bayl.ink

Trust & Security

This page is maintained by Luhte (Bayl.ink operator) to answer common security and privacy questions. It describes what we do today - not certifications we hold.

Encryption in transit

All traffic to bayl.ink and custom domains is served over HTTPS with HSTS enabled.

Isolated user data

Row-level security policies scope every read and write to the account that owns the data.

Payments via Stripe

Card details never touch our servers. Stripe (PCI DSS Level 1) processes all payments and payouts.

GDPR data rights

Export or permanently delete your account and data from Dashboard → Settings at any time.

Certified hosting infrastructure

Runs on infrastructure operated by providers that hold SOC 2 and ISO 27001 certifications. These certifications apply to those providers, not to Bayl.ink itself.

Security contact

Report vulnerabilities or abuse to luhte@luhte.com. We aim to acknowledge within 72 hours.

Shared responsibility

Bayl.ink is not SOC 2, ISO 27001, or PCI DSS certified as an organization. Our underlying infrastructure providers (hosting, database, payments) hold their own certifications that cover the platform layer. You remain responsible for the content you publish on your profile and for keeping your login credentials secure.

Your rights (GDPR)

  • Access & portability: download a JSON export of your data.
  • Erasure: permanently delete your account and public profile.
  • Rectification: edit your profile, links, and theme at any time.
  • Contact our data controller: luhte@luhte.com - Luhte, Finland.
See also Privacy Policy and Terms of Service.