Looking for Data API --> DataForB2B.ai
Looking for a People & Company Search API? Check out our partner DataForB2B.ai

Privacy Policy - Linkup API

Last update : 28/02/2025

PRIVACY POLICY

1. WHO WE ARE

LinkupAPI ("LinkupAPI", "we", "us", "our") is a service operated by:

LINKUPAPI, SAS (societe par actions simplifiee)
Registered office: 58 Rue de Monceau, 75008 Paris, France
SIREN: 995 238 540 — SIRET: 995 238 540 00018
VAT number: FR51 995 238 540
Registered with the INSEE on December 1, 2025 and with the RNE (INPI) on December 19, 2025.

LINKUPAPI SAS is the data controller for the personal data described in this
policy. For any privacy-related request, contact us at privacy@linkupapi.com.

LinkupAPI provides an API that lets software developers connect messaging and
professional accounts (such as social networking accounts and email
mailboxes) and
programmatically send messages, read replies, and manage outreach on behalf of
the account owner.

2. SCOPE

This policy applies to:
- visitors of linkupapi.com and users of our dashboard;
- customers who create a LinkupAPI account and use our API;
- end users whose accounts (social networking accounts, Gmail, Microsoft
 365, or other email
 mailboxes) are connected to LinkupAPI through one of our customers'
 applications.

It should be read together with our Terms of Use and Legal Notice.

3. DATA WE COLLECT

3.1 Account and billing data
- Name, email address, password (stored hashed), company information.
- Billing details and payment history. Payments are processed by Stripe; we
 never store full card numbers.
- API keys and account settings.

3.2 Usage data
- API request logs (endpoint called, timestamps, status, credits consumed,
 IP address, user agent).
- Technical logs needed to operate, secure, and debug the service.

3.3 Connected account data
When you (or an end user of your application) connect a third-party account to
LinkupAPI, we process the data strictly necessary to provide the requested
functionality:
- Authentication data: session tokens, OAuth access and refresh tokens, or
 SMTP/IMAP credentials. These are encrypted at rest.
- Account metadata: email address or profile identifier of the connected
 account, provider, connection status, sending health metrics.
- Message data: the content of messages sent through the API, and messages
 read from the connected inbox (for example replies, delivery failure
 notifications, and unsubscribe requests) when the customer uses inbox
 features.

4. HOW WE USE DATA

We use the data described above to:
- provide, operate, and secure the LinkupAPI service;
- authenticate to third-party providers on the connected account's behalf and
 perform the actions our customer requests through the API;
- meter usage, bill our customers, and prevent fraud and abuse;
- provide customer support;
- comply with legal obligations.

We do NOT sell personal data. We do NOT use the content of connected accounts
(emails, messages, contacts) for advertising, for profiling unrelated to the
service, or to train artificial intelligence or machine learning models.

5. GOOGLE USER DATA

Some LinkupAPI features let users connect a Gmail or Google Workspace mailbox
via Google OAuth, using the https://mail.google.com/ scope. This scope is
required because LinkupAPI accesses the mailbox over the standard SMTP and
IMAP protocols.

What we access and why:
- Sending email (SMTP): to send the messages that the user or our customer's
 application explicitly requests.
- Reading email (IMAP): to retrieve replies to messages sent through
 LinkupAPI, detect delivery failures (bounces), and detect unsubscribe or
 opt-out requests, so that senders can honor them.

Limited Use disclosure:
LinkupAPI's use and transfer to any other app of information received from
Google APIs will adhere to the Google API Services User Data Policy
(https://developers.google.com/terms/api-services-user-data-policy), including
the Limited Use requirements.

In particular:
- We only use Google user data to provide and improve the user-facing
 features described above.
- We do not transfer Google user data to third parties, except as necessary
 to provide these features, to comply with applicable law, or as part of a
 merger or acquisition with prior notice to users.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data, except (a) with the
 account owner's explicit consent for support purposes, (b) when necessary
 for security purposes such as abuse investigation, (c) to comply with
 applicable law, or (d) on aggregated and anonymized data for internal
 operations.
- We do not use Google user data to train generalized artificial
 intelligence or machine learning models.

Google OAuth tokens are stored encrypted. Users can revoke LinkupAPI's access
to their Google account at any time from their Google security settings at
https://myaccount.google.com/permissions, and can request deletion of the
associated data as described in Section 9.

6. MICROSOFT USER DATA

Users can also connect a Microsoft 365 / Outlook mailbox via Microsoft OAuth
(SMTP.Send and IMAP.AccessAsUser.All delegated permissions). We apply the same
commitments as in Section 5: access is limited to sending messages and reading
replies, bounces, and opt-outs on the user's behalf; tokens are encrypted at
rest; we do not use Microsoft user data for advertising or model training.
Access can be revoked at any time from https://account.live.com/consent/Manage
or through the organization's administrator.

7. DATA SHARING AND PROCESSORS

We share personal data only with processors that help us run the service,
under data processing agreements:
- Hosting providers located in the European Union (infrastructure and data
 storage).
- Stripe (payment processing).
- Transactional email providers (service emails to our customers).
- Anti-fraud, monitoring, and error-tracking tooling.

We may also disclose data when required by law, to protect our rights, or in
the context of a corporate transaction (with prior notice).

We never share the content of connected mailboxes or messaging accounts with
advertisers or data brokers.

8. DATA RETENTION

- Account and billing data: for the life of the customer account, then as
 required by French accounting and tax law (up to 10 years for invoices).
- API logs: up to 12 months, then deleted or anonymized.
- Connected account tokens and credentials: until the connection is removed
 by the user or customer, the account is deleted, or the token is revoked or
 expires.
- Message data processed through the API: kept only as long as necessary to
 provide the feature (delivery, inbox reading, webhooks), and at most for
 the retention period of the associated API logs.

9. DELETION AND REVOCATION

You can at any time:
- disconnect a connected account via the API or dashboard, which deletes its
 stored credentials and tokens;
- revoke LinkupAPI's access from your provider's security settings (Google:
 https://myaccount.google.com/permissions; Microsoft:
 https://account.live.com/consent/Manage);
- delete your LinkupAPI account from the dashboard or by writing to
 privacy@linkupapi.com, which deletes the personal data associated with the
 account except where retention is legally required.

Deletion requests are honored within 30 days.

10. SECURITY

We apply industry-standard measures to protect personal data, including:
- encryption in transit (TLS) for all connections;
- encryption at rest for authentication tokens and mailbox credentials;
- access controls and authentication on all internal systems;
- logging and monitoring of production access;
- periodic security reviews of our infrastructure and code.

No system is perfectly secure. If we become aware of a personal data breach,
we will notify the competent supervisory authority and affected users as
required by applicable law.

11. INTERNATIONAL TRANSFERS

Our infrastructure is hosted in the European Union. Where a processor is
located outside the European Economic Area, we rely on appropriate safeguards
such as the European Commission's Standard Contractual Clauses.

12. YOUR RIGHTS

Under the GDPR and French data protection law, you have the right to access,
rectify, and erase your personal data, restrict or object to its processing,
receive it in a portable format, and withdraw consent at any time where
processing is based on consent.

To exercise these rights, contact privacy@linkupapi.com. We may ask you to
verify your identity. You also have the right to lodge a complaint with the
French supervisory authority (CNIL, www.cnil.fr) or your local authority.

Where LinkupAPI processes end-user data on behalf of one of our customers
(acting as processor), we will direct your request to the relevant customer
or assist them in fulfilling it.

13. COOKIES

linkupapi.com and the dashboard use cookies strictly necessary for
authentication and session management, and privacy-respecting analytics where
applicable. We do not use advertising cookies.

14. CHILDREN

LinkupAPI is a professional tool and is not directed at children under 16. We
do not knowingly collect personal data from children.

15. CHANGES TO THIS POLICY

We may update this policy from time to time. Material changes will be
announced on this page with an updated "Last updated" date, and, for
significant changes affecting connected accounts, by email to our customers.

16. CONTACT

LINKUPAPI SAS
58 Rue de Monceau, 75008 Paris, France
privacy@linkupapi.com

LinkupAPI V2 - See what’s new

Launch LinkedIn campaigns, scrape intent signals, and enrich profiles in seconds. All through one powerful API platform.

50
+

Endpoints

99.9
%

Uptime

< 3
s

Avg Response