Lynko logo
  • Link PagesTurn one profile link into clicks, votes, questions and support.MiniSitesBuild a complete one-page website with blocks and live preview.Short LinksShare memorable links across social, email and print.QR CodesConnect physical moments to destinations you can update.Engagement modulesAdd Polls, AMA, Reward Unlock and an Action Hub.Growth modulesOrganize Campaign Kits and learn from privacy-friendly Analytics.
  • Templates
  • Pricing
  • Creators and communitiesFor independent creators and small communities worldwide.Restaurants and local businessesA secondary route for menus, offers, feedback and local campaigns.MiniSite demosExplore six interactive examples for businesses and creators.TrustPrivacy, security and reliable access.IntegrationsBrowse supported platforms and learn how to add them.Lynko GuideLearn how the product and modules work.MiniSite guideA step-by-step guide to blocks, photos, publishing and domains.News & UpdatesRead product news and practical ideas.RoadmapSee what Lynko is improving next.
  • Login
  • Build your page free
  • English language English Dutch language Dutch Spanish language Spanish Vietnamese language Vietnamese Indonesian language Indonesian German language German

Trust & Privacy

Privacy & GDPR Notice

Last updated: 2026-09-10

Plain-language summary

Lynko® is built to keep link, QR and creator tools privacy-friendly. We avoid third-party trackers and aim to keep data processing clear and minimal.

What Lynko® stores Account data, content you create, security logs and privacy-friendly analytics needed to run the service. What Lynko® does not do We do not sell visitor data, build advertising profiles or add third-party ad trackers to public pages. Visitor analytics Clicks, scans, visits and votes can be counted so creators can understand activity without advertising surveillance. Account data Accounts use basic details such as username, email address and a securely hashed password. Data requests You can contact Lynko® to request access, correction, deletion, restriction, portability or objection. Abuse and safety Security and abuse prevention help keep short links, QR codes and creator pages safer. Contact Use the contact page for privacy questions, data requests or support.

This notice explains how Lynko.tv handles privacy and data processing under the EU General Data Protection Regulation (GDPR) and Dutch law (Uitvoeringswet Algemene verordening gegevensbescherming - UAVG). It applies to all users of Lynko.tv.

Trust & Privacy gives a shorter product-level overview. Terms of Service explains the rules for using Lynko.tv.

  • Plain-language summary
  • 1) Who we are
  • 2) What Lynko® stores
  • 3) What Lynko® does not do
  • 4) Visitor analytics
  • 5) Account data
  • 6) Reward Unlock data collection
  • 7) Why we process your data
  • 8) Abuse and safety
  • 9) Cookies
  • 10) Retention
  • 11) Our processors
  • 12) International transfers
  • 13) Data requests
  • 14) Complaints
  • 15) Security measures
  • 16) Polls and voting data
  • 17) Children
  • 18) Changes
  • 19) Contact

1) Who we are

Madeliz operates Lynko.tv and is the controller for account administration, billing, service security and its own product analytics. For visitor details collected by creators for their own purposes, the creator determines the purpose and Lynko processes the submissions to provide the feature.

Mother Company
Madeliz (BOIP reg. no. 1442741)
Official registered brand
Lynko® (BOIP reg. no. 1530871)
Located at
The Netherlands
Chamber of Commerce (KvK)
77510194
Contact
Click here

Note: Lynko® and Madeliz® are registered trademarks in the Benelux (BOIP).

2) What Lynko® stores

Lynko® stores data needed to provide the service, secure accounts, prevent abuse and show useful statistics to account owners.

  • Account data: username, email address and password stored as a secure hash.
  • User content: short links, QR destinations, link pages, polls, AMA pages, Smart Cards, counters, Campaign Kits and related settings you create.
  • Transactional emails: activation, security and service notices.
  • Optional tokens: activation tokens, password-reset tokens and deletion-confirm tokens are stored as hashes and expire after a short period.
  • Operational logs: basic information needed for security, troubleshooting, abuse prevention and service reliability.
  • Support and abuse reports can include your name, email address, message, submitted links, network and browser information, and our handling of the request.

3) What Lynko® does not do

  • Lynko® does not sell visitor data.
  • Lynko® does not build advertising profiles from link, QR or page visitors.
  • Lynko® does not add third-party ad trackers to public pages.
  • Lynko® does not intentionally collect special categories of data.
  • Lynko® does not use voting data for advertising, tracking or cross-service identification.

4) Visitor analytics

When someone opens a short link, scans a QR code, visits a link page, votes in a poll or triggers a counter, Lynko® can count that activity and show it to the account owner.

Analytics may include counts, timestamps, referrer information, approximate country, browser language, device type, screen size and campaign context when available. The goal is practical reporting, not advertising surveillance.

Detailed link and QR events can also store the full IP address in binary form, the browser user agent, referring URL and destination URL. Binary storage is not anonymization. Insight Pixels use daily visitor estimates and technical hashes; these are not verified counts of individual people.

Turning off detailed short-link analytics still allows a total click count and last-click time. Privacy password links encrypt the stored destination with the password and disable visit analytics. This does not make visits anonymous to the destination website or network providers.

Smart Redirects: when a link owner enables Smart Redirects, Lynko® may use the visitor browser language and approximate country to route the visitor to the correct destination. Browser language is read from the request header. Country detection may use the IP address or privacy-friendly infrastructure headers. Full IP addresses do not need to be permanently stored for Smart Redirects unless already required for abuse or security logs. Analytics may store the country code, language code, matched rule type, and final destination used, while keeping only the data needed for the feature.

Public link pages suppress repeat views for five minutes using the existing session, without a separate persistent analytics cookie.

5) Account data

Account data is used to create and maintain your account, protect access, send transactional messages and provide paid plan features when applicable.

We store the registration IP address and time, plus the latest login IP address, browser information and timestamps. Security, payment and activity records are separate and can have different retention periods. Username, email and password are required to create an account.

6) Reward Unlock data collection

Some Lynko® users can enable Reward Unlock on QR codes, shortlinks or Link in Bio pages. Ask visitors for details before unlocking a reward, coupon, file or special link.

  • Possible submitted details: name, email address, phone number, company name, a message, custom fields and consent confirmation.
  • Sharing: submitted details are shared with the owner of the relevant Lynko® page, QR code or shortlink.
  • Owner tools: Lynko® stores this information so the owner can view submissions, measure results and, where available for their plan, export the information to an Excel file.
  • Retention: Personal submission details are scheduled for anonymization after 90 days. Aggregate views, claims and conversion statistics can remain. Creators can delete personal details earlier; copies they export are subject to their own retention obligations.
  • Earlier deletion: visitors can request earlier deletion of their submitted information by contacting the owner of the relevant Lynko® page or by contacting Lynko® support where applicable.

Lynko® does not sell this submitted personal data.

Submissions can also be delivered to an external service if the creator configures an integration or webhook. The creator must explain the recipients and lawful use of the data.

7) Why we process your data

  • Contract (Art. 6(1)(b) GDPR): create and maintain your account, provide the service, send activation and transactional emails.
  • Legitimate interests (Art. 6(1)(f) GDPR): secure accounts, prevent fraud and abuse, handle reports and understand service activity, subject to a balance with your privacy rights. You may object to processing based on legitimate interests.
  • Legal obligations (Art. 6(1)(c) GDPR) apply to required accounting records and lawful authority requests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.
  • Service improvement (Art. 6(1)(f) GDPR): understand aggregate steps from a public landing page to first product value, without third-party trackers or a separate analytics cookie. You may object anytime under Art. 21 GDPR.
  • Consent (if applicable): only for optional features that require it, like marketing emails or non-essential cookies. Not used by default.

8) Abuse and safety

Registration uses temporary limits on attempts, with hashed network and account identifiers. There is no fixed two-account-per-IP rule. Shared networks can still encounter temporary limits; contact support if you need help.

Safety checks can record a submitted URL, domain, risk signals, report details and moderation actions. If external threat checking is enabled, a destination URL can be sent to Google Web Risk. Contact us to request a review of a restriction.

Report abuse or contact support.

9) Cookies

Optional media and booking modules: Spotify, YouTube and Calendly content stays unloaded until you choose to load it. Loading a module sends browser information to that provider, which may use cookies and process data under its own privacy policy. You can keep using the page without loading it, open the provider directly, or unload the content at any time. Unloading stops further requests from that module; it does not erase information or cookies already received by the provider.

  • First-party cookies: On Lynko pages, cookies support secure sessions, request protection, account security, saved language choices, remembered sign-in and guest-created links when you use those features.
  • No advertising trackers: Lynko does not use third-party advertising trackers. Its privacy-friendly growth funnel uses the existing session and does not set a separate analytics cookie.

Lynko records an allowlisted first-party funnel using page, language, source, intent and plan keys plus hashes derived from the essential session. Campaign labels are hashed. This funnel does not store full URLs, IP addresses, email addresses, message content or full user agents.

For signed-in owners, these allowlisted milestones also power the task checklist and welcome-back guidance in their own workspace. They never grant product, workspace or billing authority.

10) Retention

The periods below describe the configured retention schedule. Deletion and anonymization run through scheduled maintenance, so expiry does not mean immediate erasure. Aggregated totals can remain after detailed records are removed.

  • Unactivated accounts: deleted after 3 days.
  • Activation tokens: stored as a hash, expire after 3 days, cleared on activation or expiry.
  • Password-reset and deletion tokens: stored as a hash, typically valid 24 hours, cleared on use or expiry.
  • Reward Unlock submissions: personal details are scheduled for anonymization after 90 days; aggregate statistics can remain.
  • Account and content records generally remain while your account or content exists. Account deletion removes associated records through the deletion process; payment, legal and recovery records may need separate retention.
  • Suspended shortlinks are scheduled for deletion after 90 days without paid access or a subscription grace period. Blacklisted shortlinks are scheduled for deletion after 30 days, including paid accounts. These periods begin when scheduled maintenance first records eligibility. Privacy password links are excluded from this automatic cleanup.
  • For selected blacklisted destinations, existing link registration and owner details may be kept in a restricted encrypted evidence archive for 180 days. A documented legal hold can extend this period until manually released. This archive does not download destination content or include visitor histories or passwords. Access and hold changes are logged.
  • Detailed link and QR tracking history is retained for 30 days on Free, 365 days on Bronze and Silver, and 1825 days on Gold. Insight Pixels also use plan-based history and aggregated counts; a downgrade can shorten available history.
  • Link safety review events are scheduled for deletion after 90 days. Other security, support and payment records are kept as needed to resolve incidents, deliver support, meet legal duties or handle disputes.
  • First-party funnel events: deleted after 180 days. Account-linked rows are deleted with the account, including rows scoped to workspaces owned by that account.
  • Link-page view deduplication records: Existing pseudonymous records are deleted 30 days after their last activity; new link-page views use short-lived session state instead.
  • Backups: retained for a limited period for disaster recovery, then overwritten.

11) Our processors

Lynko is hosted in the Netherlands on Eurofiber Cloud Infra infrastructure. This describes website hosting; email, payments and other connected services have their own processing locations.

Resend delivers account and service emails, such as signup messages, password resets and reminders. It receives the recipient email address and the content needed for that message, including relevant service links. Contact-form messages are sent through our own hosting mail service, not Resend.

Mollie processes payments and receives checkout and transaction information. Lynko stores customer, payment and subscription references, amounts and status information, but not full card details. Mollie also has its own responsibilities under its privacy notice.

Creators receive submissions made to their forms. External destinations, embeds and connected services can receive browser requests and process data under their own notices. Service providers may access data where needed for their work; access is not categorically excluded.

12) International transfers

Hosting location does not determine where every provider processes data. Email delivery, payment services and enabled external safety checks can involve processing outside the EEA, including the United States. Such transfers require an applicable GDPR transfer mechanism, such as an adequacy decision or standard contractual clauses. Contact us for provider and safeguard details.

13) Data requests

Contact us to request access, correction, erasure, restriction or portability, or to object to processing. We respond without undue delay and normally within one month. Where the GDPR permits an extension of up to two further months, we explain why within the first month. We may request proportionate identity verification.

Contact us

14) Complaints

You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can also seek a remedy in court.

15) Security measures

  • Password hashing.
  • CSRF protection and secure session cookies with HttpOnly, SameSite and HTTPS.
  • Account activation, password-reset and deletion tokens are stored as hashes. Registration and login records, analytics and abuse logs are separate data categories.
  • Temporary attempt limits, access controls and manual moderation help prevent abuse.
  • Access controls and least privilege for systems handling personal data.

16) Polls and voting data

  • One-vote protection: temporary storage of IP in binary form and session hash to prevent duplicate votes.
  • Voting records include the poll, chosen option, time, IP address in binary form and a session hash used to prevent duplicate votes.
  • After a poll closes, scheduled maintenance stores totals per option and removes individual vote rows, including their IP addresses and session hashes. This cleanup is not immediate at the moment of closure.
  • No profiling: voting data is never used for advertising, tracking or cross-service identification.

17) Children

Lynko.tv is not directed at children under 16. Do not register if you are under 16.

18) Changes

We may update this notice. Material changes will be highlighted here. Please review it periodically.

19) Contact

For privacy questions or requests, use the contact page.

Our replies may end up in your spam or junk folder. Please check it if you are waiting for a response.

Contact us


This notice summarizes our privacy practices to help you understand how we process your personal data under the GDPR and Dutch law (UAVG).

© 2026 Lynko.tv
Integrations Product Solutions Templates Pricing Trust Resources
More
Short Link Generator Dynamic QR Code Generator Link Pages QR Code Analytics Privacy-Friendly Link Tracking Branded Short Links Terms of Service GDPR Verify Link Report abuse Contact
Build your page free