Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains how Ivan Voitovych, sole proprietor, trading as “Urlicer” ("we", "us") collects, uses, and shares information when you use the Urlicer service at urlicer.com (the "Service"). We are the data controller for the data described here. Urlicer is designed to collect as little personal data as possible. Most notably, our click analytics are cookieless and never store your raw IP address.

1. Information we collect
  • Account data: your name, email address, a hash of your password, and your team memberships.
  • Link data: the short links you create, their destination URLs, and per-link settings (alias, expiry, password protection, targeting/rotation rules).
  • Click analytics (privacy-preserving): when someone follows one of your links we record the event to power your dashboards and to keep the Service secure. We store: an irreversible hash of the visitor's IP address combined with a salt that rotates every day; we never store the raw IP, and the daily rotation means the same visitor cannot be recognised across days; the approximate country only (country level, derived locally from the IP, not city or precise location); the referrer domain (e.g. "twitter.com", not the full referring URL); the device type, browser, and operating system derived from the user-agent; and whether the click came from a QR code. We do not set tracking cookies on visitors and do not build cross-site advertising profiles.
  • Support data: the messages and any attachments you send us.
  • Billing data: your plan and subscription status, and the billing country Paddle reports. Payment card details are collected and processed by Paddle (section 4); we never see or store full card numbers.
2. How we use information and our legal bases

We use this data to provide, maintain, secure, and improve the Service; to detect and prevent abuse (such as malware and phishing links); to process your subscription; to send you transactional email (account, billing, and security notices) and, where you have opted in or where permitted, product updates; and to comply with legal obligations. Our legal bases (GDPR / UK GDPR) are: performance of a contract (operating your account), legitimate interests (securing the Service, preventing abuse, and product analytics on pseudonymised data), consent where required, and legal obligation.

3. Cookies

Urlicer uses only strictly-necessary and functional first-party cookies. We use no advertising or cross-site tracking cookies, and neither our click analytics nor the analytics we run on our own website use cookies at all, so we do not display a cookie consent banner. The cookies we set are:

  • Authentication & session: to keep you signed in.
  • Security (CSRF): to protect form submissions.
  • Theme preference: remembers light/dark mode.
  • Protected-link unlock: set only after you enter a link's password, so you are not asked again.
  • A/B variant: set only on a link running a split test, to keep a visitor on the same destination; it stores a variant number only and is not used to track or profile.
4. Payments (Paddle)

Payments are processed by Paddle.com Market Ltd, our authorised reseller and Merchant of Record. When you check out, your payment information is provided directly to Paddle and handled under Paddle's privacy policy. Paddle is the seller of record and handles payment, tax, and invoicing; it shares back with us only limited data such as your subscription status, plan, and billing country.

5. Service providers (sub-processors)

We share data with the providers below, each under contractual data-protection obligations. We do not sell your personal information.

ProviderPurposeData involved
Paddle.com Market LtdPayments, tax, invoicing (Merchant of Record)Billing & payment data
netcup GmbHCloud hosting: the servers the Service runs onAll Service data, at rest and in transit. netcup is a German company and our servers are in its Amsterdam data centre (Netherlands, EU).
Hetzner Online GmbHCloud hosting for our mail server: sending and receiving the emails the Service usesYour email address, and the content of the emails we send you and that you send us. Hetzner is a German company and our mail server is in its Helsinki data centre (Finland, EU).
Google LLC (Safe Browsing)Checking destination URLs for malware / phishing to protect all usersThe destination URLs you shorten (which may contain query parameters)
Emvi Software GmbH (Pirsch Analytics)Privacy-friendly analytics for our own website: how many people visit our pages, and where they arrive fromAnonymous page-view data: page URL, referrer, country, device/browser/OS, and a visitor hash derived from IP address + user-agent + a salt that rotates daily. No cookies are set and no raw IP address is stored. Emvi is a German company and the data is stored in Germany.
6. International transfers

Our hosting (netcup, servers in the Netherlands), the delivery of our emails (our own mail server, hosted with Hetzner in Finland) and our website analytics (Pirsch, servers in Germany) all stay inside the EU. Some other providers, for example Google and Paddle, may process data outside your country, including in the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

7. Retention

We keep account data while your account is active and as needed for legitimate business and legal purposes. Click analytics are retained for the retention window of your plan, after which they are deleted; and because the IP-hash salt rotates daily, older click records cannot be linked back to a specific visitor. Links created without an account are given a limited lifetime and expire automatically. Abuse and security records are kept as long as needed to protect the Service.

8. Your rights

Depending on where you live (for example the EEA/UK under the GDPR, or California under the CCPA/CPRA) you may have the right to access, correct, delete, export, or restrict the processing of your data, to object to processing, and to withdraw consent. You can export your links and analytics yourself from within the app; to access, correct, or delete your account and associated data, contact privacy@urlicer.com and we will action your request. We do not sell personal information, so there is nothing to opt out of under "do not sell". You may also lodge a complaint with your local data-protection supervisory authority.

9. Security

We protect data with measures including password hashing, encryption in transit (HTTPS), pseudonymisation of analytics, and access controls. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authorities of a qualifying breach as required by law.

10. Children

The Service is not directed to children under 16 and we do not knowingly collect their data.

11. Changes & contact

We may update this policy; material changes will be posted here with a new date. Data-protection contact: privacy@urlicer.com. General enquiries: ivan@urlicer.com. To report an abusive or harmful link, see urlicer.com/report or email abuse@urlicer.com.

Ivan Voitovych, sole proprietor
Kniahyni Olgy 98v, Lviv 79053, Ukraine

See also our Terms of Service and Refund Policy.