Privacy Policy
Last updated: September 1, 2026
This policy explains what personal data snipzr.com ("Snipzr", "we") processes, why it is processed, and what your rights are. The controller is Snipzr. Contact for anything in this policy: support@snipzr.com.
What we process, and why
Account data. Email address, password (stored as a hash), optional display name and profile photo, language and timezone preferences. If you sign in with Google we receive your email, name and profile photo from your Google account. Purpose: providing your account and signing you in. Legal basis: performance of our contract.
Your links and workspaces. The destinations, titles, slugs and campaign parameters of the links you create, your connected domains, and your workspace's settings. In a shared workspace, your name, email, photo and role are visible to the other members, and content is visible to members according to their roles. Purpose: providing the Service. Legal basis: performance of our contract.
Billing data. Your plan, subscription state and invoices. Payments are processed by Stripe; we never receive your full card number. Purpose and basis: performing the contract and meeting legal (tax) obligations.
Usage and security data. Server logs for sign-in, application and API traffic, which include IP addresses, kept for a limited period for security and abuse investigation. Redirect traffic is different: see the next section. To protect sign-up and sign-in against bots we use Cloudflare Turnstile, which evaluates technical signals from your browser for that purpose. We also check link destinations against threat lists to protect visitors; this works on lists we download, not by sending your browsing to anyone. Legal basis: our legitimate interest in keeping the Service secure and abuse-free.
Emails. We send transactional email (verification, receipts, security) and product notifications such as the weekly analytics digest, which you can switch off in the settings or via the unsubscribe link. Legal basis: contract, and our legitimate interest in the notifications you can opt out of.
Support. If you write to us we process your message and address to answer you.
Clicks on short links: cookie-less measurement
When someone opens a snipzr short link we count the click for the link's owner without cookies, without storing anything on the visitor's device and without creating any visitor identifier. The visitor's IP address is used momentarily to derive a two-letter country code and is not stored in analytics. Owners see aggregate numbers only. The full description, including the legitimate-interest basis and your right to object, is in the "Link analytics" section below.
Link analytics
When you click a snipzr short link, we count the click to give the link's owner basic, aggregate statistics about how their link is performing. We designed this to be privacy-friendly by default.
We do not use cookies or any tracking for this. No cookie is set, nothing is stored on or read from your device, and we do not create any identifier for you: no cookie, no fingerprint, no "visitor ID". Because nothing is stored on your device, this measurement needs no cookie-consent banner. This describes the link-click measurement only, which is entirely first-party; no third-party analytics service counts your click. Our marketing website and the signed-in dashboard are separate products and do use Google Analytics, as described in the "Website analytics on our own pages" section below, where your choices are described.
What the link owner sees: aggregate numbers only
For each of their links, a link owner can see totals such as: how many clicks the link received over time (with a rough split of real clicks vs. bots and link-preview bots); the country a click came from (country only, never your city or precise location); the referring site's domain (never the full page address); broad device, browser, operating-system and language categories; and whether the click came from the link itself or a QR code. These are always totals, never a list of individual visits, and never anything that identifies you.
About your IP address
To work out the country, our content-delivery provider reads your IP address at its network edge and passes us only a two-letter country code. We do not store your IP address in our analytics, and we remove it from our access logs and error reports for this traffic. Your IP is used only momentarily to derive the country and is then discarded.
Legal basis
Deriving the country from your IP relies on our and the link owner's legitimate interests (Article 6(1)(f) GDPR) in understanding, in aggregate, how public links perform. The stored statistics are aggregate and do not identify you. We have carried out and documented a legitimate-interest assessment.
How long we keep it
Aggregate link statistics are kept for up to 750 days (about 25 months), regardless of the link owner's subscription plan. Subscription tiers only change how far back an owner can view their statistics; they do not change how long the data is retained. When a link or account is deleted, its analytics are deleted with it.
Your choices
Because the country derivation relies on legitimate interests, you have the right to object to it. Contact us by e-mail using the details under “Contact” above and we will address your objection. Because we hold no identifier for you, there is no visitor profile to access or export.
Because this measurement uses no cookies and no cross-site tracking, browser “Do Not Track” and Global Privacy Control signals do not change it (see “Do Not Track” above).
What we deliberately do not do: we do not track you across sites; we do not build a profile; we do not count "unique visitors"; we do not record your city or precise location; we do not store the full address of the page you came from; and we do not sell or share this data.
Website analytics on our own pages
On our website and app we use Google Analytics and Microsoft Clarity to understand how the site is used and where it fails; Clarity can replay how the interface was used during a session. These tools use cookies or similar identifiers; you can block them with your browser settings or a content blocker without affecting the Service. We also use error monitoring so that failures reach us with technical context. We do not run third-party advertising and we do not sell personal data.
Recipients
We share personal data only with processors that help us run the Service: cloud infrastructure and database providers, our payment provider (Stripe), our email delivery provider, bot protection (Cloudflare), the analytics and error-monitoring tools above, and customer support tooling. They process data for us under data processing agreements. We disclose data beyond that only where the law requires it or to protect our rights.
International transfers
We operate from the United States and our providers process data there. Where the GDPR applies, transfers rely on the European Commission's adequacy decisions (including the EU-US Data Privacy Framework where our providers are certified) or standard contractual clauses.
Retention
Account data is kept while your account exists. When you delete your account, your links and their analytics are deleted immediately and remaining account records are deleted or anonymized within 30 days, unless the law requires longer (for example invoices). Aggregate link statistics are kept for up to 750 days as described in the "Link analytics" section. Security logs are kept for a limited period.
Your rights
Where the GDPR applies you can request access, correction, deletion, restriction and portability of your personal data, and you can object to processing based on legitimate interests; where processing rests on consent you can withdraw it at any time. Write to support@snipzr.com. You also have the right to complain to a supervisory authority. California residents have the corresponding rights under the CCPA; we do not sell or share personal data as defined there.
Cookies on our own pages
Signing in uses strictly necessary cookies (session and security). The analytics tools above use their own cookies or identifiers. Your browser settings let you remove or block cookies; blocking the strictly necessary ones prevents signing in.
Children
The Service is not directed at children under 16 and we do not knowingly process their data.
Changes
We will update this policy when our practices change; the date above always shows the current version.