Privacy Policy

Last updated on September 03, 2026

Effective date: 3 September 2026

This Privacy Policy explains how Secuno LLC ("Secuno", "we", "us") handles personal data in connection with zipy.app (the "Service") — our link shortening, bio page, QR code and link analytics platform.

Please read it together with our Terms of Service and our Refund & Cancellation Policy.

1. Who we are and how to reach us

  • Legal entity: Secuno LLC
  • Registered address: 30 North Gould Street, Sheridan, Wyoming 82801, United States
  • Privacy enquiries: privacy@zipy.app
  • Data Protection Officer: dpo@zipy.app
  • Legal notices: legal@zipy.app
  • Telephone: +1 (315) 961-7074

2. Scope of this policy

This policy covers the zipy.app website, the dashboard, our API, and every short link, bio page and QR code we serve. It does not cover secuno.net, which has its own policy, nor any other product Secuno operates — each carries its own.

It also does not cover the websites your short links point to. Once a visitor follows a link they are on a third party's site, governed by that party's policy, not ours.

3. The three kinds of people in this policy

Your rights differ depending on how you interact with the Service, so it helps to be precise:

  • Account holders — people who register, sign in and create links.
  • Visitors — people who browse zipy.app without an account.
  • Link recipients — people who click a short link or scan a QR code that an account holder created.

4. Controller and processor: who is responsible for what

This distinction matters and is easy to get wrong, so we state it plainly:

  • For account, billing and support data, and for the operation of zipy.app generally, Secuno LLC is the data controller.
  • For the click and scan analytics collected on an account holder's own links, that account holder is the controller and Secuno acts as their processor. If you shorten links and share them with your audience, you are responsible for having a lawful basis for that analytics collection and for telling your audience about it in your own privacy notice.

If you are subject to the GDPR and need a Data Processing Agreement, write to dpo@zipy.app.

5. What we collect

5.1 Account and profile data

Your email address, username, display name, and your password — stored only as a bcrypt hash, never in readable form. Optionally a profile picture, billing address, and the settings you choose. If you enable two-factor authentication we store the shared secret used to verify your codes.

5.2 If you sign in with Google

We receive your Google account's email address, name and profile picture, and nothing more. We never receive your Google password and request no access to your Google data beyond basic profile information.

5.3 Subscription and billing data

Your plan, its status and renewal date, your billing address, invoices, and the last four digits and brand of your payment card where the processor supplies them. We never see or store full card numbers. Payments are handled by PCI-DSS compliant processors — which may include Stripe, PayPal, Paddle, Mollie or Paystack, depending on the method you choose — who act as independent controllers for the payment itself. Bank transfers, where offered, are reconciled manually from the reference you supply.

5.4 Content you create

The destination URLs you shorten, custom aliases, link titles and notes, bio page content, QR code designs, splash and overlay pages, uploaded images, and any tracking pixels or integrations you configure.

5.5 Click and scan analytics

Each time someone opens one of your short links or scans one of your QR codes we record: the date and time, the IP address, the country and city that IP resolves to, the browser language, the browser and operating system, the referring page, and the domain the link was served from. This is what produces the statistics in your dashboard.

We do not use this data to build advertising profiles, and we do not sell it or share it with data brokers.

5.6 Technical and security data

Server logs, session identifiers, API keys and access tokens you generate, authentication and security events, and records needed to detect abuse, spam and fraud.

5.7 Support communications

Messages you send through our contact and abuse forms or by email, and our replies.

5.8 AI features

Where an AI assistant feature is enabled, the prompts and link data you submit to it are sent to the configured model provider to generate a response. We do not permit those providers to train their models on your content.

6. Legal bases for processing (GDPR)

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract — to create and run your account, serve your links, and take payment.
  • Legitimate interests — to keep the Service secure, prevent abuse and fraud, and improve the product. We balance these against your rights and interests.
  • Consent — for non-essential cookies and for marketing email. You can withdraw consent at any time.
  • Legal obligation — to keep tax and accounting records and to respond to lawful requests.

7. How we use your data

  • To provide the Service: create accounts, resolve short links, render bio pages and QR codes, and produce your analytics.
  • To bill you, manage renewals, and issue invoices and receipts.
  • To send service messages — password resets, security alerts, plan and renewal notices. These are not marketing and you cannot opt out of them while you hold an account.
  • To provide support and answer your enquiries.
  • To detect, investigate and stop abuse: malware, phishing, spam and fraud.
  • To meet our legal obligations and enforce our Terms of Service.
  • To send marketing email, only with your consent, with an unsubscribe link in every message.

8. Who we share data with

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

We share it only with:

  • Payment processors — to take payment and prevent fraud.
  • Hosting and infrastructure providers — to run the Service.
  • Email delivery providers — to send transactional and, where consented, marketing mail.
  • Google — where reCAPTCHA is enabled to block automated abuse, and where you choose Google Sign-In.
  • Security and threat intelligence services — to check destination URLs against known-malicious lists.
  • Professional advisers — lawyers, accountants and auditors, under confidentiality.
  • Authorities — where we are legally required, or to protect the rights and safety of our users or the public. We review every request and push back on overbroad ones.
  • An acquirer — if Secuno is merged, acquired, or sells assets, subject to this policy continuing to apply.

Every provider acting on our behalf is bound by contract to protect the data and to process it only on our instructions.

9. Data retention

We keep personal data only as long as we need it. Our standard operational retention period is six months.

  • Click and scan analytics: deleted within 6 months of collection by an automated daily job.
  • Server and security logs: up to 6 months.
  • Support correspondence: up to 6 months after the matter is closed.
  • Account, profile and link data: kept while your account is open. When you delete your account, this data and its analytics are removed within 30 days, except as noted below.
  • Backups: deleted data may persist in encrypted backups for up to 6 months before those backups age out.
  • Invoices, payment records and tax documents: retained for as long as tax and accounting law requires, which is longer than six months and typically seven years. We cannot delete these on request, because we are legally required to keep them.
  • Abuse records: where an account or link was suspended for malware, phishing or fraud, we keep a minimal record for as long as needed to prevent the abuse recurring.

10. Your rights

Subject to local law, you may ask us to:

  • Access the personal data we hold about you.
  • Correct data that is wrong or incomplete.
  • Delete your data (the "right to be forgotten").
  • Export it in a structured, machine-readable format.
  • Restrict or object to our processing, including profiling.
  • Withdraw consent at any time, without affecting processing already carried out.

Much of this is self-service: you can edit your profile, export your links and analytics, and delete your account from your dashboard. For anything else, write to privacy@zipy.app. We acknowledge requests within 48 hours and resolve them within 30 days. We do not charge for this and we will not treat you worse for asking.

10.1 If you are in the EEA or the UK

You have the rights above under the GDPR and UK GDPR, and you may complain to your national supervisory authority (in the UK, the Information Commissioner's Office). We would rather hear from you first.

10.2 If you are in California

Under the CCPA/CPRA you have the right to know what we collect, to access and delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA. You may use an authorised agent to make a request.

10.3 If you are elsewhere

We apply these rights to everyone, wherever you are, to the extent our systems allow.

11. International transfers

Secuno LLC is based in the United States, and your data is processed there and in the regions our infrastructure providers operate. Where we move personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with technical safeguards including encryption in transit and at rest.

12. Cookies and similar technologies

  • Strictly necessary — your session, sign-in state, and CSRF protection. The Service cannot work without these.
  • Functional — language, theme and interface preferences.
  • Analytics — aggregate usage of zipy.app itself, set only with your consent where consent is required.

We do not set advertising cookies. Note that a bio page or splash page you build may carry tracking pixels you configure; if you enable those, disclosing them to your visitors is your responsibility, not ours. You can manage cookies in your browser, though blocking the strictly necessary ones will break sign-in.

13. Do Not Track and Global Privacy Control

Browser "Do Not Track" signals have no agreed meaning and we do not act on them. We do honour Global Privacy Control (GPC) signals as a valid opt-out where law requires it.

14. Security

We protect data with TLS in transit, encryption at rest, bcrypt password hashing, optional two-factor authentication, role-based administrative access, revocable sessions and API keys, and routine patching. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority without undue delay and, where the GDPR applies, within 72 hours of becoming aware of it.

15. Children

zipy.app is intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has given us data, write to privacy@zipy.app and we will delete it.

16. Automated decision-making

We use automated checks to detect spam, malware and phishing, which can result in a link or account being suspended. This is not legally significant automated decision-making in the GDPR sense, and you can always ask a human to review a suspension by writing to legal@zipy.app.

17. Changes to this policy

We may update this policy. We will change the effective date above, and for material changes we will email account holders and post a notice on the site at least 30 days before they take effect. Continuing to use the Service after that means you accept the updated policy.

18. Contact

Privacy questions and data requests: privacy@zipy.app
Data Protection Officer: dpo@zipy.app
Postal: Secuno LLC, 30 North Gould Street, Sheridan, Wyoming 82801, United States