Privacy policy
What we collect, why, how long we keep it, and how to make us delete it.
On this page
At a glance
- We wear two hats: controller for our customers' own account data, processor for the people our customers talk to through Linkubit.
- We do not sell personal data, to anyone, ever. What we share is limited to the processors named in our data processing addendum.
- Data is kept indefinitely by default, but erasure on request always works — and every erasure is audit-logged.
- The only thing that survives erasure is a one-way hash of an opt-out, so unsubscribes stay honoured after deletion.
- All customer data lives in Mumbai, India; tenant isolation is enforced by the database itself, not by application code.
- Reply STOP to any message to stop marketing immediately — it works in any language we support.
1. Who we are
Linkubit is operated by Adhiti Consulting Pty Ltd, a company registered in New South Wales, Australia. In this policy “we” means that company and “you” means whoever is reading — which may be a customer of ours, or a person one of our customers is in contact with. Section 3 explains why that distinction matters.
Linkubit is a business product and this site is not directed at children. We do not knowingly collect personal data from anyone under 18; if you believe we have, contact us and we will delete it.
2. Two very different roles
Linkubit is a platform our customers use to talk to their customers. That puts us in two roles at once, and your rights differ depending on which one applies.
| When | Our role | Who to contact |
|---|---|---|
| You use Linkubit as a customer — your account, your billing | Controller. We decide what to collect and why | Us, directly |
| A business uses Linkubit to message you, and their record of you sits in our system | Processor. We hold the data on their instructions and do not decide what happens to it | That business first. We will help them, and you can still reach us directly |
3. What we collect
If you are our customer
- Name, work email and organisation, held by our identity provider
- Configuration you create — qualification fields, lifecycle stages, rules, templates, workflows
- Usage counts: messages sent and received, agent turns, model tokens, documents ingested
- Operational logs, each tagged with a correlation identifier
If a business contacts you through Linkubit
- The addresses they can reach you on — email, phone number, WhatsApp identifier — normalised and stored once per channel
- Messages exchanged, in both directions, and their delivery state
- Your consent record per channel and purpose, including the basis it was given under and when
- Activity that business recorded about you: campaign sends, link clicks, ad clicks, form submissions, meetings
- Information you supplied in conversation — for a freight company that might be shipping volumes, for a property consultancy a budget
We do not buy contact data, and we do not sell it. Where a customer enriches their prospect lists, they bring their own provider key and that provider's terms apply to them, not to us.
If you contact us through this website
The contact form asks for your name, work email, company, rough message volume, industry, the channels you use and what you wrote. Sending it creates a contact and a conversation in Linkubit's own workspace — the product runs our own inbox — so that a person can reply, and records the IP address the form was sent from as evidence that you contacted us first. If you arrived from an ad or a campaign link, the identifiers in that link (UTM tags, a Google or Meta click id) are kept beside the enquiry so we know which page brought you. We use all of this to reply to you and to see which pages work, nothing else; it is kept until you ask for it to be erased, which works the same way as any other data request. The live demo keeps only a one-way hash of the phone number you type, never the number.
The site counts page views with our host's cookieless analytics: a hash of your connection that changes daily, the page URL, and no identifier stored on your device. The cookie policy lists everything the site stores in your browser.
4. Connected accounts
A customer connects a WhatsApp Business Account, Instagram or Messenger to send and receive messages, may connect their own email mailbox (Gmail or Google Workspace, or Zoho Mail) so email leaves from their own address, and may separately connect their own Google Ads or Meta ad account. Each is optional except the messaging channel itself, each is done by a person on that customer's staff, and each can be undone by them at any time.
WhatsApp, Instagram and Messenger
Connecting a WhatsApp Business Account, an Instagram professional account or a Facebook Page for Messenger works through Meta's own connection flow and grants Linkubit permission to send and receive messages on that number or account, on the business's behalf. The token Meta gives us is stored encrypted the same way as the ad tokens below, and is used only to operate the inbox: sending and receiving messages, and reading their delivery status. It reaches nobody but Meta, as the platform those messages travel on, and our AI model provider, only when the business's AI agent is on and replies to one (section 5). Disconnecting the account from Settings, or removing Linkubit under that account's own connected-apps settings, ends it either way.
Google Ads
Connecting Google Ads uses Google's sign-in, which asks the person to grant Linkubit two permissions: managing their Google Ads account and data, and sending customer data to it. Google gives us a token for that grant. We store it encrypted in a secrets store, we never show it on a screen or return it from an API, and we use it only for the things below.
- Reading the account's campaigns, ad groups, ads and daily spend, so the customer can see what each ad cost beside the leads and revenue it produced.
- Creating campaigns the customer builds in Linkubit. Everything we create starts paused; nothing spends until the customer switches it on.
- Reporting outcomes — a lead the customer qualified, a deal they won — to a conversion action the customer chose, matched on the click identifier Google issued.
- Customer lists: keeping a Google customer-match audience in step with a Linkubit audience. Only one-way hashes of an email address or phone number leave our system, only for people who have given marketing consent on that channel, and anyone suppressed is removed first.
We do not use data from a customer's Google account for our own advertising, we do not sell it, and no person at Linkubit reads it except to support that customer at their request. It is not shared with our AI model provider or any other subprocessor, it is not used to train any model, and it is disclosed to nobody except Google itself, as part of the four things above. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Disconnecting the account from Settings revokes the grant at Google and deletes the token; a customer can also revoke Linkubit's access from their Google account's third-party access settings, and either way we can no longer reach the account.
Gmail and Google Workspace mailboxes
Connecting a Gmail or Google Workspace mailbox uses Google's sign-in, which asks the person to grant Linkubit permission to send email on their behalf, to see the email address of the account, and to read their sending domain's statistics in Google Postmaster Tools. The token Google gives us is stored encrypted in a secrets store, never shown on a screen or returned from an API, and used only for the things below.
- Sending the emails the business sends to its own contacts from Linkubit — a reply a person on its staff writes in the inbox, a step of an email campaign it set up, a reply from its AI agent when it has switched one on, a payment request, and the test message the settings screen sends — so they leave from the business's own address.
- Naming the mailbox: the account's email address, read once at connection so the screen shows which mailbox is connected and messages go out from it.
- Watching for spam complaints: once a day we read the share of the sending domain's mail that Gmail users reported as spam, as Google Postmaster Tools reports it for the whole domain, and pause sending from that mailbox if it passes 0.3%, so a business does not damage its own sender reputation. We read no other Postmaster statistic and change nothing in Postmaster Tools.
The permission is send-only. Linkubit cannot read, search, store or delete anything in the mailbox through Google, and does not ask to; replies reach the Linkubit inbox only if the business chooses to forward them to us with a Gmail forwarding rule of its own. The address and the complaint rate are not shared with our AI model provider or any other subprocessor, are not used to train any model, are not used for advertising and are not sold, and are disclosed to nobody except Google itself. The same Limited Use commitment as above applies: our use of information received from Google APIs follows the Google API Services User Data Policy. Disconnecting the mailbox from Settings revokes the grant at Google and deletes the token, and access can also be removed from the Google account's third-party access settings at any time.
Meta Ads
Connecting Meta Ads uses Meta's own login, which asks the person to grant Linkubit access to manage ads on their ad account and read their Page. Meta gives us a token for that grant, stored and protected the same way as Google's, and we use it only for the things below.
- Reading the account's campaigns, ad sets, ads and daily spend across Facebook and Instagram placements, so the customer can see what each ad cost beside the leads and revenue it produced.
- Creating campaigns the customer builds in Linkubit. Everything we create starts paused; nothing spends until the customer switches it on.
- Reporting outcomes — a lead the customer qualified, a deal they won — to the dataset their own Page owns.
- Custom Audiences: keeping a Meta audience in step with a Linkubit audience. Only one-way hashes of an email address or phone number leave our system, only for people who have given marketing consent on that channel, and anyone suppressed is removed first.
We do not use data from a customer's Meta account for our own advertising, we do not sell it, and no person at Linkubit reads it except to support that customer at their request. It is not shared with our AI model provider or any other subprocessor, it is not used to train any model, and it is disclosed to nobody except Meta itself, as part of the four things above. Our use of information received from Meta APIs follows Meta's Platform Terms and Developer Policies. Disconnecting the account from Settings deletes the token; a customer can also revoke Linkubit's access from Meta Business Settings, and either way we can no longer reach the account.
5. How the AI agent uses your messages
WhatsApp, Instagram and Messenger are Meta's platforms: every message on them passes through Meta to reach us, the same way it would for any business using those channels, under Meta's own Privacy Policy. When the business you are talking to has its AI agent switched on, the content of your message — and, for a voice note, its transcript — is sent to our AI model provider to produce a reply, transcribe it, or translate it between the languages we support. That provider does not train on it, keeps it only transiently, and receives nothing else about you.
6. How long we keep it
By default, indefinitely. We are not going to pretend otherwise: the value of a customer history increases with its length, and deleting it on a timer would degrade the product. A customer can set a retention period on their workspace — 12, 24 or 36 months — and a contact who has not been in touch for that long is then erased the way an erasure request erases them, in a daily sweep, with the same audit record. Whatever the setting, erasure on request always works regardless.
7. Erasure, and the one thing that survives it
When a contact is erased, we destroy the person: the contact record, every address we could reach them on, their consent history, their conversations, their messages and their activity.
Billing references are nulled rather than deleted, so usage totals already invoiced do not change retrospectively. Every erasure is recorded in an audit log with who requested it and when. Encrypted backups keep a deleted record for up to 14 days and then it is gone from those too; a customer's own sign-in identity is held by our identity provider and deleted on request.
8. Your rights
Under India's Digital Personal Data Protection Act, and under the GDPR where it applies, you can ask for access to your data, correction of it, erasure of it, restriction of or objection to how it is processed, a portable copy of it, and withdrawal of any consent you gave.
The fastest routes are a data request for access, correction or erasure, and message preferences to stop marketing without deleting anything. Replying STOP to any message also works, in any language we support, and takes effect immediately.
A data request is confirmed by you first — through a link we email to the address, or a message you send us from your WhatsApp number — and is then passed to every business using Linkubit that holds that address. Each has 30 days to answer, and you can follow the request under its reference. If a business has not acted five days before the deadline, Linkubit erases the data or delivers the copy on its behalf, as our agreement with each business provides. A correction is always made by the business itself.
Our grievance officer under the DPDP Act is Anuj Yadav, reachable at help@linkubit.com with “Grievance” in the subject. We respond within 30 days. If you are not satisfied you may complain to the Data Protection Board of India, or, if the GDPR applies to you, to your own country's data protection authority.
9. Who we share it with, and where it lives
We do not sell personal data, to anyone, ever. Data leaves our system only to the processors named, by category and country, in the data processing addendum — each acting on our instructions, under contract, never for their own purposes — plus a customer's own connected mailbox, Google Ads or Meta account (section 4), a public authority where the law requires it (section 12), and, if Linkubit is ever acquired or sells its assets, the buyer, under the same commitments this policy makes.
Everything is stored in Mumbai, India, for every customer regardless of where they are. A small number of processors — our identity provider, our AI model provider, our hosting and its page-view analytics for this website — operate elsewhere, under the terms in the data processing addendum linked above.
10. How it is protected
- Tenant isolation is enforced by the database, not by application code. Every row carries its owner, row-level security policies are enabled and forced, and the application connects with a role that cannot bypass them. A bug in our code cannot show one customer another's data.
- Encrypted in transit and at rest
- Credentials for connected accounts are held in a secrets manager; the application stores only a reference
- Identities are only ever merged on an exact match — email, phone number, or a signed link token. We never guess that two people are the same person, and every merge is reversible
13. Changes
Material changes will be announced in the product before they take effect. The date at the top of this page is when it last changed.
14. Contact
help@linkubit.com · Adhiti Consulting Pty Ltd, NSW, Australia. A postal address is provided on request.