Privacy Policy
Effective date: July 12, 2026
What we collect from account holders
Email, name, password hash (bcrypt), and the links you create. Login events are recorded (IP + user agent) so you can review active sessions.
What we collect from link visitors
When someone clicks a short link we record: timestamp, salted one-way hash of the IP (raw IPs are never stored), country/region/city derived at the edge, device type, OS, browser, referrer, language, and UTM parameters. This is aggregate campaign analytics, not advertising surveillance:
- No third-party trackers, pixels, or ad cookies on the redirect path.
- No cross-site profiles; each link's analytics are independent.
- IP hashes cannot be reversed to identify a visitor.
Cookies
One httpOnly session cookie for logged-in users. No marketing cookies, so no cookie banner theater.
Data retention
Click analytics are kept for the life of the link. Deleted links and their analytics are hard-purged 30 days after deletion.
Your rights
Export your data any time (CSV). Request account deletion at privacy@linkforge.io — completed within 30 days. EU/UK users: we act as processor for your links' analytics; a DPA is available for business use.
Security
Passwords hashed with bcrypt (cost 12), TOTP two-factor authentication available, sessions revocable, secrets never shipped to the client, TLS everywhere, audit logging of sensitive actions.
Contact
privacy@linkforge.io