Effective date: 3 August 2026
- Controller and contact details
- Scope
- Personal data we collect
- Identity and contact data: name, alias, date of birth or age confirmation, address, country, email, phone number, government identification, selfie or verification result, and social or website identifiers used for verification.
- Account and profile data: username, password hash, authentication records, profile details, settings, followers, subscriptions, account roles, and status.
- Content and communications: posts, media, comments, messages, metadata, reports, complaints, support requests, and records of people depicted in Content where provided.
- Payment and payout data: billing address, card brand, expiry information, partial card number, payment-provider token or identifiers, bank or payout details, tax information, earnings, refunds, disputes, failed payments, and payout requests. Dmlink does not receive the full card number or card security code used in provider-hosted card entry.
- Transaction and risk data: amount, currency, Creator, product or interaction, time, status, authentication result, refund or dispute status, account history, device and location signals, velocity indicators, and payment-provider risk information.
- Technical and usage data: IP address, approximate location derived from IP, browser, device, operating system, referring page, pages and features used, timestamps, logs, cookie or storage identifiers, and diagnostic events.
- Creator business data: creator application, payout method, tax residence, business or management relationship, beneficial ownership information where relevant, payment-provider onboarding status, and compliance records.
- How we obtain data
- Purposes and legal bases
- Provide the service and perform our contract: create and secure accounts, display Content, enable messaging and subscriptions, process transactions, administer Creator Earnings and payouts, provide support, and enforce the Terms.
- Comply with legal obligations: age and identity checks, accounting and tax records, lawful requests, consumer rights, sanctions or financial controls where applicable, safety reporting, and preservation of evidence.
- Our and others' legitimate interests: operate and improve Dmlink, protect users and systems, moderate Content, prevent abuse, secure accounts, investigate complaints, defend legal claims, and conduct payment fraud prevention. We balance these interests against your rights and expectations.
- Consent: use optional cookies or similar technologies and process other data where consent is the appropriate basis. You may withdraw consent prospectively.
- Vital or public interests: protect a person in an emergency or handle serious unlawful activity where applicable law permits or requires it.
- Payments, authentication, and fraud checks
- Identity and age verification
- Cookies and similar technologies
- Sharing personal data
- payment processors, card networks, banks, issuers, payout providers, and fraud-prevention providers;
- identity, age, sanctions, and compliance verification providers;
- hosting, storage, delivery, security, communications, analytics, support, and moderation providers;
- Creators or Users as needed to provide a transaction, interaction, complaint, or safety process;
- professional advisers, auditors, insurers, and financing partners under confidentiality duties;
- a buyer, seller, investor, or successor involved in a genuine corporate transaction; and
- courts, regulators, tax authorities, law enforcement, card schemes, or other parties where required by law or reasonably necessary to protect rights, safety, and the service.
- International transfers
- Retention
- Security
- Your rights
- Complaints
- Changes to this Policy
- Contact
Dmlink ("we", "us", or "our") is the controller for the processing described in this Policy unless another notice says otherwise. The legal entity operating Dmlink and its registered contact details are identified in our Terms of Use.
Privacy questions and requests can be sent to [email protected].
This Policy covers dm.link, Dmlink accounts and features, creator applications and payouts, customer support, our public social-media interactions, and related business communications. A third party processes personal data under its own policy when it independently decides why and how to use that data, including a bank, card issuer, payment provider, identity provider, or linked website.
If you believe we hold information about a minor, contact us promptly.
We obtain data from you, your use of Dmlink, Creators and account managers you interact with, cookies and similar storage, payment and identity providers, fraud-prevention partners, social login providers, service providers, public sources used for verification, and authorities or reporters where lawful.
We and our payment providers use transaction, account, device, location, identity, authentication, velocity, refund, and dispute information for payment fraud prevention, account protection, chargeback management, and compliance. These checks may cause a payment or payout to require 3D Secure or another verification step, enter review, be delayed, or be declined.
Some risk checks are automated. Payment providers and card issuers may make independent authorization or fraud decisions under their own privacy notices. Where a decision is made solely by automated processing and produces legal or similarly significant effects, you may have rights under applicable law to information, human intervention, or challenge. Contact us with the transaction identifier and do not send full card credentials.
We may verify a Creator's identity, age, address, payout eligibility, and ownership or management information before approval and periodically afterward. Providers may compare identification, selfies, database information, and fraud signals and return verification results. We use this information for safety, contract performance, payment access, legal compliance, and fraud prevention.
Dmlink uses cookies, local storage, session storage, pixels, and similar technologies for sign-in, security, preferences, forms, performance, and analytics. The Cookie Policy describes categories, third parties, retention, available controls, and the current notice's limitations. Applicable law may require consent for optional storage; necessary technology is used to provide requested service and security.
We may share the minimum relevant data with:
We do not sell full payment-card credentials. We do not authorize a service provider to use personal data for unrelated purposes merely because it receives data on our behalf.
Providers and recipients may process data outside Sweden, the EEA, or your country. Where required, we use an adequacy decision, standard contractual clauses, another approved transfer mechanism, or a lawful exception, together with supplementary safeguards where appropriate. Contact us for information about the mechanism relevant to your data.
We keep personal data only as long as reasonably necessary for the purpose collected and any legal, tax, accounting, payment-dispute, fraud-prevention, safety, backup, and claims periods. Retention therefore varies by category. Account and Content data may be removed or de-identified after closure, while transaction, verification, complaint, and legal records may be retained longer. We delete, anonymize, or restrict data when the applicable period ends unless another lawful reason requires retention.
We use organizational and technical safeguards appropriate to the nature and risk of the data, including access controls, provider security, logging, authentication, and incident handling. No online service can guarantee absolute security. Protect your credentials and report suspected compromise promptly.
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or an explanation of processing; object to processing based on legitimate interests; withdraw consent; and challenge qualifying automated decisions. Rights may be limited where an exemption applies, another person's rights would be affected, or records must be retained by law.
Send requests to [email protected]. Describe the request and account email. We may verify identity and authority before acting. We do not require unnecessary sensitive documents by ordinary email.
Contact us first if you have a privacy concern. You may also lodge a complaint with the Swedish Authority for Privacy Protection ("IMY") at imy.se or with the competent supervisory authority where you live or work.
We may update this Policy to reflect changes in Dmlink, providers, law, or processing. The current version and effective date are published here. We will provide additional notice of material changes where required.
Dmlink privacy
Email: [email protected]