Privacy Policy

Last updated: 21 September 2026

This policy explains how tinyurls.online (“we”, “us”) handles personal data when you use our URL shortening service. We have tried to keep it short and honest: we collect very little.

1. Who is responsible

The controller of your personal data is DIGITALSERVICESONLINE, abu sinan village- moaweya st. 1- israel. For any privacy question or request, email contact@tinyurls.online.

2. What we collect and why

DataPurposeLegal basis (GDPR)Kept for
Links you shorten: the destination URL, the short code, a title if you add one. Anonymous links are not tied to any person.Provide the redirect service.Contract / legitimate interests (Art. 6(1)(b), (f))Until the link is deleted or removed for abuse. Links of a deleted account are deleted with it.
Click counters: number of clicks per link and per day. No IP address, browser details or cookies are stored in these statistics.Show statistics to the account owner.Contract / legitimate interestsAs long as the link exists.
Account data (optional): email address, password (stored only as a salted hash), dates of sign-up and last login, when you accepted the Terms.Create and secure your account; let you keep and manage your links; send a password-reset email if you ask for one.Contract (Art. 6(1)(b)); legal obligation for records of acceptanceUntil you delete your account.
Abuse-prevention data: a keyed one-way hash of your IP address and a counter, used to limit how many links can be created per hour and how often logins are attempted.Prevent spam, automated abuse and password guessing.Legitimate interests (Art. 6(1)(f)): keeping the service safe and availableDeleted automatically within about 24 hours.
Abuse reports: the reported URL, your description and, if you provide it, your email.Investigate and act on reports.Legitimate interests; legal obligationOpen reports until resolved, then up to 12 months.
Messages you send us by email.Reply to you and keep a record.Legitimate interestsAs long as needed to handle the matter.
Server logs kept by our hosting provider: IP address, requested address, browser type and time of each request.Security, fault-finding and abuse investigation.Legitimate interestsSet by the hosting provider, for a limited period.
Cookies: see the Cookie Policy.Login, security, remembering your choices.Necessary cookies: legitimate interests; optional cookies: consent (Art. 6(1)(a))See Cookie Policy.

We do not ask for your name, phone number, address or payment details. We do not make decisions about you by automated means that have legal or similarly significant effects. We do not sell personal data.

3. Analytics and advertising

We do not currently use analytics or advertising cookies. If that changes, we will update this policy and ask for your consent before any optional cookies are set.

4. Who we share data with

  • Hosting provider. Our website and database run on servers of our hosting provider (Hostinger), which processes data on our behalf under its data processing terms. Password-reset emails are sent through the hosting provider's mail system.
  • Authorities, when we are legally required to disclose data, or to protect the rights and safety of users and the public.

Destination websites receive normal browser information when a visitor is redirected to them. We do not control those websites and are not responsible for their privacy practices.

5. International transfers

Our hosting provider and Google operate in several countries. Where personal data is transferred outside the European Economic Area, the United Kingdom or Israel, we rely on adequacy decisions or Standard Contractual Clauses, or on the provider's equivalent safeguards.

6. Your rights

Depending on where you live (for example under the EU/UK GDPR, the California CCPA/CPRA and other US state laws, or the Israeli Privacy Protection Law), you may have the right to:

  • access your personal data and receive a copy (you can download it yourself from your Account page);
  • correct inaccurate data;
  • delete your data (use “Delete account” in your Account page; it takes effect immediately);
  • restrict or object to processing based on legitimate interests;
  • data portability (the download is a machine-readable JSON file);
  • withdraw consent at any time, without affecting earlier processing (use “Cookie settings” in the footer);
  • not be discriminated against for exercising privacy rights;
  • complain to a regulator: in the EU, your national data protection authority; in the UK, the ICO; in Israel, the Privacy Protection Authority; in California, the California Privacy Protection Agency.

To use a right that is not available in your account, email contact@tinyurls.online. We may need to confirm your identity. We answer within 30 days (45 days under the CCPA), and tell you if we need more time.

7. California and other US state residents

In the last 12 months we have collected these categories of personal information: identifiers (email address, hashed IP for rate limiting), internet activity (link click counts, which are not linked to an individual), and account information. We collect them to run the service, as described above. We do not sell personal information. We do not knowingly collect personal information from anyone under 16.

8. Children

The service is not directed to children, and accounts require you to be at least 16. If you believe a child has given us personal data, contact contact@tinyurls.online and we will delete it.

9. Security

We use HTTPS, store passwords only as salted hashes, use parameterised database queries, limit login and creation attempts, and restrict administrator access. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authorities as the law requires.

10. Changes to this policy

We will post any changes on this page with a new “last updated” date. For material changes we will also notify account holders by email or a notice on the site before they take effect.

11. Contact

DIGITALSERVICESONLINE · contact@tinyurls.online · see also our contact page.