Legal

Privacy Policy

Threshold exists to give you control over your own contact information. This page explains, in plain terms, what we collect to make that possible, why, and how you can see, change, or remove it.

1. Who we are

Threshold (“Threshold”, “we”, “us”) operates getthreshold.link, a service that lets you share one link for your contact information and socials while keeping the sensitive parts locked behind a request you approve. For the purposes of data protection law, Threshold is the controller of the personal data described below.

We're based in Ireland, so this policy is written to meet the UK/EU General Data Protection Regulation (GDPR). If you're elsewhere, the same standard applies to you too.

2. What we collect

We collect the minimum we need to run the product. Specifically:

Account information

  • Email address — required, used to sign you in and to notify you about your account (e.g. an access request).
  • Display name, username, bio, avatar — whatever you choose to add to your public profile. All optional beyond a username.
  • If you sign in with Google or Apple (where offered), we receive the name, email, and profile photo those providers share with us.

Access & request data

This is the core of the product, so it's worth being specific: when someone requests access to your locked information, we record who requested it, what tier they asked for, and your decision (approved, denied, revoked, or blocked) — along with a timestamp. This forms the audit trail you see in your dashboard. We do not delete this history when you revoke or deny access; we mark it as revoked/denied instead, so you retain an accurate record of who has ever asked.

Usage data

When your public profile is viewed, we log which profile was viewed and, if the visitor is signed in, their account — so you can see who's checking your page in your Analytics tab. This view analytics does not log IP addresses or device fingerprints, and we use no third-party analytics or advertising trackers.

Separately, we process your IP address transiently for security — to rate-limit sign-in, access requests, and username checks, and to prevent abuse. These rate-limit records are short-lived and are regularly purged, and we don't use your IP to build an advertising profile or track you across other sites.

Business interest form

If you register interest via our For Business waitlist, we store what you submit — company name, company size, region, an optional note about what you're hoping to solve, and your email — so we can follow up. This is a lead record only: it is not an account, it's kept separate from the product, and we don't share it. Ask us any time and we'll delete it.

What we don't collect

We don't ask for passwords (sign-in is passwordless, via a one-time emailed link) and we don't run ads or sell data to anyone, so there's no advertising profile being built on you.

3. How we use it

  • To create and operate your account, and to show your public profile at the tier each visitor is entitled to.
  • To send you account emails: sign-in links, notifications when someone requests or is granted access, and a short onboarding sequence when you first join (explained below).
  • To maintain the access audit trail that's the whole point of the product.
  • To keep the service secure and prevent abuse (e.g. rate-limiting, blocking impersonation-style usernames).
  • To understand how Threshold is used in aggregate, so we can improve it.
We do not use your data to train AI models, and we do not sell or rent personal data to third parties.

4. Our legal basis

Under GDPR, we rely on:

  • Performance of a contract — most of what we do (running your account, showing your profile, handling access requests) is necessary to provide the service you signed up for.
  • Legitimate interest — for security, fraud prevention, and the audit trail itself, which exists specifically to protect you.
  • Consent — where we ask for it separately, such as optional future marketing communications (we'll ask before sending any, and you can withdraw consent at any time).

5. Who we share it with

We don't sell your data. We do use a small number of infrastructure providers to run Threshold, each acting as a processor on our behalf, bound to only use your data to provide their service to us:

  • Vercel — hosts the application and runs it.
  • Neon — hosts our database (based in the EU — London region).
  • Resend — delivers our transactional and account emails (sign-in links, notifications, onboarding).
  • Cloudinary — stores and serves the profile avatar images you choose to upload.

We only ever disclose your information to anyone else if required by law, or with your explicit permission.

6. International transfers

Some of the providers above may process data outside the EU/UK (for example, Vercel, Resend, and Cloudinary are US-headquartered companies). Where that happens, we rely on the safeguards recognised under GDPR — such as Standard Contractual Clauses — to make sure your data stays protected to the same standard.

7. How long we keep it

  • Account and profile data: for as long as your account is active.
  • Access grants, requests, and the audit log: retained as part of the product's core function (your access history), even after you revoke someone's access — we keep the record, not the exposure.
  • You can delete your account at any time from your dashboard. It's immediate and permanent: your profile, and every access grant, request, and audit-log entry where you're the owner or the viewer, is removed — including the record other people have of having granted or revoked you, since we don't do partial deletes. We don't keep a backup copy beyond what's needed to restore the database in a disaster, and we don't retain anything for legal reasons beyond that unless the law requires it of us for a specific case.

8. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct it if it's inaccurate — most of this you can already edit directly in your dashboard.
  • Erase it (“the right to be forgotten”).
  • Restrict or object to certain processing.
  • Port your data to another service in a portable format.
  • Withdraw consent at any time, where we rely on it.

To exercise any of these, email hello@getthreshold.link. We'll respond within 30 days. If you're unhappy with how we've handled a request, you can complain to Ireland's Data Protection Commission at dataprotection.ie.

9. Cookies

We use a single strictly-necessary cookie to keep you signed in. It doesn't track you across other sites, and we don't use analytics or advertising cookies. Because it's strictly necessary for the service to function, it doesn't require a cookie-consent banner under current guidance — if that ever changes (e.g. we add optional analytics), we'll add one and ask first.

10. Children

Threshold isn't directed at children, and you must be at least 16 to create an account (the digital consent age under Irish/EU law). If we learn a child's account was created without appropriate consent, we'll remove it.

11. Security

Data is encrypted in transit and at rest. Locked profile information is withheld at the server — it's never sent to a visitor's browser until they're actually cleared for it, so there's nothing for a script or a curious visitor to find by inspecting the page. Sign-in is passwordless, so there's no password of yours for us (or an attacker) to lose.

12. Changes to this policy

If we make a material change to this policy, we'll update the date at the top and, for significant changes, notify you by email.

13. Contact

Questions, requests, or concerns about your data: hello@getthreshold.link.

Ready to take control?

Set up your Threshold and decide who sees what.

Set up your Threshold →