Privacy Policy
On this page
1. Who we are
z4ps.uk ("z4ps", "we", "us") is a URL-shortening service operated by DabbleLabs UK, a sole trader based in the United Kingdom. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), DabbleLabs UK is the data controller for the personal data described here. The service is used by visitors worldwide. You can reach us about anything in this policy at [email protected].
This policy explains, in plain terms, what personal data we hold, why we hold it, the lawful basis for each use, how long we keep it, who it is shared with, and the rights you have.
2. What we collect and why
We keep collection deliberately small. There are two broad groups: data tied to your account, and data recorded when someone clicks a short link (covered in section 3). The lawful basis for each use is shown below.
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Account email address | To identify your account, let you sign in, send account and verification emails, and contact you about the service. | Performance of our contract with you (providing the account). |
| Password (stored only as a one-way argon2id hash - we never hold your actual password and cannot recover it) | To let you sign in securely. | Performance of contract; our legitimate interest in account security. |
| Google account identifier (only if you sign in with Google - the stable "subject" id and your verified email) | To recognise you when you choose Google sign-in. We request only your email and basic sign-in ("openid email"); we do not receive your Google name, photo, contacts or any other Google data. | Performance of contract. |
| Your links and their content (the destination URLs you shorten, custom slugs, campaigns, and any settings such as passwords or expiry) | To provide the core service - to redirect your short links and let you manage them. | Performance of contract. |
| Terms acceptance record (the date and version of the Terms and Privacy Policy you accepted at signup) | To keep a record that you agreed to the terms on which the service is provided. | Performance of contract; compliance with our legal obligations. |
| Signup IP address (a single coarse record of the network address your account was created from) | Abuse prevention only. This is the only place an account's IP is stored, and it is never joined to your clicks. It lets us spot many throwaway accounts minted from one address and helps us handle abuse. | Our legitimate interest in preventing fraud and abuse of the service. |
| Anonymous link creation IP address (a single coarse record of the network address a no-account short link was created from) | Abuse prevention and rate-limiting only. Anyone can create a short link without an account from our homepage, so we record the creating network address to enforce a strict per-network creation limit and to handle abuse of that feature. It is never joined to clicks, and it travels with the link (so for an unclaimed link it is gone within 7 days - see retention). | Our legitimate interest in preventing fraud and abuse of the service. |
| Security event records (short-lived logs of sign-in, registration and password-reset attempts, and rate-limiting counters - these carry the IP address of the attempt) | To rate-limit and protect accounts against automated attacks, credential stuffing and spam. | Our legitimate interest in the security of the service and our users. |
| Abuse-guard records (if an account is suspended for abuse, we keep a record tying that suspension to a canonical form of its email address and/or its signup IP) | To stop a suspended abuser simply re-registering under a trivial variation. Kept to the minimum needed for that purpose. | Our legitimate interest in preventing repeat abuse. |
| Suspension state (if we suspend an account, the fact, time and reason) | To enforce a suspension and keep a record of moderation decisions. | Our legitimate interest in operating a safe service. |
3. Click analytics (and what we deliberately do not collect)
When someone clicks one of your z4ps.uk short links, we record analytics for you, the link owner. This is a core part of the service. We designed it to be unusually privacy-protective:
We deliberately do not store the clicker's IP address. Most link shorteners log the full IP of every click; z4ps does not. Instead, for each click we store:
- a one-way SHA-256 hash of the browser's User-Agent string (used to estimate unique visitors and to detect bots; it is not the raw User-Agent and cannot be reversed to identify anyone);
- a coarse device type, browser family and operating-system family, derived from that same User-Agent;
- the visitor's country, taken from a country header that our provider Cloudflare adds
to the request (
CF-IPCountry). We store only the two-letter country - never the IP address that Cloudflare derived it from; - the referrer URL and its host, if the browser sent one (for example, that the click came from instagram.com);
- two heuristic flags indicating whether the click looks like a bot, and whether it looks fraudulent (for click-fraud detection).
Because no IP address and no reversible identifier is kept, click records are not, on their own, ordinarily capable of identifying an individual clicker. Aggregated per-day counts (see retention) are kept indefinitely; the click-by-click detail is pruned on the schedule in section 5.
4. Cookies
z4ps uses a small number of first-party cookies and no third-party advertising or analytics cookies.
z4ps_sess- session cookie. Set when you sign in, to keep you logged in and to carry an anti-forgery (CSRF) token. It is HttpOnly, SameSite=Lax and marked Secure over HTTPS, and it lasts about 30 days so you stay signed in between visits (sign out at any time, or use "sign out everywhere" from your settings, to end it sooner). This cookie is strictly necessary for the account to work.z4ps_vid- split-test cookie. Set only when you click a link whose owner has configured A/B split-testing across several destinations. It holds 16 random bytes and nothing else - no identity, no tracking profile - and its sole purpose is to keep sending you to the same destination on repeat visits so a split test stays consistent. Ordinary links never set this cookie.z4ps_anon- anonymous-link cookie. Set only when you create a short link without an account from our homepage. It holds a single random token (and we store only a one-way hash of that token, never the token itself). Its sole purpose is to let a link you made anonymously be claimed into an account you later create in the same browser, so the link keeps its click history. It is HttpOnly, SameSite=Lax and marked Secure over HTTPS, carries no identity or tracking profile, and is never set if you do not use the no-account shortener.
We do not use cookies for advertising, cross-site tracking, or third-party analytics. The Cloudflare Turnstile challenge described in section 6, which runs on our sign-up page and on the homepage's no-account link shortener, may set its own cookies on Cloudflare's domain while it checks you are human; that is Cloudflare's cookie, not ours - see Cloudflare's own privacy policy for details.
5. How long we keep data
| Data | Retention |
|---|---|
| Account email and links | Kept for as long as your account exists. |
| Anonymous (no-account) links and their creation IP | An unclaimed anonymous link expires 7 days after it is created and is then recycled, taking its creation-IP record with it. If you sign up in the same browser and claim the link, it becomes an ordinary link on your account and is kept for as long as your account exists. |
| Signup IP address | Automatically cleared once your account is verified, in good standing (not suspended) and older than 180 days. Recent, unverified or suspended accounts keep it while it still has abuse-handling value. |
| Security event records (sign-in / registration / reset attempts, rate-limit counters) | Pruned automatically after 30 days. |
| Abuse-guard records (suspended-account email/IP) | Kept up to 180 days from the last time they were seen, then pruned. |
| Suspension state | Kept while the account remains suspended. |
| Click-by-click analytics detail | Retained per plan: 7 days (Spark / free), 90 days (Bolt), 2 years (Surge), or kept for the life of the account (Tesla). Older detail is pruned automatically. |
| Per-day aggregate click counts | Kept indefinitely (these are counts and coarse breakdowns, retained so long-run totals survive pruning of the detail). |
When you close your account, the personal data associated with it is deleted or anonymised, except where we must keep a limited record to meet a legal obligation or to enforce a suspension against re-registration as described above. To close your account, contact us at [email protected].
6. Who we share data with
We do not sell your data and we do not share it for advertising. To run the service we rely on a small number of processors and providers, and share with each only what it needs:
- Cloudflare sits in front of the site as a CDN and security layer, so it processes all requests to z4ps.uk (including visitor IP addresses, in transit) to deliver and protect the service. It also supplies the country header we use for analytics. Cloudflare acts as our processor.
- Amazon Web Services (Amazon SES) delivers our outbound email (verification and password-reset messages). When we email you, your email address and the message are passed to AWS SES to deliver it. Our SES is hosted in AWS's EU (Ireland) region.
- PayPal handles payments for paid plans. Your card or bank details are provided to and held by PayPal under its own terms and privacy policy; z4ps never sees or stores your card details. PayPal tells us when a subscription starts, renews or is cancelled, together with a subscription reference, which we use only to activate or end your plan.
- Google is involved only if you choose Google sign-in, when we verify your sign-in with Google and receive your verified email and Google account id (see section 2).
- Google Cloud Web Risk is used to check the safety of destination URLs. When a link is created or re-scanned, its destination URL is sent to Google's Web Risk service to check it against known-malicious lists; this is combined with our own local heuristics. This protects the public from phishing and malware spread through short links.
- Cloudflare Turnstile is a CAPTCHA-style human check shown on our sign-up page and on the homepage's no-account link shortener (never at login, which is already protected by rate limits instead) - raising the cost of the cheap, automated abuse that both of those entry points would otherwise attract. Completing it sends data directly from your browser to Cloudflare, including your IP address and browser/device signals used to judge whether you are human; we receive back only a pass/fail result and the hostname it was solved on, never the underlying signals. Cloudflare acts as our processor for this check, the same as for the CDN role described above.
We may also disclose data where we are legally required to, or where it is necessary to investigate abuse, protect our rights, or comply with a lawful request from law enforcement.
7. International transfers
Some of our providers are based outside the UK (for example, Cloudflare, PayPal and Google operate globally, and AWS SES is used in an EU region). Where personal data is transferred outside the UK, it is protected by appropriate safeguards such as the UK's adequacy regulations or standard contractual clauses / the UK addendum, as offered by each provider.
8. Your rights
If you are in the UK or EU you have rights over your personal data, including the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate;
- erase your data (for example, by closing your account);
- restrict or object to certain processing, including processing we carry out on the basis of our legitimate interests;
- data portability for data you provided to us; and
- withdraw consent where we rely on it.
To exercise any of these, email [email protected]. The main personal data we hold for an account is your email address and the links you have created. You also have the right to complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk, though we would appreciate the chance to put things right first.
9. Children
z4ps.uk is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has created an account, contact us and we will remove it.
10. Security
All traffic between you and z4ps is encrypted in transit with HTTPS/TLS. Passwords are stored only as argon2id hashes. We apply rate-limiting and abuse controls, and check link destinations for known malware and phishing. No online service can be perfectly secure, but we take reasonable measures to protect the data we hold.
11. Changes to this policy
If we change this policy, we will publish the new version here and update the "Last updated" date above. Where a change is material, we may also record a new policy version at the point of your next acceptance.
12. Contact
Questions, requests, or complaints about privacy: [email protected]. To report a malicious or abusive short link, use our report a link page.
See also our Terms of Service.