Privacy Policy
Last updated: September 29, 2026
1. Introduction
Short10 is a product of DOTZ AGENCY LLC ("Company", "we", "us", "our"). The Company operates the https://short10.app website and service. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service. By using Short10, you consent to the data practices described in this policy.
2. Information We Collect
Account Information: When you sign in with Google, we receive your name, email address, and profile picture. We do not receive or store your Google password.
Link Data: URLs you shorten, titles, custom short codes, and configuration settings (UTM parameters, OpenGraph data, pixel IDs, deep link URLs).
Click Analytics: When someone clicks a short link, we collect: IP address (used for approximate geolocation and bot detection; anonymized for EU/EEA visitors on collection and scheduled for deletion within 24 hours), approximate location (country, region, city), User Agent (parsed for device, browser, and operating system), browser language, a non-reversible visitor hash used to count unique visits, referrer URL, UTM/campaign parameters, timestamp, and bot classification.
Conversion & Lead Data: If you enable conversion tracking or lead capture on your links, we store the information your visitors submit or that you send us on your behalf — which may include name, email address, and an external customer/order ID — so we can attribute conversions to your links. For this data you are the data controller and we act as your processor.
Payment Information: If you subscribe to a paid plan, payment is processed by our authorized third-party payment processor. We do not store your credit card number. We receive only transaction confirmations and subscription status. The payment processor may collect additional information as outlined in their own privacy policy.
3. How We Use Your Information
We use collected information to: (a) provide and maintain the Service; (b) generate click analytics and reports; (c) detect and filter bot traffic; (d) enforce usage limits per subscription plan; (e) send service-related notifications; (f) improve the Service. We do NOT: sell your data to third parties, use your data for advertising, or share individual click data with other users.
4. Data Retention
• IP addresses: 24 hours (used only for country detection, then permanently deleted)
• Click analytics: 90 days (free plan) / 2 years (paid plans)
• Account data: Until you delete your account
• Billing records: 7 years (legal requirement)
• Server logs: 30 days
5. Cookies & Tracking
We use a session cookie (short10_session) to maintain your login state — HttpOnly, Secure, SameSite=Lax — and a preference cookie (s10_mc) that only records whether you accepted or declined optional cookies. Analytics or marketing pixels on our own marketing pages (for example Google Analytics, Meta or TikTok) are loaded only after you click Accept in the cookie banner; declining keeps the site fully usable. Retargeting pixels on short links are only fired when configured by YOU on YOUR links — we do not add tracking to links by default.
6. Third-Party Services
• Google OAuth: Authentication only. We receive name, email, and avatar.
• ipapi.co and ip2c.org: IP geolocation (country detection) when our local database has no answer. Only the visitor IP address is sent, capped at a small number of lookups per minute; no other data. Visitor IPs are not stored in analytics for EU/EEA visitors and are blanked from all raw click records on the retention schedule described above.
• Payment Processor: We use a third-party payment processor to handle billing and transactions. Your payment details are handled securely by the processor and are subject to their own privacy policy.
• Bluehost: Hosting provider. Subject to their privacy policy.
7. Data Security
We implement industry-standard security measures including: encrypted connections (HTTPS/TLS), prepared SQL statements (preventing injection), CSRF protection on all forms, password hashing (bcrypt), session hardening, rate limiting, and input sanitization. While we strive to protect your data, no method of transmission over the Internet is 100% secure.
8. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the right to: (a) Access — request a copy of your data; (b) Rectification — correct inaccurate data; (c) Erasure — delete your account and data; (d) Portability — export your data in JSON/CSV format; (e) Object — object to processing based on legitimate interests; (f) Restrict — restrict processing of your data. To exercise these rights, email [email protected] with subject line "GDPR Request".
9. California Privacy Rights (CCPA)
If you are a California resident, you have the right to: know what personal information we collect, request deletion of your data, and opt-out of the sale of personal information. We do NOT sell personal information. To exercise your rights, email [email protected].
10. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us immediately.
11. International Data Transfers
Your data may be processed in the United States. By using the Service, you consent to this transfer. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service. Your continued use after changes constitutes acceptance. We encourage you to review this page periodically.
13. Contact Us
For questions or concerns about this Privacy Policy, contact DOTZ AGENCY LLC at: [email protected]