Skip to content
iink.click
FeaturesPricingAPI docsResources
Log in↗Get started free
IINK.CLICK

Privacy notice

Effective 11 October 2026 · Version 1.2

PrivacyTermsData processing

Service provider: Yevgeniy Kovalev, ul. Okólnik 11A/77, 00-368 Warsaw, Poland. NIP: 5272991183. REGON: 521331015. Contact: support@iink.click.

Who this notice is for

This notice covers people with an iink.click account, people who contact us, and people who open a short link operated through the service. We provide short links, custom domains, QR codes, click history and an account-scoped IP lookup API.

We are responsible for our account, support and service-administration activities. The customer who creates a short link chooses its destination and the purpose for using visitor records. Where we handle those records on the customer's instructions, we act as their processor under our Data processing agreement. The customer's own notice explains their purpose, legal basis and any matching with their other records.

Information we handle

  • Accounts: email, sign-in provider identifier, status and permissions, session information and settings. Passwords are stored as Argon2id hashes. Google and Apple sign-in supply the identity claims used for authentication. Accounts are not automatically merged because their emails match.
  • Links and domains: link endings, destination URLs, domain names, ownership-verification information and link/domain identifiers and the optional screen-collection setting.
  • Link visits: the visitor's full IPv4 or IPv6 address, short URL, destination URL, link ending and click time; available device type, brand, model, operating system, browser and preferred language; and the full supplied HTTP(S) Referer URL. When the link owner enables screen collection, visits can also include browser-reported screen width and height in CSS pixels, device pixel ratio and an estimated physical screen resolution. Detailed history also stores bounded User-Agent, Accept-Language and supported UA Client Hints headers. URLs and endings are stored as they appeared at the click. A URL path or query can itself contain personal information.
  • Billing, when a paid plan is used: Stripe customer, subscription and invoice references, amounts, payment status and dates. Payment details are entered in Stripe's hosted flow; our application does not store complete card numbers.
  • Support and operations: messages and abuse reports you send, usage counters, account-management actions and limited operational records.

Device and visit information is derived from supplied request headers. Optional screen collection is disabled by default and uses a short intermediate page with a browser script and a background request before opening the destination. Screen dimensions and device pixel ratio are reported by the browser; physical pixel dimensions are estimates. These values do not verify a physical device or human visitor, may be absent or changed by the sender, and their delivery is not guaranteed. GPS location and IP classification are not collected. The API field tags contains the link owner’s current tags; referrer_url is the supplied HTTP Referer. An IP address may be shared or reassigned; a match is not proof that a particular person clicked.

How information is used

Account and service information is used to carry out the service you request: sign-in, link and domain management, plan limits and support. Payment information administers a subscription when purchased. Records needed for applicable accounting or legal obligations are handled for those obligations. Operational and abuse information helps us protect accounts, investigate reported misuse and maintain the service.

Customer-directed click information is used to deliver the customer's links, record visits and answer that customer's searches. A customer can look up the most recent matching click for each of their links using an IP they supply. They cannot search another customer's history. We do not offer a public person-identification database or sell visitor history.

The customer must establish the basis for their particular visitor processing and provide a notice before the visitor opens a tracked link. A subscription contract does not supply consent on a visitor's behalf. Clicks are recorded automatically: the service does not provide a pre-click consent screen or no-recording link mode. Customers must not use it for a purpose that needs controls the service does not provide.

Who receives information

The link-owning customer can view their click records. Service personnel access is limited to work on the service, support, security and applicable requests. We use AWS for hosting, identity, processing, storage and transactional email; Infomaniak for support email; Stripe for payments when available; and Google or Apple when you choose that sign-in method. Porkbun provides domain registration and DNS. Payment and sign-in integrations are not click-history export features.

The application database is hosted in AWS Stockholm. Content delivery uses a global edge network, and provider operations may involve other locations. We do not represent every operation as taking place exclusively in Sweden or the EEA. Contact us for information relevant to your processing arrangement and provider safeguards. Providers also publish their own notices: AWS, Infomaniak, Stripe, Google, and Apple.

Opening a short link takes your browser to its destination, where the destination operator's practices apply. Information may also be disclosed in response to an applicable legal requirement, after assessing the request.

Retention and deletion

Click history is available for 365 days from each click. Device metadata, screen measurements and raw request-header captures follow the same retention and history erasure. Measurements without a corresponding click are removed after 24 hours. Editing or deleting a link does not restart that period. Link deletion stops future redirects but preserves unexpired history. The separate Erase history action hides the account's earlier history immediately and initiates physical deletion. Old queued events cannot restore erased history. Expired events are excluded from results even if physical deletion is still pending.

Processing queues can retain events for up to four days, with failed-delivery messages retained for up to fourteen days. Database recovery copies have a rolling retention of up to 35 days. These are not ordinary history access; recovery must preserve erasure decisions. Immediate hiding does not mean every residual copy disappears instantly.

Account and configuration records support your account while it exists. For account closure, contact us so we can identify records to delete and any that must remain for a specific obligation or unresolved request. Support, complaint and accounting information is kept for the relevant request, service or applicable record-keeping requirement; it is not part of the 365-day click-history promise. Application operational logs are configured for fourteen days and do not duplicate click IPs or complete URLs.

Cookies and account security

The account uses a secure, HttpOnly session cookie for up to one hour and a temporary social-sign-in cookie for up to ten minutes. API keys are stored as hashes. Short-link redirects do not set an analytics cookie, but they do record the IP-based visit information described here. A visit should not be treated as anonymous simply because it does not set a tracking cookie.

Your requests and choices

Write to support@iink.click to ask about access, correction, erasure, restriction, portability, objection or withdrawal of consent where applicable. We may need proportionate information to verify and locate the request. An IP alone does not establish a right to receive all associated records. Do not send passwords, card details or unnecessary identity documents.

For a customer's link records, include the relevant short link and approximate time and contact that customer where possible. We can help route the request and assist the responsible customer. Applicable requests are normally answered within one month; any permitted extension will be explained. You may complain to a competent data-protection authority, including Poland's President of the Personal Data Protection Office. See the EDPB guide to individual rights.

We will date updates to this notice and communicate material changes where required.


Questions about this document? Contact support@iink.click.

iink.click

Small links. A clearer picture.

© 2026 iink.click

Product

Short linksCustom domainsQR codesPricing

Explore

Click historyAPI documentationHelp & FAQReport a link

Company

PrivacyTermsData processingYour account