Privacy Policy
Last updated: October 7, 2026.
This policy explains in plain language how URLHop handles the personal data of account holders and of people who open the links, QR codes and pages created with it. It follows Brazil's General Data Protection Law (LGPD) and applies to visitors worldwide.
Who we are
URLHop is a product of IBLabs, the controller of the data processed by the service. For any privacy matter, use the contact page and pick the “Privacy” topic.
Data about account holders
- Sign-up: name, email, password (stored only as a hash) and preferred language.
- Content you create: links, destinations, QR codes, link-in-bio pages, folders, tags, custom domains and workspace settings.
- Team: emails of the people you invite and each person's role.
- Billing (paid plans): payment happens at Stripe; we only receive the customer identifier, the subscription status and the invoices, never card details.
- Activity log: important account actions (sign-in, link changes, plan changes), without IP addresses.
Data about people who click links and scan QR codes
To show statistics to the link owner, each click or scan records: country (provided by the delivery network), referring site (domain only), device type, whether it came from a QR code, and the date and time. We do not store IP addresses, names, emails or device identifiers, and we do not build visitor profiles.
Password-protected links check the password when it is typed, without storing it.
Why we use data
We do not sell personal data and do not use your data for advertising.
- To provide the service: redirect links, generate QR codes, publish pages and show statistics.
- Security and abuse prevention: blocking scams, malware and spam and investigating reports.
- Account communication: confirmations, plan usage notices, security and billing.
- Legal and tax obligations.
Who we share data with
We use providers that process data on our behalf only to run the service: Cloudflare (worldwide delivery of links and QR codes, DNS and click statistics), Mailgun (email delivery) and Stripe (payments, when you subscribe to a paid plan). Some of them process data outside Brazil, with the safeguards the LGPD requires.
If you set up webhooks or use the API, the data you chose is sent to the addresses you gave. We may also share data when the law or a court order requires it.
Cookies and browser storage
The public site uses no tracking or advertising cookies. The dashboard only uses what it needs to work: a session cookie, protection against forged forms and, in browser storage, the access token and your chosen language.
How long we keep data
- Account data and content: while the account exists.
- Detailed click events: about 90 days; after that only daily totals remain, according to your plan's history.
- Activity and security logs: as long as security and legal obligations require.
- After a deletion request, we erase the data within 30 days, except what the law requires us to keep.
Your rights
You may request confirmation of and access to your data, correction, portability, anonymization or deletion, information about sharing, and a review of this policy. You can also export your links as CSV at any time from the dashboard. To exercise any right, use the contact page with the “Privacy” topic; we answer within 15 days. In Brazil you may also complain to the national data protection authority (ANPD).
Security
Passwords and API keys are stored only as hashes, all traffic uses HTTPS, administrative access is restricted and every important action is logged. No system is infallible; if an incident affects your data, we will notify you and the authorities as the law requires.
Changes to this policy
We will announce relevant changes in advance by email or in the dashboard. The date of the last update is at the top of this page.