1. Scope, Roles, and Information We Collect
This Privacy Policy applies to people who visit Linkrise pages, create or manage a Linkrise account, publish a public profile, interact with a public profile, contact us, or use a free or paid plan.
For most Linkrise product operations, Linkrise decides why and how information is processed and acts as the controller. When a creator publishes content or chooses to collect information from visitors through their own links or third-party destinations, that creator or third party may be responsible for their own processing.
We collect information needed to provide, secure, support, and improve Linkrise.
- Account information, such as name, email address, authentication provider, username, plan, and account settings
- Profile and Studio content, such as display name, bio, avatar, cover image, wallpaper, links, text blocks, media assets, social/contact links, theme choices, and public profile slug
- Usage and analytics data, such as page views, link clicks, timestamps, referrer, device/browser metadata, product events, and service logs
- Billing status data, such as plan, subscription status, checkout identifiers, provider customer or subscription IDs, trial dates, payment status, and billing event metadata
- Support and legal communications you send to us
Instagram DM Automation and Meta
If a creator connects an Instagram Business or Creator account, Linkrise receives and stores the professional account ID, display name, account type, granted permissions, encrypted access token and expiry, plus the automation names, keywords, and reply text the creator configures.
When an Instagram user messages that account, Meta sends Linkrise a webhook that can contain the message text, message ID, and an Instagram-scoped sender ID. Linkrise reads the text transiently to select one keyword rule and sends the creator's configured reply through Meta. Linkrise does not persist the raw incoming DM text or raw sender ID.
For delivery safety and recent aggregate reporting, Linkrise retains hashed sender and message delivery identifiers, the matched rule, outcome or bounded error, and timestamps for up to 30 days. Connected-account metadata and automation rules remain while needed to operate or reconnect the integration.
Disconnecting immediately pauses automations and stops new event persistence. Linkrise asks Meta to unsubscribe and removes the encrypted access token and scopes after success or a documented terminal-invalid credential. If Meta has a transient failure, the disabled integration retains only the encrypted credential needed for the 15-minute retry until unsubscribe completes. Account metadata and rules remain for reconnection; disconnecting is not the same as deleting a Linkrise account. A verified Meta data-deletion request or Linkrise account deletion removes integration-linked data, subject to limited backup, security, legal, or dispute exceptions. Meta processes information under its own policies, and creators remain responsible for their reply content, notices, permissions, and applicable messaging rules.
2. Public Profile Information
Content you publish to a Linkrise public profile is public by design. Anyone with access to your public profile URL may view your profile content, links, social/contact destinations, and visible media.
Published profiles are searchable by default and may be indexed by search engines, shown in social previews, cached by browsers or third-party services, or referenced by tools that discover public web pages. Linkrise may remove a profile from search discovery for moderation, legal, safety, or account-deletion reasons. Removing content from Linkrise may not remove copies already saved outside our control.
Linkrise may feature the visible layout, text, and rendered public media from a published profile in product examples, education, showcase pages, case studies, screenshots, or service marketing. We do not use private drafts or Studio-only data for those materials. Do not publish sensitive personal data or another person's personal information unless you have permission and a lawful basis to do so.
When a visitor clicks an outbound link, opens a third-party embed, or interacts with a destination outside Linkrise, that third party controls its own privacy practices. Review the privacy terms of destinations you choose to visit or publish.
Do not publish personal data, confidential information, or third-party content unless you have the right to make it public.
3. Payments Through Paddle
Paid plans are processed through Paddle. Paddle acts as merchant of record for purchases made through its checkout and processes payment details, tax/VAT information, receipts, invoices, refunds, chargebacks, and customer portal billing actions.
Linkrise does not need to store full card numbers or sensitive payment credentials. We receive limited billing and subscription information from Paddle so we can activate, renew, downgrade, cancel, or support your plan.
4. How We Use Information
We use information for the purposes below.
Where a legal basis is required, we generally rely on performance of a contract to provide Linkrise, legitimate interests to secure and improve the service, legal obligations for tax/accounting/compliance, and consent where we specifically ask for it.
- Create and operate your account, Studio, Studio drafts, and public profile
- Publish, host, optimize, and display profile content and uploaded media
- Resize, compress, convert, and store optimized image derivatives, including WebP versions, instead of retaining or serving original uploaded image files
- Provide analytics, quota enforcement, plan entitlements, billing status, and customer support
- Protect against fraud, phishing, malware, spam, abuse, unauthorized access, and service disruption
- Debug, maintain, measure, and improve the product
- Comply with legal, tax, accounting, dispute, and platform safety obligations
5. Analytics, Logs, and IP Handling
We collect product analytics and public profile analytics to help creators understand performance and to keep the service reliable. Analytics may include profile views, link clicks, device/browser metadata, timestamps, and referrer information.
We aim to minimize sensitive data. Rate-limit and abuse controls should use privacy-preserving keys where practical, and raw IP addresses should not be retained longer than necessary for security, debugging, or legal needs.
6. Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember locale and product preferences, protect against abuse, and support checkout or authentication flows.
Linkrise currently does not use advertising cookies or third-party marketing trackers. See the Cookie Policy for more detail.
You can manage cookies through your browser settings. Some Linkrise features may not work correctly if required cookies are disabled.
7. Sharing and Service Providers
We do not sell your personal information. We may share limited information with trusted providers that help us operate Linkrise, such as hosting, storage, authentication, email, analytics, abuse prevention, payment processing, and customer support providers.
We may disclose information if required by law, to enforce our Terms, to prevent harm or fraud, to respond to lawful requests, or in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.
8. Data Retention and Deletion
We retain information for as long as needed to provide Linkrise, maintain security, resolve disputes, comply with legal/accounting obligations, and enforce our agreements. Retention periods vary by data type and operational need.
If you request account deletion, we will delete or anonymize account and profile data unless retention is required for legal, security, billing, tax, backup, or dispute reasons. Public content may disappear from Linkrise after deletion, but copies may remain in third-party caches or services outside our control.
- Account and profile data: retained while the account is active and for a limited period needed for recovery, legal, security, or dispute handling after deletion.
- Billing and tax records: retained as required by payment, tax, accounting, refund, chargeback, and compliance obligations.
- Analytics and usage data: retained according to plan-aware retention settings and may be aggregated or anonymized for product reporting.
- Security logs and abuse records: retained only as long as reasonably necessary to protect Linkrise, users, and the public.
- Backups: deleted or overwritten on normal backup cycles unless preservation is required for legal, security, or incident reasons.
9. Your Rights and Choices
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal data. You may also have rights to withdraw consent where processing is based on consent.
Contact us through the support email listed below to submit a privacy request. Include the email address or profile URL connected to your request and the right you want to exercise.
We may need to verify your identity before completing the request. Where a privacy law sets a response deadline, we aim to respond within the applicable period, such as 45 days for many U.S. state privacy requests, unless an extension is allowed.
10. Regional Privacy Notes
Where applicable, Linkrise handles privacy requests in a way intended to map to local data protection rights. Availability of a UI locale does not by itself mean a dedicated market launch or local establishment.
- Indonesia: users may request access, correction, deletion, withdrawal or objection where applicable, and data portability where supported by law and product capability.
- Philippines: users may exercise rights such as being informed, access, objection, rectification, erasure or blocking, portability, complaint, and damages where available under applicable law.
- Brazil: users may exercise LGPD rights such as confirmation, access, correction, anonymization, blocking or deletion, portability, information about sharing, and review of certain automated decisions where applicable.
- Taiwan: users may request inquiry, review, copies, supplementation or correction, discontinuation of collection/processing/use, and deletion where applicable.
- Global English users may have additional rights under laws such as GDPR, UK GDPR, state privacy laws, or consumer protection rules depending on location.
- United States: if a state privacy law applies, users may have rights to know, access, correct, delete, portability, non-discrimination, and opt out of targeted advertising, sale, or sharing. Linkrise currently does not sell personal information, share personal information for cross-context behavioral advertising, or use targeted advertising cookies.
11. International Transfers
Linkrise and our providers may process information in countries other than where you live, including countries where our hosting, database, storage, authentication, analytics, email, support, and payment providers operate.
When required, we use reasonable safeguards intended to protect information across jurisdictions, such as provider data processing terms, contractual protections, security controls, and limiting provider access to what is needed for the service.
12. Security, Complaints, and Children
We use technical and organizational safeguards designed to protect information, but no online service can guarantee perfect security.
If you have a privacy complaint, contact us through the support email listed below. We will review the complaint and may ask for more information so we can investigate. Depending on where you live, you may also have the right to contact a local data protection or consumer privacy authority.
Linkrise is not intended for children under 13 or the minimum age required in your jurisdiction. Users under 18 should use Linkrise only with permission from a parent or legal guardian, and paid plan purchases must be made by an adult or someone with legal authority to pay. If you believe a child provided personal information to us, contact us so we can take appropriate action.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the last updated date.
Detailed Retention Schedule and Account Deletion
Account, profile, Studio, connected-account, and billing-status data is kept while needed to provide the service. A confirmed account-deletion request immediately unpublishes the public profile and starts a fail-closed cleanup of connected providers, stored assets, and the account. A minimal completion record that does not contain the account email or profile content may remain to prove that the request completed and to prevent replay.
Backups may retain encrypted residual copies until the applicable provider backup cycle overwrites them. Those copies are isolated from ordinary product use, and a restored backup must have completed deletion requests reapplied. Legal, tax, chargeback, security, fraud, and dispute records may be kept longer only where reasonably necessary or required by law.
- Raw public-profile analytics events: 7 days on Free, 90 days on legacy Plus, and 180 days on Pro; daily aggregate metrics remain until the related profile or account is deleted.
- Instagram automation delivery records and minimized webhook summaries: up to 30 days. Raw incoming DM text and raw sender IDs are not retained.
- Expired billing checkout intents: 7 days after expiry. Product paywall events: up to 365 days.
- Minimized billing webhook payload summaries: up to 365 days. Event identity and timestamps may remain after payload removal where needed to prevent replay, investigate payment disputes, and maintain billing integrity.
- Expired rate-limit records are removed after their reset window. Unreferenced Studio assets are eligible for cleanup after a minimum 24-hour safety window.
Contact Form Submissions
When you submit a contact form on a published profile, Linkrise processes your email address and, where the profile owner has enabled them, your name and message. We also keep the submission time, the profile and form involved, and the consent version and language shown to you.
The submission is made available to the owner of that profile, including through a downloadable CSV export, so they can respond to your request. Contact consent does not by itself permit the profile owner to send marketing. The profile owner is independently responsible for using exported information lawfully and keeping it secure.
- Contact submissions are retained for up to 180 days and are deleted sooner when the related profile or account is deleted.
- Rate-limit records used to prevent spam expire after their reset window. Linkrise does not store a raw IP address with the contact submission.
- Do not submit passwords, payment credentials, government identifiers, health information, or other unnecessary sensitive data through a profile contact form.
Service Providers and International Processing
This table identifies the principal service providers that process personal data to operate Linkrise. Locations describe normal processing regions; they are not physical data-center addresses or a promise that every transient network route remains there.
When personal data is processed outside your country, Linkrise uses provider data-processing terms and legally recognized transfer safeguards where required. Linkrise does not claim single-country storage unless a provider contract expressly guarantees it.
- Purpose
- Authentication
- Processing location
- Global
Paddle
- Purpose
- Merchant-of-record billing and transaction support
- Processing location
- United Kingdom, United States, Canada, and other transaction locations
Vercel
- Purpose
- Application hosting, request processing, and delivery
- Processing location
- Singapore (primary application runtime), United States, and global edge locations
Neon
- Purpose
- Production database hosting and backup
- Processing location
- United States provider operations and the cloud region selected for the production project
Cloudflare
- Purpose
- Object storage, asset delivery, DNS, and security
- Processing location
- Global network and the automatically selected R2 bucket location; no single-country restriction
Sentry
- Purpose
- Error and performance monitoring
- Processing location
- United States
Zoho Mail
- Purpose
- Support, legal, and privacy email
- Processing location
- United States
| Provider | Purpose | Processing location |
|---|---|---|
| Authentication | Global | |
| Paddle | Merchant-of-record billing and transaction support | United Kingdom, United States, Canada, and other transaction locations |
| Vercel | Application hosting, request processing, and delivery | Singapore (primary application runtime), United States, and global edge locations |
| Neon | Production database hosting and backup | United States provider operations and the cloud region selected for the production project |
| Cloudflare | Object storage, asset delivery, DNS, and security | Global network and the automatically selected R2 bucket location; no single-country restriction |
| Sentry | Error and performance monitoring | United States |
| Zoho Mail | Support, legal, and privacy email | United States |