Skip to main content
Legal

Privacy Policy

Last updated: 3 September 2026

This policy explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. It is written to be read — if anything in it is unclear, ask us and we will explain.

1. Who is responsible for your data

The controller for the processing described here is Joinly. Full company details are on our Imprint page.

For anything in this policy — including exercising the rights described in section 9 — write to TODO. We answer within one month, and will tell you if we need longer (which we may do once, by two further months, for complex requests).

We have not appointed a Data Protection Officer. We are not required to: we are not a public authority, our core activity is not large-scale systematic monitoring of individuals, and we do not process special categories of data on a large scale. If that changes we will appoint one and publish the contact details here.

2. Who this policy covers

This policy covers three groups of people, and not all of it applies to everyone:

  • Visitors to our website, who have not signed up for anything.
  • Creators — people who open a Joinly account to sell access to a community they run.
  • Subscribers — people who buy access to a creator's community through our checkout. Most of what we hold about you is described in sections 3 and 4; note in particular section 5, which explains where we got it, because you may never have visited our site.

3. What we collect, why, and on what legal basis

Article 6(1) GDPR requires a lawful basis for every purpose. Ours are set out below purpose by purpose. Where we rely on a contract, providing the data is necessary to enter into or perform that contract, and we cannot provide the Service without it. Where we rely on a legal obligation, we have no choice about keeping the data. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

  • Account data (name, email address, password hash, and the login provider you used, if any) — to create and operate your account and authenticate you. Basis: performance of a contract, Art. 6(1)(b).
  • Creator profile data (public display name, bio, page slug, avatar, social links) — to publish your public creator page. Basis: performance of a contract, Art. 6(1)(b). Anything you put on a public page is, by design, visible to everyone.
  • Product and subscription data (the products you create, subscription status, billing period, price, currency) — to run the sale and manage access. Basis: performance of a contract, Art. 6(1)(b).
  • Subscriber contact and platform identifiers (email address, and as applicable a Telegram user id, Discord user id, Slack user id, or WhatsApp participant identifier, which is a phone number) — to grant access when payment succeeds and withdraw it when the subscription ends. Basis: performance of a contract, Art. 6(1)(b).
  • Community identifiers (Telegram group id, Discord server and role ids, WhatsApp group id, Slack workspace and channel ids) — to target the right community. Basis: performance of a contract, Art. 6(1)(b).
  • WhatsApp session credentials, where a creator connects WhatsApp — to keep the connected account linked so members can be added and removed. Basis: performance of a contract, Art. 6(1)(b), together with the creator's separate acknowledgement of the risks (see section 8). Stored on infrastructure we control in the European Union and deleted when WhatsApp is disconnected.
  • Consent records (which cookie categories you chose, when, and against which policy version; the declarations you made at checkout) — to prove we obtained consent and that the withdrawal-right information was given. Basis: legal obligation, Art. 6(1)(c), read with Art. 7(1).
  • Payment and tax records (invoice data, amounts, tax treatment, billing country, tax identifiers) — to charge the correct tax and to keep the books. Basis: legal obligation, Art. 6(1)(c) — US federal and state tax law, which binds us as the country of our establishment, and the EU VAT rules for electronically supplied services, under which we report through the non-Union One Stop Shop.
  • Security and operational logs (IP address, user agent, timestamps, error details) — to keep accounts secure, investigate abuse and fix faults. Basis: legitimate interests, Art. 6(1)(f), being our interest and yours in a service that is not broken into or broken. We keep these short-lived and do not use them to build profiles.
  • Support correspondence, including the name, email address and messages you give us in the chat window on the site — to answer you, which we do by email. You can use the chat without an account, in which case what you type there is all we hold about you, and we store nothing in your browser. Basis: legitimate interests, Art. 6(1)(f) — answering someone who has written to us — or performance of a contract where it concerns your subscription.
  • Analytics, the optional third-party support chat, and affiliate attribution — see section 7. Basis: consent, Art. 6(1)(a), and none of it runs unless you say yes. Our own support chat is not in this group: it is part of the service and is covered by the entry above.

4. Payments

Payments are processed by Stripe. Card numbers are collected and stored by Stripe on its own PCI-DSS certified systems and never reach us — we cannot see them and do not store them. We receive the buyer's email address, the billing country and tax identifiers needed to charge VAT correctly, the amount, and the status of the payment or subscription.

When you buy access to a community, the contract for that purchase is with us as the seller, and we account for the VAT. The creator whose community you are joining supplies the content to us. This matters for you in one practical way: your invoice, your refund rights and your complaint route are all with us, at the contact address in section 1.

5. Where subscriber data comes from

If you subscribed to a creator's community, some of what we hold did not come from you directly, and Article 14 GDPR requires us to say so.

Your email address and payment status reach us from Stripe when your payment succeeds. Your platform identifier — your Telegram or Discord or Slack user id, or the phone number your WhatsApp account uses — reaches us either from you at checkout (Discord) or from the platform itself when you join the community using the invite we issued. We use it for exactly one thing: knowing whom to remove when the subscription ends.

We do not buy personal data, we do not enrich it from third-party sources, and we do not sell it.

6. Who we share data with

We do not sell personal data and we do not share it for anyone else's marketing. We use the following processors and recipients, each under a written data processing agreement where they act on our instructions:

  • Stripe Payments Europe, Ltd. (Ireland) — payment processing, subscription billing, VAT calculation and payouts. Acts as an independent controller for parts of this.
  • Supabase (EU region) — the database in which the Service's data is stored.
  • Netlify, Inc. (USA) — application hosting and content delivery.
  • Resend — transactional email delivery (access links, receipts, password resets).
  • PostHog (EU region) — product analytics. Only if you consented to analytics cookies.
  • Crisp IM SAS (France) — support chat. Only if you consented to functional cookies.
  • Rewardful — affiliate attribution for our own plan sales. Only if you consented to marketing cookies.
  • Telegram, Discord, Slack and Meta (WhatsApp) — we send the identifier needed to add or remove you from the community you paid for. Their own terms and privacy policies govern what they then do with it.
  • Our own self-hosted WhatsApp gateway, running on infrastructure we control in the European Union.
  • Professional advisers, and public authorities where the law requires it or where it is necessary to establish, exercise or defend legal claims.

7. Cookies and similar technologies

We set strictly necessary cookies — those that keep you signed in, secure a payment, remember your language, and store your cookie choice itself — without asking, because the Service cannot work without them.

Everything else is off until you switch it on. Analytics, the support chat widget and affiliate attribution load only after you consent, and we do not treat scrolling, continued browsing or silence as consent. You can change or withdraw your choice at any time using the Cookie settings link in the footer of every page; withdrawing is as easy as giving.

Every cookie we can set is listed individually — name, provider, purpose and duration — in the Cookie Policy.

8. WhatsApp connections

WhatsApp offers no official API for managing group membership, so our WhatsApp support works by linking a WhatsApp Web session to a gateway we host in the EU. Creators must acknowledge the risks of this before connecting, and we record when they did.

There is a privacy consequence creators should understand: a linked session is a linked account, not a linked group. Technically the gateway holds credentials capable of reaching that account's chats and contacts, not only the groups you sell access to. We use it solely to list your groups, rotate invite codes and add or remove members, and we access nothing else — but if that scope is more than you are comfortable with, connect a dedicated number rather than your personal one, or use one of the other platforms.

If you are a member of a WhatsApp group a creator manages through Joinly, the gateway can see the phone numbers of the group's participants, including participants who never bought anything. We store a participant's number only where it is needed to match them to a paid membership, and we delete it when that membership record is deleted.

9. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • Access — obtain confirmation of whether we process your data, a copy of it, and the information in this policy.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where one of the grounds in Art. 17 applies. Note the limit in section 13: we cannot delete invoices and accounting records before their statutory retention period expires, and we will tell you when that applies.
  • Restriction — have processing limited while, for example, a dispute about accuracy is resolved.
  • Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. Account holders can export this themselves from Settings.
  • Object — object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. We will stop unless we can show compelling legitimate grounds that override your interests.
  • Withdraw consent — for anything based on consent (cookies, analytics, chat, affiliate attribution), at any time, without affecting the lawfulness of what was done before.

10. How to exercise your rights, and how to complain

Account holders can update most of their data in Settings, export it from Settings, and delete their account there. For anything else, or if you are a subscriber without an account, write to TODO. We do not charge for this, and we will not ask you for more identifying information than we need to be sure it is really you.

We do not use automated decision-making producing legal or similarly significant effects, and we do not profile you. Access is granted or withdrawn automatically, but purely as the mechanical result of whether your payment succeeded — there is no assessment of you involved.

If you think we have got this wrong, please tell us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority: the data protection supervisory authority of the EU or EEA state where you live, where you work, or where the problem happened — the full list is at https://edpb.europa.eu/about-edpb/board/members_en. You may also bring proceedings before the competent court.

11. If you are in the United States

We are established in the United States, and most US states now have their own comprehensive privacy law — California's CCPA as amended by the CPRA, and the equivalents in Colorado, Connecticut, Virginia, Texas, Oregon and the rest. Rather than run a different policy per state, we give everyone the rights below wherever they live, and the GDPR rights in section 9 are the same rights under different names.

Two points those laws require us to state plainly. First: we do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months. Second: we do not use or disclose sensitive personal information for any purpose beyond what is needed to provide the service you asked for, so there is nothing for a “limit the use of my sensitive personal information” request to restrict.

The categories of personal information we collect, the sources we get them from, the purposes we use them for, and the recipients we disclose them to are the ones set out in sections 3, 5 and 6 — that listing does double duty as the notice at collection.

  • Know and access — ask what personal information we hold about you, where we got it, why we have it, and who we disclosed it to, and receive a copy.
  • Delete — ask us to delete what we hold, subject to the retention obligations in section 13, which we will identify if they apply to your request.
  • Correct — have inaccurate personal information put right.
  • Portability — receive the information you gave us in a portable, machine-readable format. Account holders can export this themselves from Settings.
  • Opt out of sale, sharing and targeted advertising — there is nothing to opt out of, because we do none of them, but the right stands and we will honour a Global Privacy Control signal as an opt-out request regardless.
  • Opt out of profiling that produces legal or similarly significant effects — we do not carry out any, as section 10 explains.
  • Non-discrimination — we will not deny you the service, charge you a different price, or give you a worse experience because you exercised any of these rights. We run no financial incentive programmes tied to personal information.

12. Making a US privacy request

Write to TODO and say what you want. We acknowledge a request within 10 business days and answer it within 45 days, extending once by a further 45 days where the request is complex — we will tell you if we need to. We verify a request against the account it concerns, and we ask for no more identifying information than that takes.

An authorised agent may make a request for you if they give us written permission signed by you, and we may still contact you to confirm it.

If we refuse a request, we will tell you why. Where your state gives you a right of appeal — Colorado, Connecticut, Virginia, Texas and several others do — reply to our refusal and it goes to someone who was not involved in the original decision; you will have an answer within 45 days, and we will tell you how to complain to your state Attorney General if you are still unhappy.

13. How long we keep data

We keep personal data only as long as we need it, and we delete or anonymise it when we do not:

  • Account and creator profile data — for as long as the account exists, then deleted when you delete the account.
  • Subscription and membership records — while the subscription is active, and for 12 months after it ends so that access disputes and chargebacks can be resolved, then deleted.
  • Invoices, receipts and accounting records — 10 years. Two obligations bite at once and we apply the longer: US federal and state tax law requires us to be able to substantiate what we filed, and Article 63c of Council Implementing Regulation (EU) 282/2011 requires a supplier reporting through the One Stop Shop to keep its records for 10 years from the end of the year of the transaction. This obligation overrides an erasure request; we will restrict the data instead and delete it when the period ends.
  • Cookie consent records — 3 years from the decision, so we can demonstrate what was consented to within the limitation period for a claim.
  • Checkout declarations (Terms acceptance and the withdrawal-right acknowledgements) — 6 years, which covers the general limitation period for a contract claim in the countries we sell into, since they are the evidence behind a contract.
  • Waitlist email addresses — 12 months from signup, or until you ask us to remove you, whichever is first.
  • Renewal reminder records — 90 days after the charge they covered. We keep a note of each reminder we send so you are never emailed twice about the same charge; once that charge has settled the note has no further purpose.
  • Security and error logs — 90 days, unless a specific incident requires keeping a record longer.
  • Illegal-content notices and moderation records — 3 years, to meet our reporting duties under the Digital Services Act.
  • Support conversations, including any you start without an account — 2 years after the last message in the conversation, so we can pick up a thread you refer back to; deleted sooner if you delete your account.

14. International transfers

Our database, our analytics and our WhatsApp gateway are all hosted in the European Union, and that is deliberate.

We are ourselves established in the United States, so our own staff access to that data is a transfer out of the Union. It rests on the same safeguards as the transfers described below.

Some processing nonetheless involves the United States. Netlify hosts the application and serves it through a global content delivery network. Stripe, though contracted through its Irish entity, involves US infrastructure for parts of payment processing. Telegram, Discord, Slack and Meta operate globally, and when we send a platform identifier to add or remove you, it goes wherever that platform operates.

For those transfers we rely on the European Commission's Standard Contractual Clauses, on the EU–US Data Privacy Framework where the recipient is certified under it, and on Article 49(1)(b) where the transfer is necessary to perform the contract you asked us to perform — which is the case when we pass your identifier to the platform hosting the community you bought access to. You can request a copy of the safeguards in place by writing to us.

15. Security

We use technical and organisational measures appropriate to the risk, as Article 32 requires: encryption in transit throughout, encryption at rest for the database and for the platform access tokens we hold, hashed passwords, two-factor authentication and passkey support, strict transport security, a content security policy, rate limiting on authentication endpoints, row-level security in the database, and access limited to the people who need it.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours as Article 33 requires, and we will tell you directly where Article 34 requires it.

16. Children

The Service is not directed at children. You must be at least 16 to create an account or to buy a subscription. Article 8 GDPR lets each member state set its own age between 13 and 16 for a child to consent to information society services, so we apply 16 — the ceiling — everywhere rather than tracking each country's choice. If you believe a child has given us personal data, contact us and we will delete it. In the United States the Children's Online Privacy Protection Act draws the line at 13; our own 16 is higher, so applying it satisfies both.

17. Changes to this policy

When we change this policy we update the version and the date at the top. For changes that materially affect you — a new purpose, a new recipient, a new legal basis — we will tell you in advance by email or in the app, and where the change concerns consent we will ask again rather than assume the old answer still holds.

Questions about your data, or want to exercise a right? TODO. Company details are on the Imprint page, and every cookie we use is listed in the Cookie Policy.

We ask before we track you

We use strictly necessary cookies to run this site — those need no permission. We would also like to use optional cookies for analytics, support chat and affiliate attribution. We only set those if you say yes, and you can change your mind at any time from the footer. Cookie Policy · Privacy Policy