Legal
Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains what personal data LINKNOWN collects when you use the Service, why, where it is stored, and what rights you have over it. It should be read together with our Terms of Service.
On this page
1. Data Controller
İlkay Bora, operating LINKNOWN from Türkiye, is the data controller for personal data processed through the Service. For any question or request regarding your data, contact ilkay.bora@outlook.com.
2. Data We Collect
We collect the following categories of data:
- Account data: your name, email address, age, a securely hashed password, and your security question and answer, all provided when you register.
- Content data: the URLs you shorten, the QR codes you generate, custom short codes, and the mini sites you build, including their text, images referenced by URL, and settings.
- Usage data: click counts on your links, views and link taps on your mini sites, a mobile-versus-desktop breakdown, and approximate visitor counts. Visitor counts are derived by hashing a visitor's IP address and browser user-agent into a one-way identifier with a secret salt; the raw IP is not stored.
- Technical data: IP address, browser user-agent, and timestamps in server logs, kept for security and troubleshooting.
- Billing data (Pro only): your plan, subscription status, and Paddle customer and subscription identifiers. Card details are handled entirely by Paddle; we never see or store them.
3. How We Use Data and Legal Bases
We use account and content data to provide your account and the shortening, QR, and page-building services you request (performance of our contract with you, GDPR Art. 6(1)(b) and the equivalent KVKK basis). We use usage and technical data to produce your analytics, to keep the Service secure, and to prevent abuse (our legitimate interest in a safe, working service). We use aggregate analytics from Google Analytics to understand overall usage and improve the product (legitimate interest, or consent where cookies require it). We process billing data to operate the Pro plan (contract). We do not sell personal data, and we do not use your content to train machine-learning models.
4. Cookies and Similar Technologies
LINKNOWN uses a small number of cookies and similar technologies:
- A session token keeps you signed in to the dashboard; it is strictly necessary and set only after you log in.
- Google Analytics and Google Tag Manager set analytics cookies to measure aggregate usage of the marketing site and app.
- A cookie-consent banner, provided by consentmanager, lets you accept or reject non-essential cookies and change your choice at any time.
- The site remembers your language choice.
- Public mini sites you publish do not set advertising or cross-site tracking cookies.
5. Sub-processors
We use a small number of providers to run LINKNOWN. Each processes data only as needed to provide its part of the Service.
- Vercel (Vercel Inc.) — hosts the web front end and CDN; compute runs primarily in the United States.
- Server host — a virtual server in Germany (EU) runs the LINKNOWN API that handles accounts, links, redirects, and analytics.
- MongoDB Atlas (MongoDB, Inc.) — the managed database that stores account, link, QR code, page, and click data. You can ask us for the current hosting region.
- Cloudflare (Cloudflare, Inc.) — provides the Turnstile bot check shown on the redirect page, to stop automated abuse of short links.
- Google (Google LLC) — Google Analytics and Google Tag Manager process usage data for aggregate statistics; primarily in the United States.
- consentmanager (consentmanager GmbH) — runs the cookie-consent banner; based in the EU.
- Paddle (Paddle.com Market Limited) — Merchant of Record for the Pro plan. Processes your billing and payment data as an independent controller under its own privacy policy, and sends billing and receipt emails; based in the United Kingdom.
6. International Data Transfers
Some processing happens outside your country of residence, for example Vercel compute and Google Analytics in the United States. Where personal data is transferred outside the EU/EEA, the UK, or Türkiye, we rely on the transfer mechanisms those providers offer, primarily the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. You can ask us for more detail on a specific transfer.
7. Data Retention
We keep data only as long as it is needed:
- Account data: kept while your account is open. Deleting your account anonymizes your profile so you can no longer log in; contact records are removed within 30 days, except where a legal or tax obligation requires keeping something longer.
- Content and click data: kept while your account is active. You can delete individual links, QR codes, or pages at any time from the dashboard.
- Server logs: retained for a short period, then deleted or anonymized.
- Billing records (Pro): invoice and transaction records are kept by us and by Paddle for as long as tax law requires, typically several years.
8. Your Rights
Under the GDPR, and equivalently under Türkiye's KVKK, you have the right to access, correct, export (portability), delete, or restrict the processing of personal data we hold about you, and to object to processing based on legitimate interest.
- You can exercise the access, portability, and erasure rights directly from your Profile page ("Download my data" and "Delete account").
- For any other request, or if the self-serve tools do not cover your case, contact us from your account email and we will respond within 30 days.
- You also have the right to lodge a complaint with your local data-protection supervisory authority (in Türkiye, the KVKK Board).
9. How We Protect Data
Security measures include:
- Passwords and security answers are stored only as salted hashes, never in plain text.
- All traffic is served over HTTPS/TLS.
- Dashboard data access is authorized per account and checked on every request.
- Visitor IP addresses are hashed with a secret salt and discarded; the raw IP is not written to the database.
- The database is a managed MongoDB Atlas cluster with access restricted to the application, and backups are enabled.
10. Data Breach Notification
If we become aware of a security breach affecting your personal data, we will investigate promptly, act to contain it, and notify you and any relevant supervisory authority without undue delay, within 72 hours where the law requires it, including what happened, the data involved, and what we and you can do about it.
11. Children's Privacy
LINKNOWN is not directed at children under 13, and we do not knowingly collect personal data from anyone under that age. If you are under the age of digital consent where you live (16 in the EU by default, though some member states allow as low as 13), you may only use the Service with a parent or legal guardian's consent. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date on this page, and for significant changes we will notify account holders by the contact email on the account or an in-dashboard notice before they take effect.
13. Contact
Questions about this Privacy Policy, or to exercise a privacy right, can be sent to ilkay.bora@outlook.com. If you are in the EU/EEA or UK and want a single point of contact for data protection, use the same address and mark it for the attention of the privacy contact.
İlkay Bora is the data controller for personal data processed through LINKNOWN. For the personal data of people who click your links or visit your pages, you also have your own obligations as their controller.