Privacy notice.
Version 27 September 2026
This notice applies to DonoLink's website, accounts, public donation pages, payments, dashboards, overlays, support, waitlist and stream integrations. It explains which personal data we process, why, for how long, and what choices and rights you have.
1. Who is responsible?
Tovix, trading as DonoLink, sole proprietorship, Dutch Chamber of Commerce 98227475 and VAT NL005316890B06, is the controller for the DonoLink processing described in this notice. Contact: [email protected]. DonoLink is not responsible for processing for which a creator, Stripe, a bank, payment method or connected streaming platform independently determines the purposes and means; that party is the controller under its own privacy terms. DonoLink remains responsible for its own selection, engagement and disclosure to the extent required by the GDPR.
2. What data and sources?
Account and profile data: name, email address, username, password hash, verification status, profile image/banner, bio, language, social channels, settings, two-factor status and encrypted or restricted authentication secret. We receive these from you, PocketBase or a selected social login provider.
Donation and payment data: name or nickname, message, amount, currency, payment method, status, time, transaction IDs, terms version and acceptance time. An optional email address and full payment, identity and bank details are processed directly by Stripe; DonoLink does not store a full card number, IBAN or identity document.
Content and communications: public profile content, alert media, media requests, import data, support tickets, emails and information in reports, complaints, refunds or disputes.
Streaming integrations: account and channel IDs, display name, OAuth tokens and scopes, connection status and visible live events from Twitch, Kick, YouTube, TikTok or Streamlabs, such as name, chat message, follow, subscription, gift, bits, raid, Super Chat or membership. Import keys are used only to perform the selected import and are not stored as profile data.
Referral data: the referral code you signed up with, the time, the referrer and an encrypted hash of your IP address at sign-up (never the IP itself); for referrers also their own code, the percentage, hashed IPs of recent visits, commission entries per donation (platform fee, percentage, amount, status and Stripe payment reference), the outcome of the abuse check and payouts with reference.
Technical and usage data: IP address, country code, known login locations and security events for security. For limited server statistics, we measure product milestones such as account creation, onboarding, connected features, donations and payouts under a non-reversible pseudonym; PostHog does not receive an email address, raw account ID or browser IP for this layer. Only after consent do we measure visited paths, clicks, referrer/UTM source, browser and device data and masked session recordings on product pages in the browser.
Waitlist and contact: email address, reserved username, limited source/referral information, referral code and correspondence. We may also receive data from a creator, payment provider, bank, platform or competent authority where needed for support, security or a dispute.
3. Purposes and GDPR legal bases
- Contract: provide the account, profile, donation flow, dashboard, overlays, imports, integrations and support; without required data we cannot provide that feature.
- Legal obligation: comply with recordkeeping, tax, competent orders and applicable financial or sanctions obligations.
- Legitimate interests: secure the service, prevent misuse, fraud and chargebacks, preserve evidence, handle claims, investigate failures and use limited pseudonymised server statistics to improve product operation, activation and reliability. This layer does not create session recordings, use browser tracking or build a PostHog person profile. We balance this against your privacy interests, limit the data and respect a reasoned objection.
- Consent: for the optional weekly email reminder to finish connecting Stripe (unsubscribe in any reminder email), for detailed PostHog browser analytics, dead-click analysis and masked session recordings, and wherever else we expressly request it. Withdrawal immediately stops new browser analytics, applies prospectively and does not make earlier processing unlawful.
- We rely on vital or public interest only in exceptional situations permitted by the GDPR. We do not use personal data for credit scoring or sale to data brokers.
- Abuse check for the partner program (legitimate interest: fraud prevention): we compare whether a referrer and a referred creator use the same bank account (via a fingerprint calculated by Stripe, not the IBAN), the same person or company (name and date of birth from Stripe verification), the same email address, the same browser or the same network. We only keep the outcome and hashed IPs; if they match, the commission lapses. A staff member reviews doubtful cases.
DonoLink does not sell or rent personal data and does not use Google or YouTube data for advertising, profiling or sale.
4. Recipients and roles
Only necessary data may be shared with:
- Stripe and relevant banks/payment methods for onboarding, KYC, payments, fees, payouts, refunds, fraud and disputes; Stripe also processes under its own privacy terms.
- the selected creator: donation name, message, amount, time and status for receipt, alerts, statistics and handling questions; no full payment instrument or IBAN.
- PocketBase/hosting, network, security, storage and email providers operating DonoLink's infrastructure.
- PostHog for limited pseudonymised server statistics without a person profile and, only after consent, browser analytics and masked session recordings. Entered text, form values, payment fields and OBS/QR pages are not recorded.
- Google/YouTube, Twitch, Kick, TikTok and Streamlabs when you activate such an integration. To connect your YouTube account, DonoLink requests youtube.readonly to read channel information, live streams, live chat and live events. Only when you separately authorise stream title changes does DonoLink also request youtube.force-ssl. This lets DonoLink change your active stream's title when you issue a command to do so. The separately connected YouTube bot uses youtube.force-ssl to post chat messages according to your bot settings and, with the required channel permissions, delete messages or temporarily ban viewers from chat.
- advisers, insurers, public authorities, regulators, law enforcement or a successor business, but only on a valid basis, to the necessary extent and with confidentiality where appropriate.
- the referrer who invited you: your username, sign-up date, end of the commission period and the commission your donations generate. If your leaderboard is off, the referrer only sees you anonymously and without an amount. The referrer never sees donors, messages or your balance. Legal basis: performance of the partner program and our legitimate interest in a verifiable commission calculation.
Appropriate agreements are entered into with processors and they may process data only on instructions. A recipient that independently determines purposes and means, such as Stripe for regulated payment services, a bank, payment method, creator or streaming platform, is separately responsible for lawfulness, transparency, security, retention and rights in its own processing. A request to DonoLink does not automatically delete or correct data held by such an independent party.
5. Transfers outside the EEA
Some providers or connected platforms may process data in the United States or other countries outside the European Economic Area. Where required by the GDPR, we rely on an adequacy decision, the EU-US Data Privacy Framework for a certified recipient, European Commission approved Standard Contractual Clauses and, where needed, supplementary measures. You can request information about the applicable mechanism or a copy of relevant safeguards via [email protected].
6. Retention periods
- Account, profile, settings and active OAuth integrations: while the account or integration is active; after deletion, generally within 30 days from active systems.
- Financial administration, fee invoices and necessary transaction data: up to 7 years after the relevant financial year, or longer where required by law or an ongoing dispute.
- Terms and payment evidence, fraud, refund, chargeback and claim files: as long as needed for the purpose and no later than expiry of applicable statutory limitation or dispute periods.
- YouTube OAuth data: until disconnection; we then revoke the token and delete the integration. Derived YouTube event details: no more than 30 days. Deletion at DonoLink does not alter data held by YouTube itself.
- Other stream events and import history: while needed for creator-requested statistics and service delivery, or until account deletion; real-time overlay messages are normally deleted within 5 minutes.
- Support tickets and correspondence: while the request or account is active and afterwards only while needed for a contract, complaint, claim or legal duty. Waitlist data: until withdrawal, conversion to an account or the waitlist purpose ends.
- Security data: failed-login and incident data while needed for security or investigation; known login locations remain as a limited rolling list with the active account and are deleted with the account. PostHog data follows the configured retention period of the PostHog project and is deleted earlier when no longer needed.
- Referral and commission data: for as long as the partnership or commission period runs and then 7 years because of the statutory tax retention obligation; hashed IPs for at most 90 days; the referral cookie for at most 30 days and the referrer cookie for at most 1 year.
Backups may remain isolated for a short period and are overwritten according to the backup cycle. Deletion does not apply to data we must legally retain; such data is restricted and used only for that purpose.
7. Public data and the creator
A creator profile, avatar, banner, bio, social links and uploaded overlay media are intended for public display. For a donation, the name/nickname, message, amount and time may appear on the selected creator's donation page, leaderboard and stream alert. Do not provide information you do not want made public. Once a creator selects, downloads, combines, publishes or uses received data outside DonoLink for their own purposes, that creator independently determines the processing. The creator must then have their own valid legal basis and privacy information, handle rights, apply appropriate security, retain data no longer than needed and not disclose sensitive or unnecessary data. DonoLink is not responsible for such independent, unauthorised or terms-breaching use by a creator, except to the extent the law imposes a separate duty on DonoLink. Direct a request concerning such use to the creator as well.
8. Cookies, local storage and analytics
DonoLink uses necessary storage for the login session, language, theme, security and OBS settings you choose. In addition, server processes send limited product milestones to PostHog under a secretly derived pseudonym on the basis of legitimate interests; this layer uses no browser tracking, browser IP, email address, raw account ID, session recording or PostHog person profile. Detailed browser analytics, dead-click analysis and masked session recordings start only after active consent; refusing does not affect access to the service. The browser layer uses in-memory storage, masks text and inputs, records no iframes, headers or bodies and does not run on OBS or QR routes. You can withdraw consent just as easily through Cookie settings in the footer; the open page then immediately stops new browser analytics and session recordings. You may object to the limited server statistics on grounds relating to your particular situation via [email protected].
If you follow a referral link (/r/...), we set a functional first-party cookie (donolink_ref, 30 days) containing only the code, so we can link the invitation when you sign up; we delete it after sign-up. Referrers get a functional cookie (donolink_ref_eigen, 1 year) that recognises their own browser, so they cannot invite themselves. Neither is used for tracking or advertising.
9. Security and data breaches
We use measures including TLS, restricted tokens and sensitive fields, access controls, two-factor authentication, rate limits, logging and payment status checks. No internet service can guarantee absolute security. Users remain responsible for secure devices, unique passwords, two-factor protection and keeping tokens and links confidential. If a personal data breach occurs for which DonoLink is responsible, we investigate and contain the impact and notify the Dutch Data Protection Authority and affected individuals where required. Report a suspected security issue without exploiting it via [email protected]. The liability provisions in the terms apply to the extent they do not conflict with mandatory GDPR rights.
10. Your GDPR rights
Depending on the circumstances, you have the right to:
- access and a copy of your personal data;
- rectification of inaccurate or completion of incomplete data;
- erasure or restriction of processing, unless an exception or retention duty applies;
- data portability for data you provided where processing is automated and based on consent or contract;
- object on grounds relating to your situation to legitimate-interest processing, and always object to direct marketing;
- withdraw consent for the future;
- lodge a complaint with the Dutch Data Protection Authority or the competent authority in your country of residence or work.
Send a request to [email protected]. We normally respond within one month. For complex requests, the GDPR allows us to extend this by two months and we will inform you within the first month. We may proportionately request identity verification and may refuse or charge for manifestly unfounded or excessive requests.
11. Automated decisions
DonoLink does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Technical fraud, security and payment checks may temporarily block a login or new payment. You may request human review via [email protected]. Stripe, banks and payment methods may perform their own automated checks under their terms and privacy notices.
12. Minors
A creator account is intended for persons aged 18 or over. A minor may use DonoLink only through a parent or legal guardian who manages and is responsible for the account. If you believe we process a child's data without valid guardian involvement, notify us via [email protected].
13. Changes
We may update this notice when the service, providers or law changes. The current version and date appear on this page. We appropriately notify account holders of material changes before or when they take effect. New processing requiring consent will not start without that consent.
14. Contact and complaint
Privacy questions or requests: [email protected]. You may also lodge a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.