This document describes what BZLink.io, a service of Pedro Belly, does with the data of three groups of people: the businesses that have an account, the visitors who open a profile, and the people who pay a business from its profile.
It is written to describe what the system actually does, not what these documents usually say. If something here does not match what you see, that is our mistake and we want to hear about it.
1. If you have an account
For your account to exist we store:
- Your name, your email and your username.
- Your password, always hashed one way. We do not store it in the clear and we cannot read it or recover it, only replace it.
- If you sign in with Google or Apple, the identifier that provider gives us to recognise you. We never receive your Google or Apple password.
- Your plan, your subscription status, and the customer and subscription identifiers Stripe returns to us.
- The language you use the site in, so our emails reach you in that language.
- The date and IP address of your last sign-in. It is there so you can notice an access that was not yours.
Everything you type into your profile (business name, services, prices, hours, promotions, photos, logo) is stored so we can publish it. That content is public on purpose: anyone with your link or your QR code can see it, with no account and no sign-in.
2. Cookies: there are three, and none of them is for advertising
| Cookie | What for | How long |
|---|---|---|
qrp_sid | Keeping your session open. It only exists if you signed in. | Until you sign out or the session expires |
bz_lang | Remembering whether you chose Spanish or English. | 1 year |
bz_ap | Checking that the return from "Sign in with Apple" is the same browser that left. Only created if you use that button. | Deleted on return |
That is all of them. There are no third-party cookies, no cross-site cookies, and no analytics cookie at all.
3. How we measure visits, without cookies
We need to count visits so a business can tell whether its QR code is working. We do it without putting a cookie on anyone and without being able to recognise a person from one day to the next.
When someone opens a page, instead of storing their IP address, we combine it with their browser and with a secret key that changes every day, and store only the scrambled result of that combination. That daily key is deleted after two days, so after that there is no way to redo the calculation, not even for us.
The consequence, which is deliberate: within a single day we can tell that two pages were seen by the same visitor, and the next day we cannot. We cannot follow you across sites, we cannot build a history of you, and we cannot tell whether you came back.
For each visit we store the page, the date and time, how many seconds it was visible, the device type, the operating system, the browser, the language, the domain you arrived from if your browser sends it, and the campaign parameters in the address if you came from one of our ads. We also flag whether the visitor is a search engine robot, so we can discount it.
The business owner is shown these numbers in aggregate, never data that identifies a visitor, because we do not have any.
Today these records are kept with no automatic deletion. We are putting a retention limit in place; until it exists, that is the real situation and we would rather say so.
4. Advertising: where yes and where no
We use the Meta pixel to measure our own campaigns, and only on our own sales pages: the home page, the sign-in screen and the checkout.
Business profiles do NOT carry the Meta pixel or any other third-party tracker. Someone scanning a barber shop's QR code is that barber shop's customer, not a prospect of ours. A profile page only loads code from our own domain, and you can verify that by viewing the page source.
When someone signs up or pays, we send Meta the fact of the conversion together with their email hashed one way, never in the clear, so that Meta can attribute the sale to the right campaign.
We also do not load fonts or libraries from Google's servers: all of that is served from our own domain, so opening any BZLink.io page does not generate a single request to Google.
5. The Google rating shown on a profile
When a profile shows a Google rating, that number was typed in by hand by the business owner, and the link goes to their real listing so you can check it. We do not call any Google API, we do not store reviews, and we receive no data from Google about you.
6. Payments
Your subscription
Charged by Stripe. You give your card details directly to Stripe: we never see or store the full number, the expiry date or the security code. On our side all that remains are the identifiers Stripe returns, the plan and the payment status.
If you pay a business from its profile
That charge is also processed by Stripe, and the money goes to that business's account, not to ours. Your card details go straight to Stripe. We store the amount, the date, the charge identifier and the reference you typed (for example your name and what the payment is for), because without it the business cannot tell who paid. That business sees that reference.
Stripe handles that data under its own privacy policy.
7. Who we share data with
We do not sell personal data, and we do not hand it to third parties for their advertising. The providers we rely on to run the service are:
| Provider | What for |
|---|---|
| Stripe | Charging subscriptions and processing payments to businesses |
| Supabase | The database where everything lives, hosted in the United States |
| Hostinger | The site's server and email delivery |
| Meta | Measuring our campaigns, on the sales pages only |
| Google and Apple | Only if you choose to use their sign-in buttons |
We also hand over data if a competent authority requires it through a valid legal process.
8. Emails we send you
There are two kinds, and they are treated differently:
- Service emails (welcome, password reset, failed payment, renewal, cancellation notice): always sent, because they are part of having the account. You cannot switch off the notice that your card was declined.
- Recovery and news emails (for example the reminder that you left a payment unfinished): these carry an unsubscribe link, and using it stops that kind of email. The same link also undoes it.
We keep a record of which email we sent you and when, so we do not send you the same one twice and so we can answer you if you ask whether it arrived.
9. Your rights
You can ask us at any time to:
- Give you a copy of the data we hold about you.
- Correct something that is wrong. Most of it you can correct yourself from your panel.
- Delete your account.
Exactly what happens when an account is deleted. The profile, the photos you uploaded, and that profile's visits and clicks are deleted. It is permanent and there is no backup we can hand back.
The only thing we keep is the records of payments that actually happened, with the name and email you had, because they are part of our accounting and deleting them would falsify the figures of months already closed.
If you are in California, you also have the rights the CCPA gives you, including the right to know what data we hold and to ask us to delete it. We do not sell personal data, so there is nothing to opt out of in that respect.
10. Minors
BZLink.io is for businesses. It is not directed at anyone under 18 and we do not knowingly collect data from minors. If we learn that an account belongs to a minor, we close it.
11. Security
The whole site is encrypted in transit. Passwords are stored hashed one way. Access to the database is restricted and the tables are not reachable from the internet.
Even so, no system is invulnerable. If a breach ever affects your data, we will tell you.
12. Changes
If we update this document we change the date at the top, and if the change is significant we email you.
13. Contact
To exercise any of these rights, or to ask anything about this document, write to legal@bzlink.io.