← Back to LinkTaps

Privacy Policy for LinkTaps

Effective Date: January 17, 2026
Last Updated: April 14, 2026

Introduction

LinkTaps ("we," "our," or "us") is a minimal link redirect service that operates on a privacy-first principle. We are committed to collecting only the minimum amount of data necessary to provide our service and comply with legal requirements.

This Privacy Policy explains what information we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

Our Commitment to Minimal Data Collection

LinkTaps is designed from the ground up to minimize data collection. We:

Our Commitment to Minimal Permissions

Unlike most services that request broad access to your social media accounts upfront, LinkTaps only requests the specific permissions absolutely required for the features you choose to use. We believe you should have full control over what access you grant.

Data Controller

LinkTaps acts as the data controller for the personal data we collect through our service.

Contact Information:
Email: support@linktaps.io


1. Information We Collect

1.1 Information You Provide Directly

Account Information:

Link/Campaign Data:

Link-in-Bio Data:

Feedback and Support:

CSV Import Data:

1.2 Information Collected Automatically

Click Analytics (for your links): When someone clicks on your short link, we collect:

IP Addresses:

Bot Filtering:

Web Analytics (Cloudflare Web Analytics):

1.3 Cookies

We use only ONE cookie, which is strictly necessary for our service to function:

Session Cookie (connect.sid):

We do NOT use:

Because we only use essential cookies, you will not see a cookie consent banner on our site.

1.4 Information We Do NOT Collect or Store

1.5 Social Media Automation and Meta Platform Data

LinkTaps includes optional automation features that integrate with Facebook and Instagram through the Meta Platform APIs. This section describes what data we collect, how we use it, and how you can delete it.

Minimal Permission Model

We request only the Meta permissions strictly necessary for the features you activate. When you first connect, we request only the permissions required for the feature you chose to set up -- comment monitoring and messaging if you set up DM or comment automations, or publishing permissions if you set up Upload and Publish. Permissions for insights, content management, or other capabilities are never requested until you explicitly choose to enable those features. You can see exactly which permissions have been granted at any time in Settings > Connected Accounts, and you can upgrade or revoke permissions individually. This gives you complete control over what LinkTaps can and cannot do with your accounts -- a level of granularity that most automation services do not offer.

What We Collect via Meta APIs

When you connect a Facebook Page or Instagram account to LinkTaps, and when users interact with your connected posts, our system may receive the following data:

We do not collect email addresses, phone numbers, friend lists, or any private data beyond what is listed above through the Meta APIs.

How We Use Meta Platform Data

We use the data described above exclusively to:

Real-time processing. When Meta sends us a webhook notification about a new comment on your connected post, it is processed in real time by a Cloudflare Worker. The Worker matches the comment against your keyword rules, sends any configured replies, and logs the activity. Comment data is not stored by the Worker itself -- it is passed to our database only for activity logging and duplicate prevention.

Profile picture fetching. When you choose to pull a profile picture from a social media platform during account setup, we fetch the publicly available profile page to extract the image URL. This is done via a Cloudflare Worker and no login credentials or private data are accessed. The fetched image is stored in Cloudflare R2 as your profile picture.

We do not use Meta Platform Data for advertising, profiling, selling, or any purpose other than providing the automation and publishing features you configure.

Storage and Retention of Meta Platform Data

Data TypeRetentionPurpose
Comment IDs (dedup cache)7 daysPrevents duplicate replies to the same comment
Activity log (commenter name, comment text, reply sent, action taken)Until you delete itAudit trail for your automation activity
Post metadata (caption, media URL, permalink)Until you deactivate or delete the postMonitoring and rule matching
Keyword rules and DM rulesUntil you delete themAutomation configuration
Connected account tokensUntil you disconnect the accountAPI access for automation and publishing
Publish job recordsUntil you delete themPublishing status tracking
Deleting Your Meta Data

You can delete all Meta Platform Data stored by LinkTaps at any time:

When you disconnect an account or delete Meta data, we also attempt to revoke API permissions on Meta's side. For accounts connected via Facebook Login for Business, you may also need to remove the app from Business Suite > Settings > Integrations > Connected Apps.

1.6 AI-Powered Replies and Third-Party AI Processing

When you enable the AI Replies feature, comment text and commenter context from your connected posts may be sent to a third-party AI provider (OpenRouter) for processing. This is used solely to generate a relevant reply based on the knowledge base you configure.

You can disable AI replies at any time from the AI Replies tab in the dashboard.


2. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

Data TypeLegal BasisPurpose
Email address, account dataContractual necessityTo provide you with the link redirect service you requested
Click analytics dataLegitimate interestsTo provide you with analytics about your links' performance
Security logs, rate limitingLegitimate interestsTo protect our service from abuse and ensure security
Email delivery metadataLegal obligationSOC 2 compliance and audit trail requirements
IP address (geolocation)Legitimate interestsTo provide country-level analytics for your campaigns
Cloudflare Web AnalyticsLegitimate interestsTo improve our website and service
Meta Platform Data (comments, posts)Contractual necessityTo provide the automation features you configured
AI processing of commentsContractual necessityTo generate AI-powered replies you enabled

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Service Delivery

3.2 Service Improvement

3.3 Security and Compliance

3.4 Communication

- Free tier reminder emails as you approach your 2,000-action limit (sent at 1,000 / 1,500 / 1,800 / 2,000 actions). These are necessary to operate the service and are not opt-out while you remain on the free tier. - Pro plan reminder emails when you cross 4,000 monthly actions, so you can anticipate overage charges.


4. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Data TypeRetention PeriodReason
Account informationUntil account deletionService provision
Campaign/link dataUntil you delete the campaign or accountService provision
Click analyticsIndefinitely (aggregated)Analytics and service improvement
Click identifiers (clickid)Stored with click analytics, deleted with campaign/accountUsed only for analytics accuracy, not for cross-session tracking
Email audit metadata7 yearsSOC 2 compliance, legal requirements
Security logs90 daysSecurity monitoring and incident response
Rate limit counters1-24 hours (rolling windows)Abuse prevention
Session cookies7 days or logoutAuthentication
Inactive accountsMay be deleted after 2 years of inactivityData minimization
Meta automation activity logsUntil you delete via SettingsAudit trail
Meta comment dedup cache7 daysDuplicate prevention
Connected Meta account dataUntil you disconnect the accountAPI access
You can request deletion of your data at any time by contacting us or deleting your account.


5. Data Sharing and Disclosure

We do NOT sell your personal data to third parties.

We may share your information only in the following limited circumstances:

5.1 Service Providers (Data Processors)

We use the following third-party service providers who process data on our behalf:

ProviderPurposeData SharedLocation
ConvexDatabase hostingAll account and campaign dataUnited States
Amazon Web Services (AWS SES)Email deliveryEmail addresses, metadataUnited States
CloudflareWeb analytics, CDN, DDoS protectionIP addresses, browsing dataGlobal
Cloudflare WorkersReal-time webhook processing, profile picture scrapingMeta webhook payloads (comment text, user IDs), public profile URLsGlobal
Fly.ioApplication hostingHTTP request dataUnited States
Cloudflare R2Media file storageUploaded images and videosGlobal
OpenRouterAI reply generationComment text, knowledge base context (no PII)United States
StripePayment processing for Pro subscriptionsEmail, billing details (Stripe handles card data directly -- we never see or store it)United States
All processors are contractually bound to protect your data in compliance with GDPR.

5.2 Legal Requirements

We may disclose your information if required by law, such as:

5.3 Business Transfers

If LinkTaps is involved in a merger, acquisition, or sale of assets, your data may be transferred. You will be notified of any such change.


6. International Data Transfers

LinkTaps is operated from the United States. If you access our service from outside the United States, your data will be transferred to and processed in the United States.

For users in the European Economic Area (EEA), United Kingdom, or Switzerland:


7. Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights:

7.1 Right to Access

You can request a copy of the personal data we hold about you.

7.2 Right to Rectification

You can request correction of inaccurate or incomplete data.

7.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data by:

If you have an active Pro subscription, deleting your account will automatically cancel it via Stripe — no further charges will be made. Subscription fees and overage already incurred are not refunded.

Note: Some data may be retained for legal compliance (e.g., email audit logs for SOC 2; Stripe's own records of past transactions per their own retention policy).

7.4 Right to Restriction of Processing

You can request that we limit how we use your data in certain circumstances.

7.5 Right to Data Portability

You can request a machine-readable copy of your data to transfer to another service.

7.6 Right to Object

You can object to processing based on legitimate interests (such as analytics).

7.7 Right to Withdraw Consent

Where we rely on consent, you can withdraw it at any time (though this doesn't apply to most of our processing, which is based on contract or legitimate interests).

7.8 Right to Lodge a Complaint

You can file a complaint with your local data protection authority (DPA) if you believe we have violated GDPR.

To exercise any of these rights, contact us at: support@linktaps.io

We will respond to your request within 30 days.


8. Security Measures

We implement industry-standard security measures to protect your data:

Technical Measures:

Organizational Measures:

However, no system is 100% secure. If you discover a security vulnerability, please report it to support@linktaps.io.


9. Children's Privacy

LinkTaps is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If we learn that we have collected data from a child without parental consent, we will delete it immediately.

If you believe a child has provided us with personal data, please contact us at support@linktaps.io.


10. Do Not Track (DNT)

Some browsers offer a "Do Not Track" (DNT) signal. Because there is no industry standard for DNT, we do not currently respond to DNT signals. However, we already minimize tracking by:


11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, contact us at support@linktaps.io.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will:

Continued use of our service after changes constitute acceptance of the updated policy.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: support@linktaps.io

Mailing address: OutdoorSavannah LLC, Ramsey County, Minnesota, United States

Data Protection Inquiries: For GDPR-specific requests, please include "GDPR Request" in the subject line.


14. Key Takeaways (Summary)

For your convenience, here's a summary of our privacy-first approach:

  • Minimal Data Collection: We collect only what's necessary to run our services
  • No Cookie Banner: We use only essential authentication cookies
  • No Email Content Storage: Only metadata is stored for compliance
  • No Data Selling: We never sell your data to third parties
  • Cookieless Analytics: Cloudflare Web Analytics doesn't use cookies
  • GDPR Compliant: Full user rights support (access, deletion, portability, etc.)
  • Minimal Permissions: Only the permissions you need, upgraded one at a time under your control
  • Meta Data Transparency: Clear documentation of what Meta Platform Data we collect and why
  • Self-Service Deletion: Delete all Meta data anytime from Settings > Connected Accounts
  • AI Transparency: Comment text sent to AI providers contains no personally identifiable information
  • Privacy by Design: Built with data minimization as a core principle

  • Thank you for trusting LinkTaps with your link management needs.