Privacy Policy · v0.2-beta
Privacy Policy — 短.在线
Version: v0.2-beta
Last updated: 2026-09-16
Language: English is controlling. A Simplified Chinese courtesy translation is available; in case of conflict, English prevails.
This Privacy Policy explains how Arasaka Oy (“we,” “us,” “短.在线”) processes personal data when you use the 短.在线 smart-link / QR / analytics Service. It is written for GDPR (and UK GDPR where applicable) and includes PIPL-aware notes for when personal information of individuals in China is processed.
Related: Terms of Service · Acceptable Use Policy
1. Controller and contacts
Controller: Arasaka Oy (limited company / osakeyhtiö), Business ID 2138210-8, registered office Santaradantie 7 F 203, 01370 Vantaa, Finland.
| Topic | Contact |
|---|---|
| Privacy requests | privacy@短.在线 |
| Abuse / safety | abuse@短.在线 |
| DPO | Not appointed at this time; will be designated if legally required |
Contract vs privacy law:
- Contract governing law / venue for the Terms: Finland.
- Privacy law: As a Finnish controller, GDPR applies to our processing as an EU establishment. UK GDPR applies where UK law covers the processing. Finnish contract venue does not displace additional privacy regimes that apply by law.
- PIPL-aware notes apply when personal information of individuals in China is processed.
2. Scope
This Policy covers:
- Visitors and creators using anonymous shortening or accounts.
- Recipients who open ordinary short-link URLs or QR-tagged URL variants (visit events).
- Business contacts (support, billing).
It does not cover third-party destination websites you are redirected to — those have their own policies.
Hosting is operated on an EU/global control plane with a global redirect edge and Asia capacity (including HK/SG). We do not promise mainland China ICP hosting.
3. Categories of data we process
3.1 Account and billing
- Email, name (if provided), password hashes or SSO identifiers.
- Plan, Stripe customer/subscription identifiers, payment status (card data handled by Stripe; we do not store full PAN).
- Support correspondence.
3.2 Link metadata (creators)
- Destination URL, short code / alias, titles, tags, QR settings, custom domain bindings.
- Create-path decision / reason codes (e.g. allowed, verification required, quarantined).
- Whether a public analytics card is opted in.
3.3 Visit / click events (analytics + abuse)
Shown in typical Free creator analytics UI:
- Country (coarse geo)
- Device class
- Referrer host
- Source: QR-tagged URL traffic vs ordinary short-link traffic (see below)
QR-tagged vs ordinary short-link traffic. When we generate a QR code, it typically encodes a QR-tagged short URL (for example including ?s=qr). The plain copy/share URL stays untagged. Analytics may compare QR-tagged URL traffic with ordinary short-link traffic. That reflects which URL variant was requested; it does not prove that a physical camera performed a scan.
Creator UI never shows raw IP or precise street-level location.
Server-side fields used for abuse / rate-limit / reliability (short TTL — see §5):
| Field | Notes |
|---|---|
timestamp | Event time |
link_id / short_code | Which link |
ip_hmac | Keyed HMAC of IP (server secret; rotatable). Pseudonymous — still personal data if linkable |
geo_country | Country-level |
ua_family or truncated UA | Not full UA by default |
bot_class | Bot / human classification |
referrer_host | Host only |
destination_host | Host of target |
source (or equivalent) | QR-tagged URL vs ordinary short-link / API / unknown |
Create-path decision / reason | On create |
Optional / derive-and-drop (not retained long-term for abuse): full UA, geo_region, visitor_id / session_id (consent-gated if used), UTM parameters when needed for product analytics then aggregated or dropped per schedule.
We do not store for abuse purposes:
- Precise geo (lat/long / street)
- Full raw IP beyond the short window in §5
- Clipboard contents or destination-page form personal data scraped from targets
3.4 Technical and security
- IP address (raw, briefly), keyed
ip_hmac(HMAC with rotating server secret), security cookies for continuity / CSRF, verification tokens, risk signals. - Server logs necessary to operate and secure the Service.
3.5 Public analytics cards (opt-in)
If you opt in, we may publish aggregate counts only on a public card. Cards must not display emails or names. You control titles/aliases and must not put personal data on cards.
4. Purposes and legal bases (GDPR)
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Provide the Service | Create redirects, accounts, QR, dashboards | Art. 6(1)(b) contract; or 6(1)(f) legitimate interests for anonymous use |
| Abuse prevention & security | Rate limits, verification, quarantine, bot class, Safe Browsing lookup | Art. 6(1)(f) legitimate interests; legal obligation where applicable |
| Creator analytics | Country / device / referrer host / QR-tagged vs ordinary short-link aggregates | Art. 6(1)(b) or 6(1)(f); consent where required for optional IDs |
| Public analytics cards | Opt-in aggregate publication | Art. 6(1)(a) consent (creator opt-in) |
| Billing & accounting | Stripe, invoices, tax | Art. 6(1)(b) and 6(1)(c) |
| Product improvement | Aggregated metrics, experiments | Art. 6(1)(f); consent for non-essential cookies where required |
| Communications | Service notices; marketing only with consent or soft opt-in where allowed | Art. 6(1)(b)/(f)/(a) as applicable |
We do not sell identifiable clickstreams. We may use aggregated, non-identifying statistics for benchmarks or capacity planning.
5. Retention
| Data | Retention |
|---|---|
| Raw IP | Up to 7 days for rate-limit / abuse, then discarded or retained only as ip_hmac |
Keyed ip_hmac | Up to 90 days for abuse / appeals / analytics joins, unless a longer hold is required for an active investigation or legal hold. Secrets rotate on a comparable cadence; a short dual-key window may be used so joins still work across rotation |
| Visit event fields for abuse (table in §3.3) | Aligned with raw IP / ip_hmac windows above; then aggregate or delete |
| Account profile | Life of account + short wind-down after deletion request |
| Billing records | As required by tax/commercial law (often years) |
| Aggregate analytics | Longer retention of non-identifying aggregates |
| Support tickets | As needed to resolve, then limited archive |
Creator UI never displays raw IP regardless of server retention.
6. Sharing and subprocessors
We share personal data only as needed with:
| Category | Examples | Notes |
|---|---|---|
| Infrastructure hosting | Cloud hosts for control plane / edge | EU/global + Asia (HK/SG) posture; live names on the public subprocessor list |
| Payments | Stripe | Paid plans when offered |
| Threat lookups | Google Safe Browsing Lookup API | Destination safety |
Live subprocessors are listed in public/SUBPROCESSORS.md and on the product page /legal/subprocessors. Additional providers (for example payments or URL threat lookups) are added when those features go live.
We do not promise commercial third-party URL-intel products in this Policy.
Security measure (ops posture, not a user promise of complete scanning): if Google Safe Browsing (or equivalent) is unavailable, we may prefer review or quarantine for suspicious creates rather than fail-open.
A data processing agreement (DPA) for business customers on paid plans will be made available when offered. Request via privacy@短.在线.
We may disclose data to authorities when legally required, or to defend legal claims / prevent serious harm.
International transfers: where data leaves the EEA/UK, we use appropriate tools (e.g. SCCs, adequacy decisions) as applicable. Typical regions and vendors are listed on the public subprocessor page.
7. Cookies and similar technologies
We use:
- Strictly necessary cookies/tokens (session, CSRF, anonymous continuity for fair rate-limiting, security).
- Optional analytics or preference cookies only with consent where ePrivacy/GDPR require it.
A cookie notice will ship with the product if non-essential client trackers are used. Server-side visit logging for redirects is described in §3–5 and is not a browser “cookie” but may still involve personal data.
8. Your rights
GDPR / UK GDPR (where applicable)
Access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), and withdrawal of consent without affecting prior lawful processing. You may lodge a complaint with a supervisory authority.
PIPL-aware notes (when PI of individuals in China is processed)
Where China’s Personal Information Protection Law applies, we will provide notice of processing rules, process PI under a lawful basis recognized by PIPL (e.g. contract necessity, consent), obtain separate consent where required (e.g. certain sensitive PI or cross-border scenarios), and honor individual rights of access, copy, correction, and deletion as applicable. Cross-border transfers will follow the mechanism required at the relevant threshold (contractual clauses, certification, or security assessment). We do not rely on mainland ICP hosting for the Beta Service; processing of mainland users’ PI on offshore infrastructure will be assessed as volume and features grow.
To exercise rights: privacy@短.在线. We may need to verify identity.
9. Children
The Service is not directed at children under 16 (the typical EEA/UK age of digital consent). A lower age, not below 13, applies only where a Member State sets it and we have explicitly enabled that configuration. Where local law requires a higher age to form a contract (often 18), that higher age applies to accounts. We do not knowingly collect account data from children. Contact us to delete such data if discovered.
10. No sale of identifiable clickstreams
We do not sell or rent identifiable clickstreams or raw visit logs to data brokers. Aggregate, non-identifying metrics may be used internally or published as product insights without identifying visitors or creators beyond what a creator chooses to show on an opt-in public card.
11. Security (high level)
Encryption in transit (TLS), access controls, keyed HMAC of IP addresses after the raw-IP window (rotating server secret; not a claim of anonymization), adaptive rate limits, destination scanning integrations (including Google Safe Browsing), quarantine workflows, and least-privilege operational access. Abuse-monitored redirects are an operational posture — no security measure is perfect.
12. Changes
We will update this Policy’s version and date when it changes. Material changes will be notified reasonably (in-product or email to account holders) before taking effect, except where faster change is required for law or security.
13. Contact
- Privacy:
privacy@短.在线 - Abuse:
abuse@短.在线 - Controller: Arasaka Oy (Finnish limited company), Business ID 2138210-8, Santaradantie 7 F 203, 01370 Vantaa, Finland
Note: some mail clients need the ASCII/SMTP form abuse@xn--s7y.xn--3ds443g / privacy@xn--s7y.xn--3ds443g (same mailboxes).
Controller: Arasaka Oy · Law / venue: Finland
Privacy: privacy@短.在线 · Abuse: abuse@短.在线