Privacy Policy
Last updated: 24 July 2026
In Short
Linkygo is a bio-link service that gathers your page under a single link. This document applies both to people who create an account and to people who visit a Linkygo page, and it describes what the service actually processes. In short: we use no advertising networks, we embed no third-party tracking tool such as Google Analytics, we do not follow visitors across sites, and we sell nobody's data. The visitor data we collect is the smallest set that still lets us show the page owner aggregate statistics.
The Service is operated by Selin Saygılı, a natural person resident in Türkiye, who is also the data controller for the purposes of the Turkish Personal Data Protection Law (KVKK). You can send any application, request or formal notice to the address given under "Contact" below; a postal address is provided on request where legally required.
Data We Collect
Account data. Your email address and sign-in credentials are held by the authentication layer; we neither see nor store your password in plain text. Your profile holds your username, display name, biography, profile photo and theme preferences. If you choose to sign in with Google or Apple, only the basic details needed to create the account (name, email, profile image) are passed to us by those providers.
Your page content. The title, address, icon, order, publication start/end time and any lock setting of the links you add; your short link records (slug and target address); the theme favourites you save; the images, videos and font files you upload; and the subject and body of your newsletter posts. Most of this content is public, because you publish it. If you put a password lock on a link, that password is written to the database as a salted hash — but this lock is a simple barrier for visitors, not account-grade protection; do not use it for a sensitive secret.
Visitor analytics. When a Linkygo page is opened and when a link is clicked, we record only the following:
- A random session identifier generated in the browser (a number that does not say who you are).
- A country code — read from the country header our hosting provider adds to the request; if that header is absent the value is recorded as "Unknown". No city, coordinates or comparable location data is kept.
- Device type (desktop / mobile / tablet) and, for visits, the browser family — derived roughly from the user-agent header.
- Only the domain of the referring address (e.g. the domain of a social network); the full URL, query parameters and campaign tags are not stored. If there is no referrer, "Direct" is recorded.
- The time the record was created and, for clicks, which link was clicked.
We do not write the visitor's IP address to the analytics table. The IP is used only to limit abuse, as an irreversible hash and within per-minute counters. The same session reopening the same page within 30 minutes does not count as a new visit.
Visitor interactions. If you vote in a poll on a page, the option you chose is recorded together with the session identifier so that the same session cannot vote twice. If you subscribe to a page's newsletter, your email address is stored along with which user's newsletter you subscribed to, and you can unsubscribe at any time.
Support and content reports. If you report a profile to us, we record the reported username, the address you reported, the reason you selected, your description and, if you leave one, your contact email. Administrative actions our team takes on accounts (suspension, deletion and so on) are written to a separate log for audit purposes.
Payment data. When you upgrade to Premium your card details never reach us; they are processed by the payment provider. On our side we keep only the subscription status, plan, period end date, the customer/subscription identifiers issued by the provider, and a record of the billing events received.
Why We Process Data
- Performance of a contract: creating your account, publishing your page, applying your plan entitlements, and running your subscription and billing.
- Legitimate interest: giving page owners aggregate visit/click statistics, limiting spam and abuse, diagnosing errors, and protecting the security and integrity of the Service. For each of these purposes we chose the least data that does the job.
- Explicit consent: entirely optional steps such as subscribing to a page's newsletter. You can withdraw consent at any time by unsubscribing or by writing to us.
- Legal obligation: retaining billing and financial records for the period required by law.
Cookies and Similar Technologies
Our use of cookies is deliberately narrow. The authentication cookies that keep your session open are strictly necessary; sign-in is impossible without them. We use no advertising cookies, no remarketing pixels and no third-party tracking scripts.
The session identifier used in visit statistics is not a cookie: it is a random value held in the browser's localStorage and it is not sent automatically with every server request. Because browsers isolate localStorage per domain, that value cannot be read by other sites, so no cross-site tracking is possible. If you clear your browser data or use a private window, the value is lost and can never be matched again.
The preference you give in the "Cookie Preferences" dialog in the footer of public profile pages is likewise stored only on that device, in localStorage; it is not sent to the server and is not used to build a profile.
Third-Party Service Providers
We rely on a limited number of service providers to run the Service. We transfer data to them only for the purposes below and under contractual limits; we sell data to none of them for marketing. You can request the current list of providers and the countries they operate in by writing to the contact address below.
- Cloud infrastructure and database provider — hosting your account, your page content and the files you upload, plus authentication.
- Application hosting and content delivery provider — serving pages to visitors and running scheduled maintenance jobs (data cleanup). The country information we use in analytics comes from the region header this layer adds to the request. If you connect a custom domain, your domain is registered in this provider's management interface.
- Payment service provider — subscription collection and invoicing. Your card details are processed directly by this provider and never enter our systems; only a signature-verified subscription status is reported to us.
- Email delivery provider — transactional email (the welcome message after sign-up) and delivery of the newsletter emails page owners send. Newsletters are sent as a separate email to each recipient; subscribers cannot see each other's addresses.
- Sticker (GIF) content provider — the search used when you add a sticker to your page. The search request goes through our server and our access key never reaches the browser. However, the sticker images shown on the page are loaded by the visitor's browser directly from that provider's content network, which means the provider can see the visitor's IP address and browser information. We have no control over that request and it arises only on pages that contain stickers.
How Long We Keep Data
- Visit and click records: 7 days on the Free plan, 90 days on Premium. Expired rows are permanently deleted by a regularly running cleanup job — they are not archived.
- Account and page content: for as long as your account remains open. When you request deletion, the account is closed to access immediately, your page is taken offline, and after a 30-day grace period your identity record and the profile, links, short links, theme favourites and plan entitlements attached to it are permanently deleted.
- Subscription and billing records: retained after account deletion because of financial record-keeping obligations; however, the link to the user is severed so the records are no longer associated with the person.
- Reports and administrative audit logs: kept for a reasonable period so that reviews and abuse history remain traceable.
- Abuse counters: operate in per-minute windows and contain no personal data.
Your Rights
Under Article 11 of the KVKK and under the GDPR you have the right to learn whether your personal data is being processed, to request information about it, to learn the purpose of processing and whether the data is used in line with that purpose, to know the third parties to whom the data is transferred domestically or abroad, to request correction if it is incomplete or inaccurate, to request erasure or destruction, to request that correction/erasure be notified to the parties the data was transferred to, to object to a result reached against you solely through automated analysis, and to claim compensation if you suffer damage. The GDPR additionally covers the right to receive your data in a portable format and to object to processing based on legitimate interest.
You can update your profile details, your page content and your password directly in your account settings, and you can start the deletion of your account from the same place. For any other request it is enough to write to the address below; provided we can verify your identity, we will conclude your request within the period required by law (at most 30 days under the KVKK).
Data Security
- Row-level security (RLS) is applied in the database: as a rule, each user can access only their own rows.
- The elevated-privilege service key exists only in code running on the server and is never sent to the browser; on visitor-facing endpoints (visit/click/poll/subscription/report) it is used through narrowly scoped, validated and rate-limited requests.
- Account passwords are stored by the authentication layer only as hashes; neither we nor our team can see the password itself. Link lock passwords are likewise kept as salted hashes.
- Notifications from the payment provider go through signature verification and the same event is never processed twice; maintenance jobs can only be triggered with a secret key.
- When you delete your account, your password is requested again during the process because the action is irreversible, and sessions on all devices are terminated.
No system is flawless; we cannot guarantee the absolute security of transmission over the internet. Use a strong password unique to this service to protect your account.
Children's Privacy
The Service is not directed at children under 13 and we do not knowingly collect data from anyone under that age. If we become aware of an account belonging to someone under 13, we close the account and delete the data. If you are a parent or guardian and believe your child has left data with us, please contact us.
International Data Transfers
The servers of the providers listed above may be located outside Türkiye, predominantly in the European Union and the United States. Your data may therefore be processed abroad. Transfers are made only to the extent necessary to provide the Service and within the providers' own contractual protection commitments (e.g. standard contractual clauses).
Changes to This Policy
When the data-processing behaviour of the Service changes, we update this document as well; the "last updated" date at the top of the page always reflects the version in force. When a significant change occurs we also notify registered users by email or in the application.
Contact
For privacy questions, requests and complaints: contact@linkygo.app