Ink Link ("we", "us") operates Ink Link Studio, a cloud-based estimating studio for sign, wrap, and print shops. This policy explains how we collect, use, and protect your data, and the choices you have. We are based in the United States.
When your customers' contact info appears on the estimates and invoices you create, you are the data controller and we are the data processor — we handle that data only as needed to provide the Service to you.
| Category | What | Why |
|---|---|---|
| Account info | Name, email, phone, shop name, business type | Create and manage your account |
| Information you submit | Estimates, invoices, customers, materials, rate cards, and other job data you provide | Provide the Service |
| Payment info | Processed by Stripe — we never see your card number | Process subscriptions and invoice payments |
| Usage data | Pages visited, features used, device type | Improve the Service |
Authorized Ink Link staff may access your account data when strictly needed to deliver support you requested, investigate suspected abuse or security incidents, or comply with a legal obligation. We do not browse customer data for any other purpose.
We use the following services to operate the platform. Each receives only the data needed for its role.
| Service | Purpose | What they see | Privacy link |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All stored account and business data | supabase.com/privacy |
| Vercel | Application & site hosting | Runtime traffic, edge logs | vercel.com/legal/privacy-policy |
| Stripe | Subscriptions, invoice payments & customer portal | Billing info, card data (we never see card numbers) | stripe.com/privacy |
| Resend | Transactional email | Recipient email addresses + message contents | resend.com/legal/privacy-policy |
| Anthropic | Dot AI estimator (Claude) | Only the prompts you submit to the AI features | anthropic.com/legal/privacy |
We will notify users by email at least 30 days before adding a new sub-processor that materially changes how data is handled.
You have the right to:
For requests made by your customers about data you uploaded into the Service, you (the data controller) are responsible for handling them. We will help if asked.
If you are subject to GDPR or have customers in the EU/UK, you may request a Data Processing Agreement (DPA) by emailing us. We will return a signed copy on request at no charge.
We use the minimum storage needed to keep you signed in and remember your preferences. Specifically:
We do not use third-party advertising trackers, cross-site analytics, or fingerprinting. There is nothing to "accept" — the only items stored are what's needed to operate the Service.
We use industry-standard security measures: encrypted connections (HTTPS), hashed passwords (bcrypt), token-based authentication, and role-based access control. However, no system is 100% secure.
Breach notification. If we discover a security incident that affects your data, we will notify you by email within 72 hours of confirming the incident, with what we know at the time, what data was affected, and the steps we are taking. This aligns with GDPR Article 33 timing even where it does not strictly apply.
The Service is not intended for users under 18. We do not knowingly collect data from children.
We may update this policy. Material changes will be communicated via email. Continued use constitutes acceptance.
Privacy questions? Contact us at support@goinklink.com.