Privacy Policy
Last updated 2026-09-09
This policy explains what LinkPage collects, why, and what you can do about it. It is written to match what the software actually does — the analytics described below are the same fields the code writes to the database, and nothing more.
The data controller is TODO — registered company name, company number TODO — company registration number, registered at TODO — registered address. For anything in this policy, write to TODO@example.com.
Your account
To sign in you give us an email address. If you use Google sign-in, Google tells us your email address and basic profile details instead. Passwords are hashed by our authentication provider and are never visible to us.
Account credentials are kept separately from your public profile. Your email address is never copied into the profile table and never appears on your public page.
What you publish
Your handle, display name, bio, avatar, background image and links are public by design — that is the point of the product. Anyone with your address can read them, and search engines may index them.
Uploaded avatars and backgrounds are stored in public buckets: anyone who knows the file URL can open it, even without visiting your page. Do not upload anything you would not put on a public website.
Visitor analytics
When someone opens your page or clicks one of your links, we record a row containing only these five things:
- the referring website's hostname, without the path and without the leading www. — blank when the visit came from your own page;
- a two-letter country code, supplied by our hosting provider's edge network;
- a device class: desktop, mobile, tablet or other;
- the browser name, without the version;
- the operating system name, without the version.
We do not record IP addresses, cookies, the raw user-agent string, visitor identifiers, session identifiers, fingerprints, cities, or the pages a visitor saw before yours. Nothing links one visit to another, which means we cannot count unique visitors — a trade we made deliberately. Requests identified as bots are discarded before anything is written.
Only you can read the statistics for your own page; database rules enforce that. See the Cookie Policy for why none of this needs a consent banner.
How we measure the app itself
Everything above is about your page and the people who visit it. Separately, we measure how the LinkPage app itself is used — the landing page, the sign-in screens, onboarding and your dashboard — so we can tell whether the product works. This runs on Vercel Web Analytics and Vercel Speed Insights, both provided by our hosting provider.
They record the page address with the query string and fragment removed, the referring site, a country, and the device, browser and operating system family — plus, for Speed Insights, how quickly the page rendered. They also record which of a small number of named actions happened: an account was created, a link was added, a preset was applied. Those action records carry no content you typed — no handle, no link address, no display name, no email — only our own labels and counts.
They set no cookies. To tell one browser from another within a day, Vercel derives a hash from the incoming request; it is reset every 24 hours and cannot be used to recognise you tomorrow or on another site. That is the one respect in which this differs from the visitor analytics described above, and it is why it is described separately rather than folded into that section.
None of this runs on a creator's public page, or on a link redirect. If you arrive at somebody's LinkPage and click a link, you are covered by the section above and by nothing here. It is deliberately kept that way, and enforced by a test in our source code rather than by anyone remembering.
Server logs
Like every website, ours is delivered by servers that process your IP address to route the response and to defend against abuse. Our hosting and database providers keep short-lived operational logs that can contain IP addresses. We do not copy those addresses into our own database and we do not use them for analytics.
Why we are allowed to hold it
Under the GDPR and equivalent laws, our lawful bases are:
- Performance of a contract — your account and the content you publish, without which the service cannot work;
- Legitimate interests — aggregate, non-identifying page statistics so creators can see what works, understanding how the app itself is used so we can improve it, and keeping the service secure and free of abuse. We considered the impact on visitors and reduced the data collected until nothing identifies an individual.
Who else touches the data
We do not sell data and we do not share it for advertising. Ever. We rely on a small number of providers to run the service:
- Supabase — database, authentication and file storage;
- Vercel — hosting, the country code described above, and the account-area analytics described in “How we measure the app itself”;
- Google — only if you choose Google sign-in.
One third-party request happens in a visitor's browser: for links to sites we have no built-in icon for, the page loads a favicon from Google's public favicon service, which means Google sees the visitor's IP address and the site being iconified. Web fonts are self-hosted at build time, so no font request goes to Google.
These providers may process data outside your country. Transfers rely on the providers' standard contractual clauses.
How long we keep it
Analytics rows are deleted automatically 365 days after they are recorded, by a scheduled job. The app-usage measurements described in “How we measure the app itself” are held by Vercel for the reporting window of our plan, currently one month. Account and profile data is kept until you delete your account.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable form, restrict what we do with it, or object to processing based on legitimate interests. Write to TODO@example.com and we will answer within one month.
If you think we have handled your data badly, you may complain to your national data protection authority. We would rather you told us first.
Deleting your account
Account settings has a delete button. It asks you to type your handle, then removes your account, profile, links, uploaded files and analytics rows. Deletion is immediate and cannot be undone, and it frees your handle for someone else to claim.
Children
The service is not intended for children under 13, or under the minimum age of digital consent in your country where that is higher. If you believe a child has created an account, tell us at TODO@example.com and we will remove it.
Changes to this policy
If we change what we collect or why, we will update this page and its date. Material changes will be announced in the app before they take effect.
Questions about any of this? Write to TODO@example.com and a person will answer.