Last updated: 12 October 2026
Шейп Стайл ЕООД (Shape Style EOOD), trading as Linxlay, operates the service at https://www.linxlay.com and its related subdomains.
This policy explains how we handle personal data about website visitors, account holders, invited collaborators, people whose information appears in user content, public-page visitors and people contacting or reporting content to us.
We are the controller for account administration, billing administration, security, our marketing and handling privacy requests and content reports. A business customer may be the controller of personal data it uploads or publishes, with Linxlay processing that content on its behalf. Where this applies, we will agree appropriate data-processing terms with that customer on request.
| Information | Purpose | Legal basis for our controller activities |
|---|---|---|
| Email, username, hashed password, optional profile image, typed Instagram handles and saved preferences such as colours | Create and secure accounts; provide the service | Performance of a contract |
| Uploaded images and their processed versions; grids, captions, notes, hashtags, scheduled dates, editing projects and preferences | Provide planning, editing, saving and export features | Performance of a contract for the account holder's data |
| Public-page content, covers, links, profile details and publication settings | Build and publish Link-in-Bio pages as directed | Performance of a contract for the account holder's data |
| Collaborator email addresses, invitations and sharing permissions | Allow authorised collaboration and manage access | Our legitimate interest in enabling requested collaboration; performance of a contract for participating account holders |
| Stripe customer/subscription identifiers, billing details, invoices, tax details and payment status | Manage subscriptions, payments, refunds and accounting | Performance of a contract; legal obligations |
| IP addresses and technical request information processed by infrastructure and security logs; error events, which carry the account identifier but not the IP address | Operate and secure the service; investigate faults and abuse | Legitimate interests in reliability, security and preventing misuse |
| Support messages and contact-form submissions, which arrive in our support mailbox | Answer requests and resolve problems | Performance of a contract where relevant; legitimate interests in responding to enquiries |
| Reports, evidence, reporter contact details, moderation decisions and objections | Assess reports, explain restrictions and prevent repeated misuse | Applicable legal obligations; legitimate interests in protecting people and the service |
| Marketing choices, email address and consent records | Send optional tips and newsletters; honour withdrawals | Consent for marketing; legal obligations and legitimate interests for necessary consent/suppression records |
| Consented analytics and advertising events | Understand product use and measure campaigns | Consent |
| Privacy-request details, export audit records and deletion records | Fulfil rights requests, provide secure exports and prevent deleted accounts returning after restoration | Legal obligations |
| Records of which version of the Terms you accepted and when, and records of withdrawals from a purchase | Show what was agreed; handle withdrawals and refunds | Performance of a contract; legal obligations; legitimate interests in establishing, exercising or defending legal claims |
Our legitimate interests are assessed against the rights and reasonable expectations of the people concerned. You may object to processing based on legitimate interests.
Some content may contain information about other people. We obtain that information from the user who uploads or publishes it. Public pages are accessible to anyone with their address. Contact us if your information appears in content and you have a privacy concern.
Account and authentication details are necessary to provide an account. Required billing information is necessary for paid purchases and legal compliance. Optional profile information and marketing permission are not required to use the service. Not supplying necessary information may prevent us providing the relevant feature.
We do not receive full payment-card numbers. Stripe processes payment information. Do not upload sensitive personal information unless you are entitled to do so and the service is appropriate for that use.
Your grids and editing tools can only be opened in the app when you are signed in, or when you have been invited to a shared grid with a given permission. Invited collaborators can access the shared grid according to their permissions. Account owners should invite only authorised people and remove access when no longer needed.
Uploaded images are stored at unique web addresses (URLs) and are not publicly listed by Linxlay. However, an image file is not protected by a sign-in: anyone who has the exact address of an image can view it without signing in. This storage method is not designed for material requiring confidential or restricted access. Browsers and delivery networks may keep copies of images for a long time.
Published Link-in-Bio pages expose the information the owner chooses to publish, including images, text, links and contact buttons. Search-engine indexing is discouraged by default through technical instructions; eligible paid users can enable indexing. These instructions do not make a page private or guarantee exclusion from search results.
We do not use customer uploads or published pages in our own marketing without separate permission.
We count page views, link clicks and referrer categories as daily totals. Page owners receive aggregate statistics, with the level of detail depending on their plan. These statistics do not identify individual visitors or contain their IP addresses, devices or locations.
Infrastructure still processes IP addresses to deliver pages and may log them for security. We also use IP addresses for rate limiting. Aggregate public-page statistics are separate from those technical records. We use these statistics to provide the requested page service and understand its operation, based on legitimate interests.
Public Link-in-Bio pages do not load Linxlay's analytics scripts or advertising pixels. Video covers are uploaded by page owners and served through our hosting/storage. Clicking a YouTube video card counts the click and sends the visitor to YouTube; it does not load an embedded player beforehand. Other outbound links similarly lead to services with their own privacy practices.
Essential technologies support login, security and consent choices. We also use browser storage for interface preferences and tutorial progress. Optional functionality and tracking storage are handled according to their purpose and applicable consent requirements.
On the main website/app, Google Analytics 4 and Meta Pixel run only after the relevant analytics or marketing permission. Events can include registration, first photo upload, trial start, checkout start, purchase amount and public-page publication. We use these to understand use and measure advertising. These providers may process device/network information and identifiers according to their services and settings.
CookieYes manages consent choices. You can change or withdraw optional permissions through Cookie preferences. The main technologies we use are: a login session cookie (linxlay_session) and the consent record kept by CookieYes, which are essential; browser local storage for interface preferences, tutorial progress and guide settings; and, only after you give permission, the cookies and identifiers set by Google Analytics (for example _ga) and the Meta Pixel (for example _fbp). When you withdraw analytics or marketing permission, we stop sending those events straight away and tell the advertising pixel to revoke its consent; you do not need to reload the page. Refusing marketing or analytics permission does not prevent use of the core service. Withdrawal does not affect processing that was lawful before withdrawal.
After we send a purchase event, we keep a small marker in your browser's local storage so that the purchase is not counted twice. This marker is only written when analytics or advertising permission is on.
Fonts are served from our own hosting, including licensed fonts originally obtained from Google Fonts. Loading them does not require a connection to Google Fonts.
We send account and service communications such as verification, password reset, account-ready messages, factual trial-expiry notices, billing communications, the confirmation of a purchase or plan change (with a copy of the Terms accepted), confirmations of withdrawal from a purchase, acknowledgements and decisions about reports, and notices about public-page changes. These are separate from optional marketing preferences.
Optional tips and newsletters are sent only with marketing permission. You can unsubscribe using the link in a marketing email or contact us. Account deletion removes your Mailchimp contact. We retain only any minimal suppression or consent evidence that is necessary to honour your choices or demonstrate compliance.
Resend sends transactional emails using an Ireland sending region. Open and click tracking are disabled for these emails. Delivery to a recipient's mailbox may involve their own email provider and infrastructure outside the EU.
| Provider | Service and relevant location information |
|---|---|
| Railway | Application hosting in Amsterdam, Netherlands |
| Supabase | Database and file storage in Ireland |
| Sentry | Error monitoring in an EU organisation/region; IP addresses are excluded from stored error events |
| Resend | Transactional email; Ireland sending region |
| Mailchimp | Optional marketing-email list and delivery; processing outside the EEA is possible |
| Stripe | Payments, subscriptions, refunds, invoices and customer portal; processing outside the EEA is possible |
| CookieYes | Consent management; processing outside the EEA is possible |
| Consented Google Analytics 4 and tag-management functionality; processing outside the EEA is possible | |
| Google (Gmail) | Our support mailbox: contact-form messages, report notices and privacy requests are delivered there; processing outside the EEA is possible |
| Meta | Consented advertising measurement; processing outside the EEA is possible |
| Superhosting | Domain/DNS administration; Bulgaria |
Providers receive information needed for their services. Some act as processors under our instructions; others may act as independent or joint controllers for specific activities. We may disclose information when legally required or necessary to establish, exercise or defend legal claims. Published content and authorised sharing are disclosures directed by the account owner.
EU hosting does not necessarily mean all provider processing and access stay within the EEA. Where personal data is transferred outside the EEA, an applicable transfer mechanism must protect it, such as an adequacy decision or standard contractual clauses with additional safeguards where needed. You can contact us for information about the safeguards applicable to your data.
Account information and saved content remain while the account is maintained, unless deleted earlier. We do not currently delete accounts automatically because of inactivity. We review retention and do not retain identifiable data without a continuing purpose.
Deleting an account removes its active account records, grids, content, uploaded files, sharing records, public pages and related page statistics. Billing is cancelled and the Mailchimp contact is removed. Some separate records remain as follows:
| Record | Retention |
|---|---|
| Database backups | Up to 7 days after deletion from the live database |
| Railway server logs | 7 days from creation |
| Sentry errors and traces | 30 days from creation |
| Resend delivery logs | 30 days from creation |
| Temporary export | Download link valid for 7 days; expired files removed by the subsequent scheduled cleanup run, normally within an hour |
| Export audit record | 365 days from creation, once the export file has been removed; records contain request/verification and administrator details, not the exported content |
| Deletion ledger | 30 days; account identifier and deletion date only |
| Reporter contact details | Normally erased 90 days after a report decision |
| Decided reports (dismissed, or leading to a restriction) | Normally deleted 12 months after the decision |
| Reports never decided | Normally deleted 12 months after they were received |
| Minimal page-restriction record | While needed to enforce a restriction; reviewed and removed when no longer necessary |
| Records of Terms accepted (version and time) | Deleted with the account |
| Withdrawal records | Kept with the billing and accounting records |
| Billing/accounting records | Retained for applicable statutory accounting/tax periods |
| Support mailbox correspondence | Kept only as long as needed to handle your request and any follow-up, then deleted |
Limited records may be retained longer for an ongoing dispute, appeal or legal obligation. We document the reason, review it regularly (at least every three months) and release the record when it is no longer needed, rather than retaining everything indefinitely.
When you delete an image it is removed from our storage. Delivery caches: a copy can remain in the delivery network's cache until it is invalidated, which can take time, and we do not guarantee how long. Browser copies: image responses currently allow a browser to keep a copy for up to one year, so a browser that already loaded an image may keep showing it. Copies already downloaded or saved by other people, and copies held in their browsers, cannot reliably be recalled by us. Removing a published page does not guarantee removal from third-party search results or archives.
We maintain a separate deletion ledger to reapply account deletions if a database backup is restored. Restored data is used only as necessary to complete restoration and reapply deletions. Our production reconciliation job also checks for deleted accounts hourly.
We use measures designed to protect data, including encrypted web connections, authentication, access restrictions, rate limiting, monitoring and controls on administrator exports. Uploaded image addresses are long and randomly generated, although anyone with an exact address can open the file (see section 3). Data exports and deletion records are kept in storage that cannot be opened through a public link. Export links expire and temporary files are cleaned automatically. No service can guarantee absolute security. Keep your credentials private and report suspected issues to linxlayapp@gmail.com.
Subject to the relevant legal conditions, you can request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent. Portability applies to eligible data processed automatically on the basis of consent or contract. These rights may be limited where information must be retained by law or to protect another person's rights.
Email linxlayapp@gmail.com. A request from your registered address is the usual verification route, but contact us if you no longer have access to it. We use proportionate identity checks and do not routinely require identity documents. We provide information without undue delay and normally within one month. Where the law permits an extension for complexity or number of requests, we will explain the reason within the first month.
Exports are prepared through an administrator-only tool and delivered securely. They exclude credentials, secrets and information that would improperly disclose another person's data. Rights requests are ordinarily free; legally permitted exceptions for manifestly unfounded or excessive requests may apply.
You may complain to the Bulgarian Commission for Personal Data Protection (https://cpdp.bg), or another competent supervisory authority, including in the EU country of your habitual residence or work.
Linxlay is not intended for people under 16. When you sign up, you confirm that you are at least 16 and agree to the Terms of Service, and we record which version you accepted and when. Contact us if you believe an underage person has provided personal data. We do not make solely automated decisions producing legal or similarly significant effects. Operational automation, such as subscription entitlements and security controls, supports service administration.
We update this policy when our practices change and show the update date. We will give appropriate notice of material changes. If a new purpose requires consent, we will request it rather than treating continued use as consent.
Earlier versions of this policy are kept and can be read at https://www.linxlay.com/legal.
Contact: Shape Style EOOD, ул. Комсомолец 16, гр. Брезник 2360, Bulgaria; linxlayapp@gmail.com.