Privacy Policy
Last updated: 20 August 2026
1. Who we are
AnyLinks (operated by John Tang, Hong Kong, "we", "us", or "our") provides the short-link and store-routing Service described in the Terms of Service. This Privacy Policy explains what personal data we collect, why we collect it, and the rights you have over it.
For privacy questions, contact us at [email protected].
2. Data we collect
We collect the following categories of personal data: - Account data: name (if provided), email address, a hashed password, sign-in sessions (IP address and user agent), locale preference, claimed handle, plan status, and, if you choose Google sign-in, your Google account identifier; billing-related identifiers such as a Stripe customer ID. - Link and configuration data: short paths, destination URLs, display names, QR settings, Open Graph fields, and custom-domain settings you configure. - Click analytics: aggregated counts and breakdowns derived from redirect events (for example device class, and on Pro plans country, referrer host, and campaign tags). We do not store a full browsing history of each visitor in our application database. - Marketing site data: if analytics is enabled on the public website, standard web analytics identifiers may be collected on those pages only.
3. How we use data
We use personal data to: provide and operate the Service (creating links, resolving redirects, and showing statistics); manage accounts and plan limits; process billing and payments; send transactional messages related to your account; prevent abuse and maintain security; improve reliability; and comply with legal obligations.
We do not sell personal data. We do not insert third-party advertising into the redirect path.
4. Legal bases for processing (GDPR)
If you are in the EEA or the UK, our legal bases are: - Performance of a contract: to provide the Service and manage billing. - Legitimate interests: to keep the Service secure, prevent abuse, measure aggregate traffic, and improve reliability. - Consent: where required for optional marketing-site analytics cookies. - Legal obligation: where we must retain records for tax or other legal reasons.
5. Third parties we share data with
We use service providers to run the Service: - Stripe: subscription billing and payment processing (stripe.com/privacy). - Google: optional sign-in when enabled (policies.google.com/privacy). - Cloudflare: hosting, DNS, KV/D1 storage, and Analytics Engine for click aggregates (cloudflare.com/privacypolicy).
We share only the data each provider needs to perform its role and require providers to protect it.
6. Cookies and local storage
On the dashboard and API, we use session cookies required for signed-in accounts.
On the public marketing site, we may use optional analytics (for example GA4) when configured. We do not use advertising cookies on the redirect path. Theme preference may be stored in local storage on the marketing site.
Because short-link redirects are not an advertising network, we do not run cross-site ad tracking of visitors through the redirect itself.
7. Data retention
We keep personal data only as long as needed for the purposes above: - Account and configuration data: while your account is active, and for 30 days after account closure. - Click analytics: Free accounts retain shorter windows (for example 30 days of device stats); Pro accounts retain longer windows (for example 90 days) as described in the product. Underlying analytics events are retained according to our Cloudflare Analytics Engine configuration. - Payment records: as required by Stripe and by applicable financial record-keeping law.
8. Your rights
If you are in the EEA, the UK, or another jurisdiction granting similar rights, you may request: - Access to the personal data we hold about you. - Rectification of inaccurate data. - Erasure ("right to be forgotten"). - Restriction of processing. - Data portability in a structured, machine-readable format. - Objection to processing based on legitimate interests. - Withdrawal of consent at any time (for consent-based marketing analytics).
To exercise these rights, email [email protected]. We will respond within one month. You also have the right to lodge a complaint with a supervisory authority.
9. International transfers
Your data is stored on hosting infrastructure that may be located outside your country. Where we transfer personal data from the EEA or the UK to other countries, we rely on appropriate safeguards, including the European Commission's standard contractual clauses where required.
Data is primarily stored on Cloudflare infrastructure.
10. Security
We protect data with: encryption in transit (HTTPS); hashed passwords; session-based authentication; and restricted access to production data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact [email protected] and we will delete it.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the "last updated" date and, where practicable, notified by email or through the Service.
13. Contact
For privacy questions or to exercise your rights, email [email protected].