Platform Features Pricing About

Privacy Policy

Effective: August 30, 2026 | Last updated: August 30, 2026

1. Overview

Frontstage ("we", "us", "our") respects your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights. We are a creator bio-link platform — our business is hosting your page, not selling your data.

2. Data We Collect

2.1 Account Data

  • Email address (for login, notifications, billing)
  • Handle and display name (public on your page)
  • Avatar URL (optional, you provide)
  • Hashed password (via Supabase Auth, we never see plaintext)

2.2 Page Content

  • Blocks you create: links, text, headers, dividers, socials, campaigns, forms
  • Campaign configuration: dates, descriptions, form fields, badge settings
  • Theme customizations

2.3 Analytics Data (Anonymous)

  • Page views: timestamp, referrer (truncated), country (from Cloudflare)
  • Link clicks: block ID, target URL, timestamp, bot flag
  • Aggregated metrics: CTR, top links, time-series buckets

2.4 Lead Form Submissions

  • Name, email, message, and custom fields visitors submit
  • Submission timestamp and page handle
  • Stored in your Supabase database, visible only to you

2.5 Link Health Checks

  • Outbound URL, HTTP status, latency, redirect chain
  • Checked daily via automated cron (User-Agent: Frontstage-LinkHealth/1.0)
  • Results stored in your database

3. How We Use Your Data

  • Operate the Service: Authenticate you, serve your page, store your blocks, run campaigns, deliver form submissions.
  • Analytics: Show you page views, clicks, and link health in your workspace.
  • Notifications: Email you when a lead submits a form (Pro plan only, opt-in).
  • Billing: Process Pro plan payments via Stripe (we store only Stripe customer ID).
  • Security: Detect abuse, bot traffic, and anomalous patterns.
  • Legal: Comply with lawful requests; enforce our Terms.

We do not use your data for advertising, profiling, or third-party marketing. No tracking pixels, no Facebook/Google analytics, no data brokers.

4. Data Storage and Subprocessors

SubprocessorPurposeLocation
Supabase (PostgreSQL)Primary database: accounts, blocks, analytics, forms, link healthUS-East (AWS)
Cloudflare PagesStatic hosting, Functions, Cron, D1 (if used), KVGlobal edge
Cloudflare WorkersAPI endpoints, scheduled jobsGlobal edge
Stripe (Pro only)Subscription billingUS
Resend / SendGrid (Pro only)Transactional email (lead notifications)US

All subprocessors are GDPR-compliant and sign DPAs. Data never leaves these systems without your action (e.g., CSV export).

5. Data Retention

  • Account data: Until you delete your account (+30 day grace period)
  • Page content: Until you delete it or your account
  • Analytics (page views, clicks): 365 days on Free, indefinite on Pro
  • Link health checks: 90 days (rolling)
  • Form submissions: Until you delete them or your account
  • Server logs (Cloudflare): ~7 days (standard retention)

6. Your Rights (GDPR / CCPA)

You have the right to:

  • Access: Export all your data (JSON/CSV) from workspace → Settings → Export
  • Rectify: Edit any content in the workspace at any time
  • Erase: Delete your account → all data purged within 30 days
  • Restrict: Disable analytics, link health, or form collection per page
  • Portability: Full JSON export includes all blocks, campaigns, analytics, submissions
  • Object: Opt out of Pro-plan email notifications anytime

To exercise rights, use the workspace controls or email privacy@frontstage.page.

7. Cookies and Local Storage

Frontstage sets no marketing cookies. We use:

  • Session cookie (HttpOnly, Secure, SameSite=Lax): Supabase Auth session, 1-hour rolling
  • LocalStorage: Workspace UI state (sidebar width, active tab, preview open) — never sent to server

No third-party cookies. No fingerprinting. No cross-site tracking.

8. Visitor Privacy (Page Viewers)

When someone visits your handle.frontstage.page page:

  • We log an anonymous page view (no IP stored, country from Cloudflare edge only)
  • Clicks on link blocks are counted (bot-filtered via UA + behavior heuristics)
  • Form submissions are sent to your database — we never see them unless you export
  • No cookies set on visitors unless they log into a creator account

9. Security

  • All traffic: TLS 1.2+ (Cloudflare managed)
  • Database: Encrypted at rest (Supabase/AWS), encrypted in transit
  • Secrets: Never in code — Cloudflare Pages encrypted env vars, Supabase Vault
  • Auth: Supabase Auth (email/password, magic links, OAuth), MFA supported
  • RLS: Row Level Security on all tables — creators only see their own data

10. International Transfers

Data is processed in the United States (AWS us-east-1, Cloudflare global edge). If you're in the EU/UK, transfers rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. You may request EU-only hosting (contact us — custom setup required).

11. Children's Privacy

Frontstage is not directed to children under 13 (or 16 in EU). We do not knowingly collect data from children. If you believe a child has submitted data, contact us for immediate deletion.

12. Changes to This Policy

We may update this policy. Material changes: posted here, emailed to registered users 14 days before effective date. Continued use constitutes acceptance.

13. Contact

Data Protection Officer: privacy@frontstage.page
General: legal@frontstage.page