Free during launch, through October 10. We'll email you before billing starts. See pricing

Privacy Policy

Last updated September 9, 2026

This explains what LocalLinkMatch collects, why, who else sees it, and what you can ask us to do about it. We have tried to make it specific rather than generic, because a policy that could describe any website tells you nothing about this one.

Who is responsible for your data

Surf Sigma Inc., a corporation registered in Ontario, Canada, operates LocalLinkMatch and is the data controller for the information described here. You can reach us at support@locallinkmatch.com.

What we collect

Information you give us. Your email address and password when you create an account, or your name and email address from Google if you sign in that way. The websites you add, and the contact name and email address you want used for each one. Anything you write to us.

Information from the websites you submit. When you add a website we fetch the single public page at the address you gave us, and identify the services it offers and the places it operates in. We do not crawl the rest of the site. Alongside what we concluded, we keep what that one page returned, so that a wrong result can be investigated and corrected rather than argued about.

Payment information. Handled entirely by Stripe. Card numbers never reach our servers. We keep the subscription status, the amounts, and the invoice history that Stripe reports back to us.

Usage and technical information. Standard server logs, and website analytics if you have consented to them. See the cookies section below.

One thing we want to be explicit about because people reasonably assume otherwise: we do not extract email addresses from the websites we scan. Every contact address in the system was entered by a user and confirmed by clicking a verification link.

Why we use it, and on what legal basis

For anyone in the UK or the European Economic Area, the GDPR requires us to name a legal basis for each purpose. Ours are:

  • To provide the service (running your account, scanning your websites, producing matches, passing on connection requests, taking payment): performance of our contract with you.
  • To send service email (verification, approval, connection requests, and the match digest): performance of our contract, and your consent where the message is promotional. Every notification email can be turned off.
  • To keep the platform safe and working (reviewing submitted websites, preventing abuse, debugging failures, security logging): our legitimate interest in running a service that is not overrun by spam.
  • To meet legal obligations (tax and accounting records): compliance with law.
  • To measure website traffic using analytics: your consent, and nothing loads before you give it.

What other members can see

This is the part worth reading closely, because it is the only place your details are shown to someone else.

Once a website you added is approved, it can appear to other members as a potential match. What they see is deliberately not identifying: the general area, such as the city, and the kind of service. Not the business name, not the website address, not your contact email, and nothing about your other websites. The name is removed on our servers, so it never reaches anyone else’s browser at all.

Your details leave that state only when you send a connection request. At that point the member you chose receives your contact email address, and your website address and Google listing if you ticked those. It does not work in reverse: sending a request does not give you theirs. If they want to talk they reply to you by email, which is their decision to make. A sent request cannot be un-sent, which is why we say so before you send it.

Our terms forbid anyone using an address obtained this way for anything other than discussing that match.

Public posts from other websites

To find backlink and guest-post opportunities beyond our own members, we read public posts from a small number of Reddit communities where people openly ask for exactly that. From a post we keep its title, its text, its link, the community it came from, and the poster’s Reddit username. The text is sent to the same Google AI model described below, which works out what kind of business and location it concerns.

These posts are already public and were written to be found. We rely on our legitimate interest in surfacing relevant opportunities, and we use them only to show a member a post that matches their services and area. We do not contact posters, add them to any list, or build profiles of them. A surfaced post stops being shown after 30 days.

If you posted something we picked up and you would rather we did not hold it, email support@locallinkmatch.com with the link and we will remove it.

Links to other websites

Some of what we show links out to websites we do not run, including those Reddit posts and the sites of people you deal with. Once you follow one of those links you are on someone else’s website, under their privacy policy, not ours. We have not vetted them and we are not responsible for what they do with your information.

Who else processes your data

We use other companies to run parts of the service. They act on our instructions and may only use the data to do the job we hired them for. By category:

  • Hosting and infrastructure: Running the website and storing its data
  • Payment processing: Taking payment and managing subscriptions (Stripe)
  • Email delivery: Sending and forwarding the email the service depends on
  • Content analysis: Reading the page you submit to identify its services and locations, which includes an AI model operated by Google
  • Sign-in: Optional sign-in with a Google account
  • Analytics: Measuring website traffic, only where you have consented

One of these is worth calling out by name rather than leaving in a category. To work out what a submitted page is about, its content is sent to an AI model operated by Google, which returns the services and locations it identified. Payments are handled by Stripe, and card numbers go straight to them without passing through us.

These providers are in the United States. Where data is transferred out of the UK or the EEA, that transfer relies on the European Commission’s standard contractual clauses.

Cookies and analytics

Essential cookies keep you signed in and keep your session secure. They are required for the site to work at all and cannot be switched off.

Analytics cookies from Google Analytics tell us which pages people visit and where they arrived from. These are optional. Nothing analytics related loads until you accept it, and you can change your mind at any time using the cookie settings link in the footer.

We also verify the site with Google Search Console and Bing Webmaster Tools. Those report on how the site appears in search results and do not place cookies on your browser or collect anything about you.

We do not sell personal information, and we do not use it for advertising.

How long we keep it

  • Account and website data: for as long as your account is open. Delete a website and its details go with it. Close your account and we remove your personal data.
  • Scan records: the copy of page content we kept for troubleshooting is deleted along with the website it belongs to.
  • Connection requests: retained while both accounts exist, because they are a shared record between two parties and refunds depend on them.
  • Billing and tax records: seven years, as Canadian tax law requires. We cannot delete these on request.
  • Public posts we surfaced: shown to members for 30 days, after which they stop appearing.
  • Email and error logs: kept for a limited period for troubleshooting, then cleared.

Your rights

Wherever you are, you can ask us to show you the personal data we hold about you, correct it if it is wrong, or delete it. If you are in the UK or the EEA you also have the right to restrict or object to certain processing, to receive your data in a portable format, and to withdraw consent at any time without affecting what was done before you withdrew it.

Email support@locallinkmatch.com, or use the contact page. We will respond within 30 days. We do not charge for this, and asking will never affect your account.

If you are unhappy with how we handled your request, you can complain to the Office of the Privacy Commissioner of Canada, or, in the UK or EEA, to your local data protection authority.

Security

Data is encrypted in transit and at rest. Access to the production database is restricted, and the database itself enforces row level security so accounts cannot read each other’s data even if application code were to ask it to. Passwords are hashed and we never see them. No system is perfectly secure, and if a breach ever affects your data we will tell you and the relevant regulator as the law requires.

Children

LocalLinkMatch is for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.

Changes to this policy

If we change how we use your data in a meaningful way, we will email account holders before it takes effect. The date at the top of this page always shows when it last changed.

How to reach us

Questions about this document, or a request about your own data, go to support@locallinkmatch.com, or through the contact page. A person reads it.

We use cookies that are needed to keep you signed in, and we would like to use analytics cookies to see which pages people find useful. Analytics is optional and off until you accept. Privacy Policy