Privacy Policy
Last updated 17 August 2026.
The short version
We set one cookie, and only once you sign in. There is no Google Analytics, no advertising pixel and no third-party tracker of any kind on this site — which is also why you are not being asked to dismiss a cookie banner.
We never see or store your card number. Stripe handles that. We collect the minimum needed to move money to a creator and email you a receipt, and we do not sell anything about you to anyone, ever.
On this page
1. Who is responsible
tiporsub is operated by Tip or Sub, of Chandler, AZ 85226, United States. For the purposes of the UK and EU GDPR we are the data controller for the personal data described below, except where section 8 says otherwise.
Questions, or want your data deleted? Email privacy@tiporsub.com. A person reads it.
2. If you are a creator
When you sign up and run a page, we hold:
- Your email address — to sign you in, send receipts and password resets, and contact you about your account.
- Your password, hashed — stored using scrypt with a per-account random salt. We cannot read your password and neither can anyone who steals the database.
- Your public profile — handle, display name, tagline, bio, avatar, accent color, what you call your tip unit, your prices and tiers. This is deliberately public: it is your page.
- Your Stripe account identifier — an ID like
acct_…that lets us send you money. We never receive your bank details; those live with Stripe. - Your payment records — amount, fees, date, status and clearing state for every payment made to you.
- Your settings — which notifications you want, whether your page shows supporter counts, and so on.
3. If you are a supporter
You do not need an account, and we ask for very little:
- The payment itself — amount, currency, date, which creator, whether you covered the fees, and a Stripe reference. We need this to pay the creator and to handle refunds.
- Your name and email address, if you give them — optional on a one-off tip. Required for a subscription, because the email is how you manage or cancel it and how we send renewal receipts. If you give them, the creator can see them: that is the point, so they know who supported them.
- Your message, if you write one — shown publicly on the creator's page unless you choose otherwise at checkout. Please do not type anything private into it.
- Whether you agreed to hear from the creator — there is a checkbox at checkout offering occasional updates from that creator. It is ticked by default, and you can untick it before you pay. We record exactly what you chose, and the creator sees that choice next to your name.
We never see your card details. Card number, expiry and security code are entered on Stripe's own checkout page and go straight to Stripe. What comes back to us is a reference and, for subscriptions, a Stripe customer ID — never the card.
4. Everyone who visits
- Your IP address, briefly. It is held in memory to rate-limit sign-up, sign-in and password-reset attempts, which is how we stop people brute-forcing accounts. It is never written into our database, and it is discarded when the limit window ends — at most one hour.
- Web server logs, kept by our server software, containing IP address, the page requested, the time, and your browser's user-agent string. These rotate and are deleted after 14 days. They exist to diagnose faults and detect abuse.
- Email delivery records — for every email we send, we record who it went to, the subject, whether it was accepted, and any error. This is how we can tell you whether your receipt actually arrived.
We do not build a profile of you, we do not track you across other websites, and we have no advertising relationship with anyone.
5. Cookies
One cookie. That is the whole list:
| Name | Purpose | Lifetime | Set when |
|---|---|---|---|
tsid |
Keeps a creator signed in. Contains an account ID and an expiry, signed so it cannot be altered. No personal data is stored inside it. | 30 days | Only after a creator signs in |
It is marked HttpOnly (JavaScript cannot read it), Secure (it
only travels over HTTPS) and SameSite=Lax (it is not sent from other sites).
It is strictly necessary to provide a signed-in session, so it does not require consent —
and since we set nothing else, there is no cookie banner to click through.
Supporters who never sign in are given no cookies at all by us. Stripe's checkout page, which is a different site, sets its own — see Stripe's privacy policy.
6. Why we are allowed to (legal bases)
If the UK or EU GDPR applies to you, these are the bases we rely on:
- Performance of a contract — running a creator's account, taking a payment, sending a receipt, managing a subscription. Without this data there is no service.
- Legitimate interests — keeping the service secure, preventing fraud and card abuse, rate-limiting, diagnosing faults, and keeping basic business records. We have balanced these against your interests and use the least data that works.
- Legal obligation — keeping financial records for tax and anti-money laundering purposes.
- Consent — the "occasional updates" checkbox at checkout, and nothing else. To be clear about who sends what: tiporsub does not send you marketing email at all. That checkbox records permission for the creator to contact you, and they send it from their own tool, with their own unsubscribe link. You can withdraw permission by using that link, by asking the creator, or by emailing privacy@tiporsub.com and we will update the record and tell them.
Note honestly: that checkbox is pre-ticked. Under EU and UK rules a pre-ticked box is not, on its own, valid consent, so if you are in the EU or UK and would rather we did not treat it as consent, tell us at privacy@tiporsub.com and we will remove you and tell the creator. We would rather say this plainly than bury it.
7. Who else sees it
A short list, and no advertisers on it:
- Stripe — our payment processor. They receive the payment details and, where you gave one, your email address so they can attach it to the payment. Stripe is an independent controller of what it collects: see the Stripe Privacy Policy.
- The creator you supported — sees the amount, the date, and your name, email and message where you gave them, plus whether you opted in to their updates. They do not see your card details or your address.
- Our hosting provider — the servers that run tiporsub and send our email are rented from a hosting company. They do not process your data for their own purposes.
- Authorities and advisers — where we are legally required to disclose something, or need advice about a dispute. We will resist requests that look overbroad.
- A buyer — if the business is ever sold, account data would transfer with it. We would tell you before that happened.
Our outbound email is sent from our own mail server, not handed to a third-party marketing platform. We do not sell, rent or trade personal data. There is no circumstance in which we would.
8. Creators and supporter lists
This one matters if you are a creator. Your dashboard lets you export your supporters, including their names, email addresses and whether they opted in to updates.
The moment you export that list, you become the data controller for it. That means the legal responsibility for what happens next is yours, not ours. If you add those addresses to a mailing list, you must:
- only email people who actually opted in;
- include a working unsubscribe link in every message, and honour it promptly;
- not pass the list to anyone else or use it for an unrelated purpose;
- delete someone's details if they ask you to;
- have your own privacy notice if you are in the UK or EU, or handling data of people who are.
We give you the opt-in status alongside every address precisely so you can respect it. Please do.
9. How long we keep it
| What | How long | Why |
|---|---|---|
| Payment records | 7 years after the payment | Tax, accounting and anti-fraud law |
| Creator account and profile | Until you close the account | It is your page |
| Supporter name, email and message | 7 years, as part of the payment record | Same as above; needed to handle a late dispute |
| Email delivery log | 24 months | Proving whether a receipt was delivered |
| Web server logs | 14 days | Faults and abuse |
| Rate-limiting IP counters | Up to 1 hour, in memory only | Stopping brute-force attempts |
| Magic links and password-reset tokens | 1 hour, then unusable | Security |
To close an account, email support@tiporsub.com from the address on it — a person handles it, there is no self-service button yet. We then remove the profile and stop the page. We keep the financial record of payments already made, because we are required to, but we will disconnect it from the profile where we can.
10. Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you.
- Correct anything wrong.
- Delete it — we will, except where we must keep a financial record.
- Export it in a portable format.
- Stop a particular use, including any marketing.
- Withdraw consent you previously gave.
Email privacy@tiporsub.com and we will respond within 30 days. We will not charge you and we will not make the service worse for you because you asked.
If you are in the UK you can complain to the ICO; in the EU, to your national data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising your rights.
11. How we protect it
- Everything travels over HTTPS, with HSTS so browsers refuse to downgrade.
- Passwords are hashed with scrypt and a per-account salt, never stored or logged in readable form.
- Session cookies are signed, HttpOnly and Secure.
- Card data never reaches our servers.
- Sign-in, reset and payment endpoints are rate-limited.
- Access to the production server and database is restricted to the operator.
No system is perfectly secure. If we discover a breach that puts you at risk, we will tell affected people and the relevant regulator without undue delay, and within 72 hours where the GDPR requires it. If you find a vulnerability, please email security@tiporsub.com before disclosing it publicly — we will work with you and we will not threaten you.
12. Where it is stored
Our servers are in the United States, and Stripe processes payments in the United States and elsewhere. If you are in the UK or EU, your data is therefore transferred outside your country. Those transfers rely on the UK and EU Standard Contractual Clauses, or on the EU–US and UK–US Data Privacy Framework where the recipient is certified under it. Stripe's own arrangements are described in its privacy policy.
13. Children
tiporsub is not for children. You must be 18 or over to be a creator, and we do not knowingly collect data from anyone under 13. If you believe a child has given us personal data, email privacy@tiporsub.com and we will delete it.
14. Changes
If we change this policy we will update the date at the top. If the change materially affects how we use your data, we will email creators and post a notice on the site before it takes effect. We will not apply a materially different use to data already collected without asking you first.
15. Contact
- Privacy and data requests — privacy@tiporsub.com
- General help — support@tiporsub.com
- Security reports — security@tiporsub.com
Postal: Tip or Sub, Chandler, AZ 85226, United States
See also our Terms of Service.