← Back to GoLinkr

Privacy Policy

Last updated: 14 August 2026

GoLinkr ("we", "us") provides a private, invite-only space for small trusted groups to save and discuss things they find online. This policy explains what personal data we collect, why, how we use it, who we share it with, and the rights you have over it.

GoLinkr is operated by [Company name/legal entity — placeholder], based in the United Kingdom. We're the "data controller" for the personal data described in this policy. Our registered address is [registered address — placeholder], and you can contact us at [contact/privacy email — placeholder].

This policy is written to comply with the UK GDPR and the Data Protection Act 2018. If you're accessing GoLinkr from the European Economic Area (EEA), the EU GDPR gives you equivalent rights to those described here. If you're accessing GoLinkr from elsewhere, including the United States, we apply the same standards to your data regardless of local law, unless we're legally required to do otherwise.

1. Data we collect

  • Account details: your name, email address, and password (stored as a secure one-way hash, using industry-standard hashing, we never store or can see it in plain text).
  • Content you add: links, notes, comments and replies, polls, checklists, tags, favourites, and any profile picture you upload.
  • Board and membership data: which boards you're part of, your role on each (owner, moderator, member), and invite codes you've used or created.
  • Usage data: basic activity such as when you last used GoLinkr, and interactions needed to make features work (for example, what you've favourited, or notification preferences).
  • Technical data: IP address, browser/device type, and similar information collected automatically by our hosting and authentication providers, mainly for security and to keep the Service reliable.

We don't knowingly collect any special category data (such as health, religious, or biometric data) beyond whatever you voluntarily choose to include in your own content.

2. Why we collect it (purposes)

  • To create, authenticate, and secure your account;
  • To let you and the people you invite use the boards you're part of, and to display your content to the right people;
  • To send account-related and in-app notifications (for example, replies, mentions, or a rediscovery nudge);
  • To detect, investigate, and prevent fraud, abuse, and security incidents;
  • To maintain, troubleshoot, and improve the reliability of the Service;
  • To comply with our legal obligations.

We don't use your data for advertising, we don't build advertising profiles, and we don't sell it to anyone.

3. Our legal bases for processing

Under UK GDPR, we rely on the following legal bases, depending on the activity:

  • Performance of a contract: processing needed to provide the Service you've signed up for (for example, storing your content, running your boards).
  • Legitimate interests: for example, keeping the Service secure, preventing abuse, and maintaining basic technical logs, where these interests aren't overridden by your rights.
  • Consent: for anything genuinely optional, such as choosing to enable certain notifications; you can withdraw this at any time from Account Settings.
  • Legal obligation: where we're required to process or disclose data to comply with the law.

4. Who we share it with

Content you post is visible to the other members of the same board, since that's the point of a shared space, but never to anyone outside it, and boards are never publicly listed or searchable.

We use a small number of third-party service providers to run GoLinkr, each acting as a data processor on our behalf, under contractual terms that require them to protect your data:

  • Supabase, for our database, authentication, and file storage;
  • Vercel, for application hosting;
  • Our email provider, for account confirmation and password-reset emails.

We don't sell your personal data, and we don't share it with third parties for their own marketing purposes. We may disclose it if required by law, to protect our rights, or to investigate misuse of the Service.

5. International data transfers

Some of our service providers may process or store data outside the UK, including in the European Economic Area or the United States. Where that happens, we rely on appropriate legal safeguards, such as the UK's International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or a provider's participation in a recognised adequacy or certification framework, to make sure your data continues to receive an equivalent level of protection.

[Placeholder: confirm the specific hosting region(s) used by Supabase/Vercel for this project, and reference the specific transfer mechanism(s) actually in place in each provider's Data Processing Agreement.]

6. How long we keep it

We keep your personal data for as long as your account is active. If you delete your account, we anonymise your personal content (for example, replacing your name with something like "Deleted user" on posts you made) rather than deleting a shared board's entire history outright, so the other members of a board you were part of don't lose things you all saved together. Your account details (name, email, password hash) and any profile picture are deleted, not anonymised.

If you'd like to understand exactly what would be deleted versus anonymised for your account before you go ahead, contact us and we're happy to explain.

7. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request erasure of your data (see the anonymisation approach explained above);
  • Request a copy of your data in a portable format;
  • Object to, or request that we restrict, certain processing;
  • Withdraw consent at any time, where we rely on consent (for example, notification preferences in Account Settings).

To exercise any of these rights, contact us at [contact/privacy email — placeholder]. You also have the right to complain to the Information Commissioner's Office (ICO) if you have concerns about how your data is handled, or to your local supervisory authority if you're in the EEA.

8. Cookies

We use only strictly necessary cookies, mainly to keep you signed in and to remember basic preferences needed for the Service to work. These don't require consent under UK/EU cookie rules, since they're essential to the Service. We don't use tracking, analytics, or advertising cookies.

9. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), one-way password hashing, and access controls that restrict who can view data on our systems. No method of transmission or storage is completely secure, but we work to keep your data as safe as we reasonably can and to respond quickly if something goes wrong.

If we become aware of a personal data breach that's likely to pose a risk to you, we'll notify the ICO and affected users as required by law.

10. Children

GoLinkr is not intended for anyone under 16, and we don't knowingly collect personal data from anyone under that age. If we become aware that we've collected data from someone under 16, we'll close the account and delete the associated personal data.

11. Changes to this policy

We may update this policy as the Service develops or as legal requirements change. If we make significant changes, we'll update the date at the top of this page and, where practical, let you know (for example, via an in-app notification).

12. Contact

Questions about this policy or your data? Contact us at [contact/privacy email — placeholder].

See also our Terms of Use.