Privacy policy
This page states what data we collect, why, and how long we keep it. No boilerplate: it describes exactly what the service actually does.
1. Who processes the data
The data controller is VMTech DOO Beograd, Republic of Serbia. Contact for any data question: [email protected].
2. Data of the account owner
We store: the email address, the name, the company name if you provide one, the chosen language and theme, and a hash of the password — never the password itself.
We also keep a sign-in journal: browser and operating system family, country and time. The full IP address is not stored there either. The journal exists so that you can see someone else's sign-in and end it.
3. Analytics without cookies
On each opening of a link we record: time, country, device class (phone, tablet, computer), operating system family, browser, browser language, the domain the visitor came from, and UTM marks if present.
The IP address is not stored. To approximate the number of distinct visitors we compute a hash of the address, the browser, the date and a secret salt. The salt changes every day and is not kept anywhere, so the hash cannot be turned back into an address and visits of the same person on different days cannot be linked.
There are no cookies, no browser fingerprinting and no tracking of a visitor across different links or sites. That is why no consent banner is needed.
4. Cookies
The service sets only a technical session cookie, and only once you sign in: without it the dashboard would not know who you are. There are no analytics or advertising cookies and none are shared with third parties.
5. Why we process the data
Account data is processed to perform the contract with you — without it the service cannot work. Anonymous open statistics are processed on the basis of legitimate interest: the link owner needs to see whether it works, and we need to spot abuse.
The data is not used for advertising, and we make no automated decisions with legal effect on you.
6. Who else sees the data
The servers are located in Germany (Hetzner). Traffic passes through Cloudflare, which protects the service from attacks and sees the network data of a request. Email is sent from our own server.
We do not sell data and do not pass it to advertising networks. We disclose it only upon a lawful request from a competent authority.
7. How long we keep the data
Account data is kept while the account exists. Anonymous open events are kept for as many days as your plan provides; older ones are deleted.
A sign-in record lives as long as the session itself and is deleted as soon as it expires or you end it. Deleting the account removes the account, the links and the statistics at once.
8. Your rights
You have the right to see your data, to download it, to correct it and to delete it. Download and deletion are buttons in the dashboard settings — no support ticket and no waiting.
If something is unclear or you believe we got it wrong, write to [email protected]. You also have the right to lodge a complaint with the competent data protection authority.
9. Changes to this policy
This policy may be extended as the service changes. The date of the last change is shown at the top of the page; material changes are announced to the account email address.