Privacy Policy
Last updated: 6 May 2026
1. Who we are
FoundrLinq is a social platform for founders and entrepreneurs operated by Mustafa Aria (sole trader / eenmanszaak), registered in the Netherlands.
For privacy-related questions, you can reach us at hello@foundrlinq.com.
We are the data controller for the personal data collected through foundrlinq.com.
2. What data we collect
We collect the following categories of personal data:
- Account information: name, email address, password (stored hashed), date of birth.
- Profile information: bio, profile picture, location (city/country), social links, archetypes, founder details, intent and industry.
- Content you create: messages, posts, thoughts, comments, events, asks, and any other content you submit.
- Connection data: who you connect with, follow, message, or block.
- Usage data: pages visited, features used, time spent, interactions with other users.
- Technical data: IP address, browser type, device information, cookies, session identifiers.
- Payment data: when you upgrade to Pro, payment is processed by Stripe; we never see or store your card details.
3. How we use your data
We use your personal data to:
- Provide the FoundrLinq service — including your profile, valleys, chat, connections, and other features.
- Authenticate you and keep your account secure.
- Match you with relevant founders, communities, and content.
- Send you transactional emails (verification, approvals, contact form replies, account notifications).
- Send you product updates and weekly digests if you opt in.
- Process payments and manage subscriptions.
- Detect, prevent, and address fraud, abuse, or violations of our Terms of Service.
- Comply with legal obligations.
4. Legal basis for processing (EU/UK users)
Under the GDPR, we rely on the following legal bases:
- Contract: to deliver the service you signed up for.
- Legitimate interest: to improve the platform, prevent abuse, and personalise your experience.
- Consent: for optional things like marketing emails or non-essential cookies. You can withdraw consent at any time.
- Legal obligation: where we must process data to comply with applicable law.
5. Who we share data with
We do not sell your personal data. We share limited data only with trusted service providers who help us run the platform:
- Supabase — database, authentication, real-time, file storage (servers in EU/Ireland).
- Vercel — hosting and serverless infrastructure.
- Stripe — payment processing for Pro subscriptions.
- Resend — transactional email delivery.
Each provider acts as a data processor under contract and may not use your data for their own purposes.
We may also disclose data when required by law, court order, or to protect the rights, safety, or property of FoundrLinq, our users, or the public.
6. International data transfers
Your data is stored primarily in the European Union (Supabase EU West, Ireland). Some of our providers (such as Stripe and Vercel) may process data in the United States. When data leaves the EEA, it is protected by Standard Contractual Clauses or equivalent safeguards approved under GDPR.
7. How long we keep your data
We keep your personal data for as long as your account is active. If you delete your account, all your personal data is removed from our systems. Some data may be retained in encrypted backups for up to 30 days after deletion, after which it is permanently erased.
Some data may be kept longer if required by law (for example, financial records relating to payments, which we are required to keep for 7 years under Dutch tax law).
8. Your rights
Under the GDPR (and similar laws in other jurisdictions), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your personal data (your "right to be forgotten") — you can do this directly from Settings → Account.
- Restrict or object to certain types of processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where consent is the basis for processing.
- Lodge a complaint with a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
To exercise any of these rights, email us at hello@foundrlinq.com.
9. Your rights — California residents (CCPA/CPRA)
If you are a resident of California, you also have the right to:
- Know what personal information we collect about you and how it is used.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information (we do not sell your data).
- Limit the use of sensitive personal information.
- Not be discriminated against for exercising your rights.
10. Cookies and tracking
We use a small number of essential cookies to keep you signed in and to remember your preferences. We do not use advertising cookies. For full details, see our Cookie Policy.
11. Children
FoundrLinq is not intended for users under the age of 16. We do not knowingly collect data from anyone under 16. If we discover that we have collected data from someone under 16, we will delete it immediately.
12. Security
We take reasonable technical and organisational measures to protect your personal data, including encryption in transit (HTTPS/TLS), encrypted storage, hashed passwords, role-based database access, and regular security reviews. However, no system is 100% secure. If we ever discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will also notify you by email or through the platform.
14. Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us at hello@foundrlinq.com.