Legal
Privacy Policy
Effective date: August 9, 2026 · Last updated: August 9, 2026
This Privacy Policy explains how Yoro.cc (“Yoro.cc,” “we,” “us,” or “our”) collects, uses, retains, and shares information when you create or visit a short URL, use analytics or account features, or contact us.
1. Scope and controller
This Policy applies to the Yoro.cc website, short-link redirects, related APIs, emails, and analytics features. Yoro.cc’s service operator is responsible for the processing described here. You can reach us through the contact page.
This Policy does not govern a destination website reached through a Yoro.cc link. The destination operator’s own privacy terms apply after you leave our Service.
2. Information we collect
Information you provide
- Short-link information: the destination URL, generated short code, password-protection setting, and associated service metadata.
- Account and verification information: email address, verification status, one-time login challenge information, and authentication/session records.
- Access credentials: a short-URL password or private analytics token may be stored with the URL record for compatibility with the existing service. Read-through cache entries contain only a one-way hash of that credential. Do not reuse a password that you use for another service.
- Communications: your email address, name, message, and any details you submit through the contact form or in an abuse request.
Information collected when a short URL is visited
We process the short code, click time, IP address, country code, browser name and version, operating-system name and version, device type, bot indicator, and the referrer hostname and registrable domain when available.
For clicks handled by the current Yoro.cc analytics system, we extract limited fields and do not retain the complete User-Agent string or complete referrer URL in the formal click log. The raw IP address is retained only in that short-lived formal click log. During the migration period, reports may also include normalized aggregate data read from a legacy analytics system.
Information collected automatically
We may receive standard request and security information such as timestamps, requested paths, response status, IP address, proxy headers from trusted infrastructure, CAPTCHA results, and rate-limit signals. Essential cookies or similar storage may be used for signed-in sessions, security, and interface preferences such as color mode.
3. How we use information
- create, resolve, redirect, password-protect, and manage short URLs;
- verify email addresses, send one-time login codes, maintain sessions, and respond to messages;
- produce “today” and “this month” analytics, including approximate time, country, browser, and referrer statistics;
- detect bots, prevent fraud, phishing, malware, spam, and other abuse, and enforce our Terms of Service;
- operate, troubleshoot, secure, monitor, and improve the Service; and
- comply with law, protect users and the public, and establish or defend legal claims.
4. Legal bases
Where data-protection law requires a legal basis, we rely on performance of a contract or steps you request before entering one; our legitimate interests in operating, securing, and improving the Service; compliance with legal obligations; and consent where the law requires it. You may withdraw consent at any time, without affecting processing already performed.
5. Analytics and retention
- Formal click logs: scheduled to expire 30 days after the click. These logs contain the raw IP address and processed device, browser, country, and referrer fields.
- 15-minute analytics: scheduled to expire 45 days after the relevant time bucket, including the separate high-cardinality referrer dimensions used for current-period reports.
- Daily and lifetime aggregate statistics: no scheduled expiration. These aggregates do not contain raw IP addresses or full User-Agent strings.
- Account and short-link records: retained while needed to provide, secure, and administer the Service, resolve disputes, and meet legal requirements.
- Authentication, contact, operational, and security records: retained only as long as reasonably needed for their purpose, subject to backup cycles and legal obligations.
Expiration is not instantaneous. Database cleanup jobs run periodically, and residual copies may remain temporarily in encrypted or access-controlled backups until those backups rotate.
6. How we share information
We do not sell personal information. We may share limited information:
- with hosting, database, email-delivery, CAPTCHA, network, geolocation, monitoring, and other vendors that process information for us under appropriate instructions;
- with a destination website when a visitor follows a short URL, as the visitor’s browser makes the destination request;
- when required by law or reasonably necessary to respond to lawful process, investigate abuse, protect rights or safety, or prevent fraud and security incidents; and
- in connection with a merger, financing, reorganization, sale, or transfer of all or part of the Service, subject to applicable law.
Some providers may process information in countries other than yours. Where required, we use recognized safeguards for international transfers.
7. Public links and analytics access
A short URL may be shared publicly and can reveal its destination to anyone who follows it. Anyone who obtains an analytics link, token, account session, or short-URL password may be able to access the associated feature. Do not place confidential or sensitive personal information in a destination URL, including its path or query string.
8. Security
We use administrative, technical, and organizational measures designed to protect information, including access restrictions, transport encryption, secret hashing, limited retention, and service isolation. No online service is completely secure, and we cannot guarantee that information will never be accessed, lost, altered, or disclosed without authorization.
9. Your rights and choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a data-protection authority. These rights may be limited by law, security needs, the rights of others, and the fact that some aggregate analytics cannot reasonably be linked back to an identifiable person.
Submit a request through our contact page. We may ask for information needed to verify your identity and authority over the relevant email address or short URL. We will not discriminate against you for exercising applicable privacy rights.
10. Children
The Service is not directed to children who cannot legally consent to the processing of their information. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information improperly, contact us so we can review and take appropriate action.
11. Do Not Track
Because there is no universally accepted technical standard for browser “Do Not Track” signals, the Service does not currently respond to them. We use click information to provide the redirect, security, and analytics functions described in this Policy.
12. Changes to this Policy
We may update this Policy as the Service, law, or our practices change. We will post the updated version and revise the “Last updated” date. We will provide additional notice when required by law.
13. Contact
For privacy questions or requests, use the Yoro.cc contact page. To help us locate relevant records, include the email address or short URL involved, but do not send passwords or one-time codes.