Legal · Privacy
Privacy Policy
The short version
4ul.ink processes the information needed to operate accounts, links, security controls and privacy-conscious analytics. Application analytics use rotating pseudonymous visitor hashes rather than storing a visitor’s raw IP address. Raw IP addresses can still appear for about 14 days in restricted server security logs. We do not sell personal information or use it for our own cross-context behavioral advertising.
- Essential session, language and theme storage keeps the service working; optional third-party tracking is not required.
- Link owners can configure a Meta image event, but it loads only after the visitor chooses to allow it for that visit.
- You can request access, correction, deletion or portability by writing to info@4ul.ink.
- Destination websites and integrations selected by an account holder have their own privacy practices.
Controller details
Who is responsible for this notice
- Controller / operator
- 4ul.ink
- Privacy contact
- info@4ul.ink
1. Scope, roles and responsibility
This Policy applies to the 4ul.ink website, accounts, short-link redirects, QR codes, bio pages, campaigns, custom domains, APIs and related support and safety processes. It explains what we process, why, how long we keep it and the choices available to you.
For account and platform administration, the operator shown above is the controller. When an account holder collects visitor data through a link, conversion endpoint, pixel or webhook, that account holder may be a separate controller and 4ul.ink may process limited data on its behalf. The account holder must provide any additional notice and obtain any consent required by law.
A destination website, payment page or third-party integration is governed by its own policy. This Policy does not control what those independent services do after you interact with them.
2. Information we process
The categories depend on whether you are an account holder, a link visitor, a person reporting abuse or a person communicating with us.
- Account and identity data: name, email address, account role and status, email-verification state, password hash, authentication version and timestamps.
- Security data: encrypted TOTP secrets, hashed recovery codes, hashed reset or verification tokens, API-token hashes and prefixes, authentication events, pseudonymous IP hashes and user-agent information.
- Content and configuration: destination URLs, aliases, titles, folders, tags, campaign and bio-page content, avatar URLs, custom domains, targeting rules, A/B variants, UTM/custom parameters, expiration, click limits and password hashes.
- Link and conversion analytics: time of click, daily rotating visitor hash, device class, country code when a trusted signal is available, referrer hostname, user agent, matched rule or variant, click-token hash, event type, external event ID, amount and currency when supplied.
- Communications and safety: support messages, abuse-report reason and details, reporter hash, moderation status, blocked-domain entries and limited audit metadata.
- Integration and billing data: webhook URLs, encrypted signing secrets, delivery payloads and results; provider customer, subscription, transaction and event identifiers; bank-transfer payer name, reference and note if those optional features are enabled.
3. Where information comes from
- Directly from you when you register, configure content, contact us, submit a report or request a payment review.
- Automatically from your browser or device when you use the site or follow a short link.
- From an account holder that creates a link, sends a conversion event or configures a domain, pixel or webhook.
- From security, DNS, certificate, email and payment providers when they return verification, delivery, fraud-prevention or transaction status.
- From public DNS and network information used to validate destinations and protect against phishing, malware, private-network access and unsafe redirects.
4. Purposes and legal bases
Where GDPR or a similar law applies, we rely on the legal bases below. The applicable basis depends on the feature and your relationship with us.
- Contract and pre-contract steps: create and secure your account; publish and redirect links; provide QR codes, pages, analytics, APIs, support, plan entitlements and requested billing features.
- Legitimate interests: keep the service reliable; prevent fraud, phishing, malware and abuse; enforce limits and terms; diagnose failures; understand aggregate feature use; protect users and defend legal claims. We balance these interests against individual rights.
- Consent: load a link owner’s optional Meta event, use non-essential verification or similar technology where consent is required, or send optional marketing communications. Consent can be refused or withdrawn without affecting essential service functions.
- Legal obligation: maintain records, respond to valid legal process, meet tax or accounting rules and handle lawful privacy or safety requests.
- Vital or public interests only in exceptional circumstances where processing is necessary to protect a person or respond to a serious threat.
5. Cookies and browser storage
4ul.ink keeps browser storage deliberately limited. Blocking essential storage can prevent sign-in or security features from working.
- novalink_session is a Secure, HttpOnly, SameSite=Lax session cookie. It supports authentication, CSRF protection and flash messages and normally expires when the browser session ends. Authenticated sessions also have idle and absolute time limits.
- novalink_locale stores the selected interface language for up to one year. It is not used for advertising.
- 4ulink-theme is local browser storage containing only the light, dark or system theme preference.
- Cloudflare Turnstile may process browser and connection signals on public forms only if the operator configures and enables it. Optional Meta tracking is handled separately and is not loaded before the visitor chooses it.
6. Link analytics and IP handling
To count clicks without placing a persistent analytics identifier on a visitor, the application combines the visitor IP, the UTC date and a secret key and immediately produces a one-way SHA-256 hash. The raw IP is not written to the click-analytics table. The hash rotates daily, is pseudonymous rather than guaranteed anonymous, and is used for aggregate statistics and abuse resistance.
The application can also record device class, a two-letter country code when a trusted infrastructure signal is configured, referrer hostname and the browser user-agent string. It does not intentionally collect a full referrer path. When conversion tracking is enabled, a random first-party click token can be added to the destination URL; only its keyed hash is stored by 4ul.ink.
Separately, the web server processes raw IP addresses, request time, path, status and user agent in restricted access and error logs for delivery, incident response and attack detection. Those logs are normally rotated for about 14 days. This is separate from product click analytics.
7. Pixels, webhooks and destination sites
An account holder may attach a validated Meta image event to a link. Before it loads, the transition page offers a clear choice to continue without optional tracking or allow it for that single visit. If allowed, the visitor’s browser contacts Meta directly; 4ul.ink does not receive Meta’s resulting profile or advertising data. Refusing the event does not block the destination.
An account holder may also configure an HTTPS webhook. Signed event payloads can include link and click identifiers, slug, variant, device, country, conversion type and values. The account holder chooses that recipient and is responsible for its legal basis, security and retention.
Following a link sends the visitor to a destination selected by the account holder. That destination will ordinarily see the visitor’s IP and browser data and may receive UTM, custom or conversion parameters in the URL. Review the destination’s notice before supplying information there.
8. Providers and other recipients
We disclose only the information reasonably needed to operate the relevant feature. Providers act under their own terms and, where applicable, data-protection commitments. The live list below adapts to the features configured on this installation.
IONOS
Hosting / infrastructure processorPurpose: Run the web server, database, storage, networking, backups and incident controls.
Data involved: Account content, link configuration, database records, encrypted secrets, server logs and network metadata.
When it applies: Always required to host the service.
Resend
Email delivery providerPurpose: Send verification, password-reset, security and transactional messages.
Data involved: Recipient email, sender, subject and message content plus delivery metadata.
When it applies: When the service sends email through Resend.
jsDelivr
Content-delivery networkPurpose: Deliver the QR-code library used to generate a QR image in the browser.
Data involved: IP address, request headers and browser/network metadata visible to the CDN.
When it applies: Only when a QR-code page loads the library.
Meta
Optional third-party measurement providerPurpose: Send the link owner’s selected PageView, ViewContent or Lead image event.
Data involved: IP address, user agent, request time, event and page/referrer context visible to Meta.
When it applies: Only after a visitor chooses to allow the optional event for that visit.
User-selected webhook providers
Recipient selected by the account holderPurpose: Deliver signed click or conversion events to the account holder’s system.
Data involved: Configured event payload such as link/click IDs, slug, variant, device, country, conversion and value.
When it applies: Only when an account holder enables an HTTPS webhook.
Domain, DNS and certificate services
Infrastructure and independent servicesPurpose: Verify domains, publish DNS and issue or renew HTTPS certificates.
Data involved: Hostname, DNS records, verification token, IP address and certificate-request metadata.
When it applies: Only when custom-domain features are used.
Destination websites
Independent recipient chosen by the link ownerPurpose: Open the page or resource requested through a short link, campaign, bio page or QR code.
Data involved: Visitor IP and browser data visible to the destination, plus URL parameters configured by the account holder.
When it applies: Whenever a visitor follows an outbound destination.
9. Payments and subscriptions
Billing is optional and may be disabled. If Stripe Checkout is enabled, payment-card details are entered directly on Stripe’s hosted page and do not pass through 4ul.ink. We retain provider customer, subscription, price, transaction and event identifiers, amounts, currency and status needed to grant entitlements, reconcile payments and handle support.
If bank transfer is enabled, we process the payer name, transfer reference, optional note, requested plan, amount and review result. Financial records may be retained longer where tax, accounting, chargeback or fraud-prevention law requires it.
10. Disclosure for safety, law and business changes
We may preserve or disclose information when reasonably necessary to comply with valid law or legal process; protect people, the service or the public from fraud, phishing, malware or other harm; investigate violations; establish or defend legal claims; or complete a merger, financing, acquisition or sale of assets with appropriate confidentiality safeguards. We scrutinize requests and disclose only what is reasonably necessary.
11. International data transfers
Providers and visitors may be located in countries different from the controller or account holder. Where a restricted international transfer requires safeguards, we use an available lawful mechanism such as an adequacy decision, contractual protections or another legally recognized basis. Local laws in a recipient country may differ from those where you live. Contact us for information about safeguards relevant to your request.
12. How long information is kept
We retain data only for the service, security and legal purposes described above. Defaults can be shortened by the operator, and deletion can be delayed where preservation is required by law, a dispute or a security investigation.
- Click-analytics rows: normally up to 180 days.
- Security audit events: normally up to 180 days.
- Raw web-server logs: normally about 14 days under the active rotation policy.
- Reviewed or dismissed abuse reports: normally 365 days; unresolved reports can be kept while necessary to investigate or protect the service.
- Delivered or permanently failed webhook delivery records: normally 90 days. Revoked API tokens are normally removed after 90 days.
- Expired account-action tokens are removed on a rolling schedule; used tokens may remain for up to 30 days and recently expired tokens for a short anti-abuse window.
- Account details and user content remain while the account or feature is active, then are deleted or de-identified after a verified closure or deletion request, subject to security, backup and legal exceptions.
- Transaction and accounting records remain for the period required by applicable tax, accounting, fraud and dispute rules. Backup copies disappear through the ordinary protected backup-rotation cycle.
13. Security measures
Measures include HTTPS, HttpOnly and SameSite session cookies, CSRF protection, prepared database queries, password hashing, encrypted TOTP and webhook secrets, keyed token hashes, scoped API tokens, two-factor authentication, rate limits, destination validation, phishing and malware controls, firewalling, restricted logs and security auditing. Provider secrets are kept in server configuration rather than shown in the administrator interface. No internet service is risk-free, so we cannot guarantee absolute security. Report a suspected security issue to info@4ul.ink.
14. Your privacy rights and choices
Depending on your location and subject to lawful exceptions, you may ask to access, correct, delete or receive a portable copy of personal data; restrict or object to processing; withdraw consent; and complain to your local data-protection authority. You can refuse an optional pixel on the transition page, change language or theme preferences in the interface, and disable account integrations from their settings.
- Send a request to info@4ul.ink from the email associated with your account when possible and describe the account, link or interaction concerned.
- We may request proportionate information to verify identity and authority. Authorized agents may be asked for proof of authorization.
- We will respond within the period required by applicable law and explain any lawful limitation or refusal. Exercising a right will not result in unlawful discrimination.
- Automated safety controls may reject or disable a destination that appears unsafe. You can request human review through the abuse or privacy contact.
15. California and other US state disclosures
If an applicable US state law covers your relationship with us, you may have rights to know or access categories and specific pieces of personal information, correct inaccuracies, delete information, obtain portability, and opt out of sale, sharing for cross-context behavioral advertising or certain profiling. You may also appeal a denied request where the law provides that right.
4ul.ink does not sell personal information for money and does not use personal information for its own cross-context behavioral advertising. A pixel configured by a link owner is optional and contacts Meta only after the visitor affirmatively allows it for that visit. Depending on the relationship, the link owner may be responsible for any additional “sale” or “sharing” notice and opt-out mechanism. We do not knowingly sell or share personal information of children under 16.
The categories handled during the preceding 12 months are described in sections 2 and 3; purposes are in section 4; recipients are in section 8; and retention is in section 12. We do not provide a lower quality of service because you exercise an applicable privacy right.
16. Children
The service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child supplied information to 4ul.ink, contact info@4ul.ink so we can investigate and delete it where appropriate. Account holders must not deliberately use the service to profile or target children in violation of law.
17. Changes to this Policy
We may update this Policy when features, providers, laws or practices change. The fixed effective date at the top identifies the current revision. Material changes will be highlighted in the service or communicated by another reasonable method before they take effect when law requires advance notice. Earlier versions may be requested from the privacy contact.
18. Contact, complaints and unresolved questions
For privacy requests, questions or complaints, contact info@4ul.ink and identify the account or link involved without sending passwords, recovery codes or API secrets. You may also complain directly to the data-protection or consumer-privacy authority that serves your place of residence. The controller details shown above apply to this installation.