Privacy Policy
Effective October 3, 2026
This policy covers LinkPostcard, also offered under the name LinkHangout (linkhangout.com). It is one service with one set of accounts, which gives creators one public page for their links, lessons, and podcast, and connects their creator platforms. It explains what personal data is collected, why, who it is shared with, how long it is kept, and the rights you have over it. It is written to meet the EU General Data Protection Regulation (GDPR), Portugal's data protection and electronic communications laws, and United States federal and state privacy laws.
Who is responsible for your data
LinkPostcard is operated by Erica Thompson (Brave Haven), the controller of your personal data. For anything about your data, email hr@bravehaven.io. No data protection officer has been appointed, because one is not required at this size.
The short version
- We collect only what the service needs, and use it only for the purposes below.
- We never sell your personal information, and never share it for advertising.
- Analytics stays off unless you accept it, sets no cookies, and you can change your mind at any time.
What we collect, why, and for how long
Your creator account
- What
- Email address, hashed password, name, page address (slug), bio, and avatar image link, whether and when you confirmed your email address, and, if you sign in with Google, GitHub or LinkedIn, the name and confirmed email address that provider shares
- Why we are allowed to
- Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
- How long we keep it
- For as long as you keep your account. Ask us to delete it and it is deleted within 30 days
Confirming your email address
- What
- A one-time link we email you when you sign up. We store only a scrambled (hashed) form of it
- Why we are allowed to
- Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
- How long we keep it
- Until you use it or it expires after 24 hours. Expired links are deleted the next time any confirmation link is sent or used
Your public page
- What
- The links, lessons, and podcast feed you add, and a count of how many times each link was clicked (a total, not who clicked)
- Why we are allowed to
- Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
- How long we keep it
- For as long as you keep your account. Ask us to delete it and it is deleted within 30 days
Connecting your platforms
- What
- If you connect YouTube, TikTok, Patreon, or Gumroad: your account ID there and the access tokens it issues, encrypted with AES-256-GCM before they are stored
- Why we are allowed to
- Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
- How long we keep it
- Until you disconnect the platform or delete your account
Your Pro plan
- What
- Your plan, and Stripe customer and subscription IDs and status
- Why we are allowed to
- Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
- How long we keep it
- For as long as you keep your account. Ask us to delete it and it is deleted within 30 days
Taking payment
- What
- Your email, what you bought, amount, and Stripe customer and payment IDs. Card details are handled by Stripe and never reach us
- Why we are allowed to
- Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b)), and legal obligation: tax and accounting law (gdpr art. 6(1)(c))
- How long we keep it
- As long as tax and accounting law requires, up to 10 years
Protecting signup and sign-in from bots (Vercel BotID)
- What
- When you sign up or sign in: signals from your browser and request that Vercel BotID uses to tell people from automated bots, such as browser and device characteristics and how the request was made. We receive only a verdict: person or bot
- Why we are allowed to
- Legitimate interests (GDPR Art. 6(1)(f)): keeping the service usable and protecting it from abuse
- How long we keep it
- We keep nothing. Vercel processes the signals to return the verdict
Running and securing the site
- What
- IP address, browser and device type, pages requested, and time of request, in server logs
- Why we are allowed to
- Legitimate interests (GDPR Art. 6(1)(f)): keeping the site working and protecting it from abuse
- How long we keep it
- No more than 30 days, then deleted automatically by our host
Understanding how the site is used (only if you accept)
- What
- When each page was viewed, the page address, the referring site, approximate location (country, region, city), browser, operating system, and device type. No cookies. Visits are told apart by a hash of the request that Vercel discards after 24 hours, so the data is not tied to you
- Why we are allowed to
- Consent (GDPR Art. 6(1)(a)). You can withdraw it at any time
- How long we keep it
- Vercel keeps it for our plan's reporting window, and may keep it longer. Withdrawing consent stops any further collection
What is public
Your creator page is public by design: your name, bio, avatar, links, lessons, and podcast episodes can be seen by anyone with the link.
Cookies and similar technologies
These are strictly necessary for the site to work, so they do not need your consent:
- Sign-in session cookies: Keep you signed in and protect sign-in from forgery. Kept: Until you sign out, or 30 days.
- analytics-consent (localStorage): Remembers your analytics choice. Kept: Until you clear it.
Vercel Web Analytics sets no cookies. Its script is loaded only if you choose Accept analytics; until then nothing about your visit is sent to it. You can change your choice at any time with Analytics settings at the bottom of every page. If your browser sends a Global Privacy Control signal, we treat it as a refusal and do not ask.
Who we share it with
We use these service providers (processors). Each may use your data only to provide its service to us, under a data processing agreement:
- Vercel: Hosts the site and keeps short-lived server logs. Runs Web Analytics, only if you accept. Checks signup and sign-in requests for bots (BotID), returning only a verdict. Location: United States.
- Resend: Sends the email that confirms a new account's address. Receives your email address and name. Location: United States.
- Google: Signs you in, only if you choose “Continue with Google”. Shares your name and confirmed email address with us. Location: United States.
- GitHub: Signs you in, only if you choose “Continue with GitHub”. Shares your name and the email addresses on your GitHub account with whether each is confirmed; we use and keep only the confirmed primary one. Location: United States.
- LinkedIn: Signs you in, only if you choose “Continue with LinkedIn”. Shares your name and confirmed email address with us. Location: United States.
- Our managed PostgreSQL provider: Stores the account data described above. Location: United States.
- Stripe: Takes payments. Card details go to Stripe directly and never reach us. Location: United States.
You may also use these services, which are responsible for your data themselves:
- YouTube, TikTok, Patreon, Gumroad: You approve each connection on that platform's own page, and can revoke it there at any time. Each platform is responsible for its own data.
We do not sell personal information and do not share it for cross-context behavioral advertising. We would disclose data to authorities only where the law requires it.
International transfers
Our providers store or process data in the United States. For transfers of personal data from the European Economic Area, the UK, or Switzerland, we rely on the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses in the provider's data processing terms.
Your rights
In the European Union, the UK, and Switzerland
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: have your data deleted.
- Restriction: ask us to stop using your data while a concern is resolved.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on our legitimate interests.
- Withdraw consent at any time, without affecting what was done before.
You can complain to a data protection authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt. Elsewhere, contact the authority where you live or work. We would appreciate the chance to put things right first.
In the United States
Depending on your state (including California, Colorado, Connecticut, Virginia, Texas, and others with comprehensive privacy laws), you may have the right to know what personal information we collect and how we use it, to access it, to correct it, to delete it, and to opt out of its sale, of targeted advertising, and of profiling. We do none of those three. We will not treat you differently for using any of these rights. You can use an authorized agent, and if we turn down a request you can appeal by replying to our answer.
How to make a request
Email hr@bravehaven.io and say what you would like. To protect your account, we will ask you to confirm the request from the email address on it. We answer within one month (GDPR), or within 45 days for US state privacy law requests, and tell you if a complex request needs longer. Requests are free.
How we protect it
- Every connection is encrypted with HTTPS
- New accounts must confirm their email address before they can sign in. Confirmation links work once, expire after 24 hours, are stored only hashed, and are deleted once used or expired
- Every signup and sign-in request is checked by Vercel BotID on the server and refused unless confirmed as a person
- Passwords are stored only as bcrypt hashes
- Platform tokens are encrypted with AES-256-GCM before they are stored
Children
LinkPostcard is not intended for anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
When this policy changes, we update this page and its effective date, and email account holders about significant changes.