Privacy Policy
Draft for review · Effective date pending approval · Operated by CITTAM SYSTEMS (OPC) PRIVATE LIMITED (CIN: U62099KA2026OPC219975), 401/18, 15th A Main, 13th Cross, Venkateshwara Layout, BTM 1st Stage, Bengaluru 560068, India ("ČITTAM", "we", "us"). This policy covers čittam linkbook (linkbook.cittam.com) and the lb.cittam.com short-link resolver.
This product policy supplements the CITTAM platform Privacy Policy; for čittam linkbook specifically, this page governs.
The short version
linkbook is built so that we hold as little of your data as the product allows. Your imported file bytes are parsed in your browser; eligible extracted URLs may be sent to ČITTAM for metadata. We use limited, self-hosted anonymous product analytics and privacy-scrubbed reliability monitoring, show no ads, and do not sell personal data. We share personal data only as you direct, with the processors listed below to provide the service, or where the law requires it. A raw QR record opens its encoded URL without a ČITTAM redirect. Hosted links resolve through us and can have aggregate scan counts, without per-scan visitor records. Scanner apps and destination websites have their own data practices.
What we collect, and why
| Data | When | Purpose | Kept |
|---|---|---|---|
| Email address and name (if provided) | Account creation | Sign-in, essential service notices (e.g. retention reminders) | Until account deletion |
| Short-link records (slug → destination URL, creation date, owning account) | When you create a short link | Resolving your printed QR codes — permanence is the product | Indefinitely, by design (see "Deleting your data") |
| Aggregate scan counts (a number per short link) | On scans | Shown to you on your dashboard | With the short-link record |
| Anonymous page views and product milestones, controlled source/campaign labels, and referring website main domains | While you use linkbook, unless your browser sends Do Not Track. A source is recorded only on a fresh external arrival at an approved public product or guide page, when the browser provides an eligible referring website. | Understand aggregate acquisition, sign-in, creation, export, short-link, checkout, and install progress. Demo Print/PDF requests are counted separately and do not prove a saved file or physical print. Sign-ins include returning users and are not new-account counts. | Up to 90 days for anonymous events; source memory in the current browser tab lasts at most 30 minutes |
| Privacy-scrubbed error and performance diagnostics (error type, code location, stable failure code, route template, release/environment, status and timing) | When the app or service fails; performance timings are sampled | Find and fix failures that affect reliability, billing, sign-in, export, sync, and link resolution | Up to 30 days |
| Document backups (your saved link lists, as structured data) | Only with an active subscription, only when you choose to sync | Restore across devices | 90 days after subscription lapse, then deleted |
| Credit ledger (purchases, spends, balance) | On purchase or use of credits | Operating your ČITTAM wallet across čittam apps; accounting and tax compliance | As required by Indian accounting law |
Imported file bytes are parsed locally in your browser. When online, eligible extracted URLs, including their query parameters, can be sent to ČITTAM for titles and icons. Saving a document to Vault or publishing a share sends the resulting document data; saving generated PDF or HTML exports to Vault sends those exports. Importing a file does not automatically publish the original file.
What we deliberately do not collect
No advertising identifiers, third-party product analytics, session replay, screenshots, behavioural profiling, or
per-scan records. Anonymous analytics never include account IDs, email addresses, document content,
titles, destination URLs, or short-link slugs. Referrals are reduced to a public main domain, without subdomains, paths, queries, fragments or credentials; internal names and IP addresses are excluded. The observed referring website determines the source; source tags cannot override it. Only approved campaign names are retained, not arbitrary URL parameters. Tags alone, without an eligible referring website, do not establish a source. Reliability diagnostics also exclude those fields,
plus names, request and response bodies, cookies, authorization headers, and IP addresses. When a short link is scanned we increment a counter
and redirect — we do not store the scanner's IP address, user agent, or any identifier, and
redirects are sent with a no-referrer policy to suppress the referring URL. Destination websites still receive the request and apply their own data practices.
Infrastructure and abuse prevention — the honest caveat
Like virtually every internet service, we run on infrastructure (Cloudflare) that processes connection metadata, including IP addresses, transiently in order to deliver requests and block attacks. Our own abuse protection uses short-lived, automatically expiring rate-limit counters that may be keyed on IP address. These exist solely to keep the service up; they are never joined to your account, your short links, or scan counts, and we build no records from them.
Cookies and local storage
We use one essential session cookie to keep you signed in, and your browser's local storage to hold app settings, your cached session, and pending anonymous product milestones so linkbook keeps working offline. When offline, IndexedDB may also hold up to 30 already-scrubbed error reports until they are delivered or replaced. For acquisition measurement, session storage remembers the first eligible external source in the current tab for up to 30 minutes; another source does not replace it or extend that window. Reloading, restoring a page from browser history, navigating within ČITTAM, or returning from sign-in does not start a new window. After expiry, only another fresh external arrival with an eligible referring website can start one. Visits with a hidden referrer, including some email links, receive no new source credit; an existing unexpired source is preserved. It does not identify you across tabs, devices or later visits. Expired values are cleared when the tab can run or next reads them. Attribution is not written into the persistent offline event queue, so events retried after a page reload may be unattributed. Turning analytics off in the app configuration clears source memory; pending anonymous milestones can remain for later delivery without that source. Turning it back on does not recover the old source from the page URL. Do Not Track also clears pending milestones and prevents analytics delivery. Our self-hosted analytics are cookieless. We do not use third-party cookies or join your activity across sites.
Who processes data on our behalf
| Provider | Role | What they handle |
|---|---|---|
| Cloudflare | Hosting, CDN, security | Service delivery; transient connection data |
| Sentry (EU) | Error and performance monitoring | Privacy-scrubbed diagnostics only; no session replay |
| Cashfree Payments (India) | Payment processing, INR | Your payment details — we never see or store card or banking data |
| Dodo Payments (international) | Merchant of record outside India | Payment details and applicable tax handling |
| Apple App Store / Google Play | Mobile purchases | Per their own policies |
| Transactional email provider | Service emails only | Your email address, for sign-in and service notices — never marketing without consent |
We do not sell personal data. We share it only as you direct, with the processors above to provide the service, or where the law requires us to.
Your rights
Under India's Digital Personal Data Protection Act, 2023 — and equivalent laws where you live, such as the GDPR — you may access the personal data we hold about you, correct it, ask us to delete it, and raise a grievance about how it is handled. Write to privacy@cittam.com; we respond within 30 days.
Deleting your data
You can delete your account at any time. We then delete your email, profile, and any backed-up documents. One honest carve-out, because permanence is the product: short-link records (slug → destination) are dissociated from your identity rather than erased, so that QR codes already printed on paper keep working for the people holding them. If you want specific short links of yours to stop resolving entirely, tell us — we will disable them (they then return HTTP 410). Ledger entries are retained only as long as Indian accounting and tax law requires.
Security
All traffic is encrypted in transit (TLS). Backups are stored encrypted at rest on our infrastructure provider. Access to production data is restricted to what operating the service requires.
Children
linkbook is not directed at children. You must be 18 or older (or have a guardian's consent) to create an account or make purchases.
Grievance redressal
Grievance Officer: Jagadish — Grievance Officer, CITTAM SYSTEMS (OPC) PRIVATE LIMITED — grievance@cittam.com (or support@cittam.com), at the registered address above. Grievances are acknowledged within 24 hours and resolved within 15 days of receipt, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and applicable Indian law.
Changes
If this policy changes materially, we will notify account holders by email before the change takes effect, and the effective date above will be updated. We will never weaken the "no advertising tracking, no per-scan data" commitments quietly.