Privacy Policy
Operational draft — owner and legal review required before launch.
Scope
This operational draft explains data processing by Short ZinTools and requires owner and legal review before launch.
Account data
We process name, email address, password hash, locale, account status, plan assignment, and security timestamps to provide and protect accounts.
Link data
We process destinations, aliases, labels, status, optional password hashes, expiration, usage, and moderation records to operate links.
Click analytics
We record UTC time, country when supplied by a trusted header, device category, browser and operating-system families, referrer host, bot flag, and a rotating salted one-way fingerprint. We do not expose raw visitor IP addresses or retain full referrer URLs.
Purposes and retention
Data is used for service delivery, security, analytics, quotas, and abuse prevention. Click retention follows the assigned plan and scheduled cleanup. Expired security tokens and rate-limit records are deleted by maintenance.
Sharing and processors
Hosting, database, and configured SMTP providers process data as necessary. No advertising tracker or third-party geolocation API is required for redirects.
Your choices
Use the configured support contact to request access, correction, export where available, or deletion subject to security, legal, and abuse-preservation duties.
Security and international processing
Administrative access is restricted and audited. The owner must document hosting locations, legal basis, transfers, business identity, and privacy contact before launch.
Changes
The configured legal review date and material updates should be published before changes take effect.