Linktotem
Menu

Privacy Policy

Last updated: September 17, 2026

Linktotem is operated by Guilherme Luz, Portugal. Contact: support@linktotem.com.

1. Who we are

The data controller is the operator identified above. This policy explains what we collect when you use Linktotem, as a page owner or as a visitor, and what your rights are under the General Data Protection Regulation (GDPR).

2. If you own a page

Account data: email, password (hashed, we cannot read it), name, language and, if you sign in with Google, your Google account id and email. Basis: performing our contract with you.

Page content: everything you put on your page, including images you upload. Basis: performing our contract.

Billing data: your subscription status and Stripe customer id. Card details go directly to Stripe and never reach our servers. Stripe is an independent controller for payment data (see Stripe's privacy policy). Basis: contract and legal obligations (accounting).

Usage and security data: IP address and timestamps of logins, rate limiting counters, error logs. Basis: our legitimate interest in keeping the service secure.

Emails: we send transactional emails (verification, billing, security) and a few onboarding tips in the first days. You can opt out of tips at any time; transactional emails are part of the service.

3. If you visit a page

We count views and clicks on the server without cookies or fingerprinting. We store the country (from the IP address), the referrer domain, device type and a daily anonymised hash used only to estimate unique visitors; the hash cannot be reversed and is discarded after 24 hours. The IP address itself is not stored.

If you report a page you can give us your email; we use it only to follow up on the report.

4. Where data goes

Hosting and database: Vercel and Supabase (EU and US regions, with EU standard contractual clauses). Payments: Stripe. Email delivery: Resend. Link safety: URLs on pages are checked against Google Safe Browsing. Error monitoring: Sentry. Each of these processes data on our instructions under a data processing agreement.

We do not sell personal data and do not use it for advertising.

5. How long we keep it

Account and page data: while your account exists and up to 30 days after deletion. Billing records: as required by tax law (typically 10 years). Analytics: aggregated, indefinitely; nothing in them identifies a person. Security logs: 90 days.

6. Your rights

You can access, correct, export or delete your data, restrict or object to some processing, and withdraw consent where processing is based on it. Most of this you can do yourself from your account settings; for the rest, write to the contact address above. You also have the right to complain to your data protection authority; in Portugal that is the CNPD (cnpd.pt).

7. Security

Passwords are hashed with Argon2, connections are encrypted, and access to production data is limited to what is needed to run the service. If a breach affects you, we will tell you and the authority as the law requires.

8. Changes

We will post changes to this policy here and, when they are material, email account holders.