DLDLoly

Privacy Policy

1. Personal Data Controller

The controller of personal data in DLoly is Individual Entrepreneur Orest Mykolaiovych Kostiuk. For privacy questions and the exercise of data rights, contact kostiuk.orest.m@gmail.com. The Service is available at dloly.bitbrothers.dev.

The Ukrainian version of this Policy is legally controlling. The English version is its translation.

2. User Data and User-Created Data

• Account data: e-mail, first and last name and company name if the User has provided them, a technical account identifier, language preference, and data needed for authentication. A password is stored as a cryptographic hash, not as plain text.

• Application and link data: Application name and slug, iOS and Android settings, store addresses and fallback URL, logo, destination addresses, short codes, deep-link paths, redirect behavior, campaign settings, expiry, and password protection.

• Domain data: domain name, status and technical verification data, primary-domain setting, and SSL settings.

• API data: API-key name and value, status, expiry, limit, usage count, and time of use. The User must treat an API key as a secret.

3. End Visitor Data and Click Analytics

When an End Visitor follows a Short Link, DLoly records the click time, full IP address, full browser user agent, referrer URL, request query parameters, and the browser, operating system, device type, and platform derived from the user agent. The IP address in the primary click record is stored in raw, untruncated, and unhashed form.

Fields for country, city, region, and coordinates exist in the data structure, but DLoly's ordinary redirect mechanism does not currently derive or populate them.

If deferred deep linking is enabled for a mobile Application, DLoly also creates an attribution record. In that record, an IPv4 address is truncated by replacing its last octet with 0; an IPv6 address is not truncated by this mechanism. The record also contains the full user agent, request language, derived platform, device type and browser, a technical click identifier, and a SHA-256 fingerprint made from technical characteristics.

On a deferred landing page, the browser may additionally send screen size and characteristics, time zone, language settings, platform, touch support, device memory and processor-thread count, cookie-availability and Do Not Track indicators, and a shortened canvas fingerprint and WebGL vendor/renderer data. This data is used to match a click with a later opening of the mobile application.

A link owner can see aggregated analytics and technical information about visits to that owner's links, including time, device, platform, browser, and referrer. The analytics API may return technical data for individual clicks, including the IP address, to the authorized owner of the relevant Application.

4. Purposes and Legal Bases

Data is processed to: create and protect accounts; provide redirects, QR codes, deep links, custom domains, and the API; show analytics to link owners; match mobile-app installations and openings with earlier clicks; diagnose errors; prevent phishing, spam, attacks, and other abuse; respond to requests; perform the agreement; and comply with law.

Depending on the operation, processing is based on performance of the agreement or steps before entering into it, legitimate interests in Service security, analytics, and support, consent where required, or compliance with a legal obligation. DLoly does not sell personal data or use it for third-party behavioral advertising.

5. Cookies and Local Preferences

DLoly uses only strictly necessary cookies for sessions, authentication, sign-in protection, and saving the selected interface language. The light or dark theme preference is stored locally in the browser. The Service does not use third-party advertising cookies.

An ordinary redirect through an unprotected Short Link does not set a cookie for the End Visitor. For a password-protected link, after successful password verification the session stores a technically necessary authorization indicator. A deferred landing page checks whether the browser supports cookies as a technical characteristic, but that check does not itself set a cookie.

6. Subprocessors and Processing Locations

• Hetzner Online GmbH (Germany, EU) — hosting for the DLoly application, PostgreSQL, and uploaded files in the current deployment.

• Sentry, using a German EU ingestion endpoint — error, performance, and technical-event monitoring. DLoly's configuration permits standard personal technical data to be sent in Sentry events when that data is present in an error or request context.

Core data for the current deployment is stored on Hetzner infrastructure in Germany. Each subprocessor receives the data needed for its technical function.

7. Retention

Account, Application, link, domain, API-key, click, and attribution data is retained while the link owner's account is active. No fixed automatic deletion period is currently configured for click and attribution records.

After a substantiated deletion request, data is deleted or anonymized in the ordinary technical cycle except for information that must be retained to comply with law, protect legal rights or security, or handle a request already submitted. Backups and Sentry events are retained for the periods configured in the relevant systems and are then deleted or overwritten.

8. Data Subject Rights

A User or another person whose data is processed may request access to and a copy of data, its correction, updating or deletion, restriction of or objection to processing where applicable, and may withdraw consent without affecting the lawfulness of earlier processing.

To exercise these rights, write to kostiuk.orest.m@gmail.com, describe the request, and provide information sufficient to locate the relevant account or click. We may ask the requester to verify identity and authority. Requests are handled on business days within 10 business days or within another period if required by law.

9. Security

DLoly uses access separation for Application data, password hashing, HTTPS in production, filtering of sensitive parameters from logs, and technical session protections. Users are responsible for protecting their passwords and API keys. No method of transmission or storage guarantees absolute security.

10. Changes to this Policy

The current version of this Policy is published on this page. Changes apply after the updated version is published; if required by law or the nature of a change, an additional notice will be provided or consent requested.