Privacy Policy
Last updated: Last updated: 9 August 2026
1. Data controller
The data controller for linq-io.com is Alin Ceușan, an individual based in Romania. Contact for privacy matters: [email protected].
2. What we collect
Only what the product actually needs:
- Account data: your name, email address, username and password — stored only as a cryptographic hash, never in plain text.
- Anonymous view and click stats on public pages: the referring domain (e.g. “instagram.com”) and an approximate country supplied by our hosting infrastructure. We store no IP addresses, set no tracking cookies and do no fingerprinting — the stats cannot be tied back to a person.
- Your page content: title, bio, links and the theme you picked — everything you choose to publish.
3. Cookies
We use strictly necessary cookies only, for authentication (your dashboard session). Public profile pages set no cookies at all for visitors.
4. Purposes and legal basis
We process your account data (name, email, username, password hash) to provide the service — the legal basis is the performance of our contract with you (art. 6(1)(b) GDPR). We process anonymous page statistics (referrer domain and country of visitors, with no IP address, no cookies and no device fingerprinting) based on our legitimate interest in showing creators how their pages perform (art. 6(1)(f) GDPR). We send account emails (verification, password reset) as part of the contract; we do not send marketing emails without separate consent (art. 6(1)(a) GDPR).
5. Who we share data with
We use a small number of infrastructure providers acting as processors: Vercel (hosting and image storage, EU/US — Standard Contractual Clauses for any US transfer), Neon (database, EU region), Resend (transactional email), and Cloudflare (DNS and email routing). We do not sell your data and we do not share it with advertisers.
6. How long we keep it
Your account data is kept until you delete your account, at which point it is removed along with your pages, links and statistics (cascade deletion). Visitor statistics contain no personal identifiers and are kept in aggregate form for as long as the related page exists. Operational logs and backups held by our infrastructure providers expire on their standard schedules (typically 30 days or less).
7. Your rights
Under the GDPR you have the right to access, rectify, export and erase your data, to restrict or object to processing, and to lodge a complaint with a supervisory authority (in Romania: ANSPDCP, dataprotection.ro). You can exercise most rights directly from your account settings (including full account deletion); for anything else, write to [email protected] and we will respond within 30 days.
8. Security
Passwords are stored only as hashes, connections are encrypted end to end (TLS), and database access is restricted.
9. Changes to this policy
We'll announce material changes to this policy on the site and, where appropriate, by email.