Privacy policy
Last updated August 12, 2026
The short version. For creators we keep an email address, a public profile, and the cards you make. For the people who visit your page we keep a count of views, taps and copies, plus a hashed IP, a country, and whether the device was a phone. We do not store raw IP addresses, we do not store precise location, we do not build advertising profiles, and we do not sell anything about anyone.
1. Who this covers
Two different people use this service and they are treated differently. A creator has an account. A visitor is someone who opens a creator’s public page and never signs in. Most of the data in this product is about neither: it is about links and codes.
2. What we collect from creators
- Email address. Required, because it is how you sign in. We use it for sign-in links and for account notices. It is never shown on your public page.
- Public profile. Handle, display name, avatar, bio, social links, and vertical. This is deliberately public: it is your page. If you connect a TikTok or Instagram handle at signup we read the public profile for those fields, and you can edit or clear any of them.
- Your cards. Brand, discount label, promo code, destination link, image, and ordering.
- Content you attach. The URL of a post you paste in, the platform it is on, and the public view, like, comment and share counts for that post over time. We read public numbers only. We never ask for and never hold a platform password or a posting permission.
- Optional figures you enter. For example, prior monthly affiliate income, if you choose to give it. Used to measure whether the product actually helps, never shown publicly.
- Payout details, only if payouts apply to you. Handled by Stripe. We store the Stripe account identifier and whether tax onboarding is complete. Bank details and tax forms go to Stripe directly and we never see or store them.
3. What we collect from page visitors
When someone opens a creator page, taps a link, or copies a code, one event row is written. The whole row is:
- Which card and which creator the event belongs to.
- Event type: view, click, or copy.
- Timestamp.
- Referrer host only. For example
tiktok.com. Never the full URL, never the path or query string. - Country, as a two-letter code. Nothing finer. No city, no region, no coordinates, no precise geolocation of any kind.
- A coarse device bucket, such as phone, tablet, or desktop.
- A hashed IP address. The IP is combined with a secret salt and hashed, and the salt rotates. The raw address is never written to the database and the hash is not reversible. It exists for one purpose: telling one visitor apart from a thousand fake ones during fraud checks.
There is no cookie set on a creator page for tracking, no advertising pixel, no cross-site identifier, and no fingerprinting. Nothing about a visitor is sold, shared for advertising, or used to target anyone anywhere else.
4. Cookies
- Sign-in cookies on the dashboard and admin areas. Strictly necessary: without them you cannot stay signed in.
- Product analytics on the marketing site and the dashboard, when it is enabled. It records which steps of setup people complete, so we can find where the product loses people. It honors the Do Not Track signal, and when Do Not Track is on, the analytics script is never loaded at all. It also does not run on creator pages, so somebody who arrives from a video and never signs up is not measured by it.
5. Who we share it with
Service providers only, each doing one job for us, none of them permitted to use the data for their own purposes:
- Supabase for the database, authentication, and file storage.
- Vercel and Cloudflare for hosting, the edge cache, and the redirects.
- PostHog for product analytics, and Sentry for error reports.
- Stripe for payouts and tax reporting, if and when payouts apply to you.
- Affiliate networks, only for cards you deliberately add from the network layer, and only the identifiers needed to attribute a sale back to you. A link you brought yourself is never sent anywhere.
We also disclose information where the law requires it, and we will tell you when we are permitted to.
6. What we never do
- Sell personal information, under any definition of sell.
- Share it for cross-context behavioral advertising.
- Store raw IP addresses or precise location.
- Read your direct messages, your drafts, or anything on a platform that is not publicly visible.
- Use your data to train a model that decides what you get paid.
7. How long we keep it
Account data lives until you delete the account. Individual event rows are stored in monthly partitions and are pruned once the daily totals they feed have been calculated; the daily totals, which are counts with nothing personal in them, are kept for the life of the page. Records we are required to keep for tax or accounting reasons, such as payout history, are kept for the period the law requires.
8. Your rights
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. If you are in the EU, the UK, or a country with similar law, that also includes the rights to restrict processing, to object to it, and to receive your data in a portable form, and you may complain to your local data protection authority. If you are in California, it includes the rights to know, delete, correct, and to opt out of sale or sharing. There is nothing to opt out of, because we do neither.
Deleting everything
Deleting your account from the dashboard is the complete action, not a deactivation. Removing your creator record cascades: your cards, your attached content and its history, your event rows, your manual earnings entries, and your public page all go with it. The page returns a 404 and your handle is released.
If you cannot reach the dashboard, email privacy@usecode.sh from the address on the account and we will do it for you. We respond within 30 days.
9. Where data is processed
Our providers process data in the United States and in other countries where they operate infrastructure. Where a transfer out of the EU or UK needs a legal basis, it relies on the standard contractual clauses in our agreements with those providers.
10. Children
This service is not for anyone under 18, and we do not knowingly collect information from children. If you believe a child has an account, email us and we will remove it.
11. Security
Access to data is enforced at the database with row level security, so a creator can only read their own private rows even if an application bug asked for more. Money tables are writable only by background jobs, never by a browser. Secrets for affiliate networks are held in a vault and are never present in the web application.
12. Changes
Updates are posted here with a new date. If a change means we start collecting something materially new, account holders get an email before it takes effect.
13. Contact
privacy@usecode.sh. Related reading: terms of use and the disclosure guide.