Privacy Policy

linkable.id Privacy Policy

Last Updated: November 12, 2025

1. Introduction and Scope

This Privacy Policy describes how Andes Dev LLC ("linkable.id", "we", "us") collects, processes, shares, and protects personal data.

This policy applies to personal data collected from:

  • (a) Website Visitors: Individuals who visit our public marketing websites.
  • (b) Customers and Authorized Users: Individuals who represent the B2B entities that subscribe to our Service, and the users they authorize to access the platform.
  • (c) End-Users: Individuals who interact with the links, QR codes, and Landing Pages generated by our Customers through the Service.

2. Our Role: Data Controller vs. Data Processor

This distinction is critical for understanding your rights. The legal entity responsible for data processing (the "Data Controller") has different responsibilities than the entity processing data on its behalf (the "Data Processor").

2.1. linkable.id as Data Controller

linkable.id acts as the Data Controller when we process personal data for our own business purposes. This applies to:

  • Website Visitors: Collecting analytics on our public website.
  • Customers and Authorized Users: Processing account information (name, email), billing data, and support communications. We determine the "why" and "how" of this processing for managing our business.

2.2. linkable.id as Data Processor

linkable.id acts as the Data Processor when we process data on behalf of our Customers. This is the vast majority of data on our platform. Our Customer is the Data Controller for this data and is solely responsible for its lawfulness, security, and compliance. This model is standard for B2B SaaS platforms.

We act as a Processor for:

  • Customer Content: Any personal data that our Customers or their Authorized Users upload to the Service, such as in the Brand Asset Management (BAM) module or on Landing Pages.
  • End-User Analytics Data: All data generated when an End-User interacts with a Customer's link or QR code.

3. Data We Collect (as Controller)

When linkable.id acts as the Data Controller, we collect:

  • Account Information: Name, email address, password, and "Role" for Customers and their Authorized Users.
  • Security Information: Information for Two-Factor Authentication (2FA) setup.
  • Billing Information: Payment details and billing addresses for our Customers.
  • Support & Communications Data: Any information you provide when contacting our support (email or chat).
  • Public Website Analytics: Cookie and device information from visitors to our marketing pages.

4. Data We Process (as Processor)

When linkable.id acts as the Data Processor on behalf of our Customers, we process:

  • Customer Content: Any personal data contained within the assets (logos, images, PDFs) and content (Widgets) uploaded or created by the Customer.
  • End-User Analytics Data: When an End-User clicks a Short URL or scans a Dynamic QR Code, we process the following data for our Customer's analytics:
    • IP Address
    • User-Agent String (which provides Browser and Operating System data, used for the "Targeting SO" feature)
    • Referring URL
    • Timestamp of click/scan
    • Geographic location (country/city derived from IP)
    • Source of interaction (e.g., "Click" vs. "Scan")

5. How We Use Data

  • As Controller: To provide, secure, and maintain the Service; to process payments; to provide customer support; to send service notifications; and to comply with legal obligations.
  • As Processor: We process data only as instructed by our Customer (the Data Controller). We do not scan, access, use, or sell Customer Content or End-User Analytics Data for any other purpose, such as advertising or our own marketing.

6. Data Sharing and Sub-processors

We do not sell your personal data. We may share data with third-party sub-processors (e.g., cloud hosting providers like AWS, payment processors) who help us provide the Service. We maintain a list of our sub-processors and ensure they meet our security and privacy standards.

7. Your Data Subject Rights (e.g., GDPR)

Your rights depend on our role in processing your data.

  • If linkable.id is the Data Controller (e.g., you are a Customer/Authorized User): You have the right to access, correct, or delete your personal data. You can manage your profile information via the "Mi Perfil" module or by contacting us.
  • If linkable.id is the Data Processor (e.g., you are an End-User who clicked a link): We process your data on behalf of our Customer. You must direct any requests to exercise your data rights (access, deletion, etc.) to the Customer (the brand or entity that created the link or QR code you interacted with). If we receive such a request, we will forward it to the relevant Customer.

8. Data Security and Retention

We implement robust technical and organizational security measures, including 2FA , to protect all data. We retain data we control (Customer accounts) for as long as the account is active and as required by law. We retain data we process (Customer Content, End-User Analytics) according to our Customer's instructions or until the termination of our agreement.