effective on
Privacy policy
LinkyFlow ("us", "we", or "our") operates the LinkyFlow website and the LinkyFlow software (the "Service"). This page explains what personal data we process, why, on what legal basis, for how long, and what rights you have over it.
This policy is written in accordance with Regulation (EU) 2016/679 (the "GDPR") and the French Data Protection Act (loi n° 78-17 du 6 janvier 1978 modifiée). Unless otherwise defined here, terms have the same meaning as in our Terms and Conditions.
1. Who is responsible for your data
The data controller is GOLDEN F, a French société par actions simplifiée with a share capital of €300, whose registered office is at 21 avenue Pasteur, 92400 Courbevoie, France, registered with the Nanterre Trade and Companies Register under number 998 971 410, which publishes and operates the LinkyFlow service.
For any question or request relating to your personal data: contact@linkyflow.com.
We have not appointed a Data Protection Officer, as we are not required to; the contact address above reaches the person responsible for these matters.
2. What we collect
2.1 Account data. Your email address, your name and profile picture when you sign in with Google or Discord, the sign-in method used, the date your account was created, and your account preferences.
2.2 Connection credentials. The API keys, tokens or authorisations you provide to connect a Provider (an exchange account, an online store, a payment account, and so on). They are stored encrypted at rest and are used only to call that Provider on your instruction. Secret values are never displayed again once saved.
2.3 Your queries and settings. The queries you build (which Provider, which data, which filters and fields) and your display preferences.
2.4 Usage and billing data. The plan attached to your account, its status and term, your subscription and payment history held by our payment provider, and your monthly usage counters (data rows, requests, active connections).
2.5 Technical and support data. IP address, browser and device type, pages visited, product events (which features you use), diagnostic data when an error occurs, and the content of your exchanges with our support.
2.6 The business data read from your Providers — not stored. The trades, orders, payments, products and other rows retrieved from your connected accounts pass through our servers to your spreadsheet and are not saved in our database. They exist in our systems only for the time needed to serve the request. What is kept afterwards lives in your own workbook, under your control.
3. Why we process it, and on what legal basis
- To provide the Service — creating and maintaining your account, connecting your Providers, running your queries, applying plan limits. Legal basis: performance of the contract (art. 6.1.b GDPR).
- To bill paid plans — subscription, payment, invoicing, dunning. Legal basis: performance of the contract, and legal obligation for accounting records (art. 6.1.b and 6.1.c).
- To keep the Service reliable and secure — error monitoring, technical logs, abuse and fraud prevention, enforcement of plan limits. Legal basis: our legitimate interest in operating a functioning, secure service (art. 6.1.f).
- To improve the product — aggregated product analytics, understanding which features are used. Legal basis: your consent for the cookies and trackers concerned, otherwise our legitimate interest (art. 6.1.a and 6.1.f). See our Cookie Policy.
- To communicate with you — service messages, replies to your support requests, and the onboarding email sequence sent after you create your account. Legal basis: performance of the contract and our legitimate interest; you can unsubscribe from non-essential emails at any time.
We do not carry out any automated decision-making producing legal effects concerning you, and we do not profile you for advertising purposes.
4. Where your data is hosted
Your account, your connections, your queries and your usage counters are stored on Amazon Web Services in the eu-central-1 region — that is, in Frankfurt, Germany, inside the European Union. Backups stay in that same region.
5. Who we share it with
We never sell your personal data, and we never share it with third parties for their own purposes. No advertising networks, no data brokers, no resale, no exchange.
To operate the Service we do rely on a limited number of processors, who act only on our instructions, under contract, and only for the purpose stated:
- Amazon Web Services (Frankfurt, Germany) — hosting, database, execution of our services. In the EU.
- PostHog (EU region,
eu.i.posthog.com) — product analytics and application logs. In the EU. - Brevo (France) — sending transactional and onboarding emails. In the EU.
- Sentry (United States) — technical error monitoring: the error, the page, the browser and a user identifier.
- Chargebee (United States / India) — subscription management, payments and invoicing.
- Resend (United States) — sending your sign-in link when you authenticate by email.
- Google (United States) — Google Analytics on the website, sign-in with Google, and the generative AI service used to personalise the onboarding emails.
- Discord (United States) — sign-in with Discord, if you choose it.
- Tawk.to (United States) — live chat support on the website.
- Netlify (United States) — hosting of the linkyflow.com website.
- Cloudflare (worldwide) — serving the static assets of the site.
Transfers to processors located outside the European Union are covered by the appropriate safeguards under Chapter V of the GDPR: the EU-US Data Privacy Framework where the provider is certified, and the European Commission's standard contractual clauses otherwise.
We may also disclose data where we are legally required to (a court order or a request from a competent authority), or to establish, exercise or defend legal claims.
Your Providers. When you run a query, we call the Provider you connected, with the credentials you gave us, on your instruction. That is not a disclosure to a third party for its own purposes: it is you accessing your own account through our tool.
6. How long we keep it
- Account, connections, queries and settings: for as long as your account exists, then deleted or anonymised within 30 days of your deletion request or of the closure of your account.
- Monthly usage counters: automatically deleted about six (6) months after their last update.
- Invoices and accounting records: ten (10) years, as required by article L. 123-22 of the French Commercial Code. This obligation prevails over a deletion request, for those documents alone.
- Technical logs and error reports: up to twelve (12) months.
- Product analytics: up to twelve (12) months.
- Support conversations: up to three (3) years after the last exchange.
7. Your rights
Under the GDPR and the French Data Protection Act, you have the right to:
- access your data and obtain a copy of it;
- rectify it if it is inaccurate or incomplete;
- erase it ("right to be forgotten"), subject to our legal retention obligations;
- restrict its processing;
- object to processing based on our legitimate interest;
- portability — receive the data you provided to us in a structured, commonly used, machine-readable format;
- withdraw your consent at any time where processing is based on consent, without affecting what was done beforehand;
- give directives as to what becomes of your data after your death (article 85 of the French Data Protection Act).
To exercise any of these rights, including deletion of your data, write to contact@linkyflow.com. We reply within one month of receiving your request; that period may be extended by two months for complex requests, in which case we will tell you. We may need to verify your identity before acting.
You can also delete your connections and your queries yourself, at any time, from the application.
Complaint. If you consider that your rights are not respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, www.cnil.fr.
8. Security
We take reasonable measures to protect your data: encryption in transit (HTTPS) and at rest, secret values never displayed again once saved, production access restricted to those who need it, isolation of each user's data, and monitoring for anomalies.
No method of transmission or storage is completely secure and we cannot guarantee absolute security. You also play a part: supply read-only credentials whenever you do not need write access, revoke at your Provider any key you no longer use, and protect access to your own account.
9. Cookies and similar technologies
The cookies and trackers used on the website, what they are for, and how to control them are described in our Cookie Policy.
10. Children
The Service is not intended for minors. We do not knowingly collect data relating to a person under 18. If you believe that a minor has provided us with data, contact us and we will delete it.
11. Changes to this policy
We may update this policy. Any material change is reflected by the effective date at the top of this page and, where the change is significant, we will inform you by email or inside the Service.
12. Contact us
For any question about this policy or about your personal data: contact@linkyflow.com.