Privacy Policy

Effective date: [DATE]  ·  Operated by [LEGAL ENTITY NAME], [JURISDICTION]

1. Who this policy covers

This policy explains how Redirect Console ("the Service", operated by [LEGAL ENTITY NAME] of [ADDRESS], "we", "us") handles personal information in two roles:

2. What we collect

3. Cookies

The Service sets a single strictly-necessary session cookie after sign-in. We do not use advertising, analytics, or third-party tracking cookies.

4. Retention and anonymization

Click IP addresses are stored in truncated form — IPv4 addresses keep their first three octets (e.g. x.x.x.0) and IPv6 addresses are cut to their /48 network prefix — so full visitor addresses are not retained in click logs. Country-level statistics remain accurate at this granularity. Click data is retained for a default of 730 days and then automatically deleted. Sign-in attempt logs are deleted after 30 days; in-app billing events after 90 days. Closed accounts are deleted as described in §6.

5. Access and correction

Account holders can view and correct their name and email from My Profile at any time, and download a copy of their data ("Download my data"). You may also contact [PRIVACY CONTACT EMAIL] to exercise access, correction, or privacy-rights requests (including under PIPEDA, GDPR, or applicable state law), and we will respond within a reasonable period.

6. Deletion

Accounts that own no redirects or registered domains can be deleted self-service from My Profile. Otherwise — so that shared infrastructure and other users' data are not damaged — deletion is handled by support on request to [PRIVACY CONTACT EMAIL]. Deleting an account removes the account record, credentials, two-factor data, and API tokens; click history tied to deleted redirects is removed with them.

7. Sharing

We do not sell personal information. We share it only with: infrastructure providers who host the Service ([HOSTING PROVIDER(S)]), the payment processor, and the email delivery provider used for transactional messages — each solely to operate the Service, or when required by law.

8. Security

Credentials are stored hashed; administrative access requires two-factor authentication; traffic is served over HTTPS. No system is perfectly secure, and we make no guarantee of absolute security.

9. Your jurisdiction rights

Depending on where you live, you may have additional rights (access, deletion, correction, withdrawal of consent, complaint to a regulator — e.g. a Canadian privacy commissioner, a EU member-state supervisory authority, or a US state attorney general). Nothing in this policy limits those rights.

10. Changes

We may update this policy; material changes will be reflected by a new effective date above. Continued use after a change constitutes acceptance where permitted by law.

11. Contact

Privacy questions: [PRIVACY CONTACT EMAIL]. Abuse reports: abuse@urlpath.cloud.