Skip to content
← Back to home

Privacy Policy

Last updated: May 20, 2026

This Policy explains what data YourDirect (“we”) collects when you use our service (“Service”), why we collect it, and what rights you have over it. We try to keep it short and readable; if anything is unclear, email hello@yourdirect.link.

1. Who we are

YourDirect is the operator of yourdirect.link. We are the data controller for the personal data described below.

2. What we collect

From creators (account holders)

From visitors clicking your links (“fans”)

Fan data is kept on a per-link basis and shown to the creator that owns the link in aggregate. We do NOT build cross-creator profiles or sell fan data.

3. Why we collect it (lawful basis under GDPR)

4. Cookies and similar technologies

The public bouncer pages (yourdirect.link/<slug>) set NO advertising or analytics cookies and run NO cross-site trackers. They do set a small number of strictly-necessary security cookies — short-lived, signed tokens used only to tell real visitors apart from automated scanners so redirects work reliably — and, on some pages, run Cloudflare Turnstile for invisible bot detection (see below). The dashboard (app.yourdirect.link) uses one functional storage item to keep you signed in (your Supabase session token inlocalStorage). No third-party advertising or analytics cookies are set anywhere.

Cloudflare Turnstile (bot detection)

To stop automated scrapers from harvesting creators’ destination links, some pages use Cloudflare Turnstile, a privacy-preserving CAPTCHA alternative that runs invisibly — no puzzles, no cross-site tracking. Turnstile may process technical signals from your browser (such as a challenge token and a hashed device signal) solely to distinguish humans from bots. This processing is governed by the Cloudflare Turnstile Privacy Addendum. We do not use Turnstile to track you or to build an advertising profile.

5. Third parties we share data with

Each of these has their own privacy policies. We do not share personal data with anyone else, and we do not sell personal data.

6. International transfers

Some of our processors operate from the United States. Where required, transfers rely on Standard Contractual Clauses or other appropriate safeguards under GDPR.

7. How long we keep your data

8. Your rights

If you’re in the EU/UK/CA or another jurisdiction with similar laws, you have the right to:

Email hello@yourdirect.link to exercise any of these. We respond within 30 days.

9. Security

We use HTTPS everywhere, row-level security at the database layer, hashed IPs for fan analytics, and salted token-based authentication. We do not store passwords (we use magic-link email sign-in). No system is 100% secure; if you discover a vulnerability, please email us before disclosing publicly.

10. Children

The Service is not intended for users under 18. We do not knowingly collect data from anyone under that age. If you believe a child has provided us data, email us and we will delete it.

11. Changes to this Policy

Material changes will be announced by email or in-product notice and the “Last updated” date above will be revised.

12. Contact

Questions, requests, or complaints: hello@yourdirect.link.