Privacy Policy
Your privacy is fundamental to how we build LinkForge. This policy outlines how we handle data with strict encryption, IP hashing, and compliance controls.
1. Privacy Overview & Principles
LinkForge ("LinkForge", "we", "us", "our") is committed to protecting the privacy of account holders, workspace members, and visitors who interact with branded short links hosted on our edge network.
We adhere to the core principles of Data Minimization, Privacy by Design, and Cryptographic Isolation. We never sell personal data to third-party ad brokers or data aggregators.
2. Information We Collect
We collect personal data in two distinct operational contexts:
A. Account & Workspace Data (Customers)
- Full Name and Account Email Address
- BCrypt Hashed Passwords and 2FA Verification Hashes
- Workspace Names, Custom Domain Settings, and Brand Overlay Logos
- Dodo Payments Customer & Subscription Metadata (excluding raw credit card details)
B. Link Redirect Analytics Data (End-User Visitors)
- Hashed IP Addresses (Salted via PEPPER secret — raw IPs are never stored)
- Browser User-Agent strings, Device Category, and Geolocation (Country / City level)
- Referrer Headers and Campaign UTM Parameters
- Timestamp of link redirection or QR code scan
3. IP Anonymization & Analytics Ingestion
LinkForge processes incoming link click events through a zero-knowledge IP hashing algorithm. Before click events are stored in analytics tables, raw IP addresses are hashed using a secure server-side secret (IP_HASH_PEPPER).
This ensures unique visitor counts can be computed accurately for analytics reports without maintaining identifiable IP records in database logs.
4. How We Use Your Information
- To provide, operate, and maintain LinkForge short link redirects and QR code engines.
- To compute real-time aggregated campaign metrics (clicks, unique visitors, UTM attribution).
- To perform automated security scans via Google Web Risk against phishing and malware.
- To send essential transactional notifications (password resets, email verification, 2FA codes).
- To process subscription payments and enforce workspace tier capabilities via Dodo Payments.
5. Third-Party Service Providers
We share data only with verified sub-processors necessary for platform operation:
Global edge routing, custom domain SSL provisioning, and caching.
Merchant of Record payment processing and tax invoicing.
Transactional email delivery (account verification, 2FA codes).
Automated destination safety and reputation scanning.
6. Your Rights (GDPR & CCPA)
Under the European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), you possess the following rights:
- Right of Access & Export: Request a copy of your personal data in a structured CSV format.
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your user account and workspace data.
- Right to Rectification: Update inaccurate account credentials or workspace attributes.
- Right to Restrict Processing: Pause analytics event logging for specific workspace links.
To exercise any of these rights, contact our Data Protection Officer at privacy@linkforge.site.
8. Data Retention & Security Measures
Raw click events and analytics rollups are retained for 90 days (or according to custom plan settings). Inactive account data is pruned during automated daily cleanup runs.
All communication between your browser, edge nodes, and database servers is encrypted in transit using **TLS 1.3** and encrypted at rest using **AES-256**.
9. International Data Transfers
LinkForge operates a globally distributed edge network. Data transferred outside your region is protected under Standard Contractual Clauses (SCCs) and compliant cloud hosting agreements.
10. Privacy Contact & DPO
If you have any questions or privacy requests, please contact our Data Protection Officer: