Privacy Policy
Last updated: 13 September 2026 · Effective: 13 September 2026
Linkspot.bio ("Linkspot", "we") is the data controller for the link-in-bio, QR code and analytics services provided at linkspot.bio and its subdomains (the "Service"). This policy explains which personal data we collect when you use the Service, why and on what legal basis we process it, who we share it with and what rights you have under the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Turkey's Personal Data Protection Law No. 6698 ("KVKK").
1. Scope and roles
- Controller for account holders: data of users who register and build pages ("Members").
- Controller / processor for visitors: data of people who view Members' public pages ("Visitors"). For data a Member collects through forms, email-capture blocks or polls on their own page, the Member is the controller and Linkspot acts as processor.
2. Data we collect
2.1 Data you give us
- Account data: name, username, email address, password (stored only as a one-way hash), profile photo, and identity details passed by Google or Apple when you use social sign-in.
- Page content: bio, links, images, videos, products, forms and anything else you add to your page.
- Billing data: plan, invoice details (company name, address, tax ID). Card numbers never reach Linkspot servers; they are processed PCI-DSS compliantly by our payment provider (iyzico, Stripe or PayTR).
- Support communications: whatever you send us through the contact form or by email.
2.2 Data collected automatically
- Usage and device data: IP address, browser type, operating system, device class (mobile / tablet / desktop), referring page, language, page viewed and link clicked.
- Approximate location: a country code derived from the IP address. The IP address itself is not written to analytics records; only the country is kept.
- Cookies and similar technologies: see our Cookie Policy.
2.3 Visitor data
When you view a public Linkspot page we process only the pseudonymised usage data listed in 2.2. If you submit a form, subscribe or vote in a poll on a page, that information is delivered to the page owner and is governed by their privacy practices.
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR Art. 6 / KVKK Art. 5) |
|---|---|---|
| Creating your account, authentication, providing the Service | Account and page data | Performance of a contract |
| Payments, invoicing, accounting | Billing data | Contract; legal obligation (tax law) |
| Providing page owners with visitor statistics | Pseudonymised usage data | Legitimate interest |
| Security, abuse and fraud prevention, rate limiting | IP address, usage data | Legitimate interest; legal obligation |
| Service emails (verification codes, invoices, security notices) | Contract | |
| Marketing emails | Consent (withdrawable at any time) | |
| Analytics and preference cookies | Cookie identifiers | Consent |
4. Sharing
We do not sell your personal data. We share it only as follows and only to the extent necessary:
- Processors: hosting and CDN (Cloudflare), transactional email (our SMTP provider), payments (iyzico / Stripe / PayTR), error monitoring (Sentry) and bot protection (Cloudflare Turnstile). Every processor is bound by a data processing agreement.
- Page owners: data you enter into a Member's form is delivered to that Member.
- Legal requirements: in response to a court order, prosecutor's request or a binding request from a competent authority.
- Corporate transactions: in a merger, acquisition or asset sale, subject to this policy.
5. International transfers
Our servers are hosted in Turkey. Because of CDN, email and payment services, data may be transferred to processors in the European Union or the United States. Such transfers rely on adequacy decisions, the EU Standard Contractual Clauses, the equivalent safeguards under KVKK Art. 9, or your explicit consent.
6. Retention
- Account data: for as long as your account exists; permanently deleted within 30 days of a deletion request.
- Invoices and payment records: 10 years, as required by tax law.
- Analytics events (country, device, referrer): 24 months, then aggregated.
- Access and security logs: between 1 and 2 years, as required by Turkish Law No. 5651.
- Support conversations: 3 years after the last message.
7. Security
Data is encrypted in transit with TLS 1.2+. Passwords are stored with salted one-way hashing; sensitive settings such as API keys and SMTP credentials are encrypted at the application layer. Access is limited by role-based permissions and administrative actions are recorded in an audit log. In the event of a personal data breach we notify the supervisory authority and affected users within the statutory deadlines (no later than 72 hours).
8. Your rights
Under GDPR Arts. 15-22 and KVKK Art. 11 you have the right to be informed, to access and obtain a copy of your data, to rectification, to erasure ("right to be forgotten"), to restriction of processing, to object, to data portability and to withdraw consent. Exercise these rights from Account → Profile → My data or by emailing [email protected]. We respond free of charge within 30 days. You may also lodge a complaint with the Turkish Personal Data Protection Authority or the supervisory authority of the EU member state where you live.
9. Children
The Service is not directed at children under 13; users under 18 must register with parental consent. If we learn we have collected a child's data without appropriate consent we delete it promptly.
10. Changes
We may update this policy from time to time. For material changes we give at least 14 days' notice by email or in-app notification. The current version is always published on this page.
11. Contact
Controller: Linkspot.bio · Privacy: [email protected] · Support: [email protected]
