Lnkeee
Privacy Policy

How Lnkeee collects, uses, and protects your data

This page reflects the privacy policy content provided for Lnkeee and presents it in a more readable format for the website.

Effective Date

May 23, 2026

Last Updated

May 23, 2026

Scope

Website, dashboard, redirects, and analytics

Key privacy points

No tracking cookies on shortened link redirects

Raw IP addresses are discarded after geolocation lookup

Link data remains accessible through your dashboard and API

Section 01

Information We Collect

Account data

When you create a Lnkeee account, we collect your name, email address, password (hashed - never stored in plain text), billing information (processed via Stripe - we do not store card numbers), and company or brand name if provided.

Link and campaign data

We store all shortened URLs, destination URLs, custom slugs, tags, UTM parameters, QR code configurations, expiry settings, and campaign names you create. This data belongs to you and is accessible via your dashboard and API.

Click and visitor data (analytics)

When someone clicks one of your shortened links, we collect:

  • Timestamp of the click
  • Referring URL (the page the visitor came from)
  • Device type, operating system, and browser (user agent string)
  • Country and region (derived from IP - we do not store raw IP addresses)
  • UTM parameters appended to the destination URL

IP addresses are used only to resolve geolocation data and are immediately discarded. We do not create persistent profiles of your link visitors.

Usage and technical data

We collect standard server logs including pages visited within the Lnkeee dashboard, features used, API call patterns, error events, and session duration. This data is used solely for product improvement and security monitoring.

Section 04

Cookies & Tracking Technologies

On lnkeee.com (the website and dashboard)

  • Essential cookies: Session authentication, CSRF protection tokens. Required for the service to function. No consent needed.
  • Analytics: We use a privacy-first analytics tool (Plausible Analytics) that does not use cookies or fingerprinting. Aggregate, cookieless page views only.
  • Preference cookies: Store your UI preferences (dark mode, dashboard layout). First-party only.
  • Payment cookies: Stripe sets cookies for fraud detection during checkout. Governed by Stripe's privacy policy.

On shortened link redirects

We do not set cookies on visitors who click your shortened links. The redirect is stateless from the visitor's perspective.

Section 05

Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only in these limited circumstances:

  • Stripe - Payment processing. Card data never touches our servers.
  • AWS / Cloudflare - Infrastructure and CDN. Data processed under DPA agreements.
  • Postmark / Resend - Transactional email delivery.
  • Legal requests: We will comply with valid legal process. We will notify you if legally permitted before disclosing.
  • Business transfers: In the event of a merger or acquisition, user data may be transferred. You will be notified with an opportunity to delete your data.

All third-party processors are bound by Data Processing Agreements (DPAs) that restrict their use of your data.

Section 07

Your Rights (GDPR / CCPA)

Depending on your location, you have the following rights regarding your personal data:

  • Right to access: Request a copy of all data we hold about you.
  • Right to rectification: Correct inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data.
  • Right to data portability: Export your link data in CSV or JSON format.
  • Right to restrict processing: Limit how we use your data.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Unsubscribe from marketing emails at any time.
  • CCPA - Right to opt out of sale: We do not sell personal data, so this right is inherently satisfied.

To exercise any right, email privacy@lnkeee.com. We respond within 30 days (GDPR) or 45 days (CCPA). Identity verification may be required.

Section 08

Data Security

We implement industry-standard security measures including:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Bcrypt password hashing with per-user salts
  • Regular third-party security audits and penetration testing
  • SOC 2 Type II compliant infrastructure (AWS)
  • Two-factor authentication available on all accounts
  • Role-based access controls for internal staff

In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by GDPR Article 33.

Section 09

Children's Privacy

Lnkeee is not directed at children under 13 years of age (or under 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us at privacy@lnkeee.com and we will delete the account immediately.