Last updated: September 25, 2026 (Pacific)
CraftedLink is a tag you tap. It sits on a crafted object and, when you tap or scan it with a phone, it either sends you to a link the maker chose or opens a story page — photos, a written message, sometimes audio, sometimes an embedded video.
This policy explains what we collect, what we don't, and who gets to see what. It is written to be read by three different people: someone who just tapped a tag on a gift, a solo crafter putting tags in their own work, and a business paying to run pages for its own customers. If any of it is unclear, write to us and we'll answer plainly.
CraftedLink (craftedlink.app) is an independent, owner-run business, operated by a sole proprietor based in California, USA. CraftedLink shares an operator and a database with CraftedTracker (craftedtracker.app), but it is a separate product with its own policy — this one.
Questions, requests, complaints, takedowns: support@craftedlink.app. The owner reads it — not a ticket queue.
This is the most important section in the document, because CraftedLink is sold two different ways and our legal responsibilities change depending on which one you're touching. (The maker programme is open by arrangement; Role 2 describes how it works. Where this page says "subscriber" or "subscribing business," read "a maker on a CraftedLink plan" — the programme's shape changed in August 2026, the roles did not.)
Role 1 — Our own products. We are the controller.
When we sell a crafted item with a CraftedLink tag in it and we build the story page, we decide what gets collected and how it's handled. If you sent us photos for a page on something we made, this policy is the whole answer, and you deal with us directly.
Role 2 — A subscribing business's products. We are the processor.
Businesses can subscribe to CraftedLink and run their own product pages for their own buyers. In that arrangement:
One narrow exception to "we don't access it" — you asking us for your own content back. We would rather write this down than have a promise with a quiet hole in it.
The first answer is a button, not a clause. Every page carries Save an offline copy of this page, taken from the page's own setup link or account — the keeper's door, not a visitor's. It builds one file with the photos, the words, the recordings and the guest book embedded, free, in a format any browser opens — straight from CraftedLink, without going through the business at all. See "Export and deletion."
The business can also fetch it for you and hand it over. A business subscribing to CraftedLink can retrieve the content its own customer provided and give that customer a copy — on that customer's request. Often that is the quickest way to get your photos back, because the business already knows who you are and already holds the relationship. It is also the arrangement working exactly as it is meant to: the business is the controller, you asked them, and they acted. We are not in the middle of it, and we do not read anything to make it happen — so the walled-off promise above is untouched by it.
That route is an addition. Nothing was taken away to make room for it. If the business won't help, the narrow, logged action described below is still there as the backstop. A new route in a privacy policy usually means something quietly got worse. Here it does not — this one removes work, not rights.
Behind that, every business that subscribes to CraftedLink is required by our Terms of Service to give its own customers the right to a free copy of the content they provided. That is a binding obligation on them, not a suggestion. But a promise in someone else's terms is only worth what they'll do when asked, so there is a third path if they won't:
If you gave content to a business using CraftedLink and you want a copy of it, ask that business first. If they don't answer you, write to us at support@craftedlink.app. We will contact them and give them a chance to deal with it. If they still don't, we may retrieve and give you a copy of your own content ourselves.
That is not the same thing as us browsing a subscriber's content, and the limits are the point:
The second exception — a business we cannot reach. Added September 3, 2026, and said plainly here rather than by widening a promise quietly. If the business that made your piece stops answering — you have waited past three days, or three of its customers have in a month — the maker terms let CraftedLink step in and look after that business's customers' pages until the business is back. To do that we may need to look at, and change, a page you hold: to deliver an upgrade you already paid for, to set up a tag already in your hands, to fix what you asked to have fixed. The limits are the point:
The walled-off promise stands as written for everything else. A narrow, logged, on-request action to hand someone their own photos back — or to stand in, briefly and visibly, for a business that has gone quiet — is a different thing from general access to a subscriber's content, and we've drawn the line there on purpose. The Terms of Service and the maker terms describe these same exceptions in the same terms.
If the business's subscription ends, your content and your rights do not. This is worth saying on its own, because it is the place where a three-layer arrangement usually fails a person at the bottom of it. A business subscribing to CraftedLink pays a per-page fee that buys that page's ten years of hosting outright, and that term survives their subscription ending — cancelled, unpaid, or ended by us. So the page you were given stays online for the rest of its ten years, the content on it is kept for that whole term, and your right to a copy of what you provided is unaffected. You do not lose a page you paid for because of a billing relationship you were never part of. The commercial side of this is in the Terms of Service, under "Terms for subscribers"; the part that belongs here is the retention consequence, and it is in "How long we keep things."
That split is standard for hosted software, but our version has three layers — platform, subscribing business, and that business's buyer — and the third layer is the one most policies never contemplate. We've written it the way it actually works rather than the way it's usually copied.
We ask for a piece of data only when it earns its place. Here is the whole list.
If you own tags (a maker, a shop, a subscribing business):
| What | Why |
|---|---|
| Email address | It's the only signup field. It identifies your account and lets us send you sign-in and reset emails. |
| Shop or business name | So your pages and tags can carry your name. |
| The link or page content you attach to a tag | It's the product. |
| Files you upload — photos, audio, documents | So they can appear on your pages. |
| Subscription status (when subscriptions launch) | To know what you're entitled to. |
If you tapped someone else's tag: see the next section. In almost every case, the answer is "nothing that identifies you."
If you sent content for a story page: see "Story pages and the content buyers send," below.
If you write to us through the contact form: your name, your email address, what the message is about, and the message itself — so we can answer you. Nothing else, and you are not added to any list.
We do not ask for your name, phone number, address, birthday, or anything else we don't need to run the thing.
When a CraftedLink tag is tapped or its QR code is scanned, a scan event is written to a log. Here's exactly what's in it:
And here is what is not in it:
State-level is as fine as it gets, and as fine as it will ever get here. (When we added the state in August 2026, this page was updated before the recording turned on, not after — and anything finer would get the same treatment, except that we have no plans for anything finer.)
The scan log is append-only at the database level: the permissions to UPDATE or DELETE rows have been revoked. Nobody — including us — can quietly rewrite or erase scan history. That's a design choice for integrity, and the trade-off is honest to state: because the log holds no personal identifiers, an individual scan cannot be traced to a person and there is nothing personal in it to delete.
We keep individual tap entries for 12 months at most, then they are purged under a narrow, documented exception to the no-delete rule that is scoped to the purge job and nothing else. Twelve months covers a full year of seasons, which is what makes the numbers worth anything, and we would rather hold less than more. (CraftedLink's first taps were logged in 2026, so no entry is anywhere near that age yet.)
We keep the counts for longer than that — but only the counts. Before entries are purged, they are rolled up into a simple tally that is kept: one row per tag, per month, per country and — in the United States — per state, with a number in it. No timestamps, no per-visitor rows of any kind. It tells a maker their tag was scanned 62 times in March and roughly where from, and it cannot tell anyone anything about any one person. That is the entire reason it is safe to keep.
Standard web request data (your browser sending a request to a server, so the server can send a page back) is handled by our hosting provider in the ordinary course of serving a website. We don't build that into our own analytics, and we don't keep our own copy of it.
Yes, in aggregate — and you should know that before you tap.
In plain language: when you tap a CraftedLink tag, the maker or business behind that product can see that a tap happened, roughly when, and how many taps the tag has had. They cannot see who you are.
They do not get your IP address, because it doesn't exist in our system. They don't get your city, your device, your name, or a way to contact you. They get counts and times. The maker's screen shows grouped totals of where taps came from — the country, and a US state only once that grouping reaches five or more taps; below five, a state is shown only as its country. Grouped totals, never anything about one identifiable person.
That applies to subscribing businesses too. If the tag you tapped belongs to a business that subscribes to CraftedLink, that business sees the same aggregate view we do on our own tags. Nothing more. No IP address, ever — not to us, not to them, because we never write it down in the first place. A subscribing business does not get a sharper picture of you than we do.
If we ever add anything to what a tag owner or a subscribing business can see, this section changes first and the change is dated at the top of this policy.
A story page holds a photo or several, a written message, and optionally audio. A page can also have a gallery of multiple photos, a small timeline, and one of four visual themes. Those are layout features — the same media types, no new categories of data.
How content reaches us: one private upload link. A buyer gets a link that is private, single-use, and expiring — craftedlink.app/send/<token> — and sends photos, a written message, and audio over an encrypted connection (HTTPS) straight from their browser into our storage. No email attachments. No account and no password to create — though since August 2026 you may choose to add one, and Your optional account below explains exactly what that changes.
Why that matters for your privacy: fewer hands on your photos. Your content goes from your browser into our storage and stops there. It does not sit in an email inbox and it does not pass through a marketplace's message system, so no outside message provider ends up holding a copy of your family photos under its own policies. There is no third party in the path to hold them. Most of this market takes files by email or by direct message, which quietly puts a copy of your photos somewhere neither you nor the maker controls. We don't, and that is a deliberate design choice, not a convenience.
The upload link is the only supported route. People will still sometimes email or message content anyway. When that happens we send it back and ask them to resubmit it through the link. That is how the paragraph above stays true.
Publishing is a person's deliberate act. Content goes live one of two ways: the buyer builds and publishes their own page through their private link, after ticking a permission statement — or the tag's owner places content on the page. Either way, a person holding that page's private link chose to publish it — nothing publishes itself. If you publish something and change your mind, reopen your link and change it, tell the owner, or tell us, and it comes down.
Whose content it is. The person who sent it keeps ownership of their photos, words, and recordings. We store and display them so the page works. That's all.
What we ask of tag owners. If you put someone else's photo, words, voice, or likeness on a page, you're representing that you have the right to do it. That applies to family photos, to photographer-taken images, to recordings of other people's voices, and — with extra care — to minors and to people who have died. See those two sections below.
You do not need one. Everything above still works with no account at all: you build your page from the private link, publish it, and approve guest book entries through that same link. (The link lasts 30 days and gets another 30 every time you open it; if it closes, the maker of your piece can send a fresh one.) That is a supported way to use CraftedLink, not a lesser one, and we have no plans to change it.
What we store if you do create one: your email address, and whether you'd like to be emailed when something is waiting on your page. That is the whole record. We do not ask for your name, and we do not ask why you bought the piece. The maker of your piece sees your account's email only masked (ge•••••n@…) — enough to tell two customers apart, never the full address.
If you skip the account but leave an email so we can reach you: that is optional too, and we store that one address and nothing else. We use it for exactly three things — telling you when someone signs your guest book or sends something for your page (you can switch that off), telling you about a problem with your page, and the written notice our guarantee promises if CraftedLink ever had to close. The maker of your piece is shown only a masked version (ge•••••n@…): if you lose your link or your PIN, they can ask us to email you a fresh one. Remove it yourself from the page's builder, or write to support@craftedlink.app.
Why it exists, honestly. Two reasons, and the second is the one that made us build it. First, an account means you no longer have to keep the original link — you sign in instead. Second, and more importantly: whoever holds that link can change your page. It was sent privately, but a link can be forwarded, screenshotted, or read over your shoulder, and until you add an email there is no way for us to tell you apart from anyone else holding it. Once you add one, the old link can no longer change anything — it becomes a door that asks you to sign in. If that matters to you, that is the reason to bother.
Email we will send you: the message confirming your address, sign-in links and password resets when you ask for them, and — unless you switch them off — a note when someone signs your guest book or sends something for your page, and reminders before anything still waiting is removed (at 30, 7 and 1 day left). That is the complete list.
Email we will never send you: anything marketing. You are not added to a mailing list, because there is no mailing list to add you to. This is unchanged from the promise we made before accounts existed, and creating an account does not quietly opt you into anything.
These notes deliberately tell you very little — how many things are waiting, and nothing else. Not a name, not a word of what anyone wrote, never a photo. A visitor wrote to you, not to us, and a message you haven't approved yet is by definition one nobody has looked at. So we don't put it in an inbox. You read it on your own page, which is where you were always going to read it.
The maker can be let in, temporarily, and you will know. If you ask the person who made your piece for help — or if you lose access to your email and they need to help you get back in — a support window can be opened on your page. It lasts seven days and then closes itself. You can close it sooner. If the maker opens one rather than you, we email you to say so. Every change made under a window is logged. There is no silent way for a maker to edit a page that belongs to you: a maker who never opens a window can read that the page exists and switch it off if something is wrong, but cannot change what it says. If the maker cannot be reached, CraftedLink may open a window of its own on your page — the same seven days, the same email to you, the same log — and only while you are waiting on us or the maker is under stewardship. See "The second exception" above.
A maker can only ever reach pages they made. This is enforced by the database itself, not by us remembering to check: every tag records who made it, permanently, and that record is what a support window is measured against. One maker cannot reach another maker's customers' pages under any circumstances.
Deleting it. Write to support@craftedlink.app and we will delete the account and the email address on it. Your page is not the account and does not go with it — say if you want the page removed too, and we will do that as well.
A page's owner can turn on a guest book — a section where anyone who taps the piece can leave their name and a short written message. It is off unless the owner turns it on. On a Together page the owner may also let guests add one of: a photo, a recording of up to one minute, or a link to a YouTube video. A photo is shrunk on your own phone before it is sent (to 640 pixels across), which also leaves behind the location your camera may have stored in it. We do not store video — a video is a link to YouTube.
What we store when you sign: the name you type, your message, the date, and the photo, recording or YouTube link if you added one. No email address and no account. While your entry is waiting for the owner, we also keep a one-way scrambled code made from your connection's address — it cannot be turned back into the address — so that no one person can have more than five things waiting at once; it is deleted the moment the owner decides. No IP address is kept with your entry. (To keep robots from flooding pages, our systems briefly count requests per connection; those counts clear within a day and are never attached to an entry.)
Photos, recordings and videos always wait for the page's owner, and a written message waits too unless the owner chose to let messages straight on. Anything with a photo, recording or video that the owner has not approved 90 days after it arrived is removed, file and all. A guest's photo shows only in the guest book, never in the page's photo gallery. Every approved entry has a Report link: a report takes a photo, recording or video off the page until the owner looks at it again, and records nothing about who reported.
Nothing appears until the page's owner approves it. A new entry goes to the owner first and shows on the page only if they place it. The owner can also remove any entry at any time. If you signed a guest book and want your words taken down, tell the owner — or email us at support@craftedlink.app and we'll handle it.
Sign with care. A guest book entry, once approved, is visible to anyone who taps that piece — treat it like writing in a paper guest book that stays with the object.
The owner of a Together page can invite people — family, friends — to add to it. Each invitation is a private link, good for 14 or 30 days, that the owner either has us email or copies and sends themselves.
What we store for an invitation: the name the owner typed, the email address if they gave one, and the owner's note. We send that address one email — the invitation — and nothing else, ever; it is not added to any list.
What we store when you send something through an invitation: the photos, recordings, timeline moments and YouTube links you send, with the name the owner invited you by. Photos are shrunk on your phone before they are sent (to 1600 pixels across), which leaves the camera's location data behind. Everything waits for the owner: what they add becomes part of their page and is kept like the rest of it; anything they say no to is removed, and anything they have not looked at 90 days after it arrived is removed, file and all. If you want something you sent taken down, tell the page's owner — or email support@craftedlink.app.
Some pages are gifts from a sponsor — a realtor's closing gift, a funeral home's memorial piece. The sponsor bought the piece, built its page and gave it to you; a small block of theirs stays on the page — their name, business, picture, logo, phone, website and a short line they wrote.
What the sponsor sees about a page they gave: how many times it was tapped, how many times their block was opened, and how many messages were sent to them — counts only, never who tapped. They see the name and email they sent the invitation to (they typed it), and the day it was accepted. If you accepted it with a different email, they see that address masked (ge•••••n@gmail.com), never in full. They never see your page's content through us once it is yours — no words, photos, guest book or list. If the sponsor added a review link to your page, it goes to their review site; what you write there is between you and that site.
Writing to a sponsor from a page: the message and the email you type go to the sponsor by email, with Reply set to you, so they can answer. We do not keep the words or your address; we keep only a count, which also limits how many messages one page can send.
The invitation: we email the address the sponsor gave us one invitation (and again only if the sponsor sends it again). When you accept, the page moves onto your own free account.
A page's owner can turn their page into a list — chores, feeding the cat, what to do before you leave. Anyone who taps the piece can tick things off. It is off unless the owner turns it on, and it needs no account and no password, on purpose: a list that is slower than remembering is a list nobody uses.
What we store when you tick something: that the item is done, and when. Nothing about who did it. No name, no account, no IP address — there is no field for any of it, so there is nothing to hand over, lose or be asked for. Whoever ticked the dishes off is not recorded anywhere, and cannot be worked out afterwards.
Notes, if the owner allows them. An owner can let people add a short note when they tick something — "ran it at 6". That note is stored with the item and shows on the page. The owner chooses whether notes appear straight away or wait for them to read first, and they can clear any note at any time. Notes are text only: no photos, no recordings.
Anyone with the link can tick or un-tick. That is what makes it quick, and it is worth knowing before you use one for anything that matters. If a list should not be open to whoever holds the link, put a PIN on the page — see below.
A page's owner can set a PIN. Until it is entered, the page shows nothing at all — not the photos, not the message, not the care notes. The content genuinely stays on our server; it is not sent to the browser and hidden there, so there is nothing on the page to uncover by looking at it.
What we store: a one-way scrambled version of the PIN, never the PIN itself. We cannot read it back, tell an owner what theirs is, or hand it to anyone. If it is forgotten, the owner sets a new one.
Remembering your phone. Once you enter the PIN correctly, your phone keeps a random pass — issued by us, meaningless anywhere else — for up to 30 days, so you are not asked every time you tap. It lives in your own browser and we cannot read it. Clearing your browser data removes it; so does the owner changing the PIN, which forgets every phone that had been let in. On iPhones, Safari clears this kind of storage after about a week without a visit, so you may be asked again sooner there.
What a PIN is, honestly. It keeps out passers-by — someone who picks up the object, a visitor to the house. It is not encryption and it is not protection against a determined attacker who is set on getting in. Please don't put anything on a page that you could not bear a stranger to read.
We never host video. If a page has video on it, that video is an unlisted video sitting on the customer's own YouTube account, embedded in the page.
Say it plainly: a YouTube embed means YouTube sees the viewer. When a page with an embedded video loads, your browser talks to YouTube directly, and YouTube's terms and its own data collection apply to that connection — the same as if you'd opened YouTube yourself. We don't control it and we don't receive what YouTube collects.
Two consequences worth knowing:
Anyone holding the physical object can tap the tag, so treat a story page as visible to anyone who has the item in their hands — including a future owner, a guest, a repair shop, or whoever ends up with it years from now. Don't put anything on a page you wouldn't want a stranger holding that object to read.
We ask the person sending content to tick a box saying they understand that. The upload page's checkbox confirms two things at once: that the content is theirs to share — including permission from anyone who appears in it — and that the page it lands on can be seen by anyone who taps the tag. It is its own tick, not a line buried in a policy nobody reads, and the send button stays off until it's ticked.
Being reachable by tap and being findable on Google are two different things, and we treat them as two different decisions.
noindex instruction, which asks search engines not to list them. A page is reachable by someone holding the tagged object, but it will not turn up in a search for someone's name. If we ever add an option for a page's owner to turn indexing on, it will be off by default and this page will say so.Where a page includes a minor or a person who has died, we recommend using first names only.
We use a small number of service providers. They process data so that we can run the product, and each is bound by its own agreement with us.
| Provider | What it does | What it touches |
|---|---|---|
| Supabase | Database and file storage | Accounts, page content, uploaded photos/audio/files, scan logs |
| Netlify | Hosting and serverless functions | Serving pages and running the code behind them |
| Resend | Email delivery | Sign-in, account, contact-form, guest-book and invitation emails |
| Stripe | Payments | Your email address and the fact that a page was upgraded. Never a card number — we never see one. |
Stripe handles payments when you buy an upgrade for a page — for example turning the care page that came with your piece into a full story page. This is the promise this page made before web checkout existed, kept: Stripe went into the table above on the day checkout shipped, before the first payment rather than after.
Card details go straight to Stripe and never touch craftedlink.app. Tapping the upgrade button sends you to Stripe's own hosted page. No card field is ever shown on our site, so we do not see, handle or store a card number at any point — there is nothing here for anyone to take.
What comes back to us from a payment: your email address, so we can send you the link to build your page, and the fact that a particular tag was upgraded. Not your card, not your billing address, not what else you have ever bought. Stripe keeps its own record of the transaction under its own privacy policy, as the payment processor.
Sales tax is calculated by Stripe at checkout, because the rules for digital goods differ by state.
For makers only — a phone number at plan checkout. When a business buys a maker plan or adds credit, Stripe's checkout asks for a contact phone number. That is deliberate: makers are business customers, and a callable number is how we solve a problem with your account quickly. It lives on your customer record at Stripe; we never ask a retail buyer for one.
For makers only — your shop's contact card. A maker can give their shop a support email, a website, a phone number and a mailing address in their dashboard. Here is exactly who sees what: the support email and website are customer-facing — they appear on the pages of pieces you made, so your customers' questions come to you rather than to us. The phone number is shown to your customers only if you tick the box that says so; unticked, it stays between you and CraftedLink. The mailing address is never shown to customers at all — it is kept on file so we can reach the business behind a shop, and it appears on no public page and in no payload a browser can fetch.
Some makers who use CraftedLink sell upgrades through their own shop instead. If the button on a page sends you somewhere that is not Stripe, you are dealing with that maker and their shop's own terms and privacy policy apply to the purchase. We are not in the middle of it and we never see that payment at all.
These providers run infrastructure in the United States and elsewhere. If you are outside the US, your content will be stored on servers in the US.
There are no third-party trackers, no analytics scripts, and no advertising cookies anywhere in CraftedLink. Not on the public pages, not in the app.
What is stored on your device:
If you only tapped a tag and looked at a page, we're not setting anything on you for tracking purposes. If the page has a YouTube embed, YouTube may set its own — see the embedded video section.
The one exception to that last promise: a public review you chose to post.
If you post a public review of something you bought, and that review shows your own story page, we may reshare that review — on social media or on our shop page.
We think the difference matters, so here it is plainly. We are not using your story page. We are passing along a review you decided to make public, in the form you published it, which happens to have your page in it. We are not reaching into your page to do it.
Three limits, and we mean all three:
Outside that one exception, the promise above stands exactly as written: we ask first, in writing, and saying no costs you nothing.
| What | How long |
|---|---|
| Story page content | At least 10 years from the day the tag is activated — not from the day the item was bought or the tag was made. An unactivated tag sitting in a drawer does not burn its term. We will contact you well before the ten-year mark. Never described as "lifetime" or "permanent," because neither would be true. This does not depend on anyone's subscription. Where a business subscribes to CraftedLink and pays for a page, that page's ten years are bought outright, and the content is kept for the full term even if the business's subscription ends. See the Terms of Service, "How long a story page stays online." |
| Tap logs (individual entries) | 12 months at most, then purged. See "What happens when you tap a tag." |
| Tap counts (aggregate) | Kept indefinitely, and deliberately blunt — one row per tag, per month, per country and (in the US) state, a count and nothing else, nothing per-visitor. On the maker's screen a state with fewer than five taps in a grouping shows only as its country. |
| Account data | While the account exists, then removed on request — see below. When a business's subscription ends, account content that is not part of a paid page is deleted 90 days after the end date (the export window is the first 30 of those days — see the Terms of Service). A subscribing business's account ending does not delete the content of pages already paid for: that content is kept for the rest of each page's ten years, because the page is still online and still needs it. |
| Staged content not yet published | 12 months. If you upload something and it never gets placed on a page, we remove it 12 months after upload — and we email a warning before we do, so nothing disappears on you without notice. |
| Guest-book photos, recordings and videos the owner has not approved | 90 days after they arrive, then removed with their files (the owner is reminded at 30, 7 and 1 day left). A reported one waits for the owner instead. |
| What invited people send that the owner has not added | 90 days after it arrives, then removed with its files. Anything the owner adds becomes part of their page. |
| Messages sent through the contact form | 24 months after you write to us, then deleted — long enough to find an old conversation, not kept forever. |
| Backups | Deleted content is removed from the live site right away and gone from any backup copies within 30 days (today our database plan keeps no automatic backups, so in practice deletion is immediate — 30 days is the ceiling we hold ourselves to). |
Every row above is a real number, not a placeholder. We would rather tell you a length we can keep than a comfortable word we can't.
Export is free, and it stays free. You can get a copy of your own content — your photos, your messages, your audio, your page data — at no cost, at any time, whether or not you are a paying subscriber. There is no version of CraftedLink where you have to pay to get your own material back out. That one is settled.
If you gave your content to a business that uses CraftedLink, you still have that right — and it does not depend on that business. Three routes:
And none of it lapses if that business stops subscribing. Their subscription ending does not take down a page they already paid for, and it does not end your right to a copy of the content you provided. Both carry on for the rest of the page's ten years.
Deletion. There is no self-serve delete-account button yet. Until there is, write to support@craftedlink.app and we'll do it. Content comes off the live pages promptly and is gone from any backup copies within 30 days (today our database plan keeps no automatic backups, so in practice deletion is immediate — 30 days is the ceiling we hold ourselves to).
If a page is about you and you didn't put it there — for example, a buyer or a maker published your photo or your words — write to us. If we control the page, we'll act on it. If a subscribing business controls the page, we'll route you to them and, where the content is unlawful or clearly submitted without permission, we'll act ourselves. If we cannot reach the business at all, we act ourselves on the same basis we would for our own pages.
A note on published content. Once a page is live, someone who has viewed it may have saved or screenshotted what was on it. We can take a page down. We can't recall a copy someone already made.
The account holder must be 18 or older. We do not knowingly collect information directly from children, and CraftedLink is not marketed to them.
But that's the easy half, and it's the half every policy in this market answers while ignoring the hard one. The real situation is this: story pages on a crafted object will contain photos of and messages from children. A memory gift for a grandparent. A christening keepsake. A page a child recorded a voice message for. That is a normal, intended use of this product, and pretending otherwise would be dishonest.
So, plainly:
Memorial and legacy pages are a real and likely use of this product — a page on an object left behind, a recorded voice, a written message from someone who is gone. This is the part of the market nobody has written a policy for, so here is ours.
Who may create a page about someone who has died — see the Terms of Service. The rule about who has the authority to make a memorial page, and the statement you give us when you do, live in the CraftedLink Terms of Service, not here. This policy covers the other half: what we do with the content once it exists, and how you get it corrected or taken down. The two documents are meant to be read together, and we have deliberately written each rule in only one of them so they cannot drift apart.
For the sections below, "next of kin" means what the Terms say it means: spouse or domestic partner, child, parent, sibling, grandchild, grandparent.
Who may ask for changes or removal. Any of the people in that list, or the executor or administrator of the estate, may write to support@craftedlink.app and ask us to correct, restrict, or remove content about a person who has died. Tell us the page, your relationship, and what you're asking for. We may ask for something showing the relationship — we are not running a court, and we will keep the ask proportionate.
When a family disagrees. Families do disagree about this, and we would rather say now what we'll do than improvise it later. The Terms of Service give us the right to temporarily make a page unavailable while the family sorts it out if we receive a credible objection from a relative in that list. We are not equipped to adjudicate a family dispute, and a page going quiet for a while is a smaller harm than the alternatives.
What that means for the data, which is this document's half of it: a frozen page stops being served to anyone who taps the tag. Nothing is deleted when a page is frozen. The content stays where it was, the owner keeps their access to it and can still export it, and if the objection is resolved the page goes back up unchanged. A freeze is a pause, not an erasure. If the outcome is removal, that runs through the deletion path above — off the live pages promptly, purged from backups within 30 days. Where a subscribing business controls the page, we tell them and they decide, except where the content is unlawful. If we cannot reach them, we decide, on the same basis we would for our own pages.
A legal note in plain terms. Privacy law generally protects living people — in most places, a person who has died is not a "data subject" and the usual privacy rights don't attach. What does apply varies: several states have right-of-publicity laws that survive death and differ enormously from state to state, and estate law decides who speaks for the deceased. This section is our practice, not a statement of your legal rights.
If we learn that personal information has been exposed or accessed without authorization, we will investigate, contain it, and notify affected people without undue delay, and within 72 hours of confirming a breach where we have a way to reach you.
That last part is not a dodge, and it is worth saying why it's there: for most people who tap a tag, we hold no email address and no account — there is genuinely no way for us to reach you, because not collecting that is the whole point. Where we do have a way to reach you — which now includes anyone who has created an optional account — 72 hours is the commitment.
The notice will say, in plain language, what happened, what data was involved, what we've done about it, and what you should do. We will also notify authorities where the law requires it. California requires breach notification regardless of what this policy says; the commitment above is on top of that, not instead of it.
Where we are acting as a processor for a subscribing business, we notify that business without undue delay and support them in notifying their own customers — under that arrangement, the notice to the individual comes from them. If we cannot reach that business, we notify its customers ourselves, at whatever addresses we hold, and post the notice on the pages themselves.
Wherever you are, you can write to support@craftedlink.app and ask us to:
We'll do those things for anyone who asks, without checking first whether a statute obliges us to. That's the simpler policy and it's the one we'd want.
What we are not going to claim. CraftedLink is run by one person and is pre-revenue. We almost certainly do not meet the thresholds that make the California Consumer Privacy Act apply to us. We have no establishment in the European Union and we do not target the EU market. So rather than printing a compliance badge we haven't earned, this policy describes what actually happens to your data. Whether and when specific privacy statutes apply to this business is an open legal question that is being reviewed.
If you asked us for something and think we got it wrong, say so in a reply — a person will look at it again.
If we change how any of this works, we update this page and change the date at the top. For a change that meaningfully reduces your privacy — collecting something new, sharing something we didn't share before — we will say so clearly rather than quietly editing a line, and we'll notify account holders by email before it takes effect.
Old versions are kept so you can see what changed.
What changed on September 3, 2026: "The second exception" was added — CraftedLink may stand in, briefly and visibly, for a business that cannot be reached — and the "we don't access it" promise was narrowed to say so. The export route became the button on every page. The sections on removal, on a person who has died, on support windows, and on breaches gained an "if we cannot reach the business" branch. The line about a lawyer's review came out; this document stands on its own.
support@craftedlink.app
Write to us for anything in this document: access, correction, deletion, takedown of a child's content, a request about someone who has died, or a question you just want answered. Say which page or tag you're asking about if you can — it makes it faster.
CraftedLink is operated as a sole proprietorship in California, USA. As a business that operates entirely online, email is our designated contact method for every request in this document — including privacy requests under California law.
© 2026 CraftedCarvings. All rights reserved. · v1.59