DinkyLegal

Privacy Policy

Last updated: September 24, 2026

DINKY SAS (“Dinky”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, store, and protect information when you access or use Dinky, including our website available at https://dinky.cc and related products, services, applications, creator pages, and advertising transaction tools (collectively, the “Service”). By using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for processing your personal data is:

DINKY SAS
69 Rue de Paris, 92110 Clichy, France
SIREN: 992 934 471
VAT Number: FR64 992 934 471
President: Sergei Liashenko
Privacy Contact: dev@dinky.cc
Website: https://dinky.cc

2. Scope of This Policy

This Privacy Policy applies to:

  • visitors of dinky.cc;
  • creators using Dinky;
  • advertisers using Dinky;
  • users interacting with creator pages hosted by Dinky;
  • users connecting social media accounts to Dinky;
  • individuals who follow a Dinky tracking link published in a creator's content;
  • individuals communicating with Dinky.

3. Information We Collect

3.1 Account Information

When you create an account, we may collect:

  • name;
  • email address;
  • username;
  • profile photo;
  • password credentials (stored securely and encrypted where applicable);
  • account preferences.

3.2 Creator Information

Creators may provide:

  • creator biography;
  • social media handles;
  • pricing information;
  • availability information;
  • media kit information;
  • booking preferences;
  • advertising formats;
  • uploaded documents;
  • communication history.

3.3 Advertiser Information

Advertisers may provide:

  • company name;
  • contact details;
  • billing details;
  • campaign information;
  • booking requests;
  • communications with creators.

3.4 Social Platform Data

If you connect supported platforms, Dinky may access data made available through APIs and permissions you authorize. This may include:

  • profile information;
  • follower counts;
  • audience demographics;
  • engagement statistics;
  • content performance metrics;
  • audience geography;
  • account identifiers;
  • publicly available content information.

Supported platforms may include Instagram, Facebook, TikTok, YouTube, Google, and additional platforms added in the future. We only access information permitted by the platform and authorized by the user.

3.5 Payment Information

Payments may be processed through third-party payment providers, including Stripe and Stripe Connect. Dinky does not store complete payment card numbers. We may receive payment status, transaction identifiers, payout information, billing information, connected account information, and payment-related metadata.

3.6 Advertiser Request Data

Advertisers can send a booking request to a creator directly from the creator's public page without creating an account. When you submit such a request, we collect:

  • brand or company name and website;
  • contact person name and email address;
  • the requested placement, date, and campaign period;
  • the campaign brief you provide (goal, product description, brief text, links);
  • a record of your acceptance of our Terms;
  • a hashed network identifier used for abuse prevention.

We use this information to deliver your request to the creator, to enable the creator and you to negotiate and confirm the placement, and to send you email updates about the status of your request. Declined and expired requests are deleted 24 months after closure. Accepted requests and the resulting bookings are retained for as long as necessary for contractual and accounting purposes, unless a longer retention period is required by law.

If a creator has no placements open for booking, you may instead send them a contact message from their public page. In that case we collect your brand or company name (optional), your email address, the text of your message, and a hashed network identifier used for abuse prevention. We use this information solely to deliver your message to the creator by email so they can reply to you directly.

3.7 Tracking Link Clicks

A creator may create a short tracking link (https://dinky.cc/l/…) for a placement and include it in the content they publish. If you follow such a link, we record the click and then send you on to the advertiser's page. For each click we store the date and time, a one-way fingerprint computed from your IP address together with your browser's user agent and the current day, and the origin of the site you came from (for example https://www.instagram.com — never the full address of the page you were reading). We do not keep your user agent itself: it is used to compute the fingerprint and then discarded.

We do not store your IP address. It is used only to compute the fingerprint and is written to no database column and to no log. The fingerprint cannot be turned back into an address, it changes every day, and it exists for one purpose: to tell a returning visitor from a new one, so that the creator and the advertiser can be told how many people — and not merely how many clicks — a placement produced. We set no cookie, load no tracking pixel, and build no profile of you across sites or over time.

We rely on the legitimate interests of the creator and the advertiser in measuring an advertising placement they have contracted for, balanced against your rights by the fact that we hold no identifier capable of singling you out beyond a single day. Click records are deleted 24 months after the click.

3.8 Automatically Collected Information

As you browse the Service, our servers and our hosting providers automatically receive technical information about the request. Where a specific processing operation is described elsewhere in this section, that description governs — in particular section 3.7 for tracking link clicks, where your IP address is used only to compute a one-way fingerprint and is stored in no database column and in no log of ours.

Subject to that, the information received may include:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • language preferences;
  • referral URLs;
  • usage information;
  • interaction events;
  • cookie identifiers.

3.9 Sign-Up, Sign-In and Password Reset Security

Each of these three forms causes us to send an email to whatever address is typed into it, so each of them is protected against automated abuse. When you submit one, we record the date and time and a one-way fingerprint computed from your IP address, together with which of the three forms it was. We do this to cap how many such emails one sender can cause, after a campaign used our sign-up form to send confirmation emails to people who had not asked for them.

We do not store your IP address and we do not store the email address alongside this record: the fingerprint cannot be turned back into an address, and the record says only that a send was made, never to whom. These records are deleted 30 days after the attempt.

These forms also display a security check (a “CAPTCHA”) provided by Cloudflare, Inc., which acts as our processor. Loading the check sends your IP address and technical information about your browser to Cloudflare, which uses them to tell a person from an automated script and for no other purpose; Cloudflare states that it does not use this data to profile visitors or to serve advertising. The check is necessary for the security of the Service and is therefore shown without a consent prompt; it sets no advertising cookie.

We rely on our legitimate interest in protecting the Service, the people whose addresses would otherwise receive unrequested mail, and our ability to keep delivering the transactional emails the Service depends on.

4. How We Use Information

We use information to:

  • provide and operate the Service;
  • create and manage accounts;
  • generate creator pages and media kits;
  • process advertising bookings;
  • facilitate creator-advertiser transactions;
  • process payments and payouts;
  • provide analytics and reporting;
  • verify campaign performance;
  • communicate with users;
  • improve product functionality;
  • provide customer support;
  • monitor security;
  • prevent fraud and abuse;
  • comply with legal obligations;
  • enforce our agreements.

5. Legal Basis for Processing

For users located in the European Economic Area, United Kingdom, or similar jurisdictions, we process personal data under one or more of the following legal bases:

  • Contract Performance — to provide and operate the Service.
  • Legitimate Interests — to improve our products, prevent fraud, maintain security, and develop new features.
  • Consent — where required by law, including certain analytics, marketing, and cookie activities.
  • Legal Obligations — to comply with legal, regulatory, tax, and accounting requirements.

6. Cookies and Tracking Technologies

Dinky uses cookies and similar technologies. These technologies help us:

  • operate the Service;
  • authenticate users;
  • improve performance;
  • analyze traffic;
  • understand user behavior;
  • prevent abuse.

Technologies may include cookies, web beacons, pixels, local storage, and analytics tools. We may use Google Analytics, PostHog, Meta Pixel, Microsoft Clarity, Hotjar, Sentry, and other similar providers. Where required by law, users will be asked for consent before non-essential cookies are activated. See our Cookie Policy for details.

7. Sharing of Information

We do not sell personal data. We may share information with:

Service Providers

Including providers supporting hosting, authentication, analytics, infrastructure, security, customer support, and payments. Examples may include Vercel, Supabase, Cloudflare, Stripe, Google, Meta, TikTok, and Microsoft.

Connected Platforms

When authorized by users.

Publicly Shared Campaign Reports

Once a placement has been published, the creator can generate a link that opens the campaign report for that placement — for instance to show a client, or to include in a media kit. That report shows the creator's name and the advertiser's brand name; the placement, its format and the price agreed for it; where the collaboration stands (published, report filed, or completed); the campaign period and the dates of the collaboration; the link to the published content; the placement's tracking link, the website it sends people to, and how many clicks and unique visitors it received; every performance figure recorded for the placement, with the source and date of each, together with the click-through and engagement rates calculated from those same figures; and any note the creator added.

It does not show the advertiser's campaign brief or objective, their contact or billing details, the full destination address behind the tracking link (only the website it leads to), which sites the clicks came from, whether the advertiser confirmed the publication themselves or it was confirmed automatically, the results of our own checks on the published link (whether it still opens, and whether it came down before the agreed minimum period), any invoice or credit note, the conversation between the two parties, or any file either of them uploaded. The link reaches that one report and nothing else — it is not a way into either party's account.

Anyone holding the link can open the report without a Dinky account, and we cannot control who the link is forwarded to afterwards. The link carries a random, unguessable token rather than an identifier that could be altered to reach another report; the page asks search engines not to index it and does not disclose its own address to the sites it links to. The creator may withdraw the link at any time — replacing or removing it makes every existing copy stop working immediately.

Creating, replacing or removing such a link is the creator's decision, and each of those events is recorded in the history of the collaboration, which the advertiser can read. If you are an advertiser and would prefer that a report about your campaign not be shared in this way, tell the creator, or write to us at dev@dinky.cc.

Legal Requirements

Where required by law, court order, governmental authority, or regulatory request.

Corporate Transactions

In connection with a merger, acquisition, financing, sale of assets, or business restructuring.

8. International Data Transfers

Personal data may be processed outside your country of residence. When transferring data internationally, Dinky implements appropriate safeguards, including Standard Contractual Clauses (SCCs), contractual safeguards, and technical and organizational measures.

9. Data Retention

We retain personal data only as long as necessary for:

  • providing the Service;
  • maintaining platform integrity;
  • complying with legal obligations;
  • resolving disputes;
  • enforcing agreements.

Retention periods may vary depending on the type of information and applicable legal requirements. In particular, advertiser booking requests that were declined or expired are deleted 24 months after closure; accepted requests and the resulting bookings are retained for as long as necessary for contractual and accounting purposes (section 3). Tracking link click records (section 3.7) are likewise deleted 24 months after the click. The sign-up, sign-in and password-reset security records described in section 3.9 are deleted 30 days after the attempt.

10. Security

Dinky implements commercially reasonable technical and organizational measures designed to protect personal data. These measures may include encryption, access controls, secure authentication, monitoring systems, and infrastructure security controls. However, no system can guarantee absolute security.

11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • access your personal data;
  • correct inaccurate information;
  • request deletion of personal data;
  • restrict processing;
  • object to processing;
  • withdraw consent;
  • request portability of your data;
  • lodge a complaint with a supervisory authority.

Requests may be submitted to dev@dinky.cc.

12. Account Deletion

Users may request deletion of their account and personal data by contacting dev@dinky.cc. Dinky may retain certain information where required by law, contractual obligations, fraud prevention requirements, or legitimate business interests.

13. Children

Dinky is intended for users aged 18 years or older. Users under the age of 18 may use the Service only with the involvement, supervision, and consent of a parent or legal guardian, where permitted by applicable law. If we become aware that personal information has been collected without appropriate authorization, we may take steps to remove such information.

14. Third-Party Services

The Service may contain links to third-party websites, services, applications, or content. Dinky is not responsible for the privacy practices of third parties. Users should review the privacy policies of those third parties separately.

15. Changes to This Policy

We may modify this Privacy Policy from time to time. Updated versions will be published on https://dinky.cc/privacy. Changes become effective upon publication unless otherwise specified.

16. Contact

For questions, requests, complaints, or privacy-related inquiries:

dev@dinky.cc
DINKY SAS
69 Rue de Paris, 92110 Clichy, France
Website: https://dinky.cc