Security & privacy

Security and privacy, built in.

LinkTrail sits in the path between your ads, installs, and in-app screens. We treat that responsibility seriously — here's how we protect your data and your users'.

Where we stand on compliance

We'd rather tell you exactly what we have than imply more.

UK & EU GDPR

Aligned

We are a UK controller and processor, registered as LinkTrail Ltd in England and Wales. Our Data Processing Agreement applies automatically to every customer, needs no separate signature, and we'll sign a copy on request. It includes our full sub-processor list, our security measures, and SCCs with the UK Addendum for restricted transfers.

CCPA & US state privacy laws

Aligned

We do not sell personal information and do not use it for cross-context behavioural advertising of our own. Consumer rights requests are handled at privacy@linktrail.io.

Independent certification

We do not hold SOC 2, ISO 27001, or any other independent security certification, and no certification audit is currently underway. We also do not currently run scheduled independent penetration testing. When that changes, this page will say so — and it won't say so before.

We publish this plainly because a security page that lists certifications you don't have is worse than one that admits the gap. Annex II of our Data Processing Agreement is our substantive answer, measure by measure, and it marks which items are verified and which are commitments.

How we protect your data

Encryption in transit

All traffic is served over HTTPS with no plain-HTTP fallback; HTTP requests are permanently redirected. HSTS is enabled with a 180-day max-age including subdomains. We are not on the HSTS preload list.

Encryption at rest

The production database is encrypted with AES-256, covering primary and replica instances and all backups.

Least-privilege access

Production infrastructure and database access is limited to a small number of authorised personnel. Multi-factor authentication is enforced at organisation level across our hosting, source control and network providers, so an individual can't turn it off.

API key handling

Customer SDK keys are stored only as SHA-256 hashes. The plaintext key is shown once at creation and is never retrievable afterwards. Individual keys can be revoked at any time.

Isolated environments

Production, staging and development are separate, with separate credentials. Configuration is validated at startup, so the service fails to boot rather than running with a missing secret.

Audit trail

An immutable, append-only log records changes made through the dashboard — who, what, before and after — and is available to you through our audit API endpoint.

Dependency hygiene

Automated dependency scanning runs on our repositories and alerts us to known vulnerabilities in third-party packages. We apply security updates on review.

Privacy by design — and where the trade-offs are

We don't use advertising identifiers. Our SDK never accesses the Apple IDFA, with or without App Tracking Transparency permission, and never reads the Google Advertising ID. Attribution works without them.

We do use device fingerprinting, and we say so. Where deterministic signals aren't available — no Google Play Install Referrer, no deferred click token — attribution falls back to probabilistic matching, comparing IP address, user agent, screen metrics, timezone and locale within a 7-day window. That is device fingerprinting. Under Article 5(3) ePrivacy and PECR regulation 6 it requires end-user consent, and Apple prohibits it irrespective of ATT status.

So: our SDK is consent-gated by default — no device data is collected until your app signals consent — and probabilistic matching can be switched off entirely at workspace level. Section 9 of the DPA sets out the full analysis, including the controls available and their current limits.

We'd rather you make that decision with the facts than find out at App Store review.

We never sell customer or end-user data.

Retention.Raw click and install records are kept for 13 months, then deleted by an automated purge job. Aggregated reports, with no device identifiers, are kept for 3 years. Retention periods are fixed and set out in Annex I of the DPA; they aren't configurable per customer. The analytics history in your plan is a product feature, not the retention period.

Deletion. On termination we delete your data from active production within 30 days. Residual copies persist in encrypted backups until they expire, up to 12 months; those backups are used for disaster recovery only.

Where your data lives

The European Union. Application, database and edge infrastructure all run in EU regions. We do not operate a US region. Several of our providers are US-parented, so their support and engineering staff may be able to access EU-stored data from outside the UK and EEA — where that's a restricted transfer, it's covered by the EU SCCs and the UK Addendum with a transfer risk assessment behind it.

Our current sub-processors are Render (hosting), Cloudflare (CDN, DNS, edge security) and Microsoft Azure Application Insights (error monitoring), all processing in the EU. Sentry is planned and not yet receiving data. The full list, with transfer notes, is Annex III of the DPA — published, not available-on-request.

Enterprise controls

  • Role-based access control and team seat management.
  • Immutable audit logs, available through the audit API.
  • Uptime commitment on the Scale plan — agreed in your order form, which sets out how availability is measured, what's excluded, and the remedy. No SLA or service credit forms part of our standard Terms of Service.
  • SAML / SSO is built and not yet released. We'll list it here when it ships.

Report a vulnerability

Found something? Email security@linktrail.io. We investigate every report and won't pursue good-faith research. Security incidents are also the contractual notification route under section 12 of the DPA, where we commit to telling affected customers within 48 hours.