Privacy Policy
Last updated: 5 October 2026
Who processes your data
Supreme Leader Private Limited is the controller for the data described here. Registered at 342, 2nd Floor, 14th B Cross Road, 6th Main, HSR Layout Sector 6, Bengaluru 560102. CIN: U62099KA2024PTC183352. GSTIN: 29ABMCS5017R1ZG. Privacy questions go to [email protected].
What We Collect
When someone clicks a shortened link, we collect minimal data to provide analytics:
- Browser type and version
- Operating system
- Device type
- Referring URL
- Country and city
- Hashed IP (keyed HMAC-SHA256)
The IP hash is keyed with a secret, not a plain digest. An unkeyed hash of an IPv4 address can be reversed by brute force in minutes, which would make the stored value obfuscation rather than pseudonymisation. It is used only to tell a repeat visitor from a new one.
What We Don't Do
-
Our database keeps IP addresses only as a salted hash. Our web server's security logs keep full IP addresses for up to 14 days.
-
We never run ad networks or sell data to brokers.
-
We never sell your data to anyone.
-
We never show ads or interstitials on your links.
Account Data
If you create an account, we store your email address for authentication. If you sign in with Google or GitHub, we receive your email address and basic profile from them and nothing else. You can delete your account and all associated data at any time by contacting us.
Payment data
We never see your card details.
Card numbers, expiry dates and security codes are entered on our payment provider's systems and never reach our servers or our database. We store only what we need to run the subscription: which plan you are on, the period it covers, the provider's subscription and payment identifiers, and the billing email.
We may also store a country and, where tax rules require it, a tax identifier, because we have to be able to show what tax was charged and why.
Who else touches your data
A short list, and each one is here because the product cannot work without it:
- Our hosting and database providers — they store the data described above.
- Our CDN and DNS provider — sees request metadata in transit, and supplies the country and city used for analytics.
- Our payment provider — handles card data and subscriptions for paid plans only.
- Zoho ZeptoMail — our email provider; delivers account and billing email.
- Google Web Risk — receives the destination URLs we check for phishing and malware, when a link is created or edited and when we re-check links people click.
- Cloudflare Turnstile — a bot check on the shorten form for visitors who are not signed in.
Our own servers also visit the destination of a new link, to follow its redirects and check where it really leads.
We do not sell data, and we do not share it for advertising. Providers are bound to process it only on our instructions.
How long we keep it
- Links — for as long as they exist, which is the point of the product.
- Click records — kept while the link exists, so historical analytics stay meaningful.
- QR generator — we keep a SHA-256 hash and the length of the text you turn into a QR code, never the text itself.
- Account data — until you delete the account.
- Billing records — for as long as tax and accounting law requires us to keep them, even after an account is closed.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to a particular use. Email [email protected] from the address on the account and we will respond within 30 days. Link and click data is exportable as CSV from the dashboard at any time without asking us.
Deleting your account removes your account data. It does not delete links you created, because other people may still be relying on them — tell us if you want specific links removed as well and we will remove them.
Cookies
Every cookie we set:
sessionid— keeps you signed in.csrftoken— protects form submissions.fu_dev— a random device id, set on the shorten form after the bot check passes. It counts how many links one device makes, for the fair-use limits. It lasts one year.
All three are strictly necessary.
We also use Google Analytics on the marketing
pages only: the home page, the QR generator, the blog and pages like this one.
It does not run on your dashboard, billing, checkout, sign-in pages or short-link
notices. It sets its own first-party cookies
(_ga, _gid).
If you visit from the EEA, the UK or Switzerland, analytics storage starts as
“denied”, so Google Analytics sets no cookies for you.
Those are analytics cookies rather than strictly necessary ones. They are not used
for advertising, remarketing or profiling — we do not run an ad network and
we do not sell data — and blocking them with any browser setting, extension
or Google's own opt-out breaks nothing.
Short links themselves carry no analytics cookie at all. A redirect is a redirect: your visitors are not cookied by us.
Where data is processed
Our providers operate globally, so data may be processed outside the country you are in. Where that happens we rely on the safeguards those providers offer for international transfers.
Grievance officer and customer care
Grievance officer: Kaushal Khodifad, Director, Supreme Leader Private Limited.
Email: [email protected]
- Complaints about a link or its content: we confirm we got it within 24 hours and resolve it within 15 days, as the Information Technology Rules, 2021 require.
- Customer complaints (billing, your account, the service): we confirm we got it within 48 hours and resolve it within one month.
Changes
Material changes are announced on this page with a new "last updated" date, and account holders are emailed. We will not quietly start collecting something new.