Privacy Policy
Last updated: July 3, 2026
ShortLynx ("we", "us") operates a link-shortening and campaign-analytics service. This page explains what data we collect when someone clicks one of our short links or uses our dashboard, and what we deliberately do not collect.
What we collect when a link is clicked
Every click through a ShortLynx short link is redirected instantly, and we record:
- The timestamp of the click.
- A one-way cryptographic hash of the visitor's IP address (keyed with a secret pepper, rotating hourly). The raw IP address is never stored. This hash cannot be reversed to recover the original IP and is used only to estimate unique visitors and to filter automated traffic.
- Coarse, low-detail categories derived from the browser's request headers: platform/referrer source (e.g. "Twitter", "Direct"), device class (mobile/desktop/tablet), browser family, operating system family, primary language, and — where our infrastructure supports it — country. We derive these categories once and discard the underlying raw values (the full User-Agent string and the full referring URL are never stored).
- For links created in "user-attributed" mode (used for outreach and sales tracking), the specific recipient code that was clicked, so the link creator can see which of their own contacts engaged. This does not require the visitor to sign in or provide any personal information at click time.
What we do not collect
- We do not set tracking cookies on the redirect.
- We do not collect precise geolocation, device fingerprints, or browser fingerprinting signals.
- We do not sell click data or share it with advertisers or data brokers.
- If a visitor's browser sends Do Not Track (DNT) or Global Privacy Control (Sec-GPC), we honor it: the click is still counted for aggregate volume, but none of the category data above (platform, device, browser, etc.) is recorded for that click.
Account data
If you create a ShortLynx account (to shorten links, run campaigns, or connect social accounts), we store your email address, the links and campaigns you create, and — for connected social accounts — OAuth access tokens, which are encrypted at rest and never displayed after the initial connection. You can disconnect a social account at any time, which permanently deletes its stored tokens.
Data retention and deletion
You may request deletion of your account and associated data at any time. See our Data Deletion Instructions for how to do this.
Contact
Questions about this policy or your data can be sent to hello@shortlynx.dev.