Privacy Policy
Last updated: July 2026
This Privacy Policy describes what personal information Linkssi (the "Service") collects about you, why we collect it, how we store and use it, and the rights you have over it under the Protection of Personal Information Act, 2013 (POPIA) of South Africa.
We're the "responsible party" for your personal information. Linkssi is operated from Durban, South Africa.
1. Who this policy covers
This policy applies to two different groups of people:
- Linkssi customers — the people who sign up for an account, build a link page and pay for a subscription.
- Visitors to our customers' pages — the people who click on, fill in forms on, or book through a Linkssi-hosted page. For that data, our customer is the responsible party; we're their processor. Contact the relevant page owner for requests about this data.
2. What we collect from customers
2.1 Account information
When you register we collect your name, email address and (if you set one) a profile picture. When you subscribe to a paid plan we collect your billing country. We don't store your credit card details — Paddle, our merchant of record, handles the card directly and returns a tokenised reference we use for recurring charges.
2.2 Content you upload
Anything you put on your page: images, copy, links, bookable event descriptions, lead-form configurations, newsletter content, custom domains you attach.
2.3 Usage data
We collect basic operational data: sign-in times, IP address at sign-in, browser and device type, actions taken in the dashboard. We use this to detect abuse, debug problems, and improve the product.
2.4 Analytics for your page
When someone visits or clicks on your Linkssi page, we record the event (timestamp, link clicked, referrer, rough location from IP, device type) so you can see it in your analytics dashboard. We do not sell or share this data with anyone else.
2.5 Cookies
Linkssi uses a small number of cookies: a session cookie that keeps you signed in, a CSRF-protection cookie, and (on the marketing site) a currency-preference cookie. We don't use advertising cookies or third-party trackers for marketing retargeting.
3. Why we collect it
We process your data for these specific purposes:
- To provide the Service you signed up for (you can't have an account without an email address).
- To take payment via Paddle and to reconcile renewals and cancellations.
- To send transactional emails — welcome, password reset, billing receipts, failed-payment warnings.
- To show you analytics for your page.
- To sync appointments with Google Calendar when you connect that integration (create events, Meet links for video bookings, and block busy times).
- To detect abuse and respond to security incidents.
- To comply with legal obligations (tax records, lawful requests from authorities).
We only send marketing emails to customers who have explicitly opted in. You can unsubscribe any time with one click.
4. Who we share it with
We share the minimum necessary amount of data with these service providers:
- Paddle.com Market Limited — our merchant of record. Paddle processes every paid subscription globally, collects and remits sales tax / VAT on our behalf, and handles chargebacks and refunds. Shared: name, email, billing address, plan, and transaction amount. Paddle's privacy policy.
- Cloudflare — CDN and custom-hostname routing. All traffic to Linkssi pages flows through Cloudflare's edge; Cloudflare sees IP addresses and request metadata but does not decrypt content we don't give it.
- Xneelo — our South African hosting provider, where the application servers and databases live.
- Our SMTP provider — to deliver transactional and customer newsletter emails.
- Google — only if you connect Google Calendar in Bookings. We use Google’s OAuth and Calendar APIs so Linkssi can create booking events, generate Google Meet links when you choose a video meeting, and read busy times to avoid double-booking. Shared: OAuth tokens for your connected Google account, event titles/times you book through Linkssi, and calendar free/busy ranges we need for availability. We do not sell Google user data or use it for advertising. You can disconnect at any time under Dashboard → Bookings → Integrations. See our Google API Disclosure and the Google API Services User Data Policy (including Limited Use requirements).
We don't sell your personal information. Ever.
We may disclose information if we're legally compelled to (court order, tax authority request), or when needed to protect our rights, safety, or the safety of others.
5. Where we store it
Our production databases run on servers located in Johannesburg, South Africa. Operational backups are encrypted and stored in the same jurisdiction. Some processors (Paddle, Cloudflare) are international and may store data outside South Africa — we rely on their published safeguards for cross-border transfers.
6. How long we keep it
For as long as you have an active account, plus a retention window afterwards:
- Account + content data: 90 days after account deletion, then permanently removed.
- Billing records: 5 years — SARS requires us to keep tax records this long.
- Analytics events: 365 days rolling window.
- Server logs: 30 days.
7. How we protect it
HTTPS on every request (enforced via HSTS), passwords stored as bcrypt hashes, server-side CSRF tokens on every form, SQL parameterised in every query, database backups encrypted at rest. We review our security posture periodically and patch server OS + library dependencies.
8. Your rights under POPIA
As a South African data subject — and regardless of where you live, these rights apply to the data we hold about you — you have the right to:
- Access — ask us what data we hold about you.
- Correct — ask us to fix inaccurate information.
- Delete — ask us to remove your data, subject to our legal retention obligations (see section 6).
- Object — tell us to stop processing your data for a particular purpose (e.g. marketing).
- Withdraw consent — where processing is based on consent.
- Complain to the Information Regulator of South Africa if you believe we've mishandled your data.
To exercise any of these rights, email us via the contact page. We'll respond within the POPIA-required timeframe (30 days or less).
9. Children
Linkssi is not directed at children under 18 and we don't knowingly collect data from them. If you believe a child has created an account, contact us and we'll remove it.
10. Changes to this policy
We may update this policy. If we make material changes, we'll email customers at least 30 days before the new version takes effect. The "Last updated" date at the top of the page always reflects the current version.
11. Contact us
For any privacy-related question, or to exercise a POPIA right, reach us via the contact page.