Privacy policy

Last updated 2026-09-23

Teasers is a link-in-bio service at tease.rs, operated by Teasers. This policy explains what we collect, why, and what you can do about it. It covers two kinds of people: account holders who build pages, and visitors to those pages.

1. Account holders

When you create an account or are invited to an organisation we store:

  • Your email address. It is your only sign-in identity; we do not store passwords.
  • One-time sign-in codes, kept in hashed form and valid for minutes, and the sessions they open. A session lasts 30 days and records the IP address and browser it was opened from, so you can recognise it.
  • Your organisations, your role in each, and a log of administrative actions taken there.
  • Everything you put on your pages: names, text, links, images and videos. Uploads are stored in object storage in Frankfurt, Germany, and are public by design once the page is published.
  • Custom domains you connect. The hostname is submitted to a certificate authority (Let’s Encrypt) so it can be served over HTTPS.

We use this to run the service, to email you sign-in codes and invitations, and to answer support requests. We do not sell it and we do not use it for advertising.

2. Visitors to pages

Page owners see how their page performs. To provide that, when you open a page or tap a link on it we record:

  • The page and link, the time, the referring site, and any campaign parameters (utm_*) in the address you arrived from.
  • A coarse device class (phone, tablet, desktop), whether the page opened inside a social app’s browser, and the country derived from network headers.
  • A visitor token used only to count unique visitors. It is a one-way hash of your IP address and browser identifier mixed with a secret that changes daily, so the same person is counted once per day and cannot be recognised across days or across pages of different owners. Your IP address itself is not stored with page analytics.

Raw events are folded into daily totals and deleted after 90 days. There are no advertising trackers or third-party analytics scripts on pages.

Forms on pages

Some pages ask for your email or social handle. What you submit is stored for the owner of that page, together with the country it came from, and shown to them in their dashboard. The page owner decides how it is used and is responsible for it; we process it on their behalf. Contact the page owner to have it removed, or contact us if you cannot reach them.

3. Cookies and local storage

  • Session cookie (account holders): keeps you signed in for up to 30 days.
  • Theme (account holders): remembers light or dark mode.
  • Campaign attribution (visitors): when you arrive at a page through a link with campaign parameters, a cookie remembers that first source for 30 days so a later tap is credited to the right campaign.
  • Experiment variant (visitors): when a page owner is testing two versions of a page, a cookie keeps you on the same version for 30 days.
  • Countdown timers(visitors): a page’s per-visitor countdown stores its end time in your browser so it does not restart on every visit.

None of these are used to track you across other websites.

4. Who else processes data

We rely on a small number of providers, each bound by their own data-processing terms:

  • DigitalOcean (Frankfurt, Germany): servers, database and file storage.
  • Resend: delivery of sign-in codes and invitation emails.
  • Let’s Encrypt: TLS certificates for custom domains.
  • Cloudflare: DNS for tease.rs.

Data is stored in the European Union. Providers outside it receive only what the service they perform requires, for example an email address for an email.

5. Retention

  • Account and page data: as long as the organisation exists. Deleting an organisation deletes its sites, pages, uploads, leads and analytics.
  • Sessions: 30 days, or until you sign out.
  • Raw analytics events: 90 days. Daily totals are kept with the page.
  • Leads submitted through forms: until the page owner deletes them or the organisation is deleted.

6. Your rights

You can access, correct, export or delete your data. Account holders can export an organisation’s data and delete it from the organisation settings. For anything else, including requests under the GDPR or similar laws, email login@tease.rs. If you are in the EU or EEA you may also complain to your local data-protection authority.

7. Children

The service is not directed at children under 16 and we do not knowingly collect their data.

8. Changes

We will update this page when the service changes what it collects. The date at the top tells you when. Significant changes are announced to account holders by email.

9. Contact

Teasers · login@tease.rs