Legal
Privacy Policy
This notice explains what personal data Lynko collects, why, and your rights under the UK GDPR and the Data Protection Act 2018. Lynko Ltd ("Lynko", "we") is the data controller for our website and accounts. For leads submitted to a card holder via the "Share your contact" form, the card holder is the controller and Lynko acts as their processor.
Who we are
Lynko Ltd, United Kingdom. Contact: info@getlynko.com. ICO registration: pending (we will publish our number on registration).
What we collect and why
- Account data (email, name, password hash, profile content) — to provide the service. Lawful basis: contract (Art. 6(1)(b)).
- Billing data (Stripe customer ID, subscription status, invoices) — to take payment and meet tax obligations. Lawful basis: contract + legal obligation (Art. 6(1)(b) and (c)). Card numbers never touch our servers; they are handled by Stripe.
- Card-tap analytics — we count taps and store a coarse device bucket (mobile/desktop) and source (NFC/QR/direct). We do not store IP addresses, browser fingerprints, approximate location, or visitor identifiers. This is aggregate analytics under legitimate interest (Art. 6(1)(f)). You can object at any time by emailing info@getlynko.com.
- Leads (name, email, phone, company, message a visitor submits to a card holder) — to deliver the message to the card holder. Lawful basis: the visitor's explicit consent (Art. 6(1)(a)). We log the consent text + timestamp as proof.
- Support emails — to reply. Lawful basis: legitimate interest.
Cookies and tracking
We use strictly-necessary storage (a session token in localStorage to keep you signed in, and a Stripe cookie when you're paying) and, with your consent, Google Analytics 4 to measure aggregate site usage. Analytics cookies are only set after you click Accept on our cookie banner (Google Consent Mode v2 — everything is denied by default). We do not use advertising or cross-site tracking cookies. Full details on our Cookies page.
Who we share data with (sub-processors)
We use the sub-processors below to run the service. We have written processor agreements with each. International transfers outside the UK rely on the UK IDTA or the EU SCCs + UK Addendum.
| Sub-processor | Purpose | Region | Added |
|---|---|---|---|
| Lovable Cloud / Supabase | Database, authentication, file storage | EU / US | 2026-01-01 |
| Stripe Payments UK Ltd | Payments, subscriptions, tax | UK / EU / US | 2026-01-01 |
| Cloudflare | CDN, DDoS protection | Global | 2026-01-01 |
Lovable transactional email (notify.getlynko.com) | Account & order emails | EU / US | 2026-06-22 |
| Hostinger (Titan) Mail | Inbound & outbound support mailbox (info@getlynko.com) | EU | 2026-06-26 |
| Google Ireland Ltd (Google Analytics 4) | Consent-gated site analytics | EU / US | 2026-07-02 |
| Shipping carriers (Royal Mail, DHL, Evri, DPD, UPS, FedEx, USPS) | Card delivery (name + address only) | UK / EU | 2026-01-01 |
Material changes to this list are announced by email to account holders at least 30 days before they take effect, with a right to object.
Security researchers: see our responsible-disclosure programme.
How long we keep data
- Account + profile content: while your account is active, deleted on request.
- Card-tap analytics: 13 months, then aggregated.
- Leads: until the card holder deletes them, and at most 24 months after the last interaction, after which we auto-purge.
- Custom-card design drafts (uploads + auto-saved artwork): 90 days after the draft is abandoned or the order is fulfilled.
- Invoices and tax records: 6 years (HMRC requirement).
Security and breach notification
We use industry-standard safeguards: TLS in transit, encryption at rest by our hosting provider, row-level security on every user-data table, role-based admin access, and an append-only audit log for privileged actions. If we become aware of a personal-data breach affecting you, we will notify the ICO within 72 hours and you without undue delay, as required by Art. 33–34.
Your rights and Subject Access Requests (SARs)
You have the right to: access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. You can delete your account and export your data from the dashboard (Overview → Danger zone).
To make a Subject Access Request or exercise any other right, email info@getlynko.com with the subject line "SAR" and enough information for us to identify you. We will respond within one calendar month (extendable by two further months for complex requests, in which case we will tell you within the first month). SARs are free; we may charge a reasonable fee or refuse manifestly unfounded or excessive requests, as permitted by Art. 12(5). We may ask for proof of identity before releasing personal data.
You can complain to the UK Information Commissioner's Office at ico.org.uk or 0303 123 1113.
If you're outside the UK
Lynko serves card holders and visitors across the EEA. Our EU Article 27 representative is being appointed; their details will be published here. In the meantime, EU residents can contact us at info@getlynko.com.
Age
Lynko is intended for use by people aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, email us and we will remove the account.
Changes
Material changes are announced by email to account holders at least 14 days before they take effect.
Last updated: 3 July 2026 · Last reviewed: 3 July 2026 · Version 2026-07-03-v5