Part 02
Privacy Policy
We believe you have a right to know exactly what data we collect, why we collect it, and what we do with it — in plain language.
Who we are
LinkStacked is a bio link and creator commerce platform operated by Devpitch UG (haftungsbeschränkt), registered under HRB 266731 B at Amtsgericht Charlottenburg, Tucholskystraße 51, 10117 Berlin, Germany.
For privacy matters, you can reach us at privacy@linkstacked.com. For GDPR matters involving EU/UK residents, our designated contact is eu-privacy@linkstacked.com.
Data we collect
Account data
When you create a LinkStacked account, we collect:
- Name, email address, and username
- Password (stored as a bcrypt hash — never in plaintext)
- Profile photo (stored on AWS S3)
- If you sign in with Google or Apple: your OAuth identifier and email address from that provider
Profile content
Everything you add to your public LinkStacked profile: bio, links (URLs, titles, metadata), social platform handles, custom domain settings, digital products, appearance and theme preferences, and QR code configuration.
Commerce data
- When you connect Stripe as a seller: your Stripe account ID and Connect onboarding data. We do not store raw card or bank account numbers — Stripe holds and processes those.
- When a visitor purchases your product or sends a tip: transaction ID, amount, currency, and anonymised buyer email (sufficient to send receipts).
- Download activity for digital products (timestamp, file served) for fraud prevention and seller reporting.
Usage and analytics data
We operate our own first-party analytics infrastructure. When someone visits your public profile, we record:
- Page and link events (views, clicks, QR scans)
- Approximate geographic location (country/region, derived from IP address — the full IP is not stored)
- Device type, browser, and operating system
- Referrer URL (the page that linked to yours)
We also integrate with GA4 (Google Analytics Measurement Protocol) for aggregated website analytics. If you have enabled optional analytics cookies, GA4 may set additional cookies — see our Cookie Policy.
Support and communications
If you contact us by email or through the contact form, we store your name, email address, and the content of your message to respond and to track our support obligations.
Moderation and safety data
If a report is submitted about your profile or a link (by you or a third party), we retain the report details — including the reason, any submitted evidence, and the reporter's email if provided — to investigate and document our enforcement decisions.
How we use your data
We use the data we collect for the following purposes, each grounded in a lawful basis:
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account | Contract |
| Processing product sales, tips, and payouts via Stripe | Contract |
| Sending transactional emails (receipts, password resets, security alerts) | Contract |
| Providing creator analytics on your profile | Contract / Legitimate interests |
| Detecting and preventing fraud, abuse, and security incidents | Legitimate interests |
| Improving the platform through aggregated usage data | Legitimate interests |
| Sending product update and marketing emails | Consent (you can opt out any time) |
| Optional analytics cookies and GA4 tracking | Consent |
| Retaining financial records as required by law | Legal obligation |
Creator-controlled data processing
Creators can configure certain data-processing activities that apply to their own profile visitors. LinkStacked acts as a data processor for these activities; the creator is the data controller.
Retargeting pixels
Creators may enable third-party advertising pixels (Meta/Facebook, Google Ads, TikTok, Snapchat, Pinterest, X/Twitter) on their public profile. When a visitor with marketing consent visits that profile, the corresponding pixel script is loaded — potentially setting cookies and sending event data to those platforms.
Mailchimp audience sync
Creators who connect Mailchimp to their email-capture campaigns authorise LinkStacked to sync subscriber emails to their Mailchimp audience list. The creator controls which list is targeted and is responsible for their own email marketing compliance under applicable law.
Custom domains
When a creator uses a custom domain, that domain resolves through our infrastructure (AWS + Cloudflare). Visitor traffic data for those domains is processed identically to linkstacked.com traffic.
International data transfers
Devpitch UG is headquartered in Germany (EU). Several of our sub-processors are based in the United States. Where we transfer personal data from the EEA, UK, or Switzerland to the US, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU–US Data Privacy Framework where applicable
All sub-processors are bound by Data Processing Agreements (DPAs) that ensure they provide at least equivalent data protection to European standards. A copy of the applicable SCCs is available on request at privacy@linkstacked.com.
Data retention
- Account data is retained for as long as your account is active.
- If you delete your account, we will delete or anonymise your personal data within 30 days, except where a legal hold applies.
- Transaction records (orders, payouts, refunds) are retained for 7 years to comply with German commercial and tax law (HGB §257, AO §147).
- Moderation records (reports, enforcement actions) are retained for up to 3 years to document our compliance obligations.
- Aggregated, anonymised analytics data may be retained indefinitely — it cannot be linked back to any individual.
- Backup systems may retain copies of deleted data for up to 30 additional days before full purge.
Your rights
Depending on your location, you have the following rights over your personal data. EU/UK residents can find the full GDPR detail on our GDPR page. California residents should also see our CCPA Notice.
- Access — request a copy of the personal data we hold about you. Most data is available via Settings → Data → Export.
- Correction — correct inaccurate or incomplete data directly in your dashboard.
- Deletion — delete your account at Settings → Data → Danger zone. Full deletion completes within 30 days.
- Portability — download your data in machine-readable JSON format.
- Objection — object to marketing emails via the unsubscribe link in any email, or at Settings → Notifications.
- Restriction — request restricted processing while a dispute is pending.
Security
- All data is encrypted in transit using TLS 1.2+
- Sensitive fields (TOTP secrets, payment tokens) are encrypted at rest using AES-256
- Passwords are hashed with bcrypt (never stored in plaintext)
- JWT access tokens are short-lived (15 minutes); refresh tokens are rotated on use
- Rate limiting and bot detection protect all public API endpoints (Redis-backed)
- Google Safe Browsing checks all user-submitted URLs before they are stored
- Private product files are stored in a restricted S3 bucket and served only via signed, time-limited URLs (5-minute expiry)
- Admin accounts require two-factor authentication (enforced within a configurable grace period)
No method of electronic transmission or storage is 100% secure. We encourage you to use a strong, unique password and enable two-factor authentication in Settings → Security.
Children's privacy
LinkStacked is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you are between 13 and 16 and located in the EU, we may require verifiable parental consent before processing your data beyond strict service necessity.
If you believe we have inadvertently collected data from a child, please contact us immediately at safety@linkstacked.com and we will delete it promptly.
Changes & contact
We may update this Privacy Policy when we add new features, change vendors, or when the law requires it. We will notify you of material changes by email or by posting a prominent notice in your dashboard at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.
For any questions about this policy, contact us at privacy@linkstacked.com.
Devpitch UG (haftungsbeschränkt)
Tucholskystraße 51, 10117 Berlin, Germany
HRB 266731 B · Amtsgericht Charlottenburg
Questions about this policy?
Contact our legal team at legal@linkstacked.com or privacy@linkstacked.com for data matters. We respond within 5 business days.