Privacy notice
What this CRM stores, who can see it, and how long it keeps it.
What this is
The Linker Payments CRM is an internal tool. It is used by the Linker team to keep track of merchants, partners, contracts, leads and company finances. It is not open to merchants and has no public pages other than this one and the sign-in screen.
What it stores about the people who use it
Name, work email address, the roles they have been granted, and — so that sign-in works — a hashed password and a two-factor secret. Passwords are never stored in a readable form.
It also records every sign-in (when, and which browser and operating system), and a line for every change anybody makes: who, what, and when. That record is what makes it possible to answer “who changed this figure”.
What it stores about merchants, partners and leads
Business details (company name, address, website, what the business does) and the contact details of the person Linker deals with: name, email, phone.
For onboarding it records the state of each of the 14 checks a merchant has to pass, and where the corresponding document is kept — not the document itself.
Signed agreements and fee schedules are stored as PDFs, along with a note of who uploaded them and when.
What it never stores
- Card numbers, of anyone. Any field that is given something looking like one refuses it.
- Credentials for payment providers — API keys, webhook secrets. Those are configured on the Linker platform and never travel through here.
- Identity documents and proofs of address. The onboarding checklist records that they have been received and where they are held; the files stay outside this CRM.
Who can see what
Access is granted one area at a time — merchants, contracts, partners, leads, finances, settings — and somebody who has not been granted an area cannot open it or download anything from it. Granting and removing access is itself recorded.
Signing in requires a password and a code from an authenticator app. Both are mandatory for everyone; there is no way to switch the second step off for an individual.
How long it keeps things
A sign-in session lasts 14 days, then has to be renewed. Expired sessions are deleted 30 days later.
Everything else — merchants, leads, documents, the record of changes — is kept until somebody deletes it. There is no automatic deletion rule yet: what should be kept, and for how long, is a decision Linker has still to take, and this page will say so until it has been taken.
Asking about your data
If you work at Linker and want to know what the CRM holds about you, corrected or removed, ask the person who administers it — they can read every record and the log of every change.