Privacy Policy
What Ryabi Links collects, why we collect it, who processes it, how long we keep it, and what you can ask us to do with it.
Last updated: 9 August 2026
This document is not final — 2 details still needed
- Registered legal entity: This is the product name, not a registered company. The Terms need the entity that actually contracts with the customer — the one on the Paddle merchant account.
- Registered business address: Consumer law in the UK/EU requires a real trading address on the terms, and Paddle checks it during verification. “Available on request” does not satisfy either.
The short version
- We never store the raw IP address of someone who clicks your link. We resolve an approximate location, then keep only a SHA-256 hash of the IP. The original is discarded and cannot be recovered from the hash.
- We do not sell personal data, and we do not use it to build advertising profiles.
- Your card details never reach our servers. Payments are handled by Paddle.com Market Ltd.
- For the click data your links generate, you are the controller and we are your processor. It is your data.
- You can ask us to export or delete your data at any time by emailing security@ryabils.com. If you gave your details to someone’s page rather than to us, that page’s owner can erase you themselves, immediately, from their dashboard.
1. Who we are
Ryabi Links, Registered address available on request, operates Ryabi Links.
For data about you as our customer — your account, your billing details, your support emails — we are the controller. For data about people who click or scan your links, you are the controller and we act as your processor, handling it on your instructions.
2. What we collect
Account data. Your email address, name if you give one, a password managed by our authentication provider (we never see or store it in readable form), workspace and team membership, and your two-factor secret if you enable it.
Content you create. Links and their destinations, QR codes, bio and bridge pages, uploaded files, custom domains, API keys, and routing rules.
Billing data. Handled by Paddle.com Market Ltd as merchant of record. They pass us your billing contact, country, plan, and the status of your subscription. We never receive or store your full card number.
Click and scan analytics.When someone follows one of your links we record the time, the link, the approximate country and region derived from the IP, the device type, operating system and browser from the user-agent, the referring site, any UTM parameters on the link, and a SHA-256 hash of the IP address used for deduplication and fraud detection. Precise GPS location is recorded only where you have enabled the opt-in location prompt and the visitor has granted their browser’s permission.
Operational data. Server logs and error traces, which may contain IP addresses and request metadata, retained for a short period for security and debugging.
3. How we handle IP addresses
This is the part most link shorteners get wrong, so it is worth being precise. When a click arrives, we take the IP address, resolve a coarse geographic location from it, and compute a SHA-256 hash of it with a secret salt. We then write the location and the hash. The raw IP is never written to the analytics store.
The hash lets us tell repeat clicks apart from unique ones and spot click fraud, without us holding an identifier that points back at a person. Because a hash is one-way, we cannot reverse it to tell you who clicked, and neither can anyone who obtains the database. This makes our analytics pseudonymous by design.
4. Why we process it, and on what legal basis
- To provide the service — creating and resolving your links, showing your analytics, running your workspace. Legal basis: performance of our contract with you.
- To take payment — billing, invoices, tax. Legal basis: performance of our contract, and our legal obligations.
- To keep the service safe — rate limiting, bot and fraud detection, abuse investigation. Legal basis: our legitimate interest in a service that is not overrun by abuse.
- To support you — answering your emails. Legal basis: performance of our contract, and our legitimate interest.
- Precise location, where the opt-in prompt is enabled. Legal basis: consent, given by the visitor in their browser, and revocable there.
We do not use your data or your visitors’ data to train advertising models, and we do not sell it — including under the meaning of “sale” or “sharing” in the CCPA/CPRA.
6. Who else processes your data
These are the third parties that may process data on our behalf. We keep the list short on purpose, and it reflects what is actually wired into the product.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Vercel Inc. | Application hosting, CDN, edge routing | Request metadata, logs | Global (US-headquartered) |
| Supabase Inc. | Authentication, PostgreSQL database, file storage | Account, link and analytics data; uploaded files | AWS ap-southeast-1 (Singapore) |
| Upstash Inc. | Redis cache and background job queue | Cached link configuration, rate-limit counters | Global |
| Paddle.com Market Ltd | Merchant of record, subscription billing, tax remittance | Billing contact, payment method, invoices | UK / EU |
| Resend Inc. | Transactional email | Email address, message content | US |
| Sentry (Functional Software, Inc.) | Error monitoring | Error traces, request context | US |
We will update this list before adding a new subprocessor. Beyond these, we disclose data only where the law requires it — a valid court order or lawful request — or to a successor in a merger or acquisition, in which case we will tell you before your data moves.
7. International transfers
Your primary data is stored in managed PostgreSQL on AWS in ap-southeast-1 (Singapore). Some of the providers above are based in the United States or operate globally, so personal data may be transferred outside the EEA and the UK. Where that happens, transfers are covered by the European Commission’s Standard Contractual Clauses and the UK Addendum, as incorporated into our agreements with those providers.
A category-by-category breakdown of where each kind of data physically sits is at /trust/residency. It also answers, plainly, whether we can meet a residency requirement — including when the answer is no. We do not currently offer a choice of storage region.
8. How long we keep it
Raw click and scan rows age out according to the plan the workspace is on:
| Plan | Analytics retention |
|---|---|
| Free | 30 days |
| Pro | 365 days |
| Business | 730 days |
| Enterprise | Negotiated per contract |
Aggregated counts, which identify nobody, are kept beyond those windows. Account and link data is kept while your account is open and deleted within 30 days of account deletion, except where we must keep records longer — invoices and tax records, typically for six to ten years depending on jurisdiction, and abuse records where we need them to stop a repeat offender. Server logs and error traces are kept for a short operational period.
9. Security
All traffic is served over HTTPS with HSTS. Data at rest is encrypted by our database, storage and cache providers using AES-256. Link passwords you set are bcrypt-hashed and we cannot read them back, only verify them. Workspaces are isolated, roles are enforced on every query, API keys are scoped and revocable, and sensitive actions are written to an append-only audit log.
Our Trust & Security page documents this in full, including what we do not yet have — we do not hold a SOC 2 report and will not claim one until an audit is complete.
If a breach affects your personal data and poses a risk to you, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.
10. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to processing, and withdraw consent you previously gave. If you are in the EEA or UK these come from the GDPR; if you are in California, the CCPA/CPRA gives you rights to know, delete, correct and opt out of sale or sharing — and, as above, we do not sell or share your data.
To exercise any of these, email security@ryabils.com. We will respond within 30 days. We will not discriminate against you for exercising a right.
If you gave your details to someone’s page rather than to us — you subscribed, bought something or filled in a form on a page built with Ryabi Links— that page’s owner is the controller of your data and we are their processor. They can erase you themselves, from their own dashboard, without waiting for us. Ask them first; if they do not act, tell us and we will.
What erasure actually does, so there are no surprises. Contact records are deleted: the address, name, tags, notes and consent history all go. Records attached to a payment — an order or a booking deposit — are anonymised rather than deleted: the amount, currency, date and payment reference stay, because we and the seller are required to keep transaction records, but every identifying detail is removed. Where a paid membership gave you access to something, the access token is revoked in the same operation, so the access cannot outlive the identity.
One case cannot be completed on the spot: if you hold a live subscription, it has to be cancelled first. Anonymising an active subscription would leave it billing an address nobody can resolve, which is worse for you than a short delay.
If you are unhappy with our response you can complain to your local data protection authority.
A Data Processing Agreement covering the data your links generate is available on request at the same address.
11. Children
Ryabi Links is not directed at children. You must be at least 16, or the age of digital consent in your country if that is higher, to hold an account. If we learn we hold data from a child below that age we will delete it.
12. Changes to this policy
We will update this page when what we do changes, and the “last updated” date at the top will change with it. If a change materially affects how we handle your personal data, we will tell you by email before it takes effect.
13. Contact
Privacy requests, DPAs and security reports: security@ryabils.com
Everything else: support@ryabils.com
Ryabi Links
Registered address available on request
