Privacy Policy · ShortenFor.Me
This Privacy Policy applies to ShortenFor.Me (shortenfor.me) and is compliant with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws.

1. Who We Are

ShortenFor.Me ("we", "us", "our") is a URL shortening and link analytics service operated by Team ShortenFor.Me. We act as the Data Fiduciary under the DPDP Act for all personal data processed through our platform.

Grievance Officer / Data Protection Contact:
Email: privacy@shortenfor.me
Response time: Within 48 hours for acknowledgement; 30 days for resolution.

2. What Personal Data We Collect

We collect personal data only to the extent necessary to provide our services.

Data CategorySpecific DataPurposeLegal Basis
Account Data Name, email address, password (hashed) Account creation and authentication Contract / Consent
OAuth Data Name, email, profile photo from Google / Microsoft / Meta Social login Consent
Link Data Original URLs you shorten, custom codes, link titles Providing the shortening service Contract
Analytics Data Click counts, country, device type, browser, referrer URL, IP address (hashed after 90 days) Providing click analytics to you Contract / Legitimate Interest
Payment Data Subscription plan, payment gateway customer ID (Stripe/Razorpay/PayPal). We do not store card numbers. Processing payments and managing subscriptions Contract
Communication Data Support ticket content, email address Customer support Legitimate Interest / Consent
Security Data IP address, login timestamps, failed login count, MFA secrets Security, fraud prevention, account protection Legitimate Interest
Consent Records Date, time, and IP address of consent Compliance with DPDP Act Legal Obligation

3. How We Use Your Data

We use your personal data only for the purposes stated at the time of collection:

  • Providing URL shortening, analytics, and QR code services
  • Processing payments and managing your subscription
  • Sending transactional emails (account verification, password reset, receipts)
  • Sending weekly AI analytics reports (Premium users only, with your consent)
  • Sending onboarding and product update emails (you can unsubscribe at any time)
  • Preventing fraud, abuse, and protecting the security of our platform
  • Complying with legal obligations
  • Improving our services using aggregated, anonymised data

We do not sell your personal data to any third party.

We do not use your data for automated decision-making that significantly affects you.

4. Third-Party Data Processors

We share data with the following processors only to the extent necessary to deliver our services. Each processor is contractually bound to protect your data:

ProcessorPurposeCountryData Shared
HostingerWeb hosting and databaseLithuania / IndiaAll account and usage data
StripePayment processingUSAName, email, subscription details
RazorpayPayment processing (India)IndiaName, email, subscription details
PayPalPayment processingUSAName, email, subscription details
ResendTransactional email deliveryUSAName, email address, email content
AnthropicAI-generated analytics insightsUSAAggregated, anonymised link analytics
Google / Microsoft / MetaOAuth login (if used)USAName, email, profile photo

International Data Transfers: Some processors are located outside India and the EU. Where data is transferred internationally, we ensure appropriate safeguards are in place including Standard Contractual Clauses and processor Data Processing Agreements.

5. Data Retention

We retain your personal data only as long as necessary:

  • Active accounts: Data retained while your account is active
  • Deleted accounts: Personal data permanently deleted within 30 days of deletion request; anonymised aggregate analytics may be retained
  • Click analytics: Full data retained for 24 months; IP addresses anonymised after 90 days; aggregated counts retained indefinitely
  • Support tickets: Retained for 12 months after resolution, then deleted
  • Email logs: Retained for 6 months
  • Payment records: Retained for 7 years as required by Indian financial regulations
  • Unverified accounts: Deleted automatically after 7 days if email is not verified
  • Consent records: Retained for the duration of your account plus 3 years

6. Your Rights Under DPDP Act and GDPR

You have the following rights over your personal data. To exercise any right, visit your Privacy Dashboard or email privacy@shortenfor.me.

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your account and all associated personal data
  • Right to Withdraw Consent: Withdraw marketing consent at any time without affecting lawfulness of prior processing
  • Right to Grievance Redressal: Raise a grievance with our Grievance Officer; we acknowledge within 48 hours and resolve within 30 days
  • Right to Nominate (DPDP): Nominate another person to exercise your rights in the event of death or incapacity
  • Right to Data Portability (GDPR): Receive your data in a machine-readable format
  • Right to Object (GDPR): Object to processing based on legitimate interest

You also have the right to lodge a complaint with the Data Protection Board of India (once operational) or the Information Commissioner's Office (UK) / your local EU supervisory authority if you believe we have violated your rights.

7. Cookies

We use the following types of cookies:

  • Essential cookies: Session cookies required for login and security. These cannot be disabled.
  • Analytics cookies: We may use Google AdSense which sets advertising cookies on our redirect pages for free users. These require your consent.

You can manage cookie preferences at any time via the cookie consent banner or your browser settings.

8. Children's Data

ShortenFor.Me is not intended for children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at privacy@shortenfor.me and we will delete it immediately.

Under the DPDP Act, processing of children's data requires verifiable parental consent. We rely on age confirmation at registration and will implement additional verification measures as required by DPDP rules when notified.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Passwords hashed using Argon2id with appropriate cost parameters
  • Sensitive settings (API keys, SMTP credentials) encrypted with AES-256-GCM
  • HTTPS enforced across all pages with HSTS
  • Session security including fingerprinting, idle timeout, and periodic rotation
  • Rate limiting on all authentication endpoints
  • Multi-factor authentication available to all users

Data Breach Notification: In the event of a personal data breach that poses a risk to your rights, we will notify the Data Protection Board of India within 72 hours and affected users without undue delay.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email and by displaying a notice in your dashboard. Continued use of ShortenFor.Me after changes constitutes acceptance of the updated policy.

Previous versions of this Privacy Policy are available on request.

11. Contact and Grievances

For any privacy-related questions, data requests, or grievances:

Grievance Officer: Team ShortenFor.Me
Acknowledgement: Within 48 hours
Resolution: Within 30 days


This Privacy Policy was last updated on July 13, 2026 (Version 1.0). ShortenFor.Me · privacy@shortenfor.me