Google & Meta tracking
Google Ads Data Manager, GA4 Measurement Protocol and Meta Conversions API. Connect accounts and inspect delivery results.
Explore setup →You are not buying a link shortener; you are putting a redirect in front of your customers, a domain in front of your brand and a click log in front of your data protection officer. This page tells you exactly what the software does, which plan already includes it, and what it does not do — so the answer to your questionnaire is on the page rather than in a follow-up call.
Most of what follows ships on a self-serve plan. Scale is $140 a month and uncaps everything — an agreement is for contract terms, invoicing and a response target, not for a hidden feature set.
These four are counted from this installation's own database when you load the page. We do not publish a customer count or a logo wall, because we are not going to put a number or a brand on this page that you cannot check. The 99.9% availability figure elsewhere on this site is a committed target with service credits, not a measurement.
Answered below in the order a security questionnaire tends to arrive in. Every claim on this page is implemented in the product today; anything that is not is in what we do not do, named rather than omitted.
Build repeatable campaigns and support workflows with visible permissions and usage limits.
Browse direct connectors and 47 guided HTTP workflows. OAuth providers require administrator app credentials; key-based services use a token or webhook. Guides show which setup applies before you connect.
The server rechecks feature access and connection limits for requests and background deliveries. Revoking a connection also revokes its generated API key. Expired plans return to Free access.
The administrator can configure provider routing, approved repair tools, confidence thresholds and human review. Ticket actions keep an audit trail. Provider credentials and automation settings must be configured before AI can run.
Allow or block selected incoming parameters, choose how duplicates are handled and set a destination anchor. Preview the result before changing a campaign link.
Follow screenshot-led workflows for domains, links, targeting and reporting. The API reference includes 22 request example formats and a scoped-key request console.
Your directory stays the source of truth for who works here, and the audit trail answers who did what.
Each workspace gets its own ACS endpoint. Your identity provider posts the assertion there, we read the email and display name out of it, and the person lands in the dashboard. You set the entry point, entity ID and certificate from the workspace settings — there is no ticket to raise and nothing for us to configure at our end.
A person who signs in through SSO for the first time and has no account gets one created, added to the organisation and added to the team the assertion arrived for. You do not pre-load a user list before a rollout.
A workspace can be marked SSO-required, so a password is no longer a way in for anyone in it.
Owner, admin, user and read-only. The check runs in the API layer rather than in the interface, so a role limit holds for an API key and a curl request exactly as it holds for a button that is greyed out.
Name the people who may open and edit one specific link. Everyone else in the organisation gets a 404 on it, including through the API. This is what protects a URL that is already printed on packaging from being repointed by someone who did not know.
Separate brands, regions or subsidiaries into teams, each with its own domains, members and SSO connection, all billed once.
TOTP from any authenticator app, plus WebAuthn passkeys and hardware security keys. Every active session is listed and can be revoked one at a time or all at once.
Sign-ins, link edits, domain changes, permission changes and billing events, each with the person, the entity, the IP and the timestamp. Filter by action, user or date range, and pull it out as CSV whenever your reviewers ask. It is not held back for a higher tier — the free plan has it.
The redirect is the part your audience touches. It is deliberately the simplest thing we run.
Point a DNS record at us and the certificate is issued and renewed for you, apex domains included. There is nothing to remember and nothing that expires at 2am on a bank holiday.
If your security policy says the private key for a company domain never leaves your CA, upload the certificate and key yourself instead of letting us issue one.
An HMAC signature on the short URL, so a link cannot be forged or its parameters tampered with between your system and the visitor.
Restrict which hostnames anyone in the organisation may point a link at. An open redirect on your own brand domain is an incident; this is the setting that prevents it.
A scheduled job visits monitored destinations, follows the hops by hand so a redirect loop is caught rather than exhausted, and checks DNS and certificate expiry on your connected domains. You hear about a broken destination before your audience does.
Measurement tags are loaded on the marketing site only. The redirect and the dashboard never load someone else's JavaScript, which is one fewer supply-chain question for your reviewer to ask.
Your click data is yours. Getting it out again is a supported operation, not a support ticket.
Statistics queries are bounded by the retention window your plan carries — 730 days on Free and Starter, 1,095 on Growth, 1,825 on Business, unlimited on Scale. Separately, the operator sets a platform retention policy for clicks, click detail, aggregates, closed tickets, the audit log, the sign-in log and the error log, and a daily job enforces it. That job can be dry-run first, so nobody deletes a year of history by accident.
Links, the click stream, statistics, the audit log and the bulk sheet all export as CSV or XLSX from the dashboard and from the API. Nothing is trapped behind a screen.
One request returns the account, organisations, domains, links, folders, bundles, posts, conversions, invoices and the last 5,000 audit entries as a single JSON bundle. It exists for GDPR subject requests, and it is equally the answer to "what happens if we leave".
Weekly and monthly reports run on a schedule and are delivered to the addresses you nominate. Where the operator has not connected a mail provider, the job says so plainly rather than pretending to have sent them.
Every click can be posted to an endpoint you own, with delivery attempts recorded so a failure is visible rather than silent. Use it when you want each click as it happens; use the daily export when you want the whole day in one file.
A daily job writes the previous UTC day's raw clicks as gzipped newline-delimited JSON — one file per domain you switch it on for — and uploads each file to an S3-compatible bucket with a signed PUT. The file is written to disk before it is uploaded, so a bucket that is misconfigured or unreachable loses the upload and not the data, and the run says which of the two happened. One thing to be clear about: the upload is signed with the credentials your operator connected, so a bucket you own needs a policy granting that principal write access. We do not assume the role ARN you save.
Visitor IP storage can be switched off per domain, in which case the country, region and city are still derived but the address itself is never written. Referrer hiding and a robots policy are separate switches.
The numbers a capacity planner asks for, taken from the plan table rather than from a brochure.
The limit is per plan and printed on the pricing page: 50 requests a second on Free and Starter, 100 on Growth, 200 on Business, 500 on Scale. An individual API key can be given a lower limit than its plan if you want a script boxed in. It is enforced in the API middleware, so it is the same number in production as on the page.
Keys are scoped to the whole organisation, one team or one domain, can carry an expiry date, are stored hashed, and can be revoked without touching the others. Last-used time is recorded so you can find the key nobody remembers issuing.
Import from CSV or a spreadsheet with a preview before anything is written, edit thousands of links as a sheet and apply the diff in one pass, and download the errors from a failed row as their own CSV so you fix and re-run only what broke.
Links, domains, team members, tracked clicks, conversions, folders, storage and retention are all uncapped on Scale. Enterprise exists for contract terms and support, not to unlock a number.
Any single limit or feature can be granted to one organisation without moving it to another plan, with an optional expiry date for a pilot. This is how a bespoke arrangement is honoured in the product instead of in a spreadsheet.
See where people discover your links. Markers show recorded click activity by country, sized by volume.
3 countries plotted · 72 clicks behind the markers.
This platform runs from wherever it is deployed, in one place. There is no multi-region edge network, so the figures below are what we aim at from a single deployment. They have not been measured from the regions named, and we will not print them as though they had been.
| Same region as the deployment | under 50 ms target |
|---|---|
| Neighbouring continent | under 150 ms target |
| Furthest point from the deployment | under 300 ms target |
Measured availability of the redirect path is in the band at the top of this page, and the full record is on the status page.
The importer and the cut-over are product features, not a professional-services engagement. Bitly, Rebrandly, TinyURL, Cutt.ly and Short.io exports are recognised by their own column headings.
Bitly, Rebrandly, TinyURL, Cutt.ly and Short.io exports are recognised by name, and any CSV with a destination and a slug column works. The importer maps the column headings each of those tools produces — a Bitly export's "Bitlink" column becomes the slug, tags split on commas, pipes or semicolons — so you upload the file you already have rather than reshaping it first.
The preview pass parses the file, shows what each row would create and lists the rows it cannot read, before a single link exists. Errors from a real import come back as their own CSV, so you correct and re-run only the failures.
Point the A record for your branded domain at the redirect IP the migration screen shows you. The certificate is issued automatically. Your old provider keeps serving until you are satisfied.
While the migration is switched on, a slug we do not know is looked up against your old domain, the visitor is redirected there, and the answer is cached. Nothing 404s during the cut-over, including links from a campaign nobody remembered to export.
Usually about thirty days. At that point the old account can be closed. The importer, the migration screen and the fallback switch are all in the product — none of it needs us to run a script for you.
Bulk import, the bulk edit sheet and error CSVs are on every paid plan, from Starter. See what each plan carries.
This platform is software that somebody runs. Several of the controls a reviewer cares about are set by whoever operates this installation, not shipped switched on, and it would be misleading to present them as ours:
The security page, the data processing agreement, the sub-processor list and the service level are the documents your reviewer will want. They are public — you do not have to ask us for them under NDA.
A sales page that lists only capabilities is a page you have to fact-check. These are the things a large buyer asks for that this product does not have. None of them is coming "soon" unless we tell you a date, and we will not.
There is no SCIM endpoint. Accounts are created just-in-time on first SSO sign-in, and de-provisioning is done by removing the member in the dashboard or through the API — an IdP that deactivates a user does not currently reach us on its own.
The daily click export is built and runs — a gzipped NDJSON file per domain per day, written to disk and then uploaded with a signed S3 PUT. What it does not do is call STS and assume the role ARN you save. The upload is signed with the credentials your operator connected in the integrations hub, so writing to a bucket you own means granting that principal access through your bucket policy. The ARN field is kept because that is the identity most policies are written against, but nothing in this product assumes it yet.
Not built. The export routes and the click webhook are the supported ways into a warehouse today.
The platform runs wherever the operator deploys it, in one place, on one database. There is no per-customer region selection and no multi-region replication. If your policy requires data to stay inside a specific jurisdiction, the honest answer is a dedicated installation in that jurisdiction, which is a conversation rather than a setting.
We do not have one, and we will not imply otherwise. What exists is written down: the security page, the sub-processor list and the data processing agreement all describe what the software actually does and what the operator is responsible for.
20 of them, answered from the code rather than from a positioning document.
Every self-serve tier has a public price, and Scale — the top one — is the ceiling of what you can buy with a card. Enterprise is not a bigger number on top of that; it is a contract. What it costs depends on committed volume, the term, the payment method and what support response you need, so it is quoted rather than listed. If you want a price today rather than a conversation, the pricing page has four of them.
Mostly no, and we would rather say so. Nearly everything described above ships on a self-serve plan: roles and teams from Growth, per-link permissions, multiple teams, custom certificates and priority support from Business, SSO and unlimited everything from Scale. The audit log, the API and automatic TLS are on every plan including Free; webhooks and exports start on Starter. An agreement buys contract terms, invoicing, a named response target and per-organisation limits — not a hidden feature set.
Annual is the normal term, and annual billing is a 17% saving on the published self-serve prices too. Monthly is possible on an agreement; it costs more per month for the same reason it does everywhere else. There is no multi-year lock-in requirement.
On an agreement, yes — that is arranged in the sales conversation. Be aware that the self-serve product has no PO workflow in it: card and UPI payments are taken by our payment provider and a numbered tax invoice is issued automatically for each one. Invoicing against a PO happens outside the checkout, not through it.
The published service level is 99.9% monthly availability on the redirect path, with service credits of 10%, 25% or 50% of the monthly fee depending on how far below that a month falls, applied automatically to the next invoice. The dashboard and the API are best-effort and carry no credit — they are separate from the redirect path on purpose, so an incident in one cannot take the other down. Full terms are on the service level page.
Yes. The status page is computed from recorded self-checks and from nothing else, which is why it tells you how far back it has measured instead of asserting a figure it cannot support. The band at the top of this page shows the same measured number. If the installation is new, it will say so.
The sub-processor list names every third party and what each one sees: the hosting provider, the payment provider, the email provider and a local IP geolocation database that sends nothing back. None of them is an advertising network, and none receives data for its own purposes. We give 30 days' notice before adding one, so you have time to object.
There is a published data processing agreement that forms part of the terms: we act as your processor for click data, process only on your documented instructions, bind everyone with access to confidentiality, help with subject requests, notify you of a personal data breach within 72 hours of becoming aware, and delete or return data at the end. Transfers out of the EEA or UK rely on the Standard Contractual Clauses. We will also review your own paper.
No. Nothing in this product has been through either audit, and we will not imply that it has. What we can give you is specific: the security page lists the technical measures, the sub-processor page lists who touches data, the DPA sets out the obligations, and the audit log lets you verify what happened in your own account rather than take our word for it.
Not as a setting. The platform runs in one place, on one database, wherever it is deployed — there is no per-customer region selection and no multi-region replication. If a residency requirement is firm, the realistic answer is a dedicated installation in that jurisdiction, which is a conversation rather than a checkbox.
It is self-service and usually a single sitting. You enable SAML on the workspace, paste in your identity provider's entry point, entity ID and signing certificate, and copy the ACS URL the settings screen shows you into your provider. A person signing in for the first time is provisioned automatically. SSO is included from the Scale plan onwards, so you do not need to talk to us to switch it on.
No. There is no SCIM endpoint. Accounts are created just-in-time on first SSO sign-in; removing someone is done by removing the member in the dashboard or through the API, or by cutting them off at your identity provider so they can no longer authenticate. If SCIM is a hard requirement, it is not built and we will not pretend otherwise.
A seat is a member of the organisation. Free is one, Starter two, Growth five, Business fifteen, and Scale is unlimited. Read-only members count as members. A single organisation can be given a higher seat count than its plan without moving plan, which is how a bespoke number is honoured.
The API limit is per plan — 50 requests a second on Free and Starter, 100 on Growth, 200 on Business, 500 on Scale — and it is enforced in the API middleware, not merely documented. An individual key can be given a lower ceiling than its plan. A higher ceiling than the plan is a per-organisation override, which is part of an agreement.
The importer recognises Bitly, Rebrandly, TinyURL, Cutt.ly and Short.io exports by their own column headings, previews every row before anything is written, and returns failed rows as a CSV you can fix and re-run. During the DNS cut-over, fallback resolution forwards any slug we do not know yet to your old domain and caches the answer, so nothing breaks while you switch. Every step of that is in the product.
Yes, from the Business plan. Certificates are normally issued and renewed automatically, apex domains included, but if your policy requires your own CA you can upload the certificate and key instead.
The software is a single Node process with a SQLite database and no third-party runtime dependencies, so it is genuinely deployable on your own machines — there is a Dockerfile and a deployment guide in the repository. Whether that is offered to you, and on what licence and support terms, is a conversation. It is not something you can buy from the pricing page.
Every message becomes a tracked ticket with a reference, whether it comes from this page, the contact form or the dashboard, and it is answered by email against that reference. Priority support puts a ticket higher in the queue from the Business plan onwards. A named response target and an escalation path to a person are part of an agreement rather than a plan.
You can put a request in front of the people who decide, and a large customer is heard sooner than a small one — that is honest rather than special. What we will not do is put a date on a feature in a sales conversation. If something on the roadmap section of this page is a condition of your purchase, say so now and we will tell you plainly whether it is being worked on.
You export it: the whole account as a JSON bundle, the links and click stream as CSV, the audit log as CSV, all from the product without asking us. Your branded domains are yours — you point the DNS somewhere else and the links keep working at whatever you point them at. After the agreement ends, the data is deleted or returned in line with the DPA.
This opens a tracked ticket with a reference, not an email into a void. If your requirement is something on the "what we do not do" list above, say so — we will tell you straight away rather than after two calls.
Prefer to start without talking to anyone? Create a free account — the audit log, the API and automatic TLS are all on the free plan; exports and webhooks start on Starter.
Choose the tools you need and see exactly which plan includes them. 72 available integrations, 45 guided workflows and 9 planned listings; planned listings are not working connectors.
Google Ads Data Manager, GA4 Measurement Protocol and Meta Conversions API. Connect accounts and inspect delivery results.
Explore setup →Snapchat, TikTok, X, LinkedIn, Pinterest and Reddit event connectors. Provider permissions and configuration are required.
Explore setup →Mailchimp, Brevo and supported email providers: select a list and create a campaign draft from a short link. Review and send in the provider.
Explore setup →Zapier, Make, Slack, Segment and WordPress. Browser extensions, REST API and SDKs use the same workspace quotas.
Explore setup →Other app connections and guided HTTP workflows with Make, Zapier or n8n. Follow the full illustrated setup guide.
Explore setup →Import selected URLs from supported task, form, document and scheduling accounts. API creation allowances apply.
Explore setup →Connect multiple accounts for the same provider within the plan connection allowance; manage and disconnect each independently.
Explore setup →Use current dashboard features on Android; download WordPress, SDKs and CLI installation guides. Purchases and API limits remain server-enforced.
Explore setup →Ask questions about current guides, API setup and plans; follow cited instructions and escalate account-specific problems to Support.
Explore setup →USD monthly prices. Provider subscriptions may cost extra. API-created links consume the plan's automation allowance; website links and automation are separate. Compare full plans.