Upcoming Privacy Policy

Link's updated Privacy Policy will be effective as of 20 November 2026.

This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.

Welcome

Link is a digital wallet provided by Stripe that facilitates a variety of payment-related features and services, including saving your information for an accelerated checkout experience. With a Link account, you can use your saved information when shopping with businesses that have enabled Link Services. As part of its suite of consumer services, Link also supports Financial Connections, a separate Stripe feature that allows consumers to securely connect financial accounts and share verified bank data with businesses. This Privacy Policy ("Policy") explains how Stripe collects, uses, shares and protects your Personal Data in connection with Link (including when you use services such as Financial Connections through Link), and describes the choices and rights you may have. For information on how Stripe processes Personal Data across its other services, including Payments, Radar, Billing and Identity, please refer to the Stripe Privacy Policy.

For more details about our privacy practices, including our legal bases for processing your Personal Data, please visit our Privacy Centre.

Defined Terms

In this Policy, "Link", "Stripe", "we", "our," or "us" refers to the Stripe entity responsible for the processing of your Personal Data as described in this Policy. We use the term "processing" to mean collecting, using, handling and any other activity with respect to your Personal Data. The Stripe entity responsible for the processing of your Personal Data depends on your location, and the product or service you use with us:

  • If you live in North America, Central America or South America (other than Brazil), the responsible entity is Stripe, LLC.
  • If you live in Brazil, it's Stripe Brasil Soluções de Pagamento - Instituição de Pagamento Ltda.
  • If you live in any of the other countries listed here, it's Stripe Technology Company, Limited.

Where applicable terms or notices identify another entity as responsible for the processing of your Personal Data, that entity will be responsible. We may also use Stripe Affiliates in the same location or other locations, as well as Service Providers and Sub-processors to help provide our Services to you.

  • "Personal Data" refers to any information associated with an identified or identifiable individual, which can include data that you provide to us and that we collect about you during your interaction with our Services (such as device information, IP address, etc.).
  • "Sites" means link.com or any other websites operated by or on behalf of Link or Financial Connections (when accessed via your Link account).
  • "End User Services" or "Services" refers to the products, services, devices and applications that we provide directly to individuals for their personal use, specifically limited to Link Services; Financial Connections Services; and the Sites, when used by individuals acting as consumers.
  • "Link Services" means the features and services that Stripe provides to consumers through Link for their personal use, including the ability to create and manage a Link account to save and use payment, contact, delivery and other information in connection with Link-enabled checkout experiences and other features made available through Link. Link Services include applications and account-management experiences, as well as Link-powered features and functionalities integrated into third-party websites, applications and merchant tools. Products and services offered by merchants or third-party partners are not Link Services, even where available through or used with Link. For instance, when you interact with Link Services within a third-party environment, your use of the Link-powered component is governed by this Link Privacy Policy and the Link Terms of Services, while your interaction with the third party is subject to that third party's respective terms and privacy disclosures.
  • "Financial Connections Services" means the services that Stripe makes available to consumers as governed by the Stripe Financial Connections Terms when used in connection with Link Services.
  • "Business Users" means the businesses that use Stripe products and services offered under the Stripe Services Agreement. Business Users may include Businesses that have not enabled Link Services.
  • "Financial Partners" are financial institutions, banks and other partners, such as payment method acquirers, payment intermediaries, payment aggregators, payout providers, payment method providers, payment processors and card networks that we partner with, directly or indirectly, in order to provide the Services.
  • "Transaction Data" refers to data collected or used by Stripe in relation to transactions using Link Services. Some Transaction Data is Personal Data and may include name, email address, contact number, billing and shipping address, payment method information (like credit or debit card number, bank or payment method account details or payment card image), merchant and location details, amount and date of purchase, information about payment status, and, in some instances, information about what was purchased, order fulfilment status, subscription status, applicable tax amounts, refund or chargeback information and support interactions.

Depending on the way in which you interact with Link Services or the Sites, "you" might be an End User or a Visitor:

  • End Users: When you directly interact with an End User Service, such as saving a payment method with Link, we refer to you as an "End User."
  • Visitors: When you access or interact with Link or the Sites without being logged into a Link account – including when you browse as a merchant, partner or non-Link users or when you contact us about Financial Connections or Link – we refer to you as a "Visitor." For example, you are a Visitor when you send a message to Link asking for more information about our Services.

Table of Contents

  1. What Personal Data we collect
  2. How we use Personal Data
  3. How we disclose Personal Data
  4. Legal bases for processing Personal Data
  5. Your rights and choices
  6. Security and retention
  7. International data transfers
  8. U.S. Consumer Privacy Notice
  9. Jurisdiction-specific provisions
  10. Updates and notifications
  11. Contact us

1. What Personal Data we collect

This section explains the Personal Data we may collect about End Users and Visitors. Our collection and use of Personal Data differs based on whether you are an End User or Visitor, as well as the specific Service that you are using. For example, you are an End User if you used Link to create an account and store information for transactions with a Business User, and you may also be a Visitor if you've visited link.com.

1.1 Personal Data we collect about End Users

We provide End User Services when we provide the Services, such as Link, directly to you for your personal use. Additional details regarding our collection, use and sharing of End User Personal Data, including the legal bases we rely on for processing such data, can be found in our Privacy Centre. The Personal Data we collect about End Users includes:

  • Link account, checkout, transaction and payout data. You may save a number of different types of Personal Data with Link. For instance, you may save your name, payment method details (such as your credit card, debit card, bank account information and billing address), contact information (such as email address and phone number) and shipping address to pay for transactions with Business Users. When you choose to pay using Link, we will also collect Transaction Data associated with your transactions. Learn more. Because Link is available for use with different Business Users, we may combine Transaction Data associated with your Link account across those experiences to provide and improve Link, personalise your checkout experience and help prevent fraud. Where available, you may also use Link to save payout information and to prefill information when onboarding for payout services or selecting a payout method. Where Stripe acts as merchant of record for a transaction you make using Link, product-specific terms describe Stripe's role in that transaction.
  • Agent features. Depending on your location, you may choose to connect your Link account to an AI agent, AI platform or other automated software program or service (an "Agent" or "agent operator," as defined in and subject to the Link Terms of Service) to enable automated shopping, payment, financial analysis or other features. You may authorise an Agent to initiate purchases and payments on your behalf. With your consent, Link may act as an authentication layer for Agent activity, including by issuing authentication tokens that allow an Agent to demonstrate human accountability. To initiate an agentic payment, Stripe, an Agent or a financial partner may also create a tokenised payment credential associated with your payment credential (a "payment token") and process your purchase instructions and information needed to complete the transaction, such as your contact, delivery, payment and shipping information. Link is not responsible for an Agent's logic, security or data practices, including its collection or use of personal data. Agents, merchants and financial partners may process personal data they receive under their own terms of service and privacy policies. You are responsible for reviewing an Agent's privacy practices and managing its access. For Link-connected Agents, you can view, modify or revoke the scope of an Agent's authorisation at any time in your Link account settings. For other authorisations, you should work with the Agent that established the authorisation.
  • Identity information. You can use Link to store your identity documents (such as your driving licence) and other identification information (such as tax ID) so that Link may use them for verification to access other Stripe products and services. You may also use Link to store your identity documents to share in future interactions with Business Users or other third parties you authorise to receive your identity information through Link.
  • Link Financial Partner services. You can also use your Link account to access services provided by certain Stripe Financial Partners, such as Buy Now, Pay Later ("BNPL") services or crypto wallet services. In these situations, we will collect and share additional Personal Data with those Financial Partners to facilitate your use of such services. You can save this information to your Link Account to access similar services in the future. We may also receive certain information about you from Financial Partners in connection with the services they provide. Learn more.
  • Financial Connections data. You can also share and save bank account details to your Link account using Stripe's Financial Connections product. When you use Financial Connections, Stripe will periodically collect and process your account information (such as bank account owner information, account balances, account number and details, account transactions and sometimes log-in information). You can disconnect your bank account, which will cease the collection of such data, at any time. Learn more. A bank providing an account you connect using Financial Connections may provide information about accounts that you did not select to share. In this situation, we may retain this information, such as account identifiers and account type, in order to maintain the integrity of your account connection and to provide support and troubleshooting.
  • Online activity, device and usage data. We may collect information about the devices and browsers you use across our Sites, third-party websites, apps and other online services. We may collect usage data associated with those devices and browsers and your engagement with our Services, including data such as IP address, device and browser characteristics, language preference, pages viewed, links clicked, time spent, approximate location inferred from IP address and other information about how you interact with our Sites including through the use of cookies and similar technologies. We also collect activity indicators that help us detect fraud. Learn more. See our Cookie Policy for more information and manage your cookie preferences here. We may also embed tracking pixels in some of our emails in order to analyse the effectiveness of our marketing communications, which helps us understand engagement levels and ensure that the content we provide is relevant and useful to you.
  • Communication and engagement information. We also collect information you choose to share with us through various channels, such as support tickets, emails or social media. If you respond to emails or surveys from Stripe or Link, we collect your email address, name and any other data you opt to include in your email or responses. If you engage with us over the phone, we collect your phone number and any other information you might provide during the call. Calls with Stripe or Stripe representatives may be recorded and transcribed. Learn more.
  • Stripe as merchant of record. In certain Services, including when you make an Order (as defined in the Sold through Link terms) that is Sold through Link, Stripe acts as the merchant of record for transactions. In these cases, Stripe collects Transaction Data and certain order-level details to provide the services, such as subscription status, fulfilment status, refund or chargeback information and support interactions. In these transactions, Stripe is the controller of the Personal Data we process to fulfil the purchase, if applicable, and to manage customer support, refunds, disputes and related privacy requests. Some features, such as the ability to manage a subscription Order, require a Link account; we will make this clear when you use the feature. Learn more.

We may collect the Personal Data described above directly from you or through your use of the End User Services. We may also receive Personal Data from Business Users, Financial Partners, service providers and publicly available sources.

1.2 Personal Data we collect about Visitors

When you visit the Sites or otherwise interact with us about Link or Financial Connections without using a Link account, we collect information you provide directly and information collected through cookies and similar technologies (in accordance with our Cookie Policy). Please see additional US privacy disclosures here. The Personal Data we collect about Visitors includes:

  • Online activity, device and usage data. We may collect information about the devices and browsers you use across our Sites, and third-party websites, apps and other online services. We may collect usage data associated with those devices and browsers and your engagement with our Sites, including IP address, device and browser characteristics, pages viewed, links clicked, time spent, language preference, approximate location inferred from IP address and other information about how you interact with our Sites including through the use of cookies and similar technologies. See our Cookie Policy for more information, and manage your cookie preferences here.
  • Communication and engagement information. We also collect information you choose to share with us through various channels, such as support tickets, emails or social media. If you respond to emails or surveys from Stripe or Link, we collect your email address, name and any other data you opt to include in your email or responses. If you engage with us over the phone, we collect your phone number and any other information you might provide during the call. Calls with Stripe or Stripe representatives may be recorded and transcribed. Learn more.

2. How we use Personal Data

2.1 End Users

This section explains how we use the Personal Data of End Users. More details about how we use End Users' Personal Data, along with the legal bases we rely on for processing such Personal Data, can be found in our Privacy Centre.

  • Services. We use your Personal Data to provide the End User Services to you, which includes support, contextualisation (such as language preferences, local currency checkout and setting choices), and communication about our End User Services (such as communicating Policy updates and information about our Services). For example, Stripe may use cookies and similar technologies or the data that you provide to our Business Users (such as when you input your email address on a Business User's website) to recognise you and help you use Link when visiting a Business User's website. Learn more about how we use cookies and similar technologies in Stripe's Cookie Policy. To help enable Link across Business User websites, we may use device and browser information associated with your Link account or technical information we obtain from third parties to recognise you, including when you visit a Business User's website for the first time.

  • Fraud detection, loss prevention and security. We use Personal Data to help detect fraud and prevent financial losses for you, us, our Business Users and our Financial Partners, including detecting unauthorised purchases. We also use Personal Data to help secure our services and transactions against unauthorised access, use, alteration or misappropriation of Personal Data, information and funds. As part of Link's fraud prevention, detection, security monitoring and compliance efforts, we may collect information through Link and Financial Connections and from you, Business Users, Financial Partners, publicly available sources and third parties. This information may include IP addresses and other identifiers that help us identify and respond to potential security threats. Learn more. Additionally, we may use technology to evaluate the potential risk of fraud associated with individuals arising from attempted transactions by an End User with our Business Users or Financial Partners. For example, if you use a connected bank account to make payments through a Business User, Stripe may combine your Financial Connections data, including account balances and transaction history, with other information, such as signals derived from Stripe's payments network, to assess the risk of those individual payment transactions, including the likelihood of payment failure or fraud.

  • Analysing, improving and developing our services. We collect and process Personal Data throughout our various services to improve our services, develop new services and support our efforts to make our services more efficient, relevant and useful to you. Learn more. We also may use Personal Data to generate aggregate and statistical information to understand and explain how our services are used. Examples of how we use Personal Data to analyse, improve and develop our products and services include:

    • Using analytics on our Sites, including as described in our Cookie Policy, to help us understand your use of our Sites and services and diagnose technical issues.
    • Training artificial intelligence models to power our services and protect against fraud and other harm. Learn more.
    • Providing and improving AI-powered Link features, including the Link AI assistant, using data such as your requests, chat interactions, account and Transaction Data and support communications.
    • Analysing and drawing inferences from Transaction Data for fraud and dispute purposes, as well as for other Stripe and Business User purposes.
    • Analysing call recordings and call and chat transcripts for quality assurance, training and operational purposes. Learn more.
  • Agent features. When you connect an Agent, we collect and process information the Agent shares with us, as well as information needed to operate the integration and fulfil your requests, including authentication information, your requests and interactions and transaction-related information. We may use this information to help complete purchases you instruct your Agent to make on your behalf; provide the services; prevent fraud; comply with legal and financial-partner requirements; and handle refunds, disputes and other transaction-related requests.

  • Advertising. Where permitted by applicable law, including any consent requirements, we may use your Personal Data, including Transaction Data, to assess your eligibility for and offer you other End User Services or to promote existing End User Services, including through co-marketing with partners such as Stripe Business Users. Learn more. Subject to applicable law, including any consent requirements, we may use and share End User Personal Data with third-party partners to allow us to advertise our End User Services to you, including through interest-based advertising, and to track the efficacy of such ads. We do not sell your Personal Data to third parties in exchange for monetary payment, but we may provide your data to third-party partners, such as advertising partners, analytics providers and social networks, who assist us in advertising our services to you. Learn more. You may manage your preferences here.

  • Insights for Business Users. Where permitted by applicable law, including any consent requirements, we may use your Personal Data, including Transaction Data, to derive insights and to personalise offers and communications to you for Stripe and for Business Users. You may opt-out by managing applicable data-sharing and advertising preferences under Data Sharing in Settings. Learn more.

  • Communications. We use the contact information we have about you to deliver our Services, which may involve sending codes via text message (such as SMS and RCS) or other messaging channels for your authentication. Learn more. If you are an End User or Visitor, we may communicate with you using the contact information we have about you to provide information about our services and our Affiliates' services, invite you to participate in our events, surveys or user research or otherwise communicate with you for marketing purposes, in compliance with applicable law, including any consent or opt-out requirements. For example, if you provide your contact information to us when signing up for Link or when signing up for updates, we may use this data to follow up with you regarding an event, to provide information requested about our services, and to include you in our Link marketing campaigns. Where permitted under applicable law, we may record and transcribe our calls with you to provide our services, comply with our legal obligations and perform research and quality assurance and for training purposes. Learn more.

  • Social media and promotions. If you opt to submit Personal Data to engage in an offer, programme or promotion, we use the Personal Data you provide to manage the offer, programme or promotion. We also use the Personal Data you provide, along with the Personal Data you make available on social media platforms, for marketing purposes, unless we are not permitted to do so.

  • Automated and AI-powered communications. We may leverage automated dialling systems and AI technologies, such as AI-powered voice agents and AI transcription, chat and email tools, to initiate and conduct communications with you for operational, support, sales, marketing and lead qualification purposes. These technologies are used to enhance the efficiency of our outreach and to provide immediate engagement tailored to your needs. We may use Personal Data, including call recordings and transcripts of interactions facilitated by automated systems for staff training, quality assurance and other operational purposes, as well as to train, test and improve the artificial intelligence and machine learning models. To opt out of call recording, please do so when prompted at the beginning of the call.

  • Automated decision making: We may use automated tools that process your Personal Data in certain circumstances. In these circumstances, decisions may be made automatically and without human review. We may use automated decision making in situations such as:

    • Real-time payment and fraud-risk decisioning, including sufficient funds checks, fraud controls and assessing the risk associated with attempted transactions involving Business Users or Financial Partners.
    • Payment-related decisions, such as selecting or recommending a backup payment method and evaluating disputes, chargebacks or claims, including to determine what information is needed or where applicable, to resolve a dispute.
    • To personalise the timing, eligibility and value of promotional offers or financial incentives based on your Transaction Data, payment history and use of our Services.

    If we use automated decision making to make a decision that produces legal or similarly significant effects concerning you, we will provide the notices and choices required by applicable law. These may include the right to request information about the automated processing, opt out of certain processing, request human review or intervention, express your point of view or contest or appeal a decision. You can exercise any applicable rights by contacting us at one of the methods in the "Contact Us" section.

  • Compliance with legal obligations. We use Personal Data to meet our contractual and legal obligations related to anti-money laundering, Know-Your-Customer ("KYC") laws, anti-terrorism activities, safeguarding vulnerable customers, export control and prohibition of doing business with restricted persons or in certain business fields, among other legal obligations. For example, we may monitor transaction patterns and other online signals and use those insights to identify fraud, money laundering and other harmful activity that could affect Link and its Affiliates, our Financial Partners, End Users, Business Users and others. Learn more. Safety, security and compliance for our Services are key priorities for us, and collecting and using Personal Data is crucial to this effort.

  • Minors. Our Services are not directed to children under the age of 13, and we request that they do not provide Personal Data to seek Services directly from Link. In certain jurisdictions, we may impose higher age limits as required by applicable law.

2.2 Visitors

This section explains how we use the Personal Data of Visitors. More details about how we use Visitors' Personal Data, along with the legal bases we rely on for processing such Personal Data, can be found in our Privacy Centre. Please see additional US privacy disclosures here.

  • Fraud Detection. Like End User data, we use Personal Data collected from Visitors to detect and prevent fraud against us, our Business Users and Financial Partners.
  • Personalisation. We use the data we collect about you using cookies and similar technologies to measure engagement with the content on the Sites, improve relevancy and navigation, customise your experience (such as language preference and region-specific content) and curate content about Link and our Services that is tailored to you. For instance, as not all of our Services are available globally, we may customise our responses based on your region.
  • Advertising. Where permitted by applicable law, and where required with your consent, we use and share Visitors' Personal Data with third parties, including Partners, so we can advertise and market our Services and Partner integrations. Subject to applicable law, including any consent requirements, we may advertise through interest-based advertising and track the efficacy of such ads. See our Cookie Policy. We do not sell your Personal Data to third parties in exchange for monetary payment, but we may provide your data to third party partners, like advertising partners, analytics providers and social networks, who assist us in advertising our Services. Learn more. See our Cookie Policy for more information, and manage your cookie preferences here.
  • Engagement. As you interact with our Sites, we use the information we collect about and through your devices to provide opportunities for further interactions, such as discussions about Services or interactions with chatbots, as well as to address your questions.

3. How we disclose Personal Data

This section explains how we may disclose the Personal Data of End Users and Visitors. Please see additional US privacy disclosures here.

  • Stripe Affiliates. We disclose Personal Data with other Stripe affiliates for purposes identified in this Policy.
  • Stripe's Business Users. When you use an End User Service, such as using Link to make payments with our Business Users, we disclose your Personal Data, including name, contact information, payment method details and Transaction Data with those Business Users. Learn more. You can also direct Stripe to disclose your saved bank account information and identity documents with Business Users you do business with. Once we disclose your Personal Data with Business Users, we may process that Personal Data as a Data Processor for those Business Users, as detailed in the Stripe Privacy Policy. You should consult the privacy policies of the Business Users with whom you do business for information on how they use the information disclosed to them. We may also disclose insights we derive about you from your Personal Data and Transaction Data with Business Users.
  • Service providers or processors. In order to provide, communicate, market, analyse and advertise the Services, we depend on service providers. These providers offer critical services such as providing cloud infrastructure, conducting analytics for the assessment of the speed, accuracy, and/or security of our Services, verifying identities, identifying potentially harmful activity and providing customer service and audit functions. We authorise these service providers to use or disclose the Personal Data we make available to them, which may be any of the types of Personal Data we collect, to perform services on our behalf and to comply with relevant legal obligations. We require these service providers to contractually commit to security and confidentiality obligations for the Personal Data they process on our behalf. The majority of our service providers are based in the European Union, the United States of America and India. Learn more.
  • Advertising partners. We may disclose Personal Data, including online activity and device and usage data with advertising platforms, analytics providers and social networks to advertise Link, measure and attribute advertising performance and prevent or detect fraudulent advertising activity. We limit this disclosure based on applicable law and your privacy choices.
  • Fraud detection and loss prevention. When you use End User Services in connection with a Business User or Financial Partner, we may disclose relevant Personal Data, including information about an attempted transaction, where necessary to help prevent fraud, reduce financial loss or protect the security of the transaction. Learn more about how we may use technology to assess the fraud risk associated with an attempted transaction and what information we share with Business Users and Financial Partners here and here.
  • Financial Partners. We disclose Personal Data to certain Financial Partners to provide our Services and offer certain Services in conjunction with these Financial Partners. For example, we disclose certain Personal Data to card networks in connection with handling a dispute.
  • Card networks. We disclose your personal data related to your transactions with the credit card provider that you choose to use. When a payment dispute or chargeback is filed, Link may submit evidence to the relevant card network (such as Visa, Mastercard, American Express or Discover) on behalf of the merchant. This evidence may include your personal data, such as your email address, IP address, account activity, delivery or transaction confirmation records, any information shared by Business Users or information that you disclose to us in the support request. Card networks are independent data controllers for evidence they receive, and they retain that data in accordance with their own policies and applicable card network rules.
  • Agents. If you connect your Link account to an Agent, Link may share information with participating services as directed by you or your Agent to fulfil your requests. In connection with agentic payments, Stripe may share your payment credential and/or associated payment token, and relevant transaction data, with the Agent, merchant, payment networks, financial institutions, their service providers and partners involved in authenticating, processing, settling, supporting or protecting the transaction.
  • Stablecoin and blockchain payments. Where Link supports payment or payout in stablecoins or other digital assets, your transaction will be recorded on a public blockchain. Blockchain records are permanent and cannot be altered or deleted by us or by you; this is an inherent feature of blockchain technology.
  • Corporate transactions. If we enter or intend to enter a transaction that modifies the structure of our business, such as a reorganisation, merger, sale, joint venture, assignment, transfer, change of control or other disposition of all or part of our business, assets or stock, we may disclose Personal Data to third parties in connection with such transaction. Any other entity that buys us or part of our business will have the right to continue to use your Personal Data, subject to the terms of this Policy.
  • Compliance and harm prevention. We disclose Personal Data when we believe it is necessary to comply with applicable law; to abide by rules imposed by Financial Partners in connection with the use of their payment method or infrastructure; to enforce our contractual rights; to secure and protect the Services, rights, privacy, safety and property of Link, you, Business Users and others, including against malicious or fraudulent activity or reasonable suspicion thereof; and to respond to valid legal requests from courts, law enforcement agencies, regulatory agencies and other public and government authorities, which may include authorities outside your country of residence.
  • Others with consent or your direction. We may disclose your Personal Data to third parties whenever you direct or consent to such disclosure. For example, in some situations, we may not offer a service but may instead refer you to a partner. In these instances, we will disclose the identity of the third party and the information to be conveyed, and seek your consent to disclose the information.

5. Your rights and choices

Depending on your location and subject to applicable law, you may have choices regarding our collection, use and disclosure of your Personal Data:

5.1 Opting out of receiving electronic communications from us

If you wish to stop receiving marketing-related communications from us, you can opt-out by clicking the unsubscribe link included in such communications or by updating your preferences in your Link account settings. We'll try to process your request(s) as quickly as reasonably practicable. However, it's important to note that even if you opt out of receiving marketing-related communications from us, we retain the right to communicate with you about the Services you receive (like support and important legal notices), and our Business Users might still send you messages or instruct us to send you messages on their behalf.

5.2 Your data protection rights

Depending on your location and subject to applicable law, you may have the following rights regarding the Personal Data that we process about you as a data controller:

  • The right to request confirmation of whether Link is processing Personal Data associated with you, the categories of personal data it has processed and the third parties or categories of third parties with which your Personal Data is shared;
  • The right to request access to the Personal Data that Link processes about you (Learn more);
  • The right to request that Link rectify or update your Personal Data if it's inaccurate, incomplete or outdated;
  • The right to request that Link erase your Personal Data in certain circumstances as provided by law (Learn more);
  • The right to request that Link restrict the use of your Personal Data in certain circumstances, such as while Link is considering another request you've submitted (for instance, a request that Link update your Personal Data);
  • The right to request that we export the Personal Data we hold about you to another company, provided that it's technically feasible;
  • The right to withdraw your consent if your Personal Data is being processed based on your previous consent;
  • The right to object to the processing of your Personal Data if we are processing your data based on our legitimate interests; unless there are compelling legitimate grounds or the processing is necessary for legal reasons, we will cease processing your Personal Data upon receiving your objection (Learn more);
  • The right not to be discriminated against for exercising these rights; and
  • The right to appeal any decision by Link relating to your rights by contacting Stripe's Data Protection Officer ("DPO") at dpo@stripe.com, and/or relevant regulatory agencies.

You may have additional rights, depending on applicable law, over your Personal Data. Please see the Jurisdiction-specific provisions section below.

5.3 How to exercise your data protection rights

To exercise your data protection rights related to the Personal Data we process as a data controller, visit our Privacy Portal or contact us as outlined below. For Personal Data we process as a data processor, please reach out to the relevant data controller (Business User) to exercise your rights. If you contact us regarding your Personal Data we process as a data processor, we will refer you to the relevant data controller to the extent that we are able to identify them.

6. Security and retention

We make reasonable efforts to provide a level of security that is appropriate to the risk associated with the processing of your Personal Data. We maintain organisational, technical and administrative measures designed to protect the Personal Data covered by this Policy from unauthorised access, destruction, loss, alteration or misuse. Learn more. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.

We encourage you to assist us in protecting your Personal Data. If you hold a Link account, you can help us protect your Personal Data by using a strong password, safeguarding your password against unauthorised use, and avoiding reusing login credentials from other accounts for your Link account. If you suspect that your interaction with us is no longer secure (for instance, if you believe that your Link account's security has been compromised), please contact us immediately.

We retain your Personal Data for as long as we continue to provide the Services to you or for a period in which we reasonably foresee continuing to provide the Services. Link account information is generally retained while your account remains active. We may retain Transaction Data and limited account information after account closure where necessary to comply with legal, tax, accounting and financial-recordkeeping obligations, resolve disputes or prevent fraud. Even after we stop providing Services directly to you or to a Business User that you're doing business with, and even after you close your Link account or complete a transaction with a Business User, we may continue to retain your Personal Data to:

  • Comply with our legal and regulatory obligations;
  • Enable fraud monitoring, detection and prevention activities; and
  • Comply with our tax, accounting and financial reporting obligations, including when such retention is required by our contractual agreements with our Financial Partners, and where data retention is mandated by the payment methods you've used.

In cases where we retain your Personal Data, we do so in accordance with any limitation periods and record retention obligations imposed by applicable law. Learn more.

7. International data transfers

As a global business, we may sometimes need to transfer your Personal Data to countries other than your own, including the United States and India. These countries may have data protection regulations that are different from those in your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials, such as law enforcement or security authorities. Learn more.

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK") or Switzerland, please refer to our Privacy Centre for additional details. When a data transfer mechanism is mandated by applicable law, we employ one or more of the following:

  • Transfers to certain countries or recipients that are recognised as having an adequate level of protection for Personal Data under applicable law.
  • EU Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum issued by the Information Commissioner's Office. You can obtain a copy of the relevant Standard Contractual Clauses. Learn more.
  • Other lawful methods available to us under applicable law.

Stripe complies with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce and as applicable. Learn more.

Link's privacy practices, as described in this Privacy Policy, comply with the Cross Border Privacy Rules System ("CBPR") and Privacy Rules for Processor ("PRP") systems. These systems provide a framework for organisations to ensure protection of personal data transferred among participating economies. Where CBPR and/or PRP are recognised as a valid transfer mechanism under applicable law, Link will transfer Personal Data in accordance with the CBPR and PRP certifications Stripe has obtained. More information about these frameworks may be found here and here. If you have unresolved privacy or data use concerns that we have not addressed satisfactorily, please contact our U.S. based third-party dispute resolution provider (free of charge) here. To view the status of our CBPR and PRP certifications, please see here and here, respectively.

8. US Consumer Privacy Notice

For US consumers who obtain Link or Financial Connections financial services primarily for personal, family or household purposes, our collection, use and sharing of Personal Data are governed by the Gramm-Leach-Bliley Act and described in the US Consumer Privacy Notice below. Other US privacy rights may apply only to Personal Data and processing that are not subject to the Gramm-Leach-Bliley Act.

FACTSWHAT DOES LINK DO WITH YOUR PERSONAL INFORMATION?
Why?Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share and protect your personal information. Please read this notice carefully to understand what we do.
What?

The types of personal information we collect and share depend on the product or service you have with us. This information can include:

  • Social Security Number
  • Account balances
  • Transaction history
  • Payment history
  • Credit history

When you are no longer our customer, we continue to share your information as described in this notice.

How?All financial companies need to share customers' personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers' personal information; the reasons Link chooses to share; and whether you can limit this sharing.
Reasons we can share your personal informationDoes Link share?Can you limit this sharing?
For our everyday business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations or report to credit bureausYesNo
For our marketing purposes – to offer our products and Services to youYesNo
For joint marketing with other financial companiesYesNo
For our affiliates' everyday business purposes – information about your transactions and experiencesYesNo
For our affiliates' everyday business purposes – information about your creditworthinessYesYes
For our affiliates to market to youNoWe don't share
For non-affiliates to market to youYesYes
To limit our sharing

Log in to your Link account at app.link.com/settings and toggle off data sharing from the Messaging menu.

Please note: If you are a new customer, we can begin sharing your information 30 days from the date we sent this notice. When you are no longer our customer, we continue to share your information as described in this notice.

However, you can contact us at any time to limit our sharing.

Questions?
Who we are
Who is providing this notice?Stripe, Stripe Payments Company and their affiliates that provide consumer services in the US, including Stripe, LLC and Sold through Link, LLC
What we do
How does Link protect my personal information?To protect your personal information from unauthorised access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings. We impose access controls along with ongoing monitoring to help prevent data misuse, and we require our service providers to take similar steps to help protect your information.
How does Link collect my personal information?

We collect your personal information, for example, when you

  • open an account;
  • pay your bills;
  • provide account information

We also collect your personal information from others, such as credit bureaus, affiliates or other companies.

Why can't I limit all sharing?

Federal law gives you the right to limit only

  • sharing for affiliates' everyday business purposes – information about your creditworthiness
  • affiliates from using your information to market to you
  • sharing for non-affiliates to market to you.

State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law.

What happens when I limit sharing for an account I hold jointly with someone else?Your choices will apply to everyone on your account.
Definitions
Affiliates

Companies related by common ownership or control. They can be financial and non-financial companies.

  • Our affiliates include companies operating under the Stripe name, such as Stripe Technology Europe, Ltd. and Stripe Payments UK, Ltd.
Non-affiliates

Companies not related by common ownership or control. They can be financial and non-financial companies.

  • Non-affiliates with which we share personal information include service providers that perform services or functions on our behalf, Business Users with which you choose to transact, partners with which we share data to provide you with services and advertising partners, analytics providers and social networks, who assist us in advertising our Services to you.
Joint Marketing

A formal agreement between non-affiliated financial companies that together market financial products or services to you.

  • Our joint marketing partners include financial companies we partner with to provide you with financial services.
Other important information

Vermont: If your account with us is associated with a Vermont billing address, we will not disclose information about your creditworthiness to our affiliates and will not disclose your personal information, financial information or credit report to non-affiliated third parties to market to you, other than as permitted by Vermont law, unless you authorise us to make those disclosures. For joint marketing, we will only disclose your name, contact information and information about your transactions. Additional information concerning our privacy policies can be found in our Privacy Policy and Privacy Centre.

California: If your account with us is associated with a California billing address, we will not disclose Personal Data we collect about you except to the extent permitted under California law. For instance, we may disclose your Personal Data as necessary to process transactions or provide products and services you request, at your instruction, as required for institution risk control, and to safeguard against fraud, identity theft and unauthorised transactions.

9. Jurisdiction-specific provisions

  • Australia. "Personal Data" includes "personal information" as defined under applicable privacy laws in Australia, including the Privacy Act 1988 (Cth) as amended from time to time.

    • If we use personal information to make automated decisions that could reasonably be expected to significantly affect your rights or interests, we will provide the legally required information and transparency via our Privacy Centre, and/or on a case-by-case basis.
    • If you are an Australian resident and are dissatisfied with our handling of any complaint you raise under this Policy, you may consider contacting the Office of the Australian Information Commissioner.
  • Brazil. You may exercise your rights by contacting our DPO Adi Gilad at dpo@stripe.com. Brazilian residents, for whom the Lei Geral de Proteção de Dados Pessoais ("LGPD") applies, have rights set forth in Article 18 of the LGPD. If the LGPD is applicable to the processing of your Personal Data, you may have the right to:

    • Confirm the existence of the data processing;
    • Access your Personal Data;
    • Correct incomplete, inaccurate or outdated data;
    • Anonymise, block or delete data that is unnecessary, excessive or processed in violation of the LGPD;
    • Transfer your data to another service or product provider;
    • Delete data processed with your consent;
    • Obtain information about the public or private entities with which Link has shared your Personal Data;
    • Obtain information about how to consent, and the consequences of refusing consent; and
    • Withdraw consent.

    Where required, we have put in place appropriate safeguards for the cross-border transfer of Personal Data from Brazil, including the Brazilian Standard Contractual Clauses.

  • Canada. As used in this Policy, "applicable law" includes the Federal Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Personal Information Protection Act, SBC 2003 c 63, in British Columbia, the Personal Information Protection Act, SA 2003 c P-6.5, in Alberta and the Act Respecting the Protection of Personal Information in the Private Sector, CQLR c P-39-1 ("Quebec Private Sector Act"), in Quebec. Learn more. "Personal Data" includes "personal information" as defined under those laws.

    • Stripe's Global Head of Privacy is the person in charge of personal information, including under the Quebec Private Sector Act. You may contact them via email at privacy@stripe.com. When Stripe collects Personal Data belonging to Canadian (including Quebec) residents, it transfers that data to data centres in the United States. When Stripe relies on service providers to process Personal Data as described herein, those service providers may also be located outside of Canada or Quebec.
    • You have the right to request access or rectification of the Personal Data Link holds related to you or to withdraw any consent given to the processing of such Personal Data. You may exercise those rights by contacting Stripe's Global Head of Privacy at privacy@stripe.com.
  • EEA and UK. You may exercise your rights by contacting our DPO at dpo@stripe.com. If you are a resident of the EEA or the Stripe entity accountable for your Personal Data is otherwise subject to the GDPR, and you believe our processing of your information contradicts the GDPR, you may direct your questions or complaints to the Irish Data Protection Commission. If you are a resident of the UK, direct your questions or concerns to the UK Information Commissioner's Office. You also have additional rights under the EU-US DPF and the UK Extension to the EU-US DPF. Learn more.

  • France. You have the right to define general or specific directives regarding the storage, erasure and communication of your Personal Data after your death. You may also register these directives with a "certified digital trusted third party" recognised by the CNIL. These directives may designate a person to be responsible for their execution; otherwise, your heirs will be designated. You may transmit your directives to us by contacting privacy@stripe.com.

  • Hong Kong SAR. As used in this Policy, "applicable law" includes the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of Hong Kong. The provision of your Personal Data is voluntary unless indicated otherwise. However, where the collection of Personal Data is required for us to comply with legal obligations or perform a contract with you (such as processing a payment transaction or conducting mandatory identity verification), providing your data is obligatory and failure to provide it will result in our inability to provide you with the Services. If you are a Hong Kong resident and wish to exercise your rights to access or correct your data or if you are dissatisfied with our handling of any complaint raised under this Policy, you may contact our DPO or you may choose to contact the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD).

  • India. In this Policy, "applicable law" includes the Digital Personal Data Protection Act ("DPDPA") once the DPDPA enters into effect, and rules issued thereunder. Further, the term "data controller" includes "data fiduciaries," and the term "data subject" includes "data principal," both as defined in the DPDPA.

    • Your acceptance of this Policy constitutes a clear affirmative action and signifies your agreement to Link's processing of your Personal Data for the purposes outlined in this Privacy Policy. If you do not agree with any part of this Policy, you should refrain from accessing or using our services.
    • In some cases, and as permitted under the DPDPA, we may rely on "legitimate use" as a legal basis as permitted under Section 7 of the DPDPA. For example, we might do so for the following:
      • When you voluntarily provide your Personal Data to us without indicating that you do not consent to its use, you will be deemed to have given your consent.
      • For fulfilling any obligation under any law for the time being in force in India that requires Link to disclose information to the state or its instrumentalities, provided such processing complies with applicable provisions regarding disclosure under such law.
      • For compliance with any judgment, decree or order issued under any law in force in India or by any court or tribunal in India.
    • Where we are required to obtain your explicit and informed consent, we will do so on a case by case basis.
    • In addition to other rights set forth in this Policy, you have the right to contact Link to obtain a summary of your Personal Data being processed and the related processing activities.
    • You have the right to contact Link to nominate another individual, who may, in the event of your death or incapacity, exercise your rights under this Privacy Policy and under the DPDPA and implementing regulations. You may withdraw your consent to the processing of your Personal Data at any time.
    • In certain cases, you may be asked to consent to the collection and processing of your Aadhaar number by our third-party verification partner(s), to the extent permitted under applicable law. The purpose of this collection is to facilitate the identification verification process as required under applicable laws. Your provision of Aadhaar details is purely voluntary, and you may provide other identification documents as may be accepted by us from time to time. You will not be denied service merely for not submitting Aadhaar details. The collection, use, processing and storage of your Aadhaar data will be in accordance with the terms and policies of such third-party verification partner(s).
    • If you have any questions or complaints regarding the processing of your Personal Data or the exercise of your rights or if you want to receive this Policy or communicate with us about privacy in one of India's official languages, please contact our Nodal and Grievance Officer. Learn more. Alternatively, you may contact our DPO at dpo@stripe.com. We will endeavour to address your grievance within a reasonable period of time and, in any event, within 90 days from the date of receipt of the complaint. If we are unable to address your complaint or grievance, you have the right to escalate the matter to the Data Protection Board of India.
    • Link may transfer your Personal Data to third parties or service providers located outside your jurisdiction. We ensure that any such transfers comply with applicable laws. Where authorities restrict transfers to certain countries or territories, we will adhere to those restrictions and take appropriate measures.
  • Indonesia. In this Policy, "applicable law" includes Law No. 11 of 2008 as amended by Law No. 19 of 2016 on Electronic Information and Transactions, Government Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions, and Minister of Communication and Informatics Regulation No. 20 of 2016 on Personal Data Protection in Electronic Systems, and from September 2024, Law No. 27 of 2022 concerning Personal Data Protection ("PDP Law"). If you have any questions or complaints about this Policy, please contact our DPO at dpo@stripe.com.

  • Japan. In this Policy, "applicable law" includes the Act on the Protection of Personal Information ("APPI"). When we transfer Personal Data of data subjects in Japan to jurisdictions not recognised as 'adequate' by the Personal Information Protection Commission, we enter into written agreements with any third parties located outside of Japan. These written agreements provide rights and obligations equivalent to those provided under the Japanese Act on the Protection of Personal Information. For more information on how we ensure that third parties protect your data and where your data is located, please see above or contact us as described below. For a description of foreign systems and frameworks that may affect the implementation of equivalent measures by the third party, see here. In some cases, and as permitted under the APPI, we may rely on "public interest" as a legal basis, such as fraud detection and loss prevention.

  • Malaysia. In this Policy, "applicable law" includes the Malaysian Personal Data Protection Act 2010 as amended from time to time. If you have any questions or complaints about this Policy, please contact our DPO at dpo@stripe.com.

  • New Zealand. In this Policy, "applicable law" includes the New Zealand Privacy Act 2020 as amended from time to time. Our processing of biometric data via Stripe Identity complies with the Biometric Privacy Processing Code. When you use this service, we collect and use a photo of your ID and a selfie to verify your identity and prevent fraud. This biometric data is retained for one year. If you have concerns, you have the right to contact us or the New Zealand Privacy Commissioner. For more details on what data we collect, our specific purposes for collection, and alternative verification options, please see our full Privacy Policy, our Privacy Centre and Stripe Identity documentation.

  • People's Republic of China. If you reside in the People's Republic of China (excluding Hong Kong SAR, Macao SAR and Taiwan for the purposes of this Policy only) ("Mainland China"), the following supplementary terms apply:

    • Controller: The Stripe entity acting as the data controller is set out above.
    • Processing of Sensitive Personal Information: Where required by the Personal Information Protection Law ("PIPL"), we will obtain your separate consent to process Sensitive Personal Information (as defined by PIPL). Depending on your interaction with Link, this may include bank account and payment method details, government-issued IDs, biometric data (such as selfies for verification) and credit reports. We process this data with enhanced security measures in strict compliance with applicable law.
    • Legal basis: While Link may rely on "legitimate interests" in other jurisdictions, for residents of Mainland China, where required under PIPL, we will obtain your consent as the primary legal basis for the processing activities described in this Privacy Policy.
    • Sharing and transfers: Where required with your consent, we may share your Personal Data with the Stripe affiliates and third parties disclosed in this Policy, including those located outside of Mainland China.
    • Independent controllers: Some recipients will act as independent data controllers and process your Personal Data under their own privacy policies.
    • Entrusted parties: Other recipients act as our 'entrusted parties' (data processors), they will process your data strictly according to our instructions.You can find the identities of Link affiliates as well as Link's Sub-processors here. Link's contact details are set out in the Contact Us section of this Privacy Policy.
  • Singapore. In this Policy, "applicable law" includes the Personal Data Protection Act 2012 ("PDPA") (No. 26 of 2012) as amended from time to time. In some cases, and as permitted under the PDPA, we may rely on "deemed consent" as a legal basis. For example, we do so when you voluntarily provide your Personal Data to us. If you have any questions or complaints about this Policy, please contact our DPO at dpo@stripe.com.

  • South Korea. In this Policy, "applicable law" includes the Personal Information Protection Act ("PIPA") and the Credit Information Use and Protection Act ("CIA"). Personal Data may be transferred to Link's global affiliates and service providers located in the United States and other countries for delegation, storage, operational and customer support purposes, in accordance with applicable law. Learn more.

  • Switzerland. In this Policy, "applicable law" includes the Swiss Federal Act on Data Protection ("FADP"), as revised. To exercise your rights under the FADP, please contact our DPO at dpo@stripe.com. You may also have additional rights under the Swiss-US Data Privacy Framework. Learn more.

  • Thailand. In this Policy, "applicable law" includes the Personal Data Protection Act 2019 ("PDPA"). If we rely on certain legal bases (such as "legal obligation" or "contractual necessity") and you do not provide us with your Personal Data, we may not be able to lawfully provide you services. If you have any questions or complaints about this Policy, please contact our DPO at dpo@stripe.com. Where required, we have put in place appropriate safeguards for the cross-border transfer of Personal Data from Thailand, including the EU Standard Contractual Clauses as adapted for Thailand data transfers in accordance with the Notification of the Personal Data Protection Committee on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country Pursuant to Section 29 of the Personal Data Protection Act, B.E. 2562 B.E. 2566 (2023).

  • United Arab Emirates. As used in this Policy, "applicable law" includes Federal Decree-Law No. 45 of 2021 on Personal Data Protection ("PDPL") for processing within the mainland UAE or applicable financial free zone data protection laws (such as DIFC Data Protection Law No. 5 of 2020 or ADGM Data Protection Regulations 2021) where relevant. When we transfer Personal Data outside the UAE, we ensure appropriate safeguards are implemented in accordance with Article 22 and Article 23 of the PDPL (or applicable free zone laws), such as transferring to jurisdictions recognised as providing adequate protection or putting in place approved standard contractual clauses. To exercise your rights under UAE law, please follow the process set out in this Privacy Policy or contact our Data Protection Officer at dpo@stripe.com. If you are dissatisfied with our response or handling of any privacy complaint, you may also contact the UAE Data Office or the relevant financial free zone Data Protection Commissioner.

  • United States. If you are a consumer located in the United States ("US"), we process your personal information in accordance with US federal and state privacy laws. For additional details, please review the information below and see our additional US Privacy Disclosures here. Link uses cookies, including advertising cookies, as described in our Cookie Policy. You may manage your cookie preferences here.

    • Your rights and choices. As a US consumer and subject to certain limitations under US privacy laws, you may have choices regarding our use and disclosure of your Personal Data. In addition to the above rights, you may also have the rights listed in this section. Please see our Privacy Centre to learn more about data subject rights metrics and learn more about the laws under which these rights may apply.
      • Exercising the right to know: You have a right to request additional information about the categories of personal information collected, sold, disclosed or shared; purposes for which this personal information was collected, sold or shared; categories of sources of personal information; and categories of third parties with whom we disclosed or shared this personal information.
      • Exercising the right to opt-out from a sale or sharing, including targeted advertising: We do not sell your Personal Data to third parties in exchange for monetary payment. However, as noted above, we may provide Personal Data, including identifying information, as well as online activity, device and usage data to third party partners, such as advertising partners, analytics providers and social networks, who assist us in advertising our products and Services to you. Because these third parties may use the data Link provides for their own purposes, Link's provision of data to these parties may be considered a data "sale" or "sharing" (for behavioural advertising) as those terms are defined under applicable U.S. privacy laws. You can opt out of targeted advertising and any related data "sales" or "sharing" (for behavioural advertising) here. Where we detect a Global Privacy Control ("GPC") signal, we will honour it as a request to opt out of "sales" and "sharing" (for behavioural advertising) for the device and associated browser that transmits the signal. Note that if you or your browser clear or expire cookies, you will need to opt-out or transmit a Global Privacy Control signal again to opt-out.
      • Exercising the right to limit the use or sharing of Sensitive Personal Information: We do not sell or share (for behavioural advertising) Personal Data about people we know to be under the age of 16 or Sensitive Personal Information as defined by U.S. privacy laws and have not done so in the past 12 months. We also do not use it for purposes that require us to offer a right to limit the use of Sensitive Personal Information under U.S. privacy laws. Learn more about our collection and use of Sensitive Personal Information over the last 12 months here.
      • Profiling with legal or similarly significant effects: In the event that we engage in profiling or automated decision making for which applicable law entitles you to an opt out, we will provide you with notice of how to exercise that opt-out right.
      • Appeal: If you wish to appeal any of our decisions regarding a rights request under U.S. privacy laws, you may do so by contacting Stripe's Data Protection Officer ("DPO") at dpo@stripe.com.
    • To submit a request to exercise any of the rights described above, please contact us using the methods described in the Contact Us section below. Please note that rights under some U.S. state laws do not apply to Personal Data we collect, process and disclose when you act as a consumer to obtain financial products or services from Link for personal, family or household purposes. The federal Gramm-Leach Bliley Act may govern how Link shares and protects that data instead. See our U.S. Consumer Privacy Notice above for more information.
    • We will verify your request by asking you to send it from the email address associated with your account or requiring you to provide information necessary to verify your identity, including name, address, transaction history, photo identification and other information associated with your account.
    • You may designate, in writing or through a power of attorney, an authorised agent to make requests on your behalf to exercise your rights under applicable U.S. privacy laws. Your agent may submit a request on your behalf by contacting us using the methods described in the Contact Us section below. We may still require you to directly verify your identity and confirm that you gave the authorised agent permission to submit the request.

10. Updates and notifications

We may change this Policy from time to time to reflect new services or changes in our privacy practices or relevant laws. The "Last updated" legend at the top of this Policy indicates when this Policy was last materially revised. Any changes are effective the latter of when we post the revised Policy on the Services or otherwise provide notice of the update as required by law.

We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are an End User or Representative, by contacting you through your Link account, email address and/or the physical address listed in your Link account.

11. Contact us

If you have any questions or complaints about this Policy, please contact us.