Privacy Policy

Your Privacy Matters

We're committed to protecting your privacy and being transparent about how we collect, use, and safeguard your data across our MMP platform.

Last updated: October 19, 2025

GDPR Compliant
AES-256 Encrypted
99.9% Uptime
Data Protected

TL;DR

  • We collect only what's necessary to provide our MMP platform services — account info, attribution data, and usage analytics.
  • Your data is encrypted with AES-256-GCM at rest and TLS in transit. We never sell personal data to third parties.
  • Attribution data is only shared with integrations you explicitly enable (GA4, Mixpanel, Meta CAPI, etc.).
  • You can access, export, correct, or delete your data at any time. Enterprise accounts can request data localization.
  • Data retention varies by plan (30 days Free → Unlimited Enterprise). Contact dpo@linkzly.com for any privacy concerns.

Introduction

At Linkzly, we believe privacy is a fundamental right. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Mobile Measurement Partner (MMP) platform, including deep links, Apps, attribution analytics, deep linking, app distribution, and related mobile measurement services.

By using Linkzly's MMP platform, you agree to the collection and use of information in accordance with this policy. We will not use or share your information with anyone except as described in this Privacy Policy.

If you have any questions, please contact us at privacy@linkzly.com.

Information We Collect

Account Data

  • Email address, name, and avatar/profile information
  • Password (securely hashed with bcrypt) and 2FA/TOTP settings with backup codes
  • Account preferences and notification settings
  • Team membership and organization details

Mobile App & Attribution Data

  • iOS Bundle IDs, Android Package Names, and app configurations
  • deep links data (URLs, custom aliases, campaign parameters, UTM tracking)
  • Mobile attribution events (app installs, clicks, deep link opens)
  • Device information (user agent, OS, browser, device fingerprint for attribution)
  • Geographic location (city/country level, derived from IP via MaxMind/DB-IP)
  • Deep linking data (in-app routing paths, deferred deep link parameters)
  • QR code scan tracking data

Session & Technical Data

  • Session tokens, user agent, IP address, and device fingerprint
  • API usage logs (endpoint, method, status code, response time, IP)
  • Activity logs and audit trails
  • Referrer information and bot detection signals

Payment Data

  • Stripe customer ID and subscription information
  • Billing details processed securely by Stripe — we never store full card numbers

How We Use Your Information

  • Provide and improve our Mobile Measurement Partner (MMP) platform services
  • Generate mobile attribution analytics and app install insights using ClickHouse-powered analytics
  • Enable deep links routing and Apps deep linking functionality across iOS, Android, and web
  • Process mobile attribution events and forward data to your integrated analytics tools
  • Support privacy-compliant attribution modes (strict, consent-based, and privacy-preserving)
  • Send important service updates and notifications
  • Process payments and manage your subscription via Stripe
  • Prevent fraud through bot detection, rate limiting, and security event monitoring
  • Maintain platform security through risk scoring and account lockout protections

Information Sharing

We never sell your personal data to third parties.

  • Mobile attribution data is only shared with integrations you explicitly enable (Google Analytics GA4, Mixpanel, Amplitude, Segment, Facebook Conversions API, Snapchat Ads, custom webhooks)
  • App install and attribution events are forwarded only to your configured analytics platforms
  • We share data with service providers necessary to operate our platform (see Third-Party Processors below)
  • Ad network integrations (Google Ads, Meta Ads, Snapchat Ads) only activate when you enable them
  • Legal compliance: We may disclose data if required by law or legal process
  • Business transfers: Data may be transferred in case of merger or acquisition

Third-Party Processors

We work with the following third-party service providers to deliver our platform:

AWS

Cloud infrastructure, storage, and compute

Region: US

Supabase

PostgreSQL database hosting

Region: US/EU

Cloudflare

CDN, Workers, and edge computing

Region: Global

Stripe

Payment and subscription processing

Region: US

MaxMind / DB-IP

Geolocation services for attribution

Region: US

SMTP / Nodemailer

Transactional email delivery

Region: US

The following services may be used depending on your configuration:

  • SendGrid — email delivery (if configured by your account)
  • Sentry — error tracking and performance monitoring (if configured)
  • Google Ads, Meta Ads, Snapchat Ads — only when you enable these ad network integrations

Data Security

We implement comprehensive security measures to protect your data:

Encryption

  • AES-256-GCM encryption for sensitive data at rest
  • TLS encryption in transit via AWS/Cloudflare infrastructure
  • Encrypted database backups via Supabase

Authentication

  • Bcrypt password hashing
  • JWT token system with rotation
  • 2FA/TOTP with backup codes
  • Account lockout after failed attempts

Access Controls

  • Role-based access control (RBAC)
  • API key authentication with IP restrictions
  • Multi-tier rate limiting

Monitoring

  • Security event monitoring with risk scoring
  • Automated threat detection
  • Incident response procedures

Data Retention

We retain your personal information only for as long as necessary. Retention periods vary by data type and your subscription plan:

Analytics Data Retention by Plan

Free

30 days

Starter

90 days

Professional

365 days

Enterprise

Unlimited

  • Account data: Retained while active, deleted within 30 days of deletion request
  • deep links & Apps data: Retained for the lifetime of the configuration, or until manual deletion
  • Activity logs: Audit trails retained for 90 days (DynamoDB TTL)
  • Sessions: Cleaned every 4 hours
  • Expired tokens: Daily cleanup at 3:00 AM UTC
  • Payment data: Retained as required by law and Stripe (typically 7 years)

International Transfers

Linkzly operates globally and may transfer your personal data to countries outside the European Economic Area (EEA). We ensure appropriate safeguards:

  • Data is primarily stored in secure US data centers (AWS)
  • Standard Contractual Clauses (SCCs) with all third-party processors for EU data
  • Adequacy decisions recognized for transfers to countries with EU-approved protections
  • Data Processing Agreements (DPAs) with all sub-processors ensuring compliance
  • Enterprise accounts can request data localization options
  • Cross-border transfers follow applicable privacy frameworks

Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of all personal data we hold about you, including attribution analytics and activity logs
  • Correction: Update or correct inaccurate information in your account settings or organization details
  • Deletion: Request deletion of your account and all associated data, including links and analytics
  • Portability: Export your data in a structured, machine-readable format (JSON/CSV)
  • Restriction: Request limitation of processing while we verify accuracy or process objections
  • Opt-out: Unsubscribe from marketing communications at any time

For more details on exercising your rights under GDPR, see our GDPR Compliance page.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact our privacy team:

Email: privacy@linkzly.com

Data Protection Officer: dpo@linkzly.com

Response Time: Within 30 days

Address: Linkzly Inc., 123 Tech Street, San Francisco, CA 94105

Related Documents

Questions About Your Privacy?

We're here to help. Contact our privacy team with any questions or concerns.