Privacy policy
Last updated: July 25, 2026
Who this policy covers
This describes what uhm.co (operated by Halit Software Inc., a British Columbia, Canada corporation) collects, for what purpose, and for how long, across account creation, link creation, and clicking a link. It is written from how the product actually works rather than from a generic template, which is why some passages are unusually specific.
What we collect
Account data: the email address, handled by Supabase Auth for sign-in. Link data: shortened destinations, chosen slugs and titles, and QR code settings. Click data: for every redirect, the referring site, a parsed device, OS and browser (from the User-Agent), and, where configured, an approximate country and city. Raw IP addresses are neither collected nor stored; see the next section.
How we handle IP addresses
A visitor IP address is never written to the database in raw form. It is hashed with SHA-256 together with a salt that rotates daily, and that salt exists only in the cache layer (Valkey/Redis), never in the database, and only for about two days before it is discarded. Because the salt changes daily, the same visitor hashes differently from one day to the next, and no stored salt exists anywhere that would allow a hash to be reversed back to an address.
What we use it for
Operating the redirect and the analytics shown in the dashboard, enforcing plan usage limits, checking destinations for abuse before and after a link is created, processing payments, and responding to the legal and abuse-report requests described elsewhere on this page.
How long we keep it
Individual click detail is kept for as long as the plan allows: 30 days on the free plan, 12 months on Pro, 3 years on Business. It is intended to be purged automatically once that window passes. That automated purge is not running in every environment yet. Until it is, requests to remove older click detail sooner can be made through the legal requests page. Day-by-day totals are kept indefinitely once summarized, so historical charts do not lose data; only the per-click detail behind them ages out. Account and link data is kept for as long as the account exists.
Who else touches your data
A small number of infrastructure providers are used to run the service. None of them is permitted to use this data for its own purposes.
Supabase
The database and sign-in provider, hosted in the EU (Frankfurt, eu-central-1). Account, link and click data are held here.
Stripe
Processes payments once billing is live for a workspace. Stripe receives the email address and a reference to the workspace, together with any payment details provided to it directly. Card numbers are never seen or stored by uhm.co.
AWS SES
Sends transactional email such as usage-limit notices. It receives the recipient email address and the content of that specific message, nothing further.
Google Safe Browsing
Where configured, a destination URL being shortened is sent to Google's threat-matching service to confirm it is not known malware or phishing. This is not active in every environment. When it is off, links are marked unscanned rather than treated as unsafe.
MaxMind GeoLite2
Where configured, the approximate country and city for a click is looked up against a database file held by uhm.co. This is not a live call to MaxMind per click, and no click data is sent to MaxMind. This is not active in every environment.
Cookies
A small number of cookies are used to run the site. The cookie policy sets out what each one does.
Your rights
On plans that include raw export (Pro and above), a link’s click data can be exported as CSV at any time from the dashboard; other plans show the same totals in the dashboard itself. An account can be closed at any time from the dashboard account settings. Closing an account ends all sessions and blocks new link creation, while existing links keep redirecting exactly as they do now. To also have links and click data removed, or to access, correct, or object to the processing of personal data (rights that may apply under GDPR, KVKK, or an equivalent law depending on jurisdiction), use the legal requests page. Such requests are handled directly.
Where your data is held
The primary database is hosted in the EU. For visitors and customers in Turkey, this means personal data is transferred abroad. What KVKK requires for that transfer is under review with legal counsel, and this section will be updated once that is settled.
Changes to this policy
This policy may be updated as the product changes. The date at the top of this page is updated accordingly.
Questions
For a question about personal data, or to exercise a right described above, use the legal requests page.