Legal
Privacy Policy
Last updated: · v2026-06-04
This Privacy Policy explains how zlin.io ("we", "us", "our") collects, uses, shares, and protects personal data when you use our URL shortening and link-analytics service (the "Service"). It should be read together with our Terms of Use. We act as the controller of the personal data described here. We design the Service to collect as little personal data as reasonably possible and to comply with applicable data protection laws, including the Brazilian LGPD and the EU/UK GDPR.
1. Data we collect
- Account data. Your first and last name, email address, a hash of your password (never the plain password), your preferred language, and your plan.
- Links you create. The destination (long) URLs you shorten, their short codes, titles, and related metadata.
- Click analytics. When someone opens one of your short links, we process the request to redirect it and to produce aggregated statistics: approximate location (such as country and region, derived from the IP address by our edge provider), device type, browser, referrer/source, and timestamp. We do not use third-party advertising or cross-site tracking cookies.
- Security and operational data. IP addresses and request metadata processed transiently for security, abuse prevention, and rate limiting.
- Billing data. If you subscribe to a paid plan, payment is handled by our payment processor (Stripe). We receive limited billing details (such as a customer and subscription identifier and plan status); we do not store your full card number.
- Communications. Emails we send you (for example, verification and login codes) and any messages you send us.
2. How we use your data
- To provide, operate, secure, and improve the Service, including creating accounts, redirecting links, and generating analytics.
- To authenticate you, protect accounts, prevent fraud and abuse, and enforce limits and our Terms of Use.
- To process payments and manage subscriptions.
- To communicate with you about your account and the Service.
- To comply with legal obligations and respond to lawful requests.
3. Legal bases
Where the LGPD or GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to keep the Service secure, prevent abuse, and produce aggregated analytics); consent (where required, for example certain communications); and compliance with a legal obligation.
4. Cookies
We use a strictly necessary session cookie to keep you signed in. It is set with HttpOnly, Secure (over HTTPS), and SameSite=Lax attributes. We also store your language preference locally in your browser. We do not use third-party advertising or cross-site tracking cookies.
5. How we share data
We do not sell your personal data. We share it only with service providers ("processors") that help us run the Service, under appropriate safeguards, and only as needed:
- Cloudflare — edge hosting, redirect delivery, security/WAF, and approximate geolocation.
- Neon — managed PostgreSQL database hosting.
- Amazon Web Services (SES) — transactional email delivery.
- Stripe — payment processing for paid plans.
We may also disclose data to comply with the law, enforce our Terms, protect our rights, safety, or property, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this Policy.
6. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses) to protect your data when it is transferred internationally.
7. Data retention
We keep account data for as long as your account is active and as needed to provide the Service. Aggregated click analytics are retained to give you historical statistics. When your account is closed or terminated, we delete or anonymize personal data within a reasonable period, unless we must keep it to comply with legal obligations, resolve disputes, or enforce our agreements.
8. Security
We apply defense-in-depth measures, including encryption in transit (HTTPS/HSTS), a strict Content Security Policy, password hashing with PBKDF2, storage of API tokens only as hashes, secure session cookies, captcha protection, and rate limiting. No method of transmission or storage is completely secure, but we work to protect your data and to limit what we collect.
9. Your rights
Subject to applicable law (including the LGPD and GDPR), you may have the right to access, correct, update, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it. You can update much of your account data directly in the app. To exercise other rights, contact us at [email protected]. You also have the right to lodge a complaint with your local data protection authority (in Brazil, the ANPD).
10. Children
The Service is not directed to children and is intended only for users who meet the age requirement in our Terms of Use. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
12. Contact
For privacy questions or to exercise your rights, contact us at [email protected].