Legal

Privacy Policy

This notice explains what personal data Lynko collects, why, and your rights under the UK GDPR and the Data Protection Act 2018. Lynko Ltd ("Lynko", "we") is the data controller for our website and accounts. For leads submitted to a card holder via the "Share your contact" form, the card holder is the controller and Lynko acts as their processor.

Who we are

Lynko Ltd, United Kingdom. Contact: info@getlynko.com. ICO registration: pending (we will publish our number on registration).

What we collect and why

Cookies and tracking

We use strictly-necessary storage (a session token in localStorage to keep you signed in, and a Stripe cookie when you're paying) and, with your consent, Google Analytics 4 to measure aggregate site usage. Analytics cookies are only set after you click Accept on our cookie banner (Google Consent Mode v2 — everything is denied by default). We do not use advertising or cross-site tracking cookies. Full details on our Cookies page.

Who we share data with (sub-processors)

We use the sub-processors below to run the service. We have written processor agreements with each. International transfers outside the UK rely on the UK IDTA or the EU SCCs + UK Addendum.

Sub-processorPurposeRegionAdded
Lovable Cloud / SupabaseDatabase, authentication, file storageEU / US2026-01-01
Stripe Payments UK LtdPayments, subscriptions, taxUK / EU / US2026-01-01
CloudflareCDN, DDoS protectionGlobal2026-01-01
Lovable transactional email (notify.getlynko.com)Account & order emailsEU / US2026-06-22
Hostinger (Titan) MailInbound & outbound support mailbox (info@getlynko.com)EU2026-06-26
Google Ireland Ltd (Google Analytics 4)Consent-gated site analyticsEU / US2026-07-02
Shipping carriers (Royal Mail, DHL, Evri, DPD, UPS, FedEx, USPS)Card delivery (name + address only)UK / EU2026-01-01

Material changes to this list are announced by email to account holders at least 30 days before they take effect, with a right to object.

Security researchers: see our responsible-disclosure programme.

How long we keep data

Security and breach notification

We use industry-standard safeguards: TLS in transit, encryption at rest by our hosting provider, row-level security on every user-data table, role-based admin access, and an append-only audit log for privileged actions. If we become aware of a personal-data breach affecting you, we will notify the ICO within 72 hours and you without undue delay, as required by Art. 33–34.

Your rights and Subject Access Requests (SARs)

You have the right to: access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. You can delete your account and export your data from the dashboard (Overview → Danger zone).

To make a Subject Access Request or exercise any other right, email info@getlynko.com with the subject line "SAR" and enough information for us to identify you. We will respond within one calendar month (extendable by two further months for complex requests, in which case we will tell you within the first month). SARs are free; we may charge a reasonable fee or refuse manifestly unfounded or excessive requests, as permitted by Art. 12(5). We may ask for proof of identity before releasing personal data.

You can complain to the UK Information Commissioner's Office at ico.org.uk or 0303 123 1113.

If you're outside the UK

Lynko serves card holders and visitors across the EEA. Our EU Article 27 representative is being appointed; their details will be published here. In the meantime, EU residents can contact us at info@getlynko.com.

Age

Lynko is intended for use by people aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, email us and we will remove the account.

Changes

Material changes are announced by email to account holders at least 14 days before they take effect.

Last updated: 3 July 2026 · Last reviewed: 3 July 2026 · Version 2026-07-03-v5