TL;DR
- We collect only what's necessary to provide our MMP platform services — account info, attribution data, and usage analytics.
- Your data is encrypted with AES-256-GCM at rest and TLS in transit. We never sell personal data to third parties.
- Attribution data is only shared with integrations you explicitly enable (GA4, Mixpanel, Meta CAPI, etc.).
- You can access, export, correct, or delete your data at any time. Enterprise accounts can request data localization.
- Data retention varies by plan (30 days Free → Unlimited Enterprise). Contact dpo@linkzly.com for any privacy concerns.
Introduction
At Linkzly, we believe privacy is a fundamental right. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Mobile Measurement Partner (MMP) platform, including deep links, Apps, attribution analytics, deep linking, app distribution, and related mobile measurement services.
By using Linkzly's MMP platform, you agree to the collection and use of information in accordance with this policy. We will not use or share your information with anyone except as described in this Privacy Policy.
If you have any questions, please contact us at privacy@linkzly.com.
Information We Collect
Account Data
- Email address, name, and avatar/profile information
- Password (securely hashed with bcrypt) and 2FA/TOTP settings with backup codes
- Account preferences and notification settings
- Team membership and organization details
Mobile App & Attribution Data
- iOS Bundle IDs, Android Package Names, and app configurations
- deep links data (URLs, custom aliases, campaign parameters, UTM tracking)
- Mobile attribution events (app installs, clicks, deep link opens)
- Device information (user agent, OS, browser, device fingerprint for attribution)
- Geographic location (city/country level, derived from IP via MaxMind/DB-IP)
- Deep linking data (in-app routing paths, deferred deep link parameters)
- QR code scan tracking data
Session & Technical Data
- Session tokens, user agent, IP address, and device fingerprint
- API usage logs (endpoint, method, status code, response time, IP)
- Activity logs and audit trails
- Referrer information and bot detection signals
Payment Data
- Stripe customer ID and subscription information
- Billing details processed securely by Stripe — we never store full card numbers
How We Use Your Information
- Provide and improve our Mobile Measurement Partner (MMP) platform services
- Generate mobile attribution analytics and app install insights using ClickHouse-powered analytics
- Enable deep links routing and Apps deep linking functionality across iOS, Android, and web
- Process mobile attribution events and forward data to your integrated analytics tools
- Support privacy-compliant attribution modes (strict, consent-based, and privacy-preserving)
- Send important service updates and notifications
- Process payments and manage your subscription via Stripe
- Prevent fraud through bot detection, rate limiting, and security event monitoring
- Maintain platform security through risk scoring and account lockout protections
Information Sharing
We never sell your personal data to third parties.
- Mobile attribution data is only shared with integrations you explicitly enable (Google Analytics GA4, Mixpanel, Amplitude, Segment, Facebook Conversions API, Snapchat Ads, custom webhooks)
- App install and attribution events are forwarded only to your configured analytics platforms
- We share data with service providers necessary to operate our platform (see Third-Party Processors below)
- Ad network integrations (Google Ads, Meta Ads, Snapchat Ads) only activate when you enable them
- Legal compliance: We may disclose data if required by law or legal process
- Business transfers: Data may be transferred in case of merger or acquisition
Third-Party Processors
We work with the following third-party service providers to deliver our platform:
AWS
Cloud infrastructure, storage, and compute
Region: US
Supabase
PostgreSQL database hosting
Region: US/EU
Cloudflare
CDN, Workers, and edge computing
Region: Global
Stripe
Payment and subscription processing
Region: US
MaxMind / DB-IP
Geolocation services for attribution
Region: US
SMTP / Nodemailer
Transactional email delivery
Region: US
The following services may be used depending on your configuration:
- SendGrid — email delivery (if configured by your account)
- Sentry — error tracking and performance monitoring (if configured)
- Google Ads, Meta Ads, Snapchat Ads — only when you enable these ad network integrations
Data Security
We implement comprehensive security measures to protect your data:
Encryption
- AES-256-GCM encryption for sensitive data at rest
- TLS encryption in transit via AWS/Cloudflare infrastructure
- Encrypted database backups via Supabase
Authentication
- Bcrypt password hashing
- JWT token system with rotation
- 2FA/TOTP with backup codes
- Account lockout after failed attempts
Access Controls
- Role-based access control (RBAC)
- API key authentication with IP restrictions
- Multi-tier rate limiting
Monitoring
- Security event monitoring with risk scoring
- Automated threat detection
- Incident response procedures
Data Retention
We retain your personal information only for as long as necessary. Retention periods vary by data type and your subscription plan:
Analytics Data Retention by Plan
Free
30 days
Starter
90 days
Professional
365 days
Enterprise
Unlimited
- Account data: Retained while active, deleted within 30 days of deletion request
- deep links & Apps data: Retained for the lifetime of the configuration, or until manual deletion
- Activity logs: Audit trails retained for 90 days (DynamoDB TTL)
- Sessions: Cleaned every 4 hours
- Expired tokens: Daily cleanup at 3:00 AM UTC
- Payment data: Retained as required by law and Stripe (typically 7 years)
International Transfers
Linkzly operates globally and may transfer your personal data to countries outside the European Economic Area (EEA). We ensure appropriate safeguards:
- Data is primarily stored in secure US data centers (AWS)
- Standard Contractual Clauses (SCCs) with all third-party processors for EU data
- Adequacy decisions recognized for transfers to countries with EU-approved protections
- Data Processing Agreements (DPAs) with all sub-processors ensuring compliance
- Enterprise accounts can request data localization options
- Cross-border transfers follow applicable privacy frameworks
Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of all personal data we hold about you, including attribution analytics and activity logs
- Correction: Update or correct inaccurate information in your account settings or organization details
- Deletion: Request deletion of your account and all associated data, including links and analytics
- Portability: Export your data in a structured, machine-readable format (JSON/CSV)
- Restriction: Request limitation of processing while we verify accuracy or process objections
- Opt-out: Unsubscribe from marketing communications at any time
For more details on exercising your rights under GDPR, see our GDPR Compliance page.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact our privacy team:
Email: privacy@linkzly.com
Data Protection Officer: dpo@linkzly.com
Response Time: Within 30 days
Address: Linkzly Inc., 123 Tech Street, San Francisco, CA 94105