Privacy Policy

Last updated 25 July 2026

Template. This document describes how WhizzLink is built and configured, but it has not been reviewed by a lawyer. Have counsel review and adapt it for your jurisdiction before relying on it.

Who this covers

WhizzLink is operated by WhizzAct Private Limited, which is the entity responsible for the personal data described here. This policy covers two groups: account holders, who create short links, and visitors, who click them. What we collect differs for each.

Account holders

We store the account data you give us and the records needed to operate the Service:

  • your name and email address;
  • a hash of your password — never the password itself;
  • your links, campaigns, folders, tags, QR settings, and custom domains;
  • login history, including the IP address and browser used, so you can spot unfamiliar access;
  • an audit log of sensitive actions such as link changes, suspensions, and API-token issuance.

Visitors who click a short link

When someone follows a short link we record analytics for the account holder who owns it: approximate location (country, region, city), device type, operating system, browser, referring page, browser language, UTM parameters, the time of the click, and whether the click appears to be from a bot.

IP addresses

By default we do not store raw visitor IP addresses. We store a salted hash, which lets us tell a repeat visitor from a new one without retaining the address itself. This behaviour is currently hash only (raw IPs not stored). Where raw addresses are stored, they are anonymised automatically after 30 days.

We also set a first-party cookie containing a random identifier so a returning visitor is not counted twice within the uniqueness window (24 hours by default). It carries no personal data and is not used for advertising.

How long we keep things

  • Individual click events: 180 days, then deleted.
  • Aggregated daily and hourly statistics: up to 365 days, subject to the account's plan.
  • Stored IP addresses, where enabled: anonymised after 30 days.
  • Sign-in history: 180 days. API request logs: 90 days. Security audit logs: 365 days. Resolved abuse reports: 365 days.
  • Account data: for as long as the account is open. When you delete your account it is recoverable for 30 days, then permanently erased along with its links and analytics.

A scheduled cleanup job enforces these windows automatically; it is not a manual process.

Who we share data with

We do not sell personal data and we do not share it for advertising. We share only with the service providers needed to run the Service — our hosting provider, our email provider, and, where configured, an IP-geolocation provider that resolves an approximate location. We may disclose data where legally required, or where necessary to investigate abuse of the Service.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Account holders can view and edit their profile in the dashboard and export their analytics as CSV. For anything else, contact us and we will respond within the period required by applicable law.

Region-specific detail is set out on our GDPR page (for the EU/UK) and our DPDPA page (for India), including how to reach our Grievance Officer.

Security

Passwords are hashed, sessions are regenerated on login, forms are CSRF-protected, sensitive endpoints are rate-limited, and administrative actions are audit-logged. No system is perfectly secure, but we design for least exposure — which is why raw IPs are off by default.

Contact

Privacy questions or requests: support@whizzact.com.