Privacy Policy
Last updated: 8 June 2026
This Privacy Policy explains how Snipify ("we", "us", or "our") collects, uses, and protects your personal data when you use our URL shortening service (the "Service"). We are committed to handling your data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
By using the Service, you acknowledge that you have read and understood this policy. If you do not agree with it, please do not use the Service.
1. Who is responsible for your data
The data controller responsible for your personal data is the operator of this Snipify instance. For any privacy-related questions or to exercise your rights, contact us at [email protected].
2. What data we collect
We collect only the data we need to operate the Service:
- Account data — your email address and a securely hashed version of your password (we never store your password in plain text).
- Link data — the original (destination) URLs you submit, the short aliases we generate, and the association between those links and your account.
- Technical and log data — when you make a request, our servers record limited information such as your IP address, the requested path and HTTP method, the response status, and the time taken to process the request. This is used for security, debugging, and reliability.
- Cookies — small files used to keep you signed in and to remember your display preferences. See our Cookie Policy for full details.
We do not use advertising trackers, third-party analytics, or sell your data to anyone.
3. How and why we use your data (legal bases)
Under the GDPR, we process your data on the following legal bases:
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account, shortening links, and performing redirects | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails (account activation, password reset, deactivation notices) | Performance of a contract (Art. 6(1)(b)) |
| Keeping the Service secure, preventing abuse, and maintaining server logs | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations where required | Legal obligation (Art. 6(1)(c)) |
4. Email communications
We send only transactional emails that are necessary to operate your account — for example, to confirm your registration, to let you reset your password, or to notify you that your account has been deactivated. We do not send marketing emails.
5. Who we share data with
We share personal data only with service providers that help us run the Service, namely:
- Our hosting provider, which stores the data on our behalf.
- Our email (SMTP) provider, used solely to deliver the transactional emails described above.
These providers act as data processors and are only permitted to process your data on our instructions. We may also disclose data where required by law.
6. International transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses or transfers to countries with an adequacy decision.
7. How long we keep your data
- Account data is kept for as long as your account is active.
- When you deactivate your account, your login credentials are revoked and your account can no longer be accessed or restored. Please note that links you previously created may continue to function so that they do not break for people who already have them.
- Server logs are retained only for a limited period necessary for security and operational purposes, after which they are deleted or anonymised.
8. Your rights under the GDPR
If you are in the EEA, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data ("right to be forgotten").
- Restriction — ask us to limit how we process your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email us at [email protected]. You also have the right to lodge a complaint with your local data protection supervisory authority.
9. Data security
We take appropriate technical and organisational measures to protect your data. Passwords are hashed using a strong, modern algorithm (Argon2), authentication cookies are HTTP-only and transmitted securely in production, and sessions use short-lived access tokens with rotating refresh tokens.
10. Children's privacy
The Service is not intended for children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us so we can remove it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Significant changes may be communicated to you directly where appropriate.
12. Contact us
If you have any questions about this Privacy Policy or how we handle your data, contact us at [email protected].