Privacy Policy

Last updated 24 August 2026

This text is written from what the software actually does and has not yet been through a legal review. It is accurate about the product. It is not legal advice, and the wording may change once a lawyer has read it.

What this policy covers

This policy covers OneLink at onelink.boo: the account you sign up with, the bio page you publish, and the people who visit it. It describes what the product does today rather than what it may do later. When something here stops being true, the text changes and the date above it changes with it.

The account you create

Signing up stores your email address, the display name you choose, the date the account was created, and which plan you are on. Your password is not stored here. Authentication runs on Firebase Authentication, which holds the credential.

Your page and its links

A page stores the address you claimed, its title, your short bio, the theme, whether it is published, and a visit count. Each link on it stores a label, the destination, its position, an optional icon, whether it is visible, and a click count. Once you publish the page, all of that is public, which is what the page is for.

Feedback you send

Sending feedback from the dashboard stores the message along with your account id and your email address, so that a reply can reach you.

Moderation records

If a page is suspended, an append-only record of the action is written: what was done, to which address, and when. These records stay on the server. No client can read them or change them.

People who visit your page

No record is kept of any individual visitor. Visits and clicks are counters on a document, incremented and never attributed to anyone. No IP address is retained. The rate limiter that protects the write endpoints holds addresses in memory for one minute and writes none of them anywhere.

Where the data sits

In Google Cloud Firestore, in the europe-west3 region, which is Frankfurt in Germany. Some of the processors named below operate outside the European Union, so mail and hosting data reaches them there.

Who else processes it

Google Cloud and Firebase run authentication and the database. Vercel hosts the site and provides Web Analytics, which is sampled, aggregated, and sets no cookie. Resend delivers the mail the product sends. There is no payment processor yet, and no third-party analytics product beyond the one named here.

Cookies

One cookie, and it is your signed-in session. It is strictly necessary: without it you cannot stay logged in. Nothing here sets an advertising or a tracking cookie, which is why the site asks you to accept nothing.

Email we send

Signing up sends a verification message, and finishing onboarding sends you the address of your new page. Both are transactional. There is no mailing list, no newsletter and no marketing email.

Getting a copy of your data

Ask, and your account, your page and your links are exported and sent to you. The export runs on request rather than from a control in the dashboard: the code that builds it exists, the button that would call it is not mounted yet.

Deleting your account or your page

Deletion is a manual request rather than something you can do yourself. The database refuses deletion of accounts, pages and links to every client, so no control in the product can do it. Write to the address below and it is done by hand. Until that request is handled, an address you have claimed stays claimed.

Your rights

Under the GDPR you can ask what is held about you, ask for a copy of it, ask for it to be corrected, and ask for it to be deleted. Each of those is handled by writing to the address below, and the answer comes from a person rather than from a form.

Changes to this policy

When the product changes what it stores, this page changes with it and the date at the top moves. There is no notification list, so that date is the thing to check.

How to reach us

Questions about this policy, and any request made under it, go to:

support@onelink.boo