Privacy Policy

Updated at: 2026-09-07.

Privacy Policy

Effective Date: September 7, 2026

Last Updated: September 7, 2026

This Privacy Policy governs the processing of personal data collected through our URL shortening, link management, and QR code infrastructure services operating under the domains href.lt and href.lv ("Service", "we", "us", or "our"). We are committed to processing your personal data strictly in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable European and national data protection laws.

1. Data Controller

The entity responsible for the collection and processing of your personal data under this Privacy Policy is the operator of the Service. For any questions, data subject requests, or privacy-related concerns, you may reach our Data Protection Officer / Privacy Contact directly at: hello@href.lt.

2. Categories of Data Collected and Processing Purposes

We collect and process personal data exclusively for specified, explicit, and legitimate purposes under the legal bases defined by Article 6 of the GDPR.

A. Account Registration and Management

  • Standard Registration: When you register directly, we collect your email address, chosen password (cryptographically hashed using industry standards), and account timestamps (Art. 6(1)(b) GDPR - contract performance).
  • Google Social Login: If you choose to authenticate via Google OAuth, we request and process only two minimal scopes:
    • .../auth/userinfo.email: To uniquely identify your account and verify your email address.
    • .../auth/userinfo.profile: To obtain your public name and display avatar for dashboard personalization.
    We do not request, access, or store any additional Google account data, contacts, drive contents, or credentials. Our use and transfer of information received from Google APIs to any other app adhere to the Google API Services User Data Policy, including the Limited Use requirements (Art. 6(1)(b) GDPR).

B. Service Operation, Redirection, and Telemetry

When an end user clicks a shortened link (href.lt/* or href.lv/*) or scans a dynamic QR code, our infrastructure processes technical logs to perform the redirection and generate aggregated analytics:

  • IP Address: Immediately truncated or hashed to determine coarse geographical location (country and city level) before permanent operational storage. Raw individual IP addresses are retained only in temporary web server logs for up to 14 days strictly for DDoS defense, fraud detection, and abusive traffic filtering (Art. 6(1)(f) GDPR - legitimate interest).
  • Device and Client Metadata: User-Agent string, browser type, operating system, language headers, and HTTP referrer headers (Art. 6(1)(f) GDPR).
  • Destination URLs: URLs submitted for shortening are screened against automated threat lists (including Google Safe Browsing and local abuse registries) to prevent malware, phishing, and malicious distribution (Art. 6(1)(f) GDPR).

C. Billing and Subscription Processing

If you purchase a paid subscription, all payment processing is handled through PCI-DSS Level 1 certified third-party payment processors (such as Stripe). We do not store raw credit card numbers or banking credentials on our servers. We process billing identifiers, billing country, VAT/PVM numbers, and invoice transaction histories to fulfill our contractual obligations and satisfy statutory European accounting mandates (Art. 6(1)(b) and Art. 6(1)(c) GDPR).

3. Subprocessors and Third-Party Disclosures

We do not sell, rent, or trade your personal data. We disclose data solely to bound subprocessors operating under strict Data Processing Agreements (DPAs) compliant with Article 28 of the GDPR:

  • Hosting and Infrastructure: European virtual private server (VPS) and database infrastructure located within the European Economic Area (EEA).
  • Security and Network Delivery: Cloudflare (DNS, DDoS protection, edge caching, and Turnstile automated bot validation).
  • Transactional Email: SMTP gateways used strictly for transactional delivery (email confirmation, password resets).
  • Payment Gateways: Stripe, Inc. and its affiliated regional entities for compliant payment processing and EU VAT management.

4. International Data Transfers

Your primary data is hosted on servers located inside the European Union. In instances where operational subprocessors (such as Cloudflare or Google OAuth APIs) route telemetry outside the EEA, transfers rely on valid European Commission adequacy decisions or Standard Contractual Clauses (SCCs) pursuant to Article 46 of the GDPR, ensuring an equivalent standard of protection.

5. Data Retention

  • Active Accounts: Account data and associated shortened link records are retained for the duration of your active account lifecycle.
  • Account Deletion: Upon voluntary account termination, personal identifiers and customized short links are permanently removed or anonymized within 30 days, except where longer retention is mandated by financial, tax, or legal obligations.
  • Technical Logs: Server connection logs containing raw IP addresses are rotated and automatically deleted within 14 days.

6. Security Measures

We implement appropriate technical and organizational measures (TOMs) as required by Article 32 of the GDPR, including:

  • Enforced TLS 1.3 encryption across all incoming and outgoing connections.
  • One-way cryptographic hashing of account credentials using Argon2 or Bcrypt.
  • Network firewalls, automated rate limiting, bot mitigation, and continuous vulnerability patching.
  • Restricted operational access limited to authorized administrative personnel on a strict need-to-know basis.

7. Your Rights Under the GDPR

As a data subject within the European Union, you hold enforceable statutory rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): The right to obtain confirmation and copies of your processed personal data.
  • Right to Rectification (Art. 16 GDPR): The right to correct inaccurate or incomplete data directly via your dashboard or by request.
  • Right to Erasure ("Right to be Forgotten", Art. 17 GDPR): The right to obtain the complete deletion of your account and related records.
  • Right to Restriction of Processing (Art. 18 GDPR) & Right to Object (Art. 21 GDPR): The right to limit or oppose certain processing activities based on legitimate interests.
  • Right to Data Portability (Art. 20 GDPR): The right to receive your personal data in a structured, machine-readable format (JSON/CSV).
  • Right to Lodge a Complaint: You have the legal right to submit a formal complaint to your regional supervisory authority (such as the State Data Protection Inspectorate - VDAI in Lithuania, the Data State Inspectorate - DVI in Latvia, or the Spanish Data Protection Agency - AEPD).

To exercise any of these rights, email us directly at hello@href.lt. We respond to all verified requests within the statutory 30-day timeline without undue delay.

8. Updates to this Policy

We reserve the right to modify this Privacy Policy periodically to reflect technical, regulatory, or operational updates. Material amendments will be communicated via your account dashboard or notified directly to your verified email address prior to taking effect.