Privacy Policy
Last Updated: September 11, 2026
At links.ceo ("we," "our," "us," or the "Service"), we respect your privacy and are committed to protecting the personal data of our users and the
visitors who interact with links processed by our redirection infrastructure. This Privacy Policy explains how we collect, use, disclose, and safeguard
your information when you access our website, use our Flutter WebAssembly (WASM) web or desktop applications, connect custom domains, or route clicks
through our redirection service.
1. Information We Collect
We collect information in two primary categories: information provided by registered account holders ("Users"), and technical routing data generated by
individuals clicking on shortened links ("Visitors").
1.1 Information Collected from Registered Users
-
Authentication Data: We authenticate accounts exclusively via Google / Gmail. When you register or sign in, we collect your primary
Gmail address, Google account identifier, profile name, and profile picture provided by Google authentication protocols.
-
Link and Campaign Configuration: We store the custom slugs, original destination URLs (including affiliate parameters, UTM tags, and
sub-IDs), custom domain bindings, and dynamic QR code assets you create within your dashboard.
-
Billing and Subscription Information: If you upgrade to our paid subscription plan, your payment information (such as credit card
details and billing address) is collected and processed directly by our third-party payment processor. We do not store full credit card numbers on our
servers; we retain only payment tokens, subscription statuses, transaction IDs, and renewal dates.
1.2 Information Processed from Link Visitors (Click Telemetry)
When a visitor clicks a links.ceo shortlink or custom-branded shortlink routed through our service, our serverless edge endpoints automatically process
the incoming HTTP request to execute the 302 redirect and record analytics:
-
HTTP Headers and Technical Metadata: User-Agent strings (browser type, operating system version, device category), language
preferences, and HTTP Referer headers indicating the traffic source.
- Timestamp and Request Details: Precise UTC timestamp of the redirect request, requested slug, and destination routing status.
-
IP Addresses and Geolocation: We process incoming IP addresses at the edge for rate limiting, DDoS mitigation, and coarse geographic
resolution (country/region). IP addresses are not exposed in public dashboards and are either aggregated, truncated, or discarded in accordance with our
data retention practices.
2. How We Use Your Information
We process collected information for the following operational and commercial purposes:
-
Service Delivery: To resolve shortlinks, execute instant HTTP 302 redirects, render dynamic QR codes, and generate atomic click
telemetry.
-
Account Administration: To manage user accounts, authenticate logins via Gmail, monitor subscription limits (such as the 3-link free
tier vs. unlimited plan), and send critical billing or system notifications.
-
Platform Security and Threat Prevention: To verify destination URLs against automated threat feeds (including Google Cloud Web Risk and
abuse.ch URLhaus) to prevent malware, phishing, scam networks, and infrastructure abuse.
-
Performance Optimization: To monitor uptime, debug edge routing latency, ensure compatibility across modern browsers, and optimize our
Flutter WASM client interface.
-
Legal Compliance: To enforce our Terms of Service, defend against fraudulent chargebacks, and comply with valid legal processes or
regulatory demands.
3. Third-Party Integrations and Automated Processing
We share data with third-party service providers solely to maintain infrastructure, process payments, and ensure threat safety:
- Authentication Providers: Google Identity Services / OAuth to verify and manage Gmail account authentication.
-
Cloud and Serverless Hosting: Cloud infrastructure and content delivery networks (CDNs) that execute serverless functions and
distribute shortlink routing globally.
-
Threat Intelligence Engines: Automated security APIs (specifically Google Cloud Web Risk and URLhaus) that evaluate user-submitted
destination URLs for known security risks before redirection is authorized.
- Payment Gateways: Secure payment service providers that handle recurring billing for the $9.99/month subscription tier.
We do not sell, rent, monetize, or trade your personal data or your visitors' browsing history to third-party data brokers or behavioral advertising
networks.
4. Cookies and Local Storage
-
Dashboard Users: We use essential session cookies, local storage, and secure authentication tokens strictly necessary to keep you
authenticated inside the web and desktop applications and to maintain UI preferences across sessions.
-
Redirect Visitors: Our shortlink redirection engine operates without injecting tracking cookies, persistent identifiers, or profiling
scripts onto end-user browsers. Redirects execute via clean, server-side HTTP 302 responses designed for zero browser caching (
Cache-Control: no-store, no-cache).
5. Data Retention
-
Account Data: We retain registered user data, domain settings, and link configurations for as long as your account remains active. If
you delete your account, your personal data and mapped links are queued for permanent deletion from active databases. Furthermore, to maintain platform
performance and resource optimization, we reserve the right to permanently delete link database entries and associated routing rules for any user
account that remains completely inactive for a consecutive period of 3 months.
-
Click Analytics: Click counts and associated aggregate metrics are retained to provide historical campaign data inside your dashboard
during your active account lifecycle.
-
Security Logs: Raw server connection logs processed at edge nodes for DDoS mitigation and intrusion detection are retained for standard
operational periods (typically 30 to 90 days) before automatic rotation.
6. International Data Transfers
links.ceo operates a distributed, global serverless edge network. Information collected from users and link visitors may be processed and stored on
servers located across various countries and jurisdictions. By using the Service or routing traffic through our links, you acknowledge and consent to the
transfer, storage, and processing of technical data internationally in compliance with applicable data protection standards.
7. Your Data Protection Rights
Depending on your geographical location (such as under the European Union GDPR, UK GDPR, or California Consumer Privacy Act / CCPA), you may possess
specific statutory rights regarding your personal information:
- Access and Portability: The right to request copies of the personal data we maintain about your account.
- Rectification: The right to request correction of inaccurate or incomplete information.
-
Erasure ("Right to be Forgotten"): The right to request the permanent deletion of your account, created shortlinks, and associated
configuration data.
-
Restriction or Objection: The right to object to or request restrictions on certain processing activities where applicable by law.
To exercise any of these rights, contact us using the support details below. We verify identity through your authenticated Gmail address before processing
privacy requests.
8. Security of Your Information
We implement administrative, technical, and physical safeguards to protect information processed through our systems:
-
Encryption in Transit: All web interfaces, dashboard sessions, and edge redirects are secured using Transport Layer Security
(TLS/HTTPS).
-
Access Controls: Tokenized, serverless backend access restrictions prevent unauthorized read/write permissions to customer link
databases.
-
Real-Time Threat Filtering: Automated destination URL screening blocks the propagation of malicious links across our shared domains.
While we maintain rigorous security protocols, no internet transmission or electronic storage architecture is completely impenetrable. We cannot guarantee
absolute security against all unforeseen threats.
9. Children's Privacy
Our Service is designed for business operators, marketers, and individuals aged 18 and older. We do not knowingly solicit, collect, or process personal
data from children under the age of 13 (or under 16 where required by local law). If we become aware that an account has been registered by a minor, we
will promptly terminate the account and purge associated data.
10. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our operational procedures, technical infrastructure, or applicable legal
obligations. When updates occur, the "Last Updated" date at the top of this document will be revised accordingly. Continued use of links.ceo following the
publication of changes signifies your acceptance of the updated policy.