Privacy Policy

Last updated: May 2026

These terms are a draft. We're still finalizing legal review — please reach out with any questions in the meantime.

We collect only the data needed to run your Linkhiver — your email, profile details, the links you create, and aggregated analytics about visits to your public profile. We don't sell your data. A full privacy policy with details on storage, retention, third-party processors, and your data rights will be published here once legal review is complete.

Third-party processors we share data with

We rely on the following processors to operate the service. Each one only receives the minimum data needed for its role.

  • Supabase — managed PostgreSQL database, authentication, and file storage. Hosts your account, profile, links, gallery, QR codes, and analytics events.
  • Paddle (Paddle.com Market Ltd) — our merchant of record: processes payments, subscriptions, invoicing, and tax for paid plans.
  • Sentry — application error and performance monitoring. Receives stack traces, request URLs, and limited diagnostic metadata when something fails so we can fix it.
  • Google Analytics 4 — aggregated product analytics. Off by default: it loads only after you turn it on in the cookie banner or in Settings, and it never runs on public profile, business card, or QR pages. You can revoke it at any time.
  • Cloudflare Turnstile — bot protection on sign-in and sign-up forms. Sees the form interaction signals needed to issue a verification token.

Advertising pixels on creator pages

A creator can connect their own advertising pixel (Meta, TikTok or Google Analytics) to their public page. When they do, and only after you agree to the consent bar shown on that page, those providers receive your page view, how long you stayed, which links you tapped, and any contact save or signup — under their own privacy policies and for that creator's advertising account, not ours. If you decline, no pixel loads and nothing is sent. Pages without a connected pixel show no bar and load no third-party script. You can change this answer at any time from Cookie Preferences.

Visitor analytics on public profiles

When someone opens a public Linkhiver profile we record the visit so the profile owner can see view and click counts. These records are cookieless — we store nothing on the visitor's device and no identifier for them, only the event type, the link tapped, the referring site, a coarse device category, and a country derived from the network request. We rely on legitimate interest for this, and any visitor can switch it off under Cookie preferences.

How you use your dashboard

While you are signed in we record how you use Linkhiver itself — which dashboard pages you open and which features you use, such as adding a link or creating a QR code. This is first-party product data about your own account: it stays in our database, is never shared with or sold to anyone, and we store no IP address, no browser or device fingerprint, and nothing about the content you create. We use it only to see where the product helps and where it gets in the way. It rests on legitimate interest, so it is not part of the cookie banner, and every record is deleted along with your account.

Agent access (MCP)

You can connect an AI agent — Claude or another MCP-compatible client — from Settings → Integrations. Once connected, it can read your profile, links, appearance, and analytics, and, only on a Pro plan, create, edit, reorder, and delete links and edit your profile and appearance. No subscriber or lead data is ever exposed to a connected agent, and it cannot change your username, view billing, or delete your account. We never store an agent's access token in plain text — only its HMAC-SHA256 hash, the same protection our API keys use — so a leaked database snapshot cannot be replayed as a working token. An access token is valid for one hour and renews automatically while the connection stays active; you can revoke the connection at any time from Settings → Integrations, and revocation takes effect immediately. Full setup and tool documentation is available on our agent access documentation page. Questions about this section can be sent to support@linkhiver.com.

Your rights

You can request a copy of your data (right to data portability) or permanently delete your account from Settings → Danger zone. Both actions also remove related links, gallery items, QR codes, and analytics rows.

Questions? Email support@linkhiver.com and we'll get back within one business day.

Privacy Policy · Linkhiver