Trust & Security
This page is maintained by Luhte (Bayl.ink operator) to answer common security and privacy questions. It describes what we do today - not certifications we hold.
Encryption in transit
All traffic to bayl.ink and custom domains is served over HTTPS with HSTS enabled.
Isolated user data
Row-level security policies scope every read and write to the account that owns the data.
Payments via Stripe
Card details never touch our servers. Stripe (PCI DSS Level 1) processes all payments and payouts.
GDPR data rights
Export or permanently delete your account and data from Dashboard → Settings at any time.
Certified hosting infrastructure
Runs on infrastructure operated by providers that hold SOC 2 and ISO 27001 certifications. These certifications apply to those providers, not to Bayl.ink itself.
Security contact
Report vulnerabilities or abuse to luhte@luhte.com. We aim to acknowledge within 72 hours.
Shared responsibility
Bayl.ink is not SOC 2, ISO 27001, or PCI DSS certified as an organization. Our underlying infrastructure providers (hosting, database, payments) hold their own certifications that cover the platform layer. You remain responsible for the content you publish on your profile and for keeping your login credentials secure.
Your rights (GDPR)
- Access & portability: download a JSON export of your data.
- Erasure: permanently delete your account and public profile.
- Rectification: edit your profile, links, and theme at any time.
- Contact our data controller: luhte@luhte.com - Luhte, Finland.