Privacy Policy - Linkup API
Last update : 28/02/2025
PRIVACY POLICY
1. WHO WE ARE
LinkupAPI ("LinkupAPI", "we", "us", "our") is a service operated by:
LINKUPAPI, SAS (societe par actions simplifiee)
Registered office: 58 Rue de Monceau, 75008 Paris, France
SIREN: 995 238 540 — SIRET: 995 238 540 00018
VAT number: FR51 995 238 540
Registered with the INSEE on December 1, 2025 and with the RNE (INPI) on December 19, 2025.
LINKUPAPI SAS is the data controller for the personal data described in this
policy. For any privacy-related request, contact us at privacy@linkupapi.com.
LinkupAPI provides an API that lets software developers connect messaging and
professional accounts (such as social networking accounts and email
mailboxes) and
programmatically send messages, read replies, and manage outreach on behalf of
the account owner.
2. SCOPE
This policy applies to:
- visitors of linkupapi.com and users of our dashboard;
- customers who create a LinkupAPI account and use our API;
- end users whose accounts (social networking accounts, Gmail, Microsoft
365, or other email
mailboxes) are connected to LinkupAPI through one of our customers'
applications.
It should be read together with our Terms of Use and Legal Notice.
3. DATA WE COLLECT
3.1 Account and billing data
- Name, email address, password (stored hashed), company information.
- Billing details and payment history. Payments are processed by Stripe; we
never store full card numbers.
- API keys and account settings.
3.2 Usage data
- API request logs (endpoint called, timestamps, status, credits consumed,
IP address, user agent).
- Technical logs needed to operate, secure, and debug the service.
3.3 Connected account data
When you (or an end user of your application) connect a third-party account to
LinkupAPI, we process the data strictly necessary to provide the requested
functionality:
- Authentication data: session tokens, OAuth access and refresh tokens, or
SMTP/IMAP credentials. These are encrypted at rest.
- Account metadata: email address or profile identifier of the connected
account, provider, connection status, sending health metrics.
- Message data: the content of messages sent through the API, and messages
read from the connected inbox (for example replies, delivery failure
notifications, and unsubscribe requests) when the customer uses inbox
features.
4. HOW WE USE DATA
We use the data described above to:
- provide, operate, and secure the LinkupAPI service;
- authenticate to third-party providers on the connected account's behalf and
perform the actions our customer requests through the API;
- meter usage, bill our customers, and prevent fraud and abuse;
- provide customer support;
- comply with legal obligations.
We do NOT sell personal data. We do NOT use the content of connected accounts
(emails, messages, contacts) for advertising, for profiling unrelated to the
service, or to train artificial intelligence or machine learning models.
5. GOOGLE USER DATA
Some LinkupAPI features let users connect a Gmail or Google Workspace mailbox
via Google OAuth, using the https://mail.google.com/ scope. This scope is
required because LinkupAPI accesses the mailbox over the standard SMTP and
IMAP protocols.
What we access and why:
- Sending email (SMTP): to send the messages that the user or our customer's
application explicitly requests.
- Reading email (IMAP): to retrieve replies to messages sent through
LinkupAPI, detect delivery failures (bounces), and detect unsubscribe or
opt-out requests, so that senders can honor them.
Limited Use disclosure:
LinkupAPI's use and transfer to any other app of information received from
Google APIs will adhere to the Google API Services User Data Policy
(https://developers.google.com/terms/api-services-user-data-policy), including
the Limited Use requirements.
In particular:
- We only use Google user data to provide and improve the user-facing
features described above.
- We do not transfer Google user data to third parties, except as necessary
to provide these features, to comply with applicable law, or as part of a
merger or acquisition with prior notice to users.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data, except (a) with the
account owner's explicit consent for support purposes, (b) when necessary
for security purposes such as abuse investigation, (c) to comply with
applicable law, or (d) on aggregated and anonymized data for internal
operations.
- We do not use Google user data to train generalized artificial
intelligence or machine learning models.
Google OAuth tokens are stored encrypted. Users can revoke LinkupAPI's access
to their Google account at any time from their Google security settings at
https://myaccount.google.com/permissions, and can request deletion of the
associated data as described in Section 9.
6. MICROSOFT USER DATA
Users can also connect a Microsoft 365 / Outlook mailbox via Microsoft OAuth
(SMTP.Send and IMAP.AccessAsUser.All delegated permissions). We apply the same
commitments as in Section 5: access is limited to sending messages and reading
replies, bounces, and opt-outs on the user's behalf; tokens are encrypted at
rest; we do not use Microsoft user data for advertising or model training.
Access can be revoked at any time from https://account.live.com/consent/Manage
or through the organization's administrator.
7. DATA SHARING AND PROCESSORS
We share personal data only with processors that help us run the service,
under data processing agreements:
- Hosting providers located in the European Union (infrastructure and data
storage).
- Stripe (payment processing).
- Transactional email providers (service emails to our customers).
- Anti-fraud, monitoring, and error-tracking tooling.
We may also disclose data when required by law, to protect our rights, or in
the context of a corporate transaction (with prior notice).
We never share the content of connected mailboxes or messaging accounts with
advertisers or data brokers.
8. DATA RETENTION
- Account and billing data: for the life of the customer account, then as
required by French accounting and tax law (up to 10 years for invoices).
- API logs: up to 12 months, then deleted or anonymized.
- Connected account tokens and credentials: until the connection is removed
by the user or customer, the account is deleted, or the token is revoked or
expires.
- Message data processed through the API: kept only as long as necessary to
provide the feature (delivery, inbox reading, webhooks), and at most for
the retention period of the associated API logs.
9. DELETION AND REVOCATION
You can at any time:
- disconnect a connected account via the API or dashboard, which deletes its
stored credentials and tokens;
- revoke LinkupAPI's access from your provider's security settings (Google:
https://myaccount.google.com/permissions; Microsoft:
https://account.live.com/consent/Manage);
- delete your LinkupAPI account from the dashboard or by writing to
privacy@linkupapi.com, which deletes the personal data associated with the
account except where retention is legally required.
Deletion requests are honored within 30 days.
10. SECURITY
We apply industry-standard measures to protect personal data, including:
- encryption in transit (TLS) for all connections;
- encryption at rest for authentication tokens and mailbox credentials;
- access controls and authentication on all internal systems;
- logging and monitoring of production access;
- periodic security reviews of our infrastructure and code.
No system is perfectly secure. If we become aware of a personal data breach,
we will notify the competent supervisory authority and affected users as
required by applicable law.
11. INTERNATIONAL TRANSFERS
Our infrastructure is hosted in the European Union. Where a processor is
located outside the European Economic Area, we rely on appropriate safeguards
such as the European Commission's Standard Contractual Clauses.
12. YOUR RIGHTS
Under the GDPR and French data protection law, you have the right to access,
rectify, and erase your personal data, restrict or object to its processing,
receive it in a portable format, and withdraw consent at any time where
processing is based on consent.
To exercise these rights, contact privacy@linkupapi.com. We may ask you to
verify your identity. You also have the right to lodge a complaint with the
French supervisory authority (CNIL, www.cnil.fr) or your local authority.
Where LinkupAPI processes end-user data on behalf of one of our customers
(acting as processor), we will direct your request to the relevant customer
or assist them in fulfilling it.
13. COOKIES
linkupapi.com and the dashboard use cookies strictly necessary for
authentication and session management, and privacy-respecting analytics where
applicable. We do not use advertising cookies.
14. CHILDREN
LinkupAPI is a professional tool and is not directed at children under 16. We
do not knowingly collect personal data from children.
15. CHANGES TO THIS POLICY
We may update this policy from time to time. Material changes will be
announced on this page with an updated "Last updated" date, and, for
significant changes affecting connected accounts, by email to our customers.
16. CONTACT
LINKUPAPI SAS
58 Rue de Monceau, 75008 Paris, France
privacy@linkupapi.com
Launch LinkedIn campaigns, scrape intent signals, and enrich profiles in seconds. All through one powerful API platform.
Endpoints
Uptime
Avg Response