1. Data Controller
Zipt Systems is the data controller for the personal data you provide through our Service. For any GDPR-related inquiries, contact us at [email protected].
2. Data We Collect
- Account Data: Email address, name, and billing information
- Usage Data: Browser type, device information, and click analytics. IP addresses are used for rate limiting, abuse prevention and login security; the analytics store retains only anonymized country/city geolocation, not raw IPs. Raw IPs from login and security events are kept in logs for up to 12 months.
- Link Data: URLs you shorten and associated metadata
- Payment Data: Processed securely through PayPal — we do not store credit card numbers
3. Legal Basis for Processing
We process your data under the following legal bases:
- Legitimate Interest: Click analytics and service improvement (with the cookie notice shown on our site; no separate opt-in is required for analytics because raw personal identifiers are not stored in the analytics pipeline)
- Consent: Marketing communications — you explicitly opt in, and can withdraw consent at any time
- Contract: Processing is necessary to provide our Service to you (account creation, billing, link management)
- Legal Obligation: Where required (e.g., financial record-keeping for payments)
4. Your Rights Under GDPR
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data ("Right to be Forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
5. Data Retention
We retain your account data for as long as your account is active. Analytics data is retained for 24 months. You can request deletion of your data at any time by contacting support.
6. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption at rest and in transit, regular security audits, and strict access controls.
7. Third-Party Processors
We use the following third-party processors who comply with GDPR:
- PayPal: Payment processing
- Brevo (Sendinblue): Email delivery
- Cloudflare: CDN and security
- ClickHouse: Analytics data storage
- DeepSeek: AI Support Assistant (chat responses; bounded conversation context only)
8. International Data Transfers
Your data may be processed on servers located in the European Economic Area (EEA) and the United States. We ensure adequate safeguards through Standard Contractual Clauses (SCCs) where required.
9. Data Breach Notification
In the event of a data breach that affects your personal data, we will notify you within 72 hours as required by GDPR Article 33.
10. Contact Information
For GDPR-related requests, contact our Data Protection Officer:
Email: [email protected]
Last updated: July 10, 2026