Shorten smart, Stay safe.

Privacy Policy

Last Updated: June 21, 2026Website: ylnk.cc

1. Overview and Scope

This Privacy Policy explains how yLnk collects, uses, shares, protects, transfers, and retains personal data when you use our URL shortener, QR code tools, LinkFolio pages, analytics, APIs, dashboards, public redirect pages, safety tools, and related services.

yLnk is built and operated from Bangladesh and made available globally. We use an EU-first approach: where EU/EEA, UK, or Swiss law gives stronger privacy rights, we aim to apply those standards unless another mandatory local rule requires a different approach.

2. Controller, Processor, and Customer Responsibilities

For account, billing, support, security, abuse prevention, product analytics, and service administration data, yLnk generally acts as the controller or business responsible for deciding how personal data is processed.

For visitor analytics, link destinations, QR scans, LinkFolio content, campaign metadata, and other data processed on behalf of a customer, yLnk may act as a processor or service provider. Customers remain responsible for giving their users required notices and obtaining consents for their own use of yLnk.

3. Personal Data We Collect

Data you provide

  • Account details such as name, email, password, organization, role, profile settings, and preferences.
  • Billing, invoice, subscription, tax, and payment-related data handled directly or through payment providers.
  • Content and configuration such as short links, QR codes, LinkFolio pages, landing pages, destination URLs, custom domains, DNS settings, tags, campaign parameters, uploaded assets, and notes.
  • Support messages, abuse reports, appeals, legal notices, feedback, and communications.

Data collected automatically

  • IP address, browser, device, operating system, language, approximate location, referrer, timestamps, and log data.
  • Clicks, scans, redirects, page views, destination visits, campaign parameters, link safety signals, error logs, and security events.
  • Cookies, local storage, session identifiers, and similar technologies used for authentication, preferences, analytics, advertising, security, and fraud prevention.

Data from third parties

  • Payment processors, authentication providers, hosting/CDN providers, analytics tools, advertising partners, fraud-prevention tools, support tools, and integrations.
  • Public sources and security intelligence used to detect phishing, malware, spam, fraud, or illegal content.

5. Cookies, Consent, Do Not Track, and Global Privacy Controls

We use cookies and similar technologies to operate yLnk, keep accounts secure, remember preferences, measure performance, and support advertising or analytics where permitted.

Where required, including in the EU/EEA and UK, we request consent before using non-essential cookies. You can manage cookies through browser settings and any consent controls we provide. Blocking some cookies may affect login, dashboard, payment, analytics, LinkFolio, or QR-code features.

  • Essential cookies: authentication, session security, fraud prevention, rate limiting, load balancing, CSRF protection, checkout security, and core service operation.
  • Functional cookies: preferences, language, theme, saved choices, recently used tools, and dashboard usability.
  • Analytics cookies: product usage, performance, error measurement, click analytics, QR scan analytics, aggregate reporting, and campaign performance measurement.
  • Marketing cookies: ad measurement, campaign attribution, remarketing, sponsored content, conversion measurement, and advertising frequency controls where enabled and legally permitted.
  • Do Not Track: because there is no consistent industry standard for DNT signals, we may not respond to browser DNT. Where legally required and technically feasible, we honor recognized opt-out preference signals such as Global Privacy Control for applicable processing.

6. Third-Party Sharing and Sub-Processors

We do not sell personal data. We share personal data only as needed to provide, secure, improve, fund, and legally operate yLnk. Depending on the feature, vendors and sub-processors may process account data, usage logs, billing metadata, support content, link metadata, analytics events, or security signals. Examples include:

  • Infrastructure, hosting, database, object storage, CDN, DNS, SSL certificate, email delivery, and uptime providers.
  • Analytics, product telemetry, log monitoring, crash reporting, A/B testing, and performance tools.
  • Payment processors, invoice tools, tax tools, fraud screening, subscription management, and accounting providers.
  • Email, notification, customer support, ticketing, and communication tools.
  • Advertising, consent, campaign attribution, and measurement providers where enabled.
  • Security, abuse detection, malware scanning, phishing detection, CAPTCHA, bot-prevention, sanctions screening, and threat-intelligence providers.
  • Professional advisers, regulators, courts, law enforcement, or third parties when required by law or necessary to protect rights, users, and service integrity.

7. Automated Decision-Making and Profiling

yLnk uses automated and semi-automated systems to detect spam, phishing, malware, suspicious redirects, abuse patterns, account takeover risks, bot traffic, sanctions or fraud signals, and unusual traffic. These systems may classify links, score risk, restrict redirects, show warning pages, require verification, throttle requests, block API calls, or trigger manual review.

We may also use profiling-like analytics to provide aggregate click reporting, approximate geolocation, device insights, campaign attribution, fraud prevention, product improvement, and abuse detection.

We do not use automated processing to make decisions with legal or similarly significant effects without appropriate safeguards and human review where required by law. You may appeal certain moderation or safety decisions through our appeal process.

8. International Transfers, SCCs, and Data Privacy Framework

Because yLnk is operated from Bangladesh and uses global infrastructure, personal data may be processed in countries other than your country of residence. These countries may have different data protection rules.

For EU/EEA, UK, and Swiss personal data transferred to countries without an adequacy decision, we use appropriate safeguards where required, including Standard Contractual Clauses, UK transfer mechanisms, processor agreements, security controls, and transfer risk assessments.

If a US-based vendor is certified under the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, or the Swiss-US Data Privacy Framework, we may rely on that certification where applicable. yLnk itself is not claiming DPF certification unless expressly listed on the official DPF list. If DPF is unavailable or not applicable, we rely on SCCs, contractual controls, vendor due diligence, and technical safeguards where required.

9. Retention and Security

We retain personal data only as long as needed for service delivery, account administration, legal obligations, audits, billing, dispute resolution, security, abuse prevention, backups, and legitimate business records.

We use technical and organizational measures such as encryption in transit, access controls, authentication, monitoring, logging, backups, least-privilege access, and abuse detection. No internet service is completely secure, so users should also protect credentials and enable strong authentication where available.

10. Your Privacy Rights

Depending on your location, you may have the right to access, confirm, correct, update, delete, restrict, object, withdraw consent, opt out of marketing, opt out of sale/share or targeted advertising, request portability, limit sensitive data use, and complain to a regulator.

EU/EEA, UK, and Swiss users have rights under GDPR-style laws including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.

US state residents, including California residents under CCPA/CPRA-style laws and residents of other states with similar privacy laws, may have rights to know, access, correct, delete, port, opt out of sale/share or targeted advertising, limit certain sensitive data uses, appeal denied requests, and receive non-discriminatory treatment. yLnk does not sell personal data.

To exercise rights, contact [email protected]. We may verify identity before fulfilling a request and will respond within the period required by applicable law.

11. Children, Third-Party Links, and Customer Content

The service is not intended for children under 13, or under 16 where GDPR or similar law requires a higher age. If we learn that we collected personal data from a child below the applicable age, we will delete it where required.

Short links, QR codes, LinkFolio pages, ads, integrations, and public content may lead to third-party websites. yLnk is not responsible for third-party privacy practices. Customers are responsible for the legality, notice, consent, and privacy compliance of content and destinations they create.

12. Account Deletion, Changes, and Contact

You can request account deletion from the account deletion page. Some data may be retained where required for legal, security, fraud-prevention, billing, backup, or dispute-resolution purposes.

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. For privacy questions, requests, complaints, or DPO-style inquiries, contact [email protected].

Resources and Related Pages

Legal review recommended: this policy is drafted for publication, but yLnk should obtain final review by a qualified EU data protection and technology lawyer before relying on it as formal compliance advice.