Last updated: 14 August 2026
GoLinkr ("we", "us") provides a private, invite-only space for small trusted groups to save and discuss things they find online. This policy explains what personal data we collect, why, how we use it, who we share it with, and the rights you have over it.
GoLinkr is operated by [Company name/legal entity — placeholder], based in the United Kingdom. We're the "data controller" for the personal data described in this policy. Our registered address is [registered address — placeholder], and you can contact us at [contact/privacy email — placeholder].
This policy is written to comply with the UK GDPR and the Data Protection Act 2018. If you're accessing GoLinkr from the European Economic Area (EEA), the EU GDPR gives you equivalent rights to those described here. If you're accessing GoLinkr from elsewhere, including the United States, we apply the same standards to your data regardless of local law, unless we're legally required to do otherwise.
We don't knowingly collect any special category data (such as health, religious, or biometric data) beyond whatever you voluntarily choose to include in your own content.
We don't use your data for advertising, we don't build advertising profiles, and we don't sell it to anyone.
Under UK GDPR, we rely on the following legal bases, depending on the activity:
Content you post is visible to the other members of the same board, since that's the point of a shared space, but never to anyone outside it, and boards are never publicly listed or searchable.
We use a small number of third-party service providers to run GoLinkr, each acting as a data processor on our behalf, under contractual terms that require them to protect your data:
We don't sell your personal data, and we don't share it with third parties for their own marketing purposes. We may disclose it if required by law, to protect our rights, or to investigate misuse of the Service.
Some of our service providers may process or store data outside the UK, including in the European Economic Area or the United States. Where that happens, we rely on appropriate legal safeguards, such as the UK's International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or a provider's participation in a recognised adequacy or certification framework, to make sure your data continues to receive an equivalent level of protection.
[Placeholder: confirm the specific hosting region(s) used by Supabase/Vercel for this project, and reference the specific transfer mechanism(s) actually in place in each provider's Data Processing Agreement.]
We keep your personal data for as long as your account is active. If you delete your account, we anonymise your personal content (for example, replacing your name with something like "Deleted user" on posts you made) rather than deleting a shared board's entire history outright, so the other members of a board you were part of don't lose things you all saved together. Your account details (name, email, password hash) and any profile picture are deleted, not anonymised.
If you'd like to understand exactly what would be deleted versus anonymised for your account before you go ahead, contact us and we're happy to explain.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at [contact/privacy email — placeholder]. You also have the right to complain to the Information Commissioner's Office (ICO) if you have concerns about how your data is handled, or to your local supervisory authority if you're in the EEA.
We use only strictly necessary cookies, mainly to keep you signed in and to remember basic preferences needed for the Service to work. These don't require consent under UK/EU cookie rules, since they're essential to the Service. We don't use tracking, analytics, or advertising cookies.
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), one-way password hashing, and access controls that restrict who can view data on our systems. No method of transmission or storage is completely secure, but we work to keep your data as safe as we reasonably can and to respond quickly if something goes wrong.
If we become aware of a personal data breach that's likely to pose a risk to you, we'll notify the ICO and affected users as required by law.
GoLinkr is not intended for anyone under 16, and we don't knowingly collect personal data from anyone under that age. If we become aware that we've collected data from someone under 16, we'll close the account and delete the associated personal data.
We may update this policy as the Service develops or as legal requirements change. If we make significant changes, we'll update the date at the top of this page and, where practical, let you know (for example, via an in-app notification).
Questions about this policy or your data? Contact us at [contact/privacy email — placeholder].
See also our Terms of Use.