brandlinc.Back to website

1. Who this notice covers

This notice covers BrandLinc’s website, installed web app, subscriber workspace and visitor activity on published profiles. The legal entity operating BrandLinc and its privacy contact will be identified before launch. Profile owners decide what they publish and are responsible for their own use of visitor enquiries and other people’s information.

2. Information we process

  • Accounts: email address, display name, authentication identifiers, verification and session information. Supabase Auth manages passwords; BrandLinc’s profile database does not store them.
  • Your profile: introduction, profession, location, selected contact details, social link, appearance, portfolio images, image descriptions and optional sections. Drafts and published versions are stored separately.
  • Workspace activity: labelled sharing links, studio requests, messages, contact preferences, request status and internal studio notes.
  • Visitor analytics: randomly generated visitor/session IDs, visited profile, event type, time, image or gallery details, contact/social clicks, broad traffic source and active viewing duration. These IDs are pseudonymous, not guaranteed anonymous.
  • Security and delivery: authentication rate-limit counters derived from hashed email/IP identifiers. Hosting and account providers may also process network addresses, request and delivery logs.

Account credentials and core profile fields are needed for their respective features. Optional portfolio sections, social links and preferences can be left blank. Contact details and a portrait are currently required to publish a profile.

3. Why we use it

We use information to create and protect accounts, save and publish profiles, host images, deliver verification and recovery emails, provide engagement statistics and respond to studio requests. We also use it to investigate misuse and meet applicable legal obligations. Before launch, BrandLinc must document an appropriate lawful basis for each purpose under POPIA and any other applicable law; publishing this notice alone does not establish that basis.

The current build has no advertising network or personal-data sales feature. Marketing and WhatsApp delivery are not connected. Saving a notification preference does not subscribe you to a working delivery service.

4. What becomes public

Publishing makes your selected profile information, contact destination and images accessible to visitors. Published pages and images can be shared, indexed, copied or captured by others. Pause your page in Settings to hide it from new public access through BrandLinc. Pausing does not delete your account, revoke copies already made or guarantee immediate removal from caches.

Your account email is not automatically displayed as a login identifier, but a new profile uses it as its initial contact destination. Review the Contact section before publishing. Clicking email, WhatsApp or a social link opens a third-party service governed by its own policies.

5. Cookies, browser storage and analytics

Essential cookies maintain authenticated sessions. A first-party visitor identifier is kept in browser local storage with a 30-day expiry that refreshes when a tracked visit begins. Session storage groups visits to the same profile for up to 30 minutes from session initialisation. Clearing browser storage removes these local identifiers, but does not remove previously recorded server events.

The analytics code records a broad referral category rather than the complete referring URL. It does not use fingerprinting. Active viewing time is counted while the page is visible, capped at 30 minutes per tracking session. Contact clicks indicate interest, not a confirmed enquiry or sale.

Profile analytics on this browser

This controls BrandLinc profile-view and interaction analytics. Essential sign-in and security processing continue. Your choice applies to this browser’s storage, not automatically to other devices or a separately installed app.

Loading your preference…

The installed app’s service worker does not deliberately cache private pages, API responses or photos for offline use. Ordinary browser caching and provider processing may still occur. Installing the app does not grant continuous access to your photo library; you choose the files you upload.

6. Providers and international processing

The architecture uses Supabase Auth for accounts, Cloudflare D1 for structured records, Cloudflare R2 for uploaded images and hosting infrastructure to serve the website. An email provider still needs to be selected and connected. Authorised BrandLinc studio staff may access requests needed to handle their work.

Production regions, contractual protections, subprocessors and cross-border transfer safeguards are not yet finalised. We do not currently promise South African-only storage. These choices must be reviewed and disclosed before real subscriber data is accepted. Information may also be disclosed when lawfully required or necessary to address misuse, subject to applicable law.

7. Retention and security

Profiles, images, requests and analytics currently have no automatic production deletion schedule. Authentication rate counters use 15-minute windows and are cleaned up on later authentication requests after expiry plus a further 15 minutes; inactive systems may retain them longer. A full retention and backup-deletion schedule must be configured before launch.

Implemented controls include verified-account checks, account-scoped access to workspace records, studio access restrictions and rate limiting. Production transport, provider configuration, backup restoration and incident response still require validation. No system can guarantee absolute security.

8. Your choices and rights

You can edit profile information, pause a published page and export selected account records from Settings. The current export contains profile data, links and customer-facing studio request details; it is not a complete copy of all provider logs, image binaries, analytics or internal records.

Subject to applicable law, you may request access, correction, deletion, restriction or objection to processing and withdraw consent where processing relies on it. We may need to verify identity and retain records required by law. Full account deletion and the request-handling contact are not operational yet and must be provided before launch. Uninstalling the app does not delete your account or server data.

You can find complaint guidance through the South African Information Regulator.

9. Children and changes

The proposed subscriber service is for adults aged 18 and over. Do not upload another person’s private information or images without the required rights and permissions, including appropriate permissions for children’s images. This policy will be updated as the service is finalised; material changes should be communicated before they take effect where required.