Privacy Policy — Zipt Systems

Privacy Policy

Last updated: June 29, 2026 — How Zipt Systems collects, uses, and protects your data.

Data We Collect

When you use Zipt Systems, we collect the following data to provide and improve our link analytics service. We do not store raw personal identifiers (your name, your email, or your IP address) inside the analytics pipeline: the analytics store keeps only anonymized country/city geolocation with each click event. For security and abuse prevention, raw IP addresses and User-Agent strings are recorded in our login and security logs (retained for up to 12 months, then automatically purged). Account data (email, name, billing) is collected separately when you create an account.

Server-Side Data (Collected Automatically)

  • Server UTM Parameters — utm_source, utm_medium, utm_campaign, utm_term, utm_content — for marketing attribution
  • Server Device Type — mobile, tablet, or desktop — detected from User-Agent header
  • Server Browser Language — primary language from Accept-Language header
  • Server Referrer URL — the page the visitor came from
  • Server Bot Detection — whether the request appears to be from a crawler or bot
  • Server Country & City — approximate geolocation from IP address (anonymized)

Client-Side Data (Collected via Beacon API)

  • Client Screen Resolution — width x height for responsive design optimization
  • Client Timezone — IANA timezone name (e.g., Asia/Yangon) for peak traffic analysis
  • Client Connection Type — 4G, WiFi, ethernet, etc. for mobile experience optimization
  • Client Return Visitor Status — whether the visitor has visited before (via non-personal cookie)

Cookies

We use a single non-personal cookie (zipt_return=1) to distinguish new vs. returning visitors. This cookie:

  • Contains no personal data — just a boolean flag
  • Expires after 1 year
  • Cannot be used to identify individual users
  • Can be disabled via browser settings

How We Use Your Data

  • Analytics: Understand click patterns, peak traffic times, and geographic distribution
  • Marketing Attribution: Track which campaigns drive clicks (via UTM params)
  • UX Optimization: Improve mobile experience based on device type and connection speed
  • Content Strategy: Determine optimal publishing times based on timezone data

Data Sharing

We do not sell, trade, or share your analytics data with third parties. Aggregated, anonymized statistics may be used internally for platform improvement.

Link Safety Scanning: When you create a link, the destination URL may be sent to Google Web Risk (Google LLC) for malicious-content scanning. We also check destinations against the public URLhaus and OpenPhish blocklists, which we download and match locally — URLs are not transmitted to URLhaus or OpenPhish. This protects your audience from phishing, malware, and unwanted software. Only the URL itself is used for this purpose — no account data is included. Google's privacy policy applies to data processed by Google Web Risk: policies.google.com/privacy.

Third-party processors: We use trusted processors to operate the service, including PayPal (payments), Cloudflare (content delivery and protection), Brevo (transactional email), ClickHouse (analytics storage), and DeepSeek (AI support assistant). These processors act on our behalf and receive only the data required for their function.

AI Support Assistant & DeepSeek

How it works: Our Support Chat is an AI assistant powered by DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.). When you use Support Chat, your message and a short, bounded summary of the current conversation may be sent to DeepSeek to generate a response. To answer accurately, the assistant uses our own verified tools first (for example to check your plan or a link's analytics); DeepSeek does not directly access your account.

  • Purpose: Answering support questions and resolving issues faster.
  • Data sent: Your chat messages, the current conversation summary, and only the tool results your question requires.
  • Retention: Conversations are stored in our database and are deleted when you delete the conversation, when you request deletion, or via our data-retention pipeline (see Data Retention).
  • Safeguards: DeepSeek access is server-side only — your API keys and other secrets never appear in your browser. Account secrets, passwords, and payment details are never sent to the assistant.

⚠️ Do not submit passwords, API keys, security codes, or payment-card details in Support Chat. If you need to share sensitive information, use a support ticket or email instead.

DeepSeek's privacy policy applies to data processed by DeepSeek: deepseek.com/privacy.

Data Retention

Retention: Analytics (click) data is retained for 24 months, after which it is automatically purged by our data-retention pipeline. Support conversations and tickets are retained while your account is active and are deleted on request or via the data-retention pipeline. Account data is retained while your account is active. You can request earlier deletion or an export of your data at any time by contacting support.

GDPR & CCPA Compliance

Zipt Systems is committed to data privacy:

  • GDPR: We process analytics on the legal basis of legitimate interest, and account data on the basis of consent / contract. We never sell personal data, and you can request access, correction, export, or deletion at any time.
  • CCPA: We do not sell personal information. California residents can request disclosure of data collected via [email protected].
  • Data Portability: You can request a portable export of your data at any time by contacting support; our privacy team fulfils data-subject export requests (DSAR) within 30 days.
  • Right to Deletion: Contact us to request deletion of all your data.

Contact

For privacy-related inquiries: [email protected]

For support: [email protected]