Privacy Policy

Effective

This Privacy Policy explains how serial.link handles personal data on its marketing website and author platform. It also explains the limited circumstances in which serial.link processes reader data for authors.

1. Who is responsible for your data?

The controller for the activities described in this Policy is:

MALATRAIT HUGO, entrepreneur individuel
SIREN 892852989 — SIRET 89285298900011
7 rue du Collège d’Annecy, 84000 Avignon, France
contact@serial.link

In this Policy, “serial.link,” “we,” “us,” and “our” refer to this operator.

For personal data collected on an author’s reader-facing storefront, the author generally decides why and how that data is used and is the controller. serial.link processes that data for the author as a processor. Readers should also read the privacy notice provided by the relevant author.

2. Scope

This Policy covers:

  • visits to the serial.link marketing website;
  • the serial.link waitlist;
  • author account creation and use of the author dashboard;
  • author billing and connected payment-account administration;
  • support, security, and legal compliance; and
  • reader data processed by serial.link to provide author storefronts.

It does not replace an author’s own storefront privacy notice or the privacy policies of third-party services.

3. Data we collect and why

Marketing website and waitlist

When you join the waitlist, Serial.link records your email address, where you joined, and the time and version of your consent. We use Resend to manage waitlist delivery and your unsubscribe preference. You can unsubscribe at any time.

Cloudflare Turnstile checks waitlist submissions for automated abuse. Serial.link does not retain your IP address or Turnstile token in the waitlist database. Learn how Cloudflare processes verification data in its Turnstile Privacy Addendum.

We use waitlist data to send requested launch and product updates. The legal basis is your consent. Withdrawing consent does not affect processing that occurred before withdrawal.

The website and infrastructure may also process request information such as IP address, browser or device details, requested URL, timestamps, and security signals to deliver the site, prevent abuse, and diagnose incidents. Our legal basis is our legitimate interest in operating a secure and reliable service.

Author accounts and authentication

We process an author’s name where provided, email address, email-verification status, profile image where provided, account identifiers, timestamps, session tokens, sign-in IP address and user agent, short-lived email verification records, and authentication-provider records needed to operate passwordless sign-in.

We use this data to create and secure accounts, authenticate users, prevent abuse, provide support, and maintain account history. The legal bases are performance of the Terms, steps requested before entering the Terms, our legitimate security interests, and compliance with legal obligations where applicable.

When a new author accepts the Terms, we record the accepted Terms version and a server-generated acceptance timestamp to prove the contract.

Author platform, content, and sites

We process information authors provide or generate while using the Service, including:

  • author profiles and pen-name information;
  • site names, subdomains, branding, themes, navigation, search metadata, and access settings;
  • novels, chapters, publication settings, cover images, uploaded media, and content;
  • membership tiers, benefit descriptions, publishing and access rules;
  • onboarding progress, preferences, and support communications; and
  • operational timestamps, identifiers, logs, and error information.

We use this data to provide, maintain, secure, troubleshoot, and improve the Service and to publish material according to the author’s instructions. The main legal basis is performance of the Terms. Security and proportionate product-improvement work may also rely on our legitimate interests.

Author billing and payment connections

For the author’s serial.link subscription, we process Polar customer and subscription identifiers, plan or product references, subscription status and dates, billing-reconciliation timestamps, and related support records. Polar acts as merchant of record and independently processes payment, invoice, tax, and billing details under its own privacy information.

For reader memberships, we process the author’s Stripe connected-account identifier, connection and capability status, and limited configuration identifiers needed to enable reader billing. Stripe independently processes payment credentials and payment-account compliance information under its own privacy information.

We use these records to provide paid features, confirm entitlements, connect payouts, prevent fraud, keep financial records, and handle billing support. The legal bases are performance of the Terms, our legitimate interests in preventing fraud and reconciling service access, and legal obligations.

Reader data processed for authors

Depending on an author’s configuration and a reader’s actions, serial.link may process reader email address, name or nickname, email-verification status, authentication and session data, follows and preferences, membership and entitlement status, subscription and charge references, billing country, Stripe customer or subscription identifiers, cancellation information, and support or transactional records.

For this data, the author is generally the controller and serial.link is the processor. We use the data only to host the storefront, authenticate readers, deliver follows and membership access, administer subscription status, send author-requested transactional communications, provide support, prevent abuse, and follow the author’s lawful instructions. Our Terms of Service include the applicable Data Processing Addendum.

We may separately process limited security and legal records as a controller where necessary to protect the Service, establish legal claims, or comply with law.

Communications

If you contact us, we process your contact details, message, attachments, and related correspondence to answer you, provide support, and keep an appropriate record. The legal basis is performance of the Terms or steps you request, our legitimate interest in providing support, or a legal obligation depending on the request.

4. Where data comes from

We receive personal data:

  • directly from you when you join the waitlist, create an account, configure a site, upload content, or contact us;
  • automatically from your browser, device, and use of the Service;
  • from authors when they configure storefronts and reader services;
  • from readers when they sign in, follow, subscribe, or manage a membership; and
  • from providers such as Cloudflare, Resend, Polar, and Stripe when they return verification, delivery, security, subscription, or payment-status information.

5. Required and optional data

Fields marked as required, authentication data, and information needed for billing or legal compliance must be provided for the relevant feature. If you do not provide them, we may be unable to create an account, secure access, publish a site, or provide paid features. Optional profile, branding, and content fields can be left blank unless a feature says otherwise.

6. Cookies and browser storage

serial.link uses strictly necessary cookies and similar storage to keep users signed in, protect sessions, carry an email and invite information between passwordless sign-in steps, remember onboarding work, and operate requested features. Security providers such as Cloudflare may use necessary cookies or device signals for abuse prevention.

We do not currently use advertising cookies, behavioural advertising, or a third-party analytics SDK. If this changes, we will update this Policy and request consent where required.

You can block browser storage in your browser, but authentication and other essential features may stop working.

7. Who receives data

We disclose data only as needed for the purposes above, including to:

  • Cloudflare — static-site and Worker hosting, content delivery, object storage, networking, security, logs, and Turnstile abuse prevention;
  • PlanetScale — managed PostgreSQL database infrastructure;
  • Resend — passwordless and transactional email delivery, waitlist contacts, mailing preferences, and unsubscribe handling;
  • Polar — merchant-of-record billing for author subscriptions;
  • Stripe — connected accounts and reader membership payments;
  • professional advisers, insurers, auditors, or contractors subject to appropriate confidentiality obligations; and
  • public authorities, courts, or other parties where disclosure is legally required or reasonably necessary to protect rights, safety, and the Service.

We may transfer relevant data if the Service or operating business is reorganised or transferred, subject to appropriate confidentiality and notice obligations.

We do not sell personal data or share it for cross-context behavioural advertising.

8. International transfers

Some providers operate in the United States or other countries outside the European Economic Area. Where the GDPR requires a transfer safeguard, we rely on an applicable adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful mechanism, together with supplementary measures where appropriate.

You may contact us for information about the safeguard applicable to a particular transfer.

9. Retention

We keep personal data only as long as reasonably necessary for the relevant purpose:

  • Waitlist: up to three years after your latest interaction with us, unless you withdraw consent sooner or we must retain a limited suppression record to respect an unsubscribe.
  • Author account and content: while the account and contractual relationship are active.
  • Account closure: we aim to remove active account data and hosted content within 30 days after a verified closure request. Backup copies expire within 90 days.
  • Authentication and security records: for short operational periods appropriate to fraud prevention, incident investigation, and account security. One-time verification records expire after their configured validity period.
  • Support and contract records: for the time needed to handle the request and establish, exercise, or defend legal claims.
  • Billing, tax, and accounting records: for periods required by applicable law, which may be up to ten years for certain accounting records.
  • Reader data processed for an author: while needed to provide that author’s Service and according to the author’s instructions, followed by the same active-system and backup deletion periods, unless law requires retention.

Deletion from backups may occur by expiry rather than immediate erasure. We may retain a minimal record where necessary to document consent withdrawal, enforce security, resolve disputes, or comply with law. Data is then isolated from ordinary use and deleted or anonymised when the obligation ends.

10. Security

We use technical and organisational safeguards appropriate to the nature and risk of the data, including managed infrastructure protections, encryption in transit, access controls, passwordless authentication controls, rate limits, abuse detection, restricted secrets, logging, and backups.

No online service can guarantee absolute security. Please protect access to your email and devices and notify contact@serial.link promptly if you suspect unauthorised activity.

11. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • access your personal data and receive a copy;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict or object to processing;
  • receive data you provided in a portable format where applicable;
  • withdraw consent at any time; and
  • give instructions concerning certain uses of your data after death where French law applies.

To exercise a right relating to serial.link’s own processing, email contact@serial.link. We may need to verify your identity and will normally respond within one month, subject to lawful extensions.

For data held through an author’s storefront, contact the author first because the author is generally the controller. We will assist the author with a valid request.

You may complain to the Commission nationale de l’informatique et des libertés (CNIL) or another competent supervisory authority. We would appreciate the chance to address your concern first, but that is not a condition of complaining.

12. Automated decisions

serial.link does not currently make decisions producing legal or similarly significant effects solely by automated processing, and does not profile people for advertising. Automated security signals may rate-limit or challenge suspicious requests; you can contact us if you believe a security control affected you incorrectly.

13. Age

Author accounts are for people aged 18 or older. The author platform is not directed to children. Authors are responsible for the audience rules, notices, and age controls applicable to their own storefront content and reader relationships.

If you believe a child has improperly provided personal data directly to serial.link, contact us so we can investigate and take appropriate action.

14. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will publish the current version and effective date here and give appropriate notice of material changes. If a change requires consent, we will ask for it.

15. Contact

For privacy questions, requests, or complaints, contact:

Hugo Malatrait
contact@serial.link
7 rue du Collège d’Annecy, 84000 Avignon, France