Privacy Policy
This policy is provided for transparency and does not constitute legal advice. If you have questions about your rights, you may wish to seek independent legal advice. For questions about the service, contact us at privacy@tippage.com.
On this page14 sections
Data controller
The data controller for TipPage.com is TipPage.com LTD, a private limited company registered in England and Wales under company number 16850379, with registered office at 128 City Road, London, United Kingdom, EC1V 2NX.
The named data controller is Matthew John Geoffrey Holden. To exercise your data protection rights, make a subject access request, or raise a privacy concern, contact him directly at matt@tippage.com. For general privacy questions you can also reach us at privacy@tippage.com.
TipPage.com LTD is registered with the UK Information Commissioner's Office (ICO) under registration number ZC150903. You can verify this at ico.org.uk.
For tips, overlay settings, bot configuration, and operational data, TipPage.com LTD is the data controller. For content that a Viewer submits to a specific Streamer (tip messages, media requests, donor names, TTS audio), TipPage.com LTD acts as a processor on behalf of that Streamer - the Streamer controls that content for their own channel.
Data we collect
We collect and process the following categories of personal data:
Donation and payment data (from Viewers)
- Display name you provide with your tip
- Tip amount, currency, and payment method (Stripe card or PayPal)
- Message text submitted with your tip
- Media URL and start time if you include a media request
- Payment reference identifiers (order IDs, payment intent IDs)
- A tokenised payer identifier provided by the payment processor (e.g. Stripe card fingerprint, PayPal payer ID, Stripe Link persistent token, or US bank fingerprint) - not your full card number
- Email address you enter at checkout - used to send your receipt, and kept in one-way hashed form for ban enforcement
- Card brand and last four digits as reported by the payment processor (never your full card number) - used to derive a one-way hash for ban-evasion prevention. The digits themselves are kept only in the payment records Stripe sends us, and are removed from them after 30 days (see "Data retention"). They are never shown to Streamers
- Billing details you give Stripe at checkout (name, email, and address or phone where asked) - they arrive in the payment records Stripe sends us, are used only to look into payment problems and chargebacks, and are removed after 30 days. They are never shown to Streamers
- A device identifier derived from browser signals when you submit a tip, stored only as a one-way hash, for fraud and ban-evasion prevention
Several of these exist purely so that Streamer bans can't be trivially dodged. They are stored as salted one-way hashes scoped to the individual Streamer - see "How ban enforcement protects your privacy" below for exactly what that means.
Twitch and Kick account data
From Streamers and from Viewers who sign in for sub rewards. A Streamer can connect a Twitch channel, a Kick channel, or both to one TipPage account, and a Viewer can link both to one sign-in. Viewer sign-ins are scoped per Streamer - signing in on one Streamer's tip page does not sign you in on another.
- Twitch or Kick user ID, username, display name, profile image URL
- Email address. The two platforms differ here. Twitch only shares your email if we ask for it and you grant it, and we ask for it from Streamers only - Twitch viewer sign-in never includes it. Kick returns the email on your account with every sign-in, Streamer or Viewer, and offers no way for us to leave it out; it is kept with the linked account. Streamers receive service email at it; for Viewers it is stored and not otherwise used - receipts go to the email you enter at checkout
- Account creation date (used only for the minimum-account-age check)
- Current subscription tier on the specific Streamer's channel (for sub rewards). On Kick, subscription and follow status is read from Kick's public channel pages by username
- OAuth access and refresh tokens - encrypted at rest using AES-256-GCM envelope encryption with per-tenant keys
Streamer account configuration
- Branding (display name, colours, logo)
- Payment integration details (Stripe connected account ID, PayPal merchant ID and business email)
- Custom domain records, if configured
- Word filter lists, alert toggles, bot commands, response lists, reward settings
- Account IDs of any team members (admins, moderators) invited to help run the account
- Custom bot OAuth tokens (encrypted at rest), if the Streamer has linked their own bot account
Identity and payout-account checks (Streamers only)
Before some Streamers can set up card payouts we ask them to verify their identity, and where a Streamer links a United States bank account for payouts through Stripe Financial Connections we check who the bank says owns it. Both checks exist because people have signed up with newly created streaming channels to run stolen cards through TipPage. Both are carried out by Stripe, not by us:
- Identity verification. Whether a Streamer is asked depends on their connected Twitch or Kick channel (how recently the account was created, the size of its following, and whether it is a Twitch Affiliate or Partner) and on review by TipPage staff. The check itself runs on Stripe's pages under Stripe's own privacy policy: the Streamer photographs a government-issued ID and takes a selfie, and Stripe compares the two. TipPage never receives the images. We store the outcome (passed, failed, or pending), the date, Stripe's reference for the check, the name on the verified document, and which team member completed it. A Streamer can decline; they then cannot set up card payouts until their channel is more established or the check is waived by TipPage staff, and everything else in TipPage keeps working
- Payout bank account ownership. Where a Streamer links a US bank account through Stripe Financial Connections, Stripe shares with us the account holder name(s) and address(es) the bank reports, the bank's name, and the last four digits of the account number. We use them only to confirm the payout account belongs to the person who verified their identity and set up payouts. Bank login credentials go to the bank through Stripe and never reach TipPage. This data is stored in the United Kingdom and is not shared with anyone else. Bank accounts outside the US are entered in Stripe's form directly and no ownership data is collected for them
AI voices (TipPage+, Streamers only)
A Streamer on TipPage+ can create an AI voice by uploading up to 90 seconds of recordings. For each voice we hold:
- The voice's name, description, gender label and photo, and which Streamer created it
- A record that the Streamer confirmed they hold the rights to the recordings, with who confirmed it and when
- The transcript and length of each recording. The recordings themselves are deleted from our storage as soon as the voice has been built; they are kept only while a build is in progress or has failed, so it can be retried
- The processed reference audio the voice is generated from, held in our text-to-speech worker's private storage for as long as the voice exists
- A short preview clip, generated once when the voice is built, stored on our public CDN so viewers can hear the voice before choosing it
A voice is private to the Streamer who made it unless they publish it. Publishing lists the voice in a shared library that other Streamers can browse, showing its name, photo and the publishing Streamer's display name; other Streamers can add it for their own viewers. A published voice can be unpublished at any time, which removes it from every channel that added it.
Technical data
- IP address - appears in standard HTTP access logs (retained ~30 days) and used transiently for rate limiting. When you submit a tip, a one-way hashed form of the address (scoped to that Streamer, not reversible) is kept with the tip record for ban-evasion prevention; the readable address is not stored with your tip
- Standard server logs (user agent, URL requested, response status, timestamps)
- Session identifiers stored in cookies (see our Cookies Policy)
- Error reports captured by Sentry when something crashes - may include the URL you were on and a short trace. Sensitive data is scrubbed where possible
- Product analytics captured by PostHog on the dashboard (see cookies)
Moderation and safety data
- The original unfiltered text of your name and message (retained for moderation review)
- Records of content filter actions applied to submissions, including the AI's reasoning where AI filtering is enabled
- Ban records if a Streamer bans you, including the reason and the one-way hashed identifiers associated with the banned tip (payment identity, email, device, IP, Twitch or Kick account where signed in)
- Where a banned user attempts to tip again, a record of the rejected attempt and the hashed identifiers it carried, which may be linked to the existing ban record
TipPage+ subscription data (Streamers only)
- Subscription status, plan, billing interval, and start/renewal dates
- Stripe customer ID and subscription ID
- Payment method summary (last 4 digits and card brand as reported by Stripe - we do not store full card details)
- Billing history and invoice records
Chat data (via the bot)
When a Streamer enables the bot, it receives their Twitch chat through Twitch's EventSub and their Kick chat through Kick's event webhooks, to run commands, timers and chat moderation. We do not keep a transcript of chat. We do keep, per Streamer:
- A daily count of messages per chatter, used for the Streamer's chat statistics and the bot's viewer variables
- Each chatter's most recent message, so a command can refer back to it
- A record of any moderation action the bot took, including the message it acted on
- Where a Streamer has set up a command that answers with AI: the messages sent to that command and the bot's replies, for up to 90 days, so the bot can remember the conversation. Those messages are sent to the AI providers named below to generate the reply, under the same zero-data-retention terms as the content filter
How ban enforcement protects your privacy
Streamers can ban abusive donors from their tip page. For a ban to mean anything, we need a way to recognise a banned person if they try again with a different card, account, or device. We designed this to touch as little personal data as possible:
- Everything is one-way hashed. The identifiers involved (payment identity, checkout email, device identifier, IP address) are stored as salted cryptographic hashes. A hash can be compared for equality, but it cannot be turned back into the original value - not by us, not by anyone.
- Hashes are scoped to a single Streamer. The same person produces a completely different hash on every Streamer's page, so this data cannot be used to follow you from one streamer to another - and we don't.
- If you're never banned, nothing is done with it. For donors in good standing these hashes simply sit alongside the tip record, unused. They are never used for advertising, profiling, analytics, or anything other than checking tips against that one Streamer's ban list.
- We keep only what this purpose needs. No browsing history, no behavioural profile, no data brokers - just the minimum set of hashed identifiers required to stop a banned person from walking straight back in.
- Streamers never see the identifiers. A Streamer's dashboard shows only neutral labels such as "Payment card", "Device", or a masked email like jo***@example.com - never your card number (or any part of it), your full email, or your IP address. The hashes themselves never leave our servers.
If a Streamer has banned you and you attempt to tip them again, the attempt is declined and the identifiers it carried may be linked to the existing ban record so the ban continues to hold; where two ban records turn out to belong to the same person, they may be combined. For card payments this happens before your payment is captured, so you are not charged.
How AI features protect your privacy
TipPage uses AI for two things, both optional and both switched on by the Streamer for their own channel: checking tips against the Streamer's filter list, and answering chat commands the Streamer has set up to reply with AI. A tip message or a line of chat is exactly the kind of text people would not want kept by a company they have never heard of, so we hold the AI providers we use to a stricter standard than the rest of our processors:
- Zero data retention, or we don't use them. We only send content to inference providers that commit to zero data retention: the text is processed to produce the answer and is not stored afterwards, not logged, and not used to train or improve any model. A provider that keeps prompts, even briefly for abuse monitoring, does not qualify.
- The rule is enforced by the request, not by policy alone. Every request we send is technically restricted to zero-data-retention endpoints and to a short list of providers we have vetted. If none of them can serve a request, it fails and the tip falls back to the Streamer's word-list filter or their manual review queue. It is never sent somewhere else to get an answer.
- The model's author never sees your content. We run open-weight models on the vetted providers' own hardware. The company that trained a model is not involved in processing your text and receives nothing from us.
- We send the minimum. The content filter receives the message text, the display name, the Streamer's filter list, and a count of how often that donor has been filtered before. AI chat replies receive the message sent to the command, the Streamer's character prompt, recent messages to that command, and the channel's emote names. Neither ever receives your email, payment details, IP address, or Twitch or Kick account.
- Nothing goes to a country without adequate protection. The providers we use are established in the United States and process content there under the safeguards described in "International data transfers". No content is sent to a provider established in the People's Republic of China.
- Only what you actually did is remembered, and only by us. Where a Streamer turns on conversation memory for an AI command, the recent messages to that command are kept on our own servers for up to 90 days so the bot can refer back to them. The provider is handed them for each reply and keeps nothing.
The providers currently meeting this standard are named in "Third-party processors" below. If we add or replace one, it will be held to the same standard, and this policy will be updated first.
How we use your data and lawful bases
| Purpose | Lawful basis |
|---|---|
| Processing your tip and displaying it on the Streamer's overlay | Contract (performance of the tipping service you initiated) |
| Processing payments via Stripe or PayPal | Contract |
| Generating text-to-speech audio from your message | Contract |
| Processing refund requests when a Streamer approves them | Contract / Legal obligation |
| Awarding and tracking sub reward credits via Twitch EventSub and Kick event webhooks | Contract |
| Content moderation and filtering of submissions | Legitimate interest (maintaining a safe environment for Streamers and audience) |
| Ban enforcement using one-way hashed identifiers (payment identity, checkout email, device identifier, IP address, Twitch or Kick account) - see "How ban enforcement protects your privacy" | Legitimate interest (preventing abuse and protecting Streamers and the service) |
| Invisible proof-of-work bot check on tip submission (self-hosted; runs in your browser, no data shared with third parties) | Legitimate interest (preventing automated abuse and payment fraud, including stolen-card testing) |
| Verifying a Streamer's identity before card payouts are set up, and confirming who owns a linked payout bank account - see "Identity and payout-account checks" | Legitimate interest (preventing payment fraud against card holders, Streamers and TipPage). The identity check is performed by Stripe on Stripe's pages, where the Streamer consents to Stripe's processing of their document and selfie; it can be declined, in which case card payouts simply cannot be set up yet |
| Running the chat bot (joining channels, processing commands, sending messages, chat moderation) | Contract with the Streamer |
| Generating AI chat replies and AI voices where a Streamer has enabled them | Contract with the Streamer |
| Building an AI voice from recordings a Streamer uploads, and listing it in the shared voice library when the Streamer publishes it | Contract with the Streamer, on the Streamer's confirmation that they hold the rights to the recordings |
| Sending transactional emails (setup, receipts, refunds) | Contract |
| Error tracking via Sentry | Legitimate interest (maintaining service reliability) |
| Product analytics via PostHog (dashboard only) | Legitimate interest (understanding and improving the product) |
| Processing TipPage+ subscription payments and managing subscription lifecycle | Contract (subscription agreement with the Streamer) |
| Delivering TipPage+ features (AI filter, custom domain, chargeback cover) | Contract |
| Displaying a leaderboard of donor names and amounts | Consent (by voluntarily providing a display name and submitting a tip, with the leaderboard being a visible feature) |
Third-party processors
We share data with the following processors, solely for the purposes described:
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe | Card payment processing (merchant of record: TipPage) | Payment details, donor name, amount, metadata |
| Stripe (Identity) | Identity verification for Streamers asked to verify before setting up card payouts. Runs on Stripe's own pages under Stripe's privacy policy | Government ID images and a selfie, given by the Streamer directly to Stripe. TipPage receives only the outcome, the date, Stripe's reference for the check and the verified name |
| Stripe (Financial Connections) | Linking a United States bank account for payouts and confirming who owns it | The Streamer signs in to their bank on Stripe's pages. TipPage receives the account holder name(s) and address(es), the bank's name and the last four digits of the account number only |
| PayPal | Alternative payment processing | Payment details, amount, currency |
| Twitch | OAuth, EventSub, Helix API calls, chat messaging | OAuth credentials, user ID, subscription events, chat messages |
| Kick | OAuth, event webhooks (chat, follows, subscriptions, Kicks), API calls, chat messaging | OAuth credentials, user ID, channel events, chat messages |
| Amazon Web Services (Polly) | Text-to-speech services | Message text, language, voice selection |
| OpenRouter, Inc. | Routing our AI content-filter and AI chat-reply requests to the inference providers in the next row, restricted to endpoints with a zero-data-retention policy (where the Streamer has enabled either feature) | For the content filter: message text, display name, the Streamer's filter list (which may include the Streamer's own name or address), and aggregate counts of the donor's previously filtered tips. For AI chat commands: the message sent to the command, the Streamer's character prompt, recent messages to that command, and the channel's emote names. OpenRouter passes the content through and keeps request metadata only (timestamps, token counts, cost), not the content; we do not enable its prompt logging. Established in the United States |
| DeepInfra, Fireworks AI, Novita AI, Parasail | Running the AI model (hosted inference) for the requests above. Each is reached only through OpenRouter's zero-data-retention routing: the content is processed to produce the answer and is not stored afterwards or used to train any model. The models themselves are open-weight models run on these providers' own hardware; the company that trained a model never receives any content | The same content as the OpenRouter row. Processed in the United States |
| Modal Labs | Serverless GPU hosting for our own AI text-to-speech model (TipPage+ AI voices, where enabled by the Streamer). The model runs under our control on hardware rented from Modal; Modal does not train on or otherwise use the content | Message text and voice selection for each AI-voice tip; the reference recordings a Streamer uploads to create a voice, and the processed reference audio kept for each voice. Processed in the United States |
| Fish Audio | Transcribing reference recordings uploaded to create an AI voice, only when the Streamer does not type the transcript themselves | The reference recording only. May be processed outside the UK |
| Fallback TTS (Google Translate), YouTube video title lookup (oEmbed) | Message text (TTS fallback only), YouTube video URLs | |
| Cloudflare | CDN, object storage (R2), DDoS protection, DNS, and SSL for Streamer custom domains | IP address and request headers (standard HTTP proxying); custom-domain metadata; stored files - generated text-to-speech audio (including AI-voice audio), AI voice preview clips and photos, uploaded sounds and images |
| Backblaze, Inc. | Storing encrypted backups of our database and cache, taken every half hour, so we can recover from a failure or an attack. The backups are held in Backblaze's European data centres | An encrypted copy of everything in our database and cache. We encrypt each backup ourselves before it leaves our infrastructure, with keys Backblaze never holds, so Backblaze stores data it cannot read. Backblaze is a company established in the United States; the backups are stored in the EU |
| Sentry | Error tracking | Stack traces, URLs, minimal request metadata. Sensitive data scrubbed where possible |
| PostHog | Product analytics (dashboard only) | Pageviews, click events, session and distinct-user identifiers |
| Resend | Transactional email (setup, refunds, notifications) | Email address and message content |
| Anti-fraud provider | Deriving a device identifier for fraud and ban-evasion detection, only when a tip is submitted | Browser and connection characteristics. No name, email, message, or payment data is shared; we store the resulting identifier only as a one-way hash |
AI content filtering and AI chat replies only run where a Streamer has enabled them. We only send this content to inference providers that commit to zero data retention - the text is processed to produce the answer and is not kept afterwards or used for training - and every request is technically restricted to such providers, so a request cannot be routed to one that stores or trains. Which of the listed providers handles a given message varies with price and availability. We do not publish which AI model is in use at any time, because the filter exists to defeat people actively trying to bypass it.
We do not sell your personal data. We do not share personal data for third-party advertising.
What the Streamer sees
A Streamer (and any admins or moderators they invite) can see:
- Your donor name, tip amount, message text, original (unfiltered) text, and any media you submitted
- If you've signed in for sub rewards: your Twitch or Kick display name, username, profile image, and subscription tier
Streamers do not see your payer identifier, card number, billing name, address, or phone number. When a Streamer bans a donor, the ban is placed against the tip itself - the payer identifier behind it is matched by TipPage server-side and is never shown to the Streamer or their team.
Because TipPage is the merchant of record for payments (via Stripe destination charges), Streamers do not see the customer billing details that Stripe or PayPal collect - those stay with TipPage.
International data transfers
Our core infrastructure is hosted in the United Kingdom, where TipPage.com LTD is established. For users in the EU/EEA, transfers of personal data to the UK are covered by the European Commission's adequacy decision for the United Kingdom. Some of the processors listed above are based outside the UK/EEA - in particular, AI-voice audio is generated on Modal Labs infrastructure in the United States. Our off-site backups are stored in the EU by Backblaze, a United States company; they are encrypted by us before upload, with keys Backblaze does not have, so Backblaze cannot read them. Where your data is transferred outside the UK, we rely on one or more of the following safeguards:
- The recipient country has been deemed to provide an adequate level of data protection
- Standard contractual clauses (international data transfer agreement) approved for UK transfers
- The transfer is necessary for the performance of the service you have requested (e.g. payment processing)
Where a Streamer has enabled AI content filtering or AI chat replies, the text involved is processed by the AI inference providers listed above, all established in the United States, under zero-data-retention terms: the content is processed to produce the answer and is not stored by those providers afterwards or used for training. That processing is initiated by the Streamer's configuration of their own channel and never includes your payment, contact, or account details. No content is sent to an AI provider established in the People's Republic of China.
Data retention
| Data type | Retention period |
|---|---|
| Tip and donation records | Retained while the Streamer's account is active. When the account is deleted (by the Streamer or by us) each paid tip is reduced to its amount, currency, date, processor, payment reference and refund status and kept for 6 years for tax and chargeback purposes, then deleted automatically; the tipper's name, message, media link and identity signals are deleted with the account |
| Payment records sent to us by Stripe (one per payment event) | Kept in full for 30 days, for payment troubleshooting and chargeback investigation. After 30 days the billing name, email, address and phone, the card's last four digits and expiry, and any IP address are removed; what remains (amounts, currency, status, fees and reference identifiers) is kept with the tip records |
| Pending sub-reward credits (for Viewers who haven't signed in) | 60 days |
| OAuth tokens (Streamer and Viewer) | Until you revoke access on Twitch or Kick, or delete your account |
| Dashboard session tokens | 30 days (Streamer) |
| Ban and rejection records (including their hashed identifiers) | Retained indefinitely for fraud prevention; deleted when the Streamer lifts the ban |
| Hashed identity signals stored with tips (ban-evasion prevention) | Retained with the tip records they belong to; one-way hashed and irreversible throughout |
| Chat statistics and each chatter's most recent message | While the Streamer's account is active |
| Chat moderation log | While the Streamer's account is active |
| AI command conversation memory | 90 days from the last message to that command |
| Encrypted backups of our database and cache | Taken every half hour and kept on a rolling schedule, then deleted. Data you delete, including a deleted account, stays in backups already taken until those backups expire, and is not restored into the live service afterwards except to recover from a failure (in which case deletions are re-applied). The 6-year records described in this table are kept on top of that |
| Server access logs | ~30 days |
| TTS audio (standard and AI voices), stored on our CDN | Retained for performance and replay; periodically reviewed |
| AI voice reference recordings uploaded by a Streamer | Deleted from our storage as soon as the voice is built; kept only while a build is in progress or has failed so it can be retried |
| AI voice data (name, photo, transcripts, rights confirmation, preview clip, processed reference audio) | Retained while the voice exists; deleted when the Streamer deletes the voice, or when their account is deleted. A voice taken out of service by TipPage keeps its record so tips that used it still display |
| AI filter cache | Retained for performance; periodically reviewed |
| TipPage+ subscription and billing records | Retained for at least 6 years after subscription end, for VAT and accounting purposes |
| Deleted Streamer accounts | Everything is deleted at once except the records in the rows above that carry a 6-year period, plus who the account holder was (display name, account email, connected channel IDs) so a later question about the account or a new signup from the same channel can be answered. Those are deleted automatically 6 years after the account was deleted |
| Identity verification outcome and payout bank account ownership details (Streamers) | Retained while the Streamer's account exists and for 6 years after their last card tip, alongside the payment records they protect. The ID images and selfie are held by Stripe under Stripe's own retention policy; we can ask Stripe to redact them on request |
Your rights
Under UK and EU data protection law, you have the following rights:
- Access - request a copy of the personal data we hold about you
- Rectification - request correction of inaccurate data
- Erasure - request deletion of your data, subject to lawful retention grounds
- Restriction - request that processing be limited in certain circumstances
- Data portability - receive your data in a structured, machine-readable format
- Objection - object to processing based on legitimate interest
- Withdraw consent - where we rely on it (e.g. leaderboard display)
To exercise any of these rights, contact our data controller Matthew John Geoffrey Holden at matt@tippage.com. We will respond within one month of receiving your request.
If you are a Viewer and your request is about content you submitted to a Streamer (tip messages, media requests), the Streamer is the controller of that content - we will coordinate with them.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Security
We implement appropriate technical and organisational measures to protect your data:
- HTTPS/TLS encryption for all data in transit
- AES-256-GCM envelope encryption at rest for all OAuth tokens, Stripe secrets, and PayPal credentials, with per-tenant keys wrapped by a master key stored separately from the database
- Off-site backups of our database and cache every half hour, encrypted by us before they leave our infrastructure (so the storage provider holds only data it cannot read) and stored in the EU
- HttpOnly, Secure, and SameSite cookie attributes for session tokens
- Parameterised database queries throughout
- Role-based access controls within Streamer accounts (owner, admin, moderator)
- Bot and API-internal endpoints protected by shared secrets
No system is completely secure. If you believe you've found a vulnerability, please email security@tippage.com.
Users under 18
The Service is open to users of all ages. However, paid tips involve financial transactions, and users under 18 should ensure they have appropriate permission before making a payment. The Service is not directed to children under 13 and we do not knowingly collect data from them. If you are a parent or guardian and have concerns, please contact us.
Changes to this policy
We may update this policy from time to time. Material changes will be indicated by updating the "Last updated" date at the top of this page and, where appropriate, announced in the dashboard. Continued use of the Service after changes constitutes acceptance of the updated policy.
Contact
Email privacy@tippage.com for privacy questions, or hello@tippage.com for anything else.
TipPage.com LTD, a private limited company registered in England and Wales (company number 16850379). Registered office: 128 City Road, London, United Kingdom, EC1V 2NX. ICO registration number ZC150903.