Privacy Policy
This policy explains what data Link Meet collects — both about you, if you're a practitioner or clinic using the product, and about your clients, who book appointments through your public page — and how that data is handled.
Who processes your data
The data controller is Ruben Marques, tax ID 248905724, registered at CEI, Av. do Empresário, Castelo Branco, Portugal. For any question about your data, or to exercise the rights described below, contact contacto@link-meet.com.
What data we collect
Depending on how you use Link Meet, we collect:
- From the practitioner/clinic account: name, email, password (encrypted) or the Google account used for authentication, the practice's name and public address (link).
- From booked clients: name, email, phone (when provided), appointment dates and times, the service chosen, and answers to any intake forms the practitioner sets up.
- Session notes: text the practitioner writes about each client. These may contain health data — they're visible only to the practitioner who wrote them within their organization, never to the Link Meet team during normal use of the product.
- Integrations you turn on: if you connect Google Calendar, we access your calendar's busy/free periods and create events for booked appointments. We only request the minimum permissions that feature needs.
- Technical data: IP address and device/browser information, used only for security and troubleshooting — we don't use this for advertising.
What we use the data for
- Creating and managing your account and public booking page.
- Processing bookings: confirming, reminding, allowing rescheduling or cancellation.
- Sending booking-related communications (confirmation, reminder, form, receipt).
- Syncing with your calendar and creating video-call rooms when the practitioner turns those integrations on.
- Platform security and abuse prevention.
We don't use your clients' data for advertising, and we don't sell it or share it with third parties for marketing purposes.
Who we share data with (subprocessors)
To run the service, some data passes through providers acting as subprocessors, only to the extent necessary:
- Hosting and database — data is stored on servers managed by our hosting provider (Railway), in the Europe (Amsterdam, Netherlands) region.
- Email delivery — notifications (confirmation, reminder, receipt) are sent through Resend.
- Google Calendar / Google Meet — only if the practitioner connects this integration, to sync availability and create video calls.
None of these providers may use the data for their own purposes — they only process it to deliver the service we've contracted them for.
Security and sensitive data
All communication between your device and Link Meet is encrypted in transit (HTTPS/TLS). Credentials for any integration you turn on — for example, Google Calendar access tokens — are encrypted at rest with AES-256-GCM before being stored in the database: they're never stored in plain text. Session notes, which may contain health data, are visible only to the practitioner who wrote them within their organization — the Link Meet team doesn't access them during normal use of the product. Access to the production database is restricted to the technical team and protected by our hosting provider's own authentication. In the event of a data breach affecting personal data, we will notify affected individuals and Portugal's data protection authority (CNPD) within the timeframes required by GDPR.
How long we keep the data
We keep account and booking data for as long as the account is active. When a client is archived by the practitioner, it stops appearing in lists, but the history is kept for clinical and accounting record purposes, unless a deletion request is made under the terms of the next section.
Your rights
Under GDPR, you have the right to:
- Access the data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data, where applicable.
- Request portability of your data in a structured format.
- Object to certain processing or withdraw consent given.
To exercise any of these rights, contact contacto@link-meet.com. You can also file a complaint with Portugal's data protection authority (CNPD).
Cookies
We use cookies essential to the service working: keeping you signed in, remembering the active organization, and short-lived technical cookies used during account creation and connecting integrations (for example, to recover the link you were choosing if you leave to authenticate with Google). We don't use advertising or cross-site tracking cookies.
With your permission — asked for in the cookie notice, never turned on by default — we also use analytics cookies:
- On the Link Meet website, a script from our provider Data Fast (datafa.st) measures visits to the marketing pages.
- On each practitioner's public booking pages (link-meet.com/<practitioner>), Link Meet's own analytics system records visits, visit duration, source (referrer/UTM), approximate location (country/region/city, derived from the IP, not stored), device type, and what actions the visitor took (service chosen, time chosen, booking confirmed, links clicked). A first-party, anonymous cookie (no name or email attached) identifies repeat visits from the same visitor. This data is shown to the practitioner in their Statistics area, so they can see whether their page is getting visits and converting them into bookings.
You can change your mind at any time under "Cookie preferences" in any page's footer — withdrawing analytics consent also clears the associated visitor cookie.
Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated by email to practitioners with an active account.