uselinking
docssign instart free

Privacy policy

uselinking is a deferred deep linking service operated by Smooth Path Digital S.R.L, the controller for the account data described below. This page sets out exactly what we collect, why each field exists, and when it is deleted. Last updated 24 August 2026.

Two kinds of people, two different roles

Our customers are app developers who create an account here. For their account data we are the controller — we decide what is collected and why.

End users are people who tap one of our customers’ links. For that data we act as a processor on the customer’s behalf: they decide to use deferred deep linking, and they are responsible for disclosing it in their own privacy policy and for having a lawful basis to do so. We process it only to deliver the matching service and never for our own purposes.

Account data

When you create an account we store:

  • Your email address, and whether and when it was verified.
  • A password hash (argon2id). We never store the password itself and cannot recover it.
  • Your organisation’s name, and the display name of team members.
  • Session identifiers, and short-lived single-use tokens for email verification and password reset.
  • API keys, stored as a hash plus a short non-secret prefix so the dashboard can show you which key is which.
  • The configuration you enter for your apps: bundle identifiers, package names, certificate fingerprints, fallback URLs and any branding you upload.
  • Billing identifiers from Stripe — a customer id, a subscription id and your plan. We never see or store card numbers; payment details go directly to Stripe.

Link and install data

Deferred deep linking works by recognising that the person who just installed an app is the same person who tapped a link a few minutes earlier. There is no identifier shared across that gap, so the match is probabilistic and based on a small number of coarse signals.

When someone taps a link, we record:

  • The IP address of the request. IPv6 addresses are also stored truncated to the /64 network prefix, because iOS privacy extensions rotate the second half of the address between requests.
  • Major OS version, device class (iPhone, iPad or Android) and language.
  • Which link was tapped, and when.

When the app then starts for the first time, our SDK sends:

  • Platform, OS version, device model, locale and timezone.
  • Screen width, height and scale.
  • The SDK version.
  • On Android only, the Google Play install referrer, which is the platform’s own supported mechanism for exactly this purpose and gives an exact rather than probabilistic match.

We also keep aggregate counters — clicks, store redirects, match attempts and match outcomes — so customers can see whether their links are working. These record the app and link involved, not the person.

What we deliberately do not collect

  • No advertising identifiers. We do not read IDFA, the Android Advertising ID, or any equivalent, and the SDK does not request tracking permission.
  • No cookies on link clicks. Tapping a link sets nothing in your browser. Cookies exist only in the customer dashboard, where a single session cookie keeps you signed in.
  • No cross-app or cross-customer tracking. Click data is scoped to the app it belongs to. We do not build profiles that follow a person between different customers’ apps.
  • No sale or sharing of data. We do not sell personal data, share it with advertising networks, or use it to train models.
  • No precise location. We never request GPS. An IP address implies only a coarse region.

How long we keep it

  • Pending clicks: deleted 48 hours after they expire. The window is measured in minutes for matching; the extra 48 hours only exists because Android install referrer lookups can arrive long after the iOS window closes.
  • Verification and password-reset tokens: deleted as soon as they expire.
  • Unaccepted team invitations: deleted 30 days after they expire.
  • Billing webhook records: 90 days.
  • Aggregate event counters: kept for as long as the account exists, because they are what the analytics view is built from.
  • Account data: kept while the account is open, and deleted on request.

Who else processes it

  • Amazon Web Services — all infrastructure and data storage, hosted in the eu-central-1 region in Frankfurt, Germany. Transactional email is sent via Amazon SES.
  • Stripe — subscription billing and payment processing.
  • Sentry — application error reporting, when enabled.

Data is stored in the European Union. The database is not reachable from the public internet, traffic is encrypted in transit, and passwords are hashed with argon2id.

Your rights

If you are in the EU or UK you have the right to access, correct, export or delete your personal data, to object to processing, and to complain to your data protection authority. Write to swampiapps@gmail.com and we will respond within 30 days.

If you are an end user who tapped a link and want that data removed, contact the app developer whose link you followed — they control it, and we will act on their instruction. If you would rather come to us directly, we will pass the request on.

Deleting your account deletes your account data and stops all email. Some records may persist briefly in encrypted backups before ageing out.

Children

uselinking is a developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, write to swampiapps@gmail.com and we will delete it.

Changes

If we change what we collect or how long we keep it, we will update this page and move the date at the top. Material changes affecting existing customers will also be sent by email.

Questions about any of this: swampiapps@gmail.com.

uselinking — deferred deep linking, one job
docsprivacytermssign instart free