Privacy Policy
Effective date: September 17, 2026
This policy explains what LinkStack collects, how we use it, and the choices you have.
1. What LinkStack Does
LinkStack provides tools for creators and businesses to build link-in-bio pages, create Links, route visitors to destinations, manage affiliate-style links, and understand traffic through analytics.
Public LinkStack pages are public by default. Handles, profile content, images, links, social links, and public page settings may be visible to anyone who visits the page or sees it shared elsewhere.
2. How This Policy Applies
This policy applies when LinkStack controls how personal information is collected and used, such as when you create an account, use the dashboard, visit our website, subscribe to a paid plan, or contact us.
In some cases, a LinkStack user may use our tools to collect or display information from their own visitors, customers, or followers. In those cases, that LinkStack user may be responsible for their own privacy practices. If you interact with a creator's page or linked destination, review that creator's and third party's privacy terms too.
3. Information You Provide
Account and profile information, such as your email address, name, display name, handle, login details, profile image, bio, social links, settings, plan, and billing status.
Content you add to LinkStack, including bio pages, Links, destination URLs, routing rules, images, product cards, profile text, public page settings, ad pixel settings, and related metadata.
Payment and transaction information, such as subscription plan, billing email, billing history, invoices, and payment status. Payment card details are handled by our payment provider, and we do not store full card numbers.
Support and communication information, such as messages you send us, bug reports, feedback, requests, and information needed to respond.
4. Information Collected Automatically
Usage and analytics information, such as clicks, page views, link destinations, timestamps, referring pages, device type, browser type, operating system, broad location, and interaction data.
Technical and security information, such as IP address, session identifiers, authentication events, logs, error reports, rate-limit signals, and fraud or abuse indicators.
Advertising attribution information, such as campaign identifiers, browser or click IDs, and hashed account identifiers used to measure whether a campaign led to a signup, first product activation, or paid subscription.
Affiliate attribution information, such as the requested referral name, anonymous referral token, eligible landing path, referring website origin, click time, approximate country, region, and city, device type, browser, operating system, traffic source, affiliate link placement (such as a bio corner, bottom bar, or shared link), account signup attribution, subscription revenue, commission, refund or chargeback adjustments, and payout status. Affiliate click records do not store raw IP addresses.
Email and product communication engagement, such as whether you opened a message or clicked a link, if we send product, billing, support, or marketing communications.
5. Information From Third Parties
We may receive information from services you connect or use with LinkStack, such as authentication providers, payment providers, affiliate or commerce platforms, Amazon-related services, and social platforms.
If you connect Instagram and enable Comment Memory, we may store unmatched public comment text, commenter account identifiers, post identifiers, timestamps, and related metadata for up to 90 days so those comments can appear as inbox context after the commenter becomes a contact.
We may also receive information from service providers that help with hosting, storage, database, analytics, customer support, email, security, fraud prevention, and billing.
6. How We Use Information
To provide LinkStack, including account creation, login, profile pages, Links, routing, analytics, billing, support, and service communications.
To display public pages and route visitors to links chosen by LinkStack users.
To measure traffic, generate analytics, diagnose bugs, improve performance, personalize the product experience, and develop new features.
To protect LinkStack, users, visitors, and third parties from abuse, spam, fraud, security threats, unlawful activity, and violations of our Terms.
To process payments, manage subscriptions, maintain business records, comply with legal obligations, and enforce our rights.
To operate the LinkStack Affiliate Program, preserve first-qualified referral credit, calculate and reverse commission, prevent self-referrals and abuse, review attribution corrections, prepare payouts, and send program notifications.
7. Legal Bases Where Required
Where privacy law requires a legal basis, we may process information to perform our contract with you, based on our legitimate interests, with your consent, or to comply with legal obligations.
Our legitimate interests include operating and improving LinkStack, securing the service, preventing fraud, understanding product usage, communicating with users, and supporting business operations.
8. How We Share Information
Public content: public profile pages, handles, links, images, social links, and public settings may be visible to anyone.
Service providers: we share information with providers that help us run LinkStack, including hosting, database, authentication, storage, analytics, email, payment, support, security, and monitoring providers.
LinkStack campaign measurement: advertising providers such as Meta or Google may receive signup, first-product-activation, or paid-subscription events and attribution identifiers to measure LinkStack's own advertising. Depending on the event, this may include a hashed email or account ID, IP address, browser user agent, Meta browser or click IDs, plan, currency, and transaction value. We do not include names, phone numbers, birth dates, or precise location in these events.
Payment providers: payment information is processed by third-party providers such as Stripe. Their privacy terms apply to their handling of payment details.
User-enabled ad and analytics pixels: if a LinkStack user adds their own Meta, Google, TikTok, or similar pixel settings, those providers may receive information when visitors click that user's Links.
Third-party destinations: when a visitor clicks a link, they leave LinkStack and interact with the destination service. That destination controls its own privacy practices.
Legal and safety reasons: we may share information when needed to comply with law, respond to legal requests, enforce our terms, prevent harm, investigate abuse, protect rights, or complete a business transaction such as a merger, acquisition, financing, or sale of assets.
9. Cookies and Similar Technologies
We use cookies and similar technologies for login, session management, preferences, security, analytics, and product functionality.
For our own account signup analytics, we may preserve your first visit for up to 30 days using a first-party cookie. This includes available UTM campaign values, the landing page without query parameters, the referring website without its path or query parameters, and whether a Google or Meta click parameter was present. The cookie contains no email or account ID. We attach this context to a new account, including an account awaiting email confirmation, and honor supported Global Privacy Control signals by disabling this capture.
We may use advertising pixels and server-side conversion APIs to measure our own campaigns. We honor supported browser opt-out signals, including Global Privacy Control where required.
When a visitor arrives through an eligible paid campaign, we may keep an encrypted first-party attribution token for up to 30 days. It can contain campaign, ad, placement, landing-page, referrer, and advertising click or browser identifiers, but it does not contain the visitor's email or LinkStack account ID before signup. We use it to preserve measurement through authentication handoffs and remove it after a matched signup.
When a visitor arrives through a valid LinkStack affiliate link on an eligible LinkStack page, we may keep a random first-party referral token for up to 180 days. The first qualified affiliate remains assigned during that window. Before signup, the token does not contain the visitor's email or LinkStack account ID. If the visitor creates an account, we may lock the affiliate relationship to that account and remove the browser token.
LinkStack users may enable third-party ad or analytics pixels on Link clicks. Those pixels are controlled by the user and the third-party platform they connect.
Some cookies are required for LinkStack to work. Others may help us understand usage or improve the product. Browser settings may let you block or delete cookies, but parts of LinkStack may stop working.
10. Retention
We keep information as long as needed to provide LinkStack, maintain records, resolve disputes, enforce agreements, prevent abuse, comply with law, and support legitimate business needs.
A first-party paid-campaign token expires after 30 days and may be deleted sooner after a signup is matched. A completed campaign-to-signup record and its first activation or paid-subscription outcome may be retained with account and business analytics records as needed for measurement, fraud prevention, and legal or business obligations.
An unmatched LinkStack affiliate referral token expires after no more than 180 days. Locked affiliate attribution, commission, refunds, corrections, and payout records may be retained with account and business records as needed to honor the program, prevent abuse, resolve disputes, and meet tax, accounting, and legal obligations.
Unmatched Instagram comments stored through Comment Memory expire after 90 days unless they become part of conversation history or are otherwise needed for an automation, support, security, legal, or deletion workflow.
If you delete content or close your account, some information may remain for a limited period in backups, logs, analytics, billing records, security records, or legal records.
11. Security
We use reasonable technical and organizational safeguards designed to protect information, including access controls, encrypted transport, hosted infrastructure, logging, and monitoring.
No internet service is perfectly secure, so we cannot guarantee absolute security. If you believe your account or information is at risk, contact us.
12. Children
LinkStack is not intended for children under 13, and account holders must be old enough to enter into our Terms. We do not knowingly collect personal information from children under 13. If you believe a child provided us personal information, contact us so we can take appropriate action.
13. International Processing
If you use LinkStack from outside the United States, your information may be processed in the United States or other countries where we or our providers operate. Those countries may have different privacy laws than your location.
Where required, we rely on appropriate safeguards for international transfers.
14. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.
You can update many account and profile details in your dashboard. You can delete links, edit pages, cancel subscriptions, disconnect connected social accounts, or contact us for help with account access or deletion.
We may need to verify your identity before completing certain requests.
15. U.S. State Privacy Rights
Some U.S. state privacy laws give residents additional rights, such as the right to know what personal information is processed, obtain a portable copy, request deletion, correct inaccurate information, opt out of targeted advertising or certain data sharing, and avoid discrimination for exercising privacy rights.
LinkStack does not knowingly sell personal information of children under 16. If we use advertising or analytics cookies in a way that is considered a sale, sharing, or targeted advertising under applicable law, you may opt out where required.
16. California Privacy Notice
For California residents, categories of personal information we may collect include identifiers, account information, commercial or subscription information, internet or network activity, approximate geolocation, inferences, user-generated content, and sensitive information such as login credentials.
Sources may include you, your use of LinkStack, connected services, payment providers, service providers, and third-party integrations.
We may disclose these categories to service providers, payment providers, infrastructure providers, analytics providers, security providers, professional advisers, government authorities where required, and third parties at your direction.
California residents may request to know, access, correct, delete, or opt out of certain uses of personal information, subject to legal exceptions. Authorized agents may submit requests where allowed by law, but we may require verification.
17. Complaints
If you have a privacy complaint, contact us first and we will try to resolve it. Depending on where you live, you may also have the right to complain to a privacy or data protection authority.
18. Google Workspace API Data
When you connect Google Calendar, LinkStack may receive your Google account email, calendar-list metadata such as calendar names and identifiers, free and busy time ranges, and data needed to create and manage booking events and Google Meet invitations.
We use this information only to show calendars for selection, prevent scheduling conflicts, and create, update, or delete booking events and meeting details requested through LinkStack.
We do not sell Google Workspace data, use it for advertising or credit decisions, or use or permit raw, aggregated, anonymized, or derived Google Workspace data to create, train, or improve foundational or generalized artificial intelligence or machine-learning models.
Google Calendar account details, calendar names and identifiers, free/busy information, booking events, and Google Meet details are excluded from automatic assistant page context. The assistant does not query the Google Calendar API or its stored connection records. Connecting Google Calendar does not enable AI access to your calendar.
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
19. YouTube API Data
LinkStack uses YouTube API Services when you connect a YouTube channel. With your permission, we may access your channel ID, channel name, avatar, subscriber count, lifetime channel views, public video count, and metadata for public videos, Shorts, and live streams. We may also access YouTube Analytics and Reporting data, including 30-day views, watch time, likes, comments, thumbnail impressions, click-through rate, and aggregated age, gender, and country breakdowns.
We use this data only to connect the correct channel, sync creator-owned performance metrics, and create media kits. The connection is read-only: LinkStack cannot upload, edit, or delete YouTube videos or change channel settings.
LinkStack stores the channel identifier, encrypted OAuth access and refresh credentials, current imported metrics and content metadata, and a limited private Reporting cache needed to provide sync. We refresh connected data daily when available, remove automatic provider snapshots older than 30 days, and limit the Reporting cache to the most recent 30 days. Access continues only while the channel is connected and authorization remains valid.
Your imported YouTube data remains private unless you choose to include it in a media kit and share or publish that kit. Viewers see only the metrics, audience breakdowns, and content cards you choose, subject to that kit's access settings. LinkStack does not sell YouTube API data or use it for advertising, credit decisions, or to train foundational or generalized artificial intelligence or machine-learning models. We disclose it only to service providers that help us host, store, secure, monitor, and operate LinkStack, or when law requires.
You can stop future access by disconnecting YouTube in the LinkStack media-kit editor or by revoking LinkStack in your Google Account's third-party access settings, linked below. Disconnecting immediately removes imported YouTube data from active media kits and stops scheduled syncs. To request deletion of any remaining stored YouTube connection or analytics data, follow our Data Deletion Instructions or contact us. Deleting data from LinkStack does not delete your YouTube channel, videos, comments, or other data held by YouTube.
Our use and transfer of information received from YouTube API Services adheres to the Google API Services User Data Policy, including the Limited Use requirements, and is also subject to the Google Privacy Policy and YouTube Terms of Service. Those documents and Google's revocation controls are linked below.
20. AI Processing
LinkStack uses OpenAI models through Vercel AI Gateway for AI features such as assistant answers, writing and editing, inbox reply drafts, workflow generation, comment classification, and agent replies. Depending on the feature you use or enable, requests may include your instructions, content being edited, relevant conversation history, approved knowledge sources, product information, and supported page context.
Before using the in-app assistant, you are shown what information is sent and must choose Agree and continue. Messages and files you deliberately attach are sent for that request. Document text and images are processed by the model; only file names, not file contents, are kept in local chat history. We save the disclosure version and acceptance time to your account so the agreement carries across refreshes, sign-ins, and devices. We ask again if the disclosure changes or you withdraw consent. Automatic page context is limited to reviewed pages; Settings, scheduling and product-management pages, administration pages, and unreviewed pages supply only a general navigation label. Full browser URLs, query parameters, selected text, and global navigation are not included. Older assistant chats remain viewable on your device but are not resent to AI.
AI requests are restricted to approved OpenAI models and OpenAI as the serving provider. Requests use Vercel-managed provider credentials with no-training enforcement. Dashboard-configured third-party provider keys and other serving providers are excluded. If the required protections are unavailable, the request fails rather than using an unapproved route. We do not use these inputs or outputs to train foundational or generalized models.
If you include information in an AI prompt, it is processed to fulfill that request under the same no-training restrictions. Do not include information you do not want processed by these services. No-training controls are separate from data retention. Providers may retain information for security or legal purposes under their applicable terms. These controls do not delete content you save in LinkStack or chat history stored on your device.
Open AI privacy below the assistant message field to review the disclosure or choose Withdraw consent. Withdrawal stops subsequent assistant requests on your account; it does not undo requests already sent or delete saved chats. You can delete individual chats from History or disable AI features and agents separately. To stop Google Calendar access, disconnect it in Settings under Integrations and, if desired, remove LinkStack access in your Google account permissions. Contact us for help with deletion requests.
21. Changes and Contact
We may update this Privacy Policy as LinkStack changes. If changes are material, we will make reasonable efforts to notify users.
Questions or privacy requests can be sent through the LinkStack contact form.
For YouTube connections, review the Google Privacy Policy, YouTube Terms of Service, and Google API Services User Data Policy. You can revoke LinkStack's access from your Google Account permissions.
For questions or privacy requests, use the contact form . See also our Terms of Service , Data Deletion Instructions and Cookie Notice .