RELAY2 TECHNOLOGIES, INC. / 2026-10-06-draft
Privacy Policy
1. Scope and contact
Relay2 Technologies, Inc. provides Relay². This draft covers creator accounts, website visitors, and people following shortened links, including rly2.link. Contact support@relay2.app for privacy questions, access, correction, export, deletion, or complaints. A business mailing address must be added before publication.
2. Account and eligibility information
The agreed onboarding design collects an editable display name, email/provider identity, full date of birth, country, and state/province/territory. Date of birth is private and intended for eligibility administration, not public profiles, marketing, or authentication. Full-date retention requires a documented necessity assessment and restricted storage before launch.
3. Sign-in providers
Google or Apple may supply an account identifier, name, email, or permitted profile fields. A provider may supply a private relay email address. Missing names must be entered manually. User-edited names must not be overwritten on subsequent sign-ins.
4. Social profiles
Adding a handle is distinct from authorizing a social connection. The launch design is private by default with separate brand-discovery opt-in. Supported connections may import approved profile fields and aggregate follower statistics, not unrestricted account information or follower contact lists. Show source and last-sync time, and stop syncing when disconnected.
5. Links and visitor information
Submitted URLs, labels, campaign parameters, and referral terms may be processed to operate links. Redirect requests may expose IP addresses, timestamps, requested URLs, referrers, and browser information. Cookie-free processing is not necessarily anonymous. The final notice must identify which fields are actually retained by the app, CDN, hosting providers, and analytics systems.
6. Purposes and disclosure
Information is used to provide requested services, operate and protect links, administer accounts and subscriptions, respond to support, and meet legal obligations. Providers may process information for hosting, communications, security, or payments. Disclosures may also occur when you choose to share information or where legally necessary. Vendor inventory, processing locations, and sale/sharing or advertising practices must be validated before publication.
7. Creators, brands, and visitors
A creator cannot consent to visitor tracking on a visitor’s behalf. Opening a link is not acceptance of account Terms or optional tracking. Private profiles do not make public short links private. Brand discovery must be separately enabled; identifiable visitor information must not be exposed in creator reports without a separately assessed basis.
8. Retention and deletion
Proposed launch targets—not yet verified operating guarantees—are: account data and DOB removed from active systems within 30 days of verified deletion; raw redirect logs 30 days; minimized security logs 90 days; social snapshots 12 months; support records 24 months; backup expiry 90 days. Billing and legal records require purpose-specific retention. Aggregate history may remain while the account/link is retained, subject to deletion or genuine deidentification. A free plan’s 30-day reporting limit is not a storage-retention statement.
9. Your choices and rights
Contact support@relay2.app to request access, correction, deletion, or a copy of personal information, or to raise a privacy concern. Rights and exceptions vary by location. We may need proportionate identity verification. Non-account visitors may also contact us. Applicable opt-out, appeal, consent-withdrawal, and regulator-complaint procedures must be supported before launch.
10. Children and geography
Creator accounts are intended for adults in the United States and Canada under the eligibility rule in our Terms. Public links may be encountered by minors; an adult-account rule does not remove obligations concerning their information. Quebec and other applicable regional requirements require review before launch.
11. Security and updates
The implementation must restrict DOB and credential access, protect information in transit and storage, and support deletion across processors and backups. No system is completely secure. Cross-border processing and transfer safeguards must be documented. Material policy changes will be communicated as required; the effective date will be added only when this draft is finalized.