URly / urly.tr
COMPLETE FINAL LEGAL, PRIVACY, SECURITY & TRUST PACKAGE
Authoritative English base • Comprehensive version • Effective date placeholders intentionally retained
Support: support@urly.tr • Abuse/Security: abuse@urly.tr • Legal/Privacy/IP: legal@urly.tr
Primary infrastructure: Türkiye • Governing law: Republic of Türkiye • Jurisdiction: competent courts and enforcement offices of Konya, Türkiye
Document set
1. 01 Terms of Service
2. 02 Acceptable Use Policy
3. 03 Global Privacy Policy
4. 04 Cookie Policy
5. 05 Abuse Reporting
6. 06 Retention Deletion
7. 07 Security Policy
8. 08 Copyright Takedown
9. 09 Law Enforcement
10. 10 KVKK Aydinlatma
11. 11 GDPR EEA UK
12. 12 Child Safety
13. 13 Data Subject Request
14. 14 Subprocessors
15. 15 Vulnerability Disclosure
16. 16 Freedom Content Moderation
17. 17 Transparency Report
18. 18 Security Page
19. 19 security txt
20. 20 Privacy Request Form
21. 21 Abuse Report Form
22. 22 Copyright Trademark Form
1. 01 Terms of Service
These Terms govern access to and use of URLy, including its website, Short Links, link-management features, analytics, API and related services.
1. Acceptance and scope
By creating an account, creating or accessing a Short Link, using the API, or otherwise using the Service, you agree to these Terms and the policies incorporated into them.
2. Definitions
“Service” means URLy websites, applications, APIs, Short Links, link-management and related functionality. “Short Link” means a shortened URL generated or managed by URLy. “Destination URL” means the URL to which a Short Link directs. “User Content” means URLs, titles, descriptions, account information and other material submitted by a user.
3. Eligibility
You must be legally capable of entering into these Terms and must comply with applicable law. If acting for an organization, you represent that you have authority to bind it.
4. Accounts and credentials
You must provide accurate information and keep credentials, authentication codes and API keys confidential. You are responsible for activity performed through your account unless caused by URLy’s own breach or another circumstance for which applicable law imposes responsibility on URLy.
5. Creating and using Short Links
You may create Short Links only for lawful and legitimate purposes. You must have the right to submit the Destination URL and any associated content. You must not use URLy to conceal unlawful activity or evade enforcement by another service.
6. Link ownership and deletion
URLy may retain, restrict, expire or delete Short Links according to applicable product rules, security needs, legal obligations and retention policies. Anonymous Short Links may be subject to a 30-day inactivity expiry rule.
7. Prohibited use
The following are prohibited: phishing, credential theft, malware, ransomware, spyware, fraud, scams, illegal drug activity, unlawful gambling, weapons or explosives trafficking, terrorism or violent-extremism facilitation, child sexual exploitation, grooming, non-consensual sexual content, trafficking, stolen accounts or financial data, counterfeit or piracy operations, impersonation, doxxing, harassment, extortion, illegal marketplaces, security-control circumvention, malicious automation and spam.
8. Slug protection
URLy may protect brand names, aliases, variants, typosquats, confusable forms, system terms, sensitive terms and security-sensitive identifiers. Slug Protection decisions are ALLOW, REVIEW, RESERVED or BLOCK. RESERVED is an identifier-protection state and is distinct from content RESTRICT enforcement.
9. Destination safety and moderation
URLy may use automated and human review to assess suspicious destinations, domains, accounts and activity. Content/abuse decisions may be ALLOW, REVIEW, RESTRICT or BLOCK.
10. Security measures
URLy may rate-limit requests, log security events, restrict suspicious activity, suspend accounts and disable Short Links where reasonably necessary to protect users, third parties or the Service.
11. Suspension and termination
URLy may suspend or terminate accounts, API access or Short Links for policy violations, security risks, legal requirements, fraud, repeated abuse or other legitimate enforcement reasons. Where appropriate and legally permitted, users may request review.
12. Third-party destinations
URLy is not the creator or publisher of content hosted at third-party destinations and does not generally control that content. URLy may nevertheless restrict or disable Short Links where required by law or reasonably necessary under its policies.
13. Intellectual property
URLy software, branding, documentation and original Service materials belong to or are licensed by Firma Life. These Terms do not transfer ownership of URLy intellectual property.
14. User content
You retain rights you have in your submitted material, subject to the rights necessary for URLy to operate the Service. You grant URLy the limited rights necessary to host, process, redirect, secure, analyze and display your submitted information as part of the Service.
15. Privacy
Personal-data processing is described in the Global Privacy Policy, Cookie Policy, KVKK Privacy Notice and GDPR / EEA & UK Privacy Notice where applicable.
16. Service availability
URLy is provided on an as-available basis. We do not guarantee uninterrupted availability, permanent retention of every Short Link, error-free operation or detection of every harmful destination.
17. Disclaimer
To the maximum extent permitted by law, URLy disclaims warranties not expressly required by applicable law, including implied warranties concerning uninterrupted availability, fitness for a particular purpose or complete security.
18. Limitation of liability
To the maximum extent permitted by law, Firma Life is not liable for indirect, incidental, special, consequential or punitive losses arising from use of the Service. Nothing excludes liability that cannot lawfully be excluded.
19. Indemnification
To the extent permitted by law, you agree to defend and indemnify Firma Life against claims, losses and reasonable costs arising from your unlawful use of the Service, violation of these Terms or infringement of third-party rights.
20. Abuse, legal and IP reports
Reports may be submitted to abuse@urly.tr. Privacy, copyright, trademark and formal legal matters may be submitted to legal@urly.tr.
21. Changes
We may update these Terms as the Service, law or security requirements change. Material changes may be communicated through the Service or other appropriate means.
22. Severability and entire agreement
If a provision is unenforceable, the remainder remains effective to the extent permitted by law. These Terms and incorporated policies form the agreement governing use of the Service.
Legal entity and contact
URLy is operated by Firma Life. Registered address: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye. General support is available at support@urly.tr; abuse and security reports at abuse@urly.tr; legal, privacy, copyright and trademark matters at legal@urly.tr.
Governing law
Unless mandatory law provides otherwise, the laws of the Republic of Türkiye govern. The competent courts and enforcement offices of Konya, Türkiye have jurisdiction, subject to mandatory rights and jurisdictional rules that cannot lawfully be waived.
Accounts, verification and security
URLy may require email verification, security checks, CAPTCHA or other verification mechanisms where implemented. Users must promptly notify URLy of suspected unauthorized access. URLy may require password resets, API-key rotation or other protective measures following a suspected compromise. A user must not attempt to access another user’s account, session or API credentials.
API use
API access is subject to documented limits and may be suspended when traffic is abusive, anomalous, automated in a harmful manner or inconsistent with the stated purpose of an API application. API keys are confidential credentials and must not be embedded in publicly accessible client-side code when doing so would expose them.
Link analytics
Click and access analytics may be affected by browsers, privacy tools, caching, bots, security scanners, corporate proxies and other technical conditions. Analytics are therefore estimates and should not be interpreted as guaranteed unique-person measurements.
Passwords and protected links
Where URLy offers password-protected Short Links, the password is an additional access control and does not make an otherwise unlawful destination permissible. Users remain responsible for the Destination URL.
Expiration and limits
Short Links may be subject to expiration dates, click limits, account quotas, inactivity rules or other product constraints. URLy may change operational limits for security, capacity or abuse-prevention reasons.
Brand and reserved identifiers
A user may not claim a reserved slug merely because it is technically available. URLy may reserve identifiers to reduce impersonation, confusion, abuse or trademark-related risk.
Third-party services
A Short Link may redirect to a service that has its own terms, privacy practices, cookies and security risks. Users should evaluate destinations before entering credentials or personal information.
Notices and communications
URLy may send transactional communications concerning verification, security, account status, policy enforcement, legal requests and service operation. Users may not disable communications that are necessary for security or legal compliance.
User cooperation
Users must reasonably cooperate with investigations concerning abuse, security incidents, legal process or rights complaints. Failure to cooperate may result in temporary restriction where reasonably necessary.
Survival
Provisions concerning intellectual property, privacy, liability, indemnification, dispute resolution, legal compliance and records that by their nature should survive termination will survive termination.
2. 02 Acceptable Use Policy
This Policy establishes prohibited, restricted and reviewable uses of URLy. It is intended to protect users, third parties, URLy infrastructure and the integrity of Short Links.
1. General rule
You may not use URLy to facilitate unlawful conduct, deception, serious harm, security abuse or activity that materially threatens the Service.
2. Phishing and credential theft
Fake login pages designed to capture passwords, MFA codes, session tokens or recovery codes.
Credential harvesting, authentication bypass or account-takeover campaigns.
Brand or service impersonation intended to collect credentials.
3. Fraud and scams
Investment, payment, romance, employment, delivery, tax, refund or support scams.
Advance-fee fraud, fake invoices, deceptive fundraising or impersonation of financial institutions.
Fraudulent acquisition or sale of personal or financial information.
4. Malware and malicious code
Malware, ransomware, spyware, keyloggers and destructive payloads.
Malicious download pages and drive-by exploitation.
Infrastructure intended to distribute or control malware.
5. Cyber abuse
Unauthorized access, credential stuffing, exploit delivery or persistence.
Botnet command-and-control, malicious scanning or evasion of security controls.
Links designed to facilitate unauthorized intrusion or theft.
6. Spam and automation
Unsolicited bulk messaging and malicious campaigns.
Automated abuse of link creation, analytics or referral systems.
Activity intended to overload, degrade or circumvent Service controls.
7. Drugs and controlled substances
Illegal sale, trafficking or facilitation of controlled substances is prohibited. Legitimate educational, medical, scientific or recovery-related discussion may be reviewed in context.
8. Gambling and betting
Unlawful gambling, betting, casino operations or deceptive gambling schemes are prohibited. Legitimate informational content may be reviewed in context.
9. Weapons and explosives
Illegal sales or facilitation involving weapons, explosives or other prohibited weapons are not permitted. Lawful informational, journalistic or educational material may be considered in context.
10. Terrorism and violent extremism
Content or activity that materially facilitates terrorism, violent extremist recruitment, operational support, financing or violent wrongdoing is prohibited. Neutral reporting, research and historical discussion may be treated differently based on context.
11. Child safety
CSAM, grooming, sexual solicitation of minors, sexualized content involving minors, trafficking and exploitation are prohibited and may trigger immediate restriction and preservation.
12. Sexual exploitation
Non-consensual intimate material, sexual extortion, trafficking and exploitative sexual services are prohibited.
13. Stolen accounts and financial information
The sale or distribution of stolen accounts, credentials, payment-card data, authentication tokens or unlawfully obtained financial information is prohibited.
14. Counterfeit and piracy
Counterfeit goods, deliberate piracy operations and intentional infringement facilitation are prohibited.
15. Impersonation
Deceptive impersonation of brands, governments, law enforcement, financial institutions, employers, public officials or other entities is prohibited where intended to mislead or cause harm.
16. Privacy abuse
Doxxing, unlawful disclosure of personal data, stalking, targeted harassment and publication of sensitive information for malicious purposes are prohibited.
17. Harassment, threats and extortion
Threats, coercion, blackmail, extortion and targeted abusive campaigns are prohibited.
18. Illegal marketplaces
URLy may restrict Short Links that facilitate unlawful marketplaces or transactions.
19. Security-control circumvention
Attempting to evade slug protection, moderation, rate limits, account suspension, authentication or other security controls is prohibited.
20. Context and exceptions
Journalism, research, education, public-interest reporting and legitimate security work may be considered in context. Context does not authorize unlawful conduct.
21. Enforcement
Moderation may result in ALLOW, REVIEW, RESTRICT or BLOCK. Actions may include link restriction, account suspension, API restriction, deletion or other reasonable measures.
22. False reports and appeals
Knowingly false reports may result in enforcement. Users may request reconsideration where a review channel is available.
23. No guarantee
Detection systems are imperfect. A violation may evade detection and legitimate activity may be flagged for review.
High-risk commercial combinations
Certain combinations of terms, domains, destinations and behaviors may be treated as higher risk than isolated words. For example, a general medical term may be permissible while a combination suggesting illicit sale, credential theft, malware delivery or fraudulent acquisition may trigger review or restriction.
Medical and recovery context
Medical, pharmaceutical, addiction-recovery, academic and public-health discussion is not automatically prohibited. Enforcement should distinguish legitimate informational context from unlawful sale, trafficking, counterfeit medicine or deceptive medical claims.
Financial abuse
URLy may restrict links that impersonate banks, payment providers, tax authorities, investment platforms, exchanges or financial professionals where the purpose is deception, credential collection or financial theft.
Government impersonation
Use of official names, logos or language is not automatically prohibited. The risk arises where a Short Link is designed to make users believe they are interacting with an official government or law-enforcement service when they are not.
Adult content
Adult content involving consenting adults may be subject to product, legal or hosting restrictions. Any sexual content involving minors, coercion, trafficking or non-consensual intimate material is prohibited.
Security research
Good-faith security research may be permitted when it does not facilitate real-world harm, unauthorized access or distribution of malicious payloads. Researchers should use the Vulnerability Disclosure Policy.
Copyright context
News reporting, criticism, quotation, education and other lawful uses may require contextual review. A complaint alone does not automatically establish infringement.
Domain reputation
A domain may receive elevated risk because of known abuse signals, suspicious infrastructure, repeated reports or security intelligence. Domain reputation is a risk signal, not by itself a legal finding.
Evasion and obfuscation
Attempts to evade filters through Unicode confusables, homographs, punctuation, spacing, encoding, transliteration or repeated account creation may be treated as aggravating factors.
Enforcement records
URLy may retain limited enforcement and abuse records as described in the retention policy so that repeated abuse can be identified and lawful investigations can be supported.
3. 03 Global Privacy Policy
This Policy explains what information URLy processes, why it is processed, how it is protected, when it may be shared and how users can exercise privacy rights.
1. Controller
URLy is operated by Firma Life. Registered address: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.
2. Information collected
Account and authentication information.
User-submitted URLs, Short Link metadata and API information.
IP address and approximate IP-derived country/region/city.
Browser, browser language, operating system, device type, access time and available referrer information.
Click/access information and link analytics.
Support, abuse, security, moderation and legal-request records.
3. Approximate location
IP-based location is approximate and is not precise GPS location.
4. Local IP geolocation processing
URLy resolves approximate geolocation locally on-premise using encrypted edge headers and local databases. IP addresses are NOT transmitted to third-party IP geolocation API providers (ip-api.com has been decommissioned). Approximate location is limited to country/region/city and is never precise GPS tracking.
5. Purposes
Providing and maintaining the Service.
Account and Short Link management.
Analytics and operational measurement.
Security, fraud and abuse prevention.
Phishing, malware and suspicious-domain detection.
Customer support and legal/rights requests.
Compliance with applicable law and valid legal process.
Service reliability and improvement.
6. Legal bases
Depending on the jurisdiction, processing may rely on contract, legal obligation, legitimate interests, consent or another lawful basis.
7. Analytics and advertising
URLy does not currently use third-party advertising or third-party analytics platforms for user tracking. URLy’s own infrastructure may process technical and click/access information for service analytics, security and abuse prevention.
8. Cookies
See the Cookie Policy. Essential session, authentication, security and preference technologies may be used.
9. Sharing
Data may be shared with processors, service providers, authorities where legally required or authorized, and other parties where necessary to protect rights, safety or the Service. URLy does not sell personal data.
10. International transfers
Primary infrastructure is in Türkiye. Certain processors, including the current IP-geolocation provider, may process data outside Türkiye. Where law requires transfer safeguards, appropriate lawful mechanisms and safeguards will be used.
11. Retention
General retention targets are described in the Data Retention & Deletion Policy. Exact deletion dates may vary because of legal holds, security investigations, disputes, backups and other lawful exceptions.
12. Security
URLy supports TLS 1.2/1.3, disables legacy SSL/TLS, uses modern authenticated encryption cipher suites, supports forward secrecy and X25519MLKEM768, and has received an A rating in Qualys SSL Labs testing for the primary endpoint. No security system can guarantee absolute protection.
13. Rights
Depending on applicable law, users may have rights to access, correct, delete, restrict, object, obtain portability, withdraw consent and challenge certain automated decisions.
14. Children
URLy prohibits child sexual exploitation and related abuse. Reports should be sent to abuse@urly.tr.
15. Third-party destinations
Destination websites have their own privacy practices. URLy does not generally control their content or privacy practices.
16. Changes
This Policy may be updated when practices, law or the Service changes.
Account and authentication records
Account records may include email address, verification state, password hash, password-reset or email-change tokens, account status, language preference, API-related identifiers and security timestamps. Passwords should be stored as hashes rather than plaintext.
Support and communications
When users contact support, URLy may process the name, email address, subject, message, attachments or verification information necessary to answer the request.
API applications
API application records may include project name, purpose, domain, associated account, API key metadata and source IP. These records may be used for approval, security, abuse prevention and support.
Security and abuse logs
Security records may include event type, timestamps, IP address, account or Short Link identifiers, rule identifiers, risk scores and enforcement outcomes. Access to these records should be restricted.
Referrer information
Where HTTP referrer information is collected, it may contain information supplied by the browser. URLy should minimize unnecessary query-string or fragment data where technically feasible because referrer URLs can contain sensitive information.
IP handling
IP addresses are used for security, abuse prevention, rate limiting, operational analytics and approximate geolocation. An IP address can be personal data under applicable law.
Data minimization
URLy seeks to process information that is reasonably necessary for the purposes described in this Policy. Users should avoid submitting unnecessary sensitive personal data.
Legal requests
When legally compelled or authorized, URLy may disclose relevant records. It will not promise to produce information it does not possess.
Changes in providers
If URLy adds analytics, advertising, security, geolocation, hosting or other providers that materially affect personal-data processing, privacy disclosures should be reviewed and updated.
Data breach response
URLy may investigate suspected personal-data breaches, contain affected systems, preserve evidence and make notifications required by applicable law.
4. 04 Cookie Policy
This Policy describes cookies and similar technologies used by URLy.
1. Essential cookies
URLy may use session and authentication cookies, CSRF/security-related session state and language or preference cookies.
2. Persistent technologies
Some preferences may be stored beyond a single session where needed for functionality.
3. Third-party tracking
URLy does not currently use Google Analytics, third-party advertising pixels or comparable third-party cross-site advertising/tracking platforms for user tracking.
4. Server-side analytics
URLy may process access and click information through its own infrastructure. Server-side analytics is not itself a browser cookie.
5. Browser controls
Users can disable or delete cookies through browser settings. Essential functionality may stop working.
6. Do Not Track
Do Not Track is not standardized across all environments; URLy does not promise a particular technical response to every DNT signal.
7. Future changes
If non-essential third-party tracking or advertising is introduced, this Policy and any required consent mechanism will be updated.
Session lifecycle
Session cookies may expire when a session ends or after a security timeout. Authentication cookies may be invalidated after password changes, account suspension, logout or suspected compromise.
Security attributes
All production cookies issued by URLy (including PHPSESSID, app_lang, and urly_terms_agreed) strictly enforce the Secure attribute (transmitted exclusively over encrypted TLS/HTTPS connections) and SameSite=Lax protection. Sensitive session and authentication cookies additionally enforce HttpOnly to prevent unauthorized access via clientside scripts.
CSRF protection
Where state-changing requests require CSRF protection, URLy may use session-bound tokens or equivalent safeguards. CSRF tokens should not be treated as authentication credentials.
Language preference
A language preference cookie may be used to remember the selected interface language. This is a functionality preference rather than advertising tracking.
Cookie rejection
Blocking all cookies may prevent login, account management or other essential functions.
Third-party content
A third-party destination opened after a Short Link may set its own cookies. Those cookies are controlled by the destination operator, not URLy.
Consent
Where applicable law requires consent for a non-essential cookie, URLy should obtain and record consent before setting that technology.
Policy review
Cookie inventories should be reviewed when the frontend, authentication stack, analytics implementation or third-party integrations change.
5. 05 Abuse Reporting
This Policy describes reporting channels and the review process for harmful, unlawful or rights-infringing Short Links.
1. Channels
Security, phishing, malware, fraud and abuse: abuse@urly.tr. Legal, privacy, copyright and trademark: legal@urly.tr. General support: support@urly.tr.
2. Report information
Short Link URL.
Destination URL if safely available.
Description and category of suspected abuse.
Relevant dates and context.
Evidence that can be safely shared.
Reporter contact information and authority where relevant.
3. Phishing reports
Include the impersonated organization, suspected credential collection, affected domain and any relevant indicators.
4. Malware reports
Include the malicious URL, behavior observed, malware family if known and indicators of compromise without redistributing dangerous payloads.
5. Fraud reports
Describe the deceptive conduct, impersonated entity, financial harm or attempted harm and relevant Short Links.
6. Child safety
Send serious child-safety reports to abuse@urly.tr. Do not download, copy or redistribute illegal material solely to make a report.
7. Copyright and trademark
Formal rights complaints should identify the right, the disputed Short Link/material, the legal basis and the reporter’s authority.
8. Review process
URLy may use automated signals and human review. High-risk Short Links may be temporarily restricted while investigated.
9. Enforcement
Actions may include ALLOW, REVIEW, RESTRICT or BLOCK, and may include account or API restrictions.
10. False reports
Knowingly false, fraudulent or malicious reports may be rejected and may lead to enforcement.
11. Confidentiality
Reports are handled with reasonable confidentiality, subject to law, safety and investigation needs.
12. Response times
URLy may prioritize reports according to severity. No universal response or removal deadline is guaranteed.
13. Appeals
Affected users may request reconsideration where a review channel is available.
Severity triage
Reports may be prioritized based on imminent physical harm, child safety, active credential theft, malware distribution, financial fraud, scale, persistence and potential impact.
Evidence handling
Reporters should provide only evidence reasonably necessary to establish the issue. Sensitive personal information, passwords, authentication tokens and illegal material should not be unnecessarily included.
Reporter safety
URLy may avoid disclosing a reporter’s identity to the reported user where reasonably possible, subject to legal obligations and operational needs.
Temporary restrictions
A temporary restriction may be used while a report is investigated. Temporary restriction does not constitute a final legal finding.
Restoration
If review determines that a restriction was incorrect or no longer necessary, URLy may restore a Short Link or account subject to other applicable rules.
Repeat reporting
Multiple reports concerning the same URL may be consolidated. Repeated reports do not automatically establish a violation.
Malware handling
URLy personnel should not redistribute malicious files merely to investigate a report. Technical indicators can be used without unnecessarily propagating payloads.
Phishing response
Where appropriate, URLy may disable the Short Link, restrict related accounts, preserve relevant records and cooperate with affected providers or authorities.
Copyright response
Copyright complaints may be assessed separately from security or abuse reports and may require evidence of ownership or authorization.
Report status
URLy may provide limited status information but does not guarantee disclosure of internal detection methods or investigative details.
6. 06 Retention Deletion
This Policy establishes general retention targets for categories of information. These are not guarantees of exact automatic deletion dates.
1. Account information
While active and generally up to 12 months after deletion/closure.
2. Deleted account records
Generally up to 12 months after deletion, subject to legal, security and dispute exceptions.
3. Short Links and destination records
While active and generally up to 12 months after deactivation/deletion where applicable.
4. Click/access logs
Generally up to 12 months.
5. IP/device/browser/OS/language
Generally up to 12 months.
6. Security and abuse logs
Generally up to 24 months.
7. Fraud/phishing/malware enforcement records
Generally up to 24 months.
8. Abuse reports
Generally up to 24 months.
9. Legal requests and records
For the duration of the relevant legal matter and as long as reasonably necessary afterward.
10. Aggregated/de-identified data
May be retained longer where it no longer constitutes personal data under applicable law.
11. Anonymous Short Links
Current anonymous Short Links may expire after 30 days of inactivity under product rules.
12. Legal hold
Data may be preserved beyond ordinary retention when necessary for litigation, legal process, investigations, disputes or regulatory requirements.
13. Security incidents
Relevant records may be retained longer where necessary to investigate, remediate and document a security incident.
14. Backups
Backups may retain information beyond primary-system deletion schedules for a limited operational period and may not be individually erasable immediately.
15. Deletion requests
Requests may be submitted to legal@urly.tr. Deletion does not override information that must lawfully be retained.
Creator IP
The IP address associated with creation of a Short Link (urls.creator_ip) is retained strictly for security, abuse prevention, and legal compliance. In accordance with automated retention sweeps:
- For active Short Links, creator IP is retained for up to 12 months (365 days) from creation, after which it is automatically and irreversibly anonymized (set to NULL).
- For deleted or expired Short Links, creator IP is retained for an abuse dispute window of up to 90 days, after which it is automatically set to NULL.
IP geolocation cache
IP geolocation cache records (ip_geo_cache) are retained for a maximum of 12 months (365 days) or automatically cleared when orphaned, ensuring no indefinite retention of cached location mappings.
Support tickets
Support and communication records (support_tickets) are retained strictly according to operational necessity and applicable legal dispute periods:
- Unverified pending requests (status = pending_verification): Automatically purged after 14 days if email confirmation is not completed.
- IP addresses: IP addresses associated with support submissions are retained for up to 90 days for abuse prevention and fraud screening, then automatically anonymized (set to NULL).
- Resolved/closed records and inquiries: Retained for up to 3 years from creation to facilitate quality assurance, dispute resolution, consumer inquiries, and statutory limitation periods under applicable law, after which all ticket messages, user details, and responses are permanently deleted.
API applications
Developer API records (api_applications) are retained strictly in accordance with security lifecycle and operational needs:
- Active API credentials: Retained while the application is active and valid to enable programmatic link shortening and analytics services.
- Application IP addresses: IP addresses recorded at application submission are retained for 90 days for abuse prevention and developer verification, then automatically anonymized (set to NULL).
- Rejected applications: Retained for 90 days following review to allow for applicant inquiries and appeals, after which all project details and reasons are permanently deleted.
- Disabled/inactive credentials: Keys revoked, marked inactive, or unused for more than 12 months (365 days) are automatically purged.
- Orphaned applications: Applications linked to deleted user accounts are immediately deleted during automated account purge cycles.
Rate-limit records
Rate-limit records (rate_limits) are retained strictly for operational security and automated abuse mitigation (rate limiting and brute-force prevention). Expired rate-limit windows are automatically purged 1 day (24 hours) after expiration.
Referrer minimization
Where referrer information is stored (clicks_log.referer), URLy automatically sanitizes and minimizes incoming referrers at the point of ingestion. Query strings (?token=..., ?email=...) and fragments (#...) are strictly stripped to prevent accidental retention of sensitive parameters or personally identifiable information (PII). In addition, automated retention sweeps retroactively sanitize historical referrer records, and the outbound Referrer-Policy header is configured to protect visitors upon redirection.
Deletion versus anonymization
Information that is irreversibly aggregated or de-identified may no longer be treated as personal data, subject to applicable law and the quality of the de-identification.
Legal hold
A legal hold may suspend ordinary deletion for specific records. The hold should be limited to relevant information and removed when no longer necessary.
Backups
Backup retention should be documented separately so that deletion requests and incident-response obligations can be reconciled with backup architecture.
Review cadence
Retention schedules should be reviewed periodically against actual database cleanup jobs and application behavior.
7. 07 Security Policy
This Policy describes the principal security controls and verified transport-security characteristics of URLy.
1. TLS
URLy supports TLS 1.2 and TLS 1.3. Legacy SSL/TLS protocols are disabled.
2. Cryptography
The primary endpoint uses modern authenticated-encryption cipher suites and supports forward secrecy.
3. Post-quantum key exchange
X25519MLKEM768 support is present on the primary endpoint.
4. Certificate and protocol
The primary endpoint uses a trusted TLS certificate and supports HTTP/2.
5. External testing
Qualys SSL Labs has rated the primary endpoint A. The assessment tested common TLS issues including BEAST, POODLE variants, Heartbleed, CCS, ROBOT and related conditions, with the tested endpoint reported clean or mitigated.
6. Application controls
Input validation.
Authentication and session controls.
Authorization.
CSRF protections where applicable.
Rate limiting.
Abuse prevention.
Security logging and audit records.
Secure configuration and access controls.
7. Slug Protection
URLy uses normalization, case folding, separator handling, script/confusable analysis and rule matching to protect sensitive slugs. Decisions are ALLOW, REVIEW, RESERVED or BLOCK.
8. Destination Safety
Destination Safety is separate from slug protection and evaluates URLs/domains/activity for abuse and security risk.
9. Incident response
URLy may investigate, contain, remediate and document security incidents. Relevant information may be preserved where necessary.
10. Vulnerability management
Security issues may be prioritized by severity, exploitability, affected scope and user impact.
11. Administrative access
Access to operational systems should be limited according to role and operational necessity.
12. Limitations
URLy does not guarantee absolute security, uninterrupted availability or detection of every vulnerability or malicious destination.
13. Responsible disclosure
Security researchers should use the Vulnerability Disclosure Policy and abuse@urly.tr.
Trusted proxy boundaries
IP-address and geolocation extraction must trust forwarding and edge headers (including client IP and GeoIP metadata) only when requests originate from infrastructure controlled and trusted by URLy. Untrusted clients must not be able to spoof the effective client IP or geolocation through arbitrary headers.
Cookie and session security
Production sessions enforce Secure cookies when served over HTTPS, together with HttpOnly and SameSite=Lax. Active session identifiers are immediately regenerated (session_regenerate_id) upon successful authentication and activation to prevent session fixation attacks.
SSRF protection
All destination URL validation and redirection mechanisms enforce multi-tier SSRF (Server-Side Request Forgery) defenses against internal network reachability. Controls explicitly neutralize and block:
- Private, loopback, link-local, carrier-grade NAT, and reserved CIDR ranges across IPv4 and IPv6.
- DNS rebinding attacks and hostname-to-private-IP resolutions via recursive DNS validation.
- Obfuscated IP notations including decimal integers (e.g. 2130706433), hexadecimal (0x7f000001), octal, and IPv4-mapped IPv6 formats (::ffff:127.0.0.1).
- Localhost variations, single-word internal hostnames, internal TLDs (.local, .internal, .lan, .corp, etc.), and Cloud metadata endpoints (169.254.169.254, metadata.google.internal).
- Port restrictions limiting destinations strictly to standard web services (80, 443, 8080, 8443) to prevent internal port scanning.
- Self-referential redirect loops and dynamic re-verification prior to HTTP 302 dispatch.
Rate limiting
Rate limits and brute-force defenses are strictly enforced across public and sensitive operations:
- Authentication & login attempts enforce multi-tier rate limiting combining client IP, target account/email, and composite IP+account thresholds with cooldown delays to neutralize credential stuffing and brute-force attacks.
- Account creation, password recovery, verification resend, link creation, and API endpoints enforce granular per-IP and per-target velocity limits.
Secret management
Production credentials, SMTP passwords, database passwords, API keys and cron tokens must be stored securely and rotated if exposed.
Logging access
Security logs should be access-controlled and protected against unauthorized modification. Logs should not contain unnecessary secrets.
Dependency security
Third-party libraries and runtime components should be kept reasonably current and reviewed for material vulnerabilities.
Admin security
Administrative accounts should use strong authentication, least privilege and additional controls appropriate to their impact.
Incident evidence
Relevant logs should be preserved when an incident is under investigation, while avoiding unnecessary expansion of personal-data retention.
Security disclosure limitations
Publishing exact detection thresholds, blocklists or internal security architecture may increase evasion risk and is therefore not promised.
8. 08 Copyright Takedown
This procedure explains how URLy receives and reviews copyright and trademark complaints.
1. Scope
Complaints may concern a URLy Short Link, URLy-controlled metadata or other material within URLy’s control.
2. Destination-hosted content
URLy may control a Short Link but generally cannot directly remove content hosted by the third-party destination.
3. Copyright notice requirements
Identify the copyrighted work, disputed Short Link/material, basis of ownership or authorization, contact details and declarations required by applicable law.
4. Trademark complaint requirements
Identify the mark, ownership or registration basis where relevant, disputed Short Link/material and explanation of alleged infringement or confusion.
5. Review
URLy may request clarification, evidence or authorization. A complaint does not automatically establish infringement.
6. Temporary restriction
A Short Link may be temporarily restricted when reasonably necessary to prevent continuing harm while a serious complaint is reviewed.
7. Counter-notification
Where appropriate, an affected user may submit a counter-notification or reconsideration request with the information required by applicable law.
8. Fraudulent notices
Fraudulent, knowingly false or abusive notices may be rejected and may result in enforcement.
9. Repeat infringement
Repeated substantiated infringement may result in stronger enforcement, including account or Short Link restrictions.
10. Fair use and legal exceptions
URLy will consider applicable legal exceptions where relevant and where sufficient information is provided.
11. DMCA
URLy may process valid DMCA notices where applicable but does not represent that it qualifies for any particular DMCA safe harbor.
12. Government and emergency requests
Formal government requests should be sent to legal@urly.tr. Emergency requests involving serious imminent harm may be prioritized.
Required declaration
Where a statutory notice requires a declaration of good faith, accuracy or authority, the complainant should provide the applicable declaration.
Identification standard
The disputed material should be identified with enough precision for URLy to locate it without guessing.
Authorization
A representative should identify the rights holder or provide evidence of authority when reasonably requested.
Multiple works
Where multiple works or marks are involved, each should be identified clearly enough to support review.
Bad-faith notices
Knowingly false notices, harassment through the notice system or attempts to suppress lawful criticism may be rejected.
Destination limitations
If the alleged infringement is entirely hosted by a third-party site, URLy may provide the destination operator’s appropriate reporting route where known, but does not guarantee removal there.
Temporary measures
Temporary Short Link restrictions may be used where continued availability presents a credible legal or safety risk.
Counter-notice review
Counter-notices may be reviewed for completeness and may be handled according to applicable law and any relevant provider obligations.
Repeat infringement
A pattern of substantiated infringement may be considered in account enforcement.
No legal determination
URLy’s operational action is not necessarily a judicial determination that infringement occurred.
9. 09 Law Enforcement
This Policy explains how URLy handles government, law-enforcement and formal legal requests.
1. Contact
Send requests to legal@urly.tr.
2. Request contents
Requests should identify the authority, legal basis, jurisdiction, relevant account/Short Link, date range and specific records sought.
3. Data availability
URLy can only provide information it possesses and can lawfully disclose. Historical information may no longer exist due to retention or technical limitations.
4. Preservation
Where legally permitted and technically feasible, URLy may preserve specified records for a reasonable period pending appropriate legal process.
5. User notification
Where legally permitted and where notification would not create a safety or investigative risk, URLy may notify affected users.
6. Emergency requests
Requests involving imminent risk of death or serious physical harm may receive expedited review.
7. International requests
International authorities should use legally recognized procedures appropriate to the jurisdiction and nature of the request.
8. Private requests
Private parties should use applicable legal procedures. A private request does not automatically compel disclosure.
9. Authentication
URLy may verify the authenticity and authority of a request before responding.
10. Overbroad requests
URLy may request clarification or narrow an overbroad request where appropriate.
11. Legal challenge
Where appropriate, URLy may challenge, narrow or seek clarification of a legally defective request.
12. Confidentiality
URLy may keep requests confidential where required or appropriate.
Specificity
Specific requests reduce processing time and help avoid unnecessary disclosure of unrelated information.
Date ranges
Requests should specify relevant time periods because URLy may not retain historical data indefinitely.
Identifiers
Useful identifiers may include Short Link, account email, user ID, API application or relevant timestamp.
Content requests
Requests for third-party destination content should generally be directed to the destination operator unless URLy itself controls the requested material.
Preservation scope
Preservation should identify the records and time period to be preserved and should not require indefinite preservation without appropriate legal basis.
Emergency standard
Emergency requests should describe the imminent risk and why ordinary process cannot reasonably be followed.
Authentication
URLy may verify official email domains, signed requests, reference numbers or other authenticity indicators.
Disclosure minimization
Where disclosure is required, URLy should seek to provide information reasonably responsive to the request rather than unrelated records.
Notification exceptions
Notification may be withheld where prohibited by law, court order, emergency circumstances or reasonable investigative concerns.
Transparency
Aggregate legal-request statistics may be included in transparency reporting where lawful and safe.
10. 10 KVKK Aydinlatma
This English-base notice is intended for localization into Turkish and describes processing relevant to data subjects protected by Turkish data-protection law.
1. Veri Sorumlusu
Veri sorumlusu Firma Life’tır. Adres: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.
2. Kişisel veri kategorileri
Hesap ve iletişim bilgileri.
Kimlik doğrulama ve güvenlik kayıtları.
IP adresi.
IP tabanlı yaklaşık ülke/bölge/şehir bilgisi.
Tarayıcı, işletim sistemi, cihaz türü ve dil bilgileri.
Kısa bağlantı ve hedef URL bilgileri.
Tıklama/erişim kayıtları.
Destek, abuse, güvenlik, moderasyon ve hukuki başvuru kayıtları.
3. İşleme amaçları
Hizmetin sunulması ve hesap yönetimi.
Kısa bağlantıların oluşturulması ve işletilmesi.
Güvenlik ve kötüye kullanımın önlenmesi.
Phishing, malware, fraud ve spam tespiti.
Destek ve başvuruların cevaplanması.
Hukuki yükümlülüklerin yerine getirilmesi.
Hizmet güvenilirliğinin ve performansının geliştirilmesi.
4. Hukuki sebepler
KVKK kapsamında uygulanabilir hukuki sebepler arasında sözleşmenin kurulması/ifası, hukuki yükümlülük, hakkın tesisi/kullanılması/korunması, veri sorumlusunun meşru menfaati ve gerektiğinde açık rıza bulunabilir.
5. Özel nitelikli veriler
URLy’nin amacı özel nitelikli kişisel veri toplamak değildir. Kullanıcılar gereksiz özel nitelikli verileri destek veya form alanlarına göndermemelidir.
6. Yurt dışı aktarım
Ana altyapı Türkiye’dedir. Ziyaretçi IP adresleri yerel (on-premise) altyapı ve şifreli edge ağ başlıkları üzerinden tamamen yerel olarak işlenmektedir; IP adresleri üçüncü taraf yurt dışı sorgulama servislerine aktarılmaz. KVKK Madde 9 kapsamındaki uluslararası aktarım riskleri yerel mimari ile bertaraf edilmiştir.
7. Saklama
Genel saklama hedefleri Data Retention & Deletion Policy’de açıklanmıştır.
8. Güvenlik
URLy makul teknik ve idari tedbirler uygular. TLS 1.2/1.3 ve doğrulanmış diğer güvenlik kontrolleri Security Policy’de açıklanmıştır.
9. İlgili kişi hakları
İlgili kişiler uygulanabilir KVKK hakları kapsamında başvurularını legal@urly.tr adresine iletebilir.
10. Başvuru usulü
URLy kimlik doğrulaması, başvurunun kapsamının netleştirilmesi ve hukuken gerekli bilgi/evrakların sunulmasını talep edebilir.
11. Çocuklar
Çocukların cinsel istismarı ve diğer ciddi çocuk güvenliği ihlalleri yasaktır.
12. Güncellemeler
Bu notice, işleme faaliyetleri veya mevzuat değiştikçe güncellenebilir.
Veri güvenliği
Kişisel verilerin hukuka aykırı işlenmesini, erişilmesini veya aktarılmasını önlemek için teknik ve idari tedbirler uygulanır.
IP ve güvenlik kayıtları
IP adresleri ve teknik kayıtlar güvenlik, kötüye kullanımın önlenmesi, rate limiting ve hukuki süreçler için işlenebilir.
Çerezler
Zorunlu oturum, güvenlik ve tercih çerezleri hizmetin çalışması için kullanılabilir. Zorunlu olmayan teknolojiler için uygulanabilir mevzuat kapsamında gerekli mekanizmalar kullanılmalıdır.
Veri aktarımı
Yurt içi ve yurt dışı hizmet sağlayıcılarına yapılan aktarımlar uygulanabilir KVKK hükümlerine göre değerlendirilir.
Başvuru kimlik doğrulaması
Başvurucunun verilerinin üçüncü kişilere açıklanmaması için makul kimlik doğrulaması istenebilir.
Başvuru kayıtları
KVKK başvurularının alındığını ve cevaplandığını göstermek amacıyla sınırlı başvuru kayıtları saklanabilir.
Reddetme/limitleme
Kanunen izin verilen durumlarda, başvuru diğer kişilerin hakları, güvenlik, hukuki yükümlülükler veya yasal saklama yükümlülükleri nedeniyle kısmen veya tamamen sınırlandırılabilir.
İletişim
Başvurular legal@urly.tr üzerinden alınır; uygulanabilir resmi başvuru yolları saklıdır.
11. 11 GDPR EEA UK
This Notice applies where GDPR, UK GDPR or equivalent EEA/UK privacy law applies.
1. Controller
Firma Life, Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.
2. Categories
Account, authentication, IP, approximate location, technical/device, Short Link, click/access, support, abuse, security, moderation and legal-process data.
3. Purposes
Service delivery, security, fraud/abuse prevention, analytics, support, legal compliance and protection of rights.
4. Legal bases
Contract, legal obligation, legitimate interests, consent where required, and establishment/exercise/defense of legal claims where applicable.
5. Special categories
URLy does not intentionally seek special-category data. Users should not submit unnecessary sensitive information.
6. Automated processing
URLy may use automated risk signals for slug protection, destination safety, abuse detection and moderation. Automated signals can result in review or restriction; where applicable, users may request human reconsideration.
7. International transfers
Primary infrastructure is in Türkiye. The current IP-geolocation provider may process IP information outside the EEA/UK. Where a restricted transfer occurs, URLy will use a lawful transfer mechanism and appropriate safeguards required by applicable law.
8. Rights
Access.
Rectification.
Erasure.
Restriction.
Objection.
Portability where applicable.
Withdrawal of consent where applicable.
Rights relating to certain automated decisions.
9. Identity verification
Reasonable identity verification may be required before disclosure or changes affecting personal data.
10. Retention
See the Data Retention & Deletion Policy.
11. Complaints
You may complain to the competent supervisory authority in the EEA/UK jurisdiction applicable to you.
12. Representative / DPO
URLy does not claim an EEA/UK representative or DPO unless formally appointed. If appointment becomes required and is made, this Notice will be updated.
13. Breach notification
Where required by applicable law, URLy will follow applicable personal-data breach notification obligations.
Controller contact
For privacy matters, contact legal@urly.tr. The legal entity and address are stated in the Global Privacy Policy.
Legitimate interests
Relevant legitimate interests may include securing Short Links, preventing fraud, protecting accounts, enforcing policies, maintaining service integrity and responding to abuse.
Data minimization
URLy seeks to limit collection to information reasonably necessary for identified purposes.
Processor contracts
Where required, processors should be bound by GDPR-compliant data-processing terms and confidentiality/security obligations.
Transfer safeguards
Where a transfer requires safeguards, URLy should use an applicable adequacy decision, standard contractual mechanism or other lawful transfer basis, as appropriate.
Data-subject requests
Requests may be submitted to legal@urly.tr and may require identity verification.
Automated decisions
Risk scoring may assist moderation. Where a decision has legal or similarly significant effects and applicable law grants rights, URLy will provide the rights required by law.
Children
Where services are accessed by minors, applicable age and consent requirements will be considered. Illegal child-safety activity is prohibited regardless of age.
Retention exceptions
Legal obligations, claims, fraud prevention and security investigations may justify retention beyond ordinary targets where permitted by law.
Supervisory authority
Users may complain to the supervisory authority competent for their circumstances.
12. 12 Child Safety
This Policy establishes zero-tolerance rules for child sexual exploitation and serious abuse involving minors.
1. Prohibited material and conduct
CSAM and sexual exploitation of children.
Grooming or sexual solicitation of minors.
Sexualized content involving minors.
Child trafficking or exploitation.
AI-generated or manipulated material that sexualizes or exploits minors.
Child-targeted fraud, extortion or coercion.
Doxxing or malicious exposure of minors’ personal data.
Circumvention of age controls for unlawful purposes.
2. Immediate action
URLy may immediately restrict Short Links, accounts or related activity where there is a credible child-safety risk.
3. Preservation
Relevant information may be preserved when necessary for safety, investigation or lawful requests.
4. Reporting
Reports should be sent to abuse@urly.tr. Do not download, copy, create additional copies of or redistribute illegal material merely to report it.
5. Authorities
URLy may cooperate with competent authorities where legally required or appropriate.
6. Privacy
Child-safety reports are handled with reasonable confidentiality, subject to safety and legal requirements.
7. False reports
Knowingly false or malicious reports may be rejected and may result in enforcement.
8. Appeals
Enforcement may be reconsidered where appropriate, except where doing so would create unacceptable safety, legal or investigative risk.
Grooming indicators
Attempts to build sexual trust with minors, solicit sexual images, move a minor to private communication for sexual purposes or evade parental/safety controls may trigger immediate action.
Financial exploitation
Scams, coercion or extortion targeting minors are prohibited.
Personal information
Publishing a minor’s address, school, phone number, live location or other sensitive personal information for malicious purposes may be restricted.
Age evasion
Attempts to use URLy to bypass age gates for unlawful or exploitative purposes are prohibited.
Preservation
Where appropriate, URLy may preserve relevant account, Short Link and security records subject to applicable law.
Authority cooperation
Requests from competent child-protection or law-enforcement authorities may be handled under the Law Enforcement Guidelines.
Reporter guidance
Reporters should provide URLs and concise descriptions rather than copying or redistributing illegal imagery.
False allegations
Good-faith reports are welcome even where the reporter is uncertain; knowingly fabricated allegations may be treated differently.
Confidentiality
URLy may limit disclosure of report details to protect victims and investigations.
Policy updates
Child-safety practices may be updated as law, technology and safety standards evolve.
13. 13 Data Subject Request
This procedure explains how users can exercise privacy rights under applicable law.
1. Submission
Send a request to legal@urly.tr. State the relevant account/email if applicable, requested right and sufficient information to locate the record.
2. Rights
Access, correction, deletion, restriction, objection, portability, withdrawal of consent and applicable automated-decision rights.
3. Identity verification
Reasonable verification may be requested to prevent unauthorized disclosure.
4. Clarification
We may request clarification where a request is too broad or ambiguous.
5. Response timing
URLy will respond within applicable legal deadlines. Where law allows extensions, the requester may be informed.
6. Fees
Requests are generally handled without charge unless applicable law permits a reasonable fee for excessive or manifestly unfounded/repetitive requests.
7. Deletion limits
Information may remain where legally required, necessary for security, fraud prevention, disputes, legal claims or other lawful exceptions.
8. Third-party destinations
URLy cannot generally delete personal data held independently by a third-party destination website.
9. Appeals
Where applicable, users may request reconsideration of a refusal or limitation.
10. Request records
URLy may retain limited records of privacy requests for compliance, audit and security purposes.
11. Contact
legal@urly.tr.
Access scope
An access response may include categories, purposes, recipients, retention information and copies of personal data where legally required.
Correction
Users may identify inaccurate or incomplete personal information and request correction.
Deletion
Deletion may be limited where records must be retained by law or are necessary for legal claims, security or fraud prevention.
Restriction
Where applicable, processing may be restricted while accuracy, legality or objection is assessed.
Objection
An objection may be reviewed against the lawful basis and applicable exceptions.
Portability
Where portability applies, data may be provided in a structured, commonly used and machine-readable format.
Consent withdrawal
Withdrawing consent does not invalidate processing already lawfully performed before withdrawal.
Third-party data
URLy cannot generally correct or delete data held independently by a third-party destination.
Identity fraud prevention
Verification information itself should be minimized and protected.
Records of decisions
Limited records may be retained to demonstrate compliance with privacy obligations.
14. 14 Subprocessors
This disclosure explains third-party processing categories and the currently known geolocation integration.
1. Current infrastructure
URLy’s primary infrastructure is in Türkiye.
2. Analytics and advertising
URLy does not currently use third-party advertising or third-party analytics platforms for user tracking.
3. Local IP Geolocation Architecture
URLy uses a local on-premise IP geolocation mechanism and encrypted TLS edge transport headers. IP addresses are NOT transmitted to external third-party geolocation API providers (external APIs like ip-api.com have been completely decommissioned). Geolocation is performed entirely within URLy's local infrastructure, ensuring strict privacy, KVKK and GDPR compliance without cross-border data transfer risks.
4. Processor categories
Infrastructure and hosting.
Storage and backup.
Transactional email and support communications.
Security and abuse services.
Monitoring and technical services.
IP geolocation.
Other operational processors necessary to provide the Service.
5. Processor obligations
Where required, processors should be bound by appropriate confidentiality, security and data-processing obligations.
6. International transfers
Where processors process data outside Türkiye or the EEA/UK, applicable transfer requirements and safeguards should be addressed.
7. No sale
URLy does not sell personal data.
8. Changes
Processor categories and specific vendors may change. Material disclosures will be updated where required.
9. User rights
Data-subject requests may be submitted to legal@urly.tr.
Provider inventory
The published disclosure should be reviewed when a new provider gains access to personal data or an existing provider materially changes its processing.
Purpose limitation
Processors should receive only the data reasonably necessary for their contracted function.
Security
Providers handling personal data should be assessed according to the sensitivity and risk of the processing.
IP geolocation
URLy processes IP geolocation locally within its own environment. No visitor IP addresses are sent to third-party geolocation lookup services.
Email providers
Transactional email providers may process email addresses and message metadata necessary to deliver account and support communications.
Hosting and storage
Infrastructure providers may process system data as part of hosting, backup and maintenance.
Support providers
Where third-party support tools are introduced, their processing should be reflected in this disclosure.
International transfers
Transfer mechanisms should be reviewed whenever a provider processes data in a new country.
Change notification
Where required by law or contract, users may be informed of material processor changes.
No sale
Processing by a service provider for URLy’s purposes is not a sale of personal data.
15. 15 Vulnerability Disclosure
This Policy provides a responsible channel for security researchers to report vulnerabilities.
1. Contact
Report vulnerabilities to abuse@urly.tr.
2. Good-faith testing
Limit testing to what is necessary to demonstrate the issue.
3. Prohibited testing
Do not access, modify, delete or expose other users’ data.
Do not conduct destructive or denial-of-service testing.
Do not deploy malware or persistence.
Do not social-engineer staff or users.
Do not extort or threaten URLy.
Do not publish sensitive details before reasonable coordination.
4. Short Link testing
Redirect and URL handling tests must avoid harming third parties and must not be used to facilitate real-world abuse.
5. Proof of concept
Provide concise reproduction steps and evidence. Redact personal data and secrets.
6. Credentials and secrets
Do not send passwords, API keys or other live secrets in a report. If accidentally exposed, notify URLy immediately without redistributing them.
7. Handling
URLy may acknowledge, investigate, request clarification, remediate or close a report.
8. Severity
Severity may consider impact, exploitability, affected scope, user exposure and realistic abuse potential.
9. Duplicates
Duplicate reports may be linked to an existing investigation.
10. Third-party vulnerabilities
Issues caused solely by third-party systems may be redirected to the relevant provider.
11. Bug bounty
No monetary reward is promised unless expressly announced.
12. Safe-harbor intent
URLy intends to avoid unnecessary legal escalation for good-faith research following this Policy, to the extent permitted by law. This is not a legal waiver.
13. Coordinated disclosure
Researchers are encouraged to coordinate publication where sensitive details could create user risk.
Scope examples
Examples include authentication bypass, authorization flaws, SQL injection, XSS, SSRF, insecure direct object references, sensitive-data exposure, API-key disclosure and Short Link security flaws.
Out-of-scope examples
Purely informational issues without meaningful security impact, unsupported third-party systems and social-engineering attempts against personnel may be out of scope.
Privacy
Researchers must minimize access to personal data and promptly stop testing if real user data is encountered.
Rate-limit testing
Do not intentionally exhaust production resources. Use low-volume demonstrations or coordinate a safer test where possible.
SSRF testing
Do not probe internal services or metadata endpoints beyond what is necessary to establish the vulnerability.
Account takeover
Do not use another person’s credentials. If a vulnerability demonstrates takeover potential, stop before accessing unrelated data.
Disclosure timeline
URLy may coordinate a disclosure timeline based on severity and remediation status.
Recognition
URLy may acknowledge valid reports at its discretion but does not promise public credit.
Emergency vulnerabilities
Critical vulnerabilities may require immediate temporary restrictions or emergency maintenance.
Security.txt
The public security.txt file should point to the security page and abuse reporting address.
16. 16 Freedom Content Moderation
This Policy balances lawful expression with protection from serious abuse.
1. Principle
URLy supports lawful expression, journalism, research, criticism, public-interest information and legitimate discussion.
2. Restricted content
Serious abuse, unlawful exploitation, phishing, fraud, malware, child sexual exploitation, privacy abuse, trafficking and violent-wrongdoing facilitation may be restricted.
3. Political and public-interest content
Political speech, criticism of governments and public-interest journalism are not automatically prohibited.
4. Context
Intent, audience, context, likelihood of harm, repetition and surrounding material may be considered.
5. Automated systems
Automated signals may identify suspicious slugs, destinations, domains and behavior. Automated detection can produce false positives.
6. Human review
Human review may be used where appropriate, particularly for appeals, high-risk reports and ambiguous cases.
7. Decisions
Content moderation decisions are ALLOW, REVIEW, RESTRICT or BLOCK. Slug Protection uses a separate ALLOW, REVIEW, RESERVED or BLOCK taxonomy.
8. Proportionality
Where practical, URLy may choose the least restrictive effective action consistent with safety and law.
9. Appeals
Users may request reconsideration through support@urly.tr or the relevant policy channel.
10. Confidentiality of detection
URLy may withhold exact thresholds, detection rules and security signals when disclosure would facilitate evasion.
11. Repeat abuse
Repeated or coordinated abuse may result in stronger enforcement.
12. No guarantee
URLy cannot guarantee that every violation will be detected or that every legitimate link will avoid review.
Lawful controversial content
Controversial, offensive or unpopular opinions are not automatically prohibited merely because they are controversial.
Harm threshold
Moderation may focus on credible risk of unlawful conduct, serious harm, exploitation, fraud or abuse rather than viewpoint alone.
Contextual review
The same words may carry different meaning in news reporting, historical discussion, satire, quotation or direct operational instruction.
Impersonation
Parody and commentary may be distinguished from deceptive impersonation based on context and likely user confusion.
Adult content
Adult sexual material may be subject to applicable law and product restrictions, while content involving minors or non-consensual exploitation is prohibited.
Research and security
Legitimate research may be reviewed differently from operational exploitation or malware distribution.
Appeals
Appeals should identify why the decision is believed to be incorrect and provide relevant context.
Repeated evasion
Repeated attempts to evade a valid restriction may lead to stronger enforcement.
Transparency limits
URLy may explain the general policy basis without exposing proprietary detection thresholds.
Corrections
If a moderation decision is found to be erroneous, URLy may restore the affected Short Link or account where appropriate.
17. 17 Transparency Report
This Policy describes the framework URLy may use for periodic aggregate transparency reporting.
1. Purpose
Transparency reporting may describe aggregate abuse, moderation, legal and security activity without exposing individual users.
2. Potential metrics
Abuse reports received.
Phishing/malware/fraud reports.
Short Links restricted or blocked.
Accounts or API access restricted.
Appeals and outcomes.
Copyright/trademark notices.
Government and law-enforcement requests.
Emergency requests.
Child-safety actions.
Security incidents where disclosure is appropriate.
3. Aggregation
Data may be aggregated and small counts suppressed to reduce re-identification risk.
4. Methodology
Reports may explain definitions, counting periods, methodology, corrections and limitations.
5. Privacy
No individual user’s personal data should be published merely to increase transparency.
6. Security
Details that would enable abuse, expose vulnerabilities or undermine investigations may be omitted.
7. Legal restrictions
Publication may be delayed or limited where law, court orders, confidentiality or investigation needs require it.
8. Third-party reports
Reports may distinguish reports received from third parties from actions independently detected by URLy.
9. No promise
URLy is not required to publish a report at a particular frequency unless it expressly commits to one.
10. Corrections
Material errors may be corrected with an appropriate note.
Reporting periods
A report may cover a calendar year, quarter or other defined period.
Counting methodology
One report may count reports, URLs, accounts or actions differently; definitions should be stated clearly.
Duplicates
Multiple reports concerning one Short Link may be counted separately as reports but only once as an affected Short Link.
Automated versus human action
Where feasible, metrics may distinguish automated enforcement from human-reviewed actions.
Appeal outcomes
Appeal statistics may include upheld, reversed, modified or unresolved outcomes.
Legal requests
Requests may be counted by category, jurisdiction and type where lawful.
Child safety
Child-safety metrics should be aggregated carefully to avoid exposing victims or operational details.
Security incidents
Only incidents suitable for public disclosure should be reported; active vulnerabilities may be withheld.
Small-number suppression
Very small counts may be suppressed to reduce re-identification risk.
Corrections and archives
Material corrections should be dated, and prior reports may be archived for transparency.
18. 18 Security Page
This is suggested public-facing copy for https://urly.tr/security.
Security at URLy
Security is a core part of URLy’s infrastructure. We use encrypted transport, application controls, rate limiting, abuse prevention and security monitoring to protect the Service.
Transport security
URLy supports TLS 1.2 and TLS 1.3, disables legacy SSL/TLS, uses modern authenticated encryption cipher suites, supports forward secrecy and X25519MLKEM768, uses a trusted TLS certificate and supports HTTP/2.
Security testing
The primary urly.tr endpoint has received an A rating in Qualys SSL Labs testing, with common TLS vulnerabilities tested as clean or mitigated.
Link safety
URLy separates Global Slug Protection from Destination Safety. These systems help address phishing, malware, fraud, impersonation and other abusive activity.
Report a vulnerability
Send responsible vulnerability reports to abuse@urly.tr.
Related policies
See the Security Policy and Vulnerability Disclosure Policy for additional information.
Last reviewed
[INSERT DATE]
Application security
URLy uses authentication, authorization, input validation, rate limiting, CSRF protections where applicable and security logging.
Abuse protection
The platform maintains separate slug-protection and destination-safety concepts.
Responsible disclosure
Researchers should report security issues to abuse@urly.tr and follow the Vulnerability Disclosure Policy.
Limitations
No security system is perfect and no guarantee is made that every malicious URL or vulnerability will be detected.
Public claims
The security page intentionally does not claim controls that are not verified for production.
19. 19 security txt
Recommended content for /.well-known/security.txt.
File content
Policy: https://urly.tr/security
Preferred-Languages: en,tr
Expires: [INSERT FUTURE UTC DATE]
Publication note
The Expires value must be a future UTC timestamp and should be renewed before expiration. The /security page should exist before publishing this file.
Required fields
Contact and Policy should point to live URLs/mailboxes. Expires should be a future UTC timestamp.
Language
Preferred-Languages may be updated as supported languages expand.
Maintenance
The file should be reviewed before its Expires date and kept reachable over HTTPS.
20. 20 Privacy Request Form
Suggested production copy for a privacy/data-subject request form.
Intro
Use this form to request access, correction, deletion, restriction, objection, portability or another privacy right available under applicable law.
Fields
Email address associated with the account, if applicable.
Request type.
Description of the request.
Relevant Short Link/account identifier, if applicable.
Additional information needed to locate the data.
Confirmation that the information provided is accurate.
Security notice
Do not submit passwords, authentication codes or unnecessary sensitive information.
Verification
We may request reasonable identity verification before disclosing or changing personal data.
Contact
Formal privacy requests may also be sent to legal@urly.tr.
Access request
Users may request a copy of personal data and relevant processing information where applicable.
Correction request
Users should identify the inaccurate field and the proposed correction.
Deletion request
Users should identify the account or data to be deleted; deletion may be limited by legal or security exceptions.
Objection/restriction
Users should explain the processing they object to or want restricted.
Portability
Where applicable, users may request portable data in a structured format.
Verification
URLy may request reasonable identity evidence and will seek to minimize collection of verification information.
No passwords
The form must not request the user’s password or authentication codes.
Response
Requests are handled according to applicable legal deadlines.
21. 21 Abuse Report Form
Suggested production copy for an abuse/security report form.
Intro
Use this form to report phishing, malware, fraud, scams, impersonation, illegal activity, child-safety concerns or other violations of URLy policies.
Fields
Short Link URL.
Destination URL, if safely available.
Suspected category.
Description.
Relevant dates/context.
Reporter contact information.
Safety notice
Do not download malware or illegal material to investigate a report. Do not upload or redistribute CSAM or other illegal material merely to support a report.
Priority
Serious security and child-safety reports should be sent to abuse@urly.tr.
Phishing
Include the impersonated organization and suspected credential-collection behavior.
Malware
Include the URL and observed behavior without uploading malicious payloads.
Fraud
Describe the deceptive scheme and affected service or organization.
Privacy abuse
Report doxxing, unlawful exposure of personal information or serious privacy violations.
Child safety
Use abuse@urly.tr for urgent child-safety reports and do not upload illegal material.
Weapons/drugs/gambling
Provide enough context to distinguish unlawful commercial facilitation from legitimate discussion.
False reports
Reports should be made in good faith.
Reporter safety
Do not expose your own unnecessary sensitive information in the form.
22. 22 Copyright Trademark Form
Suggested production copy for an intellectual-property complaint form.
Intro
Use this form to report alleged copyright or trademark infringement involving a URLy Short Link or URLy-controlled material.
Fields
Name and contact information.
Rights holder or authorized representative status.
Identification of copyrighted work or trademark.
Identification of Short Link/material.
Explanation of alleged infringement.
Supporting documentation where appropriate.
Required legal declarations/certifications.
Review
URLy may request additional information or temporarily restrict a Short Link while reviewing a serious complaint. A complaint does not automatically establish infringement.
Destination limitation
URLy may not control content hosted by a third-party destination.
Contact
Formal legal/IP matters may also be sent to legal@urly.tr.
Copyright fields
Identify the work, rights holder, disputed URL/Short Link and basis of the claim.
Trademark fields
Identify the mark, owner/registration where relevant and explanation of likely confusion or infringement.
Authorization
Representatives should identify their authority to act.
Evidence
Attach only evidence reasonably necessary to substantiate the complaint.
Counter-notice
Where applicable, affected users may request reconsideration or submit a legally sufficient counter-notice.
Destination limitation
Complaints about material hosted entirely by a third party may need to be sent to that host.
Bad-faith notices
Fraudulent or knowingly false complaints may be rejected.
Legal contact
Formal legal/IP matters should be sent to legal@urly.tr.
Implementation Alignment Appendix
A. Data inventory to policy mapping
Users table information maps to account, authentication and security disclosures. URLs table maps to Short Link, Destination URL, creator IP, title, click limits, expiration and status disclosures. Click logs map to IP, user agent, browser, OS, device, referrer, country/region/city, language and timestamp disclosures. IP geolocation cache maps to approximate location processing. Support tickets and API applications map to support/API processing disclosures.
B. Current technical privacy items requiring implementation alignment
The backend utilizes local on-premise IP geolocation and encrypted edge headers (ip-api.com has been removed). The ip_geo_cache table should have an explicit cleanup mechanism aligned with published retention. urls.creator_ip should have a defined retention path. Referrer storage should be reviewed for query-string and fragment minimization. Support-ticket and API-application retention should be explicitly implemented. These are implementation alignment items, not claims that they are already fixed.
C. Proxy and IP integrity
If HTTP_CF_CONNECTING_IP or X-Forwarded-For is used, only trusted proxy infrastructure should be allowed to supply the effective client IP. Otherwise clients may spoof headers and corrupt security logs, rate limits and abuse decisions.
D. Secret handling
Credentials present in the previously uploaded backend package should be treated as exposed. Database passwords, SMTP passwords, cron tokens and other production-like secrets should be rotated. If any secret was ever committed to public source control, history should be cleaned and credentials replaced.
E. Destination safety
SSRF protections should cover loopback, private, link-local and reserved IP ranges and should account for DNS rebinding and hostname-to-IP changes. Destination validation must not rely solely on a one-time hostname check.
F. Cookie verification
Production should verify Secure, HttpOnly and SameSite behavior for every authentication/session cookie. SSL Labs observations should not substitute for direct application verification.
G. Retention implementation
Published retention is a policy target. Production jobs should actually enforce cleanup for click logs, IP geolocation cache, creator IP, support/API records, rate-limit records and other personal-data stores as appropriate.
H. Slug protection architecture
Normalization should include Unicode NFKC, case folding, separator normalization, script detection, mixed-script detection, confusable skeleton, transliteration/ASCII comparison, exact/alias/variant matching, high-risk patterns, brand proximity and category scoring. Audit records should retain rule version and decision reason without exposing evasion-sensitive details publicly.
I. Moderation architecture
Content/abuse enforcement should remain separate from slug reservation. Automated risk scoring can feed REVIEW or enforcement, while human review and appeal should remain possible where appropriate.
J. Legal publication workflow
Publish the English authoritative version first. After legal approval, produce Turkish localization without changing substantive obligations accidentally. Effective dates and version numbers should be identical across language versions unless a language-specific legal notice requires otherwise.
K. Security.txt
Publish /.well-known/security.txt only after https://urly.tr/security exists. Renew the Expires timestamp before it expires.
L. Operational evidence
Keep versioned copies of published policies and record effective dates so that the policy applicable at the time of an incident or request can be established.
M. Legal review boundary
This package is a comprehensive drafting and operational-policy set, not a substitute for advice from qualified Turkish counsel or specialist privacy/IP counsel. The most important legal-review points are KVKK data transfers, GDPR/UK international transfers, copyright/takedown obligations, consumer law, electronic communications, jurisdiction and retention.
Final Go-Live Checklist
Replace all [INSERT EFFECTIVE DATE] placeholders.
Set a future UTC Expires value in security.txt.
Publish /security before publishing security.txt.
Confirm actual cookie flags in production.
Replace ip-api.com with local GeoIP if that is the chosen architecture, then update the privacy/subprocessor notices. [COMPLETED: Local GeoIP implemented; ip-api.com removed; privacy notices updated].
Implement ip_geo_cache cleanup.
Implement creator_ip retention/cleanup.
Review referrer minimization.
Define support/API record retention.
Verify trusted-proxy IP handling.
Rotate previously exposed production-like secrets.
Verify SSRF protections against DNS rebinding and private-IP resolution.
Version the policies and retain prior published versions.
Perform Turkish localization after English legal approval.
Obtain qualified legal review before relying on the policies as contractual/legal notices.