Stickylink Workspace, Privacy Policy
Last updated: August 4, 2026
What we collect
- Account data: your email address, name (if you provide one), and the corporate email domain we use to bucket you into an org.
- Workspace data: the assets, templates, and sticker mappings your team creates.
- Audit log data: timestamp, actor user ID and email, action type, object ID, and IP address for every create/view/update/archive action.
- Billing data: processed by Stripe. We do not store card numbers.
What we don't collect
We don't collect Protected Health Information, payment card data, classified information, or any of the other categories prohibited by the Workspace Terms. If you accidentally upload such data, contact us at hello@stickylink.io and we will remove it.
How we use it
To run your workspace, generate your audit log, deliver physical stickers, and bill you. We do not sell workspace data or use it to train AI models.
Subprocessors
- Supabase (database and auth), hosted on AWS
- Cloudflare (edge and DNS)
- Stripe (payments)
- Google (Google Workspace sign-in)
Data location & encryption
Data is stored in AWS US regions. Transit is encrypted with TLS 1.3. At-rest encryption is provided by the underlying hosting infrastructure.
Retention
Workspace data is retained for the lifetime of your subscription. Audit-log entries are retained for the lifetime of the organization and are not user-deletable by design. After account termination, we retain data for up to 90 days for restoration.
Your rights
You can request access to, correction of, or deletion of your personal data by emailing hello@stickylink.io. Note that audit-log entries may be retained for the lifetime of the organization even after your individual account is deleted, as required by the workspace's integrity model.
Cookies
We use only the cookies and local storage required to keep you signed in, remember session preferences, and run essential workspace features. We do not use third-party advertising or tracking cookies.
Security
Workspace connections use TLS 1.3, data is encrypted at rest by the underlying hosting infrastructure (AWS-managed KMS), and every workspace table is protected by Postgres row-level security so only approved members of your organization can read or write your data. No online service is completely secure; you can help by using strong, unique passwords and (where available) enabling multi-factor authentication.
Children's privacy
Stickylink Workspace is a B2B product intended for adult professionals. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
International users
Stickylink is operated from the United States. If you access the service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
Changes to this policy
We may update this Privacy Policy as the product evolves. Material changes will be announced in-app or by email and reflected on this page with a new "last updated" date.
Privacy questions? Contact us at hello@stickylink.io.
