Privacy Policy for theshortener.com
Last updated: August 31, 2026
1. Overview
theshortener.com ("we", "our", "us") provides URL shortening, QR-code, analytics, API, browser-extension, and related services. This Privacy Policy explains what information we collect, why we use it, how long we keep it, and how you can request access, correction, or deletion.
This policy covers the general TheShortener service and the embedded TheShortener Links Shopify app. The Shopify app has a narrower data boundary than the general service: it uses read-only product access to create a product-linked short URL and QR asset.
We comply with applicable privacy requirements and relevant platform policies, including the Google Chrome Web Store User Data Policy (Limited Use requirements), Google, X, and Facebook login requirements where those options are enabled, and Shopify App Store privacy requirements.
2. Information We Collect
2.1 Account Registration and Authentication
Some TheShortener features require an account. Depending on the service you use, we may collect:
- Email address for account identification and communication
- Authentication credentials, stored securely and not in plain text
- API keys generated for an account
- Login and security-session information
API keys are used to authenticate requests made to our API and browser extensions. The embedded TheShortener Links Shopify app does not require a separate TheShortener account; Shopify merchants use Shopify authentication for that app.
2.2 Third-Party Authentication
Depending on which sign-in options are enabled for your account, Google, X, or Facebook may provide information authorized through that login, such as:
- Provider user ID
- Username, display name, or name
- Profile image
- Email address, if the provider provides it
We use this information for authentication, account creation, identification, login, and account management. We do not access provider content or settings that are not required for authentication, and we do not post, message, or take other actions on your behalf.
Removing TheShortener from a provider's connected-app settings disconnects that provider login. It does not by itself delete the associated TheShortener account or the data held by TheShortener. Account deletion is described on our Data Deletion page.
2.3 URLs, Short Links, and QR Usage
When you use the website or API, we may process:
- URLs submitted for shortening
- Short-link aliases and identifiers
- QR-code asset identifiers and generated files
- Request counts, timestamps, and service status
We use this information to create and deliver the requested short links and QR codes, provide analytics, prevent abuse, and operate the Service.
2.4 Link and QR Analytics
When a person follows a short link or scans a QR code that resolves through a TheShortener redirect, the core service may record an event associated with that destination. Depending on configuration, the event may include:
- Short-link or QR identifier and event timestamp
- Referrer and referring domain
- Approximate country and city
- Device, operating system, browser, and two-character language information
- The visitor IP address or a derived hash of it, depending on the service configuration
This data is used to deliver the redirect, count clicks or scans, show analytics to the account owner, and prevent abuse. A QR scan is normally measured as a visit to the linked destination; the app does not identify a person by name merely because that person scanned a code.
2.5 TheShortener Links Shopify App
TheShortener Links is an embedded Shopify app for merchants. The current Shopify version requests the read-only read_products scope. It reads product identity and Online Store publication information so a merchant can select a published product and create a destination link and print-safe QR asset.
When a merchant installs or uses the app, we may process:
- The Shopify shop domain and a stable shop-scoped identifier
- Shopify installation and authentication-session information
- An administrator ID, name, or email address when Shopify provides it for authentication or session management
- Published product information such as product ID, title, handle, storefront URL, and publication or status information
- Merchant-provided asset metadata such as channel, asset name, optional custom alias, generated link and QR identifiers, short/QR URLs, status, and timestamps
The app sends the selected product destination and the necessary product and asset metadata to the protected TheShortener API to create and manage the requested short link and QR asset. Shopify authentication credentials are handled server-side and are not used for advertising or external analytics.
The app does not request or access Shopify customer records, customer contact details, orders, checkout data, payment information, billing information, POS data, or other protected customer data. It does not collect customer names, emails, postal addresses, or phone numbers through the Shopify app.
The embedded Shopify app does not currently send its limited interface events to Google Analytics, BigQuery, Cloudflare Analytics, advertising pixels, or another external analytics provider. Product selection and asset copy or download events, where used, support the app experience only. Link and QR usage analytics are handled by the separate core TheShortener redirect service described in Section 2.4.
2.6 Cookies and Similar Technologies
We may use necessary cookies or equivalent session mechanisms for login, session security, CSRF protection, redirect anti-flood controls, and recognizing repeat visits for unique-click measurement. The embedded Shopify app does not use advertising cookies or tracking pixels to profile merchants or their customers. See our Cookie Policy for additional details.
2.7 Information We Do Not Collect Through the Shopify App
TheShortener Links does not collect through its Shopify integration:
- Shopify customer records or customer contact details
- Orders, checkout, payment, billing, or POS information
- Health or medical data
- Personal communications
- Keystrokes or mouse-movement tracking
- Precise GPS or continuous location data
2.8 Paid Plans and Billing Information
If you choose a paid plan or other paid feature, we and the payment provider may process information needed to complete and support the transaction, such as:
- Plan, subscription, checkout, transaction, renewal, and cancellation details
- Amounts, currency, dates, and payment-related identifiers or status
- Name, email address, billing country, postal code, and other billing details requested at checkout
The payment provider handles payment-instrument details through its checkout and may retain payment and transaction records under its own privacy policy and legal obligations. TheShortener does not need your full card or bank credentials to provide the service. This billing disclosure is separate from the Shopify app boundary: the Shopify app does not request Shopify customer, order, checkout, payment, or billing data.
3. How We Use Information
We use information only as needed to:
- Create and manage accounts and authentication sessions
- Authenticate API and extension requests
- Generate and manage short links and QR assets
- Connect an eligible Shopify product to a short link and QR asset
- Deliver redirects and provide link or QR analytics
- Provision, renew, cancel, and support paid plans and related billing records
- Prevent spam, abuse, fraud, and security incidents
- Maintain, secure, troubleshoot, and improve the Service
- Comply with legal obligations and enforce our terms
We do not sell personal data or use the Shopify app data for unrelated advertising or profiling.
4. Data Sharing and Service Providers
We do not sell, rent, or trade personal data. We may share or process the minimum information necessary with:
- Shopify, when needed to authenticate and operate the Shopify app
- TheShortener hosting, storage/CDN, email, authentication, and security providers that help us operate the Service
- A third-party payment provider, when needed to process a paid plan, payment, renewal, refund, cancellation, or related support request
- Authorities or other parties when required by law or necessary to protect the security, integrity, or rights of the Service
- A successor in connection with a merger, acquisition, or asset transfer
The Shopify workflow routes product and asset information between Shopify, the protected Shopify connector, and the core TheShortener API. Providers may process information in the countries where their infrastructure operates. We use reasonable contractual, technical, and access controls for those processing activities.
5. Chrome Extension Limited-Use Disclosure
The TheShortener browser extension:
- Reads the active tab URL only when you explicitly initiate a shortening action
- Uses the API key stored by the extension only to authenticate requested API calls
- Does not monitor browsing activity outside its requested function
- Does not share accessed data for advertising or unrelated analytics
Extension data is used only to provide the feature requested by the user and is not used for creditworthiness, lending, or other unrelated decisions.
6. Retention and Deletion
We retain information only for the period needed for the purpose described below, legal obligations, security, abuse prevention, and reliable operation. Retention can vary by service, account settings, and plan:
- Shopify authentication sessions are retained while the installation needs them and are removed through the uninstall or authenticated shop-redaction process.
- Shopify product-to-asset mappings are retained while needed to provide the app and are removed through authenticated shop redaction.
- App-created short-link and QR records, including the generated QR object, are removed when the associated asset is deleted through the authenticated deletion process or when Shopify shop redaction requires their removal.
- Click and scan analytics follow the applicable core TheShortener service retention setting and are removed with the associated link or QR records. The Shopify app does not create a separate longer analytics-retention period.
- Security and operational logs, and limited backup copies, may remain for a limited operational, security, legal, or recovery period after primary records are removed. They are access-controlled and are not used for advertising.
Deletion of an app-created short link or QR asset can make its destination stop working, including a QR code already printed on packaging, signs, or other materials. Merchants should confirm which destinations may be retired before requesting deletion. If a new alias or destination is needed while an old printed QR must continue working, create a new asset and keep the old asset active where operationally appropriate.
When the Shopify app is uninstalled, active Shopify authentication sessions are removed. When Shopify sends an authenticated shop-redaction request, the connector removes the shop-scoped mappings and requests deletion of the associated core short links, QR records, and generated QR files. The app does not store Shopify customer records, so the customer-data request and customer-redaction handlers have no customer record to export or delete.
For general TheShortener accounts, users may request deletion at any time. The account-deletion workflow removes the account and associated primary service records it can identify, which may include authentication data, API keys, links, QR records, profiles, integrations, and associated analytics. Generated files and provider-side records may follow a separate storage or provider lifecycle. Payment, tax, dispute, fraud-prevention, security, operational, legal, and limited backup records may remain for the period needed for those purposes.
Removing third-party login access is not a substitute for deleting a TheShortener account. See the Data Deletion page for the available account and support steps.
7. Security
We use reasonable technical and organizational safeguards, including:
- HTTPS for supported public and API endpoints
- Server-side handling of authentication credentials
- Access controls and least-privilege API scopes
- Secure API-key generation and revocation
- Monitoring, backups, and recovery procedures appropriate to the Service
No system is completely secure, but we take reasonable steps to protect information against unauthorized access, loss, misuse, or alteration.
8. Your Rights and Requests
Depending on applicable law, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate information
- Request deletion or restriction of processing
- Revoke API keys or third-party login access
- Request deletion of Shopify app data associated with a shop
To make a request, email [email protected] or use the contact page. We may need to verify ownership of the account or Shopify shop before disclosing or changing account-specific data. Do not send passwords, API keys, access tokens, cookies, or payment information in a request. Account-deletion steps are also available at https://theshortener.com/page/data-deletion.
9. Changes to This Policy
We may update this Privacy Policy when our services, data practices, or legal requirements change. The current version and revision date will be posted on this public page.
10. Contact Information
Privacy and data requests: [email protected]
Website: https://theshortener.com
This policy describes current service behavior and is not legal advice.