Privacy Policy
Effective September 2, 2026
This policy covers MyLink.is and every public profile hosted on it. Two very different people appear in it and they are not owed the same explanation: someone with an account here, who built a page, and someone who visited a page that belongs to somebody else and never signed up for anything. Sections 3 to 8 are written for the second kind, because most of what this app stores about people is stored about them.
Everything here describes what the product actually does today. Where a section says we do not do something, it is because there is no code that does it.
1. Who Is Responsible for What
For your account, the page you build, and the traffic measurement described in section 3, we decide why the data exists — in data-protection terms we are the controller, and this policy is our account of it.
That controller is Kanan Digital Ltd, registered in England & Wales under company number 17438947, at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. To reach us about anything on this page, write to abuse@mylink.is.
We are registered with the UK's Information Commissioner's Office as a data controller, reference ZC247344, which you can look up on the ICO's public register of fee payers.
For anything you hand to a profile owner — an appointment you booked, a newsletter you subscribed to, a file you asked for — the owner decides why it is collected and we hold it for them. We process it only to run the feature, never for our own purposes, and we do not use it to market anything to you. The formal version of that arrangement, for newsletters, is the data processing agreement in our Terms for Data You Collect, which covers everything a page collects rather than any one feature — a booking, a subscription, a download or a purchase are all held under it.
We do not sell or rent personal data, we do not share it for advertising, and we run no advertising and no tracking of our own anywhere in this product.
One case is not ours to promise away: a profile owner can put a video, a playlist or a map on their page, and those are the provider's own players. Nothing is requested from them until you ask for it — see Players and maps on someone's page in section 3.
What we rely on to do it
Data-protection law asks us to say not just what we do but what entitles us to, and the answer is different per purpose:
- Your account and your page — performing the agreement you made with us when you created one
- Payments — performing that agreement, and our legal obligation to keep records of a sale
- Traffic measurement — our legitimate interest in knowing whether the product works. You can object simply by switching it off in section 3
- Security logging and rate limiting — our legitimate interest in keeping accounts and the service from being attacked
- Bookings, subscribers and download requests — the profile owner's basis, not ours; we hold them under their instructions
- The email in section 8 — performing the agreement, or the step you asked for
2. If You Have an Account
You sign in with an email address and a password. There is no social login here: we do not offer "sign in with Facebook" or "sign in with Google", and no identity provider is told that you have an account or when you use it. Earlier versions of this page described such a flow; it was never available.
For an account we store:
- Your email address, and your password as a bcrypt hash — never the password itself
- Single-use tokens for confirming your address and resetting your password
- Everything you put on your page: username, bio, avatar and cover images, links, appearance settings, and the services, availability and newsletter description you configure
- Credentials for a newsletter platform you connect, encrypted, and never shown back to you in full
Your page is public by construction — it lives at mylink.is/your-username and anyone can read it. Your account email is not part of it and is not published; if you want a reply-to address on your booking confirmations, you enter one deliberately.
Signing in sets one cookie, named session. It is HttpOnly, so page scripts cannot read it, and it expires after seven days.
Your account activity log
We keep a security log of activity on your own account: sign-ins and failed sign-in attempts, password changes, profiles created, changed or deleted, and every time subscriber or lead data is exported. Each entry records the approximate network you were on rather than your full IP address — the first three octets of an IPv4 address, or the first three groups of an IPv6 one — and a description like "Chrome on macOS" rather than your full browser string. You can read and export this log at any time from Account activity in the studio. Entries are deleted after 180 days.
3. If You Visit a Profile: Traffic Measurement
We count visits to this site and to the profile pages hosted on it, so we can tell whether the product works and so profile owners can see how their own page performs. We also sometimes show two versions of a page to different visitors in order to compare them.
This runs from the moment you arrive, and we tell you so in a notice at the bottom of the page. We store one cookie holding a random identifier, kept for at most 13 months, and we record:
- The page you were on, and which profile it belonged to
- Which link, social icon, or button you used
- Whether you started or finished a booking, subscription or download — not what you typed into one
- Which version of a page you were shown, when we are comparing two
- Which kind of site sent you here — "Instagram", "Google", "an email" — chosen from a fixed list of names. Never the address you came from, and nothing at all if it is a site we do not recognise
We do not send your name, your IP address, your exact location, or anything you type. We do not track you across other websites, we do not build a profile of you, and we do not sell or share this information for advertising.
We do this without asking your permission first because measurement limited in this way — first-party, statistical, not shared onward, and not used to profile you — is exempt from the usual cookie-consent requirement under the guidance we have built it against, which is France's CNIL. That is a position rather than a settled point everywhere: the UK's ICO does not recognise an audience-measurement exemption, and some other regulators are stricter still. We are telling you which argument we are relying on rather than presenting it as beyond question, and the off switch below is the reason it is a defensible one to make. That argument is also why the list above is deliberately short — every item we added to it would weaken it.
Players and maps on someone's page
A profile owner can put a YouTube or Vimeo video, a Spotify player, or a Google map on their page. Those are the provider's own frames, not ours, and loading one tells that provider your IP address and which page you were on — two of them also store a cookie of their own, which we neither set nor read.
So we do not load them until you ask. A block like that appears as a placeholder naming the provider, and nothing is requested until you tap it. If you never do, no request is made and nothing is stored. Tapping one is a choice about that provider and we do not remember it: come back tomorrow and the block is a placeholder again.
Where those events go, and what the trip itself reveals
These events are sent from your browser directly to our analytics processor, who process them for us on servers in the European Union. Like any request your browser makes, that one carries your IP address and your browser's user-agent string, and they derive an approximate country, browser, operating system and device type from them. We neither send nor store those ourselves, but they are a real consequence of how the measurement works and you should know about it rather than infer it.
If you are in the EU, that is not a transfer at all: the data stays in the Union. If you are in the UK, it reaches the EEA, which UK law already treats as offering equivalent protection, so nothing further is needed to make it lawful. Nothing in this product behaves differently depending on where you are — we do not detect your country — so whatever protection is described on this page applies to everyone reading it.
You can stop it at any time. If you do, the identifier is deleted from your device and nothing further is recorded:
4. If You Book an Appointment
Anyone can book an appointment through a profile page without creating an account. When you do, we store:
- The name and email address you enter on the booking form
- Anything you write in the notes field
- The time you booked, and the timezone your browser reported
This is shared with the profile owner you booked with — that is the point of a booking — and with nobody else. We email you a link to confirm, move or cancel it; that link is the only way to reach your booking, so treat it as private. A slot you start but never confirm is held for 15 minutes and then released, and the record is removed the next time somebody wants that time. Deleting the profile you booked with deletes these details with it. To have them removed sooner, cancel the booking or contact the profile owner.
5. If You Subscribe to Someone's Newsletter
Some profiles carry a newsletter signup form. If you use one, we store:
- The email address, and the name if you gave one
- The time you signed up and the time you confirmed
- The IP address and browser you confirmed from, and the page you signed up on
Those last two exist for your benefit as much as the sender's: they are the record of what you agreed to and when, and they are what a sender must produce if you ever dispute being on their list. This is the one place we keep a full IP address about a visitor, and it is kept because a consent record with an approximate address proves less than one with an exact one.
We do not send newsletters. The only email we send you is the one asking you to confirm. You are not subscribed until you do — if you ignore it, the record is deleted within 72 hours and nothing else happens.
Once you confirm, the profile owner is the controller of that data and we hold it for them. They can export it, and the point of exporting it is to send you email from their own platform — so your address will end up with an email service we do not choose or control. The unsubscribe link on our side removes you from the list held here; it cannot reach a copy the owner has already exported. To be removed from that, ask the sender directly. Owners are required to honour that request under our Terms.
Deleting the profile you subscribed to deletes the copy held here along with it.
6. If You Request Someone's Download
Some profiles offer a file download behind a short form. If you use one, we store:
- The name and email address you entered
- The time you requested the file and the page you requested it from
That information is shared with the profile owner who offered the file — that is the point of the feature — and they can export it. Asking for the same file again does not create a second record. Deleting the profile deletes the copy held here. It cannot delete a copy the owner already exported.
7. If You Buy Something
A profile can sell a product, a file, or a paid appointment. Paying is handled by Stripe, and the money goes to the profile owner's own Stripe account rather than to us — we never hold it and we never see your card details, which you enter on Stripe's own checkout.
For a purchase we store:
- The email address you gave, so that a receipt and any file can reach you
- What was bought, the amount, and when
- Stripe's identifier for the payment, so a sale can be matched to a payment when one of us needs to look it up
Stripe is the payment processor for that transaction and handles your card details under its own privacy policy and its own obligations as a regulated business — that part is between you and them, and it is not something we can see or change.
Our copy of that record is deleted when the profile is deleted, like everything else the page collected. Two copies are not ours to delete, and you should know they exist: Stripe keeps its own record of the payment under its own obligations as a regulated business, and the seller may be required by tax law where they live to keep their own record of what they sold. Ask us and we will delete ours; the other two are questions for Stripe and for the seller.
If you want a refund, or the item was not what you expected, the profile owner is the seller and the person to ask — reach them through their page.
8. Email We Send You
Every message this app sends leaves from no-reply@mylink.is and is sent for you to act on something, never to market to you. There are five kinds:
- Confirming your email address when you sign up, and resetting your password
- Telling you that someone tried to sign up with an address that already has an account — sent to you, not to whoever tried
- Confirming, moving or cancelling a booking, with a calendar attachment
- Asking you to confirm a newsletter subscription, once
- Notifying a profile owner that they have been booked
9. Who Else Processes Your Data
This is the complete list. We will update it here before adding another.
- Cloudflare — hosting, the database that holds everything described above, storage for the images and files people upload, and delivery of the email in section 8. Every request to this site reaches us through them.
- MailChannels — also delivers the email in section 8. We are moving that to Cloudflare, and both can carry a message until we have finished.
- Our analytics processor — the traffic measurement in section 3, on servers in the European Union. This is the only one that is not in the request path for the rest of the product, and the only one you can switch off.
- Stripe — payments, as described in section 7. Only for a profile that sells something, and only when you buy.
Two more are worth naming even though they are not quite the same kind of thing:
- YouTube, Vimeo, Spotify and Google Maps — the players and maps a profile owner can put on their page. They are not processing anything for us; they receive a request from your browser if you choose to load one, on their own terms. Section 3 says what that means and why we do not load them for you.
- The service that generates a backdrop when an account holder asks for one from a description. That is an account holder's own prompt, not a visitor's data, and nothing about you reaches it.
A newsletter platform you connect yourself — beehiiv, or a webhook you point at something — receives the subscribers you send it, at your instruction. That is your arrangement with them, not ours.
10. How Long We Keep Things
- Your account and your page — until you delete the page or ask us to close the account
- Bookings, subscribers and download leads — until the profile they belong to is deleted, or until you or the owner removes the individual record
- A record of a sale — until the profile it belongs to is deleted. Stripe's own record of the payment is separate and outlives it
- An unconfirmed newsletter signup — 72 hours
- An unconfirmed booking — 15 minutes
- Your account activity log — 180 days per entry, and the whole log goes with the account
- The measurement cookie — 13 months, or until you turn measurement off
- Your sign-in cookie — 7 days
- The throttling counter for an IP address — 24 hours after the last attempt it counted
Sign-in, signup, booking and subscription attempts are throttled by a counter keyed to the IP address the request came from, so that automated abuse can be slowed down. The count resets when its window ends, and the row holding it is deleted once it is more than 24 hours old — on the next attempt against any throttled endpoint, whether or not that address comes back. It is never joined to your account or used for anything else.
11. Your Rights, and the Controls That Answer Them
You can access, correct, export, and delete your data, object to or restrict some processing, and complain to your local data protection authority. Most of that does not need us at all:
- Turn off measurement — the button in section 3, on this page
- Unsubscribe — the link in the confirmation email, which keeps working forever
- Cancel or change a booking — the link in your booking email
- Delete a page and everything collected through it — in the studio; this removes its bookings, subscribers and leads with it
- Export — your subscribers, your download leads, and your account activity, all as CSV from the studio
- Ask a profile owner directly — for a booking, subscription or download you gave them, they are the person who decides, and they can delete individual records
Close your account — under Account in the studio. It deletes every page on the account and everything collected through them, cancels a Pro subscription if you have one, and removes the account itself: the email address, the password, the activity log and the billing record. It cannot be undone and we cannot bring any of it back.
Two things outlive a closed account, and you should know which. A report somebody made about one of your pages is kept — it records the address as it read at the time, so leaving does not erase a complaint made against you. And where you sold something, the payment provider keeps its own record of the payment under its own obligations; our copy goes with the page.
We answer a request within one month. That is the period data-protection law allows, and it applies whether you write to us about your own account or about something you handed to a profile owner. If a request is complicated enough to need longer, we will tell you inside that month rather than let it run on.
12. Age
You must be at least 16 to create an account, and at least 18 to take money through one — that second number is our payment provider's, who do not contract with minors. We do not verify anyone's age, and we have no way to know it; if we learn that an account belongs to someone younger, we delete it and everything collected through its page.
13. Security
Passwords are stored as bcrypt hashes and never in readable form. The sign-in cookie is HttpOnly and same-site. Newsletter platform credentials are encrypted before they are stored and are never returned to a browser. Booking, subscription and download links are unguessable single-purpose tokens rather than row identifiers, so knowing one reveals nothing about anyone else's. Sign-in and signup attempts are rate-limited, and security-relevant account actions are logged where their owner can see them.
No system is perfectly secure and this one is small and young. If you find a problem with it, we would rather hear from you than not.
14. How to Reach Us
For a request the controls in section 11 cannot handle — closing an account, a copy of everything we hold about you, or a complaint — contact us through the support form, or email abuse@mylink.is directly.
A message sent through the support form reaches us as an email, and carries what you typed — your email address, the topic, the subject and the message — along with any files you attach. Attachments are also stored on our own storage at an address that is not guessable and is not listed or linked anywhere else, so that we still have them if the email does not arrive intact. We keep a support message and its files for as long as we need them to answer you; ask us and we will delete them.
If your request is about a booking, a subscription or a download you gave to a profile owner, they are the person who decides — reach them through their page.
15. Changes to This Policy
We may update this policy. Material changes will be posted here with a new effective date before they take effect.
Questions about this document? Write to abuse@mylink.is.