Privacy Policy
Last updated 29 September 2026
1. Overview
linkr is operated by Ladd & Associates Pty Ltd (ABN 44 661 701 060) of Bendigo VIC 3550, Australia. In this document "we", "us" and "our" mean Ladd & Associates Pty Ltd, and "you" means the person or business using linkr.
This policy explains what personal information we handle and how, and follows the Australian Privacy Principles in the Privacy Act 1988 (Cth).
We do not sell personal information, and we do not use click data to build advertising profiles.
2. What we collect from customers
If you subscribe, we collect your name, email address, business name and the card details needed to take payment. Card numbers go directly to our payment gateway and never reach our systems — we hold only a token, the card brand, its last four digits and its expiry.
We also hold the links you create: the destination, any label, and the short code.
3. What we collect when somebody clicks a link
This is the part most link shorteners describe vaguely, so here it is plainly. When a short link is followed we record the time, the code, the country the request appeared to come from, the referring page if the browser sent one, and the browser's user agent string. We also flag whether the request looked automated.
We do not store the full IP address of the person clicking, and we do not set a tracking cookie on the redirect.
Even without a name, this can be personal information under the Privacy Act — so we treat it as such rather than calling it "just analytics". It exists so a customer can see whether their link worked, and for nothing else.
4. Sensitive information
We do not seek sensitive information as defined by the Privacy Act, and ask you not to put any into a link label, a page title, or a linkr.bio page. A destination address is visible to us and to anyone who inspects the link.
5. How we use it
To operate the service — resolve links, render preview cards, show you your own click counts, and publish your linkr.bio pages.
To bill you, and to tell you when a payment has failed.
To detect and stop abuse, and to comply with the law.
To answer you when you contact us.
6. Who we share it with
Our service providers, and only so they can provide the service: Cloudflare (redirect and hosting), Salesforce (dashboard, portal and records), and National Australia Bank / Cybersource (payments).
Anyone we are required to disclose to by law, or where we reasonably believe it necessary to prevent a serious threat.
A purchaser, if the business is sold — on the same terms as this policy.
We do not disclose your click data to any other customer, and we do not tell a destination site who sent someone to it beyond what their browser sends anyway.
7. Where it is held
Records are held in Salesforce's Australian infrastructure. Link and click data is held by Cloudflare, which operates a global network — a request from Melbourne is normally served and recorded in Australia, but data may be processed in other countries as part of that network.
Where information goes overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, but you should know it may be held outside Australia.
8. How long we keep it
Link records are kept while your account is active and afterwards, because a retired code must never be reissued — the record is what enforces that.
Click records are kept while they are useful for your reporting and are trimmed periodically.
Billing records are kept for seven years, as tax law requires.
Sign-in codes are single use and cleared the moment they are used. Session tokens expire after fourteen days.
9. Security
Traffic is encrypted in transit. Card numbers never reach us. Access to customer records is limited to people who need it.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
10. Cookies
The redirect sets no cookies. linkr.au and linkr.bio pages set no advertising or tracking cookies.
The customer portal stores a session token in your browser so you stay signed in. It is readable only by the portal, and clearing your browser data removes it.
11. Access, correction and complaints
You may ask for a copy of the personal information we hold about you, or ask us to correct it, by emailing hello@laddandassociates.com. We will respond within a reasonable time and normally within 30 days.
If you are unhappy with how we have handled your information, tell us first and we will try to resolve it. If you are still unhappy you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. Children
The service is not directed at children and we do not knowingly collect their personal information. If you believe we have, contact us and we will delete it.