Privacy policy
The short version
Linkshortner operates Linkshortner. We use the information needed to run your account, redirect links, measure first-party traffic, prevent abuse, and process payment requests. We do not sell personal information. For privacy requests, email support@linkshortner.org.
Information we collect
- Account information: your name, email, password hash, plan, account status, and the date you accepted the terms. Passwords are stored as salted hashes, never as plain text.
- Your links: destinations, aliases, titles, tags, status, expiration dates, and creation timestamps. Anyone with a short URL can see its destination host and access it through the four-step flow.
- Visit information: visit times, completed steps, referrer domain (not the full referring URL), broad device and browser category, and a keyed pseudonymous identifier derived from the network address and browser user agent. Raw IP addresses are not stored in the analytics database.
- Financial information: plan transactions, transfer references, uploaded receipts, payout methods and account details, withdrawal records, and the earnings ledger. Card details are handled directly by Stripe when it is enabled.
- Communications: contact forms, abuse reports, support replies, and account recovery requests.
Why we process it
We process account and link information to perform our agreement with you; security and traffic information for our legitimate interests in operating the service and preventing fraud; financial records to process payments and meet legal obligations; and optional preferences or public payout recognition when you consent. You may withdraw optional consent without affecting essential service functionality.
Cookies and local storage
An essential first-party session cookie maintains your account session, protects forms from cross-site requests, and binds the four-step flow to your browser. A local preference records your cookie choice. The default configuration does not load third-party advertising or analytics. If Google display advertising is configured on eligible editorial pages, it uses a separate consent process described below and in the Cookie Policy.
Optional Google advertising
If the operator enables Google advertising, eligible, operator-reviewed articles can contain one labeled display placement. A configured Google Privacy & messaging consent manager supplies the applicable TCF and other regulatory signals. The site's small preference banner is not advertising consent. The integration does not send an ad request without a usable consent signal, and Global Privacy Control suppresses ad requests.
When a permitted ad request is sent, Google and approved advertising providers may receive information such as the page address, IP address, device/browser information, consent signals, and cookie or advertising identifiers according to their policies and your choices. Google may use this information for ad selection, fraud prevention, measurement, and, where permitted and consented, personalization. See Google Privacy and Google advertising technologies.
Google ads are excluded from account pages, payments, short-link redirects, and other non-editorial screens. A session beginning a redirect journey has editorial ads suppressed for 30 minutes. Use Ad privacy choices on an eligible article to revisit the provider's consent message. Consent withdrawal affects future requests; it does not retroactively undo processing that already occurred.
Sharing and external services
Authorized administrators can review account, link, support, and financial records for service operations. Hosting and email providers may process data on our behalf. Stripe receives checkout information if you choose card payment. An external destination receives its own visit when you choose to continue to it; that website's policies then apply.
We may disclose information to comply with lawful requests or protect rights and security. Payment-proof uploads are private and are available only to the submitting account and administrators. Public payout records require the publisher's consent and show only an initial, amount, method, date, and shortened record identifier. Public records never include the uploaded proof or payout account details.
Retention
Sessions expire after seven days, and password reset tokens after 30 minutes. Incomplete redirect flows expire after 30 minutes and are periodically removed. Detailed visit analytics are kept for up to 365 days. Guest links expire after seven days. Financial ledgers, receipts, and audit records may be retained to meet accounting, anti-fraud, and dispute-resolution needs. Support and account records are kept while needed to provide the service or resolve requests. Contact us for a specific retention or deletion request.
Your rights and choices
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to the processing of your information, and to complain to a relevant regulator. You can edit your profile, change your password, export your account data, and withdraw public-payout consent in your workspace. Email us for account closure or other privacy requests; we may verify ownership before acting. Some financial or legal records may need to be retained.
Security and international processing
We use access controls, hashed credentials, private receipt storage, signed request tokens, and audit records. Production connections should use HTTPS. No system is completely secure. Where service providers process information in another country, applicable transfer protections and local rights still apply.
Children and policy changes
Accounts and earnings are intended for adults. If you believe a child provided personal information, contact us so we can investigate and remove it where appropriate. We will publish updates on this page and communicate material changes where required.
Contact
Linkshortner Contact support for business correspondence. support@linkshortner.org