Privacy notice.

This notice applies to DonoLink's website, accounts, public donation pages, payments, dashboards, overlays, support, waitlist and stream integrations. It explains which personal data we process, why, for how long, and what choices and rights you have.

1. Who is responsible?

Tovix, trading as DonoLink, sole proprietorship, Dutch Chamber of Commerce 98227475 and VAT NL005316890B06, is the controller for the DonoLink processing described in this notice. Contact: info@donolink.nl. DonoLink is not responsible for processing for which a creator, Stripe, a bank, payment method or connected streaming platform independently determines the purposes and means; that party is the controller under its own privacy terms. DonoLink remains responsible for its own selection, engagement and disclosure to the extent required by the GDPR.

2. What data and sources?

Account and profile data: name, email address, username, password hash, verification status, profile image/banner, bio, language, social channels, settings, two-factor status and encrypted or restricted authentication secret. We receive these from you, PocketBase or a selected social login provider.

Donation and payment data: name or nickname, message, amount, currency, payment method, status, time, transaction IDs, terms version and acceptance time. An optional email address and full payment, identity and bank details are processed directly by Stripe; DonoLink does not store a full card number, IBAN or identity document.

Content and communications: public profile content, alert media, media requests, import data, support tickets, emails and information in reports, complaints, refunds or disputes.

Streaming integrations: account and channel IDs, display name, OAuth tokens and scopes, connection status and visible live events from Twitch, Kick, YouTube, TikTok or Streamlabs, such as name, chat message, follow, subscription, gift, bits, raid, Super Chat or membership. Import keys are used only to perform the selected import and are not stored as profile data.

Referral data: the referral code you signed up with, the time, the referrer and an encrypted hash of your IP address at sign-up (never the IP itself); for referrers also their own code, the percentage, hashed IPs of recent visits, commission entries per donation (platform fee, percentage, amount, status and Stripe payment reference), the outcome of the abuse check and payouts with reference.

Technical and usage data: IP address, country code, known login locations and security events for security. For limited server statistics, we measure product milestones such as account creation, onboarding, connected features, donations and payouts under a non-reversible pseudonym; PostHog does not receive an email address, raw account ID or browser IP for this layer. Only after consent do we measure visited paths, clicks, referrer/UTM source, browser and device data and masked session recordings on product pages in the browser.

Waitlist and contact: email address, reserved username, limited source/referral information, referral code and correspondence. We may also receive data from a creator, payment provider, bank, platform or competent authority where needed for support, security or a dispute.

3. Purposes and GDPR legal bases

DonoLink does not sell or rent personal data and does not use Google or YouTube data for advertising, profiling or sale.

4. Recipients and roles

Only necessary data may be shared with:

Appropriate agreements are entered into with processors and they may process data only on instructions. A recipient that independently determines purposes and means, such as Stripe for regulated payment services, a bank, payment method, creator or streaming platform, is separately responsible for lawfulness, transparency, security, retention and rights in its own processing. A request to DonoLink does not automatically delete or correct data held by such an independent party.

5. Transfers outside the EEA

Some providers or connected platforms may process data in the United States or other countries outside the European Economic Area. Where required by the GDPR, we rely on an adequacy decision, the EU-US Data Privacy Framework for a certified recipient, European Commission approved Standard Contractual Clauses and, where needed, supplementary measures. You can request information about the applicable mechanism or a copy of relevant safeguards via info@donolink.nl.

6. Retention periods

Backups may remain isolated for a short period and are overwritten according to the backup cycle. Deletion does not apply to data we must legally retain; such data is restricted and used only for that purpose.

7. Public data and the creator

A creator profile, avatar, banner, bio, social links and uploaded overlay media are intended for public display. For a donation, the name/nickname, message, amount and time may appear on the selected creator's donation page, leaderboard and stream alert. Do not provide information you do not want made public. Once a creator selects, downloads, combines, publishes or uses received data outside DonoLink for their own purposes, that creator independently determines the processing. The creator must then have their own valid legal basis and privacy information, handle rights, apply appropriate security, retain data no longer than needed and not disclose sensitive or unnecessary data. DonoLink is not responsible for such independent, unauthorised or terms-breaching use by a creator, except to the extent the law imposes a separate duty on DonoLink. Direct a request concerning such use to the creator as well.

8. Cookies, local storage and analytics

DonoLink uses necessary storage for the login session, language, theme, security and OBS settings you choose. In addition, server processes send limited product milestones to PostHog under a secretly derived pseudonym on the basis of legitimate interests; this layer uses no browser tracking, browser IP, email address, raw account ID, session recording or PostHog person profile. Detailed browser analytics, dead-click analysis and masked session recordings start only after active consent; refusing does not affect access to the service. The browser layer uses in-memory storage, masks text and inputs, records no iframes, headers or bodies and does not run on OBS or QR routes. You can withdraw consent just as easily through Cookie settings in the footer; the open page then immediately stops new browser analytics and session recordings. You may object to the limited server statistics on grounds relating to your particular situation via info@donolink.nl.

If you follow a referral link (/r/...), we set a functional first-party cookie (donolink_ref, 30 days) containing only the code, so we can link the invitation when you sign up; we delete it after sign-up. Referrers get a functional cookie (donolink_ref_eigen, 1 year) that recognises their own browser, so they cannot invite themselves. Neither is used for tracking or advertising.

9. Security and data breaches

We use measures including TLS, restricted tokens and sensitive fields, access controls, two-factor authentication, rate limits, logging and payment status checks. No internet service can guarantee absolute security. Users remain responsible for secure devices, unique passwords, two-factor protection and keeping tokens and links confidential. If a personal data breach occurs for which DonoLink is responsible, we investigate and contain the impact and notify the Dutch Data Protection Authority and affected individuals where required. Report a suspected security issue without exploiting it via support@donolink.nl. The liability provisions in the terms apply to the extent they do not conflict with mandatory GDPR rights.

10. Your GDPR rights

Depending on the circumstances, you have the right to:

Send a request to info@donolink.nl. We normally respond within one month. For complex requests, the GDPR allows us to extend this by two months and we will inform you within the first month. We may proportionately request identity verification and may refuse or charge for manifestly unfounded or excessive requests.

11. Automated decisions

DonoLink does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Technical fraud, security and payment checks may temporarily block a login or new payment. You may request human review via support@donolink.nl. Stripe, banks and payment methods may perform their own automated checks under their terms and privacy notices.

12. Minors

A creator account is intended for persons aged 18 or over. A minor may use DonoLink only through a parent or legal guardian who manages and is responsible for the account. If you believe we process a child's data without valid guardian involvement, notify us via info@donolink.nl.

13. Changes

We may update this notice when the service, providers or law changes. The current version and date appear on this page. We appropriately notify account holders of material changes before or when they take effect. New processing requiring consent will not start without that consent.

14. Contact and complaint

Privacy questions or requests: info@donolink.nl. You may also lodge a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.