Privacy policy
What we collect, why, how long we keep it, and what you can ask us to do with it.
In force since September 13, 2026
1. The controller
For the data described below, the controller is 3m Spotsy, Istriei 34, Bucharest, Romania, tax code 44861010.
For any request about your data, write to gdpr@hotlink.ro. We answer within one month.
One distinction matters here: for your account data we are the controller. For the email addresses you collect through the form in your own menu, we are only a processor — you are the controller. See section 10.
2. What we collect and on what basis
| What | Why | Legal basis | How long |
|---|---|---|---|
| Name, email address, password (stored only as a hash) | Creating the account and signing you in | Performance of the contract | While the account exists, then 90 days |
| Business name, billing details | Issuing invoices and keeping accounts | Legal obligation | 10 years, under accounting law |
| Stripe payment identifiers | Managing the subscription | Performance of the contract | While the account exists, then 90 days |
| Your menu content: text, links, images | Publishing your page | Performance of the contract | While the account exists, then 90 days |
| IP address and browser, at sign-in | Account security and abuse limiting | Legitimate interest | At most 30 days |
| Traffic statistics for your page | Showing you what visitors tapped | Legitimate interest | At most 24 months |
| Messages you send us | Answering you | Legitimate interest | 2 years from the last message |
The legitimate interest relied on above is keeping the service secure, working and useful. You can object to this processing at any time, under section 8.
3. Statistics without cookies and without tracking
The statistics you see in the app — views, taps, device, source — are not obtained with cookies and do not build a profile of the visitor.
When someone opens your menu we compute a code from the IP address and the browser, mix it with a secret value that changes daily, and keep only the result. The code tells us it was the same person on the same day, and becomes useless the next. The IP address itself is not stored.
We do not track visitors across sites, we do not sell data, and there are no advertising network pixels on the public pages.
4. Cookies
We use only strictly necessary cookies — the ones without which the service cannot work. The law does not require consent for those, which is why you are not shown a cookie banner.
| Cookie | What it does | Lifetime |
|---|---|---|
| hl_session | Keeps you signed in | 30 days |
| hl_ws | Remembers the workspace you were last in | 1 year |
| hl_view_as | Our staff only, during a support check | 30 minutes |
The public menu pages set no cookies at all.
5. Who we share data with
We do not sell data. We share it only with the suppliers we need in order to run the service, each bound by contract to process it only on our instructions:
| Supplier | For what | Where they process |
|---|---|---|
| Stripe | Taking payments and invoicing | EU and US |
| Resend | Sending transactional email | EU and US |
| Our hosting provider | Running the application and the database | European Union |
We may also disclose data to authorities where the law obliges us, and to our legal or accounting advisers, who are bound by confidentiality.
6. Transfers outside the European Economic Area
Some of the suppliers above also process data in the United States. Those transfers rely on the Standard Contractual Clauses adopted by the European Commission or, where applicable, on the EU–US Data Privacy Framework.
You can request a copy of the applicable safeguards by writing to gdpr@hotlink.ro.
7. How long we keep things
The periods are those in the table in section 2. In short: account data goes 90 days after you close the account, accounting records are kept for 10 years because the law requires it, and statistics never exceed 24 months.
IP addresses used for abuse limiting are not stored as such: we keep only a code computed from them — enough to count attempts, not enough to reconstruct the address.
8. Your rights
In relation to your data you have the following rights:
- access — to find out what data we hold about you and receive a copy;
- rectification — to have what is wrong corrected;
- erasure, in the situations provided by law;
- restriction of processing;
- portability — to receive your data in a format you can take elsewhere;
- objection to processing based on legitimate interest;
- withdrawal of consent, where processing rests on it, without affecting processing carried out beforehand.
You exercise any of these by writing to gdpr@hotlink.ro. We do not require a particular form.
If your rights are infringed you may complain to the Romanian National Supervisory Authority for Personal Data Processing, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro. We would like you to write to us first, but that is not a condition.
9. Security
- passwords are stored as bcrypt hashes, never in the clear;
- sessions and reset links are stored as hashes too, so a copy of the database hands nobody a working token;
- a password reset link works once and expires within an hour;
- traffic is encrypted in transit;
- our team's access to data is limited to what is necessary, and every intervention on a customer account is recorded.
If a security breach occurs that could affect your rights, we notify you and the supervisory authority within the periods set by the regulation.
10. The data you collect
If you use the email capture form in your menu, the people who fill it in are giving their details to you, not to us. For that data you are the controller and we are the processor: we store it and make it available to you, without using it for any other purpose.
That means you are responsible for the basis on which you collect it, for informing those people and for answering their requests. The conditions under which we process it for you are set out in the Data Processing Agreement.
Our staff have no access to your contact list. Our internal console shows only how many addresses you have gathered, never which ones.
11. Changes to this policy
When we change it, we change the date at the top of the page. If the change is significant, we also email you.
Version in force since 13 September 2026.