LinkForge
Privacy & Data Protection

Privacy Policy

Your privacy is fundamental to how we build LinkForge. This policy outlines how we handle data with strict encryption, IP hashing, and compliance controls.

LinkForge Technologies (Sole Proprietorship), operated by Jayesh Lomate, Maharashtra, India

Last Updated: May 23, 2026GDPR & CCPA Compliant

1. Privacy Overview & Principles

LinkForge ("LinkForge", "we", "us", "our") is committed to protecting the privacy of account holders, workspace members, and visitors who interact with branded short links hosted on our edge network.

We adhere to the core principles of Data Minimization, Privacy by Design, and Cryptographic Isolation. We never sell personal data to third-party ad brokers or data aggregators.

2. Information We Collect

We collect personal data in two distinct operational contexts:

A. Account & Workspace Data (Customers)

  • Full Name and Account Email Address
  • Industry-standard one-way hashed Passwords and 2FA Verification Hashes
  • Workspace Names, Custom Domain Settings, and Brand Overlay Logos
  • Dodo Payments Customer & Subscription Metadata (excluding raw credit card details)

B. Link Redirect Analytics Data (End-User Visitors)

  • Hashed IP Addresses (Salted via PEPPER secret — raw IPs are never stored)
  • Browser User-Agent strings, Device Category, and Geolocation (Country / City level) — used for analytics and smart routing decisions. We may retain a normalized country code supplied by our trusted deployment edge at account registration for aggregate account reporting; raw signup IP addresses are not retained for that report.
  • Referrer Headers, Campaign UTM Parameters, and conversion tracking / attribution data
  • Timestamp of link redirection or QR code scan

3. IP Anonymization & Analytics Ingestion

LinkForge processes incoming link click events through a zero-knowledge IP hashing algorithm. Before click events are stored in analytics tables, raw IP addresses are hashed using a secure server-side secret (IP_HASH_PEPPER).

This ensures unique visitor counts can be computed accurately for analytics reports without maintaining identifiable IP records in database logs.

4. How We Use Your Information & Legal Bases

Under GDPR Article 6, we rely on the following lawful bases for processing:

  • Contract Performance: To provide, operate, and maintain LinkForge short link redirects, QR code engines, and process subscription payments (account data).
  • Legitimate Interest: To compute real-time aggregated campaign metrics (analytics), ensure security, and perform automated security scans.
  • Consent: To send marketing emails or promotional communications, where applicable.
  • Legal Obligation: To maintain compliance records and respond to lawful requests.

5. Third-Party Service Providers & Data Sharing

We share data only with verified sub-processors necessary for platform operation:

Cloudflare Workers & KV

Global edge routing, custom domain SSL provisioning, and caching.

Vercel

Application hosting and infrastructure.

Dodo Payments

Merchant of Record payment processing and tax invoicing.

Google OAuth

Authentication provider (receives name, email, profile picture).

Resend Email API

Transactional email delivery (account verification, 2FA codes).

Google Web Risk API

Automated destination safety and reputation scanning.

User-Configured Webhooks

If configured by workspace owners, custom endpoints may receive click and event data.

6. Your Rights (GDPR & CCPA)

Under the General Data Protection Regulation (GDPR) and similar laws, you possess the following rights:

  • Right of Access & Export: Request a copy of your personal data in a structured CSV format.
  • Right to Erasure ("Right to be Forgotten"): Request full deletion of your user account and workspace data.
  • Right to Rectification: Update inaccurate account credentials or workspace attributes.
  • Right to Restrict Processing: Pause analytics event logging for specific workspace links.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21): Object to processing of your data based on legitimate interests or direct marketing.
  • Right to Lodge Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.

To exercise any of these rights, contact our Data Protection Officer at privacy@linkforge.site.

7. California Privacy Disclosures

Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information.

  • Categories of PI Collected (Last 12 Months): Identifiers (name, email, IP address), commercial information, internet activity.
  • Sources: Directly from users, automatically from edge network analytics.
  • Business Purposes: Service provision, analytics, security, and compliance.
  • Third Parties Shared With: Verified sub-processors listed in Section 5.

We do not sell personal information.

8. Cookies, Tracking & Do Not Track

LinkForge uses first-party storage for security, authentication, and privacy-respecting analytics:

  • linkforge_session: Encrypted session token (`HttpOnly`, `SameSite=Lax`, `Secure`).
  • linkforge_csrf: Double-submit CSRF protection token.
  • lf_email_2fa: Ephemeral 2FA challenge verification token (10-minute expiry).
  • lf_visitor: A first-party analytics identifier retained for up to 12 months, created only when DNT and GPC are not enabled.

Creator Pages use a session-scoped first-party identifier for unique analytics. We do not use third-party cross-site tracking cookies or ad-retargeting pixels.

Browser privacy signals: LinkForge respects Do Not Track (DNT) and Global Privacy Control (GPC) signals and does not collect link, QR, CTA, or Creator Page analytics when either signal is enabled.

9. Automated Decision-Making

Under GDPR Article 22, we disclose that link safety scanning is automated via Google Web Risk API. However, human review is available upon request if a link is incorrectly flagged or disabled.

10. Children's Privacy

Our services are not directed to individuals under the age of 16 (COPPA compliance). If we discover an account belongs to someone under 16, it will be immediately terminated and all associated data deleted.

11. Data Retention & Security Measures

Account data is retained for the duration of the account plus 30 days. Analytics data is retained according to your plan tier (90 days by default). Inactive account data is pruned during automated daily cleanup runs. Upon an erasure request, data is deleted within 30 days.

All communication between your browser, edge nodes, and database servers is encrypted in transit using TLS 1.3 and encrypted at rest using industry-standard cryptographic hashing.

12. International Data Transfers

LinkForge operates a globally distributed edge network. Data is processed in the US (Vercel), via our global edge network (Cloudflare), and in India (company operations). Data transferred outside your region is protected under Standard Contractual Clauses (SCCs) and compliant cloud hosting agreements.

13. Changes to this Policy

We may update this Privacy Policy periodically. For material changes, we will notify you at least 30 days in advance via the email address associated with your account.

14. Privacy Contact & DPO

If you have any questions or privacy requests, please contact our Data Protection Officer:

Data Protection Officer (DPO)

Email: privacy@linkforge.site

Legal Team: legal@linkforge.site