Privacy Policy
Your privacy is fundamental to how we build LinkForge. This policy outlines how we handle data with strict encryption, IP hashing, and compliance controls.
LinkForge Technologies (Sole Proprietorship), operated by Jayesh Lomate, Maharashtra, India
1. Privacy Overview & Principles
LinkForge ("LinkForge", "we", "us", "our") is committed to protecting the privacy of account holders, workspace members, and visitors who interact with branded short links hosted on our edge network.
We adhere to the core principles of Data Minimization, Privacy by Design, and Cryptographic Isolation. We never sell personal data to third-party ad brokers or data aggregators.
2. Information We Collect
We collect personal data in two distinct operational contexts:
A. Account & Workspace Data (Customers)
- Full Name and Account Email Address
- Industry-standard one-way hashed Passwords and 2FA Verification Hashes
- Workspace Names, Custom Domain Settings, and Brand Overlay Logos
- Dodo Payments Customer & Subscription Metadata (excluding raw credit card details)
B. Link Redirect Analytics Data (End-User Visitors)
- Hashed IP Addresses (Salted via PEPPER secret — raw IPs are never stored)
- Browser User-Agent strings, Device Category, and Geolocation (Country / City level) — used for analytics and smart routing decisions. We may retain a normalized country code supplied by our trusted deployment edge at account registration for aggregate account reporting; raw signup IP addresses are not retained for that report.
- Referrer Headers, Campaign UTM Parameters, and conversion tracking / attribution data
- Timestamp of link redirection or QR code scan
3. IP Anonymization & Analytics Ingestion
LinkForge processes incoming link click events through a zero-knowledge IP hashing algorithm. Before click events are stored in analytics tables, raw IP addresses are hashed using a secure server-side secret (IP_HASH_PEPPER).
This ensures unique visitor counts can be computed accurately for analytics reports without maintaining identifiable IP records in database logs.
4. How We Use Your Information & Legal Bases
Under GDPR Article 6, we rely on the following lawful bases for processing:
- Contract Performance: To provide, operate, and maintain LinkForge short link redirects, QR code engines, and process subscription payments (account data).
- Legitimate Interest: To compute real-time aggregated campaign metrics (analytics), ensure security, and perform automated security scans.
- Consent: To send marketing emails or promotional communications, where applicable.
- Legal Obligation: To maintain compliance records and respond to lawful requests.
5. Third-Party Service Providers & Data Sharing
We share data only with verified sub-processors necessary for platform operation:
Global edge routing, custom domain SSL provisioning, and caching.
Application hosting and infrastructure.
Merchant of Record payment processing and tax invoicing.
Authentication provider (receives name, email, profile picture).
Transactional email delivery (account verification, 2FA codes).
Automated destination safety and reputation scanning.
If configured by workspace owners, custom endpoints may receive click and event data.
6. Your Rights (GDPR & CCPA)
Under the General Data Protection Regulation (GDPR) and similar laws, you possess the following rights:
- Right of Access & Export: Request a copy of your personal data in a structured CSV format.
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your user account and workspace data.
- Right to Rectification: Update inaccurate account credentials or workspace attributes.
- Right to Restrict Processing: Pause analytics event logging for specific workspace links.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): Object to processing of your data based on legitimate interests or direct marketing.
- Right to Lodge Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.
To exercise any of these rights, contact our Data Protection Officer at privacy@linkforge.site.
7. California Privacy Disclosures
Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information.
- Categories of PI Collected (Last 12 Months): Identifiers (name, email, IP address), commercial information, internet activity.
- Sources: Directly from users, automatically from edge network analytics.
- Business Purposes: Service provision, analytics, security, and compliance.
- Third Parties Shared With: Verified sub-processors listed in Section 5.
We do not sell personal information.
9. Automated Decision-Making
Under GDPR Article 22, we disclose that link safety scanning is automated via Google Web Risk API. However, human review is available upon request if a link is incorrectly flagged or disabled.
10. Children's Privacy
Our services are not directed to individuals under the age of 16 (COPPA compliance). If we discover an account belongs to someone under 16, it will be immediately terminated and all associated data deleted.
11. Data Retention & Security Measures
Account data is retained for the duration of the account plus 30 days. Analytics data is retained according to your plan tier (90 days by default). Inactive account data is pruned during automated daily cleanup runs. Upon an erasure request, data is deleted within 30 days.
All communication between your browser, edge nodes, and database servers is encrypted in transit using TLS 1.3 and encrypted at rest using industry-standard cryptographic hashing.
12. International Data Transfers
LinkForge operates a globally distributed edge network. Data is processed in the US (Vercel), via our global edge network (Cloudflare), and in India (company operations). Data transferred outside your region is protected under Standard Contractual Clauses (SCCs) and compliant cloud hosting agreements.
13. Changes to this Policy
We may update this Privacy Policy periodically. For material changes, we will notify you at least 30 days in advance via the email address associated with your account.
14. Privacy Contact & DPO
If you have any questions or privacy requests, please contact our Data Protection Officer: