LinkClicks
Back to Home Open App
Link Clicks Inc. Privacy Policy

At Link Clicks Inc., we take the privacy of our users seriously. This privacy policy applies to LinkClicks and associated tools (collectively, the “Service”), which include a software as a service (SaaS) platform that allows advertisers to manage ad campaigns across multiple platforms from a single dashboard, an AI Creative Studio (including the AI Image Maker, AI Video Maker, music generation, voiceovers, and storyboard-assisted creation), a Marketing Intelligence suite, integrations that let you connect an ecommerce store (such as a Shopify store) so that we can report on your sales and attribute them to your advertising, the LinkClicks tracking pixel, website uptime and competitor monitoring, and a free public website analysis tool (the “Scanner”) that allows any visitor to analyse a website URL without signing in.

Last Updated: September 1, 2026

By using the Service, you agree to the collection, use, and sharing of your personal data as described in this privacy policy. If you do not agree with our policies and practices, do not use the Service.

1. Personal data we collect

We may collect the following personal data when you use the Service:

  • Contact information, such as your name, email address, and phone number
  • Account login information, such as your email/identifier
  • Ad campaign data, such as the ad content, target audience, and budget
  • Usage data, such as the features and pages you access within the Service, and the time and duration of your usage
  • Device and browser information, such as your IP address, device type, browser type, and approximate city/country geolocation
  • Website URLs submitted for scanning via the Scanner
  • Scan results (scores, technical analysis, and metadata) stored server-side and linked to your IP address, including when you use the Scanner without an account
  • Browser-local scan history stored in your device’s localStorage when you use the Scanner (up to 10 entries; cleared when you claim scans to an account or clear browser storage)
  • AI image generation prompts, parameters, and generated image metadata when you use the AI Image Maker feature
  • AI video generation prompts, source images, model selection, and generated video metadata when you use the AI Video Maker feature
  • Music prompts, composition parameters, and generated audio metadata when you use music generation features
  • Voiceover scripts, voice selection, pronunciation settings, and generated audio metadata when you use TTS or voiceover features
  • Storyboard scene inputs, media references, timing data, and generated composition metadata when you use storyboard-assisted features
  • Ecommerce store data from stores you connect, such as orders, checkouts, refunds, line items, product catalogue entries, order totals, currency, and the landing page and referrer recorded against an order
  • Limited personal data belonging to your customers that appears on those orders — described in detail in Section 2.4
  • Storefront and website visitor events collected by the LinkClicks pixel — described in detail in Section 2.5
  • Websites and stores you ask us to monitor, and the uptime, performance, traffic and competitor results we produce for them
  • Billing data, such as your plan, subscription status, billing period, trial dates, and payment history

We offer paid subscription plans. Payment card details are collected and processed by our payment providers — Stripe for subscriptions purchased through our website or mobile apps, and Shopify for subscriptions purchased through the Shopify App Store. We never receive or store full payment card numbers. We do store your plan, subscription status, billing period, trial dates, and payment history.

2. How we use your personal data

We use your personal data to:

  • Provide, maintain, and improve the Service
  • Process and fulfill your requests, such as setting up and managing your ad campaigns
  • Communicate with you, such as to send you updates or newsletters
  • Analyze and improve the Service, such as by tracking usage patterns and identifying areas for improvement
  • Protect the security and integrity of the Service, such as by detecting and preventing fraud or abuse
  • Provide and rate-limit the Scanner, detect and prevent abuse, and generate shareable scan result pages
2.1 Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we process your personal data based on the following legal grounds:

  • Consent: When you provide explicit consent for specific processing activities (e.g., receiving newsletters).
  • Contract Performance: When processing is necessary to fulfill our contractual obligations to you (e.g., providing the Service).
  • Legitimate Interests: When processing is necessary for our legitimate business interests, such as improving the Service or preventing fraud.

2.2 Scanner Data and Anonymous Scans

When you use the Scanner without signing in, we store your IP address and the submitted URL alongside your scan result. This data is used solely for rate limiting (1 free scan/day for anonymous users; 5–500 scans/month for registered accounts depending on plan), abuse prevention, and enabling you to share your result via a unique link. Anonymous scan results may be retroactively linked to your account if you sign in and choose to claim them. We rely on legitimate interest as the legal basis for this processing under GDPR.

2.3 AI Creative Tool Data (Image Maker, Video Maker, Music, Voiceover & Storyboard)

When you use the AI Image Maker, AI Video Maker, music generation, voiceover, or storyboard-assisted features, we collect and process the following data:

  • Text prompts and generation parameters (style, industry, palette, format, overlay text) submitted for image generation
  • Video prompts, model selection, source images, and generation parameters submitted for video generation
  • Music prompts, genre or mood references, tempo or duration hints, and generation parameters submitted for audio generation
  • Voiceover scripts, selected voices, pronunciation notes, and TTS generation parameters submitted for spoken audio generation
  • Storyboard scene descriptions, linked assets, timing, and composition data submitted for multi-step creative generation
  • Generated images and videos stored in cloud storage (Amazon S3)
  • Generated music tracks, voiceovers, and other audio outputs stored in cloud storage (Amazon S3)
  • IP address and user agent associated with each generation request
  • Content moderation results, including whether a prompt was allowed or blocked and the categories of any detected violations

This data is used for: providing the image, video, music, voiceover, and storyboard generation services, automated content safety moderation (including keyword-based filtering and AI-powered safety classifiers), abuse detection and prevention, audit compliance, and improving the quality of the service. We may use third-party model and inference providers, including BytePlus, OpenAI, Google, and others we evaluate or add over time, depending on the feature and product direction.

Retention: Generation audit logs (prompts, parameters, moderation results) are retained for 90 days for standard requests. Logs associated with blocked or flagged content are retained for up to 1 year for compliance and abuse investigation purposes. Generated images, videos, music, voiceovers, and storyboard outputs are stored in S3 and are subject to the same data retention and account deletion policies described in Section 4 and Section 7 of this policy. When you delete your account, all associated generated assets and audit logs are included in the scheduled deletion process.

2.4 Connected ecommerce stores and your customers’ data

When you connect an ecommerce store to the Service — currently Shopify — you authorise us to read data from that store using the permissions you grant during installation. Some of that data is personal data belonging to yourcustomers rather than to you. Shopify classifies it as protected customer data. This section explains exactly what we receive, why, how long we keep it, and how your customers can exercise their rights.

Our role and yours. For your store’s data you are the data controller and Link Clicks Inc. acts as a data processor on your instructions. You are responsible for having a lawful basis to share this data with us and for disclosing your use of LinkClicks in your own privacy notice to your customers.

What we store, and for how long:

  • Order and checkout records retained for as long as your store is connected to your account: the platform’s order and customer identifiers, order and refund totals, currency, line items, the landing page and referring site, any advertising click identifiers present on that landing page, the customer’s first and last name, and a SHA-256 hash of the customer’s email address. We deliberately store the hash rather than the email address itself: a hash is enough to recognise a repeat buyer or match an order to a click, and is not enough to contact anyone.
  • Cross-store customer records used for lifetime-value reporting, which contain only hashed email and hashed phone values together with order counts and totals — no names, addresses or contact details.
  • Verbatim platform payloads, kept for audit, debugging and reprocessing and automatically deleted after 90 days. These are the order exactly as the platform sent it, so for that 90-day window they can include the customer’s email address, phone number and billing and shipping addresses. Nothing reads these payloads except our own ingestion and support processes.
  • For WooCommerce stores only, the customer IP address recorded against an order, which that platform supplies as part of the order itself.

We do not receive, and never store, your customers’ payment card numbers, passwords, or Shopify account credentials.

Why we process it. A single purpose: measuring and improving the advertising you run through the Service. Concretely, to match a sale to the ad click that produced it, to report revenue and return on ad spend back to you, to identify abandoned checkouts, to send conversion events to the advertising platforms you have connected (see Section 3), and to monitor the health of your store and its data feed. We do not sell this data, use it to build cross-merchant profiles, or use it to market to your customers.

Requests from your customers. Where the platform supports it, we honour the requests it forwards to us automatically:

  • Data request — we compile everything we hold about the identified customer and return it to you, the merchant, within 30 days, so that you can answer your customer as their controller.
  • Customer redaction — within 48 hours we erase that customer’s identifying fields from our records, delete their cross-store customer record, delete the matching pixel event records, and delete any verbatim payloads that mention them. We retain the order’s monetary total with the personal fields removed, so that your own historical revenue reporting remains correct — the order stays, the person does not.
  • Store erasure — when a store is uninstalled or erasure is requested, we erase that store’s data. On uninstall we additionally revoke and destroy the store’s access tokens immediately.

Your customers can also contact us directly at [email protected]. Because we hold this data as a processor, we will normally refer such a request to you as the merchant and assist you in answering it.

Security and access. Store data is encrypted in transit, and the access tokens that authorise our connection to your store are encrypted at rest. Access is limited to authorised Link Clicks Inc. personnel who need it to operate or support the Service, on the terms described in Section 3.

2.5 The LinkClicks pixel

If you install the LinkClicks pixel on your website, or connect a Shopify store (where the pixel runs as a sandboxed Shopify Web Pixel extension), it records visitor activity so that we can connect an advertisement to what a visitor did afterwards. It collects page views and, where applicable, product views, cart additions, checkout starts and purchases, together with the page URL, referring URL, advertising click identifiers present in the URL (for example a Google or Meta click ID), a first-party session identifier, the visitor’s IP address, and their browser user agent.

The pixel does not collect payment card details, passwords, or the contents of form fields. Where an email address is used to link a visit to a purchase across devices, it is used as a SHA-256 hash and the address itself is never transmitted to us by the pixel.

As with store data, the operator of the site carrying the pixel is the controller of these events and Link Clicks Inc. is a processor. If you deploy the pixel, you are responsible for any notice or consent your jurisdiction requires from your visitors. Pixel event records are retained for as long as they are needed for attribution reporting on your account, and are deleted when you delete your account, when you disconnect the store they relate to, or on a customer redaction request as described in Section 2.4.

3. Sharing of personal data

We may share your personal data with:

  • Ad Platforms: When you create or manage ad campaigns through the Service, we share the necessary data (e.g., ad content, target audience, budget) with the advertising platforms you select (e.g., Meta Ads, Google Ads, LinkedIn Ads). This data sharing is based on your explicit actions and is necessary to fulfill your requests.
  • Internal Support, Operations, and Research Personnel: Authorized Link Clicks Inc. personnel may access account data, workspace information, campaign configuration, connected platform metadata, and related usage information when reasonably necessary to provide support, investigate bugs, maintain service quality, improve product functionality, conduct internal research, enforce our terms, or protect the Service from abuse. Cross-workspace staff access is designed to be read-only during ordinary support and research workflows.
  • Advertising Platforms (conversion data): Where you have connected an advertising account and enabled conversion forwarding, we send conversion events derived from your store and pixel data to that platform on your instruction, so that your campaigns can be measured and optimised. Customer identifiers are sent as hashes wherever the receiving platform supports hashed matching. You choose which platforms are connected and can disconnect them at any time.
  • Legal or Regulatory Authorities: We may disclose your personal data if required to do so by law or if it is necessary to protect the rights, property, or safety of Link Clicks Inc. or others.

Service providers we rely on. The Service is operated with the help of the following categories of sub-processor, each bound to use the data only to provide their service to us: cloud hosting and file storage (Amazon Web Services); payment and subscription processing (Stripe, and Shopify for subscriptions purchased through the Shopify App Store); ecommerce platform APIs for the stores you choose to connect (Shopify, and other platforms as we add them); AI model and inference providers for the Creative Studio (including BytePlus, OpenAI and Google); IP geolocation data (MaxMind); and transactional email and notification delivery. We do not sell personal data to anyone.

4. Data retention

We will retain your personal data for as long as your account is active or as needed to provide the Service to you. We will also retain and use your personal data as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.

If you disconnect an ad platform from the Service, we may place associated platform data and authorization records into a pending deletion state for a limited retention period (currently up to 30 days by default) before permanent deletion. This helps support account recovery, operational integrity, and fraud prevention.

Ecommerce store data follows the retention rules set out in Section 2.4: order and event records are kept for as long as the store is connected to your account, verbatim platform payloads are deleted automatically after 90 days, access tokens are destroyed immediately on uninstall or disconnection, and a store’s data is erased on an uninstall or store-erasure request. Redaction requests concerning an individual customer are completed within 48 hours.

5. Data security

We have implemented appropriate technical and organizational measures to protect your personal data from unauthorized access, use, or disclosure. However, no method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee the absolute security of your personal data.

6. Data subject rights

You have the following rights with respect to your personal data:

  • The right to access and receive a copy of your personal data
  • The right to rectify any inaccuracies in your personal data
  • The right to erase your personal data, subject to certain exceptions
  • The right to restrict or object to the processing of your personal data
  • The right to data portability, which allows you to obtain a copy of your personal data in a commonly used format

To exercise any of these rights, please contact us at [email protected].

6.1 GDPR Rights (EU/UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have additional rights under the General Data Protection Regulation (GDPR). These include:

  • The right to access, correct, update, or request deletion of your personal information.
  • The right to object to processing of your personal information, ask us to restrict processing of your personal information, or request portability of your personal information.
  • The right to opt-out of marketing communications we send you at any time.
  • If we have collected and processed your personal information with your consent, then you can withdraw your consent at any time.
  • The right to complain to a data protection authority about our collection and use of your personal information.
7. Account Deletion

You may delete your account at any time through the Settings page. When you request deletion, your account is deactivated immediately and your data is scheduled for deletion. We then permanently delete your account and associated data after a limited pending deletion period (currently up to 30 days by default), unless a longer retention period is required by law. Some data may also remain in encrypted backups for a limited period before being permanently overwritten.

8. Public Authority Requests and Legal Process

We have established policies and procedures for handling requests from public authorities for user data. Our approach includes:

  • Required Review: We review the legality of every request from public authorities for personal data.
  • Challenging Unlawful Requests: We have provisions to challenge requests if they are considered unlawful or overly broad.
  • Data Minimization: We adhere to a strict policy of disclosing the minimum information necessary to satisfy a valid legal request.
  • Documentation: We maintain documentation of these requests, including our responses and the legal reasoning involved.
9. International Data Transfers

Link Clicks Inc. is a Canadian corporation. Your information, including personal data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. We take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

10. Children’s Privacy

Our Service does not address anyone under the age of 18 (“Children”). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

11. Third-Party Service Providers

We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

We may also use IP geolocation data to derive coarse location information such as country for analytics, security, fraud prevention, and service reporting. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

12. Data Security and Breach Notification

The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. In the event of a data breach that compromises your personal information, we will notify you and relevant authorities as required by applicable law.

13. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information, including the right to know what personal information we collect, the right to delete your personal information, and the right to opt-out of the sale of your personal information (though Link Clicks Inc. does not sell personal data). To exercise these rights, please contact us.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at [email protected].

16. Cookies and Tracking Technologies

Within the LinkClicks application we use cookies and similar technologies solely for necessary functionality, such as maintaining your session and ensuring the security of the Service. These cookies are essential for the Service to function properly and cannot be disabled.

Separately, the LinkClicks pixel — which you choose to install on your own website or storefront — uses first-party storage on your visitors’ devices to hold a session identifier and any advertising click identifier that brought them to your site, so that a later purchase can be attributed to the right campaign. That storage is described in Section 2.5 and is under your control as the operator of the site: you decide whether to deploy the pixel, and you are responsible for any consent your jurisdiction requires before it runs.