Privacy Notice
Linksembly holds two kinds of information: what you give us to run your account, and what we measure when somebody visits one of your public pages. This describes both, and what we deliberately do not keep.
Last updated 5 August 2026.
Who we are
Linksembly — founder and entrepreneur, Nilüfer, Bursa, 16100, Türkiye. Write to linksembly@linksembly.cloud about anything on this page.
What we hold about you
- Your email address and display name, so you can sign in and we can reach you about your account.
- What you create: brand names, links, descriptions, images you upload, and the settings around them.
- If you sign in with Google, your email address and name as Google supplies them. We never receive your Google password.
- Billing is handled by Paddle. We store the subscription and customer identifiers Paddle gives us, and nothing else — no card number ever reaches our systems.
What we measure on your public pages
Page views and link clicks, so the analytics in your dashboard mean something. This is the part people usually want the detail on, so here it is exactly.
| We record | We do not |
|---|---|
| A visitor identifier derived by hashing the IP address, the browser string, a secret salt and the date | The IP address itself, in any form we can reverse |
| The country the request came from | City, region, coordinates or any precise location |
| Device category, browser family and operating system | Anything that identifies the individual device |
| The referring site and any UTM parameters on the link | Anything about the visitor elsewhere on the web |
The date is part of that hash, so the identifier changes every day: the same person visiting on Monday and Tuesday cannot be joined up. It is there to count visitors rather than to follow them. We set no advertising cookies anywhere. A page you publish through Linksembly carries our measurement and nothing else — no advertising network, no external script, nothing that follows your visitors off it.
Our own marketing pages
The pages that describe the product — the home page, pricing, features, the guides and the rest of this site — also use Vercel Web Analytics, so we can tell which of them are worth writing. Vercel hosts this site, so every request already reaches them; this asks them to keep a count of it. It sets no cookies and stores nothing on your device, and its visitor identifier is a hash of the request that changes daily, on the same principle as ours above. We rely on our legitimate interest in knowing whether our own pages work, and none of it is used for advertising.
It is confined to those pages by the code rather than by intention: the measurement is loaded only by the marketing pages, and a second check drops any event whose address is not one of them. It therefore records nothing on a brand’s public page, nothing in the dashboard and nothing on the sign-in screens. A brand page you publish is unaffected in every respect.
Inside the dashboard
The signed-in dashboard — and only the signed-in dashboard — uses Microsoft Clarity to record how the product itself is used: which controls are pressed, where a screen is confusing, and where something goes wrong. It is how a small team finds out that a button nobody presses is in the wrong place. It never runs on a brand’s public page, never on this website, and never on the sign-in or password screens.
Clarity is Microsoft’s, so what it collects is processed by Microsoft under their own terms; it masks input fields by default. If you would rather not be recorded, write to us and we will exclude your account. We rely on our legitimate interest in making the product work, and we do not use any of it for advertising.
Why we are allowed to hold it
- Account information: to perform the contract you entered when you signed up.
- Public-page measurement: our legitimate interest in giving you working analytics — which is why it is aggregate and pseudonymous rather than personal.
- Account email such as password resets and receipts: necessary to run the service, not marketing.
Who else sees it
Only the companies that make the product run. We do not sell data, and there is nobody else.
| Company | What for | Where |
|---|---|---|
| Supabase | Database, authentication and file storage | Frankfurt, Germany (eu-central-1) |
| Vercel | Application hosting and content delivery | Global edge network |
| Paddle | Merchant of record — takes payment, issues invoices, handles tax | United Kingdom and United States |
| Hostinger | Domain, DNS and the mailbox that sends account email | Lithuania |
How long we keep it
- Your account and its content: for as long as your account exists.
- Analytics events: kept while your plan includes analytics history, and readable in the dashboard only as far back as your plan allows.
- Delete your account and everything above goes with it — brands, links, uploads and analytics — through cascading deletion in the database rather than a job that might be missed.
What you can ask for
- A copy of what we hold about you.
- Correction of anything wrong — your name and workspace name you can change yourself in Settings.
- Deletion of your account and its data. Settings does this immediately and irreversibly.
- To object to the public-page measurement described above.
Email linksembly@linksembly.cloud and we will answer within 30 days. If you think we have handled your data badly, you can also complain to your local data protection authority.
Connected accounts
You can connect a social account to a brand so that its name, picture and follower count stay in step with the platform. Nothing is published, scheduled or read from your messages, and no connection appears in the product until that platform has approved this application.
Google and YouTube. If you connect a YouTube channel, Linksembly's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We access, use and store only your channel's id, title, handle, description, thumbnail and public statistics, and — if you grant it — aggregate analytics figures for that channel. We use them for one purpose: to show that channel on your brand's page and in your own dashboard. We do not sell them, we do not transfer them to anybody else except the infrastructure providers listed above, we do not use them for advertising, and no human at Linksembly reads them. Profile fields are refreshed or deleted every 30 days, and disconnecting deletes the stored data rather than flagging it. You can revoke access at any time from the brand's Settings tab or from your Google account permissions. Google's own privacy policy is at google.com/policies/privacy.
Deleting connected-account data. Disconnecting removes everything we hold for that connection. Step-by-step instructions, including how to have all of it removed if you can no longer sign in, are on the data deletion page.
Security
Every request runs over HTTPS. Data is separated at the database level so one account cannot read another's, which is enforced by the database rather than by application code that could forget. Passwords are hashed by our authentication provider and are never visible to us.
Children
Linksembly is not intended for anyone under 16, and we do not knowingly collect their information. Tell us if you believe a child has an account and we will remove it.
Changes
If this notice changes in a way that affects you, we will say so on this page and, for anything significant, by email. The date at the top always reflects the current version.