Kami menghargai privasi Anda

Kami menggunakan cookie untuk menjaga situs tetap berjalan, mengukur penggunaan, dan meningkatkan pengalaman Anda. Pelajari lebih lanjut

Privacy policy

Last updated September 2026GDPR compliant
1

Privacy policy

How we collect and use your data

2

Cookie policy

Cookies and tracking technologies

3

Your rights

Data access, deletion, and control

4

Consent

Manage your privacy preferences

At Short.io, we are committed to protecting your privacy and ensuring the security of your personal data. This page outlines how we collect, use, and safeguard your information in compliance with GDPR, CCPA, and other international privacy regulations.

Privacy policy

This privacy policy explains what personal data Short.io ("we", "us") collects, how we use it, and the choices you have. It applies to short.io and the services we provide through it.

Data we collect

  • Account data — name, email address, and password when you register.
  • Usage data — links you create, click statistics, prompts you submit to AI features, and how you interact with the dashboard.
  • Technical data — IP address, browser type, device information, and cookie identifiers.
  • Billing data — payment details processed by our payment provider when you subscribe to a paid plan.

How we use your data

  • To provide, maintain, and improve the Short.io service.
  • To process payments and manage your subscription.
  • To communicate with you about your account, support requests, and product updates.
  • To analyze usage and improve performance, security, and user experience.
  • To power AI-assisted features, such as link and content suggestions and the in-product assistant.
  • To generate AI QR codes — scannable QR codes rendered as artwork — from the prompts you write.
  • To detect, prevent, and investigate fraud, abuse, and security threats.
  • To comply with legal obligations.

How we share your data

We do not sell your personal data. We share it only with the categories of recipients below, and only as needed to run the service:

  • Service providers (subprocessors) — hosting, email delivery, analytics, customer support, and similar vendors that process data on our behalf. See the list of subprocessors below.
  • Payment providers — to process payments and manage subscriptions.
  • AI providers — when you use AI-assisted features, the relevant prompt and context (which may include your links and related text) are processed by our AI subprocessors to generate a response.
  • AI image-generation providers — when you generate an AI QR code, the prompt you write and the QR image that encodes your short link are sent to Google's Gemini image models, which repaint that QR code as artwork. The prompt is stored alongside the generated QR code in your account, and the artwork is served from a public URL so that it stays scannable.
  • Fraud, security, and threat-detection providers — to score sign-ups for fraud and to check destination URLs for malware and phishing. This may involve sharing your email, IP address, and the URLs of links you create.
  • Domain registries and certificate authorities — when you register or connect a custom domain, the required registrant contact details (WHOIS) and domain names are shared to complete registration and issue TLS certificates.
  • Authorities — where we are legally required to, or in response to a valid government or law-enforcement request, we may disclose account information such as your email and login history.

Hosting and data location

We are moving Short.io's US cluster from Amazon Web Services in the United States to dedicated bare metal servers in three independent data centers in the Dallas, Texas area, operated by Hivelocity, Limestone Networks, and Interserver. While the migration is in progress, US customer data is stored both on Amazon Web Services and on these servers. The bare metal servers are single-tenant: no other company's workloads share their processors, memory, or disks. Our EU cluster runs on Amazon Web Services in Frankfurt, Germany.

Every data-bearing disk in the US cluster is encrypted. The encryption keys are generated and held by Short.io, sealed to a security chip (TPM) in each server, and released only when the server boots software we have approved and signed. The data center operators supply power, cooling, hardware, and network connectivity only; they never receive the keys and cannot read the data stored on the servers. Traffic between our servers travels through encrypted WireGuard tunnels, and public traffic reaches them through encrypted Cloudflare tunnels.

Backups of the US cluster are stored with Wasabi. Each backup is encrypted on our own servers before it is uploaded, with keys that only Short.io holds, so Wasabi stores encrypted data it cannot decrypt.

International data transfers

Where personal data is transferred outside your country, we rely on appropriate safeguards with our subprocessors: for transfers from the EU/EEA we use the European Commission's Standard Contractual Clauses, and for transfers from the UK we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

Legal basis for processing

We process personal data on the basis of contract (to provide the service you sign up for), legitimate interests (to keep the service secure and improve it), consent (for non-essential cookies and marketing), and legal obligation.

Data retention

We retain personal data only for as long as necessary to provide the service and to comply with our legal obligations. You can request deletion of your data at any time (see "Your rights" below).

Contact

For any privacy-related questions, contact us at [email protected].

Your rights

Under GDPR and other privacy regulations, you have the following rights regarding your personal data:

  • Right to access — Request a copy of your personal data we hold
  • Right to rectification — Request correction of inaccurate data
  • Right to erasure — Request deletion of your personal data
  • Right to restrict processing — Limit how we use your data
  • Right to data portability — Receive your data in a portable format
  • Right to object — Object to processing based on legitimate interests

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.