Legal
Privacy Policy
What personal data ivlink handles, why, and the choices you have. Written to be read, not just to be compliant.
Effective 3 October 2026 · Last updated 3 October 2026
1. Who we are
ivlink ("ivlink", "we", "us") is a deep-linking and link-analytics service operated by iVrs.app, 126, Gurugram Haryana. This policy covers our website at ivrs.app, the ivlink dashboard and API, the short links we serve (including on customers' own domains), and our mobile SDKs.
It is written for India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and its rules, and also explains how we handle data of people in the European Economic Area and the United Kingdom under the GDPR.
2. Our two roles
- For our own customers (people who sign up, their team members, and people who request a demo), we decide how their data is used. We are the data fiduciary (controller).
- For our customers' audiences (people who click a customer's links or use a customer's app with our SDK), we process data on the customer's behalf and under their instructions. The customer is the data fiduciary (controller) and we are their data processor. Questions about that data are best sent to the customer; we will help them respond. Our Data Processing Addendum sets out these terms.
3. Data about our customers
| What | Details |
|---|---|
| Account | Name, email address, password (stored only as a salted bcrypt hash), and email-verification status. If you sign in with Google, the name, email and profile picture Google shares with us. |
| Organization and team | Organization name, members and their roles, and the email addresses of people you invite. |
| Billing | Plan, credit balance and usage, invoices, and the billing details you enter (legal name, address, state, country, GSTIN, billing email). Payments are handled by Razorpay: we receive payment references and amounts, never your full card, UPI or bank details. |
| Content you create | Projects, links, destinations, custom link data, app settings and domains you connect. |
| Activity and security | An audit log of changes in your organization, API key usage times, and security logs (including IP addresses of requests to our dashboard and API) used to protect the service and limit abuse. |
| Sales enquiries | If you book a demo: name, work email, company, job title, company size, expected volume, the tool you use today, optional phone number and your message. |
4. Data about people who click links
When someone opens an ivlink short link, our edge network records a click so the link owner can see analytics:
- IP address: used for a moment to route the request and to derive an approximate location. We store only a one-way hash of it, salted with a secret that changes every day, so stored hashes cannot be reversed or linked across days. Raw IP addresses are not stored with click data.
- Approximate location: country, region and city, as provided by our network provider.
- Device and browser: operating system and version, device type and browser, worked out from the browser's user-agent string. The full user-agent string is not stored.
- Referring site: only the website domain the click came from, not the full address.
- Link details: the link, the time, campaign (UTM) tags, and any query parameters added to the short link.
Automated traffic and link-preview bots (for example messaging apps generating a preview) are identified and kept separate from human clicks. We do not use click data to build profiles of individuals, we do not sell it, and we do not use it for advertising.
5. Data from apps using our SDK
Customers can add our SDK to their mobile apps. On their behalf, the SDK sends us:
- Platform (iOS or Android), OS version, device model, app version and language setting.
- A random identifier the SDK creates on the device (stored by us only as a hash). We do not collect advertising IDs (IDFA/GAID), contacts, precise location or other apps' data.
- The link the app was opened with, and on Android the Play Store install referrer.
- Events and properties the customer chooses to send, and a user ID if the customer sets one.
On the first launch after an install, we may match the install to a recent click on the same network and device type (within 15 minutes on iOS) so the app can open the right content. The customer decides whether to use this feature and is responsible for telling their users about it.
6. Why we use data
- To provide the service: redirects, analytics, app linking, custom domains, team features and the API.
- To create and secure accounts, including email verification, password resets and sign-in with Google.
- To bill you: credits, subscriptions, invoices, refunds and payment reminders.
- To send service emails: invites, receipts, low-credit and payment notices. We do not send marketing email without your consent.
- To prevent fraud and abuse, including phishing and malware links, and to enforce our Acceptable Use Policy.
- To respond to demo requests and support questions.
- To meet legal obligations, such as tax and accounting records.
We rely on your consent where the law requires it, on performing our contract with you, on our legitimate interests in running a secure and reliable service, and on legal obligations. Where we act for a customer, we follow that customer's instructions.
9. Where data is stored
Our dashboard, databases and analytics run in the United States (US West). Redirects and link caches run on Cloudflare's global network, so a click is handled in a data centre close to the person clicking. This means personal data may be processed outside India. We transfer data only to countries the Government of India has not restricted, and we use providers that are contractually bound to protect it. For data from the EEA or UK, we rely on the safeguards our providers offer, such as Standard Contractual Clauses.
10. How long we keep data
- Account and organization data: while your account is active, and deleted within 90 days after you close it.
- Click and app analytics: up to 2 years, depending on the customer's plan, then deleted automatically.
- Invoices and payment records: as long as Indian tax and company law requires (generally 8 years).
- Security logs: up to 1 year. Demo requests: up to 2 years unless you become a customer.
11. Security
We encrypt data in transit with TLS, hash passwords and API keys, hash IP addresses, restrict access by role, and keep an audit log of account changes. See our Security page for details. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.
12. Your rights
Depending on where you live, you can ask us to:
- tell you what personal data we hold about you and how we use it;
- correct, complete or update it;
- delete it, unless we must keep it by law;
- withdraw consent you gave us (this doesn't affect earlier processing);
- nominate someone to exercise your rights if you die or become incapacitated (DPDP Act);
- object to or restrict some processing, or receive your data in a portable format (GDPR).
Email help@ivrs.app. We reply within 30 days. If your request is about a link or app run by one of our customers, we will pass it to them and support their response. You can also complain to the Data Protection Board of India or, in the EEA/UK, your local data protection authority.
13. Children
ivlink is a business service and is not meant for anyone under 18. We do not knowingly collect personal data from children for our own purposes. Customers must not use ivlink to track children or target them with advertising.
14. Changes to this policy
We will post changes on this page and update the date above. For significant changes we will email account owners at least 15 days in advance.
15. Contact and grievances
Questions or complaints about privacy: help@ivrs.app.
Grievance Officer: Satya Pal, iVrs.app, 126, Gurugram Haryana. Email: help@ivrs.app. We acknowledge grievances within 24 hours and resolve them within 15 days.