Privacy Policy
Version 2026-09-04 · In effect from 2 September 2026
This policy describes what [LEGAL ENTITY NAME] (“Showfinch”, “we”) collects when you create a page with us or visit someone else’s, why we collect it, and what you can ask us to do with it. It is written to be read, not to be scrolled past.
Contact: [CONTACT EMAIL] · [REGISTERED ADDRESS]
1. Who this covers
There are two different people in this document, and they are treated differently.
- Creators — people who sign up and publish a page. You give us an account, and we are the data fiduciary (DPDP Act) and controller (GDPR) for it.
- Visitors — people who open a creator’s page. We do not ask visitors to sign in, and we do not build a profile of them. What we measure is described in section 3.
2. What we collect from creators
| What | Why | Lawful basis |
|---|---|---|
| Email address | Signing in, verifying the account, password resets, service notices | Performance of the contract |
| Password (stored only as a bcrypt hash — never the password itself) | Signing in | Performance of the contract |
| Username, display name, bio, avatar, background image or video | These are your public page. Anything you put here is published by design. | Performance of the contract |
| The links you add | These are your public page | Performance of the contract |
| Google account identifier and email, if you sign in with Google | Signing in without a separate password | Performance of the contract |
| Which policy version you accepted, when, and the country reported by our edge | To show that consent was given, which the law requires us to be able to do | Legal obligation |
3. What we measure when someone visits a page
The purpose of Showfinch is telling a creator what is working, so we do measure visits. We have tried to do that without keeping a record of who each visitor is.
We do not store visitors’ IP addresses
When someone opens or clicks through a page, we take their IP address and browser User-Agent, join them with a secret salt and the current date, and store a SHA-256 digest. The digest lets us count the same person twice in one day as one visitor. It changes every day, cannot be reversed into an address, and is not linked across days or across creators. The IP address itself is never written to our database.
What is recorded alongside it
- Which page and which link, and the time
- The referring site — where the visit came from, such as Instagram or a search engine
- A campaign tag, if the link that brought the visitor carried one
- A device category — phone, tablet or desktop
- The country reported by our edge network, when available
- The full User-Agent string of the browser, on link clicks. This is more detail than the category above and can contribute to identifying a device. We are recording it today and are reducing it to the category alone.
The optional question
Some creators switch on a single, optional question asking a visitor’s age range. It is answered anonymously, it can be dismissed, it is asked at most once per visitor, and the answer is stored as a range only. Nothing on the page depends on answering it.
4. Advertising on free pages
Pages on the free plan carry advertising, served by [AD NETWORK NAME]. This is how the free plan is paid for. Paid plans carry no advertising.
We want to be exact about what this means, because it is the part of this policy with the largest effect on a visitor:
- The advertising network sets its own cookies and identifiers in the visitor’s browser. These are the network’s, not ours, and they can be used to recognise that visitor on other sites that carry the same network.
- Which advertisement is shown may be chosen using data the network holds about the visitor, not only the content of the page.
- The network receives the visitor’s IP address and browser information directly, as a consequence of loading the advertisement. We do not send it to them, and we still do not store it ourselves — but their receiving it is real, and no wording on our side changes that.
- Advertising cookies are set only if the visitor agrees. Declining leaves the page fully working, with non-personalised advertising or none at all.
No advertising is shown to anyone who tells us they are under 18, and no advertising profile is built from their visit. Indian law prohibits targeted advertising directed at children outright, and we treat that as the floor rather than the ceiling.
5. What we still do not do
- We do not sell personal data.
- We do not give the advertising network your account details, your email address, or your analytics.
- Our own measurement does not follow visitors between different creators’ pages or across the wider web. The salted digest described in section 3 is scoped to one creator and one day by design. The advertising network’s cookies are a separate thing and are not so limited — which is exactly why they are consented to separately.
- We do not use your data to train machine learning models.
6. Cookies and local storage
Necessary, and always present
Your browser holds your sign-in tokens so you stay signed in, and remembers that a page has already asked you the optional question so it does not ask again. Both are necessary for the thing you asked for, both stay in your browser, and neither can be switched off without breaking the thing they support.
Advertising, and only with agreement
On free pages, the advertising network sets cookies once a visitor has agreed to them. A visitor is asked before any advertising cookie is set, not after; refusing is one click, and the choice can be changed at any time from the same control. We do not use analytics cookies of our own — our measurement works from the daily digest in section 3 instead.
7. Private rooms
A creator on a paid plan can run a private room — a members-only area holding links, photographs, video and files. Opening one requires a Showfinch account, which is what makes the rest of this section possible to state honestly.
The creator of a room can see who has opened it. They see the handle, display name and profile picture of every signed-in person who has visited, how many times, and when that last happened. They also see whether you are a member and whether you follow the room. This is not anonymous and it is not aggregated: if you open somebody’s private room, they learn that you did.
Nobody else sees this. It is shown to the creator of that one room, about that one room, and nowhere else — not to other visitors, not to other creators, and not on any public page. Your email address is never shown to a creator by this panel; an invitation you were sent is the only thing that puts your address in their hands, and that is because they typed it.
Content inside a room is stored encrypted at rest, and is served through links that expire within minutes and are generated per view. On a plan with a retention period, uploads stop being visible when it ends; they are hidden first, not deleted immediately, so a mistake is recoverable.
8. Who else touches the data
| Service | What it handles | Where |
|---|---|---|
| Cloudflare R2 | Avatars, background images and videos you upload | Global edge storage |
| Resend | Verification, password reset and service emails | United States |
| Sign-in, only if you choose to use it | United States | |
| [AD NETWORK NAME] | Advertising on free pages. Receives the visitor’s IP address and browser information when an advertisement loads, and sets its own cookies once the visitor has agreed. | Global |
The first three are processors acting on our instructions. The advertising network is not — it decides for itself how it uses what it collects, which makes it an independent controller of that data, and its own privacy policy governs it. That distinction matters: we can tell you what it receives, but we cannot promise what it then does with it.
Where this involves moving data outside your country, we rely on the transfer mechanisms those providers offer, including Standard Contractual Clauses where the GDPR applies.
9. How long we keep things
- Your account and page — until you delete them. Deleting your account removes your profile, links, uploaded media and analytics.
- Analytics — free accounts can see 90 days; paid accounts keep the full history for as long as the account exists.
- A page address you stop using — held for 30 days, during which it redirects to your current address, then released for anyone to take.
- Consent records — kept while the account exists and for a reasonable period afterwards, because their whole purpose is to evidence consent that has been given.
- Sign-in sessions — expire on their own and are deleted automatically.
10. Your rights
Wherever you are, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to [CONTACT EMAIL] and we will respond within 30 days.
If you are in India
The Digital Personal Data Protection Act, 2023 gives you the right to access, correct, complete, update and erase your data, to nominate someone to exercise your rights if you cannot, and to have a grievance heard. Our Grievance Officer is [GRIEVANCE OFFICER NAME], reachable at [GRIEVANCE OFFICER EMAIL]. Complaints are acknowledged within 24 hours and resolved within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India.
If you are in the UK or EEA
You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your national supervisory authority. Where we rely on consent, you may withdraw it at any time; withdrawing it does not undo processing that already happened.
11. Children
Showfinch is not for people under 18. We do not knowingly create accounts for children. Indian law requires verifiable parental consent before processing a child’s data and prohibits tracking or behavioural monitoring of children, which we are not equipped to do — so the age limit is a real condition of using the service, not a formality. If you believe a child has an account, write to [CONTACT EMAIL] and we will remove it.
12. Security
Passwords are stored as bcrypt hashes. Traffic runs over TLS. Sessions can be revoked, and are revoked automatically when a password is reset. Uploads are handed directly to storage with a signed, short-lived URL scoped to one file. No service is perfectly secure, and we will tell you and the relevant authority if a breach affects you, within the timeframes the law sets.
13. Changes
Each version of this policy is dated. If we change it in a way that affects your rights or introduces a new purpose, we will ask you to accept the new version rather than change it underneath you. Your acceptance is recorded against the version you were shown.
Questions about this document can go to the contact address above. If we change it in a way that affects your rights, we will ask you to accept the new version rather than change it underneath you.