Privacy
What we collect, what we deliberately do not, and who else sees it. Written to be read rather than to be defensible.
Last updated 10 September 2026
What we collect about you
Your email address, because it is how you sign in and how we contact you about your account. Optionally your name and time zone, if you fill them in.
If you subscribe, Stripe holds your payment details and we store the customer and subscription identifiers they give us, along with which plan you are on and when it renews. We never see or store your card number.
There are no passwords on this service, so we hold no password or password hash for you.
What we collect about visitors to your links
When someone follows one of your short links or scans one of your QR codes, we record the time, the country, the browser, the operating system and the referring site, so that your statistics are useful.
We do not store the visitor’s IP address. To tell a repeat visit from a new one we store a salted one-way hash of the address for 24 hours and then discard it. The original address cannot be recovered from that hash, by us or by anyone else.
Automated traffic — crawlers, bots and link previewers — is redirected but not counted, so it neither inflates your numbers nor generates a record.
What we do not do
We do not sell your data. We do not run advertising, and there are no advertising or analytics trackers on the pages you or your visitors see.
Our emails contain no tracking pixels and no click-tracking wrappers, so we do not know whether you opened one.
We do not build profiles of your visitors or share their data between accounts.
Who else is involved
Cloudflare hosts the service and provides its database, storage, email delivery and bot protection. Every request necessarily passes through them.
Stripe processes payments and holds your billing details.
HubSpot receives what you type into the form on our contact page, if you use it.
Google Fonts serves the typeface used on these pages, which means Google receives the IP address of anyone loading them. We intend to serve the font ourselves and remove this.
If you connect PostMyLink to Zapier or point a webhook at your own systems, data goes wherever you send it. That part is your choice and your responsibility.
How long we keep things
Your account and your links stay until you delete them. Deleting a link stops it redirecting immediately; its click history is retained so that your historical totals do not silently change.
Sign-in links expire after 15 minutes and can be used once. The 24-hour visitor hashes expire on their own.
What you can ask for
You can export your links and their statistics as CSV from your dashboard at any time.
Write to us if you want your account and its data deleted, a copy of what we hold, or a correction to it, and we will do it. Deleting your account removes your links, which means they stop redirecting for everyone who has them.
Contact
Questions about any of this, or a request to see, correct or delete what we hold, go through our contact page.