1. Information we collect
We collect the minimum information required to provide the Services and to make them safer, faster and more useful.
1.1 Information you give us
- Account information — name, email address, password (hashed), workspace name and billing details.
- Content you create — short links, bio pages, QR codes, files you upload and their metadata.
- Communications — messages you send to support, sales, or through any of our forms.
1.2 Information collected automatically
- Analytics on redirects, scans and downloads — timestamp, referrer, coarse geography, device family and browser family. We do not use third-party cross-site tracking cookies for this.
- Product usage — pages viewed inside the dashboard, features used, and error diagnostics (crash reports).
- Technical — IP address (hashed after 30 days), user agent, cookie identifiers.
1.3 Information from third parties
If you sign in through Google, GitHub or Apple, we receive the basic profile information you approve. If your workspace uses SSO, we receive the identity attributes your IdP sends.
2. How we use information
- Provide, maintain and improve the Services.
- Personalize your experience (e.g. show your recent links first).
- Detect, prevent and respond to fraud, abuse and security incidents.
- Comply with legal obligations and enforce our Terms.
- Send transactional emails (billing, security, product updates you opted into).
3. Legal bases (EEA/UK)
We process personal data based on: (a) contract — to provide the Services you signed up for; (b) legitimate interests — to secure and improve the Services; (c) consent — where required, e.g. for optional marketing; and (d) legal obligation.
4. How we share information
We do not sell your personal data. We share it only with:
- Service providers under contract (hosting, payment processing, email delivery, error monitoring).
- Your workspace — content and activity is visible to your teammates and admins per role.
- Authorities when legally required, and only to the minimum extent needed.
- Successors in the event of a merger, acquisition or asset sale, with notice to affected users.
5. International transfers
Linkora is a global product. When we transfer personal data outside your region, we rely on Standard Contractual Clauses (SCCs) and equivalent safeguards.
6. Data retention
We keep account data while your account is active and for up to 90 days after cancellation to allow reactivation. Analytics events older than 24 months are aggregated. Backups are rotated every 35 days.
7. Your rights
Depending on your location, you have the right to access, correct, export, restrict, object to, or delete your personal data. Email support@linkora.solutions and we will respond within 30 days.
8. Security
We encrypt data in transit (TLS 1.3) and at rest (AES-256). We enforce SSO/MFA for our staff, least-privilege access, quarterly access reviews and third-party penetration tests.
9. Children
Linkora is not directed to children under 16. We do not knowingly collect personal data from them.
10. Changes to this policy
We may update this Policy from time to time. Material changes will be communicated by email and via an in-app banner at least 14 days before they take effect.
11. Contact
Data controller: Linkora, Inc., Herengracht 182, 1016 BR Amsterdam. Data Protection Officer: support@linkora.solutions.