LinkRunway uses explicit SDK consent, suppresses attribution for DNT and GPC clicks, separates public and server keys, and keeps raw IP addresses out of stored click records. Deployment owners control retention and access policies.
Before you begin.
- A defined purpose for each collected event
- Your own consent and privacy notices
- A deployment-level retention and deletion process
Start with a deliberate choice.
Enable SDK collection after the consent appropriate to your application. Revoking consent clears attribution state and queued SDK events. DNT and GPC requests suppress click attribution.
- Test both acceptance and refusal in your consent interface.
- Keep collection disabled before the choice is made.
- Do not use referral codes or metadata to bypass a declined choice.
Pass context, not a dossier.
Use opaque customer and sharer IDs. Send only the metadata needed to understand the campaign or product action. Keep personal data out of URLs, which can appear in browser history, referrers, and infrastructure logs.
- Prefer a campaign ID to a descriptive customer profile.
- Do not put email addresses, names, or payment details into a link.
- Review reverse-proxy logs independently of application storage.
Keep sensitive actions on the server.
Canonical identity and financial events require server keys. Workspace roles limit console actions; tenant-scoped queries keep workspaces separate. Integration credentials are encrypted at rest with a deployment-managed key.
Make the deployment match the promise.
Define who can access data, where it is hosted, how long it is retained, and how requests for deletion are completed. Automated retention and deletion are not implemented here; your operator must supply and test that process.
- Use TLS and a stable secret-management process.
- Document backups, retention periods, and deletion from downstream systems.
- Publish your business’s actual privacy notice before launch.
Find the missing connection.
A click is visible but has no attribution
Privacy-suppressed traffic can remain as an aggregate click without an attribution token. Do not try to reconstruct an identity.
Encrypted credentials stop decrypting
Restore the stable integration encryption key or reconnect the provider. Rotating the key requires a planned data migration.
A customer requests deletion
Follow your operator’s documented process, including backups and downstream exports. This guide is not a deletion endpoint.
Reviewed October 10, 2026 · LinkRunway documentation
