Privacy Policy

Effective Date: June 5, 2026  ·  Last updated: June 5, 2026

trimy.io ("trimy", "we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI link intelligence platform at trimy.io, including all associated features such as analytics, QR code generation, campaign management, team collaboration, A/B testing, smart routing, and AI-powered tools.

By accessing or using trimy, you agree to the collection and use of information described in this Policy. If you do not agree, please do not use our services.

1. Information We Collect

1.1 Account Information

When you register, we collect:

  • Name, email address, and username
  • Password (stored as a one-way hash; we never store your plain-text password)
  • OAuth provider identity (Google or GitHub) if you sign in via a third-party provider
  • Profile preferences and settings

1.2 URL and Content Data

When you use our service, we store:

  • The destination URLs you shorten and any associated metadata (title, description, tags)
  • Custom short codes you create
  • Password hashes for password-protected links
  • Link expiration dates
  • UTM campaign parameters (source, medium, campaign, term, content)
  • QR code customization settings
  • A/B test configurations and variant data
  • Smart routing rules (geo, device, OS, browser conditions)

1.3 Analytics and Click Tracking Data

When a visitor clicks one of your shortened links, we record the following data to provide analytics to you (the link creator). This data is associated with the click event, not with the visitor's trimy account:

  • Network: IP address (used to derive location; may be anonymized per plan settings), Internet Service Provider (ISP)
  • Geographic: Country, region/state, city, timezone, approximate latitude and longitude (derived from IP address — not GPS)
  • Device: Browser name and version, operating system and version, device type (mobile/tablet/desktop), screen language/locale
  • Referrer: Referring domain, referrer URL, referrer category (social, search, email, direct, other)
  • UTM Parameters: Any UTM tags present in the click URL
  • Bot Detection: Whether the click was identified as automated (bot score via Cloudflare)
  • Timestamp: Date and time of the click (stored in UTC)
  • Channel: Whether the click originated from a QR code scan or a direct link click

We use this data exclusively to provide analytics dashboards to link creators. Click-level data is retained based on your subscription plan (Free: 14 days, Starter: 60 days, Professional: 120 days, Business: 365 days).

1.4 Retargeting Pixel Data

If you (the link creator) configure retargeting pixels on your links, clicking those links may cause third-party pixel scripts (Facebook, Google Ads, LinkedIn, TikTok, Twitter/X, Snapchat) to fire in the visitor's browser. This data is collected directly by those third-party platforms under their own privacy policies. trimy does not receive or store the pixel event data itself — we only facilitate the integration.

1.5 Payment Information

If you subscribe to a paid plan, payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. We do not collect or store your card number, CVV, or full payment details. We receive from Stripe only:

  • Billing name and address
  • Last four digits of your payment method
  • Card expiration date
  • Stripe customer and subscription identifiers

1.6 Team and Organization Data

For team collaboration features, we store organization names, team names, member roles, team invitations, and activity logs. Activity logs record actions such as URL creation, member additions, and role changes, and are retained based on your plan (Professional: 30 days, Business: 90 days).

1.7 Communications Data

If you contact us via our contact form or email, we retain your name, email address, and the content of your message for the purpose of responding to you and improving our service.

1.8 Technical and Usage Data

We automatically collect technical data when you use the trimy dashboard, including browser type, operating system, pages visited, time on page, and error events. This is used for platform stability, security monitoring, and product improvement.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and provide the core URL shortening service
  • Generate analytics reports and dashboards for your links
  • Process subscription payments and manage billing
  • Send transactional emails (account verification, password reset, billing notifications, team invitations)
  • Enforce subscription plan limits and feature access
  • Detect and prevent abuse, spam, phishing, and security threats
  • Validate destination URLs against threat databases (Google Safe Browsing)
  • Perform bot detection to improve analytics accuracy
  • Monitor platform health, fix bugs, and improve performance
  • Comply with applicable laws and legal obligations
  • Respond to support requests and communications

We do not use your data for advertising profiling, and we do not sell your personal data to third parties.

3. AI Features and Data Processing

For users on eligible plans (Professional and Business), trimy offers optional AI-powered features including link title suggestions, analytics narrative summaries, A/B test interpretation, and campaign health scoring. When you use these features:

  • Relevant context (e.g., anonymized analytics aggregates, UTM parameters, link metadata) is sent to an AI language model API to generate the response.
  • We do not send personally identifiable information such as names, email addresses, or raw IP addresses to AI providers.
  • AI feature usage is logged (feature name, token counts, success/failure) for billing and quota enforcement purposes.
  • AI features are gated by your subscription quota and a global monthly token budget. Usage is tracked per organization.
  • AI responses are generated on-demand and are not permanently stored, except where you explicitly save a suggestion.

4. Third-Party Services

We use the following third-party services. Each processes certain data as described:

Service Purpose Data Shared
Stripe Payment processing Billing name, address, payment method details
Google Analytics Platform usage analytics Anonymized usage, page views (consent-gated)
Microsoft Clarity UX heatmaps & session insight Anonymized session data, scroll/click patterns (consent-gated)
SendGrid Transactional email delivery Email address, email content
Cloudflare CDN, DDoS protection, SSL, bot scoring IP addresses, request metadata
Cloud Infrastructure Provider Hosting & file storage (EU-based) Application data, generated image files
Google Safe Browsing URL threat detection Destination URLs being validated (hashed format per Google's API)
Error Monitoring Provider Application stability & error tracking Anonymized error events, no personal data
Google / GitHub OAuth Third-party sign-in Name, email, provider ID (only on login)

All third-party processors are subject to data processing agreements and are contractually obligated to protect your data.

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your information only in these circumstances:

  • Service Providers: Third-party vendors who help us operate the platform (listed in Section 4 above), bound by data processing agreements.
  • Legal Requirements: If required by law, court order, or government authority, or to protect the rights, property, or safety of trimy, our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, or sale of all or substantially all of our assets. Users will be notified via email and a prominent notice on our site before any transfer occurs.
  • Team Collaboration: Within your organization, team members may see the short links you create and the analytics associated with team-owned URLs, according to their assigned role and permissions.
  • With Your Consent: Any other sharing will only occur with your explicit consent.

6. Data Retention

We retain your data for as long as necessary to provide our services:

  • Account Data: Retained for the life of your account. Upon deletion, account data is removed within 30 days, except where retention is required by law.
  • Click Analytics Data: Retained per your subscription tier — Free: 14 days, Starter: 60 days, Professional: 120 days, Business: 365 days. Older data is purged automatically.
  • Team Activity Logs: Free/Starter: not retained, Professional: 30 days, Business: 90 days.
  • Payment Records: Billing history is retained for 7 years to comply with financial and tax regulations.
  • Communications: Support messages and contact form submissions are retained for up to 2 years.
  • AI Usage Logs: Token usage records are retained for 13 months for quota enforcement and cost auditing.

7. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated personal data ("right to be forgotten").
  • Portability: Request your data in a structured, machine-readable format.
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on our legitimate interests.
  • Withdraw Consent: Withdraw consent for analytics cookies at any time via your browser settings.
  • Complaint: Lodge a complaint with your local data protection authority (for EU/EEA residents, this is your national supervisory authority).

To exercise these rights, contact us at [email protected]. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before fulfilling your request.

GDPR — European Users

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under GDPR. Our legal bases for processing include: contractual necessity (providing the service), legitimate interests (security, fraud prevention, product improvement), legal obligation (financial records), and consent (optional analytics cookies). Business customers requiring a Data Processing Agreement (DPA) may request one at [email protected].

CCPA — California Residents

California residents have the right to know what personal information we collect and for what purpose, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at [email protected]. We will not discriminate against you for exercising these rights.

8. Security

We implement industry-standard security measures to protect your data, including:

  • TLS/HTTPS encryption for all data in transit
  • Strong one-way hashing for passwords and credentials
  • Cryptographically secure API key generation and hashed storage
  • Encrypted, signed session tokens with tamper detection
  • DDoS protection and automated bot filtering at the network edge
  • Rate limiting on all sensitive endpoints
  • Continuous monitoring, anomaly detection, and alerting

In the event of a data breach that is likely to result in high risk to your rights and freedoms, we will notify you and relevant regulatory authorities within 72 hours of becoming aware of the breach, as required by applicable law. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

9. International Data Transfers

trimy operates on EU-based cloud infrastructure. Some third-party services we use (such as Stripe and Google) may process data in the United States or other countries. Where such transfers occur, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or the UK Addendum to SCCs for UK data. By using our service, you acknowledge that your data may be transferred internationally.

10. Cookies

We use cookies and similar technologies. A full description of the cookies we use, why we use them, and how to manage them is available in our Cookies Policy.

11. Children's Privacy

Our services are not directed at children under the age of 16 (or 13 in jurisdictions where 13 is the applicable minimum age). We do not knowingly collect personal data from minors. If we become aware that a child has provided us with personal data without appropriate consent, we will take steps to delete such information promptly. If you believe we have inadvertently collected data from a minor, please contact us at [email protected].

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where required by law, notify you by email or by displaying a prominent notice on our website. We encourage you to review this policy periodically. Your continued use of trimy after changes are posted constitutes your acceptance of the revised policy.

13. Contact Us

For privacy-related questions, requests, or to exercise your rights:

Email: [email protected]
Website: trimy.io/contact

We aim to respond to all privacy requests within 30 days.

Document History

Version Date Summary of Changes
1.0 June 5, 2026 Initial policy. Covers analytics, AI features, retargeting pixels, Stripe payments, GDPR/CCPA rights, and Cloudflare/SendGrid integrations.
Last updated: June 5, 2026