Legal

Privacy Policy.

Last updated: May 2026

1. Overview

This Privacy Policy describes how 302.sh (“we,” “us”) collects, uses, and safeguards information when you use our link-shortening service. We aim to collect as little as needed to run the Service well.

2. Information We Collect

Account information

When you create an account, we store your email address, name, and authentication identifiers from sign-in providers (e.g. Google).

Link data

We store the short slugs and destination URLs you create, together with timestamps and the account that owns them.

Click analytics

When someone clicks one of your links, we record aggregate information about the request to power your dashboard. Each click event is stored with: coarse geography (country, region, city) and timezone derived from the network edge; latitude and longitude rounded to city granularity; the visitor’s primary Accept-Language; a parsed user-agent summary (device class, browser, OS, bot flag); the referring site’s host (path stripped); the Cloudflare edge point-of-presence code; and the hostname under which the link was clicked. We do not store IP addresses, IP-derived fingerprints, or any personally identifying request headers. Click analytics are retained for 90 days and then deleted automatically.

Billing information

Payments are processed by Stripe. We never see or store full card numbers; we only retain the subscription state needed to run your plan.

3. How We Use Information

  • To operate, maintain, and improve the Service
  • To authenticate you and prevent abuse
  • To show your dashboard, analytics, and billing state
  • To send transactional email (account events, billing, security)
  • To comply with legal obligations

We do not sell your personal information, and we do not use your link data to build cross-site advertising profiles.

4. Sharing of Information

We share information only with the service providers needed to run 302.sh — including Cloudflare (hosting, analytics infrastructure), Stripe (payments), and our email delivery provider. Each operates under its own terms and processes data on our behalf. We may also disclose information when required by law or to protect rights, safety, and security.

5. Cookies and Local Storage

We use a small number of first-party cookies and browser storage entries. None of them are used for cross-site advertising.

Cookies

  • Session cookies — set by our authentication system to keep you signed in.
  • Sidebar state (sidebar_state) — remembers whether the dashboard sidebar is expanded or collapsed.
  • Split-test stickiness (302_split_<slug>) — when a link owner sets up an A/B split, a short cookie pins each visitor to one variant so the experience is consistent across clicks.

Local storage

  • Theme preference — light/dark mode selection.
  • Language preference — UI locale override.
  • Timezone — used so dashboard timestamps render in your local time without a round-trip to the server.
  • Pending guest links — if you create a link before signing in, it’s held in your browser so we can attach it to your account on first sign-in.

6. Data Retention

Account and link data is retained for as long as your account is active. Click analytics are retained for 90 days. When you delete your account, your data is removed within a reasonable window, except where retention is required by law.

7. Security

We use industry-standard measures — encryption in transit, hashed credentials, scoped tokens — to protect your data. No system is perfectly secure; you use the Service at your own risk.

8. Your Rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. You can manage most of this directly from your account settings, or contact us for help.

9. International Users

302.sh may be operated from, and your data processed in, countries other than your own. By using the Service, you consent to such transfers in accordance with this policy.

10. Children

The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the Service or by email. The “Last updated” date at the top reflects the most recent revision.

12. Contact

Privacy questions or requests? Reach us at support@302.sh.