Privacy Policy
This policy explains what personal data LookLink (looklink.net) collects, why, where it is kept and what rights you have. The controller is SIA "Synchron", Ūnijas iela 74A - 45, Rīga, LV-1084, Latvia. Questions and requests: [email protected].
1. Who this policy covers
- Account holders — people who sign up and build a page.
- Visitors — people who open a public page (on looklink.net or on a custom domain connected by the account holder).
2. What we collect and why
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address, password (stored only as a salted hash) | Creating and securing your account; login links and password resets | Contract (6.1.b) |
| Username, display name, bio, profile photo, links, theme, thumbnails | Publishing your page — this is public by design | Contract (6.1.b) |
| Custom domain name and its verification token | Serving your page on your own domain and issuing its TLS certificate | Contract (6.1.b) |
| Subscription status, Stripe customer and subscription identifiers | Providing the Pro plan; we never see or store card numbers | Contract (6.1.b); legal obligation for accounting (6.1.c) |
| Page views and link clicks: timestamp, country (from the network), device type and browser family (from the user-agent), referring site | Aggregate statistics for the account holder | Legitimate interest (6.1.f) — see section 4 |
| Email addresses submitted through an “email capture” block | Passed to the account holder who owns the page | Consent of the person submitting (6.1.a); the account holder is the controller of that list |
| Server logs (IP address, requested URL, time) | Security, abuse prevention, troubleshooting; kept up to 30 days | Legitimate interest (6.1.f) |
3. Cookies
We set only one strictly necessary cookie: the session cookie that keeps you logged in. Your light/dark theme choice is kept in your browser’s local storage, not sent to us. We do not use advertising or analytics cookies and do not track visitors across sites, so no cookie banner is required.
4. Statistics on public pages
When someone opens a page or clicks a link we record the event with the visitor’s country, device type, browser family and referring site. We do not store the visitor’s IP address or any identifier in these records, and they cannot be used to recognise a person. They are shown to the account holder as totals. Requests from known bots are ignored.
5. Where your data is stored and who processes it
Accounts, pages, statistics and uploaded files are stored on our own server located in Riga, Latvia (European Union). We use the following processors, each bound by a data processing agreement:
| Processor | What for | Data involved |
|---|---|---|
| Stripe Payments Europe, Ltd. (Ireland) | Payments and subscriptions | Email, payment method, billing details — handled directly by Stripe |
| Cloudflare, Inc. (EU data centres where available) | Content delivery, DDoS protection, TLS certificates for custom domains | Request data in transit, custom domain names |
| Purelymail LLC (USA) | Sending transactional email (verification, login links, password resets) | Email address and the content of those messages |
Where a processor is outside the European Economic Area, transfers rely on the EU Standard Contractual Clauses or an adequacy decision.
6. How long we keep data
- Account and page data: until you delete the account.
- Statistics: for as long as the account exists (the Free plan shows the last 7 days).
- Backups: encrypted; deleted data leaves the backup rotation within 6 months (daily, weekly and monthly snapshots).
- Server logs: up to 30 days.
- Invoices and payment records: kept by Stripe and in our accounting for the period required by tax law (currently 5 years in Latvia).
7. Your rights
Under the GDPR you can:
- access and correct your data — most of it directly in Settings;
- delete your account and all its data yourself at any time in Settings → Danger zone; deletion is immediate;
- export your data in a machine-readable format — email us and we send it within 30 days;
- object to processing based on legitimate interest, or restrict it;
- complain to a supervisory authority — in Latvia the Datu valsts inspekcija (dvi.gov.lv), or the authority of your own EU country.
To exercise a right that is not available in Settings, write to [email protected] from the email address on your account.
8. Account holders as controllers
If you collect email addresses through your page, you are the controller of that list and responsible for having a lawful basis and informing subscribers. We process those addresses only on your behalf and delete them with your account.
9. Security
Passwords are hashed with Argon2id; all traffic is encrypted in transit (TLS); backups are encrypted at rest; access to the server is restricted to the operator. No system is perfectly secure — if we learn of a breach affecting your data we will notify you and the authority as the GDPR requires.
10. Children
The Service is not intended for children under 16 and we do not knowingly collect their data.
11. Changes
We may update this policy. Material changes are announced by email or in the dashboard before they take effect. The date at the top shows the current version.
12. Contact
SIA "Synchron", Ūnijas iela 74A - 45, Rīga, LV-1084, Latvia. Privacy requests: [email protected]. General support: [email protected]. See also our Terms of Service.