Legal

Privacy Policy

Effective date: 21 June 2026

1. Who we are

LinkRithm ("we", "us", "our") is a business operating system for service-based companies. We are the data controller for the personal data you provide when using our platform at linkrithm.com.

You can reach us at hello@linkrithm.com for any privacy-related questions.

2. What data we collect

We collect the following categories of personal data:

  • Account data — your name, email address, and profile photo when you create an account, including via Google OAuth.
  • Organisation data — the name and details of the workspace you create or are invited to.
  • Usage data — pages visited, features used, actions taken, and timestamps, collected automatically to improve the product.
  • Content you create — clients, projects, invoices, time entries, documents, and any other data you enter into the platform.
  • Billing data — handled by our payment processor, Stripe. Stripe collects the billing details and payment information needed to process your subscription. Prices are exclusive of any applicable taxes, which may be added at checkout where required by law. We do not store or process your payment card details.
  • Communications — emails you send us, and messages we send you about your account or the service.
  • Location data (optional) — if your workspace enables geolocation clock-in, we store approximate GPS coordinates (latitude, longitude, and accuracy) when you clock in to a project. Your browser asks for permission; clock-in is never blocked if location is unavailable. Only workspace admins can view location details on time records.
  • AI usage logs — when you use AI insights, we record your organisation ID, user ID, and timestamp for rate limiting and abuse prevention. We do not store the full text of your questions in these logs.
  • Audit logs — for workspaces where audit logging is enabled, we record who performed sensitive actions (e.g. sign-in, invoice changes, settings updates), what changed, and when. Audit entries may include actor name, email, action type, and related metadata.

3. How we use your data

  • To provide, operate, and maintain the LinkRithm platform.
  • To authenticate your identity and manage your account.
  • To process payments and manage subscriptions via Stripe, our payment processor.
  • To send transactional emails (password resets, invitations, notifications).
  • To analyse usage patterns and improve the product.
  • To respond to your support requests and communications.
  • To meet our legal and regulatory obligations.
  • To power optional AI insights when you ask questions about your workspace (see sub-processors below).
  • To enforce AI usage limits and protect the service from abuse.
  • To maintain audit trails for security, accountability, and compliance where audit logging is enabled for your workspace.
  • To verify on-site or field clock-ins when your organisation has enabled geolocation capture.

4. Legal basis for processing (GDPR)

If you are located in the European Economic Area or United Kingdom, we process your personal data under the following legal bases:

  • Contract — processing necessary to provide the service you have signed up for.
  • Legitimate interests — improving the product, preventing fraud, and ensuring security.
  • Legal obligation — compliance with applicable laws.
  • Consent — where we have asked for and you have given explicit consent (e.g. marketing emails).

5. Data sharing

We do not sell your personal data. We share it only with the following sub-processors where necessary to deliver the service:

  • Supabase — database hosting and authentication.
  • Vercel — application hosting and edge delivery.
  • Stripe — our payment processor. Stripe processes payments and manages subscription billing. Payment card data is collected and stored by Stripe, not by us.
  • Resend — transactional email delivery.
  • Anthropic (Claude API)— optional AI-powered features. When you use AI insights, we send your question, pre-computed workspace summaries, and bounded JSON data (e.g. invoice totals, project status) to Anthropic's API for tone refinement. We do not send full database exports or payment card data.

Each sub-processor is contractually bound to protect your data and use it only for the purpose of providing the service.

6. Data retention

We retain your personal data for as long as your account is active. If you delete your account, we will delete or anonymise your data within 30 days, except where we are required by law to retain it longer (e.g. financial records).

  • Time and location data is kept with your time entries for as long as those records exist in your workspace.
  • AI usage logs are kept while your account is active to enforce monthly query limits.
  • Audit logs are retained for 18 months, then automatically deleted. Workspace owners and admins can export audit data before it is pruned.

7. Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — request deletion of your personal data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Restriction — ask us to limit how we use your data.

To exercise any of these rights, email hello@linkrithm.com. We will respond within 30 days.

Exporting your data

Depending on your role, you can export data directly from the platform:

  • Payroll hours — CSV export from Time → Payroll.
  • Audit log — CSV export from Settings → Audit (workspace owners and admins).
  • AI answers — CSV or Excel export from the AI insights panel when tabular results are shown.
  • Invoices and payslips — PDF download from invoice detail pages and talent payslip views.

For a broader data export (e.g. full workspace portability or erasure requests), email hello@linkrithm.com and we will help you within 30 days.

8. Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but we take reasonable precautions to protect your data.

9. International transfers

Your data may be processed in countries outside your own, including the United States, where our infrastructure providers operate. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to ensure adequate protection for transfers outside the EEA or UK.

10. Your California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following rights regarding your personal information:

  • Right to know — what personal information we collect, the sources, the purposes, and the categories of third parties we disclose it to.
  • Right to access — request a copy of the personal information we hold about you.
  • Right to correct — request that we fix inaccurate personal information.
  • Right to delete — request deletion of your personal information, subject to legal exceptions (e.g. records we must keep for tax or accounting).
  • Right to opt out— opt out of the "sale" or "sharing" of personal information.
  • Right to limit — limit our use of sensitive personal information.
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. To exercise any of these rights, email hello@linkrithm.com or use the in-app data tools. We will verify your request and respond within the time required by law (generally 45 days). You may use an authorised agent to submit a request on your behalf.

11. Cookies and consent

We use strictly necessary cookies to run the platform and keep you signed in securely. Before setting any non-essential cookies (for example, optional analytics), we ask for your consent via the cookie banner shown on your first visit. You can choose to accept all cookies or essential cookies only, and you can change your choice at any time by clearing the cookie-consent preference stored in your browser.

For full details of the cookies we use, see our Cookie Policy.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the platform. Continued use of LinkRithm after the effective date of any update constitutes acceptance of the revised policy.

Questions? Email us at hello@linkrithm.com