Legal

Privacy Policy

Last updated: April 25, 2026

1. Data Controller

The data controller for your personal data is:

Kortilink
Website: kortilink.com
Email: privacidade@kortilink.com
Headquarters: Lisbon, Portugal

By using our services, you accept the practices described in this Privacy Policy.

2. Data We Collect

2.1 Data you provide directly

  • Name and email address (when creating an account or contacting us)
  • Profile information (username, profile photo, bio)
  • Payment information (processed by Stripe — we do not store card data)
  • Content you create on the platform (links, Bio Pages, UTM tags)

2.2 Automatically collected data

  • IP address and approximate location (country, city)
  • Device type, operating system and browser
  • Pages visited, links clicked and session duration
  • Click data on shortened links (including referrer, country, device)
  • Cookies and session identifiers (see section 4)

2.3 Data obtained from third parties

  • If you sign in with Google OAuth: name, email and profile photo from your Google account
  • If you sign in with Facebook OAuth: name, email and profile photo from your Facebook account

3. Purpose and Legal Basis

We process your personal data for the following purposes and legal bases under the GDPR (General Data Protection Regulation — EU 2016/679):

  • Service provision — necessary for the performance of a contract (Art. 6(1)(b))
  • Account management and authentication — necessary for the performance of a contract (Art. 6(1)(b))
  • Billing and payments — necessary for the performance of a contract (Art. 6(1)(b))
  • Analytics and service improvement — legitimate interest (Art. 6(1)(f))
  • Marketing communications — with your consent (Art. 6(1)(a))
  • Compliance with legal obligations — legal obligation (Art. 6(1)(c))

4. Cookies and Tracking Technologies

We use cookies and similar technologies to ensure the correct functioning of the platform, remember your preferences and analyse service usage. See our Cookie Policy for detailed information.

You can manage your cookie preferences at any time in your browser settings or through our consent management tool.

5. Third Parties and Subprocessors

We may share your data with the following third parties, who act as subprocessors:

Google (OAuth and Analytics)

We use Google OAuth for optional authentication. Google may process data according to its own privacy policy. Learn more at policies.google.com/privacy.

Meta / Facebook (OAuth)

We offer Facebook login as an authentication alternative. Meta processes data according to its privacy policy at facebook.com/privacy/policy.

Stripe (Payments)

Payments are processed by Stripe, Inc. We do not store credit card data. Stripe is PCI-DSS Level 1 certified. See their policy at stripe.com/privacy.

Other providers

We may use cloud infrastructure providers (such as Supabase/Firebase), CDN and transactional email services (such as SendGrid). All providers are contractually obligated to protect your data and process only strictly necessary data.

We do not sell your personal data to third parties for marketing purposes.

6. Data Retention

We retain your personal data only for as long as necessary for the described purposes:

  • Account data: while the account is active and for 30 more days after deletion
  • Link analytics data: 24 months from the date of the click
  • Billing data: 10 years (legal tax obligation)
  • Access logs: 90 days

7. Your Rights under GDPR

As a data subject residing in the EU/EEA, you have the following rights:

  • Right of access — request a copy of your personal data
  • Right of rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request the deletion of your data
  • Right to restriction of processing — restrict the way we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interest or direct marketing
  • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at privacidade@kortilink.com. We will respond within 30 days.

You also have the right to lodge a complaint with the competent supervisory authority — in Portugal, the CNPD (National Data Protection Commission): www.cnpd.pt.

8. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication available for all accounts
  • Restricted data access by staff on a need-to-know basis
  • Regular security audits
  • Monitoring of suspicious activity

In the event of a data breach that may affect your rights, we will notify the competent authorities within 72 hours and inform you if the risk is high.

9. Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will change the "last updated" date at the top of the page. For significant changes, we will notify users by email or through a prominent notice on the platform.

We recommend that you review this policy regularly to stay informed about how we protect your data.

10. Contact and DPO

For privacy-related questions, data protection, or to exercise your rights:

Kortilink — Data Protection Officer

Email: privacidade@kortilink.com
General support: suporte@kortilink.com
Headquarters: Lisbon, Portugal