Privacy Policy

Last updated: April 25, 2026 · Effective: January 1, 2025

1. Who we are

Alshorty ("we", "us", "our") is an independent web platform operating alshorty.com — providing URL shortening, SmartPages, Link-in-Bio pages, analytics, QR code generation, developer APIs, and link management tools. For privacy questions, contact us at hello@alshorty.com.

Contact page

2. What data we collect

Short links created on Alshorty are user-generated content. We do not control or verify the content of destination URLs. Any data associated with such links is processed solely to provide the redirect and analytics functionality of the service.

2.1 Data you provide directly

  • Email address — when you create an account via magic link, Google, or Microsoft sign-in.
  • URLs you shorten — stored to enable redirects and analytics.
  • Custom aliases, tags, and passwords — optional metadata you add to your links.
  • Link-in-Bio content — profile names, bios, avatars, social links, and embedded content you voluntarily publish on your bio pages.
  • SmartPages content — landing page text, headlines, forms, uploaded images, CTA buttons, metadata, and custom page content you publish through SmartPages.

2.2 Data collected automatically when links are clicked

When someone clicks one of your short links, we log:

  • Timestamp of the click
  • Country (derived from IP address — IP is not stored)
  • Device type (mobile, desktop, tablet)
  • Browser and operating system (from User-Agent string)
  • Referrer URL (the page the user came from)

We do not store IP addresses of link visitors. Country-level geolocation is performed in-memory at the Cloudflare edge and only the country name is persisted.

API requests may also be logged for abuse prevention, authentication, rate limiting, debugging, and platform security.

2.3 Usage data

Standard server logs may record request timestamps, paths, and response codes for security and debugging. These are retained for a maximum of 30 days.

3. How we use your data

  • To detect, investigate, and take action against abuse, fraud, phishing, or violations of our Terms of Service.
  • To authenticate you and maintain your session
  • To provide URL shortening, SmartPages hosting, Link-in-Bio hosting, analytics, QR code, and API services
  • To enforce our Terms of Service and prevent abuse
  • To send transactional emails (magic links, payment receipts) — no marketing emails without consent
  • To detect and block phishing, malware, and spam links
  • To generate aggregated, anonymised statistics about platform usage

We do not sell your personal data. We do not use your data for targeted advertising.

Public Link-in-Bio pages are intentionally accessible on the public internet. Only information you choose to publish on your bio page becomes publicly visible.

3.1 Legal basis for processing (GDPR Article 6)

  • Contract performance (Art. 6(1)(b)) — Authentication, session management, and link shortening/redirect services.
  • Legitimate interests (Art. 6(1)(f)) — Security monitoring, abuse prevention, fraud detection, and platform integrity.
  • Consent (Art. 6(1)(a)) — Google AdSense advertising cookies (where applicable). You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — Compliance with applicable laws, including responding to valid legal requests.

We do not build user profiles, sell personal data, or use behavioural tracking for advertising purposes.

4. Google AdSense and advertising

Alshorty may display advertisements served by Google AdSense. Google AdSense uses cookies to serve ads based on your prior visits to our website and other sites on the internet. Google's use of advertising cookies enables it and its partners to serve ads based on your visit to our site and/or other sites on the internet.

You may opt out of personalised advertising by visiting Google Ads Settings, or by visiting aboutads.info.

Google AdSense uses the following cookies on our site:

  • __gads, __gpi — Used by Google to show personalised or non-personalised ads and measure ad performance. Set by Google, not by Alshorty.
  • IDE — Used by Google DoubleClick to record and report ad actions for measurement purposes.

For more information on how Google uses data when you visit partner sites, see: How Google uses information from sites or apps that use our services.

5. Cookies

We use one first-party cookie:

  • alshorty_session — Authentication session cookie. HttpOnly, Secure, SameSite=Lax. Expires after 7 days. Required for sign-in; cannot be opted out of while logged in.

We also use browser localStorage for UI preferences (theme, UI state). No personal data is stored in localStorage.

Third-party cookies (from Google AdSense) are described in Section 4 above. For full cookie details, see our Cookie Policy.

6. Data sharing and third parties

We share data with the following third-party service providers strictly to operate the service:

We do not share your data with any other third parties except as required by law.

We may disclose user data, link information, or related records if required to comply with applicable laws, legal processes, or valid government requests, or to protect the rights, safety, and integrity of our users, platform, or the public.

6a. Public page visibility

SmartPages and Link-in-Bio pages created on Alshorty may be publicly accessible and indexable by search engines unless explicitly disabled by platform settings.

Users are responsible for the information they choose to publish on public pages, including text, links, forms, uploaded images, branding assets, and embedded content.

7. Data retention

  • Account data — Retained for as long as your account is active. Deleted within 30 days of account deletion request.
  • Link click analytics — Retained for 2 years, then automatically purged.
  • Server logs — Retained for a maximum of 30 days.
  • Payment records — Retained for 7 years as required by financial regulations.

8. Your rights (GDPR / data subject rights)

If you are in the European Economic Area, UK, or other jurisdictions with applicable data protection law, you have the right to:

  • Access — Request a copy of the personal data we hold about you.
  • Rectification — Request correction of inaccurate data.
  • Erasure — Request deletion of your personal data ("right to be forgotten").
  • Restriction — Request that we restrict processing of your data.
  • Portability — Request a machine-readable export of your data.
  • Objection — Object to processing based on legitimate interests.
  • Withdraw consent — Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email hello@alshorty.com. We will respond within 30 days.

9. Children's privacy

Alshorty is not directed at children under 13 years of age (or under 16 in the EU/UK, per GDPR). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. International data transfers

Alshorty operates on Cloudflare's global edge network. Your data may be processed in data centres across the world, including in the United States. Cloudflare participates in the EU–US Data Privacy Framework. By using Alshorty, you consent to the transfer of your data as described in this policy.

10a. India — Digital Personal Data Protection Act 2023 (DPDP)

If you are located in India, you also have rights under India's Digital Personal Data Protection Act 2023, including:

  • Right to access — Request information about the personal data we hold about you.
  • Right to correction and erasure — Request correction of inaccurate data or erasure of data no longer needed for the purpose it was collected.
  • Right to grievance redressal — File a complaint with our Grievance Officer (see our Terms of Service).
  • Right to nominate — Nominate another individual to exercise your data rights in case of death or incapacity.

To exercise these rights, email hello@alshorty.com.

11. Security

We may implement automated systems to detect spam, phishing, malicious crawlers, abusive automation, and harmful link activity.

We implement industry-standard security measures including HTTPS/TLS encryption, secure authentication cookies, rate limiting, bot detection, abuse prevention systems, API protections, and infrastructure-level security controls. However, no system is completely secure. If you discover a security vulnerability, please report it to hello@alshorty.com.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email (if you have an account) or a notice on our website. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact us

For privacy questions, data requests, or to exercise your rights:

Related pages