Operational draft — retention and legal review required before launch
Privacy Policy
Effective July 16, 2026 · Last updated July 16, 2026
What this policy covers
This policy explains how Vaz.im handles information when you use Vaz.im. It describes the service as currently implemented and is not a claim of compliance with every privacy law.
Information we handle
Accounts
For registered users, we store display name, email address, authentication and email-verification information, and account status, tier, and role. Passwords are stored only in hashed form.
Short links
We store the submitted destination URL, destination hostname, generated short code, ownership when applicable, creation source, status, expiration or restriction information, and timestamps.
Redirect analytics
For successful redirects, we may store event time, a daily rotating HMAC visitor hash derived from the requesting IP address, coarse referrer host and category, browser family, operating-system family, device class, bot classification, response type, and aggregated daily counts. Country is reserved in the data model but is not currently populated.
Abuse reports
When someone reports a link, we store the reported short link, selected reason, optional contact email and notes, submission and review timestamps, review status, the administrator responsible for the latest review when applicable, and an internal audit trail of report-status transitions. Domain block and unblock decisions also create an internal moderation audit record. Request IP addresses are used transiently to rate-limit submissions but are not stored as ordinary abuse-report records.
Privacy limits in analytics
- Raw IP addresses are not stored as ordinary redirect-analytics records. They may be used transiently for rate limiting, service security, coarse classification, and creating the visitor hash.
- Full user-agent strings are not stored in redirect analytics; only coarse classifications are retained.
- Full referrer URLs are not stored in redirect analytics; only a normalized host and broad category are retained.
- Visitor hashes rotate by the event's UTC date and are not intended to identify a person persistently across days. Automated visits currently contribute to unique-visitor aggregates.
- Infrastructure, web-server, security, and error logs may process or temporarily contain IP addresses and other request details even though ordinary analytics records do not.
How we use information
We use information to create and operate links, authenticate accounts, secure the service, enforce usage limits, prevent and investigate abuse, provide basic statistics, diagnose problems, maintain integrity, communicate service messages, and meet legal obligations.
Queues, QR codes, and service providers
Redirect analytics is processed asynchronously through database-backed queues, so counts may take time to appear. Failed analytics processing does not change a link's destination. QR codes are generated locally from the Vaz.im short URL—not the submitted destination—and may be cached.
We may use hosting, database, email-delivery, security, monitoring, and infrastructure providers to operate Vaz.im. We do not currently add advertising trackers or third-party behavioral analytics through this application.
Retention and deletion
The current operational defaults retain raw click events for 90 days, daily visitor markers for 8 days, failed queue records for 30 days, and resolved or dismissed abuse reports for 730 days. Daily aggregate counts may be retained longer. These periods are configurable and may change as operational and legal requirements are reviewed.
Account and link information may be retained while needed to operate issued links, maintain security and integrity, resolve abuse reports, produce aggregate reporting, or comply with law. If an account is deleted, issued short links may remain active and become ownerless under the current product policy. Analytics associated with an issued link may also be retained where necessary for security, integrity, or aggregate reporting.
Your requests
To ask about access, correction, or deletion of account information, email legal@vaz.im. We may need to verify your identity and may retain information when legally permitted or required.
Children
Vaz.im is not directed to children under 13, and we do not knowingly seek personal information from children under 13. Contact us if you believe a child has provided account information.
Changes and contact
We may update this policy as the service changes. We will revise the last-updated date and provide additional notice when appropriate. Privacy questions may be sent to legal@vaz.im.