Legal & Transparency
Last updated: September 13, 2026

Privacy Policy

Learn how Link collects, protects, and manages your data when you use our link shortening services.

Zero Third-Party Ads or data brokerage
Bcrypt Hashed Passwords never stored in plaintext
410 Gone Purges for expired link caches

Last Updated: September 13, 2026

Link ("we", "our", or "us") is dedicated to protecting your personal information and respecting your privacy. This Privacy Policy explains how our link shortening platform collects, uses, stores, and safeguards your data when you visit our website, register an account, or create and share shortened links.

1. Information We Collect

We collect information to provide fast, secure, and reliable link shortening and analytics services:

A. Account and Profile Information

When you create an account on Link, we collect your name, email address, password hash, and user preferences. If you authenticate via third-party OAuth providers, we receive your name and verified email address.

B. Link Metadata and Configuration

When you shorten a URL, we store the original destination URL, your custom domain slug, link description, optional tags, UTM campaign parameters, expiration timestamp, maximum-click ceiling, and whether password protection is enabled.

C. Password-Protected Links

If you choose to protect a short link with a password, the password is cryptographically hashed using bcrypt with multiple salt rounds before storage. We never store or transmit plaintext link passwords.

D. Click Analytics & Visitor Data

When visitors access a short link, our edge servers record high-level metrics including click timestamps, referring domains, user agent strings, and anonymized geographical metrics to display aggregate analytics in your dashboard.

2. How We Use Your Information

We utilize collected information for the following operational and technical purposes:

• Resolving short links into destination URLs with sub-millisecond latency using Redis caching.

• Enforcing link expiration dates, maximum-click limits, and returning HTTP 410 Gone for deactivated links.

• Providing real-time dashboard analytics, click counters, and campaign tracking.

• Preventing abuse, phishing, malware distribution, and automated bots.

• Managing your account and delivering important service notifications.

3. Data Security and Caching

Security is integral to our architecture. All web traffic is encrypted using modern TLS (HTTPS). Redirect data is cached in high-speed, secure Redis memory clusters to protect against database overload and DDoS attacks.

4. Cookies and Session Storage

We utilize essential session cookies to keep you authenticated across sessions and remember your dark/light theme preferences. We do not use invasive third-party tracking cookies or sell your personal data to ad brokers.

5. Link Expiration & Automatic Removal

Links configured with expiration timestamps or click limits automatically cease redirection when their rules are fulfilled. Visitors will immediately receive an HTTP 410 Gone status code, and target URLs are purged from Redis.

6. Your Rights and Choices

You maintain complete control over your content. At any time, you can edit destination URLs, clear or change passwords, adjust click limits, or permanently delete links through your dashboard or Payload CMS.

7. Contact Us

If you have questions or concerns about this Privacy Policy, please contact our privacy team at privacy@raju.app or via GitHub at github.com/rajuapp/link.

Have questions about our Privacy Policy?

Our legal and engineering team is here to assist with any data protection or terms inquiries.