Our Privacy Principles
Zero Tracking
We don't use cookies, pixels, or any tracking technology to monitor your visitors' behavior.
Data Minimization
We only collect the absolute minimum data necessary to provide our service.
What Information We Collect
Account Information
- • Email address: Required for account creation and login
- • Username: Your chosen public identifier
- • Profile information: Bio, avatar, social links (optional)
- • Links: URLs and titles you add to your profile
Usage Analytics (Privacy-First)
We collect minimal, anonymous analytics to help you understand your link performance:
- • Click counts: How many times each link was clicked
- • Page views: How many times your profile was viewed
- • Referrer domain: General source (e.g., "instagram.com") without specific URLs
✓ No IP addresses stored • ✓ No device fingerprinting • ✓ No behavioral tracking
Technical Information
- • Server logs: Temporary logs for debugging (deleted after 7 days)
- • Security monitoring: Failed login attempts to protect your account
What We DON'T Collect
- ✗ Personal browsing history
- ✗ Location data or GPS coordinates
- ✗ Device fingerprints or identifiers
- ✗ Social media activity outside Spookie
- ✗ Email content or private messages
- ✗ Detailed demographic or behavioral profiles
- ✗ Third-party tracking pixels or cookies
How We Use Your Information
Service Provision
To create and maintain your link-in-bio profile, process clicks, and provide analytics.
Account Security
To protect your account from unauthorized access and ensure platform security.
Communication
To send essential service updates, security alerts, and respond to support requests.
Data Sharing and Disclosure
Our Promise
We never sell, rent, or trade your personal information to third parties.
Service Providers
We work with trusted partners who help us provide our service:
- • Supabase: Database and authentication (SOC 2 compliant)
- • Vercel: Hosting and content delivery
These partners are contractually bound to protect your data and use it only for providing our service.
Legal Requirements
We may disclose information only when required by law, such as:
- • Valid legal subpoenas or court orders
- • Preventing fraud or security threats
- • Protecting the rights and safety of our users
Your Privacy Rights (GDPR Compliant)
As a user in Ireland/EU, you have enhanced rights under GDPR. We're committed to upholding these rights and making them easy to exercise.
Right of Access (Art. 15 GDPR)
Download all your data from your dashboard at any time. Request details about how we process your data.
Right to Rectification (Art. 16 GDPR)
Update your profile and account information anytime. Request correction of inaccurate data.
Right to Object (Art. 21 GDPR)
Object to processing for direct marketing or legitimate interests at any time.
Right to Erasure (Art. 17 GDPR)
Permanently delete your account and all associated data. "Right to be forgotten" applies.
Right to Portability (Art. 20 GDPR)
Export your data in machine-readable formats to take to another service.
Right to Restrict Processing (Art. 18 GDPR)
Request limitation of processing under specific circumstances outlined in GDPR.
Exercising Your Rights
Contact our Data Protection Officer (DPO) at privacy@spook.ie to exercise any of these rights. We'll respond within 30 days as required by GDPR.
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC) if you believe we're not handling your data correctly.
Data Security
Encryption
All data is encrypted in transit (TLS) and at rest (AES-256).
Access Controls
Strict access controls and regular security audits protect your data.
Team Training
Our team is trained on privacy best practices and data handling.
Contact Us
Questions about this privacy policy or how we handle your data? We're here to help.
Email: privacy@spook.ie
Response Time: Within 48 hours
Policy Updates
If we make material changes to this privacy policy, we'll notify you by email and update the "Last updated" date above. We'll never reduce your privacy rights without your explicit consent.