Privacy Policy
Last updated: August 23, 2026
Este documento se publica únicamente en inglés. El texto en inglés es la versión vinculante y, si quieres ayuda con él en tu idioma, escribe a support@linkraze.com.
1. Introduction
The LinkRaze remote access platform is operated by LinkRaze Technologies Ltd., a private company registered in Israel under company number 517376554 ("LinkRaze", "we", "us", "our", or "Company"). LinkRaze Technologies Ltd. is the data controller responsible for the personal data described in this policy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, including the web dashboard, the desktop application, and related services (collectively, the "Service").
2. Information We Collect
Account Information: When you register, we collect your email address, full name, and any optional profile information you provide.
Device Enrollment Records: Before a computer can be accessed through a LinkRaze account, we may ask the person physically at that computer to confirm it. When we do, we record which version of the confirmation notice was shown, whether it was confirmed or declined, when, and the IP address the answer came from. We keep this because it is the only record of what the person at a computer was actually asked before access to it was granted, and it is what we rely on if that access is later disputed or reported as fraud.
Device Information: When a computer is added to a LinkRaze account, we record its hostname and a hardware fingerprint — a value derived from that computer's hardware that identifies it as the same physical machine across reinstalls. We use it to recognise a device already on your account, and to stop the same computer being added to a second account without the first one being told.
Session & Activity Data: We log session metadata including: start time, duration, devices involved, IP addresses, session tokens, and session lifecycle events (when a session starts, ends or reconnects, and why it ended). IP address logging for account and session actions is enabled by default; administrative and infrastructure actions always record the client IP address for security. This data helps us detect unauthorized access, troubleshoot issues, and enforce security policies.
What We Do Not Collect: We do not record what you do inside a remote session. Keystrokes, mouse input, screen contents, clipboard contents, and transferred files are end-to-end encrypted between your browser and your own device — our servers pass them through without the keys to read them, so we cannot reconstruct, replay or hand over your session activity. We log that a session happened, not what happened in it.
Payment Information: We do not collect or store your full card number or security code — card entry happens entirely within Paddle's payment form and is never visible to us. Payments are processed by Paddle (paddle.com); we receive transaction confirmations, subscription status, and the limited card metadata contained in Paddle's transaction records (card brand, expiry date, and the last four digits).
Fraud Prevention Records: If we determine that an account has been used for remote-access fraud, we record a block against the identifiers that account cannot cheaply replace: the hardware fingerprint of a computer involved, an IP address it was used from, and the customer reference our payment provider holds for its card. Each block records the account it was raised over, the reason, who raised it, and — if it is later lifted — when and why. We separately record which computers that account had added, when we warned the person at each of them, and whether that warning was acknowledged. We keep these records because a block that could be cancelled by deleting an account or removing a device would not be a block at all, and because the record of whom we warned is the only evidence that we acted.
Technical Data: Browser type, operating system, referring URL, and error logs to improve service reliability.
Cookies: We use session cookies (httpOnly, Secure, SameSite=Strict) to maintain your authenticated state. See our Cookie Policy below.
3. How We Use Your Information
We use collected data to:
• Provide and maintain the Service
• Process transactions and send transaction confirmations
• Send security alerts (unauthorized login attempts, password changes, new devices)
• Detect, investigate, and prevent fraud and unauthorized access
• Score accounts against fraud indicators drawn from the records described above — how quickly devices are being added, how often the person at a device declines or withdraws access, and whether one address or one computer appears across several accounts — to produce a queue for a member of staff to review. No account is suspended, restricted, or refused on the strength of that score alone.
• Limit how many devices an account that has not established a payment relationship with us may add, and hold that account's first connection to a newly added device for a short period
• Refuse access to the devices, addresses, and payment instruments recorded under Fraud Prevention Records above
• Refuse connections from countries we have chosen not to serve, or serve only countries we have chosen — the country is derived from your IP address using an IP-to-country database that we download and query on our own servers, so your address is never sent to that database's publisher. It tells us which country an address range is attributed to, which is coarse by design: it is not a precise location, and it does not identify you
• Show which country an IP address is attributed to, on the internal screens our staff use — to investigate a support request, a security alert, or a report of abuse, and to count how many of our marketing site's visitors came from each country. The country is derived the same way as in the bullet above: locally, on our own servers, from an address we have already logged — or, for the visitor counts, from the visitor's address at the moment the page view is recorded, which is discarded in the same step and never stored. It is shown only to our staff, and nothing is refused, restricted, or scored on the strength of it
• Warn the person at a computer, in a message shown on that computer, when an account that had access to it has been suspended for fraud — and tell a suspended account that its access has been suspended
• Send you occasional messages about your own account's setup — for example, that your account has no device on it yet, or that a device you added has not connected — each one sent at most once, describing a single next step. These are messages about the Service you signed up for, not advertising: they promote nothing and there is nothing to buy. Every one of them carries a one-click unsubscribe link, and opting out never affects your access to the Service or the mail your account needs, such as sign-in codes, password resets and security alerts
• Tell you, once, when an account has not been used for a long time — that it is still there, that keeping it costs you nothing, and how to delete it if you would rather not. We do not delete an unused account on your behalf. This notice carries the same unsubscribe link and the same promise about your access
• Record whether you asked, when you signed up, to hear from us about new features. We collect that answer so that it exists if we ever have something to offer; nothing in the Service currently sends anything on the strength of it, and the messages described in the two bullets above are not sent on the strength of it either
• Improve service performance and reliability
• Comply with legal obligations (law enforcement requests, court orders)
• Enforce our Terms of Service and other agreements
4. Data Retention
Account data is retained for the duration of your account. After account deletion or termination, personally identifiable information is permanently deleted within 30 days, except:
• Session logs are retained for 90 days, then summarized into aggregate usage statistics and deleted (security and compliance)
• Audit trail entries (account and security actions) are retained for 180 days (security and compliance)
• Marketing site analytics events (see Section 5) are retained in raw form for 180 days, then deleted; the daily aggregate counts derived from them (page views, signups, and similar totals) are kept indefinitely for trend reporting
• Fraud prevention records (see Section 2) are retained indefinitely, including after the account they relate to is deleted (fraud prevention, and evidence of the warnings we issued)
• A record that you asked us to stop sending the account messages described in Section 3 — or that a message to your address permanently failed, or was reported as unwanted — is retained indefinitely, including after the account it came from is deleted. It is stored as an irreversible cryptographic hash of the address rather than the address itself, so it can be checked against an address we are about to write to and cannot be read back as a list of people. We keep it because that is what honouring the request requires: an opt-out that expires, or that is erased along with the account, is one we would go on to ignore
• Transaction records are retained for 7 years (tax and financial compliance)
• Data required by law is retained for the period legally mandated
5. Cookies & Tracking
Session Cookies: We use httpOnly session cookies to maintain your login state in the web dashboard. These cookies are essential for the Service to function and are automatically set when you access the app.
Marketing Site Analytics: Our public marketing site uses first-party, consent-gated analytics to measure page views and signup attribution. This does not use cookies — it stores a random identifier in your browser's local storage, and a separate per-visit identifier in session storage — and only activates if you accept the cookie banner. We store a hashed IP address and coarse (country-level) location, never a raw IP address or precise location, and this data is never shared with or sold to third parties. We do not use any third-party analytics services (Google Analytics, Mixpanel, etc.) anywhere in the Service.
How We Recognise Where You Came From: If you accept the banner, we also record which channel brought you to the site — for example a link we published in a social media profile. This is worked out from information your browser already sends us: any tracking parameters on the address you arrived at (including click identifiers such as fbclid, igshid or ttclid, which the platform adds to the link, not us), the site you came from, and whether the page was opened inside a social app's built-in browser. That result — the channel, and nothing else about the link — is stored in your browser's local storage alongside the identifier above, is attached to the page views we record, and is passed to your account if you sign up. It is deleted from your browser together with the identifier if you withdraw consent.
Counted Links: Some links we publish (for example linkraze.com/go/ig) pass through our own server so that we can count how many people followed them, before sending you to the page. This runs before and regardless of the cookie banner, because it records nothing about you: no cookie is set, nothing is written to your browser, and no IP address — not even a hashed one — is stored. All that is kept is a running total per link, per hour, split only by whether the request looked like a phone, a computer or an automated crawler.
If you go on to create an account, the marketing-site events recorded under that identifier before you signed up are linked to your account, so that we can attribute the signup. If you withdraw consent, the identifier is deleted from your browser and is not carried into signup.
Cookie Consent: On your first visit, you will see a cookie consent banner explaining our cookie and analytics usage. By accepting it, or by continuing to use the app, you acknowledge the practices described in this section.
Your Rights: You can disable cookies in your browser settings, but this will prevent the Service from functioning properly (you will not be able to maintain a session). You may accept, decline, or change your choice on the marketing site analytics at any time using the "Cookie Preferences" link in the site footer, without affecting your ability to use the Service.
6. Your GDPR Rights (EU/EEA Users)
If you are in the EU/EEA, you have:
• Right of Access: Request a copy of your personal data
• Right to Rectification: Correct inaccurate data
• Right to Erasure ("Right to be Forgotten"): Request deletion of your data
• Right to Restrict Processing: Limit how we use your data
• Right to Data Portability: Export your data in a portable format
• Right to Object: Opt out of specific processing
The right to erasure does not extend to the fraud prevention records described in Section 2. We retain those to prevent fraud and to keep a record of the warnings we issued; everything else is deleted as described in Section 4.
To exercise these rights, visit your account settings → Privacy, or contact support@linkraze.com.
7. Your CCPA Rights (California Users)
If you are a California resident, you have:
• Right to Know: Request what personal information we collect
• Right to Delete: Request deletion of your personal information, except the fraud prevention records described in Section 2
• Right to Opt-Out: Opt out of "sales" of personal information (we do not sell data, but you can opt out of any data sharing)
• Right to Non-Discrimination: We will not discriminate against you for exercising these rights
To submit a request, email support@linkraze.com or visit account settings → Privacy.
8. Third Parties
Payment Processing: Paddle (paddle.com) handles all payments. Their privacy policy governs payment data.
Password Breach Checking: When you set a password, we check whether it appears in the Have I Been Pwned database of passwords exposed in public data breaches. Your password is never sent to them, and neither is your email address or your IP address. The password is hashed, and only the first five characters of that hash are used to fetch a set of several hundred candidate hashes; the comparison is then made against that set. Five characters identify a bucket of candidates, not your password. Your browser performs this check as you type, and our server repeats it when the password is saved. The request to Have I Been Pwned is made by our server, so they see our server, not you. If the check cannot be completed, your password is accepted anyway.
No Third-Party Sharing: We do not share, sell, or rent your personal information to third parties for marketing. We share data only:
• With service providers (payment processor, email sender) under data processing agreements
• With Have I Been Pwned, limited to the first five characters of a password hash, as described above
• When legally required (subpoena, court order, law enforcement)
• To protect the safety and integrity of the Service
9. Security
We implement industry-standard security measures:
• Video and audio streams are always end-to-end encrypted (AES-256-GCM); the encryption key is derived directly between your browser and your own device, our relay servers cannot decrypt your stream, and a session cannot be established without end-to-end encryption
• Keyboard, mouse, clipboard and file transfers are end-to-end encrypted on their own separate keys
• Our servers, relays and web app require TLS 1.2 or higher in transit; the real-time video and audio path is pinned to DTLS 1.2
• Password hashing (bcrypt, 12 rounds minimum)
• Multi-factor authentication, required by default on all accounts (authenticator app; email codes may also be enabled)
• Desktop installers are code-signed so your operating system can verify their origin and integrity before they run: Authenticode with a trusted timestamp on Windows, and an Apple Developer ID signature with a stapled Apple notarization ticket on macOS
• Audit logging of account and session activity
• Regular security assessments
However, no system is completely secure. We are not liable for unauthorized access resulting from user negligence or compromised credentials.
10. International Transfers
LinkRaze Technologies Ltd. is based in Israel, and our servers currently run in a single hosting region. As we scale, we plan to expand to additional regions (e.g. in Europe and the United States) for redundancy and lower latency; when that happens, your data may be processed and stored in whichever region serves your account. Regardless of where you access the Service from, your data may be transferred to and processed in Israel, where LinkRaze is operated.
If you are in the EU/EEA: the European Commission has recognised Israel as providing an adequate level of protection for personal data, so transfers of your data to Israel do not require any additional safeguard or your separate consent. If we later process your data in a region that is not covered by an adequacy decision, we will put an appropriate transfer mechanism in place before doing so.
11. Children & Minimum Age
LinkRaze is for adults only. You must be at least 18 years old to create an account or use the Service — this is a condition of use, set out in section 1.5 of our Terms of Service, not only a statement of who we design for.
The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. We do not ask for a date of birth: we rely on the confirmation you give when you create an account, and we act on what we learn afterwards.
If we learn that we hold personal information about someone under 18, we will delete that information and close the account without undue delay.
If you are a parent or guardian and believe your child has given us personal information, or you believe an account belongs to someone under 18, email support@linkraze.com. Tell us the email address on the account and we will act on it.
12. Contact Us
For privacy-related questions, requests, or complaints, contact the data controller:
LinkRaze Technologies Ltd. (company number 517376554)
Shoval 40, Alfe Menashe, Israel
Email: support@linkraze.com
You also have the right to lodge a complaint with your local data protection authority (DPA) in your country.