1. Information you provide
- Account information such as your name, email address, workspace name, and consent records.
- Link information such as destination URLs, aliases, fallback routes, expiry settings, custom domains, and QR-code activity.
- Support messages, abuse reports, and information you choose to include in them.
- Billing contact information and provider references. Card, UPI, or bank credentials are handled by Razorpay and are not stored by Shotlink.
2. Information collected during use
- Session, security, request, and audit information needed to sign you in and protect workspaces.
- For link visits: time, referring page when supplied, device category, browser, operating system, route status, and a one-way hashed network identifier used for analytics and abuse prevention.
- Operational logs, rate-limit counters, error details, and service-health information.
3. How information is used
- Provide, secure, troubleshoot, and improve the link-routing service.
- Show workspace analytics and enforce plan limits.
- Verify branded domains and keep campaign links scoped to the correct workspace.
- Process subscriptions, reconcile payment events, and respond to billing questions.
- Detect abuse, investigate incidents, comply with law, and protect users and the public.
4. Legal grounds and consent
Depending on the context, processing is based on providing the service you request, your consent, compliance with legal obligations, and legitimate interests in security, fraud prevention, analytics, and service reliability. You can withdraw optional marketing consent without affecting core service use.
5. Sharing and service providers
Information is shared only as needed with infrastructure, database, hosting, security, email, analytics, and payment providers that help operate Shotlink. Razorpay independently processes payment information under its own terms and privacy notice.
Information may also be disclosed when required by law, to respond to valid legal process, to investigate abuse or fraud, or to protect rights and safety. Shotlink does not sell personal information.
6. Cookies and local storage
Shotlink uses essential browser cookies and related storage for secure sessions, CSRF protection, user preferences, and core application behaviour. The service does not require third-party advertising cookies.
7. Retention
Information is retained for as long as needed to provide the service, maintain security and audit records, resolve disputes, enforce agreements, and meet legal or accounting obligations. Expired links may be retained in a disabled state for security, support, and abuse-response purposes before deletion or de-identification.
8. Security
Shotlink uses controls including encrypted transport, one-way password protection, secure browser sessions, CSRF safeguards, role checks, DNS verification, rate limits, and audit events. No system can guarantee absolute security; report suspected compromise immediately.
9. Your choices and requests
You may request access, correction, deletion, or export of personal information associated with your account. Some information may be retained where necessary for legal compliance, billing records, security, fraud prevention, or the rights of others.
To make a request, email support@shotlink.in from the address connected to your account and describe the request. We may need to verify your identity before acting.
10. Children and international processing
Shotlink is not intended for children under 18. Service providers may process information in locations outside your state or country, subject to contractual and technical protections appropriate to the service.
11. Changes and contact
Material changes will be posted here with a revised effective date. Privacy questions or complaints can be sent through the Contact Us page.