Privacy Policy

What we collect, why, and what we never do with it.

Last updated: October 2026

1. Who we are

SwiftLink ("we", "us") operates this URL shortening service. This policy explains what personal data we process and your rights over it.

2. Data we collect

  • Account data: name, email address and password hash when you register. Passwords are stored using strong one-way hashing and can never be read back.
  • Links you create: destination URLs, titles, settings and creation metadata.
  • Click analytics: when someone opens a short link we log the time, referrer, country, device type, browser and OS. Visitor IP addresses are stored only as salted one-way hashes — never in plain text.
  • Support messages: the details you send via our contact form or abuse reports.
  • Security logs: authentication events and rate-limit counters used to prevent abuse.

3. Why we collect it

To operate the Service (creating and redirecting links), to show you analytics, to keep accounts secure, to prevent abuse, and to respond to your messages. We do not sell personal data and we do not use it for advertising profiles.

4. Cookies

We use strictly necessary cookies: a session cookie to keep you signed in, a CSRF token to protect forms, and a theme preference stored in your browser. See our Cookie Policy.

5. Sharing

We share data only as needed to run the Service (for example, our hosting provider and email delivery provider) or when required by law. Abuse reports that identify illegal activity may be shared with law enforcement.

6. Retention

Account and link data is kept while your account is active. Click analytics are retained for 365 days. Contact messages are retained for 365 days. Deleting your account removes your profile, links, analytics and API keys.

7. Your rights

Depending on your jurisdiction you may have the right to access, correct, export or delete your personal data, and to object to or restrict processing. Exercise these rights from your dashboard account settings or by contacting us.

8. Security

We use HTTPS, hashed credentials, CSRF protection, rate limiting and salted IP hashing. No system is perfect — if you discover a vulnerability, please report it via our contact form.

9. Changes

We may update this policy; material changes will be announced on the site with a revised "last updated" date.

This is the default policy text. The site administrator can customize it from the admin settings.