Last Updated: September 11, 2026
Welcome to Ourl.in ("we", "our", or "us"). This Privacy Policy explains how we collect, process, retain, and protect personal and technical data when you access or use our live website (ourl.in), our official Google Chrome Extension, developer REST APIs, and link management tools (collectively, the "Service").
1. Information We Collect & Process
We seek to collect and process information reasonably necessary for providing, securing, and improving the Service, preventing abuse and fraud, complying with statutory obligations, and enforcing our agreements:
- Account Information: Full name, verified email address, account password (stored exclusively using irreversible cryptographic hashing algorithms), registration timestamp, and account status.
- URL Creation & Redirection Data: Destination URLs submitted for shortening, generated short codes/slugs, custom aliases, creation timestamps, optional link-access passwords (hashed), and bio-link profile configurations.
- Security, Abuse & Fraud Prevention Records: Client IP addresses, user-agent strings, HTTP referrers, request timestamps, click-velocity statistics, failed authentication attempts, spam-detection scores, and abuse reports filed against specific links.
- API Client Identifiers: Developer API keys, IP request histories, and automated rate-limiting counters.
2. Purpose of Data Processing
We process collected data for defined, lawful purposes:
- Service Delivery: Processing URL redirection, generating QR codes, maintaining user dashboards, and rendering link-in-bio profiles;
- Threat Mitigation & Abuse Prevention: Detecting and mitigating phishing campaigns, malware distribution, financial fraud, smishing/spam flooding, botnets, and automated brute-force attacks;
- Statutory Due Diligence: Complying with due-diligence obligations under the Information Technology Act, 2000 and the IT Intermediary Rules, 2021 (as amended);
- Law Enforcement & Legal Compliance: Responding to lawful court orders, subpoenas, or statutory agency inquiries;
- Analytics & Platform Health: Aggregated, non-identifying click metrics to evaluate link performance and server load.
3. Google Chrome Extension Privacy & Data Practices
When you install and use the official Ourl.in URL Shortener & Link Manager Chrome Extension, we process only the minimal data strictly necessary to deliver the advertised link shortening, QR code generation, and link management tools. The extension adheres strictly to data minimization principles:
Information Processed by the Extension
- Submitted Destination URLs: Web addresses that you explicitly enter, paste, or submit to generate short links, custom aliases, QR codes, or bio-link pages via the Ourl.in API (
https://ourl.in/api/v1/*). - Browser Tab URLs: When you click the extension popup or context menu to shorten the current webpage, or when you explicitly click the "From open tabs" button in Bulk Shorten, the extension reads the URLs of open tabs. The extension does not run background browsing monitoring, does not read page content or form fields, and does not record or transmit your continuous web browsing history.
- Clipboard Access: The extension reads clipboard text strictly and solely upon your explicit user action when you click the "Paste" button in the single or bulk URL input interfaces. It never monitors your clipboard in the background. When you click "Copy", it writes the generated short link or QR code directly to your clipboard.
- Account Authentication: If you sign in through the extension, your email address and credentials are securely transmitted over HTTPS to authenticate your session. The resulting session token (
auth_token) is saved locally within Chrome's isolated extension storage (chrome.storage.local) so you do not need to log in repeatedly. The extension does not store your raw password. - Device Identifier (
X-Device-Id): A random UUID client identifier (X-Device-Id) is generated and stored locally in extension storage. It is transmitted with API requests for installation identification, abuse prevention, and service security. Guest quota enforcement is based on the server-side IP controls described in our Terms of Use. - Local Activity History ("Today's Activity"): Recent URLs shortened within the extension popup are cached locally on your device (destination URL, shortened URL, title, timestamp) up to 150 items. This history is stored entirely on your local machine, is never synchronized to our servers, and is automatically cleared when the extension next accesses its activity history on a new calendar day.
4. Chrome Web Store Limited Use & Permission Justifications
Ourl.in strictly complies with the Google Chrome Web Store User Data Policy, including the Limited Use requirements:
- Single Purpose: All data processed by the Chrome extension is used solely to provide, support, and enhance the user-facing link shortening, QR generation, and link-in-bio features.
- Zero Data Selling: We never sell, lease, or rent user data, tab URLs, or personal information to third parties, data brokers, or advertising networks.
- No Targeted or Cross-Site Advertising: We do not transfer or share user data with third parties for personalized, behavioral, or cross-site browsing tracking.
- No Financial Lending Use: We do not use or transfer user data to assess creditworthiness or for financial lending decisions.
- End-to-End Encryption in Transit: All communication between the extension and the Ourl.in API is encrypted using modern TLS/HTTPS protocols.
5. Data Retention & Security Logs
We maintain appropriate data retention schedules aligned with operational and statutory needs:
- Account & Link Records: Maintained for the duration of your active account to provide ongoing link redirection services. Upon account deletion, personal profile identifiers are purged or anonymized.
- Security & Abuse Logs: We retain security logs, threat indicators, IP access records, and abuse reports for as long as reasonably necessary to investigate security incidents, prevent recurrent fraud, resolve disputes, enforce our Terms, and comply with applicable statutory retention requirements.
- Chrome Extension Cache: Temporary link histories in the extension popup automatically expire and purge daily.
6. Information Sharing & Third Parties
Ourl.in does not sell, rent, or trade your personal data. Disclosures occur only in the following limited circumstances:
- Infrastructure Service Providers: Trusted cloud hosting providers, database platforms, and CDN/DDoS mitigation networks operating under strict confidentiality and security covenants.
- External Security & Threat Intelligence Providers: To detect, investigate, and mitigate malicious destinations, phishing infrastructure, and ransomware payloads, Ourl.in may query external reputation services, threat intelligence feeds, blocklists, and automated URL scanning APIs using submitted destination URLs and associated technical metadata.
- Legal & Statutory Compliance: Where required by law, court order, or authorized government agencies under the Information Technology Act, 2000 or criminal procedure codes.
- Protection of Rights: Where disclosure is necessary to investigate potential violations of our Acceptable Use Policy, combat fraud, or protect the security of users.
7. User Rights & Account Controls
Depending on your jurisdiction and applicable data protection legislation, you are entitled to exercise the following formal privacy rights:
- Right to Access: You have the right to confirm whether your personal data is being processed, and to access your profile data, link activity, QR codes, and click analytics directly via your account dashboard or by submitting a written request.
- Right to Rectification: You have the right to request correction or updating of inaccurate, outdated, or incomplete personal data via your dashboard account settings or by contacting our support team.
- Right to Erasure (Deletion): You have the right to request the deletion of your personal data and account records. You can delete individual short links at any time from your dashboard. To request permanent account closure and erasure of personal identifiers, email support@ourl.in from your registered email address.
- Right to Withdraw Consent: Where our data processing is grounded upon your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
- Right to Restrict or Object to Processing: You have the right to object to or request the restriction of processing of your personal information under circumstances recognized by applicable data protection regulations.
- Right to Grievance Redressal: You have the right to submit inquiries, concerns, or formal grievances regarding your personal data processing directly to our designated Grievance Officer, who will acknowledge and address your request within statutory timelines.
8. Children's Privacy
Ourl.in is not intended for or directed to children under the age of 18. We do not knowingly collect personal information from minors. If we learn that personal information of a minor has been collected without parental consent, we will promptly delete such records.
9. Grievance Officer & Statutory Redressal
In accordance with the Information Technology Act, 2000 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of the designated Grievance Officer for Ourl.in are provided below:
Officer: Grievance Redressal Team, Ourl.in
Email: grievance@ourl.in (cc: support@ourl.in)
Postal / Operational Address: New Delhi, India
Grievance Acknowledgment: Within 24 hours of receipt.
Grievance Resolution: Within fifteen (15) working days from acknowledgment.
10. Updates to this Policy
We may update this Privacy Policy periodically to reflect technological, operational, or legal developments. The revised date will be noted at the top of this document. Continued use of Ourl.in constitutes acceptance of the updated policy.