old file may stay in storage, not linked from your page, until your account is deleted. Its address would only be known to someone who had already seen it. If you want a particular image removed sooner, email us.
- Page view and click records: until the page owner's account is deleted.
- Live notification subscriptions: until turned off, until your browser reports they have ended, or until the streamer's account is deleted.
- Emails and reports: up to 2 years after the matter is closed, unless we need them longer for a legal claim or the law requires it.
- Provider logs and backups: for the providers' standard periods (see section 12).
12. Deleting your account
You can delete your account yourself at any time from Settings → Delete account and link in the editor. When you do:
- The images in your storage folder (profile pictures, image blocks, custom badge images and any copied TikTok picture) are deleted.
- Your account is deleted, and with it, automatically: your profile, page content and settings, badges, page view and click records, the live notification subscriptions for your page, and the record of invite codes you redeemed.
- Your username becomes free for someone else to claim.
Some things are not removed straight away, or are outside our control:
- Backups. Our database provider keeps backups for a limited period for disaster recovery. Deleted data stays in those backups until they expire and is not used for anything else. If we ever restore from a backup, we will delete again any accounts that had been deleted.
- Logs. Our hosting and database providers' technical logs expire on their own schedules.
- Copies made by others, such as search engine caches, archives and screenshots (see section 5).
- Emails we have exchanged with you, and records we must keep by law.
- Usage totals. The count of how many times an invite code has been used does not go down.
- Notifications you signed up for as a visitor on other people's pages are not connected to your account. Turn them off with the bell on each page or in your browser settings.
If you cannot log in, email Livelinkuk@outlook.com and we will delete your account once we have confirmed it is yours.
13. Security
We use reasonable technical and organisational measures to protect personal data. These include encrypted connections (HTTPS), passwords stored only as hashes by our authentication provider, database rules that let each person change only their own data, private storage of invite codes, and a signed, time-limited check during TikTok sign-in. We use established providers rather than running our own servers.
No method of sending or storing data over the internet is completely secure, so we cannot guarantee absolute security. Please use a strong password that you do not use anywhere else, keep your sign-in provider accounts secure, and tell us straight away at Livelinkuk@outlook.com if you think someone has accessed your account. If a personal data breach is likely to put your rights at risk, we will tell the ICO within 72 hours of finding out where the law requires it, and tell you without undue delay if the risk is high.
14. Children
livelinks is for people aged 13 or older, or the minimum age for using online services like this where they live, if that is higher. If you are under 18, you should have permission from a parent or guardian before creating a page. We do not knowingly collect personal data from children under 13. If we find out that we have, we will delete the account and its data. If you think a child under 13 has an account, please email us or use the report page.
We take the ICO's Age Appropriate Design Code (the Children's Code) into account. In particular, we do not show ads, we do not profile users or track them across other sites, we do not collect location data, page statistics do not identify visitors, and notifications are off unless a visitor turns them on. Because livelinks pages are public by design, younger users should think carefully about what they share and should not include personal details such as where they live or go to school.
15. Your rights
Under UK data protection law you have the following rights. Some apply only in certain circumstances.
- Access: ask for a copy of the personal data we hold about you and information about how we use it.
- Rectification: ask us to correct inaccurate data or complete incomplete data. You can edit most of your data yourself in the editor.
- Erasure: ask us to delete your data. You can delete your account yourself at any time (see section 12).
- Restriction: ask us to limit how we use your data, for example while we check its accuracy.
- Portability: ask for the data you gave us in a structured, commonly used, machine-readable format (such as JSON), or ask us to send it to another organisation where that is technically feasible.
- Objection: object to processing we carry out on the basis of legitimate interests. We will stop unless we have compelling legitimate grounds that override your interests, or we need the data for a legal claim.
- Withdrawing consent: where we rely on consent (live notifications), withdraw it at any time by turning notifications off. This does not affect anything we did before you withdrew it.
How to use your rights. Email Livelinkuk@outlook.com, ideally from the email address on your account, and tell us which right you want to use. For TikTok accounts, include your livelinks username. If we need to check your identity, we will ask for the minimum information needed, for example asking you to confirm the request from inside your account; we will not ask for official ID unless it is genuinely necessary. Visitors who turned on notifications should include the page they signed up on, as we cannot otherwise link a subscription to them.
We will respond within one month of receiving your request (or of confirming your identity, if we need to). If a request is complex or you send several, we may extend this by up to two further months, and we will tell you why within the first month. Using your rights is free, unless a request is clearly unfounded or excessive, in which case we may charge a reasonable fee or refuse, and we will explain why.
16. Complaining to the ICO
If you are unhappy with how we have handled your personal data, please contact us first so we can try to put it right. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
17. Visitors from the EEA and California
European Economic Area. If you are in the EEA, the EU General Data Protection Regulation may also apply. You have the same rights described in section 15, using the same lawful bases described in section 3, and you can complain to the data protection authority in the EEA country where you live or work.
California. We do not sell personal information, and we do not share it for cross-context behavioural (targeted) advertising, as those terms are defined in the California Consumer Privacy Act. We do not use or disclose sensitive personal information for purposes that would give you a right to limit it. To the extent California law applies to us, you can ask to know, correct or delete your personal information using the contact details below, and we will not discriminate against you for doing so.
18. Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects, and we do not profile users. Our systems apply simple, automatic rules, such as ending a free trial after 30 days, limiting how many badges a Free page shows, or checking whether a username is available, but these simply carry out the terms you signed up to.
19. Changes to this policy
We may update this policy when livelinks changes or the law changes. We will post the new version on this page and change the "Last updated" date. If a change significantly affects how we use your personal data, we will tell account holders before it takes effect, for example by a notice in the editor or by email.
20. Contact
For any question about this policy or your personal data, email Livelinkuk@outlook.com.
[Operator name and address to be added]