Privacy policy
Effective July 18, 2026
LinkPatch SEO is operated by Ellefsen Marketing (organization number 930 711 160), Korvettveien 23, 4624 Kristiansand S, Norway. Ellefsen Marketing is the controller of the information described in this policy.
What the app accesses
After a merchant installs LinkPatch, the app can read and—only after explicit approval—update product, collection, page, and article content. It also requests reachable storefront pages and sitemaps to build an internal-link graph. If a merchant enters a storefront password for a protected store, LinkPatch uses it in memory only to establish a temporary storefront session for that scan. The password is not stored or written to application logs.
What the app stores
- The shop domain and Shopify authorization session, including Shopify-issued access and refresh tokens, granted scopes and expiry, plus the authorized staff user's Shopify ID, name, email address, locale, account-owner and collaborator status, and email-verification status when Shopify provides them.
- Scan timestamps, page URLs, link counts, and issue classifications.
- Suggested links and their review status. For each actionable suggestion, LinkPatch stores HTML snapshots and hashes for its source and target so it can show the exact context and detect later revisions.
- Original and patched content for changes the merchant approves, so the change can be reverted.
- The approving staff user's name, email address, or shop domain as an audit attribution for scan, approval, apply, and revert actions.
- Technical error logs needed to operate and secure the service.
How information is used
Information is used only to provide scans, recommendations, approved edits, rollback, support, abuse prevention, and service reliability. LinkPatch does not sell merchant data or use store content to train a generative model.
Sharing and retention
Data is shared only with infrastructure providers needed to host the app and process Shopify-authorized operations. Shop-scoped application records are kept while the app is installed so scans, reviews, and rollback remain available. On uninstall, Shopify authorization sessions are deleted immediately. Remaining shop-scoped records are deleted when Shopify sends the verified shop/redact webhook, normally 48 hours after uninstall, or within 30 days of a verified erasure request, unless a longer period is legally required. Residual data can remain in provider recovery history until it ages out. As of this policy's effective date, Vercel runtime logs and Neon point-in-time recovery history are each retained no longer than 30 days. LinkPatch does not create separate application backups.
Where information is processed
Ellefsen Marketing is established in Norway, and the primary application database is hosted in the European Union. Application traffic and operational logs may be processed in the United States by Vercel, and Shopify processes authorized data in its own infrastructure. This means some information can be processed outside Europe. We use providers' contractual and technical transfer protections where applicable.
Security and merchant control
LinkPatch verifies Shopify-authenticated requests, minimizes API scopes, previews content edits, checks for intervening content changes, and keeps a rollback record. No internet service can guarantee absolute security.
Requests and support
Merchants can use Shopify Admin → Settings → Apps and sales channels → LinkPatch SEO → Get support, or email support@leadsfromurl.com. Where applicable, merchants can request access to, correction or deletion of, or restriction of or objection to our processing of their personal information. Shopify privacy webhooks are honored for access and deletion requests routed through Shopify.
Changes
This policy may be updated as the product changes. Material changes will be dated here and communicated through the app when appropriate.