Privacy Policy
Effective 2026-08-24 · The unusual part first: we never store your visitors' IP addresses.
What we collect about you (the account holder)
Your email address, a password hash (never the password), the links you create, and your plan. Payments are handled by Stripe — your card number never touches our servers; we store only Stripe's customer and subscription identifiers. Transactional email (sign-in links, receipts) is sent through Azure Communication Services.
What we collect when someone clicks a link
For each click we store: the time, the referring page, a coarse device type (mobile or desktop), and a browser family (Chrome, Safari, Firefox, Edge, other). To count unique visitors without tracking anyone, we store a one-way SHA-256 hash of the visitor's IP address and browser signature combined with the current date — the hash changes every day, so it cannot be used to follow a visitor across days or across sites, and the raw IP address is never written to disk.
We set no cookies on redirects and no third-party analytics or ad scripts run anywhere on Flit.
What we never do
- Sell or share your data, or your visitors' data, with advertisers or data brokers.
- Store raw visitor IP addresses or build cross-site visitor profiles.
- Put tracking parameters or interstitial pages into your redirects.
Where data lives
Data is stored in Microsoft Azure (United States regions), encrypted in transit and at rest. Subprocessors: Microsoft Azure (hosting, email), Stripe (payments), Cloudflare (DNS and network edge). Each processes only what its role requires.
Retention and deletion
Account data is kept while your account exists. Deleting a link deletes its click events. Deleting your account deletes your links and their analytics; backups age out within 35 days. To delete your account, email hello@flitlink.com from your account address — we confirm and complete deletion within 30 days.
Your rights
Wherever you live, we honor requests to access, correct, export, or delete your personal data — email hello@flitlink.com. If you're in the EU/UK (GDPR) or California (CCPA), these are your statutory rights; we don't "sell" personal information as those laws define it.
Changes
If this policy changes materially we'll email account holders before the change takes effect. The effective date at the top always reflects the current version.