TinyPages Data Processing Agreement

Last Updated: October 4, 2026

This Data Processing Agreement ("DPA") applies whenever you use TinyPages to collect, store or send personal data belonging to your own contacts, students and customers. It forms part of our Terms of Service and is accepted when you create your account. If any term here conflicts with the Terms of Service, this DPA prevails for anything concerning personal data.

Who is who

You are the controller: the data belongs to your audience, you decide what to collect and why. TinyPages is the processor: we store and process that data on your behalf, to run the service you asked for.

TinyPages is operated by Tiny Platforms Limited, Flat/Rm 1305, 13/F, Hollywood Centre, 233 Hollywood Road, Sheung Wan, Hong Kong S.A.R. You can reach us at hello@tinypages.co.

What we do with your data, and what we never do

We process your contacts' personal data only to provide the service: hosting your pages and site, managing your contact list, sending your emails, selling your products, running your member area and courses, collecting form responses and producing your statistics. Using the service is your documented instruction to do so.

We never use your contacts' data for our own purposes. We do not sell it, we do not share it with another creator, and we do not use it to train artificial intelligence models. If an instruction from you appears to breach data protection law, we will tell you.

This agreement lasts as long as your account does, and ends with it.

Confidentiality and security

Everyone with access to personal data on our side is bound by confidentiality. Data is encrypted in transit over HTTPS on every domain we serve, and encrypted at rest by our infrastructure providers. Each creator's data is isolated at the database level by row-level security policies, so one creator can never read another's. Sign-in uses a one-time code sent by email or an identity provider, never a stored password, and dashboard sessions are scoped so they cannot be reached from a creator site. Application errors and email deliveries are logged so we can investigate incidents.

Sub-processors

You give us general authorisation to use the sub-processors listed at the end of this document. Each one is engaged under data protection obligations no less protective than those set out here. We will tell you at least 30 days before adding or replacing one, by email or by updating this page, and you may object on reasonable grounds.

Tools you connect yourself — a Meta pixel, Google Analytics, Zapier, Make, custom code — are not our sub-processors. You are responsible for them and must declare them on your own side.

Your contacts' rights

Your dashboard lets you read, correct, export and delete your contacts' data yourself, which covers most requests without needing us. Where you do need help, we assist you as far as we reasonably can. If one of your contacts writes to us directly, we forward the request to you rather than answering it ourselves.

Data breaches

If personal data you entrusted to us is breached, we notify you without undue delay and in any case within 48 hours of becoming aware of it, with what we know at that point: what happened, which categories of people and records are affected and roughly how many, the likely consequences, and the measures we have taken.

Deletion

When you delete your account, your data and your contacts' data are erased from our production database immediately. There is no recycle bin and no retention period, so export anything you want to keep before you delete. Copies held in routine database backups are overwritten within 8 days.

Audits

We will give you the information you need to show that this agreement is being respected, and we accept one audit per year on reasonable notice, carried out in a way that preserves the confidentiality of our infrastructure and of other creators' data.

International transfers

Our servers are in the United States and our company is established in Hong Kong, so your contacts' data leaves the European Economic Area. Those transfers are governed by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), which are incorporated into this DPA by reference and accepted together with it. The official text is published at eur-lex.europa.eu/eli/dec_impl/2021/914/oj.

For the purposes of those Clauses, you are the data exporter and Tiny Platforms Limited is the data importer. The optional docking clause applies, the audit period is one year, and the Clauses are governed by the law of the EU Member State in which you are established.

Annex I — What is processed

Data subjects. Your contacts, prospects, students and customers: anyone who fills in one of your forms, joins your email list, or buys one of your products.

Categories of personal data. Identification details (first and last name, email address, phone number, country). Student account data (sign-in identifier, sign-in history, course progress, comments left on lessons). Purchase data (products bought, amount, quantity, currency, coupon used, refund status, Stripe or PayPal transaction references). Invoicing data (name, billing address, country, VAT rate and amount, invoice number and PDF). Email data (subscription and unsubscribe status, opens, clicks, deliverability, bounces). Form responses, including free-text answers written by the respondent. Audience measurement (page views, A/B variant served, an anonymous visitor identifier). Tags and segmentation you apply yourself, and total amount spent.

No payment card data. Card numbers are entered directly with Stripe or PayPal and never reach TinyPages servers.

Special categories. The service asks for none. You agree not to collect health data, political, religious or trade-union opinions, biometric data or data about sexual life through free-text fields.

Purpose and frequency. Providing the service, continuously, for as long as your account exists.

Annex II — Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageUnited States (Virginia)
VercelHosting of the application and of creator sitesUnited States
RailwayAPI, background jobs, self-hosted audience measurementUnited States (Virginia)
Postmark (ActiveCampaign)Sending your emails and transactional emailsUnited States
ResendSubscription billing emailsUnited States
Cloudflare StreamVideo hosting and deliveryGlobal network
StripePayments, subscriptions, payoutsUnited States, Ireland
PayPalPayments, where you enable itUnited States, Luxembourg
PostHogApplication error tracking and product eventsEuropean Union
UpstashJob queue, cache, AI assistant vector indexUnited States (Virginia)
OpenRouterAI text generation, at your requestUnited States
OpenAIAI text and embeddings, at your requestUnited States
AirwallexAffiliate commission payoutsHong Kong, Singapore
ArcjetAbuse protection on sensitive endpointsUnited States

Questions

Write to hello@tinypages.co. If you need this agreement signed on paper, say so and we will send you a copy.