Privacy Policy

What Ryabi Links collects, why we collect it, who processes it, how long we keep it, and what you can ask us to do with it.

Last updated: 9 August 2026

This document is not final — 2 details still needed

  • Registered legal entity: This is the product name, not a registered company. The Terms need the entity that actually contracts with the customer — the one on the Paddle merchant account.
  • Registered business address: Consumer law in the UK/EU requires a real trading address on the terms, and Paddle checks it during verification. “Available on request” does not satisfy either.

The short version

  • We never store the raw IP address of someone who clicks your link. We resolve an approximate location, then keep only a SHA-256 hash of the IP. The original is discarded and cannot be recovered from the hash.
  • We do not sell personal data, and we do not use it to build advertising profiles.
  • Your card details never reach our servers. Payments are handled by Paddle.com Market Ltd.
  • For the click data your links generate, you are the controller and we are your processor. It is your data.
  • You can ask us to export or delete your data at any time by emailing security@ryabils.com. If you gave your details to someone’s page rather than to us, that page’s owner can erase you themselves, immediately, from their dashboard.

1. Who we are

Ryabi Links, Registered address available on request, operates Ryabi Links.

For data about you as our customer — your account, your billing details, your support emails — we are the controller. For data about people who click or scan your links, you are the controller and we act as your processor, handling it on your instructions.

2. What we collect

Account data. Your email address, name if you give one, a password managed by our authentication provider (we never see or store it in readable form), workspace and team membership, and your two-factor secret if you enable it.

Content you create. Links and their destinations, QR codes, bio and bridge pages, uploaded files, custom domains, API keys, and routing rules.

Billing data. Handled by Paddle.com Market Ltd as merchant of record. They pass us your billing contact, country, plan, and the status of your subscription. We never receive or store your full card number.

Click and scan analytics.When someone follows one of your links we record the time, the link, the approximate country and region derived from the IP, the device type, operating system and browser from the user-agent, the referring site, any UTM parameters on the link, and a SHA-256 hash of the IP address used for deduplication and fraud detection. Precise GPS location is recorded only where you have enabled the opt-in location prompt and the visitor has granted their browser’s permission.

Operational data. Server logs and error traces, which may contain IP addresses and request metadata, retained for a short period for security and debugging.

3. How we handle IP addresses

This is the part most link shorteners get wrong, so it is worth being precise. When a click arrives, we take the IP address, resolve a coarse geographic location from it, and compute a SHA-256 hash of it with a secret salt. We then write the location and the hash. The raw IP is never written to the analytics store.

The hash lets us tell repeat clicks apart from unique ones and spot click fraud, without us holding an identifier that points back at a person. Because a hash is one-way, we cannot reverse it to tell you who clicked, and neither can anyone who obtains the database. This makes our analytics pseudonymous by design.

4. Why we process it, and on what legal basis

  • To provide the service — creating and resolving your links, showing your analytics, running your workspace. Legal basis: performance of our contract with you.
  • To take payment — billing, invoices, tax. Legal basis: performance of our contract, and our legal obligations.
  • To keep the service safe — rate limiting, bot and fraud detection, abuse investigation. Legal basis: our legitimate interest in a service that is not overrun by abuse.
  • To support you — answering your emails. Legal basis: performance of our contract, and our legitimate interest.
  • Precise location, where the opt-in prompt is enabled. Legal basis: consent, given by the visitor in their browser, and revocable there.

We do not use your data or your visitors’ data to train advertising models, and we do not sell it — including under the meaning of “sale” or “sharing” in the CCPA/CPRA.

5. Cookies and consent

On our own site we use cookies that are strictly necessary: your session, your locale preference, and security tokens. We do not run third-party advertising or analytics cookies on our marketing pages.

On yourlinks and pages, you decide. If you enable retargeting pixels, the pixel provider you configure (for example Meta or Google) sets its own cookies and becomes an independent controller for what it collects — its policy applies, not ours. Because you are the controller for your traffic, obtaining any consent required in your visitors’ jurisdictions is your responsibility. We build the tooling for it: you can require a consent prompt on bridge and interstitial pages, and analytics respect the visitor’s choice.

There is also a no-tracking mode for a page. Switch it on and the page runs no third-party pixels at all, whatever is configured — and because nothing on it then requires consent, it needs no cookie banner. Our own view and click counts keep working: they are two integers per page, with no cookie, no IP and no device identifier, so they never needed consent in the first place.

6. Who else processes your data

These are the third parties that may process data on our behalf. We keep the list short on purpose, and it reflects what is actually wired into the product.

ProviderPurposeDataRegion
Vercel Inc.Application hosting, CDN, edge routingRequest metadata, logsGlobal (US-headquartered)
Supabase Inc.Authentication, PostgreSQL database, file storageAccount, link and analytics data; uploaded filesAWS ap-southeast-1 (Singapore)
Upstash Inc.Redis cache and background job queueCached link configuration, rate-limit countersGlobal
Paddle.com Market LtdMerchant of record, subscription billing, tax remittanceBilling contact, payment method, invoicesUK / EU
Resend Inc.Transactional emailEmail address, message contentUS
Sentry (Functional Software, Inc.)Error monitoringError traces, request contextUS

We will update this list before adding a new subprocessor. Beyond these, we disclose data only where the law requires it — a valid court order or lawful request — or to a successor in a merger or acquisition, in which case we will tell you before your data moves.

7. International transfers

Your primary data is stored in managed PostgreSQL on AWS in ap-southeast-1 (Singapore). Some of the providers above are based in the United States or operate globally, so personal data may be transferred outside the EEA and the UK. Where that happens, transfers are covered by the European Commission’s Standard Contractual Clauses and the UK Addendum, as incorporated into our agreements with those providers.

A category-by-category breakdown of where each kind of data physically sits is at /trust/residency. It also answers, plainly, whether we can meet a residency requirement — including when the answer is no. We do not currently offer a choice of storage region.

8. How long we keep it

Raw click and scan rows age out according to the plan the workspace is on:

PlanAnalytics retention
Free30 days
Pro365 days
Business730 days
EnterpriseNegotiated per contract

Aggregated counts, which identify nobody, are kept beyond those windows. Account and link data is kept while your account is open and deleted within 30 days of account deletion, except where we must keep records longer — invoices and tax records, typically for six to ten years depending on jurisdiction, and abuse records where we need them to stop a repeat offender. Server logs and error traces are kept for a short operational period.

9. Security

All traffic is served over HTTPS with HSTS. Data at rest is encrypted by our database, storage and cache providers using AES-256. Link passwords you set are bcrypt-hashed and we cannot read them back, only verify them. Workspaces are isolated, roles are enforced on every query, API keys are scoped and revocable, and sensitive actions are written to an append-only audit log.

Our Trust & Security page documents this in full, including what we do not yet have — we do not hold a SOC 2 report and will not claim one until an audit is complete.

If a breach affects your personal data and poses a risk to you, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.

10. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to processing, and withdraw consent you previously gave. If you are in the EEA or UK these come from the GDPR; if you are in California, the CCPA/CPRA gives you rights to know, delete, correct and opt out of sale or sharing — and, as above, we do not sell or share your data.

To exercise any of these, email security@ryabils.com. We will respond within 30 days. We will not discriminate against you for exercising a right.

If you gave your details to someone’s page rather than to us — you subscribed, bought something or filled in a form on a page built with Ryabi Links— that page’s owner is the controller of your data and we are their processor. They can erase you themselves, from their own dashboard, without waiting for us. Ask them first; if they do not act, tell us and we will.

What erasure actually does, so there are no surprises. Contact records are deleted: the address, name, tags, notes and consent history all go. Records attached to a payment — an order or a booking deposit — are anonymised rather than deleted: the amount, currency, date and payment reference stay, because we and the seller are required to keep transaction records, but every identifying detail is removed. Where a paid membership gave you access to something, the access token is revoked in the same operation, so the access cannot outlive the identity.

One case cannot be completed on the spot: if you hold a live subscription, it has to be cancelled first. Anonymising an active subscription would leave it billing an address nobody can resolve, which is worse for you than a short delay.

If you are unhappy with our response you can complain to your local data protection authority.

A Data Processing Agreement covering the data your links generate is available on request at the same address.

11. Children

Ryabi Links is not directed at children. You must be at least 16, or the age of digital consent in your country if that is higher, to hold an account. If we learn we hold data from a child below that age we will delete it.

12. Changes to this policy

We will update this page when what we do changes, and the “last updated” date at the top will change with it. If a change materially affects how we handle your personal data, we will tell you by email before it takes effect.

13. Contact

Privacy requests, DPAs and security reports: security@ryabils.com
Everything else: support@ryabils.com

Ryabi Links
Registered address available on request