Account, authentication, and team data
User email addresses, roles, account identifiers, authentication cookies, API-key metadata, security stamps, and account-level settings.
Legal
Effective June 21, 2026. This policy explains how AssetLed Linkbuilding handles personal data in the website, API, Blazor app, worker jobs, reporting, and outreach workflows currently implemented in this product.
AssetLed Linkbuilding processes data needed to run account administration, asset-led link building operations, outreach, billing, reporting, and compliance workflows.
User email addresses, roles, account identifiers, authentication cookies, API-key metadata, security stamps, and account-level settings.
Submitted domains, normalized URLs, discovered linkable assets, prospect publisher domains, contact methods, outreach threads, message drafts, replies, suppressions, unsubscribe tokens, and live-link monitoring results.
Stripe checkout and subscription identifiers, Stripe customer id, Stripe subscription id, payment-method fingerprint, package quota, order status, integration usage costs, report share-link metadata, AI-visibility observations, Google impact snapshots, and performance summaries.
Application logs, job-failure records, rate-limit events, API request metadata, tenant-resolution data, email address, IP address, website URL, website domain, Stripe customer id, Stripe subscription id, and payment-method fingerprint used to protect the service and diagnose failures.
For card-required trial signup, cancellation, and upgrade workflows, AssetLed processes email address, IP address, website URL, website domain, Stripe customer id, Stripe subscription id, and payment-method fingerprint to detect and prevent repeated trial use, payment abuse, account evasion, and policy abuse without storing full card numbers.
AssetLed only sends data to configured providers when the corresponding feature is enabled or requested by an authenticated user or worker job. The public subprocessors page lists provider categories, purposes, data categories, transfer notes, and when each subprocessor is used.
Authenticated account users can use the compliance page to export account data, delete the authenticated account, and process unsubscribe tokens. Current users, former users, prospects, outreach recipients, and Google OAuth data subjects can submit deletion requests through the data deletion request page.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port personal data. Use the privacy request page for access/export, correction, deletion, unsubscribe, objection, or restriction requests. AssetLed may need to confirm account authority before acting on account-level data.
AssetLed retains data while needed to provide the service, maintain security, support billing and audit obligations, honor suppressions and unsubscribe records, and resolve disputes. Account deletion removes account-scoped operational data through the implemented compliance workflow while preserving records that must be retained for legal, security, billing, or abuse-prevention reasons. Public deletion requests can be submitted at data-deletion.
Production retention windows are seeded in SQL and managed through the authenticated privacy operations admin page with policy versioning, approval metadata, dry-run previews, cleanup run records, legal holds, and retention exceptions. The current baseline settings are:
Suppression records are governed separately by suppression settings because unsubscribe, bounce, complaint, and do-not-contact records protect recipients and prevent repeated outreach.
Security controls in the current solution include HTTPS redirection, HSTS in non-development environments, secure authentication cookies, API-key hashing with a configured pepper, role-based authorization, tenant checks, rate limiting, output-cache credential variation, SQL parameterization, Data Protection key-ring configuration, resilient outbound calls, and compliance export/delete endpoints. See Trust Center and Security Practices for the public control summary.
Submit privacy requests through privacy-request or send them to [email protected]. For security reports, use [email protected].