Privacy policy
In plain language: we collect what we need to run LINC: who you are, your organization and websites, a record of what you acknowledged, and where to pay you. The RSL Collective receives your websites and the ids of your acknowledgements, never your name, email address or bank details. Your channel partner sees your account. We do not sell personal data or use it for advertising. You can ask to see or correct your data, or to delete it where the law lets us, at licensing@joinlinc.com.
This policy explains what personal data IntentBridges collects through LINC, both the LINC app and the joinlinc.com website, how we use it, who we share it with, and the choices you have. LINC is a service for businesses, so most of what it holds is business information. The personal data in it is mostly about the people who use LINC for a publisher or a channel partner, and the people named as a publisher's contact.
1. Who we are
LINC is operated by IntentBridges Pte. Ltd. (UEN 202445703M), a company incorporated in Singapore. In this policy, “IntentBridges,” “we” and “us” mean that company. We decide how and why personal data in LINC is used, and we are responsible for it under Singapore's Personal Data Protection Act 2012 (PDPA).
IntentBridges is an Enrollment Partner of the RSL Collective. Publishers, which are businesses that own websites, use LINC to enroll their websites with the RSL Collective, which licenses their content to AI companies, and to receive what the RSL Collective allocates to them. Channel partners can manage publishers' accounts in LINC for them.
You can contact our Data Protection Officer about this policy or your personal data using the details in section 16.
2. Who this policy covers
This policy covers personal data about:
- people who sign in to LINC: staff of publishers, staff of channel partners, and our own staff;
- people invited to LINC;
- people named as a publisher's contact;
- people who register interest on the joinlinc.com website; and
- anyone who visits LINC's pages or the website.
It does not cover how the RSL Collective, AI companies or a channel partner handle data outside LINC. Their own policies apply to that.
3. What we collect
Registering interest on joinlinc.com
When you register interest on joinlinc.com, we collect your organization or publisher name, your first and last name, your work email, your website or domains, your country or market, anything you choose to tell us, and that you agreed to the Publisher Registration Terms. We use these details to assess fit, reply to you and contact you about licensing opportunities, as those terms describe. The form sends them to our customer relationship management service, Zoho CRM (section 7).
Your account
When you sign in, we receive your email address. LINC has no passwords: you sign in with Google, or with a sign-in link we email you.
If you continue with Google, Google also tells us your name and that your email address is verified. Google also sends your Google account ID and a link to your profile picture. LINC does not use the picture. If you register a publisher, the name you give there replaces the name from Google.
Our authentication provider, Supabase, keeps your sign-in identity: your email address, when it was confirmed, what Google sent, and your sessions.
Your organization
We record which organization you belong to (a publisher, a channel partner or LINC) and your role in it.
Publisher and contact details
When a publisher registers, we collect its company name and main website, and the name and email address of the person registering. When a channel partner invites a publisher, the partner gives us the same details for the publisher and its contact person. Where given, we also keep the publisher's country and the contact person's job title. A channel partner that gives us someone's details must be entitled to do so and must tell them about this policy.
Invitations
When a channel partner or our staff invite someone, we keep the invited email address, the details the inviter entered (such as a publisher's name, website, contact name and service fee), who sent the invitation and when, and when it was accepted or canceled. An invitation expires after 30 days.
We store an invitation's secret code only as a hash, which cannot be turned back into the code. The code itself is part of the invitation link, so it is in the invitation email and in our hosting provider's request logs, and it is shown once to the person who sent the invitation. We hold it with the queued email only until the email is sent. If you open an invitation link while signed out, a cookie holds the code for up to an hour (section 12).
Websites and the checks we run
For each website a publisher adds, we keep its address, the licensing terms set for it in LINC, its state, who added it and when, and the results the RSL Collective returns for it.
LINC's checker reads each website's public robots.txt file and the RSL license file it points to or, when there is none, /rsl.xml and /license.xml. It does this when a website is added, when someone selects Check now, and once a day for every website LINC may send to the RSL Collective, including websites of publishers that have not yet acknowledged LINC's authorization. It identifies itself with a User-Agent that starts with LINC-Checker. We keep what each check found (whether it passed, and the values it saw), when it ran and who ran it, but not the files themselves. LINC does not crawl a website's pages or content.
Acknowledgement records
When a member of a publisher selects Acknowledge, to give LINC's authorization or to confirm the publisher's rights to its websites, we record:
- who acknowledged: their user account, and their name or, if no name is set, their email address;
- the date and time of the click, in UTC;
- the IP address the request came from;
- the version of the wording shown;
- for the authorization, the channel partner and service fee in effect at that moment; and
- for rights, the websites covered and whether the acknowledgement reclaims a website.
Bank account details
We keep the account holder, bank name, account number or IBAN, and SWIFT/BIC code a publisher gives for its payments, with who saved them and when. When a publisher replaces its bank account, we keep the old one, marked as replaced. If an account is in a person's name, for example a sole trader's, these details are personal data.
Settlement and payment information
The RSL Collective sends us settlement and payment files. They show what it allocated to each publisher, by licensee (the AI companies it licenses) and licensing pool, and what it paid us. From them we record each publisher's allocations, fees, payments, corrections and statements, and our bank references. This is business information, but it is personal data where a publisher is an individual.
Activity history
Each publisher's account has an activity history: what happened (for example, a website added, rights confirmed, terms saved, a check, a service fee change, the bank account updated, or a result from the RSL Collective), when, and who did it, by name or, for someone with no name in LINC, by email address. When a channel partner's user acts, the partner's name is shown with theirs, and when our staff act, LINC's name is. Bank details never appear in the activity history.
Emails we send
We keep a copy of each email LINC queues: the recipient's address, the subject and text, when it was sent, and any delivery error. LINC emails the addresses that members of an organization sign in with, or the address an invitation was sent to. Emails never contain bank details. Sign-in link emails are sent by our authentication provider, Supabase, and LINC keeps no copy of them.
Technical data
Our hosting provider logs requests to LINC, including IP addresses, browser details and the pages requested, along with error messages from our servers. Our authentication provider logs sign-ins, including IP addresses. Our database keeps an audit log of privileged actions, such as each sign-in, changes to our staff's access, registrations, checks and emails sent, with the time, the user and a short detail such as an email address or a website. LINC uses only the cookies described in section 12.
The joinlinc.com website uses Cloudflare Web Analytics, which counts page visits without cookies and without identifying you. The website does not set cookies.
4. How we use it
We use personal data to:
- sign you in, keep your account secure, and decide what you can see and do, for example whether you are our staff and which invitations are for you;
- register publishers, check their websites, and enroll eligible websites with the RSL Collective;
- keep evidence that a publisher authorized LINC, agreed to its channel partner acting for it, and confirmed its rights to its websites;
- calculate fees, record what the RSL Collective paid, pay publishers and channel partners, and issue statements;
- show each account its activity history, so everyone working on it can see who did what;
- reply to people who register interest on joinlinc.com, and contact them about licensing opportunities;
- send emails about the service: invitations, service fee changes, websites the RSL Collective skipped, and payments sent;
- keep LINC secure, investigate problems and fix errors; and
- meet our legal, accounting and tax obligations, and establish or defend legal claims.
We do not sell personal data, use it for advertising, or send marketing emails. The LINC app has no analytics or advertising trackers; the website's analytics are described in section 3.
5. Our legal bases
Under the PDPA, we collect, use and disclose personal data with consent, or without it where the PDPA allows. In practice:
- To provide LINC (your account, registering publishers, enrolling websites and payments): with the consent you are deemed to give when you provide your data for that purpose, including where it is reasonably necessary to provide LINC to the organization you use it for.
- For our legitimate interests (keeping acknowledgement records with the IP address as evidence, keeping the activity history and audit logs, keeping LINC secure, and establishing or defending legal claims): under the legitimate interests exception in the PDPA. We have assessed that these interests outweigh any likely adverse effect on you, taking into account the safeguards in section 6 and section 10, for example that IP addresses are never shown to channel partners. You can ask us about this assessment.
- To meet legal obligations: accounting and tax records, and requests from authorities that the law requires us to meet.
- With your express consent, where we ask for it. You can withdraw it at any time (section 11).
If the EU or UK General Data Protection Regulation (GDPR) applies to you, our legal bases are: performance of a contract where you are a party to it, for example as a sole trader (Article 6(1)(b)); otherwise our legitimate interest, and your organization's, in providing LINC to the organization you work for, together with the legitimate interests above (Article 6(1)(f)); legal obligation (Article 6(1)(c)); and consent where we ask for it (Article 6(1)(a)).
You need to give us your email address to use LINC. A publisher must give its company name, main website and contact details to register and enroll websites, and a publisher we pay directly must give its bank details to be paid; without them we cannot provide the service. LINC's automated checks decide whether a website is sent to the RSL Collective, based on the files the website publishes, not on any assessment of you. You can ask us to review a result.
6. Who can see your data in LINC
Inside LINC, what each person sees depends on their organization, and our database enforces it.
- Members of your organization see its account, including the name recorded against what each member did.
- A publisher's channel partner. While a channel partner is assigned to a publisher (from the invitation, if the partner invited it), and until the publisher withdraws LINC's authorization, the partner's users work inside the publisher's account for it. They see the publisher's details and contact, its websites and checks, its full activity history with names (including from before the partner was assigned), its acknowledgement records without IP addresses, money for the months the partner managed, the invitations the partner sent, and the publisher's current bank account in full, so that the partner can pay the publisher. After a channel partner stops managing a publisher, it keeps its own statements for the months it managed, which show the publisher's name and that month's allocation, fees and net.
- People who act in a publisher's account. The publisher's members and its channel partner see the name, or if no name is set the email address, of each channel partner user and member of our staff who acts in the account.
- Our staff who operate LINC can see everything in LINC, including copies of emails, except the IP address recorded with LINC's authorization and invitation codes.
The IP address recorded with a rights acknowledgement is shown to the publisher's members and our staff, in the record they can download. The IP address recorded with LINC's authorization is not shown to anyone in LINC. On LINC's screens, bank account numbers are shown masked to their last four digits, except to the channel partner that pays the publisher, which sees the current account in full. Our staff who make transfers can read full bank details in our database.
7. Who we share it with
The RSL Collective
To enroll websites, we send the RSL Collective a file every night with one line for each eligible website: the publisher's LINC id, its main website, the website's hostname, and the ids and dates of the publisher's acknowledgements. The file contains no names, email addresses, IP addresses or bank details. A website's address can identify a person if the website belongs to an individual.
The RSL Collective sends back its results for each website, and the settlement and payment information described in section 3.
Channel partners
A publisher's channel partner sees the data described in section 6. For a publisher with a channel partner, we pay the partner, and the partner pays the publisher.
Service providers
These providers handle data for us, to provide LINC:
- Supabase hosts our database, which holds all the data in LINC, and provides sign-in.
- Vercel hosts LINC, which runs in Singapore. Every request to LINC passes through its network, and it keeps our server logs.
- Cloudflare hosts the joinlinc.com website, and Cloudflare Web Analytics counts visits to it.
- Zoho provides Zoho CRM, where registrations of interest from joinlinc.com are stored and managed.
- Google provides Continue with Google. LINC's pages also load fonts from Google Fonts, so your browser sends your IP address and browser details to Google's servers.
- Resend sends LINC's emails, sign-in links included, and receives each recipient's address and the email's subject and text.
Banks
Banks process the transfers: the RSL Collective's payments to us, and our payments to publishers and channel partners.
Authorities and legal claims
We disclose personal data to courts, regulators, law enforcement or other authorities when the law requires it, and where needed to establish or defend legal claims.
Professional advisers
Our lawyers, auditors and accountants, who must keep it confidential, where they need it to advise us or audit our accounts.
Business transfers
If IntentBridges or LINC is merged, acquired or sold, we may disclose personal data to the other party, as the PDPA allows, and it may continue to use it as this policy describes.
We do not sell personal data, and we share it only as this section describes.
8. International transfers
IntentBridges is based in Singapore. Our database is hosted by Supabase in Singapore. Some recipients store or process data in other countries: Supabase, Vercel, Cloudflare, Google and Resend are based in the United States and operate worldwide; Zoho CRM on zoho.com stores data in the United States; the RSL Collective is based in the United States; channel partners may be in other countries, for example Japan; and banks process transfers in the countries where they and the recipient's bank operate.
When we transfer personal data out of Singapore, we take the steps the PDPA requires so that the recipient protects it to a standard comparable to the PDPA. For our service providers, that is their data processing terms. Transfers to the RSL Collective, channel partners and banks are made where they are necessary to provide LINC to you or your organization, for example to enroll your websites, to let your channel partner manage your account and pay you, or to make a bank transfer, as the PDPA allows.
If the GDPR applies to you, transfers to our service providers are covered by the European Commission's standard contractual clauses in their terms, or by an adequacy decision such as the EU-US Data Privacy Framework where a provider is certified under it. You can ask us for details of these safeguards.
9. How long we keep it
We keep personal data only as long as we need it for the purposes in section 4, or as long as the law requires.
- Acknowledgement records are kept while any website they cover is enrolled or any money for it is still to be paid, and then for at least 6 years, the limitation period for most contract claims in Singapore, or longer while a claim or dispute about them is open. They cannot be changed in LINC.
- Settlement, payment and statement records, and the bank accounts payments go to (replaced ones included), are kept for at least 5 years after the end of the financial year they relate to, as Singapore's Companies Act and Income Tax Act require, and for at least 6 years after the last payment they support.
- Copies of emails LINC sent are kept as a record of the notices we gave. They cannot be changed or deleted in LINC.
- Profiles, memberships, publisher details, websites, check results, invitations and the activity history are kept while your organization uses LINC, and after it stops, as part of the record of what was done in each account (see our Terms of service).
- Logs. Request and sign-in logs are kept by our hosting and authentication providers for the periods they set. Our own audit log of privileged actions, the records of each upload to the RSL Collective, and the addresses of websites removed from LINC are kept indefinitely.
LINC does not yet delete or anonymize personal data on a fixed schedule, and some of it cannot yet be deleted at all: a person who has acted in LINC, or a publisher that has acknowledged LINC's authorization, stays in it. Until that changes, we keep this data protected as section 10 describes. When we set periods after which we delete it, we will update this policy.
10. How we protect it
- Our database enforces who can see what: each organization sees only its own data, and a channel partner only the publishers assigned to it. Apart from that, only our staff who operate LINC can see data across accounts, and when LINC's own systems act outside the database's access rules, they log it.
- Data is encrypted in transit (HTTPS) and at rest by our database provider.
- LINC stores no passwords: you sign in with Google or an emailed link, and only a confirmed email address can sign in.
- Sign-in cookies cannot be read by scripts on the page, and on the live site they are sent only over encrypted connections.
- Bank account numbers are masked on LINC's screens, except to the channel partner that pays the publisher, and our staff who make transfers can read them in full. They never appear in emails or the activity history.
- LINC offers no way to change or delete acknowledgement records, and our database refuses any change to payment records.
No system is perfectly secure. If a data breach is likely to result in significant harm to the people affected, or affects 500 or more people, we will notify the Personal Data Protection Commission within 3 calendar days of assessing that it must be notified. If it is likely to result in significant harm to you, we will also notify you, unless the PDPA does not require it, for example because we have taken action that makes significant harm unlikely, or a law enforcement agency or the Commission tells us not to.
11. Your rights
Under the PDPA, you can:
- Ask for access to the personal data we hold about you, and how it has been used or disclosed in the past year.
- Ask for a correction of personal data that is wrong or incomplete. LINC has no screen yet for changing your name or contact details, so ask us. A publisher's members can replace its bank account themselves.
- Withdraw your consent to our collecting, using or disclosing your personal data, by giving us reasonable notice. We will first tell you the likely consequences: for example, we may no longer be able to provide LINC, enroll your websites or pay you. We will then stop collecting, using and disclosing the data for that purpose within a reasonable time, unless the PDPA allows us to continue without consent, for example to keep the records described in section 9.
You can also ask us to delete your personal data. The PDPA does not give a general right to deletion, but we will tell you what we can delete or anonymize, and why we must keep the rest. We cannot delete records we must keep (section 9), and LINC does not yet offer account deletion in the app.
If the GDPR or a similar law applies to you, you may also have the right to have your personal data erased, to restrict its processing, to object to processing based on legitimate interests, and to receive data you gave us in a portable format, in each case as that law provides.
To make a request, contact us (section 16). We may need to confirm who you are. We will respond to an access or correction request within 30 days; if we cannot, we will tell you within that time when we will. Correcting your data is free. We may charge a reasonable fee for an access request to cover our costs; if we do, we will tell you the amount before we proceed. When we correct your data, we also send the correction to any organization we disclosed it to in the past year that needs it, such as your channel partner. Where the GDPR applies, we respond within one month, which we may extend by up to two more months for complex requests.
If you are not satisfied with our response, you can complain to Singapore's Personal Data Protection Commission (PDPC) at pdpc.gov.sg, or to the data protection authority where you live.
12. Cookies
LINC uses only the cookies it needs to sign you in and keep it secure. It sets no analytics, advertising or third-party cookies, and stores nothing else in your browser, except as listed here.
- Sign-in cookies (named sb-…-auth-token, sometimes split into several parts) hold your session and keep you signed in for up to 400 days after your last visit. Signing out removes them. A similar cookie holds a one-time code while you sign in.
- linc_invite keeps an invitation's code for up to one hour when you open an invitation link while signed out, so that you can accept it after you sign in. It is deleted when you sign in.
Scripts on the page cannot read LINC's sign-in and invitation cookies. Because LINC needs these cookies to work, we do not ask for consent to them. You can block or delete cookies in your browser, but then you cannot sign in.
Every page loads its fonts from Google Fonts. That is a request from your browser to Google (section 7), not a cookie LINC sets.
13. Google user data
If you continue with Google, LINC asks Google, through our authentication provider Supabase, only for the openid, email and profile permissions. Google then gives us your Google account ID, your name, your email address and whether it is verified, and a link to your profile picture. LINC does not access your Gmail, contacts, calendar, files or any other Google data.
How we use it. We use your email address to sign you in, to decide which organization and invitations are yours, and to email you about LINC. We use your name to identify you in LINC: it is shown with what you do in your organization's activity history and acknowledgement records, which the people in section 6 can see, unless you give a different name when you register a publisher. We use your Google account ID only to link your Google sign-in to your LINC account. We do not use your profile picture.
How we store and share it. Supabase stores this data in our database, protected as section 10 describes. We share it only as section 6 and section 7 describe: inside LINC with the people who can see your name, and outside LINC with the service providers that run it, or where the law requires. We do not send it to the RSL Collective. We do not sell it, use it for advertising, or use it to develop, improve or train AI or machine-learning models.
How long we keep it. As section 9 describes; your name stays on acknowledgement records you gave for as long as they are kept. You can remove LINC's access to your Google account at any time at myaccount.google.com/permissions; Google then asks for your permission again the next time you continue with Google. Removing access does not delete what LINC already holds; to ask us to delete it, contact us (section 16).
LINC's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
14. Children
LINC is a service for businesses and the people who work for them. It is not meant for anyone under 18, and we do not knowingly collect personal data from children.
15. Changes to this policy
We may update this policy. When we do, we will change the date at the top of this page. If a change is significant, we will email the members of each organization before it takes effect.
16. Contact us
For questions, requests or complaints about this policy or your personal data, contact our Data Protection Officer:
IntentBridgesIntentBridges Pte. Ltd.UEN 202445703MSingaporeEmail: licensing@joinlinc.com