Privacy policy
In short: we collect what a link platform needs to work, you can switch IP storage off per domain, nothing is sold, and nothing leaves this installation unless you connect it yourself.
Last reviewed against the code that implements it. Where this page states a number — a retention window, a cookie lifetime, a list of destinations — that number is read from the running software, not typed in by hand.
Who is responsible for what
For your account — your name, your email, your billing details — we are the controller. For the click data your links generate, you are the controller and we are your processor: it is your audience, your links and your instructions. The data processing agreement sets that out in the terms the GDPR expects.
What we collect
From you, the account holder
- Your name, email address and a password hash. We never store or log the password itself.
- Your organisation name, billing country and, for Indian customers, a GST number if you give one.
- Payment records — amount, currency, date and the gateway's reference. Card numbers never reach our servers; the payment gateway handles those.
- Sign-in events: when, from which address, and whether it succeeded. This is what lets you investigate a compromised account.
- An audit log of what was changed in your organisation and by whom.
From visitors who click your links
One row per click. It holds the time, the link and where the visitor was sent, plus:
- IP address, and the continent, country, region, city, postcode, coordinates and timezone derived from it, together with which source produced that location — a database lookup or a header from the network in front of us. The record also notes the network operator and whether the address looks like a proxy or VPN.
- Browser, browser version, operating system, device type, screen size and language, read from the request.
- The referring URL and its host, if the browser sent one, and the search term where a search engine passed one.
- Campaign parameters present on the link — source, medium, campaign, term and content.
- Whether the click came from a QR scan, which A/B variation was served, and whether it completed a goal you configured.
- Whether we judged the visitor to be a bot, and which one. Bots are recorded and labelled, never silently dropped.
From visitors to this marketing site
Page views on this website — not on the redirect path — are counted so we know which pages are useful. That uses two first-party cookies: msv, a random id that lasts 400 days, and mss, which groups the views into one visit for 30 minutes. The id is a random value, not a fingerprint of your device, so clearing cookies genuinely ends it rather than regenerating the same identity.
This installation stores the visitor's IP address for those page views in full form, and deletes site-visit records after 400 days. No third-party analytics account is connected, so nothing about these page views leaves this installation.
IP addresses, specifically
An IP address is personal data, and it is the single most sensitive thing a link platform touches. Two controls exist:
- Per domain, you can switch it off. Turn on Hide visitor IP in Domain settings and the address is used to derive the location and then discarded — the click row stores no address at all. Country and city still work.
- Platform-wide, addresses age out of click records ahead of the clicks themselves. The retention table below shows the window; the rule clears the address, user agent, coordinates and postcode while leaving every count and chart intact.
Why we collect it
Account data to run your account and bill you. Click data to produce the statistics that are the entire point of the product, and to detect abuse of the redirect service. We have no advertising business, so there is no third purpose.
How long we keep it
Two windows apply, and the shorter one wins.
The window your plan carries
How far back your own statistics can reach:
| Plan | How far back statistics reach |
|---|---|
| Free | 730 days (about 2 years) |
| Starter | 730 days (about 2 years) |
| Growth | 1,095 days (about 3 years) |
| Business | 1,825 days (about 5 years) |
| Scale | kept for as long as the account is open |
The window this installation enforces
A job runs once a day and applies these rules to everything in the database, whoever it belongs to. A rule set to keep forever is skipped.
| Record | Kept for | What happens |
|---|---|---|
| Raw clicks | 730 days | deleted |
| Click stream detail | 90 days | identifying columns cleared, counts kept |
| Aggregated statistics | kept until the operator sets a window | deleted |
| Closed support tickets | 365 days | deleted |
| Audit log | 730 days | deleted |
| Sign-in log | 90 days | deleted |
| Error log | 30 days | deleted |
| Data left by deleted accounts | 30 days | deleted |
These are the windows this installation is running right now, read from the retention policy the daily job enforces. An operator can change any of them, and the admin panel dry-runs a change before applying it.
Beyond that: account data lives while your account is open and for 30 days after you close it, so a deletion you regret can be undone; invoices are kept as long as tax law requires, which in India is eight years.
Who your data reaches
Our own processors
Only what is needed to run the service — the hosting provider, the payment gateway and the email provider. The current list, with what each one sees, is on the sub-processors page. We give 30 days' notice before adding one. We do not sell data and we do not share it for advertising.
Destinations you connect yourself
Nothing below is on by default. Each is off until someone in your organisation configures it, and each can be switched off again. Where you do connect one, you are sending your own click data to a company with its own privacy policy, and that transfer is yours rather than ours.
A click can be forwarded, per domain, to:
- Google Analytics 4
- Meta (Facebook and Instagram)
- TikTok
- X
- Snapchat
- Google Ads
- Segment
- a webhook of your own
Separately, an account can be connected to Slack, Discord, Telegram, Microsoft Teams, Microsoft 365, Google Analytics 4, GA4 Measurement Protocol, Meta Conversions API, Mixpanel, HubSpot, Zapier, Make, Asana, n8n, Pabbly Connect, Integrately, IFTTT Webhooks, Workato, Notion, WordPress, Shopify, GitHub, Webhook, MCP server, Airtable, Dropbox, Google Sheets, Segment, TikTok Ads, Snapchat Ads, X / Twitter Ads, LinkedIn Ads, Pinterest Ads, Reddit Ads, Google Ads, Mailchimp, Brevo, MailerLite, SendGrid Marketing, Google Chat, Mattermost, Rocket.Chat, Flock, Lark, Zulip, Gotify, ntfy, Trello, ClickUp, monday.com, Todoist, Basecamp, Wrike, Smartsheet, Coda, Google Drive, Google Calendar, Gmail, Microsoft Outlook, Microsoft OneDrive, Microsoft Excel, Salesforce, Zoho CRM, Pipedrive, Freshdesk, Zendesk, Intercom, Help Scout, Crisp, Klaviyo, ActiveCampaign, Kit, Constant Contact, Campaign Monitor, GetResponse, AWeber, Omnisend, Drip, SendPulse, Mailjet, Mailgun, Webflow, Wix, Squarespace, WooCommerce, BigCommerce, Ecwid, PrestaShop, Adobe Commerce, Gumroad, Eventbrite, Calendly, Typeform, Jotform, Coda · Direct, Smartsheet · Direct, Wrike · Direct, Jotform · Direct, Calendly · Direct, Trello · Direct, ClickUp · Direct, Todoist · Direct, Typeform · Direct, Pipedream, Activepieces, Zoho Flow, Albato, Tray.io, Latenode, Microsoft Power Automate. What each connection sends is listed on its own page in the dashboard before you enable it.
When the law requires it
We disclose data if we are legally required to, and we tell you first unless we are forbidden from doing so.
Cookies
Every cookie this software sets, what it is for and how long it lasts, is listed on the cookie policy. None of them are advertising cookies.
Your rights, and how to use them
If you are in the EU or UK, the rights of access, rectification, erasure, restriction, portability and objection apply, and you may complain to your supervisory authority. We honour the same requests wherever you are.
- Export — sign in and use Profile → Export data. It downloads a JSON bundle of everything your organisation owns: links, domains, clicks, conversions, invoices, team, tickets and audit log. No request to us is needed and there is no delay.
- Deletion — you can close your account and delete your data from the same profile screen.
- Everything else — access, correction, restriction, objection, or a request about someone who clicked your link rather than about you: write to privacy@shortfreeurl.com, or open a ticket. We answer within 30 days.
Being straight about the plumbing: the export and the account deletion above are self-serve and immediate. Any other kind of request is handled by a person — it reaches our compliance queue, where a deadline is recorded against it and every step is logged — but there is no public self-serve form that files one for you. You have to write to us, and we then log it. If that ever changes, this paragraph will change with it.
Children
The service is not for under-16s and we do not knowingly hold their data. Write to privacy@shortfreeurl.com if you believe we do and we will delete it.
Security
How accounts and data are protected — password hashing, two-factor, encryption of stored third-party tokens, the audit log, and how to report a vulnerability — is on the security page. We make no claim to any certification or third-party audit, because we have not had one.
Changes
Material changes are announced in the dashboard and by email at least 30 days before they take effect.
Still have a question?
Ask about anything on this page — including "what exactly do you hold about me?". A privacy question is never a nuisance, and privacy@shortfreeurl.com reaches the same queue as the form.
Open a support ticket Read the documentation
The contact form opens a real ticket, gives you a reference number and a link to follow the answer — you do not need an account. Choose General question as the subject so it reaches the right person. If you already have a ticket open, reply on its link rather than starting a second one.
Last updated 2026-09-08.

