Legal
Privacy policy
What we collect when you use DiGi Links or click one of its links, why, how long we keep it, and the rights you have under the UAE’s Personal Data Protection Law and, in India, the Digital Personal Data Protection Act, 2023.
Last updated
The short version
- DIGI GROWTH IT SOLUTION L.L.C, a company registered in Dubai, UAE, is responsible for your personal data. Our servers may be outside your country.
- We collect what we need to run your links: your account, your links and numbers, and basic click analytics.
- We never store visitors’ IP addresses with click data. Unique visitors are counted with a keyed, one-way hash.
- We never see your WhatsApp chats. They happen inside WhatsApp, between you and your customer.
- Payments go through Razorpay. We never see your full card number or UPI PIN.
- We don’t sell personal data or use it for advertising, and we set no advertising cookies.
- You can access, correct and delete your data at any time by writing to [email protected].
This summary is here to help you read the full text below. If anything differs, the full text applies.
1.Who we are
DiGi Links is operated by DIGI GROWTH IT SOLUTION L.L.C (“we”, “us”), a limited liability company registered in Dubai, United Arab Emirates, under trade licence no. 1515657, with its registered office at Office 504, Ghaith Saeed Khalaf Al Ghaith Building, Al Barsha 1, Dubai, United Arab Emirates.
For the personal data described in this policy we are the controller under the UAE’s Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) and, for users in India, the data fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). The exception is click data we process on behalf of the businesses that own the links, as explained in link owners and their visitors.
For users in India this policy also follows the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Where another country’s data protection law applies to us, such as the GDPR, we follow it too. Questions go to [email protected].
2.Who this policy covers
- Customers: people who sign up, belong to a workspace or pay for a plan.
- Visitors to our website, including people who use the contact or report forms.
- Link visitors: people who click or scan a DiGi Links link that a business shared, before they are sent on to WhatsApp.
3.Information we collect
Account information
Your name, email address and password when you sign up. We store the password only as a salted one-way hash, never in readable form. If you choose to sign in with Google, we receive your name, email address and profile picture from Google. We also keep your sign-in sessions and the workspaces and roles you have.
Workspace and link information
What you and your team put into a workspace: its name, link names and titles, the phone numbers that chats go to and their labels, routing rules (business hours, countries, sources), pre-filled messages, notes, tags, time zone, and the email addresses of people you invite. Link passwords are stored only as one-way hashes. Phone numbers of your team are personal data: add a number only if its user has agreed.
Click information about link visitors
When someone opens a DiGi Links link, we record:
- the time of the click and which link was opened;
- the visitor’s country, looked up on our own servers from a local IP-location database; the IP address isn’t sent to anyone else for this;
- device type, operating system and browser, read from the browser’s user-agent;
- the referring website or app and the traffic source, for example Instagram or a QR code;
- which number and message version the visitor got, and the chat code if the link uses one;
- a visitor ID: a keyed, one-way hash of the IP address and browser. It lets us count unique visitors and keep a returning visitor with the same teammate, and it can’t be turned back into an IP address;
- whether the click came from a bot or a link-preview fetcher, so it can be left out of the numbers.
We never store IP addresses with click data
A visitor’s IP address is used for a moment to find the country and compute the visitor ID, and is then discarded. We don’t learn the visitor’s name or phone number from a click, and we never see the WhatsApp conversation that follows.
Billing information
For paid plans: the billing name and business name, the billing address with its state or region and country, any tax ID you add (such as a GSTIN, VAT number or TRN), the billing email address printed on invoices, your plan and payment history, and the invoices we issue. Payments are handled by Razorpay. We receive only limited details from Razorpay, such as the payment method type, the payment status and reference numbers. We never see or store full card numbers, CVVs, UPI PINs or netbanking passwords.
Messages and reports you send us
What you write in the contact form (name, email, company, topic and message), in the report form (the link, the reason, your description and, if you choose to give it, your email address), and in emails to us.
Links you start on our homepage
If you create a link on our homepage before signing up, we keep the phone number and message you typed for up to 7 days so we can add the link to your account, and delete them after that if the link isn’t claimed.
Technical and security information
Like every website, our servers see the IP address of each connection. We use it in memory to keep the service safe, for example to limit repeated password attempts or form submissions, and the limiter itself only holds a keyed hash. Our web servers and hosting provider may keep security logs that include IP addresses for up to 180 days, to meet log-keeping rules such as India’s CERT-In Directions of 2022. These logs are used only for security and legal compliance, never for analytics or marketing.
Cookies and local storage
We use a few essential cookies to keep you signed in, and your browser’s local storage for preferences such as the colour theme. There are no advertising or third-party analytics cookies. See the cookie policy.
4.How we use information
- To provide the service: accounts and workspaces, creating links, redirecting visitors, routing chats and showing analytics.
- For billing: taking payments, issuing invoices and credit notes, and keeping tax and accounting records.
- For security and safety: preventing fraud, spam and abuse, reviewing reported links, and protecting visitors, customers and our domains.
- To talk to you: account emails such as verification, password resets, invitations and important changes, and replies to your messages. We only send marketing emails if you have opted in, and each one has an unsubscribe link.
- To improve the service: using aggregated, de-identified information about how features are used.
- To meet legal obligations and respond to lawful requests from authorities.
We don’t sell personal data, we don’t use it for advertising, and we don’t build advertising profiles of customers or link visitors.
5.Why we may use it
We process personal data only on one of these grounds:
- Consent. When you create an account you agree to this policy and to the processing described in it. You can withdraw consent at any time, as easily as you gave it, by deleting your account or writing to us. Withdrawal doesn’t affect processing that happened before it, and we may still keep what the law requires.
- Our contract with you and our legal obligations. Under the PDPL we may process personal data without separate consent where it is needed to provide the service you signed up for, such as running your account and taking payments, or to meet a legal obligation, such as keeping invoices or responding to court orders.
- Legitimate uses allowed by Section 7 of the DPDP Act, for users in India, such as using information you voluntarily give us for the purpose you gave it (for example, answering a contact form or reviewing a report), and meeting legal obligations such as keeping tax records or responding to court orders.
If you are in the European Union or the United Kingdom, the equivalent grounds are contract, consent, legal obligation and our legitimate interest in keeping the service secure.
6.Link owners and their visitors
The business that shares a DiGi Links link decides why the link is used and what happens with its analytics. For click data, that business is the controller (the data fiduciary, under the DPDP Act) and we process the data on its behalf, as its processor. We also use click data ourselves, as a controller, to keep the service secure and to detect abuse.
If you share DiGi Links links, you are responsible for your visitors, which means:
- telling them, where the law requires it, for example in your own privacy notice, that you use a link service that records click analytics;
- handling the personal data people share with you in WhatsApp chats lawfully, which is outside our service;
- dealing with visitors’ requests about their click data. Permanently deleting a link also deletes its click history.
If you clicked a link: we can’t identify you from our records, because we don’t store IP addresses, names or phone numbers. Contact the business that shared the link. If you still have the chat code from the message, include it in a request to [email protected] and we will pass the request to that business.
8.Where data is stored and cross-border transfers
We are based in the United Arab Emirates. Our main servers and database are run by our hosting provider in a data centre that may be outside the UAE. Some service providers, such as our payment provider, our network security provider and our email delivery provider, may process data in other countries. This means your personal data may be stored and processed outside the country where you live. Ask [email protected] where your data is held.
We transfer personal data across borders only as the law allows: under the PDPL, to countries with an adequate level of protection or with appropriate safeguards, such as contracts that bind our providers to protect it; and under the DPDP Act, never to a country that the Government of India restricts. We choose providers that protect personal data at least as well as this policy does.
9.How long we keep it
- Account and workspace information: for as long as the account or workspace exists, then deleted.
- Links: until you delete them. Deleted links stop working straight away.
- Click history: for as long as the link exists. Your dashboard shows the period your plan includes (Free: 7 days; Starter: 30 days; Pro: 90 days; Business: 1 year). Permanently deleting a link, or the workspace it belongs to, deletes its click history.
- Invoices and billing records: 8 years, as the tax and accounting record-keeping laws that apply to us require, even after an account is deleted.
- Contact messages and support emails: up to 2 years after the conversation ends. Abuse reports may be kept longer when they are needed for a legal claim or an investigation.
- Security logs: up to 180 days, unless the law requires longer.
- Backups: deleted data can remain in encrypted backups for up to 35 days before it is overwritten.
10.How we protect it
- Every connection to DiGi Links is encrypted with HTTPS.
- Account and link passwords are stored only as salted one-way hashes, and visitor IDs are hashed with a secret key.
- Access is limited by role inside workspaces, and only the few staff who need it can reach production systems.
- Payments are handled by Razorpay, which is PCI DSS compliant, so card details never reach our servers.
No system is perfectly secure. If a personal data breach happens, we will inform the authorities the law requires us to notify, such as the UAE Data Office and the Data Protection Board of India, and the people affected, and tell you what we are doing about it.
11.Your rights
Under the PDPL and, for users in India, the DPDP Act, you have the right to:
- Access a summary of the personal data we hold about you, what we do with it, and who we have shared it with;
- Correct, complete or update personal data that is inaccurate or incomplete;
- Erase personal data we no longer need, unless the law requires us to keep it;
- Restrict or object to processing in the cases the PDPL allows, for example direct marketing;
- Withdraw consent at any time;
- Grievance redressal: have your complaint handled by our Grievance Officer;
- Nominate someone to exercise these rights for you if you die or become unable to (DPDP Act).
If you live elsewhere, you may have similar rights under your local law, such as the GDPR, and we will respect them.
12.How to exercise your rights
You can do much of this yourself in the dashboard: edit your profile, change or delete links, remove team members, and delete your account from Settings. Deleting your account also deletes every workspace where you are the only member, with its links and click history; we email you a link to confirm first. For anything else, write to [email protected] from the email address on your account. We may ask you to confirm your identity before acting, and we reply within 30 days.
If you aren’t satisfied with our answer, contact the Grievance Officer (below). If the matter is still not resolved, you can complain to the data protection authority where you live: in the UAE, the UAE Data Office; in India, the Data Protection Board of India.
13.Children
DiGi Links is for businesses and isn’t meant for anyone under 18. We don’t knowingly collect personal data from children. If you believe a child has created an account, write to [email protected] and we will delete it.
14.Changes to this policy
We update this policy when our practices or the law change. For material changes we email account owners or show a notice in the dashboard before the change takes effect. The date at the top of this page shows the current version.
15.Contact and Grievance Officer
The controller of your personal data is DIGI GROWTH IT SOLUTION L.L.C, Office 504, Ghaith Saeed Khalaf Al Ghaith Building, Al Barsha 1, Dubai, United Arab Emirates. For privacy questions and requests, write to [email protected]. Our Grievance Officer, appointed for users in India under the DPDP Act and the Information Technology Rules, 2021, handles complaints from anyone and can be reached at:
- Grievance Officer
- Grievance Officer
- [email protected]
- Postal address
- DIGI GROWTH IT SOLUTION L.L.C, Office 504, Ghaith Saeed Khalaf Al Ghaith Building, Al Barsha 1, Dubai, United Arab Emirates
We acknowledge grievances within 24 hours and resolve them within 15 days.
Questions about this policy?
Write to [email protected]. A person on our team reads every message.

