Last updated: August 13, 2026 (Pacific)
CraftedLink is a tag you tap. It sits on a handmade object and, when you tap or scan it with a phone, it either sends you to a link the maker chose or opens a story page — photos, a written message, sometimes audio, sometimes an embedded video.
This policy explains what we collect, what we don't, and who gets to see what. It is written to be read by three different people: someone who just tapped a tag on a gift, a solo crafter putting tags in their own work, and a business paying to run pages for its own customers. If any of it is unclear, write to us and we'll answer plainly.
CraftedLink (craftedlink.app) is an independent, owner-run business, operated by a sole proprietor based in California, USA. CraftedLink shares an operator and a database with CraftedTracker (craftedtracker.app), but it is a separate product with its own policy — this one.
Questions, requests, complaints, takedowns: support@craftedlink.app. The owner reads it — not a ticket queue.
This is the most important section in the document, because CraftedLink is sold two different ways and our legal responsibilities change depending on which one you're touching. (The subscriber tier is not open for signup yet; Role 2 describes how it works when it opens.)
Role 1 — Our own products. We are the controller.
When we sell a handmade item with a CraftedLink tag in it and we build the story page, we decide what gets collected and how it's handled. If you sent us photos for a page on something we made, this policy is the whole answer, and you deal with us directly.
Role 2 — A subscribing business's products. We are the processor.
Businesses can subscribe to CraftedLink and run their own product pages for their own buyers. In that arrangement:
One narrow exception to "we don't access it" — you asking us for your own content back. We would rather write this down than have a promise with a quiet hole in it.
The first answer will be a button, not a clause. We are building export into the platform itself, so you will be able to retrieve the content you provided directly from CraftedLink, free, without going through the business at all — and subscriber story pages do not go live to end customers before that exists. See "Export and deletion."
The business can also fetch it for you and hand it over. A business subscribing to CraftedLink can retrieve the content its own customer provided and give that customer a copy — on that customer's request. Often that is the quickest way to get your photos back, because the business already knows who you are and already holds the relationship. It is also the arrangement working exactly as it is meant to: the business is the controller, you asked them, and they acted. We are not in the middle of it, and we do not read anything to make it happen — so the walled-off promise above is untouched by it.
That route is an addition. Nothing was taken away to make room for it. If the business won't help, the narrow, logged action described below is still there as the backstop. A new route in a privacy policy usually means something quietly got worse. Here it does not — this one removes work, not rights.
Behind that, every business that subscribes to CraftedLink is required by our Terms of Service to give its own customers the right to a free copy of the content they provided. That is a binding obligation on them, not a suggestion. But a promise in someone else's terms is only worth what they'll do when asked, so there is a third path if they won't:
If you gave content to a business using CraftedLink and you want a copy of it, ask that business first. If they don't answer you, write to us at support@craftedlink.app. We will contact them and give them a chance to deal with it. If they still don't, we may retrieve and give you a copy of your own content ourselves.
That is not the same thing as us browsing a subscriber's content, and the limits are the point:
The walled-off promise stands as written for everything else. A narrow, logged, on-request action to hand someone their own photos back is a different thing from general access to a subscriber's content, and we've drawn the line there on purpose. The Terms of Service describe this same exception in the same terms, from the subscriber's side.
If the business's subscription ends, your content and your rights do not. This is worth saying on its own, because it is the place where a three-layer arrangement usually fails a person at the bottom of it. A business subscribing to CraftedLink pays a per-page fee that buys that page's ten years of hosting outright, and that term survives their subscription ending — cancelled, unpaid, or ended by us. So the page you were given stays online for the rest of its ten years, the content on it is kept for that whole term, and your right to a copy of what you provided is unaffected. You do not lose a page you paid for because of a billing relationship you were never part of. The commercial side of this is in the Terms of Service, under "Terms for subscribers"; the part that belongs here is the retention consequence, and it is in "How long we keep things."
That split is standard for hosted software, but our version has three layers — platform, subscribing business, and that business's buyer — and the third layer is the one most policies never contemplate. We've written it the way it actually works rather than the way it's usually copied.
We ask for a piece of data only when it earns its place. Here is the whole list.
If you own tags (a maker, a shop, a subscribing business):
| What | Why |
|---|---|
| Email address | It's the only signup field. It identifies your account and lets us send you sign-in and reset emails. |
| Shop or business name | So your pages and tags can carry your name. |
| The link or page content you attach to a tag | It's the product. |
| Files you upload — photos, audio, documents | So they can appear on your pages. |
| Subscription status (when subscriptions launch) | To know what you're entitled to. |
If you tapped someone else's tag: see the next section. In almost every case, the answer is "nothing that identifies you."
If you sent content for a story page: see "Story pages and the content buyers send," below.
We do not ask for your name, phone number, address, birthday, or anything else we don't need to run the thing.
When a CraftedLink tag is tapped or its QR code is scanned, a scan event is written to a log. Here's exactly what's in it:
And here is what is not in it:
State-level is as fine as it gets, and as fine as it will ever get here. (When we added the state in August 2026, this page was updated before the recording turned on, not after — and anything finer would get the same treatment, except that we have no plans for anything finer.)
The scan log is append-only at the database level: the permissions to UPDATE or DELETE rows have been revoked. Nobody — including us — can quietly rewrite or erase scan history. That's a design choice for integrity, and the trade-off is honest to state: because the log holds no personal identifiers, an individual scan cannot be traced to a person and there is nothing personal in it to delete.
We keep individual tap entries for 12 months at most, then they are purged under a narrow, documented exception to the no-delete rule that is scoped to the purge job and nothing else. Twelve months covers a full year of seasons, which is what makes the numbers worth anything, and we would rather hold less than more. (CraftedLink's first taps were logged in 2026, so no entry is anywhere near that age yet.)
We keep the counts for longer than that — but only the counts. Before entries are purged, they are rolled up into a simple tally that is kept: one row per tag, per month, per country and — in the United States — per state, with a number in it. No timestamps, no per-visitor rows of any kind. It tells a maker their tag was scanned 62 times in March and roughly where from, and it cannot tell anyone anything about any one person. That is the entire reason it is safe to keep.
Standard web request data (your browser sending a request to a server, so the server can send a page back) is handled by our hosting provider in the ordinary course of serving a website. We don't build that into our own analytics, and we don't keep our own copy of it.
Yes, in aggregate — and you should know that before you tap.
In plain language: when you tap a CraftedLink tag, the maker or business behind that product can see that a tap happened, roughly when, and how many taps the tag has had. They cannot see who you are.
They do not get your IP address, because it doesn't exist in our system. They don't get your city, your device, your name, or a way to contact you. They get counts and times. The maker's screen shows grouped totals of where taps came from — the country, and a US state only once that grouping reaches five or more taps; below five, a state is shown only as its country. Grouped totals, never anything about one identifiable person.
That applies to subscribing businesses too. If the tag you tapped belongs to a business that subscribes to CraftedLink, that business sees the same aggregate view we do on our own tags. Nothing more. No IP address, ever — not to us, not to them, because we never write it down in the first place. A subscribing business does not get a sharper picture of you than we do.
If we ever add anything to what a tag owner or a subscribing business can see, this section changes first and the change is dated at the top of this policy.
A story page holds a photo or several, a written message, and optionally audio. A page can also have a gallery of multiple photos, a small timeline, and one of four visual themes. Those are layout features — the same media types, no new categories of data.
How content reaches us: one private upload link. A buyer gets a link that is private, single-use, and expiring — craftedlink.app/send/<token> — and sends photos, a written message, and audio over an encrypted connection (HTTPS) straight from their browser into our storage. No email attachments. No account, no password to create.
Why that matters for your privacy: fewer hands on your photos. Your content goes from your browser into our storage and stops there. It does not sit in an email inbox and it does not pass through a marketplace's message system, so no outside message provider ends up holding a copy of your family photos under its own policies. There is no third party in the path to hold them. Most of this market takes files by email or by direct message, which quietly puts a copy of your photos somewhere neither you nor the maker controls. We don't, and that is a deliberate design choice, not a convenience.
The upload link is the only supported route. People will still sometimes email or message content anyway. When that happens we send it back and ask them to resubmit it through the link. That is how the paragraph above stays true.
Nothing publishes itself. Uploaded content lands in a staging area visible only to the tag's owner. It is never published until the owner reviews it and places it on a page. If a buyer sends something and then changes their mind before the page goes live, tell the owner, or tell us, and it comes out of staging.
Whose content it is. The person who sent it keeps ownership of their photos, words, and recordings. We store and display them so the page works. That's all.
What we ask of tag owners. If you put someone else's photo, words, voice, or likeness on a page, you're representing that you have the right to do it. That applies to family photos, to photographer-taken images, to recordings of other people's voices, and — with extra care — to minors and to people who have died. See those two sections below.
We never host video. If a page has video on it, that video is an unlisted video sitting on the customer's own YouTube account, embedded in the page.
Say it plainly: a YouTube embed means YouTube sees the viewer. When a page with an embedded video loads, your browser talks to YouTube directly, and YouTube's terms and its own data collection apply to that connection — the same as if you'd opened YouTube yourself. We don't control it and we don't receive what YouTube collects.
Two consequences worth knowing:
Anyone holding the physical object can tap the tag, so treat a story page as visible to anyone who has the item in their hands — including a future owner, a guest, a repair shop, or whoever ends up with it years from now. Don't put anything on a page you wouldn't want a stranger holding that object to read.
We ask the person sending content to tick a box saying they understand that. The upload page's checkbox confirms two things at once: that the content is theirs to share — including permission from anyone who appears in it — and that the page it lands on can be seen by anyone who taps the tag. It is its own tick, not a line buried in a policy nobody reads, and the send button stays off until it's ticked.
Being reachable by tap and being findable on Google are two different things, and we treat them as two different decisions.
noindex instruction, which asks search engines not to list them. A page is reachable by someone holding the tagged object, but it will not turn up in a search for someone's name. If we ever add an option for a page's owner to turn indexing on, it will be off by default and this page will say so.Where a page includes a minor or a person who has died, we recommend using first names only.
We use a small number of service providers. They process data so that we can run the product, and each is bound by its own agreement with us.
| Provider | What it does | What it touches |
|---|---|---|
| Supabase | Database and file storage | Accounts, page content, uploaded photos/audio/files, scan logs |
| Netlify | Hosting and serverless functions | Serving pages and running the code behind them |
| Resend | Email delivery | Sign-in and account emails |
There is no in-app payment today, and Stripe is deliberately not in the table above, because it is not handling anything for us yet. Stripe is planned for public launch as web checkout only; when that ships, card details go to Stripe and we never see or store a card number. Stripe gets added to the table on the day web checkout goes live — before the first payment, not after.
These providers run infrastructure in the United States and elsewhere. If you are outside the US, your content will be stored on servers in the US.
There are no third-party trackers, no analytics scripts, and no advertising cookies anywhere in CraftedLink. Not on the public pages, not in the app.
What is stored on your device:
If you only tapped a tag and looked at a page, we're not setting anything on you for tracking purposes. If the page has a YouTube embed, YouTube may set its own — see the embedded video section.
The one exception to that last promise: a public review you chose to post.
If you post a public review of something you bought, and that review shows your own story page, we may reshare that review — on social media or on our shop page.
We think the difference matters, so here it is plainly. We are not using your story page. We are passing along a review you decided to make public, in the form you published it, which happens to have your page in it. We are not reaching into your page to do it.
Three limits, and we mean all three:
Outside that one exception, the promise above stands exactly as written: we ask first, in writing, and saying no costs you nothing.
| What | How long |
|---|---|
| Story page content | At least 10 years from the day the tag is activated — not from the day the item was bought or the tag was made. An unactivated tag sitting in a drawer does not burn its term. We will contact you well before the ten-year mark. Never described as "lifetime" or "permanent," because neither would be true. This does not depend on anyone's subscription. Where a business subscribes to CraftedLink and pays for a page, that page's ten years are bought outright, and the content is kept for the full term even if the business's subscription ends. See the Terms of Service, "How long a story page stays online." |
| Tap logs (individual entries) | 12 months at most, then purged. See "What happens when you tap a tag." |
| Tap counts (aggregate) | Kept indefinitely, and deliberately blunt — one row per tag, per month, per country and (in the US) state, a count and nothing else, nothing per-visitor. On the maker's screen a state with fewer than five taps in a grouping shows only as its country. |
| Account data | While the account exists, then removed on request — see below. When a business's subscription ends, account content that is not part of a paid page is deleted 90 days after the end date (the export window is the first 30 of those days — see the Terms of Service). A subscribing business's account ending does not delete the content of pages already paid for: that content is kept for the rest of each page's ten years, because the page is still online and still needs it. |
| Staged content not yet published | 12 months. If you upload something and it never gets placed on a page, we remove it 12 months after upload — and we email a warning before we do, so nothing disappears on you without notice. |
| Backups | Deleted content is removed from the live site right away and gone from any backup copies within 30 days (today our database plan keeps no automatic backups, so in practice deletion is immediate — 30 days is the ceiling we hold ourselves to). |
Every row above is a real number, not a placeholder. We would rather tell you a length we can keep than a comfortable word we can't.
Export is free, and it stays free. You can get a copy of your own content — your photos, your messages, your audio, your page data — at no cost, at any time, whether or not you are a paying subscriber. There is no version of CraftedLink where you have to pay to get your own material back out. That one is settled.
If you gave your content to a business that uses CraftedLink, you still have that right — and it does not depend on that business. Three routes:
And none of it lapses if that business stops subscribing. Their subscription ending does not take down a page they already paid for, and it does not end your right to a copy of the content you provided. Both carry on for the rest of the page's ten years.
Deletion. There is no self-serve delete-account button yet. Until there is, write to support@craftedlink.app and we'll do it. Content comes off the live pages promptly and is gone from any backup copies within 30 days (today our database plan keeps no automatic backups, so in practice deletion is immediate — 30 days is the ceiling we hold ourselves to).
If a page is about you and you didn't put it there — for example, a buyer or a maker published your photo or your words — write to us. If we control the page, we'll act on it. If a subscribing business controls the page, we'll route you to them and, where the content is unlawful or clearly submitted without permission, we'll act ourselves.
A note on published content. Once a page is live, someone who has viewed it may have saved or screenshotted what was on it. We can take a page down. We can't recall a copy someone already made.
The account holder must be 18 or older. We do not knowingly collect information directly from children, and CraftedLink is not marketed to them.
But that's the easy half, and it's the half every policy in this market answers while ignoring the hard one. The real situation is this: story pages on a handmade object will contain photos of and messages from children. A memory gift for a grandparent. A christening keepsake. A page a child recorded a voice message for. That is a normal, intended use of this product, and pretending otherwise would be dishonest.
So, plainly:
Memorial and legacy pages are a real and likely use of this product — a page on an object left behind, a recorded voice, a written message from someone who is gone. This is the part of the market nobody has written a policy for, so here is ours.
Who may create a page about someone who has died — see the Terms of Service. The rule about who has the authority to make a memorial page, and the statement you give us when you do, live in the CraftedLink Terms of Service, not here. This policy covers the other half: what we do with the content once it exists, and how you get it corrected or taken down. The two documents are meant to be read together, and we have deliberately written each rule in only one of them so they cannot drift apart.
For the sections below, "next of kin" means what the Terms say it means: spouse or domestic partner, child, parent, sibling, grandchild, grandparent.
Who may ask for changes or removal. Any of the people in that list, or the executor or administrator of the estate, may write to support@craftedlink.app and ask us to correct, restrict, or remove content about a person who has died. Tell us the page, your relationship, and what you're asking for. We may ask for something showing the relationship — we are not running a court, and we will keep the ask proportionate.
When a family disagrees. Families do disagree about this, and we would rather say now what we'll do than improvise it later. The Terms of Service give us the right to temporarily make a page unavailable while the family sorts it out if we receive a credible objection from a relative in that list. We are not equipped to adjudicate a family dispute, and a page going quiet for a while is a smaller harm than the alternatives.
What that means for the data, which is this document's half of it: a frozen page stops being served to anyone who taps the tag. Nothing is deleted when a page is frozen. The content stays where it was, the owner keeps their access to it and can still export it, and if the objection is resolved the page goes back up unchanged. A freeze is a pause, not an erasure. If the outcome is removal, that runs through the deletion path above — off the live pages promptly, purged from backups within 30 days. Where a subscribing business controls the page, we tell them and they decide, except where the content is unlawful.
A legal note in plain terms. Privacy law generally protects living people — in most places, a person who has died is not a "data subject" and the usual privacy rights don't attach. What does apply varies: several states have right-of-publicity laws that survive death and differ enormously from state to state, and estate law decides who speaks for the deceased. This section is our practice, not a statement of your legal rights, and it may change once a lawyer has reviewed it.
If we learn that personal information has been exposed or accessed without authorization, we will investigate, contain it, and notify affected people without undue delay, and within 72 hours of confirming a breach where we have a way to reach you.
That last part is not a dodge, and it is worth saying why it's there: for most people who tap a tag, we hold no email address and no account — there is genuinely no way for us to reach you, because not collecting that is the whole point. Where we do have a way to reach you, 72 hours is the commitment.
The notice will say, in plain language, what happened, what data was involved, what we've done about it, and what you should do. We will also notify authorities where the law requires it. California requires breach notification regardless of what this policy says; the commitment above is on top of that, not instead of it.
Where we are acting as a processor for a subscribing business, we notify that business without undue delay and support them in notifying their own customers — under that arrangement, the notice to the individual comes from them.
Wherever you are, you can write to support@craftedlink.app and ask us to:
We'll do those things for anyone who asks, without checking first whether a statute obliges us to. That's the simpler policy and it's the one we'd want.
What we are not going to claim. CraftedLink is run by one person and is pre-revenue. We almost certainly do not meet the thresholds that make the California Consumer Privacy Act apply to us. We have no establishment in the European Union and we do not target the EU market. So rather than printing a compliance badge we haven't earned, this policy describes what actually happens to your data. Whether and when specific privacy statutes apply to this business is an open legal question that is being reviewed.
If you asked us for something and think we got it wrong, say so in a reply — a person will look at it again.
If we change how any of this works, we update this page and change the date at the top. For a change that meaningfully reduces your privacy — collecting something new, sharing something we didn't share before — we will say so clearly rather than quietly editing a line, and we'll notify account holders by email before it takes effect.
Old versions are kept so you can see what changed.
support@craftedlink.app
Write to us for anything in this document: access, correction, deletion, takedown of a child's content, a request about someone who has died, or a question you just want answered. Say which page or tag you're asking about if you can — it makes it faster.
CraftedLink is operated as a sole proprietorship in California, USA. As a business that operates entirely online, email is our designated contact method for every request in this document — including privacy requests under California law.
© 2026 CraftedCarvings. All rights reserved.