Privacy Policy
Last updated: September 2026
This policy explains what data Shortlink processes and why.
Account data
- When you register we store your name, email address and a hashed password. Sessions are stored server-side and identified by a random cookie.
Click analytics
- When someone opens a short link we record the time, the link, the country/region/city derived from the request (when provided by the hosting platform), the device type, browser, operating system, the referring site and any UTM parameters.
- We do not store raw IP addresses. Requests are de-duplicated with a keyed, daily-rotating hash of the IP address and user agent that cannot be reversed.
- A first-party cookie may be set on the short-link domain to remember a click id for the link and, for password-protected links, that the password was entered.
Abuse reports
- If you report a link we store the name, email address and description you submit so we can review the report and contact you if needed.
Third parties
- The service can be self-hosted; in that case the operator of the instance is the data controller. Optional integrations (webhooks, custom domains) send data only to endpoints you configure.
Your rights
- You can delete your account from the account settings page. To exercise other data-protection rights contact abuse@[placeholder].