pr

Privacy Policy

Last updated on July 10, 2026

LinkMatch is a browser extension that helps recruiters and sales teams move professional profile information into their CRM or ATS. This policy explains what we do with personal data.


1. Who we are

Logical Pure Minds SRL, Strada Lazăr Vicol nr. 15, bl. E37, sc. A, ap. 47, Suceava 720245, Romania. Trade Registry J33/1494/2020 · VAT RO43302770.

Privacy questions: [email protected] · Security reports: [email protected]

2. Two kinds of data

Data about you, our customer. Your account, billing, support history and use of the extension. We are the controller of this. Sections 3 to 10 cover it.

Data you move through LinkMatch. The profile and CRM records of your candidates and prospects. You are the controller; we are your processor, acting on your instructions. Section 11 covers it.

We never use the data you process through LinkMatch for our own purposes. We do not sell it, build a contact database from it, or combine it across customers. We do not use it to train machine learning models, and the AI provider we use for certain product features does not train its models on it either.

3. How the extension works

LinkMatch supports professional networking platforms (the “Supported Platforms”). The extension operates only on the Supported Platforms and on the LinkMatch settings page. It does not read or transmit data from any other website you visit.

When you open a profile on a Supported Platform with LinkMatch active, the extension reads the profile information visible on that page and checks it against your connected CRM. Profile data passes through our servers in the European Union to perform that lookup. If you choose to save a record, the fields you selected are sent to your CRM. Nothing is written to your CRM unless you click to save it.

Matching cache. To keep lookups fast and reduce load on external services, we temporarily store a limited set of profile fields on our servers in the EU. This cache is isolated per customer: data cached for one customer is never served to another, and we never combine profile data across customers. Records expire 7 days after they are first stored, and that expiry is not extended when a record is viewed again. The cache is deleted immediately when you disconnect your CRM or close your account, and when you delete a record we remove it from the cache too.

Our handling of data received through the LinkMatch extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

4. What we collect about you

  • Account: name, work email, company, password (stored only as a salted hash)
  • Billing: billing address, VAT number, card brand and last four digits. Our payment processor handles card details, and we never see or store full card numbers
  • CRM connection: OAuth tokens, CRM instance URL, and for HubSpot an API access credential. These are encrypted at rest and deleted immediately when you disconnect or close your account
  • Usage and technical: features used, sync counts, errors, IP address, approximate location, browser and OS, timestamps
  • Support: whatever you send us in a ticket, email or demo call
  • Marketing: pages viewed, campaign source and cookie identifiers, subject to your cookie choices

LinkMatch is a business tool. We do not knowingly collect data from anyone under 16.

Purpose Legal basis
Running your account, providing the extension and syncs, support Contract
Billing, invoicing, VAT and accounting records Contract and legal obligation
Security, fraud prevention, debugging, monitoring Legitimate interests
Product analytics and improvement Legitimate interests
Emails to existing customers about our own products Legitimate interests, unsubscribe in every message
Marketing to non-customers; advertising cookies in the EU/UK; testimonials Consent
Legal claims and responding to legal process Legal obligation and legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights and concluded they do not override them; you can request a summary, and you can object (section 9). Where we rely on consent, you can withdraw it at any time without affecting earlier processing.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

6. Who we share it with

We do not sell your personal data or share it for third parties’ own marketing.

We share it with categories of service providers who help us run LinkMatch: hosting and infrastructure, payment processing, transactional and marketing email, customer support, website analytics, and AI processing for certain product features. A current, named list of these providers is available on request at [email protected]. Customers are notified by email at least 30 days before we add or replace any provider that handles customer data.

We also disclose data where required by valid legal process, where necessary in good faith to investigate fraud or protect the rights and safety of our users, and to a buyer as part of a merger, acquisition or sale of assets, in which case we will notify account holders in advance.

7. Where it’s stored

Your account data, and all profile and CRM data processed through LinkMatch, is hosted in the European Union.

One exception applies. Certain AI-assisted features are provided by a third-party AI provider whose processing takes place in the United States, under the EU-US Data Privacy Framework and Standard Contractual Clauses. That provider does not use the data to train its models. EU-based AI processing is available on our enterprise plans. Contact [email protected] to arrange it.

Some of our providers are established in the United States. Where personal data reaches them, we rely on the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses. A copy of the safeguards is available at [email protected].

8. How long we keep it

  • Account data: deleted within 30 days of account closure
  • CRM credentials: deleted immediately on disconnection or closure
  • Matching cache: 7 days from first storage, not renewed on access; deleted immediately on disconnection or account closure
  • Invoices and accounting records: 5 years, as required by Romanian Accounting Law 82/1991 (Art. 25). Annual financial statements: 10 years
  • Security and access logs: 90 days, retained for security monitoring, incident investigation and debugging. These record account identifiers, IP addresses, endpoints, timestamps and error codes, and do not contain profile or CRM record content
  • Usage statistics: deleted within 30 days of account closure
  • Support tickets: 365 days from resolution
  • Marketing contacts: until you unsubscribe, after which we keep a minimal suppression record

9. Your rights

You have the right to access, correct, delete, restrict, port and object to processing of your personal data, to withdraw consent, and not to be subject to solely automated decisions with legal effects. Your right to object to direct marketing is absolute.

Use the tools in your account settings or email [email protected]. It’s free. We respond to data export requests within 72 hours and to all other requests within 30 days, extendable by up to two months for complex requests as Article 12(3) permits. We may need to verify your identity.

If you’re unhappy with how we’ve handled your data, please tell us first, but you can also complain to a supervisory authority. Ours is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, Romania · [email protected] · www.dataprotection.ro. You may also complain to the authority where you live or work; in the UK, the ICO (ico.org.uk).

10. Cookies, security, and US privacy choices

Cookies. We use Google Tag Manager, Google Analytics and the Meta (Facebook) Pixel. The Meta Pixel may send Meta information about your visit, such as pages viewed and a hashed identifier, so we can measure advertising performance. In the EU, UK and EEA we ask for consent before any marketing cookie loads. Change or withdraw it via Cookie settings in the footer. In the US and elsewhere they run by default; opt out via Your Privacy Choices, and we honour the Global Privacy Control signal automatically. Full cookie list: linkmatch.com/cookies.

Security. All connections use HTTPS, with TLS in transit and encryption at rest for credentials, cached records and backups. We enforce multi-factor authentication on administrative and production systems, log and review access to production systems, apply role-based least-privilege access, run vulnerability scans and test backup restores quarterly, and bind everyone with access to personal data by confidentiality obligations. No system is completely secure and we cannot guarantee absolute security. If a breach affects your personal data we will notify ANSPDCP within 72 hours where Article 33 requires it, and notify you without undue delay where the risk to you is high.

US residents. You have rights to know, delete, correct, and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them. We don’t sell personal information for money; our Meta Pixel use may constitute “sharing” for cross-context behavioural advertising, which you can opt out of as described above. Authorised agents accepted with proof of authorisation.

11. Data you process using LinkMatch

For candidate and prospect data you move into your CRM, you are the controller and we are your processor.

You decide what to collect and why, you need a lawful basis for it, and you are responsible for giving those individuals the notice Article 14 requires, generally within one month of obtaining their data, or at first contact if sooner, and for handling their requests.

We process that data only on your documented instructions, keep it confidential, notify you without undue delay of any breach affecting it, help you respond to data subject requests, and delete or return it on termination. The full Article 28(3) terms, including sub-processing, audit rights and the Standard Contractual Clauses, are in our Data Processing Addendum, which is incorporated into our Terms of Use and applies automatically. A countersigned copy is available on request.

If you’re a candidate whose data is in someone’s CRM: we have no direct relationship with you and generally can’t identify which customer holds your record. Please contact the organisation that contacted you. If you can’t identify them, write to [email protected] and we’ll help where we can.

12. Changes

We may update this policy. For material changes, meaning a new purpose, a new category of recipient, a change of legal basis, a new international transfer or a longer retention period, we will email account holders at least 30 days beforehand, and ask for consent where consent is required. Other changes take effect on publication. Every version is dated above.

13. Contact

[email protected] · Logical Pure Minds SRL, Strada Lazăr Vicol nr. 15, bl. E37, sc. A, ap. 47, Suceava 720245, Romania.


LinkedIn® is a registered trademark of LinkedIn Corporation. XING® is a registered trademark of New Work SE. LinkMatch is an independent product and is not affiliated with, endorsed by, or sponsored by either company.