Legal

Privacy Policy

Effective date: July 11, 2026

This Privacy Policy describes how Quoinlock (“Quoinlock,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the isbn.link website, publisher portal, resolver, APIs, hosted product pages, and related services (collectively, the “Service”). By using the Service, you agree to this Policy. If you do not agree, do not use the Service.

1. Who we are

isbn.link is operated by Quoinlock. It provides a GS1-conformant Digital Link resolver, catalog and barcode tools for book publishers, enterprise APIs, and optional hosted product pages.

For privacy inquiries, see Contact us.

2. Scope

This Policy applies to:

  • Visitors to our marketing site and documentation (e.g. about, pricing, docs, status).
  • Publisher accounts using the portal, APIs, barcode studio, bulk import, and settings.
  • End users who scan or open Digital Link URIs resolved by the Service (e.g. /01/{GTIN}), including redirects and hosted product pages you enable.

It does not apply to third-party websites or apps you link to as destinations; those are governed by their own policies. When the Service redirects a scan to your product page or another URL, that destination’s operator is independently responsible for its own privacy practices.

3. Information we collect

3.1 Account and organization information

When you register or administer an account we may collect: email address; display name; organization or imprint name; plan tier; authentication data (password credentials where used, WebAuthn / passkey public credentials, optional authenticator/OTP secrets stored in hashed or encrypted form); role memberships within a team; and billing-related identifiers if payment is enabled through a processor.

3.2 Catalog and content data

You (or systems acting for you) may provide: titles, descriptions, authors and other bibliographic fields; ISBNs/GTINs and formats; destination URLs and link settings; cover images and barcode assets; ONIX or CSV imports; custom domain configuration; webhooks; and similar publishing metadata. This content may include information about individuals (e.g. author names) that you choose to publish.

3.3 Scan and resolution telemetry

When a Digital Link is resolved we may log operational data such as: timestamp; GTIN and path/qualifiers; HTTP status and outcome (redirect, linkset, error); approximate geography (e.g. country derived from network headers when available—not precise location); coarse device class from user-agent; referrer when provided; resolver host (primary domain or verified custom domain); and whether a fallback path was used. We design scan analytics for publisher operations, not for selling personal profiles of readers.

3.4 Technical and security logs

We automatically collect IP address, request headers, timestamps, and diagnostic logs needed for security, rate limiting, abuse prevention, debugging, and uptime. IP addresses may be hashed or truncated where product design allows, subject to security needs.

3.5 Communications

If you contact support or legal, we collect the content of your message and associated contact details.

3.6 Third-party bibliographic sources

If you use optional ISBN lookup or import features that call industry metadata services, we request records on your behalf and store the results you choose to keep in your catalog (including covers obtained for catalog display). Those providers have their own terms governing access to their databases.

4. How we use information

We use information to:

  • Provide, operate, and improve the Service (resolution, catalog, barcodes, hosted pages, APIs, webhooks).
  • Authenticate users, enforce roles, and secure accounts and infrastructure.
  • Generate publisher analytics and health checks for destinations.
  • Communicate about the Service (security notices, product changes, support responses).
  • Detect, investigate, and prevent fraud, abuse, and policy violations.
  • Comply with law, enforce agreements, and protect rights and safety.
  • Develop new features and understand aggregate usage patterns.

We do not sell personal information as “sale” is commonly defined under US state privacy laws, and we do not share personal information for cross-context behavioral advertising.

6. How we share information

We may share information with:

  • Service providers (hosting, storage, email, monitoring, payment processors) under contracts that limit use to providing services to us.
  • Your organization — other seats and admins in your account may access shared catalog and analytics according to roles you configure.
  • Public by design — information you publish via resolver destinations, linksets, or hosted product pages is accessible to anyone who requests those URLs (including covers served at public cover paths you enable).
  • Legal and safety — regulators, law enforcement, or parties to legal process when we believe disclosure is required or appropriate to protect rights, safety, or the Service.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to continued confidentiality obligations.

7. Retention

We retain account and catalog data for as long as your account is active and as needed to provide the Service. After deletion or closure, we may retain limited records for legitimate business purposes (billing disputes, security logs, legal compliance) according to internal schedules.

Scan and analytics events are retained according to plan-level retention and operational needs, then deleted or aggregated. You may export analytics where the product provides export features.

Security logs are retained for a period appropriate to incident response and abuse investigation, then deleted or anonymized.

8. Security

We implement administrative, technical, and organizational measures designed to protect information, including encryption in transit (TLS), access controls, session management, rate limiting, and least-privilege practices for staff access. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

You are responsible for protecting account credentials, passkeys, API keys, and webhook secrets, and for configuring destinations and public content appropriately.

9. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or export personal data; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority.

Publishers: you can update much of your account and catalog data in the portal. For deletion of an account or assistance with rights requests, contact us (below). We may need to verify your identity before fulfilling a request.

Readers / scanners: resolution logs are typically not used to identify you. If you believe we hold personal data about you in connection with a scan or hosted page, contact us and we will evaluate your request under applicable law.

California residents may have additional rights under the CCPA/CPRA (access, deletion, correction, and information about categories of data). We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under California law.

10. Cookies and similar technologies

We use essential cookies and similar storage for authentication sessions, security (e.g. CSRF protections where applicable), and preferences such as appearance (theme). These are necessary for the Service to function.

We may use limited analytics technologies to understand aggregate traffic to marketing pages. Where required by law, we will obtain consent for non-essential cookies. You can control cookies through your browser settings; disabling essential cookies may prevent login or portal use.

11. International transfers

We may process and store information in the United States and other countries where we or our providers operate. Those countries may have different data-protection laws than your country of residence. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers of personal data from the EEA/UK.

12. Children

The Service is directed to publishers and businesses, not to children under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

13. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised Policy on this page and update the effective date. For material changes, we may provide additional notice (e.g. email to account owners or a notice in the portal). Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

14. Contact us

For privacy questions or requests, contact:

Related: Terms of Service. This Policy is provided for transparency and does not create rights beyond those required by applicable law except as expressly stated in a written agreement with Quoinlock.