Privacy Policy
Last Updated:
1. What we collect
This policy describes what Shorty actually collects when you use the service.
- Account information — when you register: your email address, a securely hashed password, an API key, your chosen plan, and the IP address used at registration and login.
- Link information — the long URLs you shorten, the short slugs we assign, and any QR-code settings you save.
- Click / request data — when someone visits a short link we create, we record technical data: IP address, user-agent (browser/device) string, referring page, timestamp, and an approximate country from a built-in offline geolocation lookup. Each link also keeps a running click count.
- Cookies — we set a cookie containing a signed session token when you log in, so you stay authenticated. Access to the admin area sets a separate short-lived session cookie. Your theme preference (dark/light) is kept in your browser’s local storage on your device, not on our server.
- Abuse reports — when you use the Report Abuse form, we store the reported short URL, the reason, any additional details you provide, and (if you give one) your email address, so we can review and act on the report.
2. Why we collect it
- To provide and secure the service, including authentication and abuse detection.
- To power the click analytics (country, referrer, device) shown in your dashboard.
- To detect and disable malicious or permitted-only links, and to enforce our Acceptable Use Policy.
3. Cookies
We use a first-party token cookie (httpOnly) to keep you logged in, and an admin_session cookie for the operator’s admin area. We do not currently use third-party advertising or analytics cookies.
4. Analytics
Analytics are produced from the data described above using built-in tools (e.g., an offline IP-geolocation database). We do not currently embed third-party analytics trackers such as Google Analytics.
5. Retention
We retain link and click data as long as needed to operate the service and respond to abuse. You may ask us to delete your account and the data associated with it (see Contact). We may keep a minimal record for legal or security purposes where required.
6. Security
We use HTTPS, sign session tokens, hash passwords, and restrict the admin area to the operator. No system is fully secure, and we cannot guarantee absolute protection. If you find a security issue, please use our Security page.
7. Sharing with third parties
- During the normal operation of
Shorty, we do not sell your data. - We may disclose information if required by law, a valid legal request, or to protect the service and its users.
8. Your rights
Depending on where you live, you may have rights to access, correct, or delete your data, and to object to processing. Contact us to exercise these rights, and we will respond within a reasonable time.
9. Contact
Privacy questions: [email protected]