Data Retention & Deletion Policy
URly / urly.tr
Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]
This Policy establishes general retention targets for categories of information. These are not guarantees of exact automatic deletion dates.
1. Account information
While active and generally up to 12 months after deletion/closure.
2. Deleted account records
Generally up to 12 months after deletion, subject to legal, security and dispute exceptions.
3. Short Links and destination records
While active and generally up to 12 months after deactivation/deletion where applicable.
4. Click/access logs
Generally up to 12 months.
5. IP/device/browser/OS/language
Generally up to 12 months.
6. Security and abuse logs
Generally up to 24 months.
7. Fraud/phishing/malware enforcement records
Generally up to 24 months.
8. Abuse reports
Generally up to 24 months.
9. Legal requests and records
For the duration of the relevant legal matter and as long as reasonably necessary afterward.
10. Aggregated/de-identified data
May be retained longer where it no longer constitutes personal data under applicable law.
11. Anonymous Short Links
Current anonymous Short Links may expire after 30 days of inactivity under product rules.
12. Legal hold
Data may be preserved beyond ordinary retention when necessary for litigation, legal process, investigations, disputes or regulatory requirements.
13. Security incidents
Relevant records may be retained longer where necessary to investigate, remediate and document a security incident.
14. Backups
Backups may retain information beyond primary-system deletion schedules for a limited operational period and may not be individually erasable immediately.
15. Deletion requests
Requests may be submitted to legal@urly.tr. Deletion does not override information that must lawfully be retained.
Creator IP
The IP address associated with creation of a Short Link (urls.creator_ip) is retained strictly for security, abuse prevention, and legal compliance. In accordance with automated retention sweeps:
- For active Short Links, creator IP is retained for up to 12 months (365 days) from creation, after which it is automatically and irreversibly anonymized (set to NULL).
- For deleted or expired Short Links, creator IP is retained for an abuse dispute window of up to 90 days, after which it is automatically set to NULL.
IP geolocation cache
IP geolocation cache records (ip_geo_cache) are retained for a maximum of 12 months (365 days) or automatically cleared when orphaned, ensuring no indefinite retention of cached location mappings.
Support tickets
Support and communication records (support_tickets) are retained strictly according to operational necessity and applicable legal dispute periods:
- Unverified pending requests (status = pending_verification): Automatically purged after 14 days if email confirmation is not completed.
- IP addresses: IP addresses associated with support submissions are retained for up to 90 days for abuse prevention and fraud screening, then automatically anonymized (set to NULL).
- Resolved/closed records and inquiries: Retained for up to 3 years from creation to facilitate quality assurance, dispute resolution, consumer inquiries, and statutory limitation periods under applicable law, after which all ticket messages, user details, and responses are permanently deleted.
API applications
Developer API records (api_applications) are retained strictly in accordance with security lifecycle and operational needs:
- Active API credentials: Retained while the application is active and valid to enable programmatic link shortening and analytics services.
- Application IP addresses: IP addresses recorded at application submission are retained for 90 days for abuse prevention and developer verification, then automatically anonymized (set to NULL).
- Rejected applications: Retained for 90 days following review to allow for applicant inquiries and appeals, after which all project details and reasons are permanently deleted.
- Disabled/inactive credentials: Keys revoked, marked inactive, or unused for more than 12 months (365 days) are automatically purged.
- Orphaned applications: Applications linked to deleted user accounts are immediately deleted during automated account purge cycles.
Rate-limit records
Rate-limit records (rate_limits) are retained strictly for operational security and automated abuse mitigation (rate limiting and brute-force prevention). Expired rate-limit windows are automatically purged 1 day (24 hours) after expiration.
Referrer minimization
Where referrer information is stored (clicks_log.referer), URLy automatically sanitizes and minimizes incoming referrers at the point of ingestion. Query strings (?token=..., ?email=...) and fragments (#...) are strictly stripped to prevent accidental retention of sensitive parameters or personally identifiable information (PII). In addition, automated retention sweeps retroactively sanitize historical referrer records, and the outbound Referrer-Policy header is configured to protect visitors upon redirection.
Deletion versus anonymization
Information that is irreversibly aggregated or de-identified may no longer be treated as personal data, subject to applicable law and the quality of the de-identification.
Legal hold
A legal hold may suspend ordinary deletion for specific records. The hold should be limited to relevant information and removed when no longer necessary.
Backups
Backup retention should be documented separately so that deletion requests and incident-response obligations can be reconciled with backup architecture.
Review cadence
Retention schedules should be reviewed periodically against actual database cleanup jobs and application behavior.