Legal
Privacy Policy
Effective date: August 9, 2026 · Last updated: August 12, 2026
This Privacy Policy explains how Yoro.cc (“Yoro.cc,” “we,” “us,” or “our”) collects, uses, retains, and shares information when you create or visit a short URL, use analytics or account features, or contact us.
1. Scope and controller
This Policy applies to the Yoro.cc website, short-link redirects, related APIs, emails, and analytics features. Yoro.cc’s service operator is responsible for the processing described here. You can reach us through the contact page.
This Policy does not govern a destination website reached through a Yoro.cc link. The destination operator’s own privacy terms apply after you leave our Service.
2. Information we collect
Information you provide
- Short-link information: the destination URL, generated short code, password-protection setting, and associated service metadata.
- Account and verification information: email address, verification status, one-time login challenge information, and authentication/session records.
- Access credentials: a short-URL password or private analytics token may be stored with the URL record for compatibility with the existing service. Read-through cache entries contain only a one-way hash of that credential. Do not reuse a password that you use for another service.
- Communications: your email address, name, message, and any details you submit through the contact form or in an abuse request.
- Social Card information: the share title, description, destination URL, crop selection, and images you submit or ask us to retrieve from a public website.
- Billing profile: cardholder name and billing address. We store these fields even if a payment fails so that you can correct and retry a checkout. Paygate does not accept these address fields, so they are not sent to Paygate or Stripe and are not used for address verification (AVS).
- Card credentials: card number, CVC, and expiry month/year are forwarded in memory to Paygate for the requested checkout. Yoro.cc does not write these values to MySQL, Redis, application logs, error messages, or emails.
Information collected when a short URL is visited
We process the short code, click time, IP address, country code, browser name and version, operating-system name and version, device type, bot indicator, and the referrer hostname and registrable domain when available.
For clicks handled by the current Yoro.cc analytics system, we extract limited fields and do not retain the complete User-Agent string or complete referrer URL in the formal click log. The raw IP address is retained only in that short-lived formal click log. During the migration period, reports may also include normalized aggregate data read from a legacy analytics system.
Information collected automatically
We may receive standard request and security information such as timestamps, requested paths, response status, IP address, proxy headers from trusted infrastructure, CAPTCHA results, and rate-limit signals. Essential cookies or similar storage may be used for signed-in sessions, security, and interface preferences such as color mode.
3. How we use information
- create, resolve, redirect, password-protect, and manage short URLs;
- verify email addresses, send one-time login codes, maintain sessions, and respond to messages;
- create, edit, render, and deliver Social Card metadata and processed preview images;
- process Plus subscriptions, reconcile renewals, administer cancellation, and send payment confirmations;
- produce “today” and “this month” analytics, including approximate time, country, browser, and referrer statistics;
- detect bots, prevent fraud, phishing, malware, spam, and other abuse, and enforce our Terms of Service;
- operate, troubleshoot, secure, monitor, and improve the Service; and
- comply with law, protect users and the public, and establish or defend legal claims.
4. Legal bases
Where data-protection law requires a legal basis, we rely on performance of a contract or steps you request before entering one; our legitimate interests in operating, securing, and improving the Service; compliance with legal obligations; and consent where the law requires it. You may withdraw consent at any time, without affecting processing already performed.
5. Analytics and retention
- Formal click logs: scheduled to expire 30 days after the click. These logs contain the raw IP address and processed device, browser, country, and referrer fields.
- 15-minute analytics: scheduled to expire 45 days after the relevant time bucket, including the separate high-cardinality referrer dimensions used for current-period reports.
- Daily and lifetime aggregate statistics: no scheduled expiration. These aggregates do not contain raw IP addresses or full User-Agent strings.
- Account and short-link records: retained while needed to provide, secure, and administer the Service, resolve disputes, and meet legal requirements.
- Social Card images: uploaded or retrieved originals are held in a private temporary storage prefix and scheduled for deletion within 24 hours. After processing, only the 1200 × 630 JPEG and WebP derivatives are retained while the Social Card remains in use or as reasonably needed for backups and dispute handling.
- Billing and subscription records: billing profile, order identifiers, subscription state, payment-attempt status, and quota usage are retained for service administration, fraud prevention, disputes, accounting, and legal obligations. Card number, CVC, and expiry are not part of these records.
- Authentication, contact, operational, and security records: retained only as long as reasonably needed for their purpose, subject to backup cycles and legal obligations.
Expiration is not instantaneous. Database cleanup jobs run periodically, and residual copies may remain temporarily in encrypted or access-controlled backups until those backups rotate.
6. How we share information
We do not sell personal information. We may share limited information:
- with hosting, database, email-delivery, CAPTCHA, network, geolocation, monitoring, and other vendors that process information for us under appropriate instructions;
- with Amazon S3-compatible storage and CloudFront for private image processing and delivery of processed Social Card images;
- with Paygate and its payment processor, Stripe, to process card subscriptions and retrieve payment status. Only checkout data accepted by Paygate is sent; Yoro.cc billing-address fields are not sent;
- with a destination website when a visitor follows a short URL, as the visitor’s browser makes the destination request;
- when required by law or reasonably necessary to respond to lawful process, investigate abuse, protect rights or safety, or prevent fraud and security incidents; and
- in connection with a merger, financing, reorganization, sale, or transfer of all or part of the Service, subject to applicable law.
Some providers may process information in countries other than yours. Where required, we use recognized safeguards for international transfers.
7. Public links and analytics access
A short URL may be shared publicly and can reveal its destination to anyone who follows it. Anyone who obtains an analytics link, token, account session, or short-URL password may be able to access the associated feature. Do not place confidential or sensitive personal information in a destination URL, including its path or query string.
8. Security
We use administrative, technical, and organizational measures designed to protect information, including access restrictions, transport encryption, secret hashing, limited retention, and service isolation. No online service is completely secure, and we cannot guarantee that information will never be accessed, lost, altered, or disclosed without authorization.
9. Your rights and choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a data-protection authority. These rights may be limited by law, security needs, the rights of others, and the fact that some aggregate analytics cannot reasonably be linked back to an identifiable person.
Submit a request through our contact page. We may ask for information needed to verify your identity and authority over the relevant email address or short URL. We will not discriminate against you for exercising applicable privacy rights.
10. Children
The Service is not directed to children who cannot legally consent to the processing of their information. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information improperly, contact us so we can review and take appropriate action.
11. Do Not Track
Because there is no universally accepted technical standard for browser “Do Not Track” signals, the Service does not currently respond to them. We use click information to provide the redirect, security, and analytics functions described in this Policy.
12. Changes to this Policy
We may update this Policy as the Service, law, or our practices change. We will post the updated version and revise the “Last updated” date. We will provide additional notice when required by law.
13. Contact
For privacy questions or requests, use the Yoro.cc contact page. To help us locate relevant records, include the email address or short URL involved, but do not send passwords or one-time codes.