Privacy policy

We sell software, not data. This page lists exactly what we hold, why, and how to get rid of it.

Version 1Last updated 15 August 2026First draft — not yet lawyer-reviewed
We don't sell dataNo brokers, no ad networks, no behavioural sharing. Our revenue is software subscriptions and nothing else.
Your audience is yoursThe emails your widgets collect are yours: a CSV export on Pro, or email us and we send them — free, no waiting period.
Counted, not trackedPage views are counted with a salted one-way hash, never a raw IP. No fingerprinting, and nothing third-party loads until you say yes.
The short version— not a substitute for the full text below
We don't sell data. Revenue is subscriptions, not your audience.
Fans aren't tracked across the web. Our own counting is server-side and anonymous; anything more asks first.
You control your data. Close your account yourself in Settings. Exports are still a request we action by hand.
Payments stay with Stripe. We never see full card numbers.
Minimal cookies. Login, your consent choice, and a referral cookie only if you accept it.
One policy for everyone. Access, correction and deletion, wherever you live — no EU-only tier.

A first draft, in plain terms

Written so lnkrr can launch with real policies in place — not a substitute for review by a qualified lawyer, and not legal advice. It describes how the product works today and will be revised as proper legal review happens. Corrections: privacy@lnkrr.me.

1

Who this covers

lnkrr is a link-in-bio platform where creators build a page and fans do things on it — vote, tip, buy, book, join. This policy covers two kinds of people: creators who hold an account, and visitors who interact with a creator’s public page. Where the two are treated differently, we say so.

2

What we collect

Creator account data. When you sign up we store your email address, and — as you fill them in — your display name, avatar image, and a referral code. Sign-in is by email and password, with a one-time email link as an alternative. Your password is stored only as a salted hash by our authentication provider (Supabase) — neither they nor we can read it back — and if you turn on two-factor authentication, the secret behind your codes is held there too.

The page you publish. Your handle, bio, social links, the blocks you add (their titles, prices, poll questions, and other content you type), your theme, and — on the Ultra plan — the optional FAQ you write for your page assistant. This is content you choose to make public.

Visitor interactions. When someone votes in a poll, answers a quiz, moves a slider, asks a question, or follows a page, we store the interaction with a random browser-generated visitor id (kept in the browser, not an identity we can trace to a person) and a salted, one-way hash of their IP address used only for rate limiting. We never store raw IP addresses.

Emails collected by a creator’s widgets. If a creator adds an email-capture or form widget and a visitor submits it, we store the email address (and optional name) the visitor entered, on the creator’s behalf, so the creator can reach them.

Payments. Card payments are processed by Stripe on Stripe-hosted checkout — card numbers are entered on Stripe and never reach lnkrr. We store the buyer’s email, the amount and currency, any public tip message, Stripe identifiers, and, for fraud prevention, an opaque card fingerprint from Stripe (a stable token per card that is not a card number and cannot be reversed into one).

Subscriptions and Circle memberships. For Pro/Ultra subscriptions we store the plan, status, and Stripe subscription and price identifiers. For a creator’s Circle, we store each member’s email, optional name, tier, and Stripe identifiers.

Referrals. Who referred whom, a ledger of commission earned from paid invoices, and — where a referral is flagged for review — the evidence behind the flag (card fingerprints and timing), used to prevent self-referral and payment fraud.

Core analytics — deliberately minimal, always on. We count page views and block clicks server-side, with no cookie, no browser script, no raw IP address, and no user-agent string (it is discarded after we derive a coarse device class such as “mobile”). What we keep is the referring site’s host (not the full URL), that coarse device class, and a salted hash of your IP combined with the calendar day — which cannot be reversed and cannot link you across different days. This runs for everyone because it sets nothing on your device; it is not the analytics category on the banner.

Product analytics (PostHog) — only if you accept. Separately, we use PostHog to understand in aggregate how the product itself is used — which flows people complete, where they get stuck — so we can improve it. This one does run a script and set storage in your browser, so it loads only if you accept the analytics category on the cookie banner, and switching that category back off stops it and clears what it set. We do not create a personal profile for an anonymous visitor, and this is our own measurement of our own product — it is not advertising, and lnkrr still adds no advertising pixel of its own to any page.

A creator’s own advertising pixel. Creators on our Pro and Ultra plans can add their own Meta (Facebook) or TikTok pixel ID to their page, so that ads they pay for can be measured. Where a creator has done that, and only if you accept the ad-pixel category on the cookie banner, that platform’s script loads in your browser on their page and reports the visit to them. It is the creator’s tracker and the creator is its data controller; what Meta or TikTok then collect is governed by their own policies, not ours. lnkrr adds no pixel of its own to any page, and nothing loads on the pages of the great majority of creators, who have not set one.

The AI page assistant (Ultra only). On pages whose owner is on the Ultra plan, a visitor can chat with an AI assistant. We store the conversation (the visitor’s questions and the AI’s answers) so the creator can see what people ask, together with a salted IP hash. See the processors section for what is sent to the AI provider.

Email + passwordso you can sign in and we can reach you about payoutswhile the account exists
Your page contenttiles, copy, images, prices — the thing you builtwhile the page exists
Stripe account idto route payouts; we never see card numbers or bank detailswhile the account exists
Orders and billing recordsmoney that moved — kept where the law requiresas required by law
Views and clicksyour analytics counts, from a salted daily hash and a referrer hostwhile the page exists
Emails your widgets collectthe list your fans opted into — yoursuntil you or we delete them
We never see or store a card number. Stripe handles that end to end.
3

How we use it

  • To run the product — show creator pages, record votes and follows, deliver purchases, and pay creators out through Stripe.
  • To process payments and subscriptions, and to keep a creator's own records (their orders, members, and earnings) accurate.
  • To prevent fraud and abuse — the referral fraud checks, rate limiting, and the trust & safety enforcement described on our safety page.
  • To answer support, billing, referral, and partnership emails you send us.
  • To understand, in aggregate, how pages are used — from the minimal analytics above.

We do not sell personal data, and we do not use it for third-party advertising. The creator ad pixel described above is not an exception to that: it is the creator’s own measurement of their own ads, it requires your consent, and lnkrr receives nothing from it.

4

Who processes it for us

We share data with a small set of service providers who process it on our behalf, only as needed to run lnkrr:

  • Stripe — payments, payouts (via Stripe Connect), and subscriptions. Receives card data (entered directly on Stripe), buyer and creator email, amounts, and, for physical goods, the shipping address Stripe collects at checkout.
  • Supabase — our database, file storage (avatars), and authentication provider. Stores everything above, and sends the sign-in / magic-link emails.
  • Vercel — hosting, and visitor counts for our own marketing pages (the home page and pricing). Those counts are cookieless and collected first-party: no third-party script loads, nothing is stored on your device, and no profile is built. Creator pages are not counted this way. Vercel serves every request to lnkrr in any case, so nothing new is disclosed by it.
  • Sentry — error monitoring, configured to suppress personal data: it does not capture IP addresses, cookies, request bodies, or session recordings. It receives technical error details only.
  • PostHog — product analytics, and only if you accept the analytics category on the cookie banner. It records how the product is used — the pages you visit within lnkrr and events like completing a flow — to help us improve it. We do not create a personal profile for an anonymous visitor. Decline the category, or switch it back off, and nothing is sent.
  • Anthropic — the Ultra AI assistant only. When a visitor sends a message, that message, the recent conversation, and the creator’s public page content are sent to Anthropic’s API to generate a reply. It is not used to train their models under our API terms.
  • Resend — transactional email. Two things go through it. The in-product feature-suggestion form, which sends us the suggesting creator’s email and message and sends them a short acknowledgement back. And the welcome email to a new creator’s own address, when they sign up or publish their page. Both go to people who already have an account with us; we do not hold an email address for anyone who does not. The sign-in and password-reset emails are not on this list; Supabase sends those.
  • oEmbed providers — when a creator pastes a media link (YouTube, Spotify, Vimeo, and similar), the URL is sent to that provider to fetch a preview. No visitor data is involved.

We may also disclose information if required by law, to enforce our terms, or to protect the safety of people using lnkrr.

Nothing you or your fans write is used to train a model — the assistant's provider is bound by API terms that exclude it.
5

Cookies and local storage

The complete list, because a partial one is worse than none. There are four things, and only one of them asks your permission.

  • Session cookies from our authentication provider — what keeps a signed-in creator signed in. Essential; there is no product without them.
  • A consent cookie (lnkrr_consent) remembering the choice you made in the banner, for twelve months. Storing your answer is the only way not to ask again.
  • A referral cookie (lnkrr_ref), set only if you arrived from a creator’s referral link, so that creator gets credited if you sign up. This is the one we ask about — it serves us, not you — and it is off unless you accept it. It clears itself once a signup is attributed.
  • Local storage, not cookies: an anonymous per-browser id and flags for whether you have already voted, answered or followed. That id exists so a poll can’t be answered twice from one browser; it is not derived from anything about you and carries no signal. Clearing your browser storage clears it, and you get a new one.
  • PostHog analytics storage (a ph_* cookie and local storage), set only if you accept the analytics category. It carries an analytics id for our own product measurement described above. Switching the category back off stops it and clears this storage; declining never sets it at all.

lnkrr sets no advertising cookie and no cross-site tracking cookie. We do run our own product-analytics script (PostHog, above) — but only after you accept the analytics category, never for ads, and never shared across sites. The one third-party advertising tracker you can meet on lnkrr is a Meta or TikTok pixel that the creator whose page you are on has added themselves; it rides the same category, stays off until you switch it on, loads only on the pages of creators who have set one up, and switching the category back off removes it and clears the cookies it set.

If you accepted that category before this update, we asked you again. It used to cover only a creator’s own ad pixel; it now also covers lnkrr’s own product analytics, and a yes to the narrower thing is not a yes to the broader one. Rather than quietly stretch your old answer to cover something you were never shown, we discarded it and the banner asked once more — the same thing we did when the category first appeared, and the promise this page keeps whenever what we’re asking about changes.

to change your mind at any time.

6

How long we keep it, and deleting your data

We keep data for as long as the account or page it belongs to exists. Emails collected by capture widgets, form responses, questions, tip messages, and AI-assistant transcripts persist until the page or the account holding them is deleted. Analytics events are swept on a schedule; nothing else is.

Closing your account is self-serve. Settings → Close your account asks for your password and for you to type your handle, then does it immediately. There is no grace period and it cannot be undone. Your page comes down and your photos, bio, links and connected accounts are deleted. If you are still owed money — a Stripe balance not yet paid out, or referral commission not yet settled — it tells you the amount and refuses, so closing cannot strand a payment.

Two things survive it, deliberately. Records of completed sales and memberships are kept where we are required to keep financial records — they are your buyers’ receipts as much as yours — and they no longer carry your name. And your handle is held for 180 days rather than released to the next person, so links your audience already shared do not quietly become somebody else’s page. Salted IP hashes cannot be reversed to an address at any point.

To request a copy of your data or a correction, email privacy@lnkrr.me — those are still actioned by hand, and we reply.

7

Your choices

  • Edit or remove your page content at any time in the editor — hiding or deleting a block removes it from your public page.
  • Close your account yourself, from Settings. It takes effect immediately.
  • Ask us for a copy of your data or a correction, at the address above.
  • Visitors: clearing your browser storage removes the anonymous visitor id and local interaction state.
8

Children

lnkrr is not directed to children, and is not intended for anyone under the age at which they can hold an account under their local law (at least 13, and 16 where required). We do not knowingly collect data from children.

9

Where data is processed

lnkrr runs on cloud infrastructure and the providers named above, which may process and store data in countries other than yours. By using lnkrr you understand that your data may be handled in those locations under this policy.

10

Changes

This is v1 and will change as the product and its legal review do. We’ll update the date at the top when we revise it, and announce material changes before they take effect where we reasonably can.

Data protection contactprivacy@lnkrr.me — a person replies. You can also complain to your local supervisory authority.Read the terms
0% fees, always · © 2026 lnkrrHomeTermsTermsTrust & safety