Legal

Privacy Policy

Last updated: June 28, 2026

This policy explains what personal information knit.bio collects, how we use and share it, and the choices and rights you have. It covers our website, the creator dashboard, and the published pages we host on your behalf. We've written it to reflect how the product actually works, including the data your page visitors and customers generate.

1. Who we are & our two roles

knit.bio (“knit.bio”, “we”, “us”) is a link-in-bio platform that lets creators build a page, share links, grow an audience, and sell products. Because of what the platform does, we handle personal data in two different capacities, and your rights depend on which applies:

  • As a controller: for the personal data of our account holders (creators). This includes your signup details, profile, billing information, and how you use the dashboard. This policy governs that data directly.
  • As a processor (service provider): for the personal data a creator collects from their own page visitors and customersthrough knit.bio, such as page analytics, form/lead submissions, and order details. The creator is the controller of that data; we process it on their behalf under our Terms. If you visited someone's knit.bio page and have a request about your data, please contact that creator first. We will support them in responding.

2. Information you give us

When you create an account or use knit.bio as a creator, you provide:

  • Account & identity: email address, username, password, and (optionally) display name, user type, and category. Passwords are hashed by our authentication provider. We never see or store them in plain text.
  • Profile & page content: your bio, profile photo/avatar, optional phone number, social links, and any text, images, files, or products you add to your page.
  • Payment & payout details: when you subscribe to a paid plan or sell products, our payment processor (Stripe) collects your card and, for payouts, your bank/identity details directly. We store only limited billing metadata: a Stripe customer reference, your plan, billing period, and subscription status. We do not store full card numbers.
  • Support & communications: the contents of messages you send us and any information you include when contacting support.

3. Information we collect automatically

When you use the dashboard, we and our providers automatically collect:

  • Device & log data: IP address, browser type, operating system, device type, and the actions you take in the app, used to operate, secure, and debug the service.
  • Product analytics: we use PostHog to understand how creators activate and use features (e.g., sign-up, page published, block added, upgrade interest). These events are tied to your account ID and plan so we can improve the product.
  • Performance metrics: anonymous speed and performance data (via Vercel Speed Insights) to keep pages fast.

4. Information about your visitors & customers

When someone visits a published knit.bio page, interacts with it, or buys a product, we collect data on the creator's behalf so they can see how their page performs. Here, the creator is the controller and we are the processor:

  • First-party page analytics:a pseudonymous, randomly generated visitor ID and session ID (stored in the visitor's own browser storage, not advertising cookies), the type of event (view, click, impression, submission), the referring URL, any UTM campaign tags in the link, and device type, OS, and browser inferred from the browser's user agent.
  • Approximate location:a coarse country, region, and city derived from the visitor's IP address. We use the IP to determine this location and to rate-limit and protect the endpoint; we do not store the raw IP address in the analytics record.
  • Lead & form submissions: if a creator adds an email capture, contact form, phone capture, or poll, we store what the visitor submits (such as email, phone, name, form answers, or poll choice) so the creator can view it in their dashboard.
  • Orders & purchases: when a visitor buys a digital product, we record the order: buyer email, product, amount, currency, payment references, and a secure download token. Card details are handled directly by Stripe, not stored by us.

5. How we use information

We use personal information to operate and improve knit.bio. Where the GDPR applies, our legal basis is shown in brackets.

  • Provide, maintain, and secure the platform and your account (performance of a contract).
  • Process subscriptions, payments, and creator payouts (performance of a contract).
  • Give creators analytics and insights about their pages, audience, and sales (legitimate interests; processing on the creator's behalf).
  • Detect, prevent, and respond to fraud, abuse, and security incidents (legitimate interests / legal obligation).
  • Understand usage and improve features and reliability (legitimate interests; consent where required).
  • Send transactional and service messages (receipts, security alerts, important updates) (contract); marketing only where you have opted in, with an opt-out in every message (consent).
  • Comply with legal, tax, and accounting obligations (legal obligation).

6. How we share information

We do not sell your personal information.We share it only with the service providers (“sub-processors”) that run the platform, with integrations you choose to connect, and where required by law:

  • Supabase: managed database, authentication, and file storage that host your account, page content, and uploads.
  • Stripe: payment processing, subscription billing, and Connect payouts for creators selling products.
  • PostHog: product analytics about how creators use the platform (US-hosted).
  • Vercel: application hosting, performance insights, and IP-based geolocation used to derive approximate visitor location.

We may also disclose information to comply with law or valid legal requests, to enforce our Terms or protect rights, property, and safety, and as part of a business transfer (such as a merger or acquisition), in which case we will notify you of any change in control of your data.

7. Integrations you connect

Creators can connect third-party tools to a page, for example Google Analytics (GA4), Meta/Facebook Pixel, Google Ads, Mailchimp, ConvertKit, Beehiiv, Resend, SendGrid, PayPal, Zapier, and WhatsApp. When you enable an integration:

  • Relevant data (such as page events, leads, or orders) may be shared with that provider, and the provider's own privacy policy governs what they do with it.
  • Some integrations (like analytics pixels) may set their own cookies on your published page when enabled.
  • Any API keys or tokens you provide are encrypted at rest and are never exposed to your page visitors or returned to the browser.
  • You control these connections and can disconnect an integration at any time from your dashboard.

8. Cookies & local storage

We keep our use of browser storage minimal and purposeful:

  • Essential cookies set by our authentication provider keep you securely signed in to the dashboard. The service does not work without them.
  • Local & session storage on published pages holds the pseudonymous, random analytics identifiers described above. These are not advertising cookies and are not used for cross-site tracking. Visitors can clear them through their browser settings.
  • Third-party cookies may be set only when a creator has connected an analytics or advertising pixel to their page. Those are governed by the relevant provider and the creator's configuration.

9. International data transfers

We and some of our providers (including Stripe, PostHog, and Vercel) operate in the United States, so your information may be processed in the U.S. and other countries where data-protection laws may differ from yours. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to protect data transferred internationally.

10. Data retention

We keep personal information only as long as we need it for the purposes above:

  • Account & profile data: for as long as your account is active. After you close it, we delete or anonymize your data, except where we must retain it to meet legal obligations.
  • Order & transaction records: retained as required by tax and accounting law (typically up to 7 years).
  • Page analytics & submissions: retained to provide creators with reporting. Creators can delete their own analytics events and lead submissions from the dashboard at any time.

11. How we protect your data

We apply technical and organizational measures designed to protect personal information, including:

  • Encryption of data in transit (TLS) and at rest.
  • Row-Level Security that isolates each account's data so creators can only access their own records.
  • Integration secrets (API keys and tokens) encrypted at rest with dedicated keys.
  • Private storage for paid digital products, delivered only through short-lived, single-purpose signed download links after a verified purchase.
  • Access controls, authentication, rate limiting, and PCI-DSS-compliant payment handling through Stripe.

No system is perfectly secure, so we cannot guarantee absolute security, but we work continuously to protect your information and to respond quickly to any incident.

12. Your privacy rights

Depending on where you live (including under the GDPR/UK GDPR and the CCPA/CPRA), you have rights over your personal information:

  • Access & portability: get a copy of your data, or have it transferred.
  • Correction: fix inaccurate or incomplete information.
  • Deletion: ask us to erase your personal information.
  • Restriction & objection: limit or object to certain processing, including processing based on legitimate interests.
  • Withdraw consent: where we rely on consent, withdraw it at any time, and opt out of marketing in every message.
  • No sale or “sharing”: we do not sell or share your personal information for cross-context behavioral advertising, and we will never discriminate against you for exercising your rights.

You can manage much of your data directly in your account settings, or email us at privacy@knit.bio. If you interacted with a creator's page and want to exercise rights over that data, contact the creator (the controller); we will assist them as their processor.

13. Children

knit.bio is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

14. Changes & contact

We may update this policy as the product and the law evolve. When we make material changes, we'll update the “Last updated” date above and, where appropriate, notify you. Your continued use of knit.bio after an update means you accept the revised policy.

Questions, requests, or concerns about your privacy? Reach our team at:

privacy@knit.bio

Create your page