Privacy Policy

Last updated: 19 September 2026.

Who we are

LinkBuilder.com is operated by Codiny s.r.o., company ID (IČO) 22290621, Zenklova 32/28, Libeň, 180 00 Prague 8, Czech Republic. When this policy says “we”, “us” or “our”, it means Codiny s.r.o. We are the controller of the personal data described here, which means we decide why and how it is processed.

For anything about your personal data — questions, requests, complaints — write to [email protected]. For everything else, [email protected].

This policy covers linkbuilder.com and the services we provide through it. Other companies we link to run their own sites under their own policies.

What we collect

What you give us. When you create an account: your name, email address and password. When you contact us through the form, live chat or email: your name, email address, phone number if you enter one, and whatever you write to us. When you buy something: billing details, the plan you chose, and the records of what you paid.

What we collect as you use the site. Your IP address, browser and device type, the pages you open, what you clicked, where you arrived from, and the language and country settings your browser reports. Our servers keep access logs containing the same information.

What we collect with your consent. If you allow analytics or marketing cookies, we and the partners named below collect identifiers stored on your device and records of what you did on the site. Without that consent these are not collected — see “Cookies and similar technologies”.

How you use the application. When you are signed in to the LinkBuilder.com application, we record which features you open and which actions you take, so that we can see what works and what gets in the way. This is product analytics about the use of a service you asked for, and it is kept separate from the advertising described below.

We do not ask for and do not want special categories of data — health, beliefs, political views, biometrics. Please do not send them to us in messages.

Why we use it, and on what legal basis

To provide the service you asked for — running your account, giving access to the catalogue and tools, taking orders, processing payments, and answering you when you write. Legal basis: performance of a contract with you, or steps taken at your request before entering one.

To keep the service working and safe — server logs, fraud and abuse prevention, rate limiting, backups, debugging. Legal basis: our legitimate interest in a service that stays available and is not abused.

To send service messages — changes to the service, security notices, billing and account matters. These are part of the service and are not marketing; you cannot opt out of them while you hold an account. Legal basis: performance of a contract.

To send marketing emails — product news, offers, blog updates. Legal basis: your consent, or our legitimate interest where you are an existing customer and we are writing about services similar to those you already bought. Every one of these emails carries an unsubscribe link, and you can object at any time with no reason given.

To measure and improve the site — which pages work, where people give up, which campaigns bring visitors. Legal basis: your consent, given through the cookie banner.

To advertise — showing our ads on other platforms and measuring whether they worked. Legal basis: your consent, given through the cookie banner.

To meet legal obligations — accounting and tax records, answering lawful requests from authorities. Legal basis: compliance with a legal obligation.

Cookies and similar technologies

A cookie is a small file a site stores on your device. We also use comparable technologies such as local storage and tracking pixels; everything below applies to those as well.

Strictly necessary. These make the site work and cannot be switched off. They keep your session (linkbuilder_session), protect forms against cross-site request forgery (XSRF-TOKEN), remember the cookie choice you made (cookies_accept, kept for 7 days), and run our live chat (cw_conversation). Our live chat runs on our own servers, so what you type in it does not go to a third-party chat provider.

Preferences. Remember choices such as language, so you do not set them again on every visit.

Analytics. Google Analytics 4, which tells us how the site is used in aggregate. Typical cookies: _ga, _ga_<id>.

Marketing. Google Ads and the Meta pixel, used to measure our advertising and to show you our ads on other platforms. Typical cookies and identifiers: _gcl_au, _fbp, _fbc.

Nothing in the last three groups is set until you agree to it. If you are in the European Economic Area, the United Kingdom or Switzerland, analytics and marketing start switched off and stay off unless you turn them on. You can accept everything, accept only what you pick, or reject everything — refusing is one click, exactly like accepting.

You can change your mind at any time through the Cookie settings link at the bottom of any page, and withdrawing is as easy as giving. Withdrawal does not undo what was lawfully done before it. You can also delete cookies in your browser, though that will also remove the record of your choice and we will ask again.

If your browser sends a Global Privacy Control signal, we treat it as an instruction to stop sharing your data for advertising, and advertising cookies stay off regardless of what the banner says.

Who we share it with

We do not sell your personal data for money. We do share it with the following, each for the purpose named and no other.

Google Ireland Limited / Google LLC — Google Analytics, Google Ads, Google Tag Manager and reCAPTCHA, which protects our forms from automated abuse. Only after you consent, except reCAPTCHA, which we rely on to keep the forms usable at all.

Meta Platforms Ireland Limited — the Meta pixel, for advertising measurement and audiences. Only after you consent to marketing cookies.

Amplitude — product analytics inside the LinkBuilder.com application, telling us which features are used and where people get stuck. This runs in the application, not on this website.

Sinch (Mailgun) and Intuit (Mailchimp) — sending transactional and marketing email on our behalf.

Cloudflare — serving and protecting the site, which means it processes the traffic between you and us.

Stripe, PayPal and CoinGate — taking payments. Your card or wallet details go to them, not to us; we receive only what we need to recognise the payment.

We also share data with our hosting and infrastructure providers, and with professional advisers, auditors or authorities where the law requires it. Anyone processing data on our behalf is bound by a contract that lets them use it only on our instructions.

Sharing your data with Google and Meta for advertising counts as “sharing for cross-context behavioural advertising” under California law, even though we receive no money for it. See “If you are in the United States”.

Where your data is kept, and when it leaves Europe

Our servers are in Austria, inside the European Union, and that is where your account data, your orders and your messages to us are stored.

Some of the companies above are in the United States or process data there. Where that happens we rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework if the recipient is certified under it, and otherwise on the Commission’s Standard Contractual Clauses together with additional measures where they are needed. Write to [email protected] and we will tell you which one applies to a particular transfer and send you a copy of the safeguards.

How long we keep it

Account data — while your account exists, and for a short period afterwards so the account can be restored if you deleted it by mistake.

Orders, invoices and payment records — for as long as accounting and tax law requires us to, which in the Czech Republic is measured in years and not in our discretion.

Messages you send us — while we deal with your request and for as long afterwards as we may need them if the matter comes back.

Server and security logs — a short period, long enough to investigate an incident.

Marketing consent and unsubscribes — the record of your choice is kept for as long as we need to prove we respected it.

Your cookie choice — 7 days, after which we ask again.

When we no longer need something for the purpose it was collected for, we delete it or anonymise it so it can no longer be linked to you.

Your rights

If the GDPR applies to you, you have the right to:

  • Access — get confirmation of whether we process your data and a copy of it. The first copy is free.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where one of the grounds in the GDPR applies.
  • Restriction — have processing paused while a dispute about accuracy or grounds is resolved.
  • Portability — receive the data you gave us in a machine-readable format, or have it sent to another provider.
  • Object — object to processing based on our legitimate interests. Where you object to direct marketing, we stop. There is no balancing test and you do not have to give a reason.
  • Withdraw consent — at any time, as easily as you gave it, without affecting what was done before.
  • Complain — to a supervisory authority, in particular in the country where you live or work. Ours is the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, uoou.gov.cz). We would rather you came to us first, but that is your choice, not a condition.

Write to [email protected]. We answer within one month, and tell you if we need longer, which the GDPR allows by up to two further months for complicated requests. We may ask you to confirm who you are before we hand over data about you.

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.

If you are in the United States

Depending on your state, you may have the right to know what personal information we collect and why, to get a copy of it, to have it corrected, to have it deleted, to opt out of its sale or sharing for cross-context behavioural advertising, and to limit the use of sensitive personal information. We do not use or disclose sensitive personal information for purposes that require a limitation right.

We do not sell personal information for money. We do share it with Google and Meta for advertising as described above, and California treats that as sharing.

To opt out, use the Your Privacy Choices link at the bottom of any page, or send an authorised agent to [email protected]. We also honour the Global Privacy Control signal automatically, so if your browser sends it you do not need to do anything else.

We will not deny you service, charge you a different price or give you a worse experience because you exercised any of these rights.

Children

This service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, write to [email protected] and we will delete it.

How we protect it

Our infrastructure is hosted in the European Union. We use encryption in transit, restrict access to those who need it for their work, and keep our systems patched. No service can promise perfect security, and we will not pretend otherwise; if a breach happens that is likely to put your rights at risk, we will tell you and the supervisory authority as the law requires.

Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we use your data, we will tell you before it takes effect, by email or a notice on the site, so that you can react.