Legal
Privacy Policy
What personal data BridgeLink uses, why it is used, who receives it, how long it is kept, and your choices.
01Controller and contact
BridgeLink is operated by HOLSETER DEVELOPMENT, a Norwegian sole proprietorship (organization number 830 131 922), owned by Joachim Holseter. HOLSETER DEVELOPMENT is the data controller for the personal data described in this policy.
Business address: Steinstemmyrå 39, 4313 Sandnes, Norway. Privacy questions and requests can be sent to privacy@bridgelink.app.
02Data we collect and its source
Discord provides your user ID, username, display name, avatar, and, when made available through the authorized OAuth scope, email address. BridgeLink never receives your Discord password.
If you join as a guest, you provide a display name and BridgeLink assigns an installation identifier used for session continuity and abuse prevention. Your display name, role, assignments, and operation activity are visible to the host and other authorized participants. BridgeLink records the version of the Terms shown when an account signs in or a guest joins.
You and other operation or organization members provide account preferences, organization details, operation plans, unit assignments, participant records, debrief notes, operational logs, expenses, rewards, asset-loss reports, saved units, ships, presets, and other content entered into the service. Organization administrators may provide membership, role, security, inventory, planning, and webhook information concerning their organization and members.
BridgeLink automatically receives session identifiers, timestamps, IP-derived security data, browser or device information, connection diagnostics, feature activity, and low-cardinality search analytics. Payment status, customer identifiers, subscription identifiers, and transaction status are received from Stripe; BridgeLink does not store full payment-card details.
03Purposes and legal bases
- Contract: authenticate you; provide accounts, operations, voice routing, organizations, archives, subscriptions, support, and requested service features (GDPR Article 6(1)(b)).
- Legitimate interests: secure and troubleshoot the service, prevent fraud and abuse, preserve service integrity, understand aggregate feature performance, and enforce the Terms (Article 6(1)(f)). These activities are limited to what is reasonably necessary and balanced against user rights.
- Legal obligations: keep records or disclose information where accounting, tax, consumer, court, or regulatory law requires it (Article 6(1)(c)).
- Consent: optional marketing email, if offered and enabled by you (Article 6(1)(a)). You may withdraw consent in account preferences at any time without affecting earlier processing.
Discord identity and core operation data are required to provide signed-in and collaborative features. Optional profile fields, marketing preferences, organization content, and most saved content can be left blank or disabled, although the corresponding feature may then be unavailable.
04Cookies, device storage, and voice
BridgeLink sets only strictly necessary first-party cookies to protect and complete Discord OAuth and maintain an authenticated browser session. The desktop client may store its authentication token locally so that the requested signed-in session continues.
Browser or desktop local/session storage keeps functional information requested by you or necessary for the feature being used: a guest installation identifier and resumable-operation state; operation entry/create codes for the current journey; keybind, volume, performance and onboarding preferences; saved local units, presets or data packs when not synced to an account; dashboard layout/comparison preferences; recent searches on that device; and a dismissed-update version. These values remain on the device until replaced, cleared by the feature, signed out where applicable, or removed through browser/app storage controls. They are not used for advertising or cross-site tracking.
BridgeLink does not currently set optional analytics or advertising cookies or storage. Because current storage is necessary for a requested feature or the user-selected setting itself, BridgeLink does not show a consent banner. A new non-essential analytics, advertising, embedded-media, or tracking technology must be blocked until any required consent is obtained.
BridgeLink facilitates real-time voice but does not intentionally record or store voice conversations. Encrypted voice traffic is sent between participants where possible and may temporarily pass through STUN or TURN relay infrastructure when a direct connection cannot be established.
05Recipients and service providers
BridgeLink does not sell personal data. Data is disclosed only as needed to provide the service, follow your instructions, protect the service, or comply with law. Current provider categories and recipients are:
- Railway as hosting, PostgreSQL, networking, logging, and backup provider
- Resend as transactional and preference-controlled email delivery provider
- Metered as TURN credential and relayed-voice provider when a direct voice connection is unavailable
- Stripe for checkout, subscription management, billing status, fraud prevention, tax-related information, and payment processing; Stripe acts as a processor for some services and as an independent controller for activities it determines, including regulated payment functions
- Discord as the independent operator of the Discord service and the source of OAuth identity information used by BridgeLink
- Customer-selected webhook destinations, which receive the event data an authorized organization administrator instructs BridgeLink to send
Operation participants and authorized organization members or administrators receive collaborative data according to their role and the organization’s access settings. We may also disclose information to professional advisers, authorities, or courts where legally necessary.
06International transfers
Some providers and their subprocessors process data outside Norway or the European Economic Area. This can include the United States for Railway, Resend, Stripe, or Discord, and Canada or other infrastructure locations for Metered. Where GDPR requires a transfer mechanism, BridgeLink relies on an applicable adequacy decision, the European Commission’s Standard Contractual Clauses, and any necessary supplementary measures. BridgeLink maintains a recipient and transfer register and reassesses provider changes. Contact us to request information about safeguards relevant to your data.
07Retention
- Free personal and Basic organization archives, associated AAR images, and operation-event history are deleted after 14 days. On downgrade, records already older than 14 days are eligible for deletion by the next scheduled sweep.
- Pro and Organization Premium archives have no plan-based expiry while the relevant subscription remains active. They are still deleted when no longer necessary, when the account or organization is deleted, or following a valid deletion request, subject to shared-record and legal exceptions.
- Closed resumable live-operation sessions expire after 6 to 72 hours depending on plan and organization context. Browser authentication sessions expire after 14 days.
- Connection and player activity diagnostics and search analytics are kept for 90 days.
- Webhook delivery logs and expired or revoked one-time operation codes are kept for 30 days.
- Completed or expired notifications, organization activity, and completed organization security requests are kept for 365 days. Processed Stripe webhook records are kept for 90 days. Consumer withdrawal declarations and acknowledgement evidence are normally kept for three years to document and handle the request and related legal claims.
- Account, organization, saved content, and active subscription records are kept while needed to provide the service. Billing and transaction records may be kept longer where accounting, tax, fraud-prevention, or legal rules require it.
Deletion from the live database does not necessarily remove a record immediately from encrypted backups. Backup copies are isolated from normal use and disappear through the hosting provider’s configured backup rotation unless law or a security incident requires longer preservation.
08Your rights
Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent where consent is the legal basis. The Dashboard account page provides a JSON export and self-service account deletion; contact us for any other request.
Account deletion removes personal account content and active sessions and anonymizes identity in shared records. You may first need to transfer organization ownership, finish active operations, release active fleet assets, or end an active subscription. Limited records may remain where required by law, needed for security or legal claims, or inseparable from other participants’ shared records; identity is minimized or anonymized where possible.
We normally respond within one month. You may complain to Datatilsynet, the Norwegian Data Protection Authority, or to the supervisory authority where you live or work.
09Security and automated decisions
BridgeLink uses access controls, authenticated sessions, encryption in transit, database protections, secret management, rate limits, and audit or security records intended to protect personal data. No online service can guarantee absolute security.
BridgeLink does not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, and does not use personal data for targeted advertising.
10Age limit and policy changes
BridgeLink is an 18+ service. You must be at least 18 years old to create an account, join as a guest, use an organization workspace, or buy a subscription. BridgeLink does not knowingly offer the service to children. Contact us if you believe a person under 18 has provided personal data so that we can investigate and delete it where appropriate.
Material policy changes will be dated and published here and, where appropriate, notified in the service or by email. Discord API data is used in accordance with Discord’s developer terms and policies.