Privacy Policy
1. Overview & Scope
This Privacy Policy describes how SetLinks (the "Service") collects, uses, retains, and shares information when you create an account, create or manage links, or visit a link created through the Service. It applies to the marketing site you are reading now and to the dashboard application.
2. Data Controller
The data controller for the purposes of this Policy is {{LEGAL_ENTITY}}, located at {{ADDRESS}}. You can reach us at {{CONTACT_EMAIL}} for any question about this Policy or your data.
3. Data We Collect
We collect the following categories of data:
- Account data — your name and email address, collected through Firebase Authentication when you sign in with Google or with an email and password.
- Team and role data — which team you belong to and your role within it (owner, admin, or member), stored in our own database.
- Usage data — aggregated click and scan counts for your links, the visitor's country (derived from their IP address at the moment we process the click, and not stored as a raw IP address long-term), a coarse platform/device class (for example, "iOS" or "Android"), and the referring source, where available. We do not perform browser-fingerprint-based visitor identification — this is a deliberate design choice, not merely an absence of the feature, made because fingerprinting individual visitors carries privacy exposure we are not willing to accept.
- Billing data — handled entirely by Stripe. We never receive or store your card number; Stripe shares with us only your subscription's plan and status.
4. How We Use Data
We use the data described above to:
- Operate the Service, including resolving links and generating QR codes;
- Show click and scan analytics to your account's team;
- Process payment for paid plans through Stripe;
- Respond to support requests you send us.
5. Data Retention
Raw click events are retained for 90 days and then deleted; the dashboard never shows analytics older than that window. Account and team data is retained until you delete your account. Aggregated, daily click totals derived from raw events may be retained longer than 90 days for the purpose of showing your account's own historical trend, without the underlying per-click detail.
6. Third-Party Processors
We share data with the following categories of processor, each for a specific purpose:
- Firebase / Google Identity — authentication.
- Stripe — payment processing and subscription billing.
- Our cloud infrastructure provider — hosting and content delivery for the Service. The specific provider is an internal implementation detail, not a fact a visitor needs in order to understand how their data is handled.
7. Cookies & Local Storage
This marketing site sets no tracking cookies — it is static, and click/scan analytics for your links are collected server-side from access logs, not by a client-side tracker running on this page. The dashboard, a separate application, uses a session mechanism to keep you signed in; that mechanism is out of this document's marketing-site scope but is mentioned here for completeness.
8. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or export the personal data we hold about you, subject to applicable law in your jurisdiction ({{JURISDICTION}}). To exercise any of these rights, contact us at {{CONTACT_EMAIL}}.
9. Children's Privacy
The Service is not directed at children under 16, and we do not knowingly collect personal data from them.
10. Changes to this Policy
We may update this Policy from time to time. We will notify you of a material change by email or by an in-dashboard banner before the change takes effect.
11. Contact
Questions about this Policy may be sent to {{CONTACT_EMAIL}}.