shor10shor10LEGAL

Privacy Policy

UPDATED 11 SEP 2026

DATA CONTROLLERTOMERA Co., Ltd. (Head Office) · Tax ID 0105569170293 · No. 111/6, Lat Phrao 23 Alley, Chandrakasem Sub-district, Chatuchak District, Bangkok 10900, Thailand

IN ONE
LINE

We do not sell click data or build profiles of your visitors. The data we collect is listed below. Raw click rows are kept to your plan's window whether or not the link expires: 30 days on Free and Pro, and for as long as you remain on Max. A link with an expiry is deleted about an hour after it expires; its click rows outlive it and end at that window instead.

01 · WHAT WE STORE ABOUT YOU

We store your email address so you can sign in and receive expiry warnings. We may also store an optional display name, your default timer and timezone, notification preferences, links, aliases, destinations, timers, and plan. An API key is stored as a short display prefix and a hash of the secret, so we cannot read the key itself or show it to you again. A custom domain is stored as the hostname you connect, and we send that hostname to Cloudflare so it can issue a certificate for it. If you join a waitlist we keep the email address and the option you picked, with no time limit, because what it is for — telling you when Pro opens — has not happened yet. Your IP address reaches us with every request: we keep the address itself for up to about an hour in a rate-limiting record, and with a guest link draft you never claimed, where it is deleted with the draft about two days after you created it. A waitlist signup stores no IP address. Everywhere else we store a hash of it instead, as section 02 describes. If you subscribe later, Stripe handles billing and card details never reach our servers. We do not ask for a phone number or store a password.

Your email, links, plan and settings — plus API keys, custom domains, and the IP behind a request.

02 · WHAT A CLICK RECORDS

Most redirects write one row. Repeat hits from the same visitor inside a minute collapse into the first, and once a link has written 60 rows in a minute the rest of that minute is not recorded. The fields are deliberately coarse. The two hashes are how we count unique visitors: they stay inside shor10 and appear in no export or download.

FIELDEXAMPLEKEPT FOR
Link iduuid of the short linkPLAN*
Row iduuid of the click rowPLAN*
Time of the hit2026-07-29T14:02ZPLAN*
User-agent hashsha256... (not the raw string)PLAN*
IP hashsha256... (not the raw address)PLAN*
After-expiry flagtrue when the hit returned 410PLAN*
Outcome410_view / fallback_302 / cta_clickPLAN*
Full user agentnot storedNEVER
Country code / device class / referrer hostTH / mobile / example.comPLAN*

* Plan retention: raw click rows are kept to your plan's window whether or not the link expires. Free and Pro delete a row 30 days after the click it records, without rolling it into a hidden aggregate, and Max keeps them while you remain on Max. If you downgrade, the 30-day window applies again. A link with an expiry is deleted about an hour after it expires, but its click rows outlive it: an hourly sweep ends them at the window above, not with the link. Deleting a link deletes its click rows too. Link totals remain either way: deleting a link, or letting one expire, leaves a compact archive row holding the shortcode, the destination, the click total, the time of the last click, when the link was created, when it expired, and when and why it was archived, attached to your account and kept with no time limit.

03 · COOKIES

Signing in sets up to three cookies: the session cookie itself, and two Auth.js security cookies written the moment you start signing in, before sign-in completes. A fourth, NEXT_LOCALE, remembers your language for a year; it can be set on your very first page view, before you sign in and before you touch the notice, and scripts on the page can read it. There are no analytics tags, advertising pixels, or third-party scripts on the redirect path, and visitors who only follow a link receive no cookie. Marketing pages show a short notice; acknowledging it stores a preference in localStorage on your device, not a tracking cookie. If you create a link without an account, localStorage also holds a random device id so those links can be claimed when you sign up; it is cleared once you claim them. We also keep a one-way hash of that id for 30 days, with when it made its first link, how many it made, and whether that browser later signed in to a new or an existing account, to count how many people try shor10 and how many go on to sign up. The hash cannot be turned back into the id, and the record does not say which account signed in.

Your session, two sign-in security cookies, and your language. None for your visitors.

04 · WHO ELSE PROCESSES IT

Cloudflare

Runs redirects and stores links, and keeps the operational logs, which record shortcodes and account ids on Cloudflare's own retention clock. Global.

Stripe

Will process subscription payments and hold card details when paid plans open. Not in use today. US/EU.

Resend

Sends sign-in, expiry and daily digest emails. An expiry email carries the shortcode and a shortened destination, so Resend sees link destinations. EU.

We use two sub-processors today, Cloudflare and Resend, and no ad networks. Stripe joins them when paid plans open. We will update this list before adding another one.

05 · OPERATOR ACCESS AND MODERATION

An administrator at shor10 can open your account to answer a support request or act on a report. They see your dashboard as you see it: your email address, your links and their destinations, your custom domains, the names of your API keys, and your click analytics including the CSV export. They cannot change anything — every write is refused while an account is being viewed this way — and they cannot read an API key, because only its prefix and a hash are stored. A session like this ends when the administrator stops it, and expires on its own 30 minutes after it started. We record the start of every one, the end when an administrator stops it, and any analytics CSV taken during one; a session left to time out records no end, so a start can stand alone. We do not notify you when this happens. Administration and moderation actions go to an audit trail holding account ids, hostnames and shortcodes — never email addresses or IP addresses — kept for 24 months, including after the account it names has been deleted. That is the longest window in this policy, deliberately: it is the accountability record for the administrator access described above, and a question about who opened your account deserves an answer long after the fact. If someone reports one of your links, we keep the report: the shortcode, a snapshot of the destination, the reason chosen and up to 1000 characters the reporter typed. The reporter's IP address limits how often the form can be submitted and is not stored with the report. Reports are kept after the link and the account are gone. A resolved report is deleted 90 days after it was resolved; an open one is not deleted on a timer, because an unanswered complaint is a backlog rather than stale data.

A person here can look at your account, cannot change it, and is timed out after 30 minutes. Starts and CSV downloads are recorded.

06 · WHAT YOU CAN ASK FOR

You can schedule account deletion from Settings by typing your email. You have 14 days to cancel, and short links keep working during that period. After hard deletion your account record, links, click rows and analytics totals are removed, and every link you owned returns 404. Some records outlive the account: compact link archives may remain without your account, with no time limit; a waitlist signup keeps the email address you gave it, with no time limit and no IP address; a report someone filed about one of your links keeps that link's shortcode and destination until 90 days after it is resolved, or for as long as it stays open; the administration audit trail keeps the account id of actions taken on the account for 24 months; and a guest link draft you never claimed keeps its destination and the IP that created it until it is swept, about two days after it was created. Cancelling starts a 24-hour cooldown before you can schedule deletion again. You may sign up with the same email afterward, but old data is not restored. Under GDPR and PDPA, you may also object, correct, restrict, or ask for a copy of your data. Email us and a person will reply.

There is a 14-day grace period before hard deletion. A few records outlive the account. Send other data requests by email.

Privacy question or data requestprivacy@shor10.co← Terms of Service