Privacy notice
Last updated July 15, 2026
This beta notice explains the data MyOfLink needs to host creator pages, operate outbound links, show lightweight analytics, and offer the optional connected Instagram media grid.
Creator and visitor data
Creators provide account details, profile copy, images, destinations, social links, and page settings. Public visitors may generate page-view, destination-click, social-click, and share-attempt events with limited device, browser, operating-system, referrer, and coarse-location context. MyOfLink does not claim to know whether a provider app successfully opened.
Connected Instagram
Connecting Instagram is optional and is limited to a Professional Business or Creator account linked to a Facebook Page. MyOfLink stores the selected Facebook and Instagram account identifiers, username, granted scopes, token expiry when supplied by Meta, and encrypted access tokens. OAuth continuation choices and every token remain server-only.
MyOfLink requests recent media from Meta approximately every six hours. A public grid can contain up to six sanitized media previews, captions, timestamps, and Instagram permalinks. The grid is on by default after a successful connection. A creator can turn the grid off while keeping the static Instagram destination available.
A transient provider error keeps the last good media and shows a warning to the creator. Expired or revoked access clears imported media and asks the creator to reconnect. Images and links served by Meta remain subject to Meta's own privacy and availability practices.
Use, security, and transfers
We use collected information to operate and secure the service, publish creator-directed pages, provide analytics, communicate service updates, and prevent abuse. Sensitive provider credentials are encrypted and restricted to server-side service operations. Where data is processed outside a user's country, we rely on the safeguards required by applicable law and our service-provider agreements.
Deletion and retention
Disconnecting Instagram deletes stored provider credentials and clears imported media from private and public page state in one operation. A valid Meta data-deletion request performs the same cleanup for every matching connection and returns a confirmation-status URL.
Expired OAuth selection records are pruned after a short operational window. Hashed data-deletion confirmations are retained for up to 90 days. Immutable aggregate or security records may be retained when needed to protect the service, but provider tokens and imported media are not retained after a completed disconnect or Meta deletion request.
Your controls and rights
Creators can edit or remove public destinations, disable the Instagram grid, disconnect Instagram, or use Meta's application data-deletion control. Depending on local law, users may request access, correction, deletion, restriction, portability, or objection to processing. Browser cookie and analytics choices remain available through the site's cookie controls.
Contact
Privacy or data-rights questions can be sent to admin@myoflink.com.