Privacy Policy
Last updated: September 17, 2026
Linktotem is operated by Guilherme Luz, Portugal. Contact: support@linktotem.com.
1. Who we are
The data controller is the operator identified above. This policy explains what we collect when you use Linktotem, as a page owner or as a visitor, and what your rights are under the General Data Protection Regulation (GDPR).
2. If you own a page
Account data: email, password (hashed, we cannot read it), name, language and, if you sign in with Google, your Google account id and email. Basis: performing our contract with you.
Page content: everything you put on your page, including images you upload. Basis: performing our contract.
Billing data: your subscription status and Stripe customer id. Card details go directly to Stripe and never reach our servers. Stripe is an independent controller for payment data (see Stripe's privacy policy). Basis: contract and legal obligations (accounting).
Usage and security data: IP address and timestamps of logins, rate limiting counters, error logs. Basis: our legitimate interest in keeping the service secure.
Emails: we send transactional emails (verification, billing, security) and a few onboarding tips in the first days. You can opt out of tips at any time; transactional emails are part of the service.
3. If you visit a page
We count views and clicks on the server without cookies or fingerprinting. We store the country (from the IP address), the referrer domain, device type and a daily anonymised hash used only to estimate unique visitors; the hash cannot be reversed and is discarded after 24 hours. The IP address itself is not stored.
If you report a page you can give us your email; we use it only to follow up on the report.
4. Where data goes
Hosting and database: Vercel and Supabase (EU and US regions, with EU standard contractual clauses). Payments: Stripe. Email delivery: Resend. Link safety: URLs on pages are checked against Google Safe Browsing. Error monitoring: Sentry. Each of these processes data on our instructions under a data processing agreement.
We do not sell personal data and do not use it for advertising.
5. How long we keep it
Account and page data: while your account exists and up to 30 days after deletion. Billing records: as required by tax law (typically 10 years). Analytics: aggregated, indefinitely; nothing in them identifies a person. Security logs: 90 days.
6. Your rights
You can access, correct, export or delete your data, restrict or object to some processing, and withdraw consent where processing is based on it. Most of this you can do yourself from your account settings; for the rest, write to the contact address above. You also have the right to complain to your data protection authority; in Portugal that is the CNPD (cnpd.pt).
7. Security
Passwords are hashed with Argon2, connections are encrypted, and access to production data is limited to what is needed to run the service. If a breach affects you, we will tell you and the authority as the law requires.
8. Changes
We will post changes to this policy here and, when they are material, email account holders.