Privacy Policy

Last Updated: February 6, 2026

Effective Date: February 6, 2026

In Plain English

Before the legal language, here is a summary of the key points. This summary is not legally binding — the full policy below governs how we handle your data.

  • We never sell your personal data. Not now, not ever. Period.
  • We never use your data to train AI. Your content and analytics data are never fed into machine learning or AI models.
  • You own your data. Your links, analytics, and content belong to you. You can export or delete it at any time.
  • We collect only what we need. We collect account info, usage data, and analytics to provide and improve the service.
  • We use Paddle for payments. We never see or store your credit card details. Paddle handles all payment processing as our Merchant of Record.
  • We respect your privacy rights. Whether you are in California, the EU, or anywhere else, you have the right to access, correct, and delete your data.
  • We use cookies responsibly. Only essential cookies are required. Analytics cookies are opt-in via our cookie banner.

1. Introduction

This Privacy Policy ("Policy") describes how sniplink.co ("Sniplink," "we," "our," or "us") collects, uses, discloses, and protects information about you when you use our link shortening and analytics platform, including our websites, applications, APIs, and all related services (collectively, the "Service").

By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree to this Policy, please do not access or use the Service.

This Policy applies to information collected through the Service and does not apply to information collected by third parties, including websites or services that we may link to.

2. Information We Collect

2.1 Categories of Personal Data

The following table summarizes the categories of personal data we collect and how we use them:

CategoryExamplesPurpose
IdentifiersName, email address, account ID, IP addressAccount management, authentication, communications
Commercial InformationSubscription plan, billing history, transaction recordsPayment processing, subscription management
Internet/Network ActivityBrowser type, device info, pages visited, referrer URL, click dataAnalytics, service improvement, security
Geolocation DataCountry, region, city (derived from IP address)Link analytics, compliance, localization
Professional InformationWorkspace name, team role, organization nameWorkspace management, collaboration features
User-Generated ContentURLs, custom aliases, tags, QR code configurations, support messagesService delivery, customer support
InferencesUsage patterns, feature preferencesService improvement, personalization

2.2 Information You Provide to Us

We collect information you provide directly, including:

  • Account Information: Name, email address, password (encrypted using industry-standard hashing), and optional profile information.
  • Payment Information: Billing details are collected and processed by Paddle (our Merchant of Record). We do not store credit card numbers, CVVs, or complete payment card data on our servers.
  • Link Data: URLs, custom aliases, tags, metadata, QR code configurations, and A/B test settings.
  • Communications: Support inquiries, feedback, and associated contact information.
  • Workspace Data: Workspace names, team invitations, member roles, and collaboration settings.

2.3 Information We Collect Automatically

When you access or use the Service, we automatically collect:

  • Click Analytics Data: When someone clicks a shortened link, we collect IP addresses (anonymized for GDPR compliance), device information (type, operating system, browser), geographic location (country, region, city), referrer information, and timestamps.
  • Log Data: Server logs including IP addresses, browser type, access times, pages viewed, and request/response metadata.
  • Device Information: Hardware model, operating system, browser type and version, unique device identifiers, screen resolution, and language preferences.
  • Cookies and Similar Technologies: We use cookies, web beacons, and similar tracking technologies. See our Cookie Policy for details.

2.4 Information from Third Parties

  • OAuth Providers: If you sign in using Google, GitHub, or other OAuth providers, we receive basic profile information (name, email, profile picture) as permitted by your provider settings.
  • Payment Processor (Paddle): Transaction confirmations, payment status, and subscription lifecycle events. We do not receive your full payment card details.
  • Analytics Services: Aggregated analytics data from PostHog and similar services that help us understand how the Service is used.

2.5 Data Controller and Processor Roles

Sniplink acts in a dual capacity depending on the context:

  • Data Controller: For your account information, payment data, and our own product analytics, Sniplink determines the purposes and means of processing and acts as the data controller under GDPR Article 4(7).
  • Data Processor: When you use Sniplink to collect click analytics and visitor data on your shortened links, Sniplink acts as a data processor on your behalf under GDPR Article 4(8). You, as the link creator, are the data controller for that visitor data.

If you require a formal Data Processing Agreement (DPA) pursuant to GDPR Article 28, please contact us at Loading contact information. Our standard DPA is available upon request and covers data processing instructions, security obligations, sub-processor management, breach notification, and data subject rights assistance.

2.6 Consent Tracking

When visitors click on shortened links, we track their consent preferences to ensure GDPR compliance:

  • Consent Status: Whether the visitor has given consent for analytics tracking (stored in the sniplink_consent cookie).
  • Consent Method: How consent was obtained (e.g., "cookie_banner").
  • Consent Timestamp: When consent was granted or updated.

Important: Your Responsibilities as a Link Creator

If you use Sniplink to track clicks on your links, you are the data controller for the analytics data collected from your visitors. You are responsible for obtaining valid consent before we collect their analytics data. We provide consent banner components and consent management APIs to help you comply with GDPR and other privacy regulations.

3. How We Use Your Information

3.1 Purposes of Processing

We use the information we collect for the following purposes:

  • Service Delivery: To operate, maintain, and provide the Service, including link shortening, analytics, QR code generation, custom domain management, and team collaboration.
  • Payment Processing: To facilitate subscription payments through Paddle, prevent fraud, and manage billing.
  • Communications: To send transactional emails (account verification, password resets, billing receipts), technical notices, security alerts, and support responses.
  • Analytics and Insights: To provide you with link performance analytics, visitor insights, and usage statistics.
  • Personalization: To customize your experience based on your preferences and usage patterns.
  • Security: To detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms of Service.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and law enforcement requests.
  • Service Improvement: To develop new features, improve algorithms, fix bugs, and enhance the overall Service experience.
  • Marketing: With your explicit consent, to send promotional communications about new features, updates, and offers. You may opt out at any time.

3.2 What We Do NOT Do With Your Data

  • We do not sell your personal data. We have never sold personal data and have no plans to do so.
  • We do not use your data to train AI or machine learning models. Your content, analytics data, and personal information are never used for AI training purposes.
  • We do not share your data with data brokers.
  • We do not use your data for behavioral advertising by third parties.

3.3 Conversion Tracking (Optional Feature)

What It Is: If you enable conversion tracking, we collect data about visitor actions on your website (purchases, signups, downloads, etc.) to help you measure the effectiveness of your shortened links.

Consent Required

Conversion tracking REQUIRES explicit visitor consent. We will only track conversions if:

  1. Your visitor has accepted analytics cookies via your cookie banner, AND
  2. You have configured consent checks in your implementation

Data Collected for Conversions

  • Conversion Type: The type of action taken (e.g., purchase, signup, download)
  • Conversion Value: Monetary value associated with the conversion (if provided by you)
  • Time to Conversion: Time elapsed from initial click to conversion
  • Link Attribution: Which shortened link led to the conversion

Your Responsibilities

When using conversion tracking, you must:

  • Obtain valid consent from visitors before enabling tracking
  • Disclose conversion tracking in your own privacy policy
  • Provide visitors with an opt-out mechanism
  • Only track conversions for visitors who have consented to analytics

4. Categories of Sources

We collect personal data from the following categories of sources:

  • Directly from you: Account registration, profile updates, support requests, and content you submit.
  • Automatically: Through your use of the Service via cookies, server logs, and analytics tools.
  • Third-party service providers: OAuth providers (Google, GitHub), payment processors (Paddle), analytics services (PostHog), and automation platforms (Make.com).
  • Publicly available sources: Domain registration data (for custom domain verification).

5. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:

  • Contractual Necessity (Article 6(1)(b) GDPR): Processing necessary to perform our contract with you, including providing the Service, managing your account, and processing payments.
  • Legitimate Interests (Article 6(1)(f) GDPR): Processing necessary for our legitimate business interests, including security, fraud prevention, service improvement, and analytics, where such interests are not overridden by your data protection rights.
  • Consent (Article 6(1)(a) GDPR): Where you have given explicit consent for specific purposes, such as marketing communications and optional analytics cookies.
  • Legal Obligation (Article 6(1)(c) GDPR): Processing necessary to comply with legal requirements, such as tax obligations, law enforcement requests, and regulatory requirements.

6. How We Share Your Information

We do not sell your personal information. We may share your information only in the following limited circumstances:

6.1 Categories of Recipients

Recipient CategoryPurposeData Shared
Payment Processor (Paddle)Payment processing, invoicing, tax complianceName, email, billing address, subscription details
Cloud InfrastructureHosting, storage, computeAll data (processed per our instructions under DPA)
Analytics ProvidersProduct analytics, service improvementUsage data, anonymized interaction data
Email Service ProvidersTransactional and marketing emailsName, email address
OAuth ProvidersAuthenticationAuthentication tokens (as initiated by you)
Automation Platforms (Make.com)API integrations for workflow automation (when you connect your Sniplink account)Account ID, workspace data, link data, analytics data (per your integration settings)

6.2 Other Circumstances

  • Business Transfers: If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
  • Legal Requirements: We may disclose information if required to do so by law or in response to valid legal process (e.g., court orders, subpoenas, warrants, or government requests). We may comply with such requests without prior notice to you where prohibited by law or where we determine, in our sole discretion, that prior notice would be impractical, ineffective, or would create a risk of harm. Sniplink shall have no liability for disclosures made in good faith compliance with legal process.
  • Protection of Rights: We may disclose information to enforce our Terms of Service, protect our rights, privacy, safety, or property, or that of our users or the public, and to detect, prevent, or address fraud, security, or technical issues.
  • With Your Consent: We may share information with third parties when you give us explicit consent.

6.3 Sub-Processors

We use sub-processors to assist in providing the Service. A current list of our sub-processors is available upon request by contacting Loading contact information. We will notify you of any material changes to our sub-processor list at least 30 days in advance by email or in-app notification. All sub-processors are bound by data processing agreements that require them to process personal data only as instructed and to implement appropriate technical and organizational security measures.

6.4 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. This data may be used for industry analysis, benchmarking, research, and other lawful business purposes.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities. For a detailed description of the cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy.

Key points:

  • Essential Cookies: Required for the Service to function (authentication, security, session management). Always active.
  • Analytics Cookies: Help us understand usage patterns. Opt-in only via our cookie banner.
  • Functional Cookies: Enable enhanced features like theme preferences and workspace selection.

You can manage cookies through our cookie banner or your browser settings. Disabling certain cookies may limit functionality.

8. Data Retention

We retain your information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by law. Specific retention periods:

Data TypeRetention PeriodNotes
Account InformationUntil account deletion + 90 days90-day grace period for security and fraud prevention
Click Event Data30 daysPersonal identifiers automatically deleted after 30 days
IP Addresses7 days (then anonymized)Replaced with an irreversible anonymized hash
Aggregated AnalyticsIndefinitelyContains no personally identifiable information
Transaction Records7 yearsRequired for financial and tax compliance
Support Communications3 yearsQuality assurance and legal compliance
Server Logs90 daysSecurity monitoring and debugging

When information is no longer needed, we securely delete or anonymize it using industry-standard methods. Our automated data retention cleanup job runs daily to remove expired data.

Notwithstanding the above, we reserve the right to anonymize or delete any data at any time without notice if required to comply with applicable law, respond to legal process, address security concerns, or enforce our Terms of Service. Anonymized data that cannot reasonably be used to identify any individual may be retained indefinitely.

9. Data Security

We implement appropriate technical and organizational security measures to protect your information, including:

  • Encryption of data in transit using TLS 1.2+ / SSL
  • Encryption of sensitive data at rest using AES-256
  • Password hashing using industry-standard algorithms (argon2)
  • Regular security audits and vulnerability assessments
  • Role-based access controls and principle of least privilege
  • Multi-factor authentication for administrative access
  • Automated monitoring for unauthorized access attempts
  • Incident response and breach notification procedures

No method of transmission over the Internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security. If you discover a security vulnerability, please report it to Loading contact information.

Analytics Data Accuracy: Analytics data provided through the Service (including click counts, geographic data, device information, and referrer data) is provided on an "as is" basis and may be approximate. We do not warrant the accuracy, completeness, or reliability of analytics data. Factors such as VPNs, ad blockers, bot traffic filtering, consent requirements, and browser privacy features may affect data accuracy. Analytics data should not be relied upon as the sole basis for business decisions.

10. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal data:

10.1 Access and Portability

You have the right to access your personal data and receive a copy in a structured, commonly used, machine-readable format (e.g., JSON or CSV).

10.2 Correction

You can update or correct your account information at any time through your account settings, or by contacting us.

10.3 Deletion

You may request deletion of your account and personal data. We will delete your data within 30 days, except for information we are required to retain by law or for legitimate business purposes (e.g., transaction records for tax compliance).

10.4 Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest its accuracy or object to processing.

10.5 Objection

You have the right to object to the processing of your personal data based on our legitimate interests. We will cease processing unless we have compelling legitimate grounds that override your interests.

10.6 Withdraw Consent

Where we rely on your consent for processing, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

10.7 Opt-Out of Marketing

You can opt out of marketing communications by clicking the unsubscribe link in any marketing email, or by updating your communication preferences in your account settings.

10.8 Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (GDPR Article 22). We do not currently engage in purely automated decision-making that produces legal effects. If this changes, we will update this Policy and obtain your explicit consent where required.

10.9 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. See Section 20 for details on how to contact the relevant authority in your jurisdiction.

10.10 How to Exercise Your Rights

To exercise any of these rights, please contact us at Loading contact information. We will verify your identity before processing your request and respond within 30 days (or as required by applicable law). We will not charge a fee for reasonable requests, but may charge a reasonable fee for manifestly unfounded or excessive requests.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those of your country.

When we transfer personal data from the EEA, UK, or Switzerland to other countries, we implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission or UK ICO
  • EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework (where applicable)
  • Data Processing Agreements with all sub-processors that handle personal data on our behalf, ensuring they are contractually bound to process data only as instructed and to implement appropriate security measures

You may request a copy of the safeguards we have in place by contacting Loading contact information.

12. Children's Privacy

The Service is not intended for use by individuals under the age of 16 (or 13 in the United States, consistent with the Children's Online Privacy Protection Act, or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete such information within 30 days.

If you believe we have collected information from a child, please contact us immediately at Loading contact information.

13. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

13.1 Right to Know

You have the right to request that we disclose: (a) the categories of personal information we have collected about you; (b) the categories of sources from which we collected the information; (c) the business or commercial purpose for collecting or selling the information; (d) the categories of third parties with whom we share the information; and (e) the specific pieces of personal information we have collected about you.

13.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., we may retain information needed to complete a transaction, for security purposes, or as required by law).

13.3 Right to Correct

You have the right to request correction of inaccurate personal information we maintain about you.

13.4 Right to Opt-Out of Sale or Sharing

We do not sell or share (as defined by the CCPA/CPRA) your personal information. We have never sold personal information and have no plans to do so. Because we do not sell or share personal information, there is no need to opt out, but you may still contact us to confirm.

13.5 Right to Limit Use of Sensitive Personal Information

We do not collect or process sensitive personal information (as defined by the CPRA) beyond what is necessary to provide the Service.

13.6 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you services, charge different prices, or provide a different level of quality because you exercise your privacy rights.

13.7 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority and your identity before processing such requests.

13.8 How to Submit a Request

To exercise your California privacy rights, contact us at Loading contact information. We will verify your identity and respond within 45 days (with a possible 45-day extension if needed). You may make up to two requests per 12-month period.

13.9 Data Retention

For information about how long we retain each category of personal information, please see Section 8 (Data Retention) above.

13.10 Financial Incentives

We do not offer financial incentives (as defined by the CCPA/CPRA) in exchange for the collection, sale, or retention of your personal information. Our free and paid plans differ in features and usage limits, not in data collection practices.

13.11 California "Shine the Light"

Under California Civil Code Section 1798.83, California residents may request information about our disclosure of personal information to third parties for direct marketing purposes. Because we do not disclose personal information to third parties for their direct marketing purposes, this provision does not apply.

14. Nevada Privacy Rights

If you are a Nevada resident, you have the right to opt out of the sale of certain "covered information" (as defined under Nevada SB 220). We do not sell your covered information as defined under Nevada law. To submit an opt-out request or for any questions, contact us at Loading contact information.

15. Other U.S. State Privacy Rights

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), or other states with comprehensive privacy laws, you may have similar rights, including:

  • Right to access your personal data
  • Right to correct inaccuracies
  • Right to delete your personal data
  • Right to data portability
  • Right to opt out of targeted advertising, sale of personal data, and profiling
  • Right to appeal our decision regarding your request

To exercise these rights, contact us at Loading contact information. If we deny your request, we will provide a written explanation. You may appeal by emailing Loading contact information with "Privacy Appeal" in the subject line. We will respond to appeals within 60 days (or as required by your state's law). If you are not satisfied with our appeal response, you may file a complaint with your state's attorney general.

16. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay (GDPR Article 34).

We will also comply with all applicable state and federal breach notification laws, including notifying affected individuals within the timeframes required by their jurisdiction of residence.

Our breach notification obligations are limited to breaches of data within our systems and under our direct control. We are not responsible for breaches of Destination Sites, third-party services, or data that you, as a data controller, independently collect or process outside of the Service. Our liability for data breaches is subject to the limitation of liability provisions set forth in our Terms of Service.

17. Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals. There is no uniform standard for interpreting DNT signals. We currently do not respond to DNT signals, but we honor opt-out preferences expressed through our cookie banner and account settings.

18. Data Ownership

You retain all ownership rights in the data you submit to the Service, including your links, custom domains, QR code configurations, and analytics configurations. Our right to use your data is limited to providing and improving the Service as described in this Policy. You may export your data at any time through your account settings or by contacting Loading contact information. Upon account termination, we will provide a reasonable period (not less than 30 days) for you to export your data before deletion.

We contractually commit that we will not use your data to train artificial intelligence or machine learning models.

19. Third-Party Links and Destination Sites

19.1 Nature of the Service

Sniplink is a link shortening and QR code generation service. The core function of the Service is to redirect users to third-party websites and resources ("Destination Sites") chosen entirely by link creators. Sniplink does not control, operate, own, or have any affiliation with Destination Sites.

19.2 No Responsibility for Destination Sites

We are not responsible for the privacy practices, data collection, content, security, legality, or availability of any Destination Site. Each Destination Site is governed by its own privacy policy and terms of service, which may differ significantly from ours. We do not review, audit, or verify the privacy practices of Destination Sites.

19.3 Data Collected by Destination Sites

When you click a shortened link and are redirected to a Destination Site, that site may independently collect your personal data (including IP address, browser information, cookies, and other tracking technologies) according to its own privacy policy. Sniplink has no control over and bears no liability for data collected by Destination Sites. We encourage you to review the privacy policy of any Destination Site you visit.

19.4 Link Creator Responsibility

Link creators are solely responsible for the Destination Sites to which their shortened links and QR codes redirect. If you create links through the Service, you represent that you have reviewed the privacy practices of your Destination Sites and that directing visitors there does not violate applicable privacy laws or your obligations as a data controller.

19.5 No Endorsement

The existence of a shortened link or QR code to any Destination Site does not imply our endorsement, sponsorship, affiliation, or recommendation of that site, its content, its products, or its privacy practices.

20. Supervisory Authority

If you are located in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have processed your personal information in violation of applicable data protection law. We encourage you to contact us first at Loading contact information so we can try to resolve your concern.

  • EEA residents: You may contact your local supervisory authority. A list is available at edpb.europa.eu.
  • UK residents: You may contact the Information Commissioner's Office (ICO) at ico.org.uk.
  • Swiss residents: You may contact the Federal Data Protection and Information Commissioner (FDPIC).

Sniplink is based in Tel Aviv, Israel. The Israeli Privacy Protection Authority (PPA) is the relevant data protection regulator for our company under the Protection of Privacy Law, 5741-1981 (the "Israeli Privacy Law").

Under Israeli law, you have the right to access and correct personal data held about you (Section 13 of the Israeli Privacy Law). Israel has been recognized by the European Commission as providing an adequate level of data protection (Commission Decision 2011/61/EU), which facilitates the transfer of personal data from the EEA to Israel. We comply with the Israeli Information Security Regulations (5777-2017) and register databases as required under the Israeli Privacy Law. The Israeli PPA can be contacted at gov.il/privacy.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will notify you by:

  • Posting the updated Policy on this page with a new "Last Updated" date
  • Sending an email notification to the address associated with your account
  • Displaying a prominent notice within the Service

We will provide at least 30 days' notice before material changes take effect. Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree, you must stop using the Service and may request deletion of your data.

22. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Legal Entity: sniplink.co

Address: Tel Aviv, Israel

Privacy Inquiries: Loading contact information

General Support: Loading contact information

Data Protection Officer: Our designated Data Protection Officer can be reached at Loading contact information. The DPO is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws.

Privacy & Security Issues: Loading contact information

This Privacy Policy is provided in English. Any translation is provided for convenience only. In the event of any conflict or inconsistency between the English version and any translation, the English version shall prevail.