Privacy Policy
Last updated: August 9, 2026
1. Introduction
xoxo.bio ("we," "our," or "us") provides a creator commerce platform: a link-in-bio storefront where creators can publish links, sell digital products, courses, memberships and bookings, collect email subscribers, and automate messages. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
This policy covers two groups of people: Creators (people with an xoxo.bio account) and Visitors and Customers (people who view a creator's page, join their list, or buy from them). Where a creator is the controller of customer data, we act as a processor on their behalf.
By using xoxo.bio you agree to this policy. If you do not agree, please do not use the Service.
2. Information We Collect from Creators
Account information
- Email address and password (stored only as a secure hash)
- Username, which forms your public URL
- Display name and, optionally, your profile photo and bio
- Plan, trial status, and billing state
Google sign-in
If you sign up or log in with Google, we receive your name, email address and profile image from Google. We do not access your Gmail, contacts, calendar or any other Google data.
Page and store content
- Links, headers, image links, embeds, and social profiles
- Products: titles, descriptions, images, pricing, and delivery files
- Courses: modules, lessons, uploaded or hosted video, and attachments
- Bookings: availability, time zone, meeting links, and session details
- Themes, fonts, colors, layout and other design preferences
- Custom domain settings, if you connect one
Payment and payout information
Selling on xoxo.bio requires a connected Stripe account. Stripe collects your identity, tax and bank details directly for verification and payouts. We never see or store your full bank details or card numbers. We store your Stripe account ID, onboarding and payout status, and order-level records such as amounts, currency and product purchased.
Your own xoxo.bio subscription is billed through Stripe. We retain your customer ID, plan, renewal date and payment status.
Instagram connection (optional)
If you connect an Instagram professional account, we receive an access token plus your account ID, username and profile picture. Where you have created an automation rule, we receive comment events on your posts (comment text, commenter's Instagram ID and username, and the post it belongs to) and send the direct messages and public replies you configured. Tokens are stored encrypted and used only to run the automations you set up. Disconnecting your account in the dashboard deletes the stored token and stops all processing.
Support and communications
Messages you send us, and records of service emails we send you, including onboarding, billing and security notices.
3. Information We Collect from Visitors and Customers
Page analytics
When someone views a creator's page, we record:
- Page views, link clicks and product views
- Referring website or source, and campaign attribution parameters
- Approximate country and city derived from IP address; the raw IP is not stored
- Device type, operating system and browser
- An anonymous session identifier
Purchases
At checkout we collect the buyer's name and email address so the purchase can be delivered and receipted. Card details are entered directly into Stripe's hosted payment fields and never touch our servers. We store the order record, product, amount, status and delivery or access history, and where applicable the login used to access purchased content in the customer library.
Email lists and automations
If a visitor joins a creator's list or makes a purchase, we store their email address, name where given, source, subscription status and engagement events such as sends, opens and unsubscribes, so the creator can send newsletters and automated sequences. Every marketing email includes an unsubscribe link.
Abandoned checkout recovery
If a buyer enters their email at checkout but does not complete the purchase, we store that email and the intended product so the creator's recovery email can be sent. These records are deleted when the checkout is completed or after the retention period for the creator's recovery sequence ends.
Bookings
For a booked session we collect the attendee's name, email, chosen time, time zone and any message they provide, and share it with the creator hosting the session.
4. How We Use Information
- Operate, maintain and secure the Service and your public page
- Process payments, deliver purchases and grant access to courses and memberships
- Send transactional messages: receipts, delivery links, booking confirmations, password resets and security alerts
- Run the email campaigns, sequences and Instagram automations you configure
- Show analytics, revenue reporting and recovery attribution in your dashboard
- Detect, prevent and investigate fraud, spam and abuse
- Improve the Service and troubleshoot errors
- Comply with legal, tax and accounting obligations
We do not sell your personal information, and we do not use your content or your customers' data to advertise to them on our own behalf.
5. Legal Bases (EEA/UK)
Where GDPR or UK GDPR applies, we rely on: contract to provide the Service and process orders; legitimate interests to secure the platform, prevent abuse and measure aggregate performance; consent for marketing emails and optional integrations, which you may withdraw at any time; and legal obligation for tax and record-keeping.
6. Cookies & Local Storage
We use essential cookies and browser local storage to keep you signed in, remember preferences, and attribute a visit to the link or campaign that produced it. We do not run advertising networks or third-party tracking cookies on creator pages.
If a creator adds a Google Analytics measurement ID to their page, Google may set additional cookies on visitors' browsers under Google's own privacy policy. That choice belongs to the creator.
7. Service Providers We Share Data With
- Stripe — payments, Stripe Connect payouts, subscriptions and tax reporting (Stripe Privacy Policy)
- Supabase — database, authentication and file storage infrastructure
- Cloudflare — hosting, content delivery, custom domain routing and security filtering
- Bunny Stream — hosting and delivery of course video for paid courses
- Email delivery providers — sending transactional and creator marketing email
- Meta / Instagram — only if you connect an Instagram account, to receive comment events and send messages and replies
- Google — sign-in, and Google Analytics only where a creator configures it
These providers act on our instructions under contract. We may also disclose information where required by law, to enforce our Terms, or as part of a merger or acquisition, in which case we will notify affected users.
8. International Transfers
Our providers operate globally, so your information may be processed in the United States and other countries. Where required, transfers rely on Standard Contractual Clauses or another approved safeguard.
9. Security
We use encrypted connections (HTTPS/TLS), hashed passwords, encrypted storage of third-party access tokens, signed URLs for paid content, row-level security policies on our database, and webhook signature verification for payment and Instagram events. No system is perfectly secure, and we cannot guarantee absolute security.
10. Retention & Deletion
We keep account and store data while your account is active. You can delete your account from Settings, or by contacting us. On deletion:
- Your page, links, products, courses and uploaded media are permanently removed
- Your username becomes available again
- Analytics, subscriber lists and automation rules are deleted
- Connected Instagram tokens are revoked and deleted
- Order and payment records are retained where required for tax, accounting and dispute resolution
Customers of a creator may ask that creator, or us, to delete their subscriber or purchase record, subject to the same legal retention limits.
11. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data
- Object to or restrict certain processing
- Receive your data in a portable format
- Withdraw consent, including by unsubscribing from marketing email
- Lodge a complaint with your local data protection authority
To exercise these rights, email us at the address below. If your request concerns data held by a specific creator, we will forward it to them and assist as needed.
12. Children's Privacy
xoxo.bio is not intended for children under 13, and selling on the platform requires you to be at least 18. We do not knowingly collect personal information from children under 13, and will delete it promptly if we learn we have.
13. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be posted here with a new "Last updated" date, and where appropriate notified by email. Continued use after changes means you accept the updated policy.
14. Contact Us
Questions about this policy or your data? Contact us at: hello@xoxo.bio