Privacy Policy

How LinkTrail handles personal data across our website, dashboard, link endpoints, and mobile SDKs — what we collect, why, how long we keep it, and the rights you have.

Last updated: 29 July 2026 · Version 1.0.

In short

LinkTrail is a mobile deep linking and attribution platform. We collect personal data in two different situations, and they work differently.

If you are one of our customers — you signed up for an account, use the dashboard, or contact us — we decide how your data is used, and Sections 4 and 6 to 13 explain what we collect, why, and for how long.

If you are an end user of an app built by one of our customers, we handle click and install data about you on that customer's instructions. They decide what is collected; we act on their behalf, and their privacy notice governs it. Section 3 explains how to reach us anyway if you can't identify the app, and is honest about the limited purposes for which we use that data on our own account.

Our platform runs on servers in the European Union. We do not sell personal data. We do not use advertising identifiers — we never access the Apple IDFA or the Google Advertising ID. We do use device fingerprinting for attribution where other signals aren't available, which Section 5 describes plainly. We use cookies on our website only after you accept them. You can contact us at privacy@linktrail.io and you can complain to the Information Commissioner's Office.

1. Who we are

LinkTrail Ltd ("LinkTrail", "we", "us") is a company registered in England and Wales, company number 17312947, registered office 66 Paul Street, London EC2A 4NA, United Kingdom.

We are the controller for the personal data described in Section 4, and for the limited purposes described at the end of Section 3.

Privacy contactprivacy@linktrail.io
Postal addressLinkTrail Ltd, 66 Paul Street, London EC2A 4NA, United Kingdom
Security contactsecurity@linktrail.io
Data Protection OfficerWe have not appointed a DPO. Privacy questions go to privacy@linktrail.io.
EU representative (Art 27 EU GDPR)A representative has been engaged and we are awaiting confirmation of the appointment. Their name and address will be published here once confirmed. In the meantime, EEA residents and supervisory authorities can contact us at privacy@linktrail.io.
Supervisory authorityInformation Commissioner's Office (ICO), United Kingdom

This policy covers our website at linktrail.io and our documentation, the dashboard at developer.linktrail.io, our link endpoints (including customer custom domains), our APIs, and our iOS, Android, React Native and Flutter SDKs. We refer to all of this as the Services.

2. Which law applies

We are established in the United Kingdom, so UK GDPR and the Privacy and Electronic Communications Regulations (PECR) apply to us, and the ICO is our lead supervisory authority. Because we offer the Services to customers and end users in the European Economic Area, EU GDPR also applies to that processing.

3. Two roles: controller and processor

Data protection law separates the party who decides why data is processed (the controller) from the party who processes it on someone else's instructions (the processor). LinkTrail is both, depending on whose data it is.

We are the controller for data about our own customers and prospects: people who visit linktrail.io, contact us, sign up for an account, administer a team, pay us, or raise a support ticket. Section 4 governs that data.

We are a processor for data about end users of our customers' apps: clicks on links, install signals, device identifiers, device characteristics used for attribution matching, and any custom payload the customer attaches to a link. Our customer decides what is collected and why. We process it under a data processing agreement, on their documented instructions, to provide attribution, deep linking and fraud detection back to them. The customer's own privacy notice governs that data.

If you are an end user of an app that uses LinkTrail and you want to exercise your rights, contact the app's developer — they are the controller and they hold the relationship with you. If you contact us instead, we will identify the relevant customer where we can and pass your request to them, and we will tell you we have done so, normally within one month. We cannot grant access, deletion or objection requests over that data on our own authority, because it is not ours to decide.

Where we use end-user data for our own purposes

We are open about this because it is a genuine exception to the paragraphs above. As well as processing end-user data on each customer's behalf, we use it for three purposes of our own, which makes us a controller for those purposes:

  • Improving fraud detection. Fraud patterns only become visible across many apps at once — a device farm hitting twenty customers looks like noise inside any one account. We analyse signals across our customer base to develop and tune the heuristics that detect it.
  • Aggregate statistics and benchmarks. We produce aggregate measures of platform performance, including match rates and attribution accuracy, some of which we publish or share with customers as benchmarks. These are aggregate figures and do not identify any individual.
  • Product development and debugging. We use real processing data to diagnose faults, reproduce bugs and develop the Services.

Our lawful basis is legitimate interests (Art 6(1)(f)): operating a platform whose core promise is accurate, fraud-resistant attribution, which cannot be delivered from any single customer's data in isolation. We use the minimum data needed, we do not use it to build profiles of individuals for any purpose unrelated to fraud detection or service quality, and we do not disclose one customer's data to another in identifiable form. You can ask us for the balancing assessment behind this at privacy@linktrail.io, and you can object under Section 11.

4. What we collect as controller, and why

This table covers data where we decide the purpose — our customers, prospects and website visitors. Data collected through our link endpoints and SDKs is covered by Section 5 instead.

What we collectWhyLawful basisHow long we keep it
Account data — name, work email, password (stored hashed), company name, team members and their rolesTo create and run your account, authenticate you, and give team members the right level of accessContract (Art 6(1)(b))For the life of the account, then 90 days after closure. Residual copies persist in backups until they expire — see Section 12
Billing data — plan, subscription status, billing contact, invoices and transaction records. Card details go directly to Stripe; we never hold full card numbersTo take payment, manage renewals and produce tax recordsContract; legal obligation (Art 6(1)(c)) for tax records6 years from the end of the accounting period to which they relate
Usage data — dashboard logins, API key usage, features used, IP address and user agent when you use the dashboardTo operate and secure the dashboard, investigate faults, and understand which features are usedLegitimate interests — running and improving a service you have asked for, and keeping it secure12 months
Support data — tickets and emails sent to support@linktrail.ioTo answer your questions and keep a record of what was agreedContract; legitimate interests for prospects who are not yet customers24 months after the last contact
Enquiry data — name, email, company and message from contact and sales formsTo respond to you and follow up on a sales enquiryLegitimate interests — responding to someone who has approached us24 months after the last contact
Website analytics — pages viewed, interactions, approximate location from IP, campaign source, collected through Google Analytics for Firebase and a Google Ads conversion cookieTo measure how the website performs and whether an ad click led to a signupConsent (PECR reg 6 and UK GDPR Art 6(1)(a)) — collected only after you accept on our cookie bannerThe period configured on our analytics property; contact privacy@linktrail.io for the current setting. The analytics cookies themselves last 2 years and the Google Ads conversion cookie 90 days
Website server logs — IP address, request path, timestamp, user agent for requests to linktrail.io and developer.linktrail.ioTo deliver content, diagnose faults, and detect abuse and attacksLegitimate interests — network and information security90 days
Diagnostic and error data for the website and dashboard — stack traces and the request context attached to an error, which can include an IP address and a user identifierTo detect and fix faultsLegitimate interests — keeping the Services working correctly90 days
Marketing data — your email address and whether you opened or clicked our emailsTo send product updates and marketing where you have asked for them or where the PECR soft opt-in appliesConsent; or legitimate interests under the PECR soft opt-in for existing customers, for our own similar products, with an opt-out in every messageUntil you unsubscribe, then a suppression record kept indefinitely so we do not email you again
Security logs relating to your account — failed logins, key rotations, admin actionsTo protect accounts from takeover and to investigate incidentsLegitimate interests; legal obligation where a breach is notifiableThe source IP is cleared after 12 months. The remaining entry is kept for the life of the account as an integrity record

Where we rely on legitimate interests, you can ask us for the balancing assessment behind it, and you can object (Section 11).

Do you have to give us this data? Account and billing data are required to enter into and perform our contract with you — without them we cannot give you an account or take payment. Everything else is optional: you can decline analytics cookies, decline marketing, and use the Services without contacting support.

5. What we process as processor, on our customers' behalf

We set this out for transparency. Our customer, not LinkTrail, decides which of these are collected and configures consent inside their app. The lawful basis for it is theirs to establish, and their privacy notice governs it. Section 3 explains the separate, limited purposes for which we use this data on our own account.

CategoryWhat it includes
Click and redirect dataTimestamp, link ID, workspace and campaign identifiers, channel, referrer, the destination a click was routed to, and a deferred click token
Network dataIP address, and the approximate location and network derived from it
Device and environmentUser agent, device model, OS and version, screen metrics, timezone, language and locale
Device identifiersiOS: identifier for vendor (IDFV), with a randomly generated persisted UUID as fallback where IDFV is unavailable. Android: App Set ID, with a randomly generated persisted UUID as fallback. Both are scoped to the app developer and are not shared between companies
Advertising identifiersNone. We do not access the Apple IDFA at any point, with or without App Tracking Transparency permission, and we do not read the Google Advertising ID
Clipboard (iOS)Where a link leads to the App Store, a short random code is written to the device clipboard so that the app can identify the originating link after install. The code contains no information about the individual and is cleared by the app once read
Install signalsGoogle Play Install Referrer, install timestamp, first-open event
App contextApplication bundle identifier, platform
Derived dataAttribution match type, confidence score and fraud score
Deep link payloadThe deep link path and any custom data the customer attaches to a link, which is within the customer's control
Post-install eventsEvents the customer chooses to send us, such as signup or purchase value
Link endpoint and API logsIP address, request path, timestamp and user agent for requests to our link endpoints and API

How long we keep it. Raw click and install records, which include device-level signals, are retained for 13 months and then deleted by an automated purge job. Aggregated attribution reports, which contain campaign-level counts and no device identifiers, are retained for 3 years. Link endpoint and API logs are retained for up to 90 days. A customer can ask us to delete their data sooner, and we delete it on termination in line with the data processing agreement — see Section 12 on what that means for backups. Note that the analytics history included in each plan is a product feature and is not the same as these retention periods.

Device fingerprinting

Our attribution waterfall uses deterministic signals first — the Google Play Install Referrer, or a deferred click token carried through the install. Where neither is available, it falls back to probabilistic matching: we compare the IP address, user agent, screen metrics, timezone and language/locale of a click against those of an install within a matching window, and produce a confidence score for the match.

This is device fingerprinting, and we describe it as such. Under Article 5(3) of the ePrivacy Directive and PECR regulation 6, reading information from a user's device in this way requires the end user's consent, and the European Data Protection Board confirmed in Guidelines 2/2023 that this applies to fingerprinting as much as to cookies. Legitimate interests is not an available basis for it. The same is true of reading the IDFV or App Set ID, and of writing the clipboard code described above.

The fact that we do not use advertising identifiers does not change this analysis, and we do not present it as if it did.

Because we act as processor here, obtaining that consent is the customer's responsibility. Our SDKs are built to support that: collection is gated on a consent signal from the host app by default, and where no consent signal has been given, no device data is collected. A customer can disable that gate in their SDK initialisation options, in which case responsibility for obtaining consent beforehand rests entirely with them.

Controls available to customers. Probabilistic matching can be switched off, and the matching window changed, at workspace level. These controls do not currently operate per app or per link. A customer needing to separate one app from another must use separate workspaces.

6. Cookies and similar technologies

On our website we store one strictly necessary value to remember your cookie choice. Only if you accept do we set Google Analytics cookies to measure usage, and a Google Ads cookie to measure whether an ad click led to a signup. We use that Google Ads cookie for conversion measurement only — not for remarketing or personalised advertising — and we run no other advertising cookies.

Our banner offers Accept and Reject with equal prominence, and rejecting takes one click. You can change your choice at any time using "Cookie settings" in the footer of any page. Our Cookie Policy lists each cookie, its provider, purpose and duration.

The SDK and link signals described in Section 5 are separate from website cookies and are governed by the customer's own consent flows.

7. Who we share data with

We do not sell personal data. We share it in these situations.

Service providers and sub-processors who process data on our behalf under contract, restricted to our instructions and bound to confidentiality and security obligations:

ProviderRoleProcessing location
RenderCloud hosting, application and databaseEuropean Union
CloudflareCDN and edge delivery, DNS and securityEuropean Union
Microsoft Azure Application InsightsApplication performance and error monitoringEuropean Union (West Europe)
StripePayment processing and subscription billingIreland and United States
ResendTransactional and marketing emailIreland
Titan (purchased via Hostinger)Business email, including the support@linktrail.io mailboxUnited States and India
GoogleGoogle Analytics for Firebase and Google Ads conversion measurement, website onlyUnited States

We are also preparing to introduce Sentry (Functional Software, Inc.) for SDK and application error monitoring, processing in the European Union. It is not receiving data yet. We will update this list and notify customers before it begins.

We maintain this list and will update it when it changes. Stripe is not only our processor: it acts as an independent controller for fraud prevention, anti-money-laundering and its own regulatory obligations, and its own privacy policy governs that processing.

Ad networks and analytics tools, at our customers' direction. Where a customer configures an integration — Meta Ads, Google Ads, TikTok Ads, Apple Search Ads, Amplitude, Mixpanel, Segment, Braze, Iterable, BigQuery — we send attribution results to that destination on their instruction. The customer chooses the destination and is responsible for the lawful basis and consent covering it. These destinations are not our sub-processors; they receive the customer's data on the customer's own arrangements.

Our customers, where we act as processor and return attribution results to the controller of that data.

Professional advisers — lawyers, accountants and auditors, under professional duties of confidentiality.

Authorities and legal claims, where we are required by law or legal process, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of LinkTrail, our users, or the public.

A buyer or successor, in connection with a merger, acquisition, financing or sale of assets. We will tell you if your data becomes subject to a different privacy policy as a result.

8. Where data is processed, and international transfers

Our platform runs in the European Union. Application, database and edge infrastructure are hosted in EU regions, and customer and end-user data is stored there. We do not operate a US region.

Personal data may still be transferred outside the UK and EEA in three situations, and we apply safeguards to all of them:

  • Website analytics. Google Analytics and Google Ads conversion measurement transfer data to Google in the United States. This happens only if you accept analytics cookies, and you can decline or withdraw at any time.
  • Business email. Our support and business mailboxes are provided by Titan, whose infrastructure and support operations are located in the United States and India. This affects email correspondence with us, not platform data.
  • Vendor support and administration. Several of our providers are US-parented. Even where data is stored in the EU, their support and engineering staff may be able to access it from outside the UK and EEA, which counts as a restricted transfer.

For those transfers we rely on UK adequacy regulations where they apply, and otherwise on the ICO's International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, supported by a transfer risk assessment.

You can request details of the safeguards in place for a specific transfer at privacy@linktrail.io.

9. Automated processing

Attribution matching. We compare the signals of a click against those of an install to identify the most likely source of that install, producing a match type and a confidence score. This assigns credit to a marketing campaign. It does not produce legal or similarly significant effects on the individual whose install is matched, so Article 22 does not apply to it.

Fraud scoring. Every install is scored against velocity, device-signal and spoofing heuristics, and installs at or above the threshold are flagged in the customer's reporting. Scoring affects reporting only. LinkTrail does not make payment, payout or account decisions about any individual on the basis of a fraud score. Where a customer uses our reporting to decide whether to pay an advertising partner or affiliate, that decision is made by the customer in their own systems, and they are responsible for it — including for providing human review where the law requires it.

10. How we protect data

We use TLS 1.2 or above for all data in transit, with HTTP Strict Transport Security enabled and no plain-HTTP fallback, and AES-256 encryption at rest for the production database, its replicas and its backups. Internal access is limited to a small number of authorised personnel on a least-privilege basis, with multi-factor authentication enforced at organisation level on our hosting, source control and network providers. Production, staging and development are separate environments with separate credentials. Customer SDK API keys are stored only as SHA-256 hashes and are never retrievable after creation. An immutable audit trail records changes made through the dashboard. Automated dependency scanning alerts us to known vulnerabilities in third-party dependencies, and we apply security updates on review.

We do not currently hold an independent security certification and do not currently operate scheduled independent penetration testing. Our infrastructure is hosted in the European Union.

No system is completely secure. If a personal data breach occurs we will notify the ICO and affected individuals where the law requires it.

11. Your rights

Where we are the controller, you have the right to:

  • access the personal data we hold about you, and get a copy;
  • rectify data that is inaccurate or incomplete;
  • erase your data in certain circumstances;
  • restrict how we process it while a dispute is resolved;
  • object to processing based on legitimate interests — including the purposes in Section 3 — and to direct marketing at any time. For marketing this right is absolute and we will always stop;
  • portability — receive data you gave us in a structured, machine-readable format, where processing is based on consent or contract and is automated;
  • withdraw consent at any time where consent is our basis, without affecting processing already carried out; and
  • complain to a supervisory authority.

To exercise any of these, email privacy@linktrail.io. We respond within one month, and will tell you if we need to extend that by up to two further months for a complex request. We may need to verify your identity first. Exercising your rights costs nothing and we will not treat you differently for doing so.

If your request is about an app that uses LinkTrail, see Section 3 — we act as processor and will pass your request to the app's developer.

Device-level controls. Because we do not use advertising identifiers, resetting your advertising ID will not affect our attribution. What does affect it is the consent prompt shown by the app you are using: declining it stops our SDK collecting device data at all. On iOS you can also review app permissions in Settings → Privacy & Security. On Android, Settings → Privacy → Ads controls ads personalisation generally.

Complaints. You can complain to the ICO at ico.org.uk, on 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If you are in the EEA, you can complain to your national supervisory authority. We would rather hear from you first, at privacy@linktrail.io.

12. Deletion and backups

When data reaches the end of a retention period in Sections 4 or 5, or when you ask us to delete it, we delete it from our active production systems within 30 days.

Residual copies remain in database backups and point-in-time recovery archives, which expire on a rolling basis up to 12 months. Those backups are held encrypted, are not used for any purpose other than disaster recovery, and are not searched or restored to serve a request. Deletion is therefore complete in production within 30 days and complete across all copies once the relevant backup expires. Where we certify deletion in writing, the certificate covers production systems and states this backup position.

We may retain data for longer only where the law requires it — for example the billing and tax records in Section 4 — and where we do, it is used only for that purpose.

13. Children

The Services are sold to businesses and are not directed to children. You must be 18 or over to create an account, and we do not knowingly collect personal data from anyone under 18 through our website or dashboard.

End users of our customers' apps may include children, depending on the app. Customers must not use our SDKs or link endpoints in apps directed to children under 16, or under the age of digital consent applicable in the end user's country where that is lower, without our prior written agreement. Where we do agree, the customer is responsible for establishing a lawful basis before sending us data about children, and for configuring the Services accordingly — including disabling probabilistic matching.

If you believe a child's data has reached us, contact privacy@linktrail.io.

14. Changes to this policy

We update this policy when our practices, technology, or the law change. The version number and "last updated" date at the top always reflect the current version. Where a change materially affects how we use your data, we will tell you by email or through the dashboard before it takes effect.

15. Contact

Questions, requests and complaints: privacy@linktrail.io

Security reports: security@linktrail.io

Post: LinkTrail Ltd, 66 Paul Street, London EC2A 4NA, United Kingdom

Appendix: US residents

If you are a resident of a US state with a comprehensive privacy law — including California, Virginia, Colorado, Connecticut and Texas — you may have rights to know what personal information we hold about you, to obtain a copy, to have it corrected or deleted, and to opt out of targeted advertising and of the sale or sharing of personal information.

We are a UK company and our platform runs in the European Union. We do not sell personal information, and we do not use it for cross-context behavioural advertising of our own. Where a customer configures us to send their attribution results to an advertising platform, that is the customer's processing decision and their disclosures apply.

To make a request, email privacy@linktrail.io. We will honour applicable rights and will not treat you differently for asking. You may use an authorised agent, subject to verification. We treat the Global Privacy Control browser signal as a valid opt-out request and as a decline of our cookie banner.