Privacy Policy
This Privacy Policy describes how ShieldLink processes the personal data of people who use the ShieldLink browser extension, the website shieldlink.cloud, and the subscription service (paid plans). It is governed by Law 1581 of 2012 and Decree 1377 of 2013 of the Republic of Colombia, and by the General Data Protection Regulation (Regulation (EU) 2016/679 — GDPR) with respect to users located in the European Economic Area.
1. Data Controller
- Controller: Diego Alexander Carvajal (natural person), founder of ShieldLink.
- Identification: C.C. No. 1.144.171.850.
- Domicile: Bogotá D.C., Colombia.
- Contact for data protection and exercise of rights: protecciondedatos@shieldlink.cloud
For GDPR purposes, the Controller acts as Data Controller with respect to the data described in this policy.
2. Scope
This policy applies to three contexts, which process different data:
| Context | Who it applies to |
|---|---|
| Browser extension | People who install and use the extension |
| Subscription service (retail) | People who subscribe to a paid plan |
Website shieldlink.cloud |
Visitors to the public site |
Corporate/B2B use (organizations that deploy ShieldLink to their employees) is additionally governed by Section 11.
3. What data we process and for what purpose
3.1 Browser extension
ShieldLink has a single purpose: to detect and block phishing and brand-impersonation sites. All processing is limited to that purpose.
- Page addresses (URLs / web history): the extension analyzes the page URL locally. When the result is uncertain (the "gray zone"), that URL is sent to our backend to check its reputation (VirusTotal), its age (crt.sh) and, where applicable, an AI analysis. These queries are transient; we do not build or store your browsing history.
- Page content, only upon suspicion (AEGIS Vision): if a page is already suspicious and visual analysis is enabled, the extension captures an image and a text sample of that tab solely to detect visual impersonation, and discards it after analysis. A capture may incidentally contain data visible on screen; ShieldLink does not extract or store it.
- License and device data: a random device identifier (
extension_instance_id), the token/license, and aggregated security counters (e.g., number of blocks). These validate the license, sync lists, and produce the security report.
3.2 Subscription service (retail)
When you subscribe to a paid plan:
- Email address: we receive it from the payment gateway (Mercado Pago) upon completing the subscription, to send you your license, manage the subscription, and provide support.
- Payer identifier and subscription reference: technical data provided by Mercado Pago (payer ID, subscription ID, plan, dates, status) to reconcile the payment and administer your license (activation, renewal, expiry, cancellation).
- Payment data (card, etc.): we do NOT process or store it. Payment is processed by Mercado Pago, which acts as controller of that data under its own policy.
3.3 Website
- Usage analytics (Umami): we measure visits in an aggregated, cookieless way, without identifying you personally.
- Server logs: IP address and connection data, retained for a limited time, for security and abuse prevention.
3.4 Legal basis
| Purpose | Legal basis (GDPR, Art. 6) | Legal basis (Law 1581) |
|---|---|---|
| Provide the extension's protection | Performance of a contract / legitimate interest | Data subject's authorization |
| Manage your subscription and send your license | Performance of a contract | Data subject's authorization |
| Security, fraud and abuse prevention | Legitimate interest | Authorization / controller's interest |
| Comply with legal obligations (e.g., accounting/tax) | Legal obligation | Legal obligation |
| Website analytics | Legitimate interest | Authorization |
4. What we do NOT do
- We do not read the content of your emails, documents, chats, or forms.
- We do not collect passwords, credentials, or authentication data.
- We do not store card or payment data (handled by Mercado Pago).
- We do not profile you for advertising or sell your data.
- We do not perform keylogging or track clicks, mouse, or behavior.
- We do not collect health or location (GPS) data.
- We do not make automated decisions with legal effects on you.
5. Who we share it with (Processors)
ShieldLink does not sell or transfer your data. It transmits only the strictly necessary information to providers acting on ShieldLink's behalf (processors), under confidentiality and security obligations:
| Provider | What it receives | Purpose | Location |
|---|---|---|---|
| Mercado Pago | Payment data and email | Process the subscription charge | LatAm |
| Resend | Customer email + email content | Deliver the license by email | USA |
| VirusTotal | The URL to evaluate | URL reputation | USA |
| AI provider (Anthropic) | URL, technical signals and —only in visual analysis— the capture | Issue the security verdict | USA |
| crt.sh | The domain | Estimate domain age | — |
| Umami | Aggregated site metrics (cookieless) | Visit analytics | Provider cloud |
The keys for these services are encrypted on ShieldLink's server and never travel to the browser.
6. International data transfers
Some processors are located outside Colombia and the EU (e.g., the USA). These transfers are carried out with appropriate safeguards: standard contractual clauses (SCC) or other valid mechanisms under the GDPR, and in accordance with the principles of Law 1581 and the guidelines of the Superintendence of Industry and Commerce (SIC). By using the service, you authorize such transfers for the purposes described.
7. Retention
We apply data minimization: we keep data only as long as necessary.
- URLs and captures: transient processing (real-time analysis); not retained.
- Email and subscription data: while the subscription is active and, after termination, for the period required by legal obligations.
- Billing/payment records: in accordance with Colombian tax and commercial regulations (generally up to 5 years).
- Aggregated security metrics: limited retention, in aggregated form.
- Server logs: approximately 14 days.
8. Security
- Encryption in transit: all communication travels over HTTPS/TLS.
- Encryption at rest: secrets (third-party keys, tokens) are stored encrypted on the server.
- Zero secrets on the client: service credentials do not live in the extension.
- Minimal surface: only strictly necessary permissions and services are used.
- Signature verification of payment notifications; anti-injection controls; and security testing prior to each production deployment.
No system is infallible; in the event of a security breach affecting personal data, we will act in accordance with applicable law, including, where appropriate, notifying the authority and affected data subjects.
9. Your rights
As a data subject (Law 1581, Colombia) you have the right to: access, update, and rectify your data; request proof of authorization; be informed of its use; file complaints with the SIC; revoke authorization and/or request deletion where applicable; and access your data free of charge.
As a data subject (GDPR, EU) you have the right to: access, rectification, erasure ("right to be forgotten"), restriction of processing, portability, objection, and not to be subject to automated decisions; as well as to lodge a complaint with your supervisory authority.
10. How to exercise your rights
Write to protecciondedatos@shieldlink.cloud stating your request and contact details. We will respond within the legal deadlines:
- Law 1581: consultations within 10 business days; complaints within 15 business days (extendable as provided by law).
- GDPR: generally within 1 month (extendable to 2 months in complex cases).
You may disable optional layers (AI / visual analysis) from the extension options, cancel your subscription from Mercado Pago, and uninstall the extension at any time (whereupon all local processing ceases).
11. Use in organizations (B2B)
When ShieldLink is deployed in an organization, the organization is the Data Controller with respect to its users and ShieldLink acts as a Processor, per its instructions and this policy. The administrator manages licenses, lists, appearance, and policies, and may receive the aggregated security report.
12. Minors
ShieldLink is a general-purpose security tool, not directed at minors, and does not knowingly collect their data.
13. Supervisory authorities
- Colombia: Superintendence of Industry and Commerce (SIC) — Deputy Office for the Protection of Personal Data.
- EU: the supervisory authority of your country of residence.
14. Changes to this policy
We may update this policy. We will publish the current version at shieldlink.cloud/privacy with its update date. When a change is material, we will inform you by reasonable means.
Drafted as a technical-legal draft. We recommend review by a data protection lawyer before publication, especially due to payment handling.