TinyPages Data Processing Agreement
Last Updated: October 4, 2026
This Data Processing Agreement ("DPA") applies whenever you use TinyPages to collect, store or send personal data belonging to your own contacts, students and customers. It forms part of our Terms of Service and is accepted when you create your account. If any term here conflicts with the Terms of Service, this DPA prevails for anything concerning personal data.
Who is who
You are the controller: the data belongs to your audience, you decide what to collect and why. TinyPages is the processor: we store and process that data on your behalf, to run the service you asked for.
TinyPages is operated by Tiny Platforms Limited, Flat/Rm 1305, 13/F, Hollywood Centre, 233 Hollywood Road, Sheung Wan, Hong Kong S.A.R. You can reach us at hello@tinypages.co.
What we do with your data, and what we never do
We process your contacts' personal data only to provide the service: hosting your pages and site, managing your contact list, sending your emails, selling your products, running your member area and courses, collecting form responses and producing your statistics. Using the service is your documented instruction to do so.
We never use your contacts' data for our own purposes. We do not sell it, we do not share it with another creator, and we do not use it to train artificial intelligence models. If an instruction from you appears to breach data protection law, we will tell you.
This agreement lasts as long as your account does, and ends with it.
Confidentiality and security
Everyone with access to personal data on our side is bound by confidentiality. Data is encrypted in transit over HTTPS on every domain we serve, and encrypted at rest by our infrastructure providers. Each creator's data is isolated at the database level by row-level security policies, so one creator can never read another's. Sign-in uses a one-time code sent by email or an identity provider, never a stored password, and dashboard sessions are scoped so they cannot be reached from a creator site. Application errors and email deliveries are logged so we can investigate incidents.
Sub-processors
You give us general authorisation to use the sub-processors listed at the end of this document. Each one is engaged under data protection obligations no less protective than those set out here. We will tell you at least 30 days before adding or replacing one, by email or by updating this page, and you may object on reasonable grounds.
Tools you connect yourself — a Meta pixel, Google Analytics, Zapier, Make, custom code — are not our sub-processors. You are responsible for them and must declare them on your own side.
Your contacts' rights
Your dashboard lets you read, correct, export and delete your contacts' data yourself, which covers most requests without needing us. Where you do need help, we assist you as far as we reasonably can. If one of your contacts writes to us directly, we forward the request to you rather than answering it ourselves.
Data breaches
If personal data you entrusted to us is breached, we notify you without undue delay and in any case within 48 hours of becoming aware of it, with what we know at that point: what happened, which categories of people and records are affected and roughly how many, the likely consequences, and the measures we have taken.
Deletion
When you delete your account, your data and your contacts' data are erased from our production database immediately. There is no recycle bin and no retention period, so export anything you want to keep before you delete. Copies held in routine database backups are overwritten within 8 days.
Audits
We will give you the information you need to show that this agreement is being respected, and we accept one audit per year on reasonable notice, carried out in a way that preserves the confidentiality of our infrastructure and of other creators' data.
International transfers
Our servers are in the United States and our company is established in Hong Kong, so your contacts' data leaves the European Economic Area. Those transfers are governed by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), which are incorporated into this DPA by reference and accepted together with it. The official text is published at eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
For the purposes of those Clauses, you are the data exporter and Tiny Platforms Limited is the data importer. The optional docking clause applies, the audit period is one year, and the Clauses are governed by the law of the EU Member State in which you are established.
Annex I — What is processed
Data subjects. Your contacts, prospects, students and customers: anyone who fills in one of your forms, joins your email list, or buys one of your products.
Categories of personal data. Identification details (first and last name, email address, phone number, country). Student account data (sign-in identifier, sign-in history, course progress, comments left on lessons). Purchase data (products bought, amount, quantity, currency, coupon used, refund status, Stripe or PayPal transaction references). Invoicing data (name, billing address, country, VAT rate and amount, invoice number and PDF). Email data (subscription and unsubscribe status, opens, clicks, deliverability, bounces). Form responses, including free-text answers written by the respondent. Audience measurement (page views, A/B variant served, an anonymous visitor identifier). Tags and segmentation you apply yourself, and total amount spent.
No payment card data. Card numbers are entered directly with Stripe or PayPal and never reach TinyPages servers.
Special categories. The service asks for none. You agree not to collect health data, political, religious or trade-union opinions, biometric data or data about sexual life through free-text fields.
Purpose and frequency. Providing the service, continuously, for as long as your account exists.
Annex II — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States (Virginia) |
| Vercel | Hosting of the application and of creator sites | United States |
| Railway | API, background jobs, self-hosted audience measurement | United States (Virginia) |
| Postmark (ActiveCampaign) | Sending your emails and transactional emails | United States |
| Resend | Subscription billing emails | United States |
| Cloudflare Stream | Video hosting and delivery | Global network |
| Stripe | Payments, subscriptions, payouts | United States, Ireland |
| PayPal | Payments, where you enable it | United States, Luxembourg |
| PostHog | Application error tracking and product events | European Union |
| Upstash | Job queue, cache, AI assistant vector index | United States (Virginia) |
| OpenRouter | AI text generation, at your request | United States |
| OpenAI | AI text and embeddings, at your request | United States |
| Airwallex | Affiliate commission payouts | Hong Kong, Singapore |
| Arcjet | Abuse protection on sensitive endpoints | United States |
Questions
Write to hello@tinypages.co. If you need this agreement signed on paper, say so and we will send you a copy.