How PassLink collects, uses and protects your personal data.
The data controller for personal data collected via passlink.me is:
By using the PassLink service, you acknowledge and accept the practices described in this Privacy Policy.
PassLink collects only the data strictly necessary to operate the service:
| Category | Data | Source |
|---|---|---|
| Account | Email address | Provided by the user at login |
| Public Profile | Name, title, bio, photo, links, colors, layout | Provided by the user in the dashboard |
| Billing | Stripe customer ID, subscription status, current plan | Generated automatically via Stripe (no card data stored) |
| Analytics | IP address (anonymized), country, city, browser, OS, device, links clicked | Collected automatically on profile page visits |
| Technical | Auth token (cookie), login logs | Generated automatically on sign-in |
No card data is ever stored on our servers. All payments are handled exclusively by Stripe, certified PCI-DSS Level 1.
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account authentication and management | Contract performance (Art. 6.1.b) |
| Delivering and displaying the public profile | Contract performance (Art. 6.1.b) |
| Subscription management and billing | Contract performance + Legal obligation (Art. 6.1.b/c) |
| Profile visit analytics | Legitimate interest (Art. 6.1.f) |
| Sending transactional emails (login codes, receipts) | Contract performance (Art. 6.1.b) |
| Fraud prevention and security | Legitimate interest (Art. 6.1.f) |
PassLink does not sell or rent your personal data to any third party. Your data may be shared only with the following processors, strictly for the purpose of delivering the service:
| Partner | Role | Location |
|---|---|---|
| Stripe Inc. | Payment processing | USA (Standard Contractual Clauses) |
| Hosting provider (see Legal Notice) | Server infrastructure & storage | European Union |
| Email provider | Transactional email delivery | European Union |
Beyond these partners, your data is not shared with any third party, unless required by law or court order.
PassLink uses a minimal number of cookies, strictly necessary for the service to function:
| Cookie | Purpose | Duration |
|---|---|---|
session (PHP) | Maintains the authenticated session | Session (closed when browser is closed) |
pl_auth | Persistent cookie for automatic re-login | 30 days |
We use no advertising cookies and no third-party tracking tools (Google Analytics, Facebook Pixel, etc.). Our analytics are self-hosted on our own servers.
Under the General Data Protection Regulation (GDPR — EU 2016/679), you have the following rights regarding your personal data:
Obtain a copy of all the data we hold about you.
Correct inaccurate or incomplete data directly from your dashboard.
Request deletion of your account and personal data.
Object to certain processing activities based on our legitimate interest.
Request that processing of your data be restricted in certain circumstances.
Receive your data in a structured, machine-readable format.
To exercise any of these rights, contact us at: contact@passlink.me. We will respond within a maximum of one month.
PassLink implements appropriate technical and organizational measures to protect your data against loss, unauthorized access, disclosure or alteration:
For any questions about your personal data or this policy, contact us:
If you believe, after contacting us, that your rights are not being respected, you have the right to lodge a complaint with your local data protection authority. In France, this is the CNIL: www.cnil.fr. In the EU, you may also contact your national supervisory authority.