Privacy policy
Last updated: July 31, 2026
1. Who we are
short-code.io ("we", "us") is a URL shortening and QR code service. The controller for the processing described in this policy, within the meaning of Art. 4(7) GDPR, is the operator named in our imprint, where you will also find our postal address and email address. We are not required to designate a data protection officer (§ 38 BDSG). If you have any questions about this policy or your data, email [email protected] or use our contact form.
2. Data we collect
Account data
We do not use passwords, and we never store one. You sign in either with a one-time link we email to you, or with your Google account. For each account we store your email address, the time you last signed in, your chosen plan, and your account settings. We use this data to provide the service, to authenticate you, and to contact you about your account.
Links, QR codes, and domains
We store the short links you create, their destination URLs, custom names, reusable QR template settings, uploaded logos, and any custom domains you connect. This stored data is required to operate the service and is only visible to your account. Generated SVG and PNG files are produced on demand and are not retained.
Click analytics
When someone opens one of your short links or scans one of your QR codes, we record the link that was opened, the time of the click, and the country of origin. The country is derived from the visitor's IP address by our CDN provider, or from the browser's language settings as a fallback. We do not store IP addresses, precise locations, referrers, device or browser information, or any other data that identifies the individual visitor.
Payment data
Payments are processed by Stripe. Your card or bank details are transmitted directly to Stripe and never touch our servers. We only store the identifiers needed to associate your subscription with your account: the Stripe customer and subscription IDs, the subscription status, and the end of the current billing period. If you subscribe before creating an account, we receive your email address from Stripe in order to create one for you. See the Stripe privacy policy for details.
Contact requests
When you use our contact form, we process your email address, the selected subject, and your message. Your message is delivered to our mailbox by email and is not stored in the short-code.io database. To keep the form from being abused, it is protected by Cloudflare Turnstile: your IP address and technical characteristics of your browser are transmitted to Cloudflare for that check, and we additionally keep your IP address in our server's memory for 15 minutes as a rate-limiting key. It is not written to disk and not stored with your message.
Server logs
We do not keep web server access logs. Our application writes an error log for troubleshooting, which may incidentally contain data from a failed request; these logs are deleted after 14 days.
3. Legal bases
We process your data on the following legal bases under the GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR) — account data, sign-in, link and QR code data, and payment processing.
- Legitimate interest (Art. 6(1)(f) GDPR) — aggregated click analytics, abuse prevention on the contact form, error logging, and the security and stability of the service. Our interest lies in operating a functioning, non-abusable service; we have weighed this against your interests and use no data that identifies individual visitors.
- Contract, legal obligation, or legitimate interest (Art. 6(1)(b), (c), or (f) GDPR) — handling contact requests, depending on the nature of your request.
- Legal obligation (Art. 6(1)(c) GDPR) — retention of billing records under tax and commercial law.
We currently carry out no processing based on your consent. Should we ask for your consent in the future, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
4. Third-party processors
We share data only with service providers we need to operate short-code.io, each under a data processing agreement in accordance with Art. 28 GDPR:
- Stripe (Stripe Payments Europe, Ltd., Ireland) — payment processing and subscription management.
- Cloudflare (Cloudflare Germany GmbH / Cloudflare, Inc.) — content delivery, DDoS protection, country-level geolocation of clicks, and Turnstile abuse protection on the contact page.
- Amazon Simple Email Service (Amazon Web Services EMEA SARL, Luxembourg) — delivery of our emails, including sign-in links, account and billing notifications, and contact correspondence. We send from the Frankfurt region (eu-central-1), so the messages themselves are processed in Germany.
- Google (Google Ireland Limited) — only if you choose to sign in with your Google account. In that case Google confirms your identity and email address to us. We embed no Google fonts, analytics, or other Google content anywhere on this website or in the dashboard.
- Hetzner (Hetzner Online GmbH, Gunzenhausen) — hosting. Our servers are located in Germany.
We do not sell your data, and we do not share it with advertisers.
5. Transfers outside the EU
Stripe, Cloudflare, Amazon Web Services and Google are corporate groups with parent companies in the United States, so despite our contracts being with their European entities, personal data may be transferred to or accessed from the United States. Those transfers are covered by the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified under it, and otherwise by the EU standard contractual clauses (Art. 46(2)(c) GDPR) together with supplementary measures. You can request a copy of the safeguards we rely on by writing to [email protected]. Please note that despite these safeguards, US authorities may have access rights that fall short of the level of protection guaranteed in the EU.
6. Cookies and local storage
This website does not use tracking cookies, advertising cookies, or third-party analytics, and it stores nothing on your device.
Two exceptions apply elsewhere in the service. The dashboard stores an authentication token in your browser's local storage so you stay signed in; it is used solely for that purpose and for nothing else. On our contact page, Cloudflare Turnstile stores and reads information on your device in order to distinguish you from automated bots. Both are strictly necessary to provide the service you have expressly requested and are therefore permitted without your consent under § 25 Abs. 2 Nr. 2 TDDDG; the associated processing of personal data is based on Art. 6(1)(b) and Art. 6(1)(f) GDPR respectively. You can remove the authentication token at any time by signing out or clearing your browser storage.
7. Data retention
We keep your data for as long as your account exists. When you delete your account, your account data, links, reusable QR template settings, uploaded logos, and click history are deleted immediately, and any active subscription is cancelled. Expired links and their associated click history are deleted automatically. Error logs are deleted after 14 days. Contact correspondence is kept only as long as needed to answer and handle the request. Invoices and other billing records are retained for as long as tax and commercial law requires — generally ten years under § 147 AO and § 257 HGB — and are during that period only processed to comply with those obligations.
8. Your rights
Under the GDPR you have the right to obtain information about the data we hold about you (Art. 15), to have inaccurate data corrected (Art. 16), to have your data erased (Art. 17), to have processing restricted (Art. 18), and to receive the data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller (Art. 20). Where we process data on the basis of consent, you may withdraw that consent at any time with effect for the future (Art. 7(3)). To exercise any of these rights, email [email protected] or use our contact form.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your residence, place of work, or the place of the alleged infringement. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.
9. Your right to object
Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to that processing at any time, on grounds relating to your particular situation. This applies in particular to our click analytics, our abuse prevention, and our error logging. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims (Art. 21(1) GDPR).
If we were ever to process your data for direct marketing purposes, you would have the right to object to that at any time, without giving reasons; we would then stop the processing for those purposes entirely (Art. 21(2) and (3) GDPR).
An objection is free of charge and can be sent informally to [email protected].
10. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
11. Do you have to provide your data?
Providing your email address is necessary to create an account and to conclude a contract with us — without it we cannot sign you in or provide the service. Providing payment data is necessary for a paid plan. There is no statutory obligation to provide any of this data, and there is no obligation to use short-code.io at all.
12. If you clicked a short link
If you arrived here after opening a short link or scanning a QR code created by one of our users: we recorded only the link, the time, and your country of origin — nothing that identifies you, and no cookies or other information were stored on your device. The destination you were redirected to is operated by the user who created the link, not by us, and its own privacy policy applies there.
13. Changes to this policy
We may update this policy as the service evolves. The date at the top reflects the latest revision. If changes are significant, we will notify account holders by email.