1. Who we are
clkr.in is run by [Company legal name], with its registered office at [Registered office address, India] ("clkr.in", "we", "us" or "our"). This policy explains what personal data we collect, why, and the choices you have. It's written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under it.
2. Whose data this covers
We deal with three groups of people, and our role is different for each:
- Account holders: people who sign up for clkr.in and use the dashboard or API. For their data, we decide how and why it's used (we're the "Data Fiduciary" under the DPDP Act).
- People who click or scan links created by our customers. We record click data on behalf of the customer who created the link, who decides what to do with it; for that data we act as the customer's processor. If you have questions about a particular link, contact the business that sent it to you. We can help pass on your request.
- Visitors to our website at www.clkr.in and blog.clkr.in.
3. Data about account holders
| What | Why |
|---|---|
| Email address | To create your account, send you sign-in codes and contact you about your account and the Service. |
| Workspace details, such as its name and the people you invite | To set up and run your workspace. |
| Your links and settings: destination URLs, slugs, titles, tags, QR codes, custom domains and targeting rules | To provide the Service. Destination URLs are also checked against lists of unsafe sites. |
| Sign-in and security data: one-time codes, session and API key records, IP address and browser type | To sign you in and keep your account secure, prevent abuse and enforce rate limits. We store sign-in codes, session tokens and API keys only in hashed form. |
| Audit log of changes in your workspace, such as who created, edited or deleted a link | Security, accountability and compliance with TRAI and CERT-In requirements. |
| Billing details, if you're on a paid plan: billing name, address, GSTIN and payment history | To bill you and meet tax law. Card and bank details are handled by our payment provider; we never see or store full card numbers. |
| Messages you send us | To answer you and improve our support. |
4. Data about people who click links
When someone opens a clkr.in short link or scans a clkr.in QR code, we record:
- the link that was opened, the time, and whether it came from a QR code;
- approximate location (country, region and city), worked out from the IP address;
- device type, operating system and browser, from the browser's user agent;
- the referring site, if the browser sends one, and any UTM tags on the link;
- a visitor identifier: a one-way hash of the IP address and browser details combined with a secret value, used only to count unique visitors. It can't be reversed to get the IP address back.
We don't store the raw IP address in click analytics, and short links don't set cookies. We don't build profiles of individual visitors or track them across different customers' links.
Like any web service, our systems handle the IP address briefly to deliver the redirect, block abuse and keep security logs, as described in section 10.
5. Data about website visitors
Our marketing website and blog don't use advertising or tracking cookies. We may use cookieless, aggregate traffic statistics, such as Cloudflare Web Analytics, to see which pages are popular. Our website loads fonts from Google Fonts, which means your browser connects to Google and shares your IP address with it. If you email us or sign up, we handle that data as described above.
6. How we use data
We use personal data only to:
- provide, maintain and improve the Service;
- show our customers analytics for their own links;
- sign you in, secure accounts and detect and prevent fraud, spam, phishing and other abuse;
- send service messages, such as sign-in codes, security alerts, billing notices and changes to our terms;
- send product news, if you've agreed to it. You can unsubscribe from these emails at any time, and doing so won't affect service messages;
- comply with the law, respond to lawful requests and enforce our Terms of Use.
We process account holders' data with their consent, given when they sign up, and for legitimate uses permitted by the DPDP Act, such as complying with the law. You can withdraw consent at any time by closing your account; this won't affect processing already done.
We don't sell personal data, and we don't use it for advertising or to train AI models.
7. Cookies
We keep cookies to a minimum:
- Session cookie on app.clkr.in (
__Host-session): keeps you signed in for up to 30 days. It's strictly necessary, can only be read by our servers, and isn't used for tracking. - Cloudflare Turnstile on our sign-in pages may use cookies or similar storage to tell people from bots.
Short links and QR code redirects set no cookies. Because we only use strictly necessary cookies, we don't show a cookie banner. You can block cookies in your browser, but you won't be able to sign in to the dashboard.
8. Who we share data with
We share personal data only with:
- Service providers who process it for us under contract, listed below;
- Our customers, who see analytics for clicks on their own links. These show aggregate counts, not raw IP addresses;
- Authorities, when required by law, such as a court order or a lawful request from a government agency or CERT-In, or when needed to protect people from harm or fraud;
- A buyer or successor, if we're involved in a merger, acquisition or sale of assets. This policy would continue to apply to your data.
| Provider | What they do for us | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, global network, storage, analytics processing and bot protection (Turnstile) | Global network, including India |
| Resend, Inc. | Sending login codes and service emails | United States |
| Google LLC | Checking link destinations against lists of unsafe sites, and web fonts on this website | United States and global |
When we add a payment provider for paid plans, we'll add it to this list.
9. Where data is processed
clkr.in runs on Cloudflare's global network, so short links are answered from a location near each visitor, and data may be processed in India and in other countries where our providers operate. We transfer data outside India only as the DPDP Act allows, and never to a country the Government of India has restricted. We keep security logs that Indian law requires us to hold in India there.
10. How long we keep data
| Data | How long |
|---|---|
| Sign-in codes | Until used, or 10 minutes, whichever is first |
| Sessions | Up to 30 days after your last activity, or until you sign out |
| Account data, links and settings | While your account is open, then deleted within 30 days of closing it |
| Click analytics | For the click-history period of your plan (on the free plan, currently 30 days), and deleted when your account closes |
| Security logs, including IP addresses | 180 days, as required by CERT-In directions |
| Workspace audit log | While your account is open, and as long as the law requires after |
| Billing and tax records | 8 years, as required by Indian tax law |
We may keep data longer where the law requires it, or to deal with a legal claim or an abuse investigation. Backups are overwritten on a rolling schedule.
11. Security
We protect data with encryption in transit (HTTPS everywhere) and at rest, by hashing sign-in codes, session tokens and API keys, by limiting staff access to what each person needs, and with rate limiting and bot protection. No system is perfectly secure. If a personal data breach affects you, we'll tell you and the Data Protection Board of India as the DPDP Act requires, and report incidents to CERT-In within the time it sets.
12. Your rights
Under the DPDP Act, and other privacy laws that may apply to you, you can:
- get a summary of the personal data we hold about you and how we use it;
- have inaccurate or incomplete data corrected and kept up to date;
- have your data erased when it's no longer needed, subject to what the law requires us to keep;
- withdraw consent, which may mean closing your account;
- nominate someone to exercise your rights if you die or become unable to;
- complain to our Grievance Officer, and then to the Data Protection Board of India.
You can update most account details and delete links yourself in the dashboard. For anything else, email privacy@clkr.in from the address on your account. We may need to confirm your identity first. We'll respond within 30 days.
If you clicked a link created by one of our customers, contact that customer first. If you can't reach them, write to us and we'll help.
13. Children
clkr.in is for people aged 18 and over. We don't knowingly collect personal data from children to create accounts. If you think a child has signed up, contact us and we'll delete the account.
14. Changes to this policy
We may update this policy as the Service or the law changes. We'll post the new version here and update the "Last updated" date. If we make a significant change to how we use your data, we'll email account holders before it takes effect.
15. Grievance Officer and contact
For privacy questions or complaints, contact our Grievance Officer:
[Grievance Officer name]
[Company legal name]
[Registered office address, India]
Email: grievance@clkr.in
We'll acknowledge your complaint within 24 hours and aim to resolve it within 15 days. For anything else, email hello@clkr.in.