Privacy Policy
Last updated: September 17, 2026
1. Information We Collect
LinkForge provides link management, profile hosting, and real-time click intelligence. In order to provide and improve our service, we collect the following types of information:
- Account Information: When you register, we collect your name, email address, password (stored exclusively as cryptographic salted hashes using bcrypt), chosen username, and profile metadata.
- Authentication & Session Data: Authentication sessions, authentication tokens, IP address, and login timestamps to secure account access and mitigate unauthorized sessions.
- Link Configuration: Destination URLs, link titles, scheduling parameters, position orders, and associated social media handles.
- Click & Traffic Telemetry: When visitors access your public profile or click your shortened links, we collect anonymized aggregated telemetry including timestamp, referrers, device family, browser name, and country/geographic region derived from IP.
2. How We Use Your Information
The information we collect is utilized strictly for the following functional purposes:
Routing & Delivery
Executing high-performance redirects to your configured destination URLs and serving public creator profiles.
Analytics Aggregation
Providing creators with real-time insight into audience engagement, device breakdowns, and geographical distribution.
Security & Fraud Prevention
Detecting abusive automated bots, open redirect exploits, rate-limit violations, and malicious destination URLs.
Transactional Communications
Sending critical account notices, milestone notifications, subscription updates, and password reset requests.
3. Data Protection & Security Controls
We apply defense-in-depth security engineering to safeguard all user information:
- Encryption in Transit & at Rest: All web traffic and API endpoints strictly require TLS 1.3 encryption with automated HSTS headers.
- Decoupled Public Identifiers: Internal database primary keys (UUIDs) are decoupled from public routing using random cryptographically generated public IDs.
- Multi-Tenant Isolation: Data queries enforce authenticated user ownership validation at the ORM layer (Prisma).
- No Plaintext Credentials: Passwords and API secrets are never stored in plaintext or logged in server telemetry.
4. Third-Party Service Providers
We partner with trusted infrastructure providers to deliver specialized capabilities:
- Stripe: Payment processing and subscription management. Payment card information is handled directly by Stripe in compliance with PCI-DSS standards.
- Resend: Transactional email delivery for account verification, password resets, and milestone reports.
- Cloudinary: Secure cloud asset storage for avatar and media uploads.
- Sentry: Real-time error boundary monitoring and performance profiling with sensitive data sanitization.
5. Your Rights and Data Deletion
You retain complete ownership over your links and profile. You may update, archive, or permanently delete links and account records directly through your dashboard. For specific data removal inquiries, contact us through our verified channels.
6. Contact Information
If you have any questions regarding this Privacy Policy or data handling practices, please contact our team via the Contact Page or review our Security Policy.