Privacy Policy

Last Updated August 17, 2026

This Privacy Policy explains how minzo.link ("minzo.link," "we," "us," or "our") collects, uses, discloses, and protects information when you use our website, dashboard, API, and related services (collectively, the "Service"), including our link shortening, QR code, link-in-bio, survey, monitor, overlay, splash page, campaign, channel, and file hosting tools.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the Service.

1. Who We Are
minzo.link is operated by [minzodotlink]. For any question regarding this Policy or your personal data, contact us at contact@minzo.link.

2. Scope of This Policy
This Policy applies to all visitors, registered users, and API clients of the Service. It covers data we collect directly from you (as an account holder) and, where relevant, data collected about visitors who click on links, scan QR codes, or interact with content created by our users (such as bio pages, surveys, overlays, and splash pages).

If you are a visitor who clicked a shortened link, scanned a QR code, or filled out a survey/overlay created by one of our users, please note that the person or organization who created that content ("the Link Creator") is independently responsible for how they use our tools and for their own compliance with applicable law regarding the people who interact with their content. We act as a service provider to the Link Creator in that context.

3. Information We Collect
3.1 Information You Provide Directly
Account information: username, email address, password (stored hashed, never in plain text), profile details you choose to add.
Content you create: shortened links and their destination URLs, custom aliases, QR code data (including vCard, WiFi, crypto wallet addresses, calendar events, or file uploads you embed), bio page content and widgets, survey questions and design, overlay and splash page content, campaign and channel names, custom domains you connect, pixel IDs you attach to your links.
Files you upload: through the link shortening, QR, bio page, or file hosting features, including any files you optionally choose to password-protect or encrypt at rest.
Survey responses: if you fill out a survey created by one of our users, we process the answers you submit on behalf of that Link Creator.
Form submissions: messages sent through overlay contact forms, newsletter capture overlays, our Contact Us form, and abuse/link reports.
Payment and donation information: when you make a donation or purchase a paid plan, payment details are collected and processed by our third-party payment processors (see Section 9). We do not store full payment card numbers on our servers.
Identity verification documents: if you go through our optional identity verification (KYC) process, you may be asked to upload a government-issued document, which is reviewed by our staff and retained only as long as necessary for verification and fraud-prevention purposes.
Communications: any correspondence you send us via email, contact forms, or support channels.
3.2 Information Collected Automatically
Device and connection data: IP address, browser type and version, operating system, device type (mobile/desktop/tablet), screen resolution, and language settings.
Usage and click data: timestamps of clicks/scans/visits, referrer URL, approximate geographic location (country/city) derived from your IP address using a geolocation database, and interaction patterns with links, QR codes, bio pages, surveys, and overlays.
Cookies and similar technologies: see Section 4 below.
Security and infrastructure logs: our infrastructure sits behind a content delivery/security network (such as Cloudflare), which processes connection-level data, including IP addresses, to protect the Service from abuse, bots, and attacks.
3.3 Information from Third Parties
Social login: if you register or log in using Google, Facebook, or Twitter/X, we receive basic profile information (such as your name, email, and profile picture) from that provider, as permitted by your settings with them.
Payment processors: confirmation of successful or failed transactions, subscription status, and limited billing metadata from our payment gateways.
Integrations you connect: if you connect third-party tools such as Zapier, Slack, WordPress, Mailchimp, or iOS Shortcuts to your account, we exchange the data necessary to operate that integration, governed also by that third party's own terms and privacy policy.
4. Cookies and Tracking Technologies
We use cookies and similar technologies for:

Strictly Necessary: authentication/session cookies, security tokens (CSRF protection), and load balancing. These cannot be disabled without breaking core functionality.
Functional: remembering your theme preference (light/dark), language, and other display settings.
Analytics: understanding aggregate usage of the Service via Google Analytics, only loaded after you consent through our cookie banner.
Advertising: cookies that may be used to serve or measure advertisements on free-tier pages, only loaded after you consent through our cookie banner.
We display a cookie consent banner on your first visit, and you can review or change your preferences at any time via the "Cookie Settings" link in our website footer. A separate long-lived cookie may be used on public survey pages to prevent duplicate submissions from the same browser.

5. Tracking Pixels Attached by Link Creators
Our platform allows registered users to attach third-party retargeting/analytics pixels to their own short links, including but not limited to Google Tag Manager, Google Analytics, Google Ads, Meta/Facebook, LinkedIn, Twitter/X, TikTok, Pinterest, Snapchat, Reddit, Quora, Bing, and AdRoll.

This is important for anyone clicking a minzo.link short link or scanning a related QR code: when a pixel is attached to a link, the corresponding third-party provider may collect data about your visit (such as your IP address, device identifiers, and browsing behavior) directly, independent of minzo.link, and in accordance with that provider's own privacy policy. We do not control, and are not responsible for, how these third parties process that data. Link Creators are solely responsible for disclosing their use of tracking pixels to their own audience where required by applicable law, and for obtaining any consent that law requires.

6. How We Use Information
We use the information we collect to:

Provide, operate, maintain, and improve the Service, including redirecting shortened links, generating QR codes, rendering bio pages, and displaying analytics to account holders about their own content.
Create and manage your account, authenticate you, and provide customer support.
Process payments, donations, subscriptions, vouchers, and coupon redemptions.
Detect, prevent, and investigate fraud, malware, phishing, spam, abuse, and violations of our Terms of Service, including automated safe-browsing/malware scanning of submitted URLs and uploaded files.
Send you transactional and security emails (such as login alerts, password resets, 2FA codes, donation receipts) and, where you have opted in, product announcements and marketing communications.
Respond to abuse reports and copyright/DMCA notices submitted through our Report a Link and Contact forms.
Comply with legal obligations and enforce our Terms of Service.
Generate aggregated, de-identified statistics about Service usage.
7. Legal Bases for Processing
Depending on your location, we process personal data on one or more of the following bases: performance of a contract with you (providing the Service you signed up for), our legitimate interests (such as fraud prevention, service security, and improving the Service), your consent (such as for optional cookies, marketing emails, or KYC verification), and compliance with legal obligations.

8. How We Share Information
We do not sell your personal data to data brokers. We may share information with:

Service providers ("processors") who help us operate the Service, including hosting providers, email delivery providers, security and content-delivery infrastructure, geolocation database providers, and analytics providers (Google Analytics).
Payment processors listed in Section 9, solely to process the transaction you initiate.
Third-party integrations you explicitly connect to your account (Zapier, Slack, WordPress, Mailchimp, OAuth login providers, iOS Shortcuts).
Legal and safety purposes: when required by law, subpoena, or court order, or to protect the rights, property, or safety of minzo.link, our users, or the public, including sharing information related to malicious links, fraud, or illegal content with law enforcement.
Business transfers: if minzo.link is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction, subject to this Policy or a materially similar one.
With your consent or at your direction: for example, if you make your link, bio page, survey results, or campaign public.
9. Payment and Donation Processing
Payments and voluntary donations may be processed through one or more of the following third-party processors, depending on what is enabled at any given time: Stripe, PayPal, Mollie, Paddle, and PayStack, as well as manual bank transfer. Each processor has its own privacy policy governing how it handles your payment data. We only receive confirmation of payment status and limited billing metadata necessary to manage your account and plan.

10. Data Retention
Account data is retained for as long as your account is active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
Click, scan, and visitor analytics data is retained according to the statistics retention period associated with your plan, shown on your Billing page (the default retention window may be changed by the Service administrator at any time).
Deleted content (links, QR codes, bio pages, etc.) may be held temporarily in a recovery window (a courtesy period, currently up to approximately 90 days) before permanent deletion, to allow recovery from accidental deletion.
Identity verification documents, if submitted, are retained only as long as necessary to complete verification and satisfy any applicable legal retention requirement, then deleted.
You may permanently delete your account and associated data at any time via your account settings; some information may be retained where required by law or for legitimate business purposes (such as fraud logs or financial records).
11. Data Security
We use industry-standard measures to protect your information, including encrypted password storage, encrypted data transmission (HTTPS/TLS), optional two-factor authentication (TOTP and email-based), optional at-rest encryption for hosted files, and access controls for our administrative systems. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security of your information.

12. International Data Transfers
Your information may be processed and stored on servers located in a country other than your own. By using the Service, you consent to the transfer of your information to countries which may have data protection laws different from those of your country of residence. We take reasonable steps to ensure your data is treated securely wherever it is processed.

13. Children's Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children under that age. Some features (such as bio pages) include an age-gate mechanism that Link Creators may enable for age-restricted content; enabling that gate does not, by itself, verify the age of a visitor. If you believe a child has provided us with personal data, please contact us at contact@minzo.link so we can investigate and delete it.

14. Your Rights and Choices
Depending on your location, you may have the right to:

Access the personal data we hold about you.
Correct inaccurate or incomplete data via your account settings.
Delete your account and personal data through our self-service account deletion feature, or by contacting us.
Export/port certain data you have created (many of our tools support CSV/PDF export of your own links, QR codes, and statistics).
Object to or restrict certain processing, including opting out of marketing emails via the unsubscribe link in any such email.
Withdraw consent at any time for processing based on consent (such as optional cookies), without affecting the lawfulness of processing carried out before withdrawal.
Manage cookie preferences at any time via the "Cookie Settings" link in our footer.
To exercise any of these rights, contact us at contact@minzo.link. We may need to verify your identity before fulfilling certain requests.

Please note: because tracking pixels described in Section 5 are controlled by third parties, requests to access or delete data collected through those pixels must generally be directed to the relevant third-party provider directly.

15. Do Not Track
Some browsers offer a "Do Not Track" signal. There is currently no accepted industry standard for how to respond to such signals, and our Service does not currently respond differently based on them.

16. Automated Processing
We use automated systems (including malware/phishing scanning services) to screen submitted URLs and uploaded files, which may result in a link or file being automatically disabled pending or following review. We do not use automated decision-making that produces legal or similarly significant effects concerning individuals beyond enforcement of our Terms of Service.

17. Third-Party Websites
Our Service is designed to redirect visitors to destination URLs chosen by our users, and to display QR codes and bio pages that may link to third-party websites, applications, and social media profiles. We are not responsible for the privacy practices or content of any third-party website or service you access through the Service. Review the privacy policy of any third-party site before providing it with personal data.

18. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a notice on the Service and/or sending an email to the address associated with your account. The "Last Updated" date at the top of this Policy indicates when it was last revised. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

Email: contact@minzo.link
Entity: minzodotlink