Global Privacy Policy
URly / urly.tr
Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]
This Policy explains what information URLy processes, why it is processed, how it is protected, when it may be shared and how users can exercise privacy rights.
1. Controller
URLy is operated by Firma Life. Registered address: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye.
2. Information collected
Account and authentication information.
User-submitted URLs, Short Link metadata and API information.
IP address and approximate IP-derived country/region/city.
Browser, browser language, operating system, device type, access time and available referrer information.
Click/access information and link analytics.
Support, abuse, security, moderation and legal-request records.
3. Approximate location
IP-based location is approximate and is not precise GPS location.
4. Local IP geolocation processing
URLy resolves approximate geolocation locally on-premise using encrypted edge headers and local databases. IP addresses are NOT transmitted to third-party IP geolocation API providers (ip-api.com has been decommissioned). Approximate location is limited to country/region/city and is never precise GPS tracking.
5. Purposes
Providing and maintaining the Service.
Account and Short Link management.
Analytics and operational measurement.
Security, fraud and abuse prevention.
Phishing, malware and suspicious-domain detection.
Customer support and legal/rights requests.
Compliance with applicable law and valid legal process.
Service reliability and improvement.
6. Legal bases
Depending on the jurisdiction, processing may rely on contract, legal obligation, legitimate interests, consent or another lawful basis.
7. Analytics and advertising
URLy does not currently use third-party advertising or third-party analytics platforms for user tracking. URLy’s own infrastructure may process technical and click/access information for service analytics, security and abuse prevention.
8. Cookies
See the Cookie Policy. Essential session, authentication, security and preference technologies may be used.
9. Sharing
Data may be shared with processors, service providers, authorities where legally required or authorized, and other parties where necessary to protect rights, safety or the Service. URLy does not sell personal data.
10. International transfers
Primary infrastructure is in Türkiye. Certain processors, including the current IP-geolocation provider, may process data outside Türkiye. Where law requires transfer safeguards, appropriate lawful mechanisms and safeguards will be used.
11. Retention
General retention targets are described in the Data Retention & Deletion Policy. Exact deletion dates may vary because of legal holds, security investigations, disputes, backups and other lawful exceptions.
12. Security
URLy supports TLS 1.2/1.3, disables legacy SSL/TLS, uses modern authenticated encryption cipher suites, supports forward secrecy and X25519MLKEM768, and has received an A rating in Qualys SSL Labs testing for the primary endpoint. No security system can guarantee absolute protection.
13. Rights
Depending on applicable law, users may have rights to access, correct, delete, restrict, object, obtain portability, withdraw consent and challenge certain automated decisions.
14. Children
URLy prohibits child sexual exploitation and related abuse. Reports should be sent to abuse@urly.tr.
15. Third-party destinations
Destination websites have their own privacy practices. URLy does not generally control their content or privacy practices.
16. Changes
This Policy may be updated when practices, law or the Service changes.
Account and authentication records
Account records may include email address, verification state, password hash, password-reset or email-change tokens, account status, language preference, API-related identifiers and security timestamps. Passwords should be stored as hashes rather than plaintext.
Support and communications
When users contact support, URLy may process the name, email address, subject, message, attachments or verification information necessary to answer the request.
API applications
API application records may include project name, purpose, domain, associated account, API key metadata and source IP. These records may be used for approval, security, abuse prevention and support.
Security and abuse logs
Security records may include event type, timestamps, IP address, account or Short Link identifiers, rule identifiers, risk scores and enforcement outcomes. Access to these records should be restricted.
Referrer information
Where HTTP referrer information is collected, it may contain information supplied by the browser. URLy should minimize unnecessary query-string or fragment data where technically feasible because referrer URLs can contain sensitive information.
IP handling
IP addresses are used for security, abuse prevention, rate limiting, operational analytics and approximate geolocation. An IP address can be personal data under applicable law.
Data minimization
URLy seeks to process information that is reasonably necessary for the purposes described in this Policy. Users should avoid submitting unnecessary sensitive personal data.
Legal requests
When legally compelled or authorized, URLy may disclose relevant records. It will not promise to produce information it does not possess.
Changes in providers
If URLy adds analytics, advertising, security, geolocation, hosting or other providers that materially affect personal-data processing, privacy disclosures should be reviewed and updated.
Data breach response
URLy may investigate suspected personal-data breaches, contain affected systems, preserve evidence and make notifications required by applicable law.