Privacy
What we collect, and what we don't.
This is the whole policy. If a sentence here is unclear, write to us and we'll fix the sentence, not just answer the question.
OneLink is run by Noettic Labs. We keep only what the product needs to work, we don't sell any of it, and we don't show ads.
If you make a page
Your account. Your email address and a password, or a sign-in through Google if you choose that. We use the address to sign you in and to send you receipts and notices about your account. We don't send marketing email unless you ask for it.
Your page. Everything you put on it: your name, bio, pictures, links, tiles, events, the design you pick, and the addresses of any feeds you connect. This is public by design; it's the page you share.
Payments. Card details go straight to Stripe, our payment processor. We never see or store your card number. We keep the plan you're on and Stripe's reference for your subscription so we can show you your billing history.
Imports. When you paste the address of an old link page, we fetch that public page once, on your instruction, to copy its links and pictures onto your OneLink page. We don't keep the fetched page afterwards.
Instagram. If you connect your Instagram account to show your posts on your page, you log in on Instagram's own screen and allow OneLink to read your profile name and your posts. We never see your Instagram password. We keep a sign-in key from Instagram, which only our servers can read, and a copy of each post's caption, picture, address and date, so the post can appear on your page as a tile. We don't post, comment, read messages or look at anyone else's account. Disconnect Instagram in your dashboard, or remove OneLink in your Instagram settings, and we delete the sign-in key at once. Ask Instagram to delete your data and we also delete the posts we copied and the tiles made from them.
LinkedIn. If you connect LinkedIn so OneLink can post your new stories there, you log in on LinkedIn's own screen and allow OneLink to see your name and email address and to post on your behalf. We never see your LinkedIn password. We keep your LinkedIn member ID, your name and a sign-in key, which is encrypted and only our servers can read. We also keep the posts we prepare for you: each story's headline, link and your text, whether it was posted, and the LinkedIn post's ID. We only post what you ask us to, and we don't read your feed, your messages, your connections or anyone else's profile. Disconnect LinkedIn in your dashboard, or remove OneLink in your LinkedIn settings, and we delete the sign-in key at once. The record of past posts stays with your page until you delete the page or your account.
LinkedIn carousels and share buttons. When you turn a story into a LinkedIn carousel, we read the opening of that public story to write the pages, and the PDF is made on your own device. We don't keep the text or the PDF. When a visitor uses a share button on your page, their own browser opens LinkedIn or the app they pick. We only count that a share happened and which app it went to.
Insights. When someone taps a tile or button on your page, or views it, we record that a tap or view happened, which tile or button, the site the visitor came from (such as instagram.com) and whether they were on a phone or a computer. That's all. We don't record who the visitor was, and we don't store their IP address. These numbers belong to you and are never deleted while your account exists.
Lists. If you turn on the email box, message box or event sign-ups, the addresses and messages people send you are stored in your dashboard for you to read and export. They're yours. We don't use them for anything else.
If you visit someone's page
We count the visit and any taps as described above, without identifying you. If you type your email into a sign-up box, a message box or an event form, that goes to the person who runs the page, and their own privacy practices apply to what they do with it. If you tap "Save my contact", a contact card is generated on your device.
If you say you're going to an event, we email you a confirmation with a calendar invite, a note if a waitlist spot opens for you, and a reminder the day before if the page owner switched reminders on. Every one of those emails has a link to cancel. Your browser also remembers the name and email you gave on that page, so next time you can say yes in one tap. That stays on your device, and “Not you?” clears it.
If you tap play on a Spotify, Apple Music, Apple Podcasts, SoundCloud, YouTube, Vimeo or Mixcloud tile, that service's player loads, and its own privacy policy applies to what it collects. Nothing from those services loads until you tap play. Podcast episodes play straight from the podcast's own host.
Cookies
A cookie keeps you signed in to your dashboard. Our hosting provider sets a short-lived cookie that helps it tell people from bots. OneLink itself doesn't use advertising or tracking cookies. A page owner on a paid plan can add their own analytics to their page (Google Analytics, Meta Pixel, Adobe Analytics, Chartbeat or Parse.ly). When they do, visitors in the EU, the UK and Switzerland are asked first and nothing loads unless they agree, and Meta's pixel doesn't load for browsers that send Global Privacy Control. What those companies collect is covered by the page owner's own policy and theirs.
Who else touches the data
- Supabase hosts the database and the pictures you upload.
- Stripe handles payments.
- Cloudflare serves the site and keeps standard server logs for a short time, as every host does.
- Resend sends our emails, such as invitations, notices and the summary email.
- Lovable is the platform OneLink is built and deployed on.
- Google Fonts serves the typefaces, which means Google's servers see a font request from your browser.
- Firecrawl fetches a public page for you when a site refuses to answer our own servers during an import.
Each of these processes data only to do that job for us. We don't hand your data to anyone else. If you connect your own tools to your page, such as Slack, a webhook or a CRM, we send them the details you asked for, on your instruction. The current list is also on our subprocessors page.
Where it lives, and for how long
Data is stored on servers in the United States. We keep it for as long as you have an account. Close your account and we delete your page, your uploads and your lists within thirty days; receipts stay with Stripe for as long as tax law requires.
Your choices
- Export your subscriber, message and event lists from the dashboard at any time.
- Change or delete anything on your page yourself.
- Ask us to send you everything we hold about you, or to delete your account entirely, by writing to support@onelinkin.bio.
Children
OneLink is not for anyone under 16, and we don't knowingly keep data about anyone that young.
Changes
If this policy changes in a way that matters, we'll email account holders before it takes effect. Small wording fixes just get made. This version is dated September 28, 2026.