SMARTLINK

Privacy Policy

Last updated 2026-08-23

Exactly what we hold, why, who else touches it, and how to get it back or get rid of it. Written from the code, not from a template.

Who is responsible

[LEGAL ENTITY NAME], at [REGISTERED ADDRESS, GREECE], is the data controller for the personal data described here. Contact us at support@alexincodeland.xyz about anything on this page.

We are established in the EU and this policy is written to meet the GDPR.

What we collect from you

When you create an account and use it, we hold:

  • your email address, and a securely hashed password — we never see the password itself
  • a display name and an avatar image, if you set them
  • the content you create: brand names and handles, page titles, descriptions, links, social handles, design settings, and any images or video you upload
  • billing records: which plan you are on, whether it is monthly or annual, when the period ends, the amount charged, and the identifiers Stripe gives us for you and your subscription
  • custom domains you connect, and the verification record used to prove they are yours

What we never hold

We do not store card numbers, expiry dates or security codes. Payment happens on Stripe's own checkout page; the card details never reach our servers.

We do not store visitors' IP addresses. See below — this one is worth reading.

What we collect from visitors to your pages

When somebody opens one of your pages or clicks one of your links, we record a single row so you can see how your page is doing. That row holds the time, which page or link it was, the country (as reported by our hosting provider), the browser's user-agent string, and the website they came from — the site only, never the full address they were on.

To avoid counting the same person twice, we need to recognise a repeat visit for half an hour. We do that by combining the visitor's IP address and browser string into a one-way cryptographic hash together with a rotating time window. The hash is stored; the IP address is not, and cannot be recovered from it.

We do not use cookies to track visitors across sites, and we do not run advertising or third-party analytics on your pages.

Requests that look like bots — link previewers, crawlers, scrapers — are identified and not counted at all.

Why we are allowed to hold it

Your account and content: to perform the contract between us. We cannot run your pages without them.

Billing records: to perform the contract, and to meet accounting and tax obligations.

Page and click statistics: our legitimate interest, and yours, in you being able to see whether your pages work. This is kept to the minimum that answers the question, which is why the IP address is discarded rather than stored.

Emails about your account — confirmations, password resets, notices that your password or address changed: to perform the contract and to keep your account secure.

Who else touches your data

We use a small number of providers. Each processes data only on our instructions.

There is no advertising network, no third-party analytics, and no font or asset service involved. Typefaces are served from our own servers, so viewing a page does not put a visitor in touch with anyone but us.

  • Supabase — database and sign-in. Hosted in Frankfurt, in the EU.
  • Vercel — hosting and delivery of the site and your pages. Frankfurt region.
  • Stripe — payments. Stripe is the controller of your payment details, under its own privacy policy.
  • Resend — sending account emails such as confirmations and password resets.

How long we keep things

Your account and content: for as long as your account exists.

When you delete your account, we delete your brands, pages, links, uploaded files and statistics. Deletion is immediate and cannot be undone. Your brand handle is held for 30 days so that only you can reclaim it, and then released.

Billing records are kept for as long as tax and accounting law requires, even after an account is closed.

Your rights

Under the GDPR you can ask us for a copy of your personal data, ask us to correct it, ask us to delete it, object to processing based on legitimate interests, and ask for it in a portable form.

Write to support@alexincodeland.xyz and we will respond within one month. If you think we have handled your data badly, you can complain to the Hellenic Data Protection Authority, or to the authority where you live.

Security

Data is held in the EU. Access between accounts is restricted at the database itself, not only in the application, so one customer's records cannot be read by another.

Changing your password signs out other devices, and we email you when your password or email address changes so an unexpected change does not go unnoticed.

No system is perfectly secure. If a breach ever affects your personal data, we will tell you and the regulator as the law requires.

Children

SmartLink is not intended for children. Do not create an account if you are below the age of digital consent where you live. If we learn that we hold a child's data without proper consent, we will delete it.

Changes

If we change what we collect or why, we will update this page and email you before the change takes effect.