Back to Home
Legal & Compliance

Privacy Policy

This Privacy Notice for TrimLynk ("we," "us," or "our") describes how and why we might collect, store, use, and share your personal information when you use our shortener, QR builder, and bio link platform.

Last updated: September 18, 2026
Summary of Key Points

This summary provides key points from our Privacy Notice. Reading this notice will help you understand your privacy rights and choices.

  • What personal information do we process? When you visit, use, or navigate our Services, we process personal information depending on how you interact with us (e.g. account email, shortened destination URLs, anonymous telemetry).
  • Do we process sensitive personal information? No sensitive personal information (such as racial or ethnic origins, sexual orientation, or biometric data) is collected. We strictly process account credentials necessary for authentication.
  • Third-party disclosures: We do not sell personal data. We disclose telemetry only to vetted infrastructure sub-processors (e.g., cloud database, edge CDN, security scanners).
  • How do we keep your information safe? We maintain robust organizational and technical controls including TLS 1.3 transit encryption and AES-256-GCM / bcrypt stored token hashing.
  • How do you exercise your rights? You can review, export, or delete your data at any time via your Privacy Center or account Settings.

1. What Information Do We Collect?

Personal information you disclose to us

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products, participate in activities on the Services, or contact us directly.

The personal information we collect may include:

  • Full name or display name
  • Email address
  • Billing address (for subscription plans)
  • Account passwords (stored exclusively as one-way salted hashes)

Payment Data

We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and security code. All payment data is handled, tokenized, and stored by Stripe. You may view their privacy policy at stripe.com/in/privacy .

Social Media Login Data

We provide you with the option to register and sign in using your existing Google or GitHub account details. Where you choose to do this, we receive basic profile info (name, email address, avatar) strictly needed to identify your session.

Application Data & Push Notifications

If you use our web applications or progressive web app (PWA), we may request permission to send you Web Push notifications regarding link milestones or security alerts. You may revoke push notification permissions at any time in your device or browser settings.

Information automatically collected

When you access or click short links on TrimLynk, our edge network automatically collects diagnostic and routing telemetry:

  • Log and Usage Data: Redirection timestamps, referring URLs, operating system, and browser user-agent strings.
  • Device Data: Hardware platform and browser characteristics.
  • Location Data: Imprecise, aggregate geolocation (country and city derived via Cloudflare IP headers). We do NOT store persistent raw personal IP addresses in our analytics database.

Google API Compliance

Our use of information received from Google APIs adheres strictly to the Google API Services User Data Policy , including the Limited Use requirements.

2. How Do We Process Your Information?

We process your information to provide, improve, and administer our Services, communicate with you, ensure security and fraud prevention, and comply with law:

  • Facilitate account creation and authentication: To authenticate your logins and maintain your workspace settings.
  • Deliver high-speed short link routing: To execute sub-25ms redirection lookups and conditional geo/device routing.
  • Generate aggregate click analytics: To provide creators and businesses with traffic trends, referrers, and device distributions.
  • Threat prevention: Real-time heuristic scanning of destination URLs against malware, phishing, and scam directories (Google Safe Browsing).
  • Save or protect an individual's vital interest: When necessary to prevent imminent harm or illegal acts.

3. What Legal Bases Do We Rely On?

Under the General Data Protection Regulation (GDPR) and UK GDPR, we only process your personal information when we have a valid legal basis:

  • Consent: Where you have given explicit permission for a specific purpose (e.g. newsletter subscriptions or optional cookies). You can withdraw consent at any time.
  • Contractual Necessity: To provide you with short link routing, QR services, and account features per our Terms of Service.
  • Legal Obligations: To cooperate with lawful requests from law enforcement bodies or regulatory agencies.
  • Vital Interests: Where necessary to mitigate potential safety threats or fraud attacks.
  • Legitimate Interests: To prevent abuse of our link network, optimize edge performance, and safeguard infrastructure.

For users located in Canada, we process personal information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) under express or implied consent and applicable statutory provisions.

4. When and With Whom Do We Share Your Personal Information?

We may share information during business transfers (e.g., mergers, financing, or asset acquisitions). Furthermore, we partner with vetted third-party sub-processors who adhere to stringent confidentiality and data protection standards:

Sub-ProcessorRole & FunctionLocation
Netlify Inc.Frontend application hosting, global CDN, and edge routingUSA / Global Edge
Render Services Inc.Production backend API server hostingUSA
Aiven Ltd.Managed PostgreSQL database and Valkey in-memory cacheFinland / Global Cloud
Upstash Inc.Serverless edge Redis cache for sub-25ms global redirection lookupsUSA / Global Edge
Google LLC (Safe Browsing)Real-time URL malware, phishing, and abuse threat inspectionUSA
Google LLC (OAuth 2.0)Optional social single sign-on authenticationUSA
GitHub Inc. / MicrosoftOptional developer single sign-on authenticationUSA
Resend Inc.Transactional system email delivery (verification, password resets)USA
Stripe Inc.Payment processing and subscription billingUSA / Global
Google LLC (Analytics 4)Aggregated web traffic measurement and telemetryUSA
Google Cloud AIAI alias generation and link categorizationUSA

5. Cookies and Tracking Technologies

We use cookies and similar technologies (such as local storage tokens) to maintain the security of your session, preserve workspace preferences, and ensure responsive site operation.

Google Analytics: We use Google Analytics 4 to evaluate aggregated platform usage. You can opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on .

Advertising Disclosures: TrimLynk is currently ad-free. If third-party advertising is enabled in the future, you may manage personalized advertising preferences via Google Ads Settings or aboutads.info .

6. Artificial Intelligence-Based Products

As part of our Services, we offer features powered by artificial intelligence and machine learning technologies, such as our AI short-link alias generator and link categorization tools.

We provide AI products through vetted enterprise service providers, including Google Cloud AI. All data processed using our AI features is transmitted securely and is never used to train third-party public foundation models without your express authorization.

7. How Do We Handle Your Social Logins?

When you choose to register or log in using third-party social credentials (Google or GitHub), we only request access to basic profile identity: your public username, verified email address, and profile picture.

We do not request access to your private GitHub code repositories or Google Drive data, nor do we ever post or publish on your behalf.

8. How Long Do We Keep Your Information?

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Notice, unless a longer retention period is required by law.

  • Redirection Event Telemetry: Raw individual click event logs (timestamp, referrer, device type, approximate geo) for non-registered short links are automatically purged after thirty (30) days.
  • Workspace Records: Aggregated link statistics and custom alias records are retained while your account remains active.
  • Account Deletion: Upon your request to delete your account via Settings, all associated links, analytics rows, and assets are permanently purged from active databases within 30 days.

9. How Do We Keep Your Information Safe?

We have implemented extensive technical and organizational security safeguards designed to protect personal data:

  • Full TLS 1.3 encryption across all client-to-server and inter-service communications.
  • Password hashes stored using salted bcrypt algorithms; sensitive credentials stored with AES-256-GCM encryption.
  • Automated bot and DDoS mitigation filters at the edge.
  • Role-Based Access Control (RBAC) preventing unauthorized tenant cross-contamination.

10. Do We Collect Information From Minors?

We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 years old or the legal age of majority in your jurisdiction.

11. What Are Your Privacy Rights?

Depending on your geographic location (such as the EEA, UK, Switzerland, and Canada), you possess fundamental privacy rights:

  • Right of Access: Request a copy of personal information we maintain about you.
  • Right to Rectification: Request correction of inaccurate or incomplete records.
  • Right to Erasure: Request permanent deletion of your data ("Right to be Forgotten").
  • Right to Restrict Processing & Data Portability: Obtain an export of your link records in structured JSON format.
  • Right to Withdraw Consent: Withdraw previously granted consent at any time without affecting past lawful processing.

UK & EEA Supervisory Authorities

If you reside in the UK and are dissatisfied with our response, you may lodge a complaint with the UK Information Commissioner's Office (ICO):

Website: ico.org.uk/make-a-complaint

Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

12. Controls for Do-Not-Track & Global Privacy Control

Most browsers include a Do-Not-Track ("DNT") feature. Because there currently is no uniform standard for recognizing DNT signals, we do not respond to generic DNT signals at this time.

Global Privacy Control (GPC) Honored

We recognize and automatically honor Global Privacy Control (GPC) signals. If your browser transmits a GPC signal, we treat this as a valid opt-out request under applicable state laws including CCPA/CPRA. Learn more at globalprivacycontrol.org .

13. Do United States Residents Have Specific Privacy Rights?

If you reside in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, state laws afford you rights to know, access, correct, delete, and opt out of the sale or sharing of personal data.

Categories of Personal Information Collected (Past 12 Months)

CategoryExamplesCollected
A. IdentifiersReal name, alias, postal address, online identifier, IP address, email address, account nameYES
B. California Customer RecordsName, billing address, payment detailsYES
C. Protected ClassificationsRace, gender, age, ethnicityNO
D. Commercial InformationSubscription history, purchase recordsYES
E. Biometric InformationFingerprints, voiceprintsNO
F. Internet / Network ActivityReferring URLs, click timestamps, browser user agentYES
G. Geolocation DataApproximate country and city derived from edge headersYES
H. Audio / Visual InformationRecordings or sensory dataNO
I. Professional InformationJob history, resumesNO
J. Sensitive Personal InformationAccount login credentialsYES

California Shine the Light: California Civil Code Section 1798.83 permits California residents to request details regarding disclosure of personal data to third parties for direct marketing. TrimLynk does not disclose personal data for third-party marketing purposes.

14. Do Other Regions Have Specific Privacy Rights?

Australia and New Zealand

We process personal information under Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. If you believe we are unlawfully processing your personal data, you may submit a complaint to the OAIC or the NZ Privacy Commissioner .

Republic of South Africa

Under the Protection of Personal Information Act (POPIA), you may contact the Information Regulator (South Africa) at enquiries@inforegulator.org.za or submit complaints to POPIAComplaints@inforegulator.org.za.

15. Do We Make Updates To This Notice?

We may update this Privacy Notice from time to time. The revised version will be indicated by an updated "Last updated" date at the top of this page. If we make material modifications, we may notify you by displaying a prominent banner on the website or by sending an email notice.

16. How Can You Contact Us About This Notice?

If you have questions, feedback, or data privacy requests regarding this notice, please reach out to us:

TrimLynk

Nadiya Nagar

Indore, Madhya Pradesh 452011

India

Online Support: https://trimlynk.com/contact

17. How Can You Review, Update, or Delete Your Data?

Based on applicable data protection laws, you have the right to request access to the personal data we hold, correct inaccuracies, or permanently delete your records.

You can directly execute telemetry data exports and submit account deletion requests through our dedicated self-service portal: