Effective Date: January 17, 2026 Last Updated: October 6, 2026
Introduction
LinkTaps ("we," "our," or "us") is a minimal link redirect service that operates on a privacy-first principle. We are committed to collecting only the minimum amount of data necessary to provide our service and comply with legal requirements.
This Privacy Policy explains what information we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.
Our Commitment to Minimal Data Collection
LinkTaps is designed from the ground up to minimize data collection. We:
- Do NOT store email body content
- Do NOT use non-essential cookies or tracking cookies
- Do NOT store uploaded CSV files
- Do NOT fingerprint users
- Do NOT sell or share your data with third parties for marketing purposes
Our Commitment to Minimal Permissions
Unlike most services that request broad access to your social media accounts upfront, LinkTaps only requests the specific permissions absolutely required for the features you choose to use. We believe you should have full control over what access you grant.
- Granular permission requests: When you first connect, we request only the permissions required for the feature you chose to set up. If you set up DM or comment automations, we request comment monitoring and messaging permissions. If you set up Upload and Publish, we request only publishing permissions. Additional permissions like insights or content management are only requested when you explicitly enable those features.
- Incremental scope upgrades: You can expand permissions one at a time as you need them. Each upgrade clearly explains what new access is being requested and why.
- Multiple connection methods: You choose how to connect -- via Facebook Login for Business (recommended, with never-expiring system tokens), traditional Facebook OAuth, or Instagram Business Login. Each method offers different permission configurations suited to your needs.
- Full transparency: Your current permissions are visible in Settings at all times, and you can disconnect or revoke access at any point.
Data Controller
LinkTaps acts as the data controller for the personal data we collect through our service.
Contact Information: Email: support@linktaps.io
1. Information We Collect
1.1 Information You Provide Directly
Account Information:
- Email address (required for passwordless authentication)
- Creator username/slug (optional, for custom branded short links on shared domain)
- Custom domain names (optional, if you choose to use your own domain)
Link/Campaign Data:
- Short link slugs (the custom path in your short URLs)
- Destination URLs (where your short links redirect to)
- iOS and Android deep link URLs (optional, for mobile app redirects)
Link-in-Bio Data:
- The links, text, images, headings, and customization (colors, layout) for your Link-in-Bio landing page hosted on LinkTaps
- Optional header image you upload for the Link-in-Bio page
- Display name and bio text you choose to show on the page
Feedback and Support:
- Messages you send through our feedback form
- Associated campaign or URL context (if provided)
CSV Import Data:
- Campaign data you upload via CSV (slugs, URLs, deep links)
- Note: CSV files are processed in-memory and are NOT stored on our servers
1.2 Information Collected Automatically
Click Analytics (for your links): When someone clicks on your short link, we collect:
- Device type (mobile, desktop, tablet)
- Operating system (iOS, Android, Windows, macOS, Linux)
- Browser type
- Whether the click came from an in-app browser (and which app browser: Facebook, Instagram, TikTok, etc.)
- User agent string
- HTTP referrer (the website they came from)
- Country (derived from IP address via geolocation)
- Timestamp of the click
- Click identifier (clickid) - A temporary, unique identifier for a single click. We use it to provide accurate analytics about verified transitions from in-app browsers to external browsers. We also add it to the address of the link's destination, so that the link's owner can attribute what happens next (for example, an app install) to that click. It is not used to track users across sessions or for any other purpose. If the visitor's browser sends a Global Privacy Control or Do Not Track signal, we do not add a click identifier to the destination, and we do not create one at all unless the click came from an in-app browser.
App install and open reports (for your links): If you use install attribution, your app-attribution provider (such as Branch or AppsFlyer) or your app can tell us that a click on your link led to an install or an open of your app. For each report we store:
- The click identifier of the click it belongs to
- The event (install or open)
- When the click happened and when we received the report, and, if the report says, when the event happened
- Whether it came from your provider or from your app, the provider's name, and whether the report said it was the app's first session
A report contains no device identifier. Of what a report sends us, we read and store only the fields above; we do not store an advertising identifier (IDFA or GAID), IP address or user ID it carries. A report is kept as long as the click it belongs to: after 37 calendar months both are folded into daily totals, which keep counts and no click identifiers. A report is deleted sooner when the link, the Domain LinkTaps site or its workspace is permanently deleted.
When your provider reports a click that we cannot match to one of your links, we count it per workspace, day, event and reason, so that you can see a broken integration. These counts hold no visitor data and are kept 400 days.
IP Addresses:
- We collect IP addresses for geolocation (to determine country, and — for links that route by location — approximate region/province) and security purposes
- Approximate region/province is used only to route a visitor's current request to the correct destination; it is NOT stored (only country is retained in click analytics)
- IP addresses are NOT stored long-term for analytics purposes
- We do NOT track individual users across sessions using IP addresses
Bot Filtering:
- We automatically exclude known bot and crawler traffic (such as Facebook's link preview crawler and GPTBot) from analytics to ensure accurate click counts
- These automated requests are not logged or tracked
Web Analytics (Cloudflare Web Analytics):
- We use Cloudflare Web Analytics to understand how our website (not your links) is used
- Cloudflare Web Analytics does NOT use cookies
- It collects: page views, referrer information, browser type, and country
- Data is aggregated and anonymized
- See Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/
1.3 Cookies
We set no marketing, advertising or cross-site tracking cookies, and no third party sets cookies through our service. Every cookie below is first-party: it is set by the site you are on, and only for the feature described.
On linktaps.io, when you use the LinkTaps app:
Session Cookie (__sid):
- Purpose: Maintains your authenticated session after passwordless login
- Type: Essential/Strictly Necessary (does NOT require consent under GDPR)
- Duration: 90 days after your last activity (each visit moves the expiry forward), or until you log out
- Attributes: HttpOnly, Secure (HTTPS only in production), SameSite=Lax
- Domain: linktaps.io
Device Cookie (__did):
- Purpose: Recognises a browser you have signed in from before, so we can email you when a sign-in comes from a new device (account security). It holds a random value and is kept after you log out.
- Duration: 2 years
- Attributes: HttpOnly, Secure (HTTPS only in production), SameSite=Lax
Connection Cookie (lt_oauth_bind):
- Purpose: Set only while you connect a Facebook, Instagram or Threads account. It ties Meta's reply to the browser that started the connection, so a connection cannot be completed from another browser.
- Duration: 10 minutes
AI Assistant Sign-in Cookie (__mcp_authz):
- Purpose: Set only when you authorise an AI assistant to use your account and need to sign in first. It remembers the authorisation page to return you to.
- Duration: 10 minutes
On LinkTaps short links, when someone clicks one:
These cookies are short-lived, HttpOnly and SameSite=Lax. They are used only to count one click once and to carry that click out of an in-app browser (such as Instagram's). None of them lasts longer than 10 minutes, and none identifies a visitor across visits.
lt_c(5 seconds, in-app browsers and the browser a tap is carried out to): the click identifier of this click, so the same tap in an in-app browser, and its arrival in the external browser after leaving the in-app browser, is not counted twice
otandlt_oclk(120 seconds, in-app browsers only): recognise the same tap when it returns after leaving the in-app browser
lt_comb_pending(90 seconds, multi-button pages in an in-app browser): carries the tap through the same move
lt_comb_priority_seen(10 minutes, multi-button pages with a featured button): so the featured button opens only once
lt_bio_t(15 seconds, link-in-bio pages): so a link preview fetched by the app and the real tap count as one visit
On websites that use the LinkTaps snippet (Domain LinkTaps): the snippet sets no cookie.
Internal: lt_vdebug (30 days) is set only on devices of LinkTaps staff who unlock the debug console with a secret token. It is never set for visitors.
We do NOT use:
- Marketing cookies
- Advertising cookies
- Social media tracking cookies
- Third-party tracking cookies
The cookies we set on linktaps.io and on short links are strictly necessary for the features described, so you will not see a cookie consent banner on our site.
1.4 Information We Do NOT Collect or Store
- Email body content - We use a metadata-only email logging system for SOC 2 and GDPR compliance. We store only: recipient email, subject line, email type, timestamp, and delivery status. We do NOT store login codes, magic link URLs, or message content.
- Uploaded files - CSV files are processed in-memory and immediately discarded after processing
- Passwords - We use passwordless authentication (magic links and login codes)
- Payment card details - Card numbers, CVV, and expiration dates are entered directly into Stripe's hosted checkout/portal — they never reach our servers. We only store the Stripe customer/subscription ID and billing-period dates needed to verify Pro access.
- Precise geolocation - We do NOT collect GPS, street-, or city-level location. We derive only approximate location — country, and (where available) region/province — from IP addresses, used to route visitors and provide country-level analytics
1.5 Social Media Automation and Meta Platform Data
LinkTaps includes optional automation features that integrate with Facebook and Instagram through the Meta Platform APIs. This section describes what data we collect, how we use it, and how you can delete it.
Minimal Permission Model
We request only the Meta permissions strictly necessary for the features you activate. When you first connect, we request only the permissions required for the feature you chose to set up -- comment monitoring and messaging if you set up DM or comment automations, or publishing permissions if you set up Upload and Publish. Permissions for insights, content management, or other capabilities are never requested until you explicitly choose to enable those features. You can see exactly which permissions have been granted at any time in Settings > Connected Accounts, and you can upgrade or revoke permissions individually. This gives you complete control over what LinkTaps can and cannot do with your accounts -- a level of granularity that most automation services do not offer.
What We Collect via Meta APIs
When you connect a Facebook Page or Instagram account to LinkTaps, and when users interact with your connected posts, our system may receive the following data:
- Public profile information -- The name, username, and profile picture of people who comment on your connected posts, as displayed publicly on their comments.
- Comment content -- The text of comments posted on your connected Facebook and Instagram posts.
- Direct message content -- The text of direct messages sent to your connected Facebook Pages and Instagram pages, used to match the keywords you configure, trigger the auto-reply you set up, and let you read and answer conversations in your LinkTaps inbox. If you turn on AI replies to direct messages, or ask for a suggested reply in the inbox, the message and the earlier messages in that conversation are also sent to a third-party AI provider to suggest a reply (see "AI-Powered Replies and Third-Party AI Processing" below). DM content is stored while the account is connected and is not used for any other purpose. If you disconnect the account, its messages are kept for 180 days after you disconnect it, so that reconnecting the account restores your inbox, and are then permanently deleted; a conversation that another account still connected to the same workspace can take over is kept with that account rather than deleted. They are deleted sooner if you delete your Meta data (see "Deleting Your Meta Data" below), if the workspace is deleted (once its 30-day restore window ends), or if you delete your LinkTaps account (for the workspaces you own).
- User ID -- A Meta-assigned, platform-scoped identifier used solely to send a direct message in response to a comment.
- Post metadata -- Captions, media URLs, thumbnails, and permalinks of posts you choose to monitor.
- Page and account identifiers -- Facebook Page IDs, Page names, Instagram account IDs, and Instagram usernames for accounts you connect.
- Engagement insights -- Post-level metrics such as likes, comments, shares, saves, reach, and impressions (only if you grant the Insights permission).
We do not collect email addresses, phone numbers, friend lists, or any private data beyond what is listed above through the Meta APIs.
How We Use Meta Platform Data
We use the data described above exclusively to:
- Detect comments on your connected posts that match keywords you configure.
- Send a direct message (via Instagram DM or Facebook Messenger) containing the reply you configured for that keyword.
- Post a public reply to a comment as a fallback if a direct message cannot be delivered.
- Generate AI-powered replies based on your knowledge base, when you enable the AI Replies feature (see Section 1.6).
- Publish content (images, videos, carousels) to your connected Facebook Pages and Instagram accounts, when you use the Upload and Publish feature.
- Display engagement insights and analytics for your connected posts, when you grant Insights permissions.
Real-time processing. When Meta sends us a webhook notification about a new comment or direct message on your connected account, our application server processes it in real time: it matches it against your keyword rules, sends any configured replies, and records the activity in our database for your activity log and to prevent duplicate replies. Our application logs (see section 4) record that an event was processed; we keep the text of comments and messages, and the names, usernames and IDs of the people who wrote them, out of those logs.
Profile picture fetching. When you choose to pull a profile picture from a social media platform during account setup, we fetch the publicly available profile page to extract the image URL. Our application server makes this request directly, and no login credentials or private data are accessed. The fetched image is stored in Cloudflare R2 as your profile picture.
We do not use Meta Platform Data for advertising, profiling, selling, or any purpose other than providing the automation and publishing features you configure.
Storage and Retention of Meta Platform Data
| Data Type | Retention | Purpose |
|---|---|---|
| Comment IDs (dedup cache) | 7 days | Prevents duplicate replies to the same comment |
| Reply review queue (AI replies waiting for your review, sent, rejected or not answered, with the comment or message each one answers) | 90 days after the reply was queued | Reviewing AI replies before they are sent, and showing the questions the AI could not answer |
| Activity log (commenter name, comment text, reply sent, action taken) | Until you delete it, or 180 days after the account is disconnected | Audit trail for your automation activity |
| Post metadata (caption, media URL, permalink) | Until you deactivate or delete the post, or 180 days after the account is disconnected | Monitoring and rule matching |
| Keyword rules and DM rules | Until you delete them, or 180 days after the account is disconnected | Automation configuration |
| Direct messages and conversations | While the account is connected; 180 days after you disconnect it; a conversation that another account still connected to the same workspace can take over is kept with that account rather than deleted | Your inbox, and keyword matching for DM automations |
| Repost queue | While the account is connected; 180 days after you disconnect it | Scheduling the reposts you set up |
| Connected account tokens | Until you disconnect the account | API access for automation and publishing |
| Disconnected accounts (the account's identity and automation setup, without its tokens) | 180 days after you disconnect, then permanently deleted; we email the workspace owner 14 days before if the account still has an automation, or 10 or more conversations or queued reposts | So that reconnecting restores your setup |
| Publish job records | Until you delete them | Publishing status tracking |
You can delete all Meta Platform Data stored by LinkTaps at any time:
- In the dashboard: Go to Settings > Workspace and choose Reset Meta Integration (available to the workspace's owner and admins). This permanently deletes the Meta data the workspace holds for every account connected to it now or disconnected in the last 180 days: account records, direct messages and conversations, the repost queue, monitored posts, rules, activity logs and queued replies. Your uploads, publish history, AI knowledge base and settings, campaigns and analytics are not affected. Deletion runs in the background, and you receive a confirmation code and a link to its status.
- Through Meta: If you remove LinkTaps from your Facebook settings and ask for your data to be deleted, Meta sends us a deletion request. We delete Meta data for every account connected with that login, in any LinkTaps workspace, including accounts disconnected in the last 180 days, and Meta gives you a confirmation code and a link to its status. Data on an account you later connected separately, for example through Instagram Login, stays with that account. To delete it now, use Reset Meta Integration in Settings > Workspace, which deletes the Meta data of every account in the workspace. Disconnecting that account instead keeps its data for 180 days and then deletes it.
- Disconnect individual accounts: Click Disconnect on an account in Settings. We stop taking in new data from it and delete its access tokens at once. Its automations, messages and repost queue are kept for 180 days so that reconnecting the account to the same workspace restores them, and are then permanently deleted; a conversation that another account still connected to the same workspace can take over is kept with that account rather than deleted. Reconnecting it to a different workspace does not bring them back.
- By email: Contact support@linktaps.io to request deletion.
When you disconnect an account connected through Facebook Login, we also attempt to revoke its permissions on Meta's side, unless that would also cut off other accounts still connected to LinkTaps with the same Facebook login. Disconnecting does not end the permissions of accounts connected through Facebook Login for Business, Instagram login or Threads; only Meta can, when you remove LinkTaps there: in Business Suite > Settings > Integrations > Connected Apps for Facebook Login for Business, in your Instagram settings on instagram.com for Instagram login, and in Settings > Website Permissions on threads.com for Threads. Resetting the Meta integration does not revoke permissions on Meta's side; to end them, disconnect accounts connected through Facebook Login first, or remove LinkTaps in your Facebook settings or in the places above.
1.6 AI-Powered Replies and Third-Party AI Processing
When you enable the AI Replies feature, comment text and commenter context from your connected posts may be sent to a third-party AI provider (OpenRouter) for processing. This is used solely to generate a relevant reply based on the knowledge base you configure.
- What is sent: The comment text, a summary of your knowledge base entries, and your custom AI instructions.
- What is NOT sent: Commenter names, user IDs, email addresses, or any personally identifiable information about the commenter.
Direct messages are sent to the AI provider too, when you use AI for them. If you turn on AI replies to direct messages, each incoming direct message is sent to OpenRouter to decide whether your knowledge base answers it and to write the reply. If you ask for a suggested reply in your LinkTaps inbox, the latest message is sent in the same way.
- What is sent: The text of the message, the text of earlier messages in the same conversation (both theirs and yours), a summary of your knowledge base entries, and your custom AI instructions.
- What is NOT sent: The sender's name, username, user ID or profile picture. The message text is sent as written, so anything the sender typed into it, including personal information, reaches the provider.
- Provider: OpenRouter (https://openrouter.ai). See their privacy policy at https://openrouter.ai/privacy.
- Retention by provider: We do not control data retention by OpenRouter. Consult their privacy policy for details.
You can disable AI replies at any time from the AI Replies tab in the dashboard.
Keyword rules also use AI, whether or not AI Replies is enabled. When a keyword rule fires on a comment that contains the keyword mid-sentence, or on a rule set to answer general questions, the comment text is sent to an AI provider to decide whether the commenter is actually asking for what the rule sends. This runs on keyword automations on their own, so it is not covered by the AI Replies toggle above.
- What is sent: The comment text (truncated to 1,000 characters) and the rule's keyword or reply text.
- What is NOT sent: Commenter names, user IDs, email addresses, or any personally identifiable information about the commenter.
- Providers: TypeSafe (https://typesafe.ai) and, where TypeSafe is unavailable, OpenRouter.
- Retention by provider: We do not control data retention by either provider. Consult their privacy policies.
To stop this, turn off the keyword rule, or set it to exact-match only.
2. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Email address, account data | Contractual necessity | To provide you with the link redirect service you requested |
| Click analytics data | Legitimate interests | To provide you with analytics about your links' performance |
| Security logs, rate limiting | Legitimate interests | To protect our service from abuse and ensure security |
| Email delivery metadata | Legitimate interests | Troubleshooting delivery and preventing abuse of our email; kept 1 year |
| IP address (geolocation) | Legitimate interests | To provide country-level analytics for your campaigns, and to route location-targeted links by approximate country/region |
| Cloudflare Web Analytics | Legitimate interests | To improve our website and service |
| Meta Platform Data (comments, posts) | Contractual necessity | To provide the automation features you configured |
| AI processing of comments | Contractual necessity | To generate AI-powered replies you enabled |
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Service Delivery
- Authenticate you into your account (via email-based magic links/codes)
- Create and manage your short links and campaigns
- Redirect visitors who click your links to the appropriate destination
- Provide analytics about link performance (clicks, devices, locations, etc.)
- Send transactional emails (login codes, domain verification, alerts)
3.2 Service Improvement
- Analyze aggregated usage patterns to improve our service
- Monitor service performance and reliability
- Troubleshoot technical issues
3.3 Security and Compliance
- Prevent fraud, abuse, and unauthorized access
- Enforce our Terms of Service
- Comply with legal obligations (such as GDPR) and our security commitments (such as SOC 2)
- Maintain audit logs for security incidents
3.4 Communication
- Send you important service notifications (domain SSL certificate expiration, account disconnection alerts, etc.)
- Send transactional usage notifications:
- Respond to your support requests and feedback
- Send occasional product updates (you can opt out)
4. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Until account deletion | Service provision |
| Campaign/link data | Until you delete the campaign or its workspace is deleted (deleting your account deletes the workspaces you own; a campaign in someone else's workspace stays with that workspace) | Service provision |
| Deleted workspaces | 30 days after deletion, then permanently deleted | So a workspace deleted by mistake can be restored; everything in it, including direct messages and the uploaded images we can attribute to it, is deleted when the 30 days end |
| Holds on a deleted workspace's username, account handles and Domain LinkTaps domain | 60 days after deletion | So nobody else can take over the links, handles or domain of a workspace that was just deleted |
| Click analytics | 37 calendar months as individual clicks, then as daily totals until the link or its workspace is deleted | Analytics for your links. Daily totals keep counts by day and by country, browser, operating system, platform, whether the link opened an app, and referring site (the site only, not the page), and no click identifiers |
| Click identifiers (clickid) | 37 calendar months with the individual click, or sooner if the campaign or its workspace is deleted; daily totals keep none | Used for analytics accuracy and, on the link's destination, for the link owner's attribution; not for cross-session tracking |
| Install and open reports | 37 calendar months with the click they belong to, then as daily totals that keep no click identifiers; sooner if the link, the Domain LinkTaps site or its workspace is permanently deleted | Telling the link's owner which clicks led to an install or an open of their app; no device identifiers |
| Unmatched install and open counts | 400 days, then deleted | Showing you reports we could not match to your links; per workspace and day, no visitor data |
| Domain LinkTaps daily counts | Until the site or its workspace is deleted | Per-day totals for your site's analytics; no visitor data |
| Email audit metadata | 1 year (365 days) | Troubleshooting delivery and preventing abuse of our email |
| Security logs | 1 year (365 days) | Security monitoring and incident response |
| Application logs | 30 days, then automatically deleted | Troubleshooting and investigating outages. They can include error details, and email and IP addresses in masked form (the first letter and domain of an email address, and an IP address without its last part), but not access tokens or the text of comments or messages from your connected accounts |
| Backups | 30 days, then automatically deleted | Encrypted copies of our database, kept so the service can be restored after a failure. Data you delete can remain in a backup until that backup is deleted |
| Records of deletion requests | 1 year (365 days) after the request is completed; kept until resolved if it fails or while part of it is still outstanding; a record of deleting a workspace that had a Stripe billing customer is kept for that year or until our payment provider confirms the customer record is deleted, whichever is later | So the status of a deletion request, including a Meta data deletion confirmation code, can still be checked; a billing record is kept so that a later payment by that customer cannot bring a deleted workspace back |
| Rate limit counters | Until the counter's time window ends, then deleted | Abuse prevention |
| Sign-in attempt counters and account lockouts | A lockout ends after 24 hours; the records themselves are not yet deleted on a schedule, except that those naming your email address are deleted with your account | Protecting accounts from repeated sign-in attempts |
| Session cookies | 90 days after your last activity, or until you log out | Authentication |
| Reply review queue | 90 days after the reply was queued, then deleted | Holding AI replies for you to review before they are sent, and showing the questions the AI could not answer; each entry keeps the comment or message it answers and who wrote it |
| Meta automation activity logs | Until you delete it, or 180 days after the account is disconnected | Audit trail |
| Meta comment dedup cache | 7 days | Duplicate prevention |
| Connected Meta account data | Until you disconnect the account, then 180 days | API access; access tokens are deleted at once when you disconnect |
| Meta direct messages and conversations | While the account is connected, then 180 days after you disconnect it; a conversation that another account still connected to the same workspace can take over is kept with that account rather than deleted | Your inbox and DM automations |
| Meta repost queue | While the account is connected, then 180 days after you disconnect it | Scheduling the reposts you set up |
| Disconnected Meta accounts | 180 days after you disconnect, then permanently deleted | So that reconnecting restores the account's automations, messages and repost queue |
5. Data Sharing and Disclosure
We do NOT sell your personal data to third parties.
We may share your information only in the following limited circumstances:
5.1 Service Providers (Data Processors)
We use the following third-party service providers who process data on our behalf:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Convex | Database hosting | All account and campaign data | United States |
| Amazon Web Services (AWS SES) | Email delivery | Email addresses, metadata | United States |
| Cloudflare | Web analytics, CDN, DDoS protection | IP addresses, browsing data | Global |
| ip-api.com | IP geolocation (country/region) when CDN geo headers are unavailable | IP address | Global |
| Cloudflare Workers | Uptime monitoring of our own site | None (it requests our public pages and health check) | Global |
| TypeSafe | Keyword-intent decisions on incoming comments | Comment text (truncated, no PII), rule keyword | United States |
| Fly.io | Application hosting | HTTP request data | United States |
| Axiom | Application log storage | Application logs: error details, and masked email and IP addresses | United States |
| Cloudflare R2 | Media file storage; encrypted database backups | Uploaded images and videos; encrypted copies of our database (see Backups in section 4) | Global |
| OpenRouter | AI reply generation | Comment text, knowledge base context (no PII) | United States |
| Stripe | Payment processing for Pro subscriptions | Email, billing details (Stripe handles card data directly -- we never see or store it) | United States |
5.2 Legal Requirements
We may disclose your information if required by law, such as:
- In response to valid legal process (subpoena, court order)
- To protect our rights, property, or safety
- To prevent fraud or security threats
- To comply with regulatory obligations
5.3 Business Transfers
If LinkTaps is involved in a merger, acquisition, or sale of assets, your data may be transferred. You will be notified of any such change.
6. International Data Transfers
LinkTaps is operated from the United States. If you access our service from outside the United States, your data will be transferred to and processed in the United States.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland:
- We rely on adequacy decisions, Standard Contractual Clauses (SCCs), or other legally recognized transfer mechanisms
- Our service providers (AWS, Cloudflare, Convex) comply with GDPR requirements
7. Your Rights Under GDPR
If you are located in the EEA, UK, or Switzerland, you have the following rights:
7.1 Right to Access
You can request a copy of the personal data we hold about you.7.2 Right to Rectification
You can request correction of inaccurate or incomplete data.7.3 Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data by:- Deleting your account through the dashboard
- Emailing us at support@linktaps.io
Deleting a workspace is different from deleting your account, and only the workspace's owner can do it. A deleted workspace stops working within a minute: its links, pages and automations stop, its connected Meta accounts are disconnected, and any subscription on it is cancelled at once, with no further charges. Messages and comments that reach its connected accounts while it is deleted are not answered and not kept. Everything in the workspace is kept for 30 days so that the owner can restore it, and is then permanently deleted, including direct messages people sent to its connected accounts and the images and media uploaded to it that we can attribute to the workspace. Any uploaded file we cannot attribute to it is kept for manual review and then removed by hand. For 60 days after deletion, the workspace's username, its connected accounts' handles and its Domain LinkTaps domain stay reserved, so nobody else can take them over. A restored workspace comes back with its content, but its Meta accounts must be reconnected and its subscription started again. Direct messages and comment replies that were due to be sent while it was deleted are not sent, and posts scheduled for that time are not published; reposts resume on their normal schedule.
Deleting your account is immediate and cannot be undone; there is no restore window. Every workspace you own is deleted with everything in it, including any you deleted in the last 30 days, which can then no longer be restored. That includes direct messages people sent to their connected accounts and the images and media uploaded to them that we can attribute to a workspace; any uploaded file we cannot attribute is kept for manual review and then removed by hand. Any subscription on those workspaces is cancelled at once, with no further charges. Subscription fees and overage already incurred are not refunded. You are removed from every workspace you are a member of, and your MCP keys and connected AI apps are deleted; content you created in someone else's workspace stays with that workspace. Your sessions, devices, login codes and the invitations sent to your address are deleted. Security records of actions you took are kept, with you shown as "deleted user", as are the records of usernames, account handles and Domain LinkTaps sites you deleted. In security records about your account, your address and the details of the event are removed, except in a few records whose purpose is the address itself (the deletion, changes of email address or username, session revocations and data exports), which keep your address for fraud prevention. Records of what other people did that concern you, such as an invitation to a workspace or an administrator's action on your account, do not keep your address; where they identify you at all, it is by your account or by a one-way fingerprint of your address. The record of emails we sent you keeps only a one-way fingerprint of your address, and no address in any email subject. For 60 days after a workspace you own is deleted, its username, its connected accounts' handles and its Domain LinkTaps domain stay reserved, so nobody else can take them over.
Note: Security logs and the record of emails we send are kept for the periods in section 4, and Stripe keeps its own records of past transactions under its own retention policy.
7.4 Right to Restriction of Processing
You can request that we limit how we use your data in certain circumstances.7.5 Right to Data Portability
You can request a machine-readable copy of your data to transfer to another service.7.6 Right to Object
You can object to processing based on legitimate interests (such as analytics).7.7 Right to Withdraw Consent
Where we rely on consent, you can withdraw it at any time (though this doesn't apply to most of our processing, which is based on contract or legitimate interests).7.8 Right to Lodge a Complaint
You can file a complaint with your local data protection authority (DPA) if you believe we have violated GDPR.To exercise any of these rights, contact us at: support@linktaps.io
We will respond to your request within 30 days.
8. Security Measures
We implement industry-standard security measures to protect your data:
Technical Measures:
- Encryption in transit: All data transmitted over HTTPS (TLS 1.2+)
- Encryption at rest: Database encryption via Convex
- Secure session management: HttpOnly, Secure, SameSite cookies
- Rate limiting: Protection against brute force and abuse
- Account lockouts: Automatic lockout after 10 failed login attempts (24 hours)
- Email bounce tracking: Prevents sending to invalid/bounced addresses
- Security logging: Comprehensive audit trail of security events
Organizational Measures:
- Privacy by design and by default
- Metadata-only email logging (no sensitive content stored)
- Minimal data collection principle
- Regular security monitoring
- Access controls and authentication
However, no system is 100% secure. If you discover a security vulnerability, please report it to support@linktaps.io.
9. Children's Privacy
LinkTaps is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If we learn that we have collected data from a child without parental consent, we will delete it immediately.
If you believe a child has provided us with personal data, please contact us at support@linktaps.io.
10. Do Not Track (DNT)
Some browsers offer a "Do Not Track" (DNT) signal, and some offer Global Privacy Control (GPC). When a click on a short link comes from a browser sending either signal, we do not add a click identifier to the link's destination, and we do not create one at all unless the click came from an in-app browser (where it is used only on our own pages, to record the move to an external browser). Beyond that, because there is no industry standard for DNT, we do not currently respond to these signals. However, we already minimize tracking by:
- Using only essential cookies
- Using cookie-less analytics (Cloudflare Web Analytics)
- Not using third-party advertising or tracking scripts
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: What personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information, so this right is not applicable
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at support@linktaps.io.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email (to the address on file)
- Provide prominent notice on our website
Continued use of our service after changes constitute acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@linktaps.io
Mailing address: LinkTaps LLC, Ramsey County, Minnesota, United States
Data Protection Inquiries: For GDPR-specific requests, please include "GDPR Request" in the subject line.
14. Key Takeaways (Summary)
For your convenience, here's a summary of our privacy-first approach:
Thank you for trusting LinkTaps with your link management needs.