Privacy Policy
Last updated: February 2026
Link Up ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our mobile application, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information We Collect
Account Information (required):
- Email address (for login)
- Name and username (displayed on your profile)
- Password (stored as a secure bcrypt hash — we cannot read your password)
Profile Information (optional, provided by you):
- Bio, interests, and availability status
- Profile photo (stored as a URL link)
- Home location (city/neighbourhood text only — not GPS coordinates)
- Social media links (Instagram, Spotify, Twitter, website)
- Profile prompts (e.g. "ideal weekend", "always down for")
Business Account Information (optional):
- Business name, category, address, phone number, website
- Operating hours, photo gallery, promotions
Plan & Activity Data:
- Plans you create, including: title, description, activity type, date/time, duration, location name, address, and GPS coordinates of the plan location
- Plans you join and your participation status
Messages:
- In-plan group chat messages are stored in plain text to provide the chat service
Technical Data:
- Push notification tokens (to deliver notifications to your device)
- Authentication tokens (to keep you logged in)
- Consent timestamp and version (to record when you agreed to these terms)
2. Information We Do NOT Collect
- We do NOT store your live GPS location. Location is only used in real-time to show nearby plans and is never saved to our database.
- We do NOT collect IP addresses
- We do NOT collect device IDs or fingerprints
- We do NOT use cookies or tracking technologies
- We do NOT collect analytics or usage tracking data
- We do NOT store your password in readable form
3. How We Use Your Information
- To provide the Link Up service: creating plans, joining plans, finding nearby activities
- To display your profile to other users
- To send push notifications about your plans (e.g. someone joined, plan cancelled)
- To enable in-plan group chat
- To allow you to find and connect with friends
- To enforce our Terms of Service (e.g. processing reports and blocks)
4. Lawful Basis for Processing (UK GDPR)
- Contract: Processing necessary to provide you with the Link Up service you signed up for
- Legitimate interest: Ensuring safety through user reporting and blocking features
- Consent: You consent to our data practices when creating your account (recorded with timestamp)
5. Information Sharing
We do not sell, rent, or trade your personal information. Your information may be shared as follows:
- With other Link Up users: Your name, username, profile photo, bio, and interests are visible to other users. Your email address is never shared with other users.
- With service providers who help us operate the app:
- MongoDB Atlas (database hosting)
- Render (server hosting)
- Expo (push notification delivery)
- Carto (map tile images — no personal data is shared)
- OpenStreetMap Nominatim (address search — no personal data is shared)
- Apple (Sign In with Apple authentication)
- When required by law, regulation, or legal process
- To protect the rights, safety, or property of Link Up or its users
6. Data Storage & Security
- All data is stored on MongoDB Atlas cloud servers
- All traffic is encrypted in transit via HTTPS
- Passwords are hashed using bcrypt (industry standard, irreversible)
- Authentication uses signed JWT tokens with a secure secret key
- Rate limiting is applied to prevent brute-force attacks on login and other sensitive endpoints
7. Data Retention
- Your data is retained for as long as your account is active
- When you delete your account, all your data is permanently deleted, including: your profile, plans you hosted, your participation in other plans, messages, notifications, friendships, blocks, group memberships, and push tokens
- User reports may be retained after account deletion for safety and legal purposes
8. Your Rights (UK GDPR)
Under UK data protection law, you have the right to:
- Access your data: You can export all your data at any time via Settings > Export My Data
- Rectification: You can update your profile information at any time
- Erasure (right to be forgotten): You can permanently delete your account and all associated data via Settings > Delete Account
- Restrict processing: You can control location permissions and notification preferences via your device settings
- Data portability: Your data export is provided in a machine-readable format
- Object: You can block other users to prevent them from interacting with you
- Withdraw consent: You can delete your account at any time, which removes all your data
9. International Data Transfers
Your data may be processed and stored on servers located outside the UK (MongoDB Atlas and Render use cloud infrastructure). These transfers are necessary to provide the service.
10. Children's Privacy
Link Up is intended for users aged 16 and over. We do not knowingly collect information from anyone under 16. If we become aware that we have collected data from a user under 16, we will delete their account and data promptly.
11. User-Generated Content
Other users may create and share content on Link Up, including but not limited to plans, events, activities, and communications. Link Up does not endorse, verify, screen, monitor, or assume any responsibility whatsoever for any user-generated content or the accuracy, safety, legality, or appropriateness of activities organized by other users.
You acknowledge that you may be exposed to content that is inaccurate, offensive, or otherwise objectionable. You agree to exercise appropriate caution and judgment when participating in any meetups, events, or activities arranged through the platform. Your participation in any such activities is undertaken entirely at your own risk.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the app. Your continued use of Link Up after changes are posted constitutes acceptance of the updated policy.