Back to home

Privacy Policy

Last updated: 26 September 2026

This policy describes what data we process, for what purpose and on what legal basis. It distinguishes two roles that differ materially in law — please read section 2 first.

The German version is the operative one; this English text is a convenience translation.

1. Controller

Nordility UG (haftungsbeschränkt), Volksdorfer Damm 56a, 22359 Hamburg, Germany

Commercial register: Hamburg Local Court, HRB 187685 · VAT DE369362596

Email: info@nordility.eu

2. Two roles — please read first

This policy covers two distinct situations.

As controller we process data about you as a customer — your account, sign-ins and billing. We decide the purposes and means, and this policy applies directly.

As processor we process data about people who click our customers' links. The customer decides: they create the link, choose the campaign parameters and determine the retention period. We execute. For that data the customer is the controller, under a data processing agreement (section 9).

If you clicked a link and want to know what is processed about you, please contact the operator of that link. On request we will identify the controller.

3. Data we process as controller

Login history is visible in your security settings and can be deleted there at any time.

DataPurposeLegal basisRetention
Email, name, hashed passwordAccount and authenticationArt. 6(1)(b) GDPRUntil account deletion
Login history: IP address, location, device, browser, OSDetecting unauthorised accessArt. 6(1)(f) GDPR90 days, then deleted automatically
Billing data, planPerformance of contractArt. 6(1)(b) GDPRUntil deletion, then statutory retention
Support requestsHandling your requestArt. 6(1)(b) GDPRUntil account deletion

4. Click data — processed on instruction

When someone opens a link created with LinkGravity, we process on our customer's behalf:

  • A hash of the IP address. The address is hashed on arrival using a secret key that rotates daily. The address itself is never stored. Because we hold the key, this is pseudonymised rather than anonymous data.
  • Country and city, derived from the IP before it is discarded.
  • Browser-supplied technical data: user agent, platform, browser, OS, device type, referrer.
  • Campaign parameters (UTM) chosen by the customer.
  • A device fingerprint (see section 5).

Purpose: routing the click to the right destination, and attribution for the customer. Retention follows the customer's plan. Note: the plan-based periods currently limit the visibility of the data but are not yet technically enforced as deletion. This policy will be updated when deletion is active.

5. Device fingerprint for deep links

If someone opens a link to content in an app they do not have installed, an interstitial page captures device characteristics so they can be taken to the right place after installation.

Captured: platform, user agent, timezone, locale, screen size, plus a salted hash of the IP address and subnet.

Not captured: the IP address itself, advertising identifiers, contact details.

Retention: iOS 24 hours · Android up to 90 days (matching the Google Play Install Referrer window). A background job deletes expired records every fifteen minutes.

This data serves that single match only. It is not combined into profiles, not used for advertising, and not shared.

6. Cookies and analytics

Cookies: exactly one — token — for authentication. It is httpOnly and strictly necessary; sign-in is impossible without it.

Analytics: Umami, self-hosted on our own infrastructure in Germany. Umami works without cookies and without cross-site recognition. No data is sent to third parties.

We do not use: Google Analytics, advertising pixels, tag managers, third-party embedded fonts or comparable services.

7. Hosting

LinkGravity runs on Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in German datacentres. All application data is stored and processed there.

8. Recipients and processors

Paddle acts as Merchant of Record. When you buy a paid plan the purchase contract is therefore with Paddle, not with us. Paddle issues the invoice and remits the tax. For payment and transaction data Paddle is an independent controller; its own privacy policy applies.

Paddle passes your purchase data to us on the basis of legitimate interests. We use it solely to provide the service, process the order, prevent fraud and provide support — not for marketing.

Transfers to the United Kingdom rely on the European Commission's adequacy decision.

RecipientPurposeLocation
Hetzner Online GmbHHostingGermany
IONOS SETransactional emailGermany
Paddle.com Market Ltd.Payment processing, invoicingUnited Kingdom

9. Data processing agreement

Customers on paid plans enter into a data processing agreement under Art. 28 GDPR, covering instructions, confidentiality, technical and organisational measures, sub-processors and deletion.

The agreement is available at linkgravity.io/legal/dpa.

10. Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7(3)).

You can delete your account at any time, which removes your links, click data and configuration.

You may also lodge a complaint with a supervisory authority. Ours is the Hamburg Commissioner for Data Protection and Freedom of Information.

11. Security

Transport exclusively over TLS. Passwords hashed with bcrypt. Production access limited to the management. IP addresses in click data are hashed before storage.

12. Changes

We update this policy when processing changes. Material changes are communicated to registered users by email.

13. Contact

Nordility UG (haftungsbeschränkt), Volksdorfer Damm 56a, 22359 Hamburg, Germany

Email: info@nordility.eu