Services Privacy Policy

Last Updated: 4 May 2026

This Services Privacy Policy describes how LinkForty ("we," "us," or "our") processes end-user personal data on behalf of our customers when those customers integrate our mobile or web SDK, use our redirect/click-tracking infrastructure, or otherwise route end-user events through the LinkForty platform. It does not cover information we collect directly from visitors to our own website or from holders of LinkForty accounts — for that, see our Website Privacy Policy.

Controller and Processor Roles

When our customers use LinkForty to process their end-users' data, our customer is the data controller and LinkForty, Inc. acts as the data processor under a Data Processing Agreement. Our customer determines what data is collected and for what purposes; we process that data only to provide the Service. End-users with questions about the use of their data should contact the customer whose application or link they interacted with.

1. Scope and Roles

This policy applies to personal data we process on behalf of our customers in the following contexts:

  • Mobile SDKs: iOS, Android, React Native, and Expo SDKs that our customers embed in their applications
  • Redirect and click tracking: Short links and custom domains that route end-users to destinations specified by our customer
  • Install attribution: Matching click events to subsequent app installs and first-opens
  • In-app event ingestion: Custom conversion events forwarded by our customer's application
  • Analytics dashboards: Aggregated and event-level reporting visible to our customer

For all of the above, our customer is the data controller. LinkForty, Inc. is the data processor and processes the data only on the customer's documented instructions, including those reflected in our standard Data Processing Agreement and these Services terms.

2. Data We Process on Behalf of Our Customers

The categories of end-user personal data we may process for our customers include:

  • Advertising identifiers (where available): Apple Identifier for Advertisers (IDFA), Google Advertising ID (GAID), Android ID, Identifier for Vendors (IDFV)
  • Device fingerprint signals: Operating system, OS version, device model, screen resolution, language, timezone, user agent, carrier, and network type — combined probabilistically to match a click to an install when a direct identifier is unavailable
  • Click and install events: Short link clicked, deep-link parameters, click timestamp, referrer, install timestamp, and first-open timestamp
  • In-app conversion events: Custom events passed explicitly by our customer's application
  • IP address: Used transiently for geolocation (country/city) and fraud detection, then truncated or discarded per retention schedule
  • User-agent and request metadata: Browser type, device class, and other request headers used for routing and analytics

We do not sell this data and we do not use it to build cross-customer advertising or identity graphs. Data processed on behalf of one customer is not commingled with another customer's data for analytics purposes.

3. Purposes of Processing

We process the data described above only to:

  • Route end-users to the destinations specified by our customer (deep linking, deferred deep linking, web fallbacks)
  • Match click events to install events to enable attribution reporting
  • Generate analytics dashboards and exports for our customer
  • Detect and prevent fraud, abuse, click spam, install farms, and SDK spoofing
  • Provide technical support and debug attribution issues raised by our customer
  • Maintain the security, integrity, and reliability of the Service
  • Comply with legal obligations applicable to us as a processor

4. Data Sharing and Sub-processors

We engage trusted third-party sub-processors to operate the Service. Sub-processors process data only on our documented instructions and are bound by contractual obligations equivalent to those we accept from our customers. Categories include:

  • Cloud infrastructure: Hosting, databases, and storage
  • Edge networking: CDN and custom-domain routing
  • GeoIP services: Country and city derivation from IP addresses
  • Email delivery: Transactional notifications related to the Service
  • Operational monitoring: Logging and error tracking

A current list of sub-processors is available on request. We will provide reasonable advance notice of changes to our sub-processor list so that our customers may object before a new sub-processor begins processing data.

Beyond sub-processors, we disclose end-user data only when required by law, legal process, or government request, or to protect our rights, property, or safety. Where legally permitted, we will notify the affected customer before disclosure.

5. Storage, Security, and Retention

5.1 Storage and Security

  • Data is stored in secure data centers operated by our infrastructure sub-processors
  • We use industry-standard encryption for data in transit (TLS) and at rest
  • Access to production systems is restricted by role-based access controls and audited
  • We perform regular security reviews and maintain monitoring and incident-response procedures
  • Database backups are performed regularly and stored securely

5.2 Retention by Plan Tier

Click and install events are retained for the period associated with our customer's subscription tier:

  • Free: 7 days
  • Pro: 90 days
  • Business: 180 days
  • Unlimited: 365 days

Events older than the applicable retention window are automatically deleted by a scheduled job. Aggregated, non-identifiable analytics may be retained longer for service-improvement purposes. Backups containing event data may persist for up to 90 days. On termination of our customer's account, we delete or return their data within 30 days, subject to legal retention obligations.

5.3 Breach Notification

In the event of a personal-data breach affecting data we process on a customer's behalf, we will notify the affected customer without undue delay and, where feasible, within 72 hours of becoming aware, with the information required for the customer to fulfill its own notification obligations.

6. End-User Rights

Because our customer is the data controller for end-user data, requests from end-users to exercise privacy rights — including access, correction, deletion, restriction, objection, and portability under GDPR, UK GDPR, the Swiss FADP, CCPA/CPRA, and other applicable laws — should be directed to the customer whose application or link the end-user interacted with.

If an end-user contacts us directly, we will, where possible, forward the request to the appropriate customer and assist that customer in responding. We will act on individual requests only on the customer's instructions, except where we are independently required to do so by law.

7. International Data Transfers

End-user data may be transferred to and processed in countries other than the country of origin, including the United States. When we transfer personal data out of the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on one or more of the following legal mechanisms:

  • Standard Contractual Clauses (SCCs): European Commission-approved clauses incorporated into our Data Processing Agreement and our agreements with sub-processors
  • UK International Data Transfer Addendum: For transfers originating in the United Kingdom
  • EU-U.S. Data Privacy Framework (DPF), UK Extension, and Swiss-U.S. DPF: Where we or our sub-processors are certified participants
  • Adequacy decisions: Transfers to countries recognized as providing adequate protection

Customers may request a copy of the relevant transfer mechanism by contacting us using the details in Section 10.

8. Children's Data

The Service is not intended for use with end-users below the applicable age of digital consent (under 13 in the United States under COPPA, under 16 under GDPR unless a member state has set a lower age, and any higher age set by other local laws). Our customers must not configure the SDK or platform to collect or process personal data from end-users below these ages, and must not transmit such data to us.

If we become aware that we have processed personal data of a child in violation of this policy, we will delete it promptly and notify the affected customer. Parents or guardians who believe their child's data has been processed through the Service should contact the customer whose application was used and may also contact us using the details in Section 10.

9. Customer Obligations and Data Processing Agreement

As the data controller, our customer is responsible for:

  • Establishing a lawful basis for processing end-user data, including obtaining any required consent under applicable law (including GDPR, the ePrivacy Directive, CCPA/CPRA, and App Store tracking rules such as Apple's App Tracking Transparency framework and SKAdNetwork/SKAN constraints)
  • Providing end-users with all required notices, including a privacy notice that describes the customer's use of LinkForty and the categories of data processed
  • Honoring end-user rights requests as the controller
  • Configuring the SDK and platform in compliance with applicable platform policies (Apple App Store, Google Play, and others)
  • Not transmitting categories of data to us that they have not disclosed to their end-users

Customers processing personal data subject to GDPR, UK GDPR, the Swiss FADP, or other regional laws that require a data processing agreement may execute our standard Data Processing Agreement, which includes Standard Contractual Clauses and the UK Addendum where applicable. Contact us using the details in Section 10 to request a copy.

10. Changes and Contact

10.1 Changes to This Policy

We may update this Services Privacy Policy from time to time. Material changes will be notified to our customers via email or in-app notification at least 30 days before taking effect. Continued use of the Service after changes constitutes acceptance.

10.2 Contact Us

For questions about how we process end-user data on behalf of our customers, to request our Data Processing Agreement, or to request our current sub-processor list:

Company: LinkForty, Inc.
Product: LinkForty
Data Protection Officer: [email protected]
Email: [email protected]
Response Time: Within 14 days