MrLinQ Privacy Policy
Version 1.0 — Effective date: 1 November 2026
Last updated: 1 November 2026
1. Who we are and how to reach us
MrLinQ ("MrLinQ", "we", "us", "our") is a mobile and web directory that helps construction companies, contractors, suppliers and specialist trades in Cyprus find and contact each other directly.
MrLinQ is operated as a sole-trader business by:
Panayiotis Yiakoumi, trading as MrLinQ
Registered address: 299 Strovolos Avenue, Strovolos, Nicosia, Cyprus
Privacy contact: support@mrlinq.app
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018), we are the controller of the personal data described in this Policy.
We have not appointed a Data Protection Officer because we are not required to. All privacy questions and requests should be sent to the privacy contact above. We aim to acknowledge every request within 5 working days and to respond in full within one month.
2. What this Policy covers
The service is offered to users in Cyprus, Greece, the United Kingdom and the United States.
This Policy explains what personal data we collect when you use the MrLinQ mobile app, the MrLinQ website (together, the "Service"), how we use it, who we share it with, how long we keep it, and the rights you have.
It applies to everyone who uses the Service: visitors who browse without an account, businesses that publish a profile, businesses and individuals that search for and contact other businesses, and people who write to us.
Where you tap through from MrLinQ to another service — for example, to open WhatsApp, place a telephone call, send an email, visit a business's website, or pay for a subscription by card through Stripe on app.mrlinq.app or through the Apple App Store or Google Play — that provider's own privacy terms apply to the data it handles.
3. The short version
- We collect the information you type into the Service, the information your device sends automatically, and a record of how the Service is used.
- Business profiles are designed to be seen by other users. Telephone numbers, WhatsApp numbers and email addresses are not shown to visitors and are only revealed to signed-in accounts with active access, one profile at a time, and every reveal is logged.
- We use your data to run the Service, keep it safe from abuse and scraping, comply with the law, and — only if you have agreed — send you news and offers.
- We do not sell personal data. We share it only with the service providers we need to operate, including Stripe for web card payments and Apple or Google for in-app purchases, and when the law requires it.
- Your data is stored in the European Union.
- You can pause your profile at any time. You can also delete your account; we then delete or anonymise your data within 30 days, keeping only the limited records described in Section 9.
- You have the right to access, correct, delete and export your data, and to complain to the Cyprus Commissioner for Personal Data Protection.
4. The data we collect
4.1 Data you give us
Account data. Your email address, a password (stored only in hashed form — we never see it), the account type you choose (for example contractor, subcontractor, supplier, mobile service, private individual), the language you prefer, and the date you registered.
Business profile data (only if you publish a business profile). Business name, trades and categories, districts and localities served, typical project sizes, team size, years of experience, year established, languages spoken, equipment and specialist capabilities, a short description and a longer "about" text, a logo, project photographs with titles, districts and years, the types of projects you undertake, and a website and social-media links if you choose to add them.
Contact-person data. The name of a contact person (optional), a telephone number, a WhatsApp number and a contact email address. If you are a sole trader or a very small business, some of this information — including your business name — may identify you personally. We treat it as personal data.
Verification data (only if you request verification). Company registration number, VAT number, insurance details, licence or certification details, and the documents you upload to prove them — for example a certificate of incorporation, a VAT certificate, an insurance certificate, or an identity document for a sole trader.
Billing data (businesses that subscribe). Your subscription plan, start and end dates, and payment records from Stripe, Apple App Store or Google Play, depending on where you purchased. We do not receive or store your full card number.
Ratings and reviews (where the feature is enabled). The star rating and any comment you write about a business, together with your display name and the date. Reviews are public.
Reports. If you report a profile, we record which profile you reported, the reason you chose, any explanation you wrote, and your account identity. Your identity is not shown to the business you reported.
Correspondence. Anything you send us by email, through the app's contact form or through the app stores, including support requests and privacy requests.
4.2 Data we collect automatically
Device and technical data. Device type and operating-system version, app version, language and region settings, time zone, IP address, and crash and error reports.
Usage data. The screens you open, the searches you run (trade, category, district, locality and the free-text terms you type into filters), the profiles you view, the businesses you save as favourites, the profiles you recently viewed, the tips and prompts you dismiss, and the dates and times of these actions.
Contact-reveal records. When a signed-in account taps to reveal a business's telephone number, WhatsApp number or email address, we record which account revealed which business's contact details and when. We record only the fact of the reveal and the time. We do not record what you then say or write to each other.
Contact-button records. When you tap Call, WhatsApp, Email or Website on a profile we record which button was tapped on which profile and when, for statistics and for detecting abuse.
Security signals. Rate and pattern of profile views and contact reveals, sign-in attempts, and similar signals used to detect automated scraping, bulk harvesting of contact details, and other misuse.
We do not collect precise location (GPS) data. Districts and localities are the ones you choose. If we ever add a feature that uses your device's location, the app will ask for your permission first and this Policy will be updated.
4.3 Data about other people
If you upload project photographs, add a contact person, or write a review, you may give us personal data about someone else. Please only do so if that person is aware of it and would not object. Do not upload photographs in which private individuals — for example your clients or their families — are identifiable, and do not include private client details in project descriptions.
5. Why we use your data and our legal basis
Under the GDPR we must have a legal basis for each use of personal data. The table below sets out what we do and why.
| What we do | Data used | Legal basis |
|---|---|---|
| Create and run your account; let you sign in; keep you signed in securely | Account data, device data | Performance of a contract (our Terms of Use) |
| Publish your business profile so other users can find and contact you | Business profile data, contact-person data | Performance of a contract |
| Show you search results and profiles; remember your favourites and recently viewed profiles | Usage data, account data | Performance of a contract |
| Reveal a business's contact details to accounts with active access, and log each reveal | Contact-person data, contact-reveal records | Performance of a contract; legitimate interest in protecting businesses from scraping |
| Verify a business and show a verification badge | Verification data | Performance of a contract; legitimate interest in keeping the directory trustworthy |
| Manage free trials, subscriptions and payments | Billing data | Performance of a contract; legal obligation (tax and accounting law) |
| Send you service emails: password reset, profile approved or rejected, verification decisions, subscription confirmations, the yearly "are your details still correct?" check, security notices | Account data | Performance of a contract; legitimate interest in keeping the directory accurate |
| Send you news, tips and offers about MrLinQ | Account data | Consent — only if you tick the marketing box, and you can withdraw at any time |
| Detect and prevent scraping, bulk harvesting of contact details, fake or duplicate profiles, fraud and abuse; suspend or restrict accounts that break our Terms | Usage data, security signals, contact-reveal records, hashed identifiers | Legitimate interest in the security of the Service and the protection of its users |
| Handle reports about profiles, disputes and complaints | Reports, correspondence, relevant profile data | Legitimate interest; legal obligation where applicable |
| Translate reviews and search terms between Greek, English, Arabic and Russian using an automated translation service | Review text, search terms | Legitimate interest in making the Service usable in four languages |
| Produce statistics about the Service — number of businesses by trade and district, popular searches, activity levels — to run and improve MrLinQ and to report on its performance to prospective partners and investors | Aggregated, anonymised data only | Legitimate interest. Statistics never identify an individual business or person |
| Comply with legal obligations, respond to lawful requests from authorities, and establish, exercise or defend legal claims | Any relevant data | Legal obligation; legitimate interest |
Where we rely on legitimate interest, we have considered the impact on you and concluded that our interest does not override your rights and freedoms. You have the right to object — see Section 11.
We do not use your data to make decisions about you by fully automated means that have a legal or similarly significant effect. Our anti-scraping system automatically flags unusual activity and can temporarily pause contact reveals for an account; any suspension of an account is reviewed by a person.
6. Who can see your business profile
Visitors without an account can see basic profile information: business name, trades, districts served, project sizes, badges, photographs and descriptions. They cannot see telephone numbers, WhatsApp numbers or email addresses, and these are not present in the pages or data sent to their device.
Signed-in accounts with active access (a free trial, a subscription, or access granted by us) can tap to reveal your contact details. Each reveal is counted and logged, and accounts are limited in how many contact details they can reveal per hour and per month. These limits exist to protect you from having your details harvested in bulk.
Private individual accounts never have a public profile. They can search and contact businesses but cannot be found.
MrLinQ administrators can see all profile data in order to approve, verify, moderate and support accounts. Access to verification documents is restricted to a single designated reviewer (see Section 8).
Once another user has revealed your contact details, what they do with them is their responsibility as an independent controller under the GDPR. Our Terms of Use forbid using MrLinQ data for unsolicited marketing, resale, or building competing databases, and we act on reports of misuse.
7. Who we share your data with
We do not sell personal data and we do not share it with data brokers. We share data only as described here.
7.1 Service providers (processors)
Companies that process data on our behalf under written contracts that require them to protect it and use it only on our instructions:
| Provider | What they do for us | Where data is processed |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions that run the Service | European Union |
| Expo (Expo.dev) | Building and delivering the mobile app; push notifications if enabled | EU / United States* |
| [EMAIL PROVIDER, e.g. Resend] | Sending service and marketing emails | EU / United States* |
| Apple Inc. and Google LLC | Distributing the apps and processing in-app subscription purchases | United States* |
| Stripe, Inc. | Processing card payments for web subscriptions | Not specified here; see Stripe's documentation |
| [AI TRANSLATION PROVIDER] | Automated translation of reviews and search terms | EU / United States* |
| [ANALYTICS / CRASH PROVIDER, if used] | App performance, crash reports and anonymised usage statistics | [REGION]* |
* Where a provider processes data outside the European Economic Area, we rely on the safeguards in Section 10.
7.2 Other users of the Service
Your business profile is shared with other users as described in Section 6. Reviews you write are shown publicly with your display name.
7.3 Legal and safety
We may disclose personal data to courts, regulators, law-enforcement bodies or other authorities where the law requires it, to enforce our Terms, or to protect the rights, property or safety of MrLinQ, our users or the public.
7.4 Business transfers
If MrLinQ is incorporated as a company, restructured, sold, merged or receives investment, personal data may be transferred to the new or successor entity. The new entity will be bound by this Policy, and we will notify you of any change of controller.
8. Verification documents
We take particular care with the documents you upload to verify your business, because they can include identity documents and confidential business records.
- Documents are stored in a private, access-controlled storage area. They are never shown on your public profile or to other users.
- Only one designated MrLinQ reviewer has access to them, solely to decide your verification request.
- For security, verification documents are automatically and permanently deleted 30 days after the verification decision (approval or rejection). After that we keep only a record that verification took place, the type of document reviewed, the decision, the date, and — for approved checks — which items were confirmed (for example "registration", "VAT", "insurance"), which is what the verification badge on your profile represents.
- If you withdraw a pending verification request, the documents are deleted immediately.
- A verification badge means that selected information was reviewed on a given date. It is not a guarantee of quality of work, financial standing, insurance cover, licensing, safety performance or completion of any future project.
9. How long we keep your data
We keep personal data only for as long as we need it for the purposes above, and then delete or anonymise it. The main periods are:
| Data | How long |
|---|---|
| Account and business profile data | For as long as your account exists. A paused (hidden) profile is kept in full so you can reactivate it |
| Verification documents | 30 days after the verification decision, then permanently deleted (Section 8) |
| Verification records (type of document, decision, date, items confirmed) | For as long as your account exists, plus the closed-account period below |
| Contact-reveal and contact-button records | 24 months, then anonymised |
| Search history linked to your account | 12 months, then anonymised |
| Security and anti-abuse logs | 24 months |
| Administrator audit logs (approvals, suspensions, verification decisions, access grants) | 6 years, in line with the limitation period for legal claims in Cyprus |
| Billing and subscription records | 7 years after the transaction, as required by Cyprus tax and accounting law |
| Reports about profiles and the outcome | 6 years |
| Email logs (which service email was sent, to which address, when) | 12 months |
| Support and privacy correspondence | 3 years after the matter is closed |
| Marketing consent record (when you gave or withdrew consent, and which version of this Policy you saw) | For as long as consent stands, plus 3 years as proof |
9.1 Pausing your profile
You can hide your business profile at any time from your account settings. A hidden profile is not shown in search results and cannot be found or contacted, but all your data is kept so that you can switch it back on with one tap. Nothing is deleted.
9.2 Deleting your account
You can request deletion of your account from your account settings or by writing to us. When you do:
- Your profile is hidden immediately.
- For 30 days your account is held in a suspended state so that you can change your mind and restore it by signing in.
- After 30 days we permanently delete your public profile, photographs, descriptions, favourites, recently viewed profiles, search history, and your contact person's name, telephone number, WhatsApp number and email address from your account.
We keep the following after deletion, because we have a lawful reason to:
- Records we must keep by law — billing and subscription records (Section 9, 7 years).
- Records needed for legal claims and safety — administrator audit logs, reports made about or by the account, suspensions and verification records, for 6 years.
- Anti-abuse identifiers — a one-way cryptographic hash of the email address, telephone number(s) and business registration number that were on the account, for up to 5 years. A hash cannot be reversed to reveal the original value. We use it only to recognise a business that was suspended or removed for breaking our Terms if it tries to register again, and to prevent duplicate profiles. It is never used to contact you.
- A closed-account statistical record — business name, business type, trades, districts served, registration date, closure date and, if you gave one, the reason for leaving. This record contains no telephone number, email address or contact-person name, and is used only for the statistics described in Section 5.
- Anonymised data — statistics that can no longer be linked to you, which we keep indefinitely.
- Reviews you wrote may remain visible with your display name replaced by "Former user", unless you ask us to remove them.
9.3 Staying in touch after deletion (optional)
When you delete your account we will ask whether you would like MrLinQ to keep your business name, email address and telephone number on file so that we can contact you about the relaunch of your profile, new features, or opportunities relevant to your trade. This is entirely optional, unticked by default, and based on your consent. If you agree, we keep those details on a separate contact list until you tell us to stop, which you can do by replying to any message or writing to the privacy contact. If you do not agree, they are deleted as described above.
9.4 Inactive accounts
If an account has not been signed into for 3 years, we will email the account holder and, if there is no response within 60 days, treat the account as deleted under Section 9.2.
10. Where your data is stored and international transfers
Our database, authentication system and file storage are hosted by Supabase in data centres located in the European Union.
Some of our service providers (Section 7.1) are based in, or may process data in, countries outside the European Economic Area, in particular the United States. Where that happens we make sure the transfer is protected by one of the safeguards recognised by the GDPR: an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework for certified providers), or the European Commission's Standard Contractual Clauses together with any additional measures needed. You can ask us for details of the safeguard that applies to a particular provider.
11. Your rights
Under the GDPR you have the following rights. They are free of charge, and we will respond within one month (extendable by two months for complex requests, in which case we will tell you).
- Access — ask us to confirm whether we process your personal data and to give you a copy of it, together with the information in this Policy.
- Rectification — ask us to correct inaccurate data or complete incomplete data. You can edit most profile data yourself in the app.
- Erasure — ask us to delete your data. See Section 9.2 for what we delete and what we lawfully keep.
- Restriction — ask us to limit how we use your data while a dispute about accuracy or lawfulness is resolved.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format (we provide JSON or CSV), or have it sent to another provider where technically feasible.
- Objection — object to processing based on our legitimate interests. We will stop unless we have compelling legitimate grounds that override your interests, or the processing is needed for legal claims. You can object to direct marketing at any time and we will always stop.
- Withdraw consent — where processing is based on consent (marketing emails, the stay-in-touch list), you can withdraw it at any time by using the unsubscribe link in any email, from your account settings, or by writing to us. Withdrawal does not affect processing that took place before it.
- Not to be subject to automated decisions with legal or similarly significant effects. We do not make such decisions (Section 5).
To exercise any right, email support@mrlinq.app from the address on your account, or use the options in your account settings. We may ask you to confirm your identity before acting on a request, so that we do not give your data to someone else.
Complaints. If you are unhappy with how we handle your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the supervisory authority in Cyprus:
Office of the Commissioner for Personal Data Protection
1 Iasonos Street, 1082 Nicosia, Cyprus
P.O. Box 23378, 1682 Nicosia
Tel. +357 22 818 456 · commissioner@dataprotection.gov.cy · www.dataprotection.gov.cy
If you live in another EU country you may complain to your local authority instead.
12. Marketing communications
We will send you marketing emails — news about MrLinQ, tips for getting more work through the Service, and offers — only if you have ticked the marketing box when you register or later in your account settings. The box is unticked by default.
Every marketing email contains an unsubscribe link. You can also switch marketing off in your account settings at any time. Service emails (password resets, profile decisions, security notices, the yearly details check) are not marketing and will still be sent while you have an account, because they are necessary to run the Service.
We do not send marketing text messages or WhatsApp messages, and we do not share your details with third parties for their own marketing.
13. Security
We protect your data with technical and organisational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- passwords stored only as salted hashes; secure session tokens stored in the device's protected storage;
- row-level access controls in our database so that each account can only read the data it is entitled to, enforced on the server and not only in the app;
- contact details excluded from all data sent to visitors and revealed only through an audited, rate-limited process;
- private, access-controlled storage for verification documents with automatic deletion;
- automatic detection of scraping and bulk-harvesting behaviour;
- server-side validation of uploads (type and size) and sanitisation of text you enter;
- administrator actions logged in an audit trail;
- access to production systems limited to the owner and, for verification documents, a single designated reviewer.
No system is completely secure. If we become aware of a personal-data breach that is likely to result in a high risk to you, we will tell you without undue delay, and we will notify the Commissioner for Personal Data Protection within 72 hours where the GDPR requires it.
Please keep your password confidential, use a password you do not use elsewhere, and tell us at once if you think your account has been accessed without your permission.
14. Cookies and similar technologies on our website
The MrLinQ mobile app does not use cookies. It stores a secure sign-in token, your language choice and small preference settings on your device so that the app works; these are not used for tracking.
The MrLinQ website uses cookies and similar technologies as follows:
- Strictly necessary cookies — needed for the site to work (for example to keep you signed in, remember your language, and protect against attacks). These do not require consent.
- Analytics cookies — help us understand how the website is used so we can improve it. These are set only if you accept them in the cookie banner. Where possible we use analytics configured so that IP addresses are truncated and no cross-site profile is built.
- Marketing cookies — we do not currently use any. If we ever do, they will be set only with your consent and this section will be updated.
When you first visit the website you will see a cookie banner where you can accept or reject non-essential cookies. You can change your choice at any time from the "Cookie settings" link in the website footer, and you can also delete cookies through your browser settings. A full list of the cookies we set, their purpose and their lifetime is available on our Cookie Policy page.
15. Children
MrLinQ is a directory for businesses and for people who want to hire them. You must be at least 18 years old to create an account, because an account involves entering into a contract with us and, for businesses, publishing information about a trade or company. Anyone may browse the public parts of the Service without an account, and there is nothing in the Service that is unsuitable for younger people.
We do not knowingly collect personal data from anyone under 18 through an account. If you believe a child has created an account, please contact us and we will delete it.
16. Other countries
MrLinQ currently operates in Cyprus. If we expand to other countries, users in those countries will be shown the version of this Policy that applies to them, including any country-specific supervisory authority, retention periods and legal bases. Cyprus users' data will continue to be governed by this Policy and by the GDPR.
17. Changes to this Policy
We may update this Policy from time to time — for example when we add features, change providers or when the law changes. The "Last updated" date at the top shows when it was last changed. For significant changes we will notify you in the app or by email before they take effect, and where a change requires your consent we will ask for it. Continuing to use the Service after a change takes effect means you accept the updated Policy, except where consent is required.
Previous versions of this Policy are available on request.
18. Language
This Policy is provided in Greek, English, Arabic and Russian. The English text is the master version. If there is any inconsistency between versions, the English version prevails until a certified Greek translation has been published, after which the Greek version prevails for users in Cyprus.
19. Contact
Questions, requests and complaints about privacy:
Panayiotis Yiakoumi, trading as MrLinQ
299 Strovolos Avenue, Strovolos, Nicosia, Cyprus
support@mrlinq.app
End of Privacy Policy v1.0