Privacy Policy

Effective Date: September 2, 2026 • Last Updated: September 2, 2026

At ShortLink (“we”, “our”, or “us”), we take your privacy seriously. We operate with a core commitment to data minimization and privacy by design: we do not sell your personal information, we do not engage in invasive cross-site user fingerprinting, and we collect only the minimal data strictly necessary to shorten URLs, provide click analytics, serve advertisements, and protect our infrastructure from abuse.

This Privacy Policy explains what information we collect when you visit our website, use our shortening tools, generate QR codes, or click on a shortened link created via ShortLink, and how you can exercise your privacy rights.

1. Information We Collect

A. Information You Provide Directly

  • Destination URLs: When you submit a long URL to shorten, we store the original destination web address to enable the redirection service.
  • Custom Aliases: If you choose a custom alias (e.g., /my-campaign), we store this identifier alongside your destination URL.
  • QR Codes: When generating a QR code, the code encodes your shortened link; we do not store additional personal data during QR generation.
  • Communications: If you reach out to our support or abuse teams, we collect your email address and any details provided in your correspondence.

B. Click & Analytics Data (When a Link is Visited)

When someone clicks a ShortLink shortened URL, we log minimal, privacy-centric metadata to provide aggregate click statistics to the link creator. We specifically protect user anonymity:

  • Anonymized IP Hashing: We do not store raw IP addresses in our database. Each incoming IP is irreversibly transformed via a one-way cryptographic SHA-256 hash combined with a secret cryptographic salt before recording, preventing re-identification.
  • Approximate Geolocation: We record the visitor’s country code (e.g., “US”, “DE”) derived at the edge network header (x-vercel-ip-country). We never collect exact GPS coordinates, cities, or street-level locations.
  • Device & Browser Information: We inspect the HTTP User-Agent header to categorize visits into high-level device types (Mobile, Tablet, Desktop) and common browser engines.
  • Referrer: We record the HTTP Referer header to identify the referring domain or application where the link was clicked.
  • Timestamp: The exact date and time the redirection occurred.

2. How We Use Your Information

We process collected information for the following legitimate purposes:

  • URL Redirection: Resolving requested short slugs and delivering immediate HTTP 308 Permanent Redirects to destination URLs.
  • Aggregate Analytics: Generating high-level click counters and analytics graphs (total clicks, daily timeline, device breakdown, top countries) accessible to the creator.
  • Abuse & Threat Mitigation: Identifying and filtering automated bot traffic, crawlers, DDoS attacks, spam links, malware, and phishing attempts before logging clicks or routing traffic.
  • System Reliability: Monitoring server performance, debugging operational errors, and ensuring high service availability.

3. Cookies and Local Storage

First-Party Cookies & Local Storage: ShortLink does not use tracking cookies for guest users. We utilize browser Local Storage on your local device to store a list of links you created as a guest, so you can easily reference and copy them from your browser without requiring a user account.

Third-Party Advertising Cookies: To keep our core URL shortening services free and accessible, we display advertisements provided by reputable third-party advertising partners (such as Google AdSense and advertising networks). These partners may use cookies, web beacons, or unique device identifiers to deliver relevant advertisements based on visits to this and other websites. You may opt out of personalized advertising by visiting the Digital Advertising Alliance Consumer Choice page or Google Ads Settings.

4. Data Sharing and Third-Party Vendors

We never sell, trade, or monetize your personal data. We share information only with trusted service providers who help us operate our infrastructure:

  • Cloud & Hosting Infrastructure: Global edge compute providers (e.g., Vercel) and managed PostgreSQL cloud databases (e.g., Neon) that host our services under strict data processing agreements.
  • Advertising Partners: Third-party ad networks that serve non-invasive display banners on our pages.
  • Legal Compliance: When required by a valid court order, subpoena, or applicable law, or to investigate and protect against malicious cyber attacks or fraud.

5. Data Retention & Security

Short links remain active indefinitely unless they are set to expire, deleted, or removed due to an abuse report or terms violation. Aggregated click statistics are stored alongside the link record.

We implement industry-standard technical safeguards, including TLS 1.3 encryption in transit, strict rate limiting, cryptographic hashing of IP addresses, database firewalls, and least-privilege administrative access controls to safeguard all data.

6. Your Rights Under GDPR & CCPA/CPRA

Depending on your location (including the European Economic Area, United Kingdom, and California), you may have statutory privacy rights regarding your personal data, including:

  • The right to access and receive a copy of data we hold about you.
  • The right to rectify or update inaccurate personal information.
  • The right to request deletion (“Right to be Forgotten”) of your links or submitted data.
  • The right to object to or restrict certain types of data processing.
  • The right to non-discrimination for exercising your privacy rights.

To exercise any of these rights, please email us at privacy@shortlink.com. We will verify and process your request within statutory timeframes.

7. Children’s Privacy

ShortLink is not directed to children under the age of 13 (or under 16 in the EEA). We do not knowingly collect or solicit personal information from children. If you believe a child has provided us with personal data, please contact us immediately so we can promptly delete the information.

8. Changes to This Policy

We may periodically update this Privacy Policy to reflect enhancements to our service, security practices, or changes in legal regulations. When changes are made, the revised policy will be posted on this page with an updated “Last Updated” date.

9. Contact Us

If you have questions, feedback, or concerns regarding this Privacy Policy or our data handling practices, please contact us at:

ShortLink Privacy & Data Protection Team

Email: privacy@shortlink.com

Abuse Inquiries: abuse@shortlink.com