Privacy Policy

Last updated: April 4, 2026

1. Introduction

This Privacy Policy explains how Linki (“we”, “us”, “our”) collects, uses, and protects your information when you use our platform. We are committed to protecting your privacy and handling your data transparently.

2. Information We Collect

From Sellers (Account Holders)

  • Account information: email address, password (hashed), WhatsApp phone number.
  • Shop information: shop name, logo, tagline, catalog slug, banner images, brand colors, social media links.
  • Product information: product names, descriptions, prices, images, categories, variants.
  • Delivery information: delivery partner API credentials (encrypted), pickup area.

From Buyers (Catalog Visitors)

  • Order information: name, phone number, delivery address notes, items ordered.
  • Technical data: IP address, browser type, device type (collected automatically via server logs).

Buyers do not create accounts. No payment information is collected — all transactions use cash on delivery (COD).

Automatically Collected

  • Authentication cookies (required for seller login sessions).
  • Cart data stored in your browser's local storage (not sent to our servers until checkout).

3. How We Use Your Information

  • To provide the Service: displaying your catalog, processing orders, managing your dashboard.
  • To communicate with you: order notifications, account-related emails, service updates.
  • To improve the Service: understanding usage patterns, fixing bugs, developing new features.
  • To protect the Service: fraud prevention, abuse detection, security monitoring.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Data Sharing

We share data only in the following circumstances:

  • Seller ↔ Buyer: when a buyer places an order, their name, phone, and address are shared with the seller to fulfill the order.
  • Delivery partners: when a seller dispatches an order via an integrated delivery partner (e.g., Wakilni), customer delivery information is shared with that partner.
  • Service providers: we use Supabase (database and authentication hosting), Vercel (application hosting), and Resend (email delivery). These providers process data on our behalf under data processing agreements.
  • Legal requirements: we may disclose information if required by law, court order, or governmental authority.

5. Data Storage and Security

  • Data is stored on Supabase servers (AWS infrastructure, EU region).
  • Passwords are hashed using industry-standard algorithms (bcrypt via Supabase Auth).
  • All data is transmitted over HTTPS/TLS encryption.
  • Product images are stored in Supabase Storage with public read access (as they are part of public catalogs).
  • Access to production databases is restricted to authorized personnel only.

6. Data Retention

  • Active accounts: data is retained as long as your account is active.
  • Deleted accounts: upon account deletion, your shop, products, and orders are deleted within 30 days. Some data may be retained longer if required for legal or compliance purposes.
  • Buyer data: order records are retained as part of the seller's order history. Buyers may contact the seller to request deletion of their order data.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data via your account settings.
  • Delete your account and associated data.
  • Export your order data via the CSV export feature.
  • Object to data processing for reasons related to your particular situation.

To exercise these rights, contact us at support@linki.shop.

8. Cookies and Local Storage

We use essential cookies only — specifically, Supabase authentication session cookies. These are required for the Service to function and cannot be disabled. We do not use advertising or tracking cookies.

Cart data is stored in your browser's local storage to persist between page refreshes. This data is not sent to our servers until you complete checkout.

9. Children's Privacy

The Service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service. The “Last updated” date at the top indicates when the policy was last revised.

11. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at support@linki.shop.