Privacy Policy & Compliance

Compliance statement under GDPR (EU 2016/679), POPIA (South Africa Act 4 of 2013), and CCPA/CPRA.

1. Privacy-First Commitment & Scope

sitelinks ("we", "our", "us") is dedicated to uncompromising privacy and data minimization. This policy explains how we process personal information in strict compliance with the EU General Data Protection Regulation (GDPR), the South African Protection of Personal Information Act (POPIA), and the California Consumer Privacy Act (CCPA/CPRA).

2. Responsible Party & Information Officer (POPIA Sec. 55 / GDPR Art. 37)

The responsible party for data processing is sitelinks. For privacy inquiries or to exercise your statutory data subject rights:

3. Lawful Bases for Processing (GDPR Art. 6 / POPIA Sec. 11)

  • Performance of Contract (GDPR Art. 6(1)(b) / POPIA Sec. 11(1)(b)): To manage user accounts, authenticate sessions, process link redirects, and fulfill your subscription.
  • Legitimate Interests (GDPR Art. 6(1)(f) / POPIA Sec. 11(1)(f)): To compute aggregated traffic analytics, protect platform infrastructure against fraud/abuse, and ensure security.
  • Compliance with Legal Obligations: To comply with statutory financial recordkeeping and lawful orders.

4. Data We Collect & Process

  • Account Data: Email address, cryptographically salted and hashed password, optional account name, and payment token references. We never store payment card numbers.
  • Short Link Redirect Data (Zero Tracking Cookies / Zero IP Storage): When visitors click a link, our edge servers extract non-identifying telemetry (country, city, device category, sanitized referrer). We do NOT store IP addresses. We do NOT use tracking cookies or advertising pixels.

5. ePrivacy Directive & Zero-Cookie Architecture

Under Article 5(3) of the EU ePrivacy Directive (2002/58/EC) and GDPR Recital 30, cookie banners are required only when non-essential tracking cookies are placed on user devices. Because sitelinks drops zero tracking cookies on link visitors and uses only strictly necessary functional session cookies for authenticated dashboard users, no invasive cookie consent banner is required.

6. Data Subject Rights (GDPR Articles 15–22 & POPIA Sections 23–25)

You have full statutory control over your personal data:

  • Right to Access & Data Portability (GDPR Art. 15, 20 / POPIA Sec. 23): You can export an instant machine-readable JSON copy of your entire account, links, and click totals at /dashboard/account.
  • Right to Rectification & Correction (GDPR Art. 16 / POPIA Sec. 24): You can update your profile, email, and preferences in your account settings.
  • Right to Erasure / "Right to be Forgotten" (GDPR Art. 17 / POPIA Sec. 24): You can permanently erase your account, all short links, click records, and audit logs at /dashboard/account.
  • Right to Object & Restrict Processing (GDPR Art. 18, 21 / POPIA Sec. 11(3)): You may object to specific processing activities by contacting our Information Officer.

7. Data Retention & Destruction Policy

Click metrics are retained during your active subscription. Deleting a short link immediately purges all associated click records from our database and invalidates cached entries in edge KV. Account erasure immediately wipes all user records and authentication sessions.

8. International Data Transfers & Safeguards

All data is transmitted via TLS 1.3 encryption and stored in secure, hardened database clusters. International transfers adhere to Standard Contractual Clauses (SCCs) and POPIA Section 72 cross-border data transfer safeguards.

9. Supervisory Authority Complaints

If you believe your data has been handled in violation of applicable privacy laws, you have the right to lodge a complaint:

  • South Africa: Information Regulator (South Africa) — inforegulator.org.za
  • European Union: Your national Data Protection Authority (DPA) under GDPR Art. 77.