Tolinks · Legal
Privacy Policy
Last updated: 11 August 2026
How Tolinks collects, uses, stores, and protects your personal data — and how you can exercise your rights under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
1. Overview
This Privacy Policy explains how Tolinks (“we”, “us”, “our”, operating at tolinks.in) collects, uses, discloses, stores, and protects personal data when you use our Platform. We are committed to protecting your privacy and handling your personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the DPDP Rules, 2025 (“DPDP Rules”), the Information Technology Act, 2000 (“IT Act”), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and other applicable Indian and international laws.
This Policy applies to all users of the Platform, wherever they are located, and to the visitors of pages created on the Platform. By creating an account, signing in, or continuing to use the Platform, you consent to the collection, use, and processing of your personal data as described in this Policy. If you do not agree with any part of this Policy, please do not use the Platform.
This Policy is an integral part of our Terms of Service and should be read together with our Cookie Policy, Payment & Billing Policy, Acceptable Use Policy, and Grievance Redressal Policy.
Section 5 of the DPDP Act and Rule 3 of the DPDP Rules require a Data Fiduciary to provide a clear, itemised, plain-language notice of what personal data is processed, for what purpose, and how the Data Principal may exercise their rights. The sections below constitute that notice. A summary in plain language is provided in Section 3, and the full itemised list is provided in Section 4.
2. Roles and Definitions
“Personal data” means any data about an individual who is identifiable by or in relation to such data, as defined in Section 2(t) of the DPDP Act. “Data Fiduciary” means any person who alone or in conjunction with others determines the purpose and means of processing personal data — under the DPDP Act, we act as a Data Fiduciary in respect of your account data. You act as a Data Fiduciary in respect of the personal data you collect through your page (for example, via newsletter capture, lead forms, or visitor analytics). “Data Principal” means the individual to whom the personal data relates — that is, you, and also the visitors of your page. “Processing” includes any operation performed on personal data, including collection, recording, storage, use, disclosure, and deletion.
As a Data Principal, you have rights under Chapter III of the DPDP Act, and the obligations of a Data Principal (including the duty not to file false or frivolous complaints) also apply to you. Where you collect personal data from your own visitors through your page, you must satisfy your own obligations as a Data Fiduciary — this Policy explains what data processing the Platform performs on your behalf and what is your responsibility.
3. Plain-Language Summary
Here is the short version. We collect only what we need to run Tolinks: your account details, the content you publish, and basic usage and technical information. We use it to provide the service, keep it secure, send you important emails, and improve the product. We do not sell your personal data, and we do not run behavioural advertising. Your page is public by design — anything you publish on it, including links and buttons, is visible to anyone with the link. Payment details are processed by our payment gateway, Razorpay; we do not see or store your full card number. You can access, correct, or delete most of your data yourself from the dashboard, and you can ask us for anything else at any time.
This summary is not a replacement for the detailed notice below. If anything in this summary and the detailed notice conflict, the detailed notice governs.
| What we collect | Why we process it | How you can exercise rights |
| Account identity (name, email, password hash, handle) | To create and secure your account and page | Settings → account data, or email us |
| Profile content (links, bio, avatar, theme) | To publish your page | Edit or delete from the dashboard |
| Visitor analytics on your page (views, clicks, pages) | To show you page statistics | Stored per page; no personal identifiers |
| Technical data (IP, browser, device, logs) | Security, abuse prevention, diagnostics | De-identified where possible; retained per schedule |
| Payment records (amount, plan, gateway reference) | Billing, invoices, refunds, compliance | Dashboard → billing |
| Correspondence (support emails, contact forms) | To respond to you | Deleted after resolution unless required by law |
4. Information We Collect
We collect personal data only for lawful purposes, and only as required for those purposes, in line with the data minimisation principle in Section 4(2) of the DPDP Act. The categories below are itemised as required by Rule 3 of the DPDP Rules.
4.1 Account information
- Full name or display name, email address, and password (stored only as a salted, hashed value — never in plain text).
- Your chosen username or handle, profile bio, avatar image, theme selection, and any other profile fields you fill in.
- Authentication information for third-party sign-in (Google and GitHub): we receive the name, email, and identifier provided by that provider when you choose to sign in with it. We never receive your third-party password.
- Referral information: if you sign up through a referral link, we store a cookie indicating which page referred you, so we can credit the referring page with a free-grace grant.
4.2 Content you publish
- Every link, button, text block, QR code, embedded video, newsletter form, lead form, and scheduling setting you create on your page.
- Images you upload, including your avatar. These are stored with your page and are public once published.
- Visitor data captured through your page: email addresses collected by your newsletter forms and submissions to your lead forms. We process these on your behalf and you are the Data Fiduciary for them.
4.3 Analytics data
When someone visits your public page, we record aggregate events: a view event, and click events per link. These events are associated with your page, not with the identity of the visitor. We do not fingerprint visitors, and we do not use third-party advertising trackers on public pages. Where available, we also store daily-rolled aggregates so your dashboard statistics load quickly.
4.4 Device and browser information
Like most web services, our servers automatically log technical information when pages are requested: IP address, browser type and version, operating system, device type, referring URL, requested path, and timestamps. We use this information for security (rate limiting, abuse detection), diagnostics, and understanding aggregate traffic. These logs are retained for a limited period and routinely deleted; see Section 9.
4.5 Cookies and local storage
We use essential cookies for authentication and preferences, and analytics cookies for measuring how the site itself is used (not for advertising). Details, including duration and how to manage them, are in our Cookie Policy.
4.6 Payment-related information
When you purchase a subscription, payment processing is performed by Razorpay, our payment gateway. We receive from Razorpay: the payment identifier, order identifier, amount, currency, plan purchased, and payment status. We do not receive or store full card numbers, card expiry, CVV, or bank account details — those are handled entirely by Razorpay as a PCI-DSS-compliant processor. Your transaction data is also covered by Razorpay's own privacy practices.
5. How We Use Your Information
- To provide and operate the Platform: create your page, publish your links, render analytics, send lead notifications, and operate billing and subscriptions.
- To communicate with you: verification emails, password reset emails, welcome emails, receipts, renewal notices, payment-failure alerts, onboarding nudges, and occasional product or policy updates. You can stop non-essential emails from the dashboard; transactional emails (receipts, security, billing) are always sent when they apply to you.
- To secure the Platform: detect and prevent abuse, fraud, spam, phishing, denial-of-service attacks, and violations of the Acceptable Use Policy.
- To improve the Platform: understand aggregate usage patterns, fix errors, and measure feature performance — using aggregated or de-identified data wherever possible.
- To comply with law: respond to lawful requests, enforce our Terms, and meet legal, tax, and regulatory obligations.
6. Legal Basis and Consent
We process personal data on the basis of consent (Section 6 of the DPDP Act) and, where applicable, the legitimate uses set out in Section 7 of the DPDP Act — including enforcing legal claims, providing government services where applicable, and complying with court orders or legal obligations.
Consent is sought in a free, specific, informed, unconditional, and unambiguous manner, with a clear affirmative action — for example, submitting the sign-up form after reading this Policy. Consent may be withdrawn at any time, and withdrawing consent is designed to be as easy as giving it: most changes can be made from your dashboard, or by writing to us at privacy@tolinks.in. Consent withdrawal does not affect the lawfulness of processing that already occurred before withdrawal, and may cause features that depend on that data (for example, receiving weekly reports) to stop working.
Where you, as a page owner, collect personal data of your visitors through newsletter or lead forms, you are responsible for obtaining their consent in a manner that complies with the DPDP Act and the DPDP Rules, including providing them with your own notice and honouring their rights.
7. Sharing and Disclosure
We do not sell, rent, or trade your personal data. We share it only in the following circumstances:
- Service providers: Neon (PostgreSQL database hosting), Cloudflare R2 (image and file object storage) and Cloudflare CDN (content delivery and DDoS protection), Vercel (hosting of the application), Brevo (transactional email delivery), and Razorpay (payment processing). Each provider processes personal data only for the purposes we specify and under terms that require them to protect it. When permitted, data is encrypted in transit and at rest.
- With the public, by your design: content you publish on a public page is public. Anyone with the link can see it, including search engines and social platforms that render previews.
- Legal requirements: if required by law, regulation, court order, or government authority, or to protect our rights, property, or safety and those of our users or the public, we may disclose personal data. Where permissible and operationally possible, we will notify you before complying with a request directed at your data.
- Business transfers: in the event of a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy continuing to apply and to the DPDP Act's notice obligations.
- With your consent or at your direction: for example, when you initiate an account transfer to another person or contact us with a specific request.
8. Data Retention
We keep personal data only as long as necessary for the purposes for which it was collected, as required by Section 8(5) of the DPDP Act. The schedule below summarises typical retention periods; exact periods may vary with technical pruning and backups.
| Data | Typical retention |
| Account data (name, email, handle) | Until the account is closed |
| Profile content and links | Until the account is closed or content removed |
| Visitor analytics | Rolled into daily aggregates; raw events pruned after a fixed window |
| Server logs (IP, user-agent) | A rolling window, routinely deleted |
| Payment records | As required by Indian tax law (typically 5–8 years from the end of the relevant financial year) |
| Verification and reset tokens | Hours to days; tokens expire automatically |
| Backups | 7 days for scheduled snapshots, per our backup policy |
9. Security of Your Data
We maintain reasonable security safeguards as required under Section 8(5) of the DPDP Act and the SPDI Rules, including: encryption of data in transit (TLS 1.2+), encryption of data at rest, hashed passwords (never stored as plain text), row-level security and per-user authorization checks on every database query, least-privilege access controls for our own team, rate limiting and abuse detection, dependency and vulnerability scanning, and automated scheduled backups.
No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot guarantee absolute security. You can help by using a strong, unique password, enabling nothing less than a verified email address, and not sharing your login credentials.
In the unlikely event of a personal data breach, we will notify the Data Protection Board of India and affected individuals without delay, in plain language and as required by Section 8(6) of the DPDP Act and the DPDP Rules, describing the nature of the breach, its likely impact, and the steps we have taken — unless the breach is unlikely to result in a risk to the rights of data principals.
10. Your Rights as a Data Principal
The DPDP Act gives you enforceable rights over your personal data. Unless an exemption applies, you may exercise them at any time and without cost:
- Right to access: ask us for a summary of personal data we process about you, the purposes, and the recipients (Section 11 of the DPDP Act).
- Right to correction: request correction or completion of your data — most corrections can be made directly in the dashboard (Section 12).
- Right to erasure: request deletion of your data where the purpose has been served, consent is withdrawn, or retention is no longer necessary (Section 12).
- Right to grievance redressal: ask us to address any grievance; we will respond without delay, and in no case later than within the timeline set out in the Grievance Redressal Policy (Section 13).
- Right to nominate: nominate another individual to exercise your rights in the event of your death or incapacity (Section 14).
- Right to withdraw consent: withdraw consent at any time, as easily as it was given.
- Right to complain to the Board: if you are not satisfied with our response, you may approach the Data Protection Board of India.
11. Children's Data
Tolinks is not directed at children under 18, and we do not knowingly collect personal data from children under 18 without verifiable parental consent, in line with Section 9 of the DPDP Act. We do not allow account creation by children under 18. We do not track or profile any child or target advertising at children, including through any page or tool on the Platform.
If you believe a child has provided us personal data, please contact us at privacy@tolinks.in and we will delete it promptly where verifiable.
12. International Processing and Transfers
The Platform is operated primarily from India, and your data may be processed on cloud infrastructure located in India and other regions (including data centres in the United States and Europe operated by our hosting providers). Under the DPDP Act's permissive cross-border transfer framework and the DPDP Rules, transfers to jurisdictions not notified under a negative list are permitted. Where personal data is transferred outside India, we rely on contractual safeguards with our processors requiring comparable protection.
If you are located outside India, note that your data may be processed in India, and your use of the Platform constitutes consent to such processing to the extent permitted by your local law.
13. Contact and Grievance Officer
For any privacy-related question, request, or complaint, write to:
- Email: privacy@tolinks.in (privacy matters) or support@tolinks.in (general support).
- Grievance Redressal: our designated Grievance Officer and the procedure for complaints — including acknowledgement and resolution timelines under the IT Rules, 2021 — are published on our Grievance Redressal page.
- Postal address for a Data Protection Officer or authorised representative, if designated: to be published on this page as required by law.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Platform, or the law. Material changes will be communicated by email to registered users and by a notice on the Platform. The “Last updated” date at the top of this page indicates when the Policy was last revised. Continued use of the Platform after changes take effect constitutes acceptance of the revised Policy.