Privacy Policy
Last updated: 2 June 2026
1. Who we are
LinQR Digital Link Solutions provides QR code management, review collection, and payment link services for UK businesses. We are the data controller for personal data collected through this website.
Contact us at: privacy@linqr.io
2. What data we collect
We collect the following categories of personal data:
- Enquiry data: When you submit a free business enquiry, we collect your name, business name, email address, phone number (if provided), and details about your requirements.
- Review data: When customers use a LinQR review page, we collect only the review text they choose to submit. No account creation is required.
- Usage data: We may collect anonymised data about how our platform is used, including page views and QR code scan counts. This data does not identify individuals.
- Business configuration: Business clients may store staff names and review platform URLs in our system. This data is used solely to provide the LinQR service.
3. How we use your data
We use your personal data for the following purposes:
- To respond to your business enquiry and provide our services
- To send service-related communications (e.g. your enquiry confirmation)
- To improve our platform and user experience
- To comply with legal obligations
We will not use your data for unsolicited marketing without your explicit consent.
4. Legal basis for processing
We process your personal data under the following lawful bases (UK GDPR Art. 6):
- Contract: To fulfil our obligations as a service provider to business clients.
- Legitimate interests: To respond to enquiries and improve our services.
- Consent: For any marketing communications (you may withdraw consent at any time).
5. Data sharing
We share personal data only with the following third parties, solely to operate our services:
- Resend (resend.com): Our transactional email provider, used to send enquiry notifications. Resend processes email data on our behalf.
- Neon (neon.tech): Our database provider, used to store enquiry and business data securely in the EU/US. Neon is SOC 2 Type 2 certified.
- Vercel: Our hosting provider. Data is processed in accordance with their privacy terms.
We do not sell, rent, or trade personal data with third parties.
6. Data retention
We retain personal data only for as long as necessary:
- Enquiry data: Retained for 2 years from submission, or until you request deletion.
- Business client data: Retained for the duration of the service agreement plus 1 year.
- Anonymised analytics: Retained indefinitely (no personal data).
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict our processing of your data
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is consent-based
To exercise any of these rights, email us at privacy@linqr.io. We will respond within 30 days.
You also have the right to lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk.
8. Cookies
Our website uses only essential cookies required for the site to function (e.g. localStorage for business configuration). We do not currently use tracking or advertising cookies.
If we introduce analytics or marketing cookies in future, we will update this policy and request your consent.
9. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all data in transit
- Encrypted database storage via Neon
- Access controls limiting who can view personal data
No method of transmission over the internet is 100% secure. We will notify you of any data breach that affects your rights and freedoms within 72 hours as required by law.
10. International transfers
Our database provider (Neon) may process data in the United States. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required under UK GDPR.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify business clients of material changes by email. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact us
If you have any questions about this Privacy Policy or how we handle your data: