Privacy Policy · v0-draft
Privacy Policy — 短.在线
Version: v0-draft
Last updated: 2026-09-13
DRAFT — NOT LEGAL ADVICE — NOT YET IN FORCE for production. Founder accepted for soft-launch prep (2026-09-13); live publish needs a separate explicit go-ahead.
Controller: Arasaka Ltd (Singapore contract venue). Soft-launch prep only — not production-published until explicit go-ahead. Registered address / number TBD.
This Privacy Policy explains how Arasaka Ltd (“we,” “us,” “短.在线”) processes personal data when you use the 短.在线 smart-link / QR / attribution Service. It is written for GDPR (and UK GDPR where applicable) and includes PIPL-aware notes for when personal information of individuals in China is processed.
Related: Terms of Service · Acceptable Use Policy
1. Controller and contacts
Controller: Arasaka Ltd (registration number and registered address TBD).
| Topic | Contact |
|---|---|
| Privacy requests | privacy@短.在线 (SMTP: privacy@xn--s7y.xn--3ds443g) |
| Abuse / safety | abuse@短.在线 (SMTP: abuse@xn--s7y.xn--3ds443g) |
| DPO | Not appointed at MVP; will be designated if legally required |
Contract vs privacy law (important):
- Contract governing law / venue for the Terms: Singapore (founder lock — see Terms).
- Privacy law: GDPR / UK GDPR still apply as privacy law to personal data of individuals in the EU/EEA/UK where those regimes cover the processing — independent of Singapore being the contract venue. This Policy is written to meet those standards for such processing.
- PIPL-aware notes apply when personal information of individuals in China is processed.
- Controller: Arasaka Ltd (Singapore law/venue). Formality: customer-facing name stays Arasaka Ltd unless ACRA/registry requires “Pte. Ltd.” — do not rewrite in drafts.
2. Scope
This Policy covers:
- Visitors and creators using anonymous shortening or accounts.
- Recipients who click or scan short links / QR codes (visit events).
- Business contacts (support, billing).
It does not cover third-party destination websites you are redirected to — those have their own policies.
MVP hosting posture: EU/global control plane + global redirect edge + Asia endpoint (HK/SG). We do not promise mainland China ICP hosting in MVP materials.
3. Categories of data we process
3.1 Account and billing
- Email, name (if provided), password hashes or SSO identifiers.
- Plan, Stripe customer/subscription identifiers, payment status (card data handled by Stripe; we do not store full PAN).
- Support correspondence.
3.2 Link metadata (creators)
- Destination URL, short code / alias, titles, tags, QR settings, custom domain bindings.
- Create-path decision / reason codes (e.g. allowed, CAPTCHA required, quarantined).
- Whether a public analytics card is opted in.
3.3 Visit / click events (analytics + abuse)
Shown in Free creator analytics UI (only):
- Country (coarse geo)
- Device class
- Referrer host
- Via: QR vs link
Creator UI never shows raw IP or precise street-level location.
Server-side fields used for abuse / rate-limit / reliability (short TTL — see §5):
| Field | Notes |
|---|---|
timestamp | Event time |
link_id / short_code | Which link |
ip_hash | Salted hash of IP |
geo_country | Country-level |
ua_family or truncated UA | Not full UA by default |
bot_class | Bot / human classification |
referrer_host | Host only |
destination_host | Host of target |
via | QR vs link (etc.) |
Create-path decision / reason | On create |
Optional / derive-and-drop (not retained long-term for abuse): full UA, geo_region, visitor_id / session_id (consent-gated if used), UTM parameters when needed for product analytics then aggregated or dropped per schedule.
We do not store for abuse purposes:
- Precise geo (lat/long / street)
- Full raw IP beyond the short window in §5
- Clipboard contents or destination-page form PII scraped from targets
3.4 Technical and security
- IP address (raw, briefly), salted
ip_hash, security cookies for continuity / CSRF, CAPTCHA tokens, risk scores. - Server logs necessary to operate and secure the Service.
3.5 Public analytics cards (opt-in)
If you opt in, we may publish aggregate counts only on a public card. Cards must not display emails or names. You control titles/aliases and must not put personal data on cards.
4. Purposes and legal bases (GDPR)
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Provide the Service | Create redirects, accounts, QR, dashboards | Art. 6(1)(b) contract; or 6(1)(f) legitimate interests for anonymous use |
| Abuse prevention & security | Rate limits, CAPTCHA, quarantine, bot class, GSB lookup | Art. 6(1)(f) legitimate interests; legal obligation where applicable |
| Creator analytics | Country / device / referrer host / via aggregates | Art. 6(1)(b) or 6(1)(f); consent where required for optional IDs |
| Public analytics cards | Opt-in aggregate publication | Art. 6(1)(a) consent (creator opt-in) |
| Billing & accounting | Stripe, invoices, tax | Art. 6(1)(b) and 6(1)(c) |
| Product improvement | Aggregated metrics, experiments | Art. 6(1)(f); consent for non-essential cookies where required |
| Communications | Service notices; marketing only with consent or soft opt-in where allowed | Art. 6(1)(b)/(f)/(a) as applicable |
We do not sell identifiable clickstreams. We may use aggregated, non-identifying statistics for benchmarks or capacity planning.
5. Retention
| Data | Retention (MVP lock) |
|---|---|
| Raw IP | ≤ 7 days for rate-limit / abuse, then discarded or held only as hash |
Salted ip_hash | ≤ 90 days for abuse / appeals, unless a longer hold is required for an active investigation or legal hold |
| Visit event fields for abuse (table in §3.3) | Aligned with raw IP / hash windows above; then aggregate or delete |
| Account profile | Life of account + short wind-down after deletion request |
| Billing records | As required by tax/commercial law (often years) |
| Aggregate analytics | Longer retention of non-identifying aggregates |
| Support tickets | As needed to resolve, then limited archive |
Creator UI never displays raw IP regardless of server retention.
6. Sharing and subprocessors
We share personal data only as needed with:
| Category | Examples (MVP) | Notes |
|---|---|---|
| Infrastructure hosting | Cloud hosts for control plane / edge (names TBD in live list) | EU/global + HK/SG posture |
| Payments | Stripe | Paid plans |
| Threat lookups | Google Safe Browsing Lookup API | Destination safety; disclosed for MVP |
Provisional inventory: see SUBPROCESSORS.md (draft; planned vs live). Hosting candidates include Vercel (duan-web), Cloudflare (DNS/TLS), Fly.io EU (Shlink stack), and Stripe (v1b billing). Email provider TBD.
| Email / support | Provider TBD | Transactional mail |
| Analytics infra | Self-hosted or disclosed vendor | Prefer first-party |
We do not promise commercial third-party URL-intel products in this v0 Privacy Policy.
Security measure (ops posture, not a user promise of 100% scanning): if Google Safe Browsing (or equivalent) is unavailable, we may prefer REVIEW / quarantine for suspicious creates rather than fail-open.
Future DPAs: a light DPA for paid plans (v1b); a fuller attribution DPA when customer webhooks ship (v1c). Business customers may request the then-current DPA via privacy@短.在线 once published.
We may disclose data to authorities when legally required, or to defend legal claims / prevent serious harm.
International transfers: where data leaves the EEA/UK, we will use appropriate tools (e.g. SCCs, adequacy) once subprocessors and entity are finalized. Details will be listed on a public subprocessor page before publish.
7. Cookies and similar technologies
We use:
- Strictly necessary cookies/tokens (session, CSRF, anonymous continuity for rate-limit fairness, security).
- Optional analytics or preference cookies only with consent where ePrivacy/GDPR require it.
A cookie notice will ship with the live product if non-essential client trackers are used. Server-side visit logging for redirects is described in §3–5 and is not a browser “cookie” but may still involve personal data.
8. Your rights
GDPR / UK GDPR (where applicable)
Access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), and withdrawal of consent without affecting prior lawful processing. You may lodge a complaint with a supervisory authority.
PIPL-aware notes (when PI of individuals in China is processed)
Where China’s Personal Information Protection Law applies, we will provide notice of processing rules, process PI under a lawful basis recognized by PIPL (e.g. contract necessity, consent), obtain separate consent where required (e.g. certain sensitive PI or cross-border scenarios), and honor individual rights of access, copy, correction, and deletion as applicable. Cross-border transfers will follow the mechanism required at the relevant threshold (contractual clauses, certification, or security assessment). MVP does not rely on mainland ICP hosting; processing of mainland users’ PI on offshore infrastructure will be assessed as volume and features grow.
To exercise rights: privacy@短.在线. We may need to verify identity.
9. Children
The Service is not directed at children under 16 (or lower age of digital consent only where explicitly allowed and configured). We do not knowingly collect account data from children. Contact us to delete such data if discovered.
10. No sale of identifiable clickstreams
We do not sell or rent identifiable clickstreams or raw visit logs to data brokers. Aggregate, non-identifying metrics may be used internally or published as product insights without identifying visitors or creators beyond what a creator chooses to show on an opt-in public card.
11. Security (high level)
Encryption in transit (TLS), access controls, salted IP hashing after the raw-IP window, rate limits, destination scanning integrations (including GSB), quarantine workflows, and least-privilege operational access. No security measure is perfect.
12. Changes
We will update this Policy’s version and date when it changes. Material changes will be notified reasonably (in-product or email to account holders) before taking effect, except where faster change is required for law or security.
13. Contact
- Privacy:
privacy@短.在线(SMTP/ASCII form:privacy@xn--s7y.xn--3ds443g) - Abuse:
abuse@短.在线 - Controller: Arasaka Ltd — contract venue Singapore
Controller: Arasaka Ltd · Law / venue: Singapore
Privacy: privacy@短.在线 · Abuse: abuse@xn--s7y.xn--3ds443g