Skip to content

Legal

Privacy policy

Last updated

Privacy is part of how Forkly is built, not an afterthought. We collect only what we need to run the service, we never sell personal data, and our link analytics works without cookies or stored IP addresses.

1.Who we are and what this covers

Forkly (“Forkly”, “we”, “us”) provides smart links, dynamic QR codes, custom domains and analytics. This policy explains how we handle personal data in two different roles:

  • Customers — people who create an account, join a workspace or contact us. For this data we act as the controller.
  • Visitors — people who open a link or scan a QR code created by one of our customers. For link analytics we act as a processor on behalf of the customer who owns the link.

2.Information we collect from customers

  • Account data: name, email address, a hashed password or the identifier of the sign-in provider you use, and optional two-factor authentication settings.
  • Workspace content: links, destinations, routing rules, tags, notes, QR designs, uploaded logos, domains, team members and API keys (we store only a hash of each key secret).
  • Billing data: plan, billing interval and invoice history. Card details are collected and stored by our payment processor, never by us.
  • Security data: active sessions, the approximate device and browser used to sign in, and an audit log of changes in your workspace.
  • Communications: messages you send through our contact form or by email, and abuse reports you submit.

3.Link analytics and visitors

We designed our analytics to be useful to customers while revealing as little as possible about individual visitors.

  • No cookies. Redirects and analytics do not set cookies, local storage or any other identifier on the visitor’s device.
  • No raw IP addresses stored. The IP address of a request is used transiently to derive an approximate location (country, region and city) and to protect the service from abuse. It is not written to our analytics database.
  • Daily-rotating salted hashes. To estimate unique visitors, we compute a one-way keyed hash of the date, IP address, user agent and workspace. Because the date is part of the input, the value changes every day and cannot be used to recognise someone across days or across workspaces.
  • Aggregated technical data. We record the time of the visit, device type, operating system, browser, preferred language, referring website, UTM parameters and which destination was used.
  • Bots are detected from the user agent and excluded from reports.

Customers can see this aggregated data only for their own links, and only for as long as their plan’s analytics history allows. Link passwords are verified server-side and are never shown to anyone.

4.Cookies on our website and dashboard

When you sign in to the dashboard we use strictly necessary first-party cookies to keep you signed in and to protect forms against cross-site request forgery. We may remember your theme preference in your browser. We do not use advertising or cross-site tracking cookies on our website or dashboard.

5.How we use information

  • To provide, operate and maintain the service, including routing links and generating reports.
  • To authenticate users, secure accounts and detect fraud, spam, phishing and malware.
  • To process payments and send transactional emails such as verification, invitations, receipts and security alerts.
  • To respond to support requests and abuse reports.
  • To comply with legal obligations and enforce our Terms of Service and Acceptable Use Policy.

7.Sharing and subprocessors

We do not sell personal data and we do not share it for advertising. We share data only with service providers that help us run Forkly, under contracts that require them to protect it:

  • Cloud infrastructure and hosting providers (compute, databases, storage and backups).
  • Content delivery and DNS providers.
  • Payment processing and invoicing providers.
  • Transactional email delivery providers.
  • Error monitoring and operational logging providers.
  • Security and malicious-URL screening services.

We may also disclose information if required by law, to protect the rights and safety of our users or the public, or as part of a merger or acquisition subject to this policy.

8.Data retention

  • Account and workspace data is kept while your account is active and deleted when you delete your account or workspace, subject to backups that expire on a rolling basis.
  • Link analytics is available for the history included in your plan (90 days on Free, 2 years on Pro, 3 years on Business) and removed after that.
  • Deleted link slugs are reserved for 30 days to prevent hijacking before being released.
  • Billing records are kept as long as required by tax and accounting law.
  • Security logs and abuse reports are kept for as long as needed to protect the service and meet legal obligations.

9.Your rights

Depending on where you live, including under the GDPR and UK GDPR, you have the right to:

  • access the personal data we hold about you and receive a copy in a portable format;
  • correct inaccurate data;
  • have your data deleted;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • withdraw consent at any time; and
  • lodge a complaint with your local data protection authority.

You can update your profile and delete your account yourself in the dashboard. For any other request, email support@forkly.dev. We respond within one month. If you are a visitor to a link, please contact the owner of that link first; we will assist them in answering your request.

10.Security

We protect data with encryption in transit, hashed passwords and API key secrets, optional two-factor authentication, role-based access within workspaces, audit logging and least-privilege access for our staff. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.

11.International transfers

Our providers may process data in countries other than your own. Where data leaves the EEA, UK or Switzerland, we rely on adequacy decisions or standard contractual clauses together with appropriate safeguards.

12.Children

Forkly is not directed to children under 16 and we do not knowingly collect their personal data to create accounts.

13.Changes and contact

We will post any changes to this policy on this page and update the date above. If changes are material we will notify account owners by email. Questions? Contact us at support@forkly.dev or through our contact form.