RelaySign in

Last updated 13 August 2026

Privacy Policy

This explains what Relay does with personal data. Relay is a link-in-bio service at relayme.bio, operated by ClearPath Advisory.

1. Who is responsible

ClearPath Advisory
ul. Michała Kleofasa Ogińskiego 11 lok. 9, 03-318 Warszawa, Poland
NIP 9512604332
hello@relayme.bio

We have not appointed a Data Protection Officer, and are not required to, because we do not carry out large-scale monitoring or process special category data as a core activity. Write to the address above with any question about this policy.

2. Two kinds of people

This policy covers two groups, and they are treated differently:

  • Account holders — people who sign up and build a page.
  • Visitors — people who open somebody’s public page at relayme.bio/name.

Where a section applies to only one group, it says so.

3. What we collect from account holders

Your email address. Collected when you sign in. We use passwordless sign-in, so we never receive or store a password.

The content of your page. Your username, display name, bio, links, social handles, chosen theme, fonts and colours, and any profile photo or background image you upload. All of this is content you choose to publish, and it is public by design once your page is live.

Subscription details, if you pay. We store a Stripe customer reference, your plan, its status and its renewal date. We never see or store your card details — those go directly to Stripe and never touch our servers.

4. What we collect from visitors

When someone taps a link on a public page, we record:

  • which link was tapped, and which page it belongs to
  • the time of the tap
  • whether the browser looks like a phone or a computer
  • the referring website address, where the browser supplies one

We do not record IP addresses, device identifiers, names, or anything that identifies a visitor personally. We do not set cookies on visitors, and we do not build profiles, follow people between pages, or share this data with advertisers. Tap counts are shown only to the owner of the page in question.

5. Storage in your browser

Relay stores three things in your browser. None are advertising or analytics trackers, and all three are necessary for the service to work:

  • Your sign-in session — keeps you logged in, until you sign out.
  • relay.pending — holds Pro settings you are trying out, so they survive the trip through checkout. Cleared when applied or discarded.
  • relay.invite.seen — remembers you have dismissed the sign-up prompt, so we do not show it again.

Because these are strictly necessary to provide a service you asked for, they fall within the exemption in Article 5(3) of the ePrivacy Directive and do not require consent. We tell you about them here rather than interrupting you with a banner. Should we ever add analytics or advertising, we will ask first.

6. Why we are allowed to process this

PurposeLegal basis
Running your account and publishing your pageContract, Art. 6(1)(b)
Sending sign-in linksContract, Art. 6(1)(b)
Taking payment and managing subscriptionsContract, Art. 6(1)(b)
Counting taps so page owners can see what worksLegitimate interests, Art. 6(1)(f)
Keeping the service secure and preventing abuseLegitimate interests, Art. 6(1)(f)
Meeting accounting and tax obligationsLegal obligation, Art. 6(1)(c)

Where we rely on legitimate interests we have weighed those interests against your rights. Tap counting records no personal identifier, which is what makes that balance come out the way it does.

7. Who else is involved

We use a small number of processors, each handling data only on our instructions.

ProviderWhat they doWhere
SupabaseDatabase, authentication, file storageEU (Frankfurt)
VercelWebsite hosting and deliveryUS, edge worldwide
StripePayment processingEU and US
ResendSending emailUS

Transfers outside the EEA are covered by the European Commission’s Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework.

Counting a visit. When someone opens a Relay page or taps a link, we record the event so the page’s owner can see how it is doing. To avoid counting the same person over and over, we take a one-way hash of their IP address, keep only the hash, and delete it within a few hours. The address itself is never stored, and the hash cannot be turned back into one.

Fonts are served from our own servers, not from a font network, so loading a Relay page does not reveal your IP address to any third party for typography.

One exception. Where a link’s own website does not publish an icon, we fall back to Google’s favicon service for that small image. Your browser fetches it directly, so Google receives your IP address for that request. It happens only on pages containing such a link, and only for the icon.

8. How long we keep it

  • Account and page data — for as long as your account exists.
  • After you delete your account — removed within 30 days, other than anything we must keep for tax or accounting.
  • Tap records — 24 months, then deleted.
  • Payment records — five years from the end of the relevant tax year, as Polish accounting law requires.

9. Your rights

Under the GDPR you may ask us to:

  • give you a copy of your data (access)
  • correct anything wrong (rectification)
  • delete your data (erasure)
  • pause processing while a dispute is resolved (restriction)
  • hand your data to you or another provider (portability)
  • stop processing based on legitimate interests (objection)

Write to hello@relayme.bio. We reply within one month, at no charge unless a request is clearly unfounded or repetitive.

Most of this you can do yourself. Edit or delete any link, page or image from your dashboard, and delete your whole account from the account panel there.

If we get it wrong, you can complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority where you live or work.

10. Security

Access is enforced at the database level by row-level security, so one account cannot read another’s private data even if the application layer were to fail. Card details never reach our servers. Administrative credentials are used only in server-side code and are never exposed to browsers.

No system is perfect. If a breach occurs that is likely to risk your rights, we will notify the supervisory authority within 72 hours and tell you directly where the risk is high.

11. Children

Relay is not intended for children under 16 and we do not knowingly create accounts for them. If you believe a child has signed up, write to us and we will delete the account.

12. Changes

If we change this policy in a way that affects you, we will email account holders before it takes effect. The date at the top always shows the current version.

Questions about any of this? hello@relayme.bio — a person reads it.

HomeTermsRelay is made by ClearPath Advisory.