Last updated 2026-07-25.
NTNL (ntnl.nu) provides smart links and advertising tooling to artists, labels and marketers ("customers"). This page describes what happens to data on both sides of the product: our customers' account data, and the data of visitors who open a customer's smart link.
When someone opens a link we record: a timestamp, the country/region derived at the edge, device class, referrer, a random first-party visitor id stored in a cookie, and a device fingerprint hash used to detect automated traffic. If the customer has enabled it, an email address the visitor types in is stored too. We do not store raw IP addresses in our database.
These events are also sent to the customer's own Meta pixel through the browser and the Conversions API, with identifiers hashed (SHA-256) before transmission, so that the customer can measure and optimize their advertising. The customer is the controller of that data; NTNL is a processor acting on their instructions.
No advertising cookies from third parties are set by us, and no data is sold or shared with data brokers.
We store your email, name, a salted password hash, your workspace configuration, and encrypted OAuth tokens for the platforms you connect. Tokens are encrypted at rest with AES-GCM and are never shown back to you or to anyone else.
Cloudflare (hosting, database, object storage), Meta (advertising, when you connect an account), Stripe (payments), and an email delivery provider for account mail. That is the full list.
Event data is retained while the workspace is active and for 30 days after deletion. You may request access, correction, export or deletion of your data at any time by writing to hello@ntnl.nu. Visitors may request deletion of data associated with them via the data deletion page.