OdyLinksCreate yours

Privacy Policy

How OdyLinks handles personal data — what is collected, why, how long it is kept, who it reaches, and what you can require us to do about it.

Last updated 21 September 2026.


1. The short version

  • A contact page is published deliberately and is public. Everything you put on one — your name, your numbers, your addresses, your photograph — is visible to anyone who has the link, and to search engines unless you keep the link private.
  • We do not run advertising, analytics, tracking pixels, or behavioural profiling, and we do not sell or rent personal data to anyone, for any purpose.
  • There are no accounts. We do not ask for a password, and we do not hold one.
  • You can change or delete your page at any time, and deletion is real deletion — see section 7.

This summary is for orientation only. The sections below are the operative text and prevail over it wherever they differ.

2. Who we are, and our role

OdyLinks is a product of Odiyansh Private Limited, a company incorporated in India, which operates the service (“we”, “us”). We decide the purposes and means of the processing described here. That makes us the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (India) and the controller under Regulation (EU) 2016/679 (the GDPR) and the UK GDPR.

Two distinct relationships run through this policy, and they carry different rights:

  • Authors — people who build and publish a contact page. Most of this policy concerns you.
  • Visitors — people who open a published page, scan its code, or save its contact card. We hold almost nothing about you; see section 5.

3. What we collect

Profile content you enter. Whatever you type into the builder and choose to publish. Depending on what you fill in, that may include your name, job title, employer, work and personal email addresses, work and personal telephone numbers with their country codes, work and personal locations, a company website, a short quote, a short biography, links you add, your social profile addresses, and a photograph of you.

Some of this is capable of identifying you directly, and a photograph of a face is capable of revealing characteristics that several laws treat as sensitive. You decide every field. Nothing is compulsory except the handful marked required in the builder, and you should publish only what you are content for strangers to read.

Technical data, when you use the service.

  • Your IP address, used to count requests so that one source cannot flood the service. It is held as a short-lived counter, keyed to the address, and expires automatically — see section 7.
  • Ordinary request data handled by our hosting provider in the course of delivering the page: the address requested, the time, the response status, and the characteristics your browser advertises.

What we do not collect. We do not use advertising or analytics cookies, tracking pixels, web beacons, session recording, fingerprinting, or cross-site trackers. We do not buy personal data, and we do not enrich what you give us from outside sources.

4. Storage in your own browser

We set no cookies. The builder does keep a small amount of data in your browser’s local storage, which stays on your device and is never transmitted to us:

  • an unpublished draft of your page, so closing the tab does not lose your work;
  • the link and edit key of a page you published from this browser, so you can return to it;
  • small display preferences.

This is strictly necessary to provide the service you asked for, so under the ePrivacy Directive and its national implementations it does not require consent. Clearing your site data removes all of it — and with it your ability to edit a page from this browser unless you have kept the edit link.

5. If you are visiting someone's page

You do not need an account and we do not ask you for anything. Opening a published page, downloading its contact card, or scanning its code creates no record of you beyond the rate-limit counter and the hosting logs described in section 3.

The contact card you download is a file. Once it is on your device it is yours, governed by your own device and whatever address book you put it in. We have no visibility of it and cannot recall it.

6. Why we process it, and on what basis

Under the DPDP Act our basis is your consent, given when you publish a page, together with the legitimate uses in section 7 of that Act for security and for compliance with law. Under the GDPR and UK GDPR:

  • Publishing your page — Article 6(1)(b), performance of the contract you enter into by using the service. Where your photograph or other content reveals data within Article 9, our basis is Article 9(2)(e): you have manifestly made it public by publishing it yourself.
  • Keeping the service available and abuse-free — Article 6(1)(f), our legitimate interest in a service that stays up. We have weighed this against your interests and consider the impact slight: the data is an address, held briefly, and used for nothing else.
  • Meeting legal obligations — Article 6(1)(c), where a law requires us to retain or disclose something.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not profile you.

7. How long we keep it

  • Your published page: until you delete it, or until you replace it with a newly generated link, at which point the superseded record is removed. There is no other expiry; a page stays up because it is meant to be found.
  • Rate-limit counters: automatically expired by the storage layer within minutes of being written. They are not read for any purpose other than counting, and are not aggregated.
  • Hosting logs: retained by our provider for its own short operational period and not copied into a store of ours.
  • Your browser’s local storage: until you clear it. We cannot clear it for you.

Deleting your page removes the stored record and releases the username for anyone else to claim. It cannot reach copies that already left our control: search engine caches, screenshots, contact cards already saved to someone’s phone, or a QR code already printed. Those are outside our reach and, in the case of a printed code, outside anyone’s.

8. Who else sees it

Anyone with your link. That is the purpose of the service. A published page is not access-controlled, is not hidden behind a login, and may be indexed by search engines.

Our hosting provider. The service runs on Cloudflare, Inc., which delivers requests and stores the published records on our behalf. It acts as our Data Processor under the DPDP Act and our processor under the GDPR, under terms that restrict it to acting on our instructions.

Nobody else. We do not share, sell, rent, licence or trade personal data with advertisers, data brokers, analytics companies or anyone else. We disclose data to a public authority only where we are compelled by a valid legal instrument, and only so far as that instrument requires.

9. Where it is processed

The service runs on a distributed network, so a request is served from a location near the person making it, and data may therefore be processed outside the country you are in — including outside India and outside the European Economic Area.

For transfers out of the EEA or the United Kingdom we rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies. For India, section 16 of the DPDP Act permits transfer except to a country the Central Government has restricted by notification; we will not transfer to a restricted country.

10. How it is protected

We take the measures set out below. They are stated plainly so you can judge them, rather than described as “industry standard”.

  • All traffic is encrypted in transit, and HTTPS is enforced.
  • A page is edited by holding its edit key. The key travels in the part of the address that browsers never send to a server, so it does not appear in our logs. It can be replaced at any time from the builder, which immediately invalidates the old one.
  • Uploaded images are verified to be genuine images before being stored, and are served under a policy that prevents a browser treating them as anything else.
  • A strict Content Security Policy, framing protection and related headers are applied to every response.
  • Write operations are rate limited to blunt automated abuse.

The edit key is the only credential. Anyone holding it can edit or delete that page. Treat it like a password: do not post it, and replace it from the builder if you think it has been seen.

Where a personal data breach occurs, we will report it to the Data Protection Board of India as required by section 8(6) of the DPDP Act and the rules made under it, and to the relevant supervisory authority within 72 hours where Article 33 of the GDPR applies. Affected people will be informed where the law requires it.

11. Your rights

Under the DPDP Act, 2023 you have the right to access a summary of your personal data and our processing of it (s.11), to correction and erasure (s.12), to grievance redressal (s.13), and to nominate another person to exercise your rights in the event of death or incapacity (s.14). You also have duties under section 15, including not impersonating another person and not filing false complaints.

Under the GDPR and UK GDPR you have the rights of access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), and the right to withdraw consent at any time without affecting processing already carried out.

Exercising them is mostly immediate. Because we hold no accounts, the builder itself is the fastest route: open your page with your edit link to see everything held about you, change any of it, or delete the page outright. That satisfies access, correction, erasure and portability in a single step, without waiting on us.

Where you would rather ask us, or where you cannot reach your page, use the contact route in section 13. We respond within 30 days. We do not charge for this, and we will not ask you for more identification than we need to be sure the request is yours.

12. Children

This service is not intended for children. Under section 9 of the DPDP Act, processing the personal data of a person under 18 in India requires verifiable parental consent, and tracking or behavioural advertising directed at children is prohibited outright. We are not equipped to verify parental consent, so you must not use this service to publish a page about a person under 18, whether that person is you or someone else.

Where the GDPR applies, the equivalent threshold is 16, or a lower age set by a Member State but never below 13. If we learn that a page concerns a child, we will delete it.

13. Complaints and grievances

If you are unhappy with how your personal data has been handled, raise it with us first. Under section 13 of the DPDP Act you must exhaust this route before approaching the Data Protection Board of India.

Odiyansh Private Limited

info@odiyansh.com

Tell us what the matter concerns and, where it is about a page, the exact link. We acknowledge within 24 hours and resolve within 15 days.

You may also complain to a regulator. In India that is the Data Protection Board of India. In the EEA it is the supervisory authority of the place you live, work, or where the matter arose. In the United Kingdom it is the Information Commissioner’s Office. You do not need our permission, and complaining to us first does not shorten any time limit that applies to a complaint to them.

14. Changes to this policy

We may revise this policy. The date at the top always reflects the current version. Where a change materially affects your rights or materially widens what we do with your data, we will make that change prominent on the site rather than rely on you noticing a new date, and it will not be applied retrospectively to data already collected.